diff --git a/config/overlays.mk b/config/overlays.mk index e50d69d67..2355c13cd 100644 --- a/config/overlays.mk +++ b/config/overlays.mk @@ -58,6 +58,7 @@ build/src/ov_SC01_005/ov_SC01_005_jr_8013F350.o: JTBL_PADS := 0,0 # §8e pads ( build/src/ov_SC01_005/ov_SC01_005_jr_80154C24.o: JTBL_PADS := 0,0 # §8e pads (jtbl_carve.py) tables=+0x0,+0x24 build/src/ov_SC01_005/ov_SC01_005_jr_801588CC.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x28 build/src/ov_SC01_005/ov_SC01_005_jr_80159C84.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x20 +build/src/ov_SC01_005/ov_SC01_005_jr_8015AE2C.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x20 ov_SC01_005_CHECK_SHA := config/check.ov_SC01_005.sha ov_SC01_005_SYMBOLS := config/symbols.ov_SC01_005.txt ov_SC01_005_SIG := .run/sig.ov_SC01_005.jsonl @@ -86,6 +87,7 @@ build/src/ov_SC01_006/ov_SC01_006_jr_8013F350.o: JTBL_PADS := 0,0 # §8e pads ( build/src/ov_SC01_006/ov_SC01_006_jr_80154C24.o: JTBL_PADS := 0,0 # §8e pads (jtbl_carve.py) tables=+0x0,+0x24 build/src/ov_SC01_006/ov_SC01_006_jr_801588CC.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x28 build/src/ov_SC01_006/ov_SC01_006_jr_80159C84.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x20 +build/src/ov_SC01_006/ov_SC01_006_jr_8015AE2C.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x20 ov_SC01_006_CHECK_SHA := config/check.ov_SC01_006.sha ov_SC01_006_SYMBOLS := config/symbols.ov_SC01_006.txt ov_SC01_006_SIG := .run/sig.ov_SC01_006.jsonl @@ -114,6 +116,7 @@ build/src/ov_SC03_001/ov_SC03_001_jr_8013F350.o: JTBL_PADS := 0,0 # §8e pads ( build/src/ov_SC03_001/ov_SC03_001_jr_80154C24.o: JTBL_PADS := 0,0 # §8e pads (jtbl_carve.py) tables=+0x0,+0x24 build/src/ov_SC03_001/ov_SC03_001_jr_801588CC.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x28 build/src/ov_SC03_001/ov_SC03_001_jr_80159C84.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x20 +build/src/ov_SC03_001/ov_SC03_001_jr_8015AE2C.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x20 ov_SC03_001_CHECK_SHA := config/check.ov_SC03_001.sha ov_SC03_001_SYMBOLS := config/symbols.ov_SC03_001.txt ov_SC03_001_SIG := .run/sig.ov_SC03_001.jsonl @@ -200,6 +203,7 @@ build/src/ov_SC02_000/ov_SC02_000_jr_8013F350.o: JTBL_PADS := 0,0 # §8e pads ( build/src/ov_SC02_000/ov_SC02_000_jr_80154C24.o: JTBL_PADS := 0,0 # §8e pads (jtbl_carve.py) tables=+0x0,+0x24 build/src/ov_SC02_000/ov_SC02_000_jr_801588CC.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x28 build/src/ov_SC02_000/ov_SC02_000_jr_80159C84.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x20 +build/src/ov_SC02_000/ov_SC02_000_jr_8015AE2C.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x20 ov_SC02_000_CHECK_SHA := config/check.ov_SC02_000.sha ov_SC02_000_SYMBOLS := config/symbols.ov_SC02_000.txt ov_SC02_000_SIG := .run/sig.ov_SC02_000.jsonl @@ -228,6 +232,7 @@ build/src/ov_SC02_003/ov_SC02_003_jr_8013F350.o: JTBL_PADS := 0,0 # §8e pads ( build/src/ov_SC02_003/ov_SC02_003_jr_80154C24.o: JTBL_PADS := 0,0 # §8e pads (jtbl_carve.py) tables=+0x0,+0x24 build/src/ov_SC02_003/ov_SC02_003_jr_801588CC.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x28 build/src/ov_SC02_003/ov_SC02_003_jr_80159C84.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x20 +build/src/ov_SC02_003/ov_SC02_003_jr_8015AE2C.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x20 ov_SC02_003_CHECK_SHA := config/check.ov_SC02_003.sha ov_SC02_003_SYMBOLS := config/symbols.ov_SC02_003.txt ov_SC02_003_SIG := .run/sig.ov_SC02_003.jsonl @@ -256,6 +261,7 @@ build/src/ov_SC03_002/ov_SC03_002_jr_8013F350.o: JTBL_PADS := 0,0 # §8e pads ( build/src/ov_SC03_002/ov_SC03_002_jr_80154C24.o: JTBL_PADS := 0,0 # §8e pads (jtbl_carve.py) tables=+0x0,+0x24 build/src/ov_SC03_002/ov_SC03_002_jr_801588CC.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x28 build/src/ov_SC03_002/ov_SC03_002_jr_80159C84.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x20 +build/src/ov_SC03_002/ov_SC03_002_jr_8015AE2C.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x20 ov_SC03_002_CHECK_SHA := config/check.ov_SC03_002.sha ov_SC03_002_SYMBOLS := config/symbols.ov_SC03_002.txt ov_SC03_002_SIG := .run/sig.ov_SC03_002.jsonl @@ -284,6 +290,7 @@ build/src/ov_SC03_006/ov_SC03_006_jr_8013F350.o: JTBL_PADS := 0,0 # §8e pads ( build/src/ov_SC03_006/ov_SC03_006_jr_80154C24.o: JTBL_PADS := 0,0 # §8e pads (jtbl_carve.py) tables=+0x0,+0x24 build/src/ov_SC03_006/ov_SC03_006_jr_801588CC.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x28 build/src/ov_SC03_006/ov_SC03_006_jr_80159C84.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x20 +build/src/ov_SC03_006/ov_SC03_006_jr_8015AE2C.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x20 ov_SC03_006_CHECK_SHA := config/check.ov_SC03_006.sha ov_SC03_006_SYMBOLS := config/symbols.ov_SC03_006.txt ov_SC03_006_SIG := .run/sig.ov_SC03_006.jsonl @@ -312,6 +319,7 @@ build/src/ov_SC04_000/ov_SC04_000_jr_8013F350.o: JTBL_PADS := 0,0 # §8e pads ( build/src/ov_SC04_000/ov_SC04_000_jr_80154C24.o: JTBL_PADS := 0,0 # §8e pads (jtbl_carve.py) tables=+0x0,+0x24 build/src/ov_SC04_000/ov_SC04_000_jr_801588CC.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x28 build/src/ov_SC04_000/ov_SC04_000_jr_80159C84.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x20 +build/src/ov_SC04_000/ov_SC04_000_jr_8015AE2C.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x20 ov_SC04_000_CHECK_SHA := config/check.ov_SC04_000.sha ov_SC04_000_SYMBOLS := config/symbols.ov_SC04_000.txt ov_SC04_000_SIG := .run/sig.ov_SC04_000.jsonl @@ -340,6 +348,7 @@ build/src/ov_SC04_018/ov_SC04_018_jr_8013F350.o: JTBL_PADS := 0,0 # §8e pads ( build/src/ov_SC04_018/ov_SC04_018_jr_80154C24.o: JTBL_PADS := 0,0 # §8e pads (jtbl_carve.py) tables=+0x0,+0x24 build/src/ov_SC04_018/ov_SC04_018_jr_801588CC.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x28 build/src/ov_SC04_018/ov_SC04_018_jr_80159C84.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x20 +build/src/ov_SC04_018/ov_SC04_018_jr_8015AE2C.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x20 ov_SC04_018_CHECK_SHA := config/check.ov_SC04_018.sha ov_SC04_018_SYMBOLS := config/symbols.ov_SC04_018.txt ov_SC04_018_SIG := .run/sig.ov_SC04_018.jsonl @@ -368,6 +377,7 @@ build/src/ov_SC04_019/ov_SC04_019_jr_8013F350.o: JTBL_PADS := 0,0 # §8e pads ( build/src/ov_SC04_019/ov_SC04_019_jr_80154C24.o: JTBL_PADS := 0,0 # §8e pads (jtbl_carve.py) tables=+0x0,+0x24 build/src/ov_SC04_019/ov_SC04_019_jr_801588CC.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x28 build/src/ov_SC04_019/ov_SC04_019_jr_80159C84.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x20 +build/src/ov_SC04_019/ov_SC04_019_jr_8015AE2C.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x20 ov_SC04_019_CHECK_SHA := config/check.ov_SC04_019.sha ov_SC04_019_SYMBOLS := config/symbols.ov_SC04_019.txt ov_SC04_019_SIG := .run/sig.ov_SC04_019.jsonl @@ -396,6 +406,7 @@ build/src/ov_SC05_000/ov_SC05_000_jr_8013F350.o: JTBL_PADS := 0,0 # §8e pads ( build/src/ov_SC05_000/ov_SC05_000_jr_80154C24.o: JTBL_PADS := 0,0 # §8e pads (jtbl_carve.py) tables=+0x0,+0x24 build/src/ov_SC05_000/ov_SC05_000_jr_801588CC.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x28 build/src/ov_SC05_000/ov_SC05_000_jr_80159C84.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x20 +build/src/ov_SC05_000/ov_SC05_000_jr_8015AE2C.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x20 ov_SC05_000_CHECK_SHA := config/check.ov_SC05_000.sha ov_SC05_000_SYMBOLS := config/symbols.ov_SC05_000.txt ov_SC05_000_SIG := .run/sig.ov_SC05_000.jsonl @@ -424,6 +435,7 @@ build/src/ov_SC06_000/ov_SC06_000_jr_8013F350.o: JTBL_PADS := 0,0 # §8e pads ( build/src/ov_SC06_000/ov_SC06_000_jr_80154C24.o: JTBL_PADS := 0,0 # §8e pads (jtbl_carve.py) tables=+0x0,+0x24 build/src/ov_SC06_000/ov_SC06_000_jr_801588CC.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x28 build/src/ov_SC06_000/ov_SC06_000_jr_80159C84.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x20 +build/src/ov_SC06_000/ov_SC06_000_jr_8015AE2C.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x20 ov_SC06_000_CHECK_SHA := config/check.ov_SC06_000.sha ov_SC06_000_SYMBOLS := config/symbols.ov_SC06_000.txt ov_SC06_000_SIG := .run/sig.ov_SC06_000.jsonl @@ -452,6 +464,7 @@ build/src/ov_SC07_000/ov_SC07_000_jr_8013F350.o: JTBL_PADS := 0,0 # §8e pads ( build/src/ov_SC07_000/ov_SC07_000_jr_80154C24.o: JTBL_PADS := 0,0 # §8e pads (jtbl_carve.py) tables=+0x0,+0x24 build/src/ov_SC07_000/ov_SC07_000_jr_801588CC.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x28 build/src/ov_SC07_000/ov_SC07_000_jr_80159C84.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x20 +build/src/ov_SC07_000/ov_SC07_000_jr_8015AE2C.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x20 ov_SC07_000_CHECK_SHA := config/check.ov_SC07_000.sha ov_SC07_000_SYMBOLS := config/symbols.ov_SC07_000.txt ov_SC07_000_SIG := .run/sig.ov_SC07_000.jsonl @@ -509,6 +522,7 @@ build/src/ov_SC01_008/ov_SC01_008_jr_8013F350.o: JTBL_PADS := 0,0 # §8e pads ( build/src/ov_SC01_008/ov_SC01_008_jr_80154C24.o: JTBL_PADS := 0,0 # §8e pads (jtbl_carve.py) tables=+0x0,+0x24 build/src/ov_SC01_008/ov_SC01_008_jr_801588CC.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x28 build/src/ov_SC01_008/ov_SC01_008_jr_80159C84.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x20 +build/src/ov_SC01_008/ov_SC01_008_jr_8015AE2C.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x20 ov_SC01_008_CHECK_SHA := config/check.ov_SC01_008.sha ov_SC01_008_SYMBOLS := config/symbols.ov_SC01_008.txt ov_SC01_008_SIG := .run/sig.ov_SC01_008.jsonl @@ -537,6 +551,7 @@ build/src/ov_SC01_009/ov_SC01_009_jr_8013F350.o: JTBL_PADS := 0,0 # §8e pads ( build/src/ov_SC01_009/ov_SC01_009_jr_80154C24.o: JTBL_PADS := 0,0 # §8e pads (jtbl_carve.py) tables=+0x0,+0x24 build/src/ov_SC01_009/ov_SC01_009_jr_801588CC.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x28 build/src/ov_SC01_009/ov_SC01_009_jr_80159C84.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x20 +build/src/ov_SC01_009/ov_SC01_009_jr_8015AE2C.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x20 ov_SC01_009_CHECK_SHA := config/check.ov_SC01_009.sha ov_SC01_009_SYMBOLS := config/symbols.ov_SC01_009.txt ov_SC01_009_SIG := .run/sig.ov_SC01_009.jsonl @@ -565,6 +580,7 @@ build/src/ov_SC01_074/ov_SC01_074_jr_8013F350.o: JTBL_PADS := 0,0 # §8e pads ( build/src/ov_SC01_074/ov_SC01_074_jr_80154C24.o: JTBL_PADS := 0,0 # §8e pads (jtbl_carve.py) tables=+0x0,+0x24 build/src/ov_SC01_074/ov_SC01_074_jr_801588CC.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x28 build/src/ov_SC01_074/ov_SC01_074_jr_80159C84.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x20 +build/src/ov_SC01_074/ov_SC01_074_jr_8015AE2C.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x20 ov_SC01_074_CHECK_SHA := config/check.ov_SC01_074.sha ov_SC01_074_SYMBOLS := config/symbols.ov_SC01_074.txt ov_SC01_074_SIG := .run/sig.ov_SC01_074.jsonl @@ -593,6 +609,7 @@ build/src/ov_SC01_080/ov_SC01_080_jr_8013F350.o: JTBL_PADS := 0,0 # §8e pads ( build/src/ov_SC01_080/ov_SC01_080_jr_80154C24.o: JTBL_PADS := 0,0 # §8e pads (jtbl_carve.py) tables=+0x0,+0x24 build/src/ov_SC01_080/ov_SC01_080_jr_801588CC.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x28 build/src/ov_SC01_080/ov_SC01_080_jr_80159C84.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x20 +build/src/ov_SC01_080/ov_SC01_080_jr_8015AE2C.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x20 ov_SC01_080_CHECK_SHA := config/check.ov_SC01_080.sha ov_SC01_080_SYMBOLS := config/symbols.ov_SC01_080.txt ov_SC01_080_SIG := .run/sig.ov_SC01_080.jsonl @@ -621,6 +638,7 @@ build/src/ov_SC01_084/ov_SC01_084_jr_8013F350.o: JTBL_PADS := 0,0 # §8e pads ( build/src/ov_SC01_084/ov_SC01_084_jr_80154C24.o: JTBL_PADS := 0,0 # §8e pads (jtbl_carve.py) tables=+0x0,+0x24 build/src/ov_SC01_084/ov_SC01_084_jr_801588CC.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x28 build/src/ov_SC01_084/ov_SC01_084_jr_80159C84.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x20 +build/src/ov_SC01_084/ov_SC01_084_jr_8015AE2C.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x20 ov_SC01_084_CHECK_SHA := config/check.ov_SC01_084.sha ov_SC01_084_SYMBOLS := config/symbols.ov_SC01_084.txt ov_SC01_084_SIG := .run/sig.ov_SC01_084.jsonl @@ -649,6 +667,7 @@ build/src/ov_SC02_004/ov_SC02_004_jr_8013F350.o: JTBL_PADS := 0,0 # §8e pads ( build/src/ov_SC02_004/ov_SC02_004_jr_80154C24.o: JTBL_PADS := 0,0 # §8e pads (jtbl_carve.py) tables=+0x0,+0x24 build/src/ov_SC02_004/ov_SC02_004_jr_801588CC.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x28 build/src/ov_SC02_004/ov_SC02_004_jr_80159C84.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x20 +build/src/ov_SC02_004/ov_SC02_004_jr_8015AE2C.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x20 ov_SC02_004_CHECK_SHA := config/check.ov_SC02_004.sha ov_SC02_004_SYMBOLS := config/symbols.ov_SC02_004.txt ov_SC02_004_SIG := .run/sig.ov_SC02_004.jsonl @@ -677,6 +696,7 @@ build/src/ov_SC02_005/ov_SC02_005_jr_8013F350.o: JTBL_PADS := 0,0 # §8e pads ( build/src/ov_SC02_005/ov_SC02_005_jr_80154C24.o: JTBL_PADS := 0,0 # §8e pads (jtbl_carve.py) tables=+0x0,+0x24 build/src/ov_SC02_005/ov_SC02_005_jr_801588CC.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x28 build/src/ov_SC02_005/ov_SC02_005_jr_80159C84.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x20 +build/src/ov_SC02_005/ov_SC02_005_jr_8015AE2C.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x20 ov_SC02_005_CHECK_SHA := config/check.ov_SC02_005.sha ov_SC02_005_SYMBOLS := config/symbols.ov_SC02_005.txt ov_SC02_005_SIG := .run/sig.ov_SC02_005.jsonl @@ -705,6 +725,7 @@ build/src/ov_SC02_011/ov_SC02_011_jr_8013F350.o: JTBL_PADS := 0,0 # §8e pads ( build/src/ov_SC02_011/ov_SC02_011_jr_80154C24.o: JTBL_PADS := 0,0 # §8e pads (jtbl_carve.py) tables=+0x0,+0x24 build/src/ov_SC02_011/ov_SC02_011_jr_801588CC.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x28 build/src/ov_SC02_011/ov_SC02_011_jr_80159C84.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x20 +build/src/ov_SC02_011/ov_SC02_011_jr_8015AE2C.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x20 ov_SC02_011_CHECK_SHA := config/check.ov_SC02_011.sha ov_SC02_011_SYMBOLS := config/symbols.ov_SC02_011.txt ov_SC02_011_SIG := .run/sig.ov_SC02_011.jsonl @@ -733,6 +754,7 @@ build/src/ov_SC02_015/ov_SC02_015_jr_8013F350.o: JTBL_PADS := 0,0 # §8e pads ( build/src/ov_SC02_015/ov_SC02_015_jr_80154C24.o: JTBL_PADS := 0,0 # §8e pads (jtbl_carve.py) tables=+0x0,+0x24 build/src/ov_SC02_015/ov_SC02_015_jr_801588CC.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x28 build/src/ov_SC02_015/ov_SC02_015_jr_80159C84.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x20 +build/src/ov_SC02_015/ov_SC02_015_jr_8015AE2C.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x20 ov_SC02_015_CHECK_SHA := config/check.ov_SC02_015.sha ov_SC02_015_SYMBOLS := config/symbols.ov_SC02_015.txt ov_SC02_015_SIG := .run/sig.ov_SC02_015.jsonl @@ -761,6 +783,7 @@ build/src/ov_SC02_016/ov_SC02_016_jr_8013F350.o: JTBL_PADS := 0,0 # §8e pads ( build/src/ov_SC02_016/ov_SC02_016_jr_80154C24.o: JTBL_PADS := 0,0 # §8e pads (jtbl_carve.py) tables=+0x0,+0x24 build/src/ov_SC02_016/ov_SC02_016_jr_801588CC.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x28 build/src/ov_SC02_016/ov_SC02_016_jr_80159C84.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x20 +build/src/ov_SC02_016/ov_SC02_016_jr_8015AE2C.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x20 ov_SC02_016_CHECK_SHA := config/check.ov_SC02_016.sha ov_SC02_016_SYMBOLS := config/symbols.ov_SC02_016.txt ov_SC02_016_SIG := .run/sig.ov_SC02_016.jsonl @@ -789,6 +812,7 @@ build/src/ov_SC02_017/ov_SC02_017_jr_8013F350.o: JTBL_PADS := 0,0 # §8e pads ( build/src/ov_SC02_017/ov_SC02_017_jr_80154C24.o: JTBL_PADS := 0,0 # §8e pads (jtbl_carve.py) tables=+0x0,+0x24 build/src/ov_SC02_017/ov_SC02_017_jr_801588CC.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x28 build/src/ov_SC02_017/ov_SC02_017_jr_80159C84.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x20 +build/src/ov_SC02_017/ov_SC02_017_jr_8015AE2C.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x20 ov_SC02_017_CHECK_SHA := config/check.ov_SC02_017.sha ov_SC02_017_SYMBOLS := config/symbols.ov_SC02_017.txt ov_SC02_017_SIG := .run/sig.ov_SC02_017.jsonl @@ -817,6 +841,7 @@ build/src/ov_SC02_021/ov_SC02_021_jr_8013F350.o: JTBL_PADS := 0,0 # §8e pads ( build/src/ov_SC02_021/ov_SC02_021_jr_80154C24.o: JTBL_PADS := 0,0 # §8e pads (jtbl_carve.py) tables=+0x0,+0x24 build/src/ov_SC02_021/ov_SC02_021_jr_801588CC.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x28 build/src/ov_SC02_021/ov_SC02_021_jr_80159C84.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x20 +build/src/ov_SC02_021/ov_SC02_021_jr_8015AE2C.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x20 ov_SC02_021_CHECK_SHA := config/check.ov_SC02_021.sha ov_SC02_021_SYMBOLS := config/symbols.ov_SC02_021.txt ov_SC02_021_SIG := .run/sig.ov_SC02_021.jsonl @@ -845,6 +870,7 @@ build/src/ov_SC02_026/ov_SC02_026_jr_8013F350.o: JTBL_PADS := 0,0 # §8e pads ( build/src/ov_SC02_026/ov_SC02_026_jr_80154C24.o: JTBL_PADS := 0,0 # §8e pads (jtbl_carve.py) tables=+0x0,+0x24 build/src/ov_SC02_026/ov_SC02_026_jr_801588CC.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x28 build/src/ov_SC02_026/ov_SC02_026_jr_80159C84.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x20 +build/src/ov_SC02_026/ov_SC02_026_jr_8015AE2C.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x20 ov_SC02_026_CHECK_SHA := config/check.ov_SC02_026.sha ov_SC02_026_SYMBOLS := config/symbols.ov_SC02_026.txt ov_SC02_026_SIG := .run/sig.ov_SC02_026.jsonl @@ -873,6 +899,7 @@ build/src/ov_SC02_027/ov_SC02_027_jr_8013F350.o: JTBL_PADS := 0,0 # §8e pads ( build/src/ov_SC02_027/ov_SC02_027_jr_80154C24.o: JTBL_PADS := 0,0 # §8e pads (jtbl_carve.py) tables=+0x0,+0x24 build/src/ov_SC02_027/ov_SC02_027_jr_801588CC.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x28 build/src/ov_SC02_027/ov_SC02_027_jr_80159C84.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x20 +build/src/ov_SC02_027/ov_SC02_027_jr_8015AE2C.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x20 ov_SC02_027_CHECK_SHA := config/check.ov_SC02_027.sha ov_SC02_027_SYMBOLS := config/symbols.ov_SC02_027.txt ov_SC02_027_SIG := .run/sig.ov_SC02_027.jsonl @@ -901,6 +928,7 @@ build/src/ov_SC02_028/ov_SC02_028_jr_8013F350.o: JTBL_PADS := 0,0 # §8e pads ( build/src/ov_SC02_028/ov_SC02_028_jr_80154C24.o: JTBL_PADS := 0,0 # §8e pads (jtbl_carve.py) tables=+0x0,+0x24 build/src/ov_SC02_028/ov_SC02_028_jr_801588CC.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x28 build/src/ov_SC02_028/ov_SC02_028_jr_80159C84.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x20 +build/src/ov_SC02_028/ov_SC02_028_jr_8015AE2C.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x20 ov_SC02_028_CHECK_SHA := config/check.ov_SC02_028.sha ov_SC02_028_SYMBOLS := config/symbols.ov_SC02_028.txt ov_SC02_028_SIG := .run/sig.ov_SC02_028.jsonl @@ -929,6 +957,7 @@ build/src/ov_SC02_031/ov_SC02_031_jr_8013F350.o: JTBL_PADS := 0,0 # §8e pads ( build/src/ov_SC02_031/ov_SC02_031_jr_80154C24.o: JTBL_PADS := 0,0 # §8e pads (jtbl_carve.py) tables=+0x0,+0x24 build/src/ov_SC02_031/ov_SC02_031_jr_801588CC.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x28 build/src/ov_SC02_031/ov_SC02_031_jr_80159C84.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x20 +build/src/ov_SC02_031/ov_SC02_031_jr_8015AE2C.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x20 ov_SC02_031_CHECK_SHA := config/check.ov_SC02_031.sha ov_SC02_031_SYMBOLS := config/symbols.ov_SC02_031.txt ov_SC02_031_SIG := .run/sig.ov_SC02_031.jsonl @@ -957,6 +986,7 @@ build/src/ov_SC02_035/ov_SC02_035_jr_8013F350.o: JTBL_PADS := 0,0 # §8e pads ( build/src/ov_SC02_035/ov_SC02_035_jr_80154C24.o: JTBL_PADS := 0,0 # §8e pads (jtbl_carve.py) tables=+0x0,+0x24 build/src/ov_SC02_035/ov_SC02_035_jr_801588CC.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x28 build/src/ov_SC02_035/ov_SC02_035_jr_80159C84.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x20 +build/src/ov_SC02_035/ov_SC02_035_jr_8015AE2C.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x20 ov_SC02_035_CHECK_SHA := config/check.ov_SC02_035.sha ov_SC02_035_SYMBOLS := config/symbols.ov_SC02_035.txt ov_SC02_035_SIG := .run/sig.ov_SC02_035.jsonl @@ -985,6 +1015,7 @@ build/src/ov_SC02_039/ov_SC02_039_jr_8013F350.o: JTBL_PADS := 0,0 # §8e pads ( build/src/ov_SC02_039/ov_SC02_039_jr_80154C24.o: JTBL_PADS := 0,0 # §8e pads (jtbl_carve.py) tables=+0x0,+0x24 build/src/ov_SC02_039/ov_SC02_039_jr_801588CC.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x28 build/src/ov_SC02_039/ov_SC02_039_jr_80159C84.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x20 +build/src/ov_SC02_039/ov_SC02_039_jr_8015AE2C.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x20 ov_SC02_039_CHECK_SHA := config/check.ov_SC02_039.sha ov_SC02_039_SYMBOLS := config/symbols.ov_SC02_039.txt ov_SC02_039_SIG := .run/sig.ov_SC02_039.jsonl @@ -1013,6 +1044,7 @@ build/src/ov_SC02_041/ov_SC02_041_jr_8013F350.o: JTBL_PADS := 0,0 # §8e pads ( build/src/ov_SC02_041/ov_SC02_041_jr_80154C24.o: JTBL_PADS := 0,0 # §8e pads (jtbl_carve.py) tables=+0x0,+0x24 build/src/ov_SC02_041/ov_SC02_041_jr_801588CC.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x28 build/src/ov_SC02_041/ov_SC02_041_jr_80159C84.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x20 +build/src/ov_SC02_041/ov_SC02_041_jr_8015AE2C.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x20 ov_SC02_041_CHECK_SHA := config/check.ov_SC02_041.sha ov_SC02_041_SYMBOLS := config/symbols.ov_SC02_041.txt ov_SC02_041_SIG := .run/sig.ov_SC02_041.jsonl @@ -1041,6 +1073,7 @@ build/src/ov_SC03_003/ov_SC03_003_jr_8013F350.o: JTBL_PADS := 0,0 # §8e pads ( build/src/ov_SC03_003/ov_SC03_003_jr_80154C24.o: JTBL_PADS := 0,0 # §8e pads (jtbl_carve.py) tables=+0x0,+0x24 build/src/ov_SC03_003/ov_SC03_003_jr_801588CC.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x28 build/src/ov_SC03_003/ov_SC03_003_jr_80159C84.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x20 +build/src/ov_SC03_003/ov_SC03_003_jr_8015AE2C.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x20 ov_SC03_003_CHECK_SHA := config/check.ov_SC03_003.sha ov_SC03_003_SYMBOLS := config/symbols.ov_SC03_003.txt ov_SC03_003_SIG := .run/sig.ov_SC03_003.jsonl @@ -1069,6 +1102,7 @@ build/src/ov_SC03_007/ov_SC03_007_jr_8013F350.o: JTBL_PADS := 0,0 # §8e pads ( build/src/ov_SC03_007/ov_SC03_007_jr_80154C24.o: JTBL_PADS := 0,0 # §8e pads (jtbl_carve.py) tables=+0x0,+0x24 build/src/ov_SC03_007/ov_SC03_007_jr_801588CC.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x28 build/src/ov_SC03_007/ov_SC03_007_jr_80159C84.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x20 +build/src/ov_SC03_007/ov_SC03_007_jr_8015AE2C.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x20 ov_SC03_007_CHECK_SHA := config/check.ov_SC03_007.sha ov_SC03_007_SYMBOLS := config/symbols.ov_SC03_007.txt ov_SC03_007_SIG := .run/sig.ov_SC03_007.jsonl @@ -1097,6 +1131,7 @@ build/src/ov_SC03_010/ov_SC03_010_jr_8013F350.o: JTBL_PADS := 0,0 # §8e pads ( build/src/ov_SC03_010/ov_SC03_010_jr_80154C24.o: JTBL_PADS := 0,0 # §8e pads (jtbl_carve.py) tables=+0x0,+0x24 build/src/ov_SC03_010/ov_SC03_010_jr_801588CC.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x28 build/src/ov_SC03_010/ov_SC03_010_jr_80159C84.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x20 +build/src/ov_SC03_010/ov_SC03_010_jr_8015AE2C.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x20 ov_SC03_010_CHECK_SHA := config/check.ov_SC03_010.sha ov_SC03_010_SYMBOLS := config/symbols.ov_SC03_010.txt ov_SC03_010_SIG := .run/sig.ov_SC03_010.jsonl @@ -1125,6 +1160,7 @@ build/src/ov_SC03_011/ov_SC03_011_jr_8013F350.o: JTBL_PADS := 0,0 # §8e pads ( build/src/ov_SC03_011/ov_SC03_011_jr_80154C24.o: JTBL_PADS := 0,0 # §8e pads (jtbl_carve.py) tables=+0x0,+0x24 build/src/ov_SC03_011/ov_SC03_011_jr_801588CC.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x28 build/src/ov_SC03_011/ov_SC03_011_jr_80159C84.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x20 +build/src/ov_SC03_011/ov_SC03_011_jr_8015AE2C.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x20 ov_SC03_011_CHECK_SHA := config/check.ov_SC03_011.sha ov_SC03_011_SYMBOLS := config/symbols.ov_SC03_011.txt ov_SC03_011_SIG := .run/sig.ov_SC03_011.jsonl @@ -1153,6 +1189,7 @@ build/src/ov_SC03_012/ov_SC03_012_jr_8013F350.o: JTBL_PADS := 0,0 # §8e pads ( build/src/ov_SC03_012/ov_SC03_012_jr_80154C24.o: JTBL_PADS := 0,0 # §8e pads (jtbl_carve.py) tables=+0x0,+0x24 build/src/ov_SC03_012/ov_SC03_012_jr_801588CC.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x28 build/src/ov_SC03_012/ov_SC03_012_jr_80159C84.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x20 +build/src/ov_SC03_012/ov_SC03_012_jr_8015AE2C.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x20 ov_SC03_012_CHECK_SHA := config/check.ov_SC03_012.sha ov_SC03_012_SYMBOLS := config/symbols.ov_SC03_012.txt ov_SC03_012_SIG := .run/sig.ov_SC03_012.jsonl @@ -1181,6 +1218,7 @@ build/src/ov_SC03_013/ov_SC03_013_jr_8013F350.o: JTBL_PADS := 0,0 # §8e pads ( build/src/ov_SC03_013/ov_SC03_013_jr_80154C24.o: JTBL_PADS := 0,0 # §8e pads (jtbl_carve.py) tables=+0x0,+0x24 build/src/ov_SC03_013/ov_SC03_013_jr_801588CC.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x28 build/src/ov_SC03_013/ov_SC03_013_jr_80159C84.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x20 +build/src/ov_SC03_013/ov_SC03_013_jr_8015AE2C.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x20 ov_SC03_013_CHECK_SHA := config/check.ov_SC03_013.sha ov_SC03_013_SYMBOLS := config/symbols.ov_SC03_013.txt ov_SC03_013_SIG := .run/sig.ov_SC03_013.jsonl @@ -1209,6 +1247,7 @@ build/src/ov_SC03_014/ov_SC03_014_jr_8013F350.o: JTBL_PADS := 0,0 # §8e pads ( build/src/ov_SC03_014/ov_SC03_014_jr_80154C24.o: JTBL_PADS := 0,0 # §8e pads (jtbl_carve.py) tables=+0x0,+0x24 build/src/ov_SC03_014/ov_SC03_014_jr_801588CC.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x28 build/src/ov_SC03_014/ov_SC03_014_jr_80159C84.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x20 +build/src/ov_SC03_014/ov_SC03_014_jr_8015AE2C.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x20 ov_SC03_014_CHECK_SHA := config/check.ov_SC03_014.sha ov_SC03_014_SYMBOLS := config/symbols.ov_SC03_014.txt ov_SC03_014_SIG := .run/sig.ov_SC03_014.jsonl @@ -1237,6 +1276,7 @@ build/src/ov_SC03_015/ov_SC03_015_jr_8013F350.o: JTBL_PADS := 0,0 # §8e pads ( build/src/ov_SC03_015/ov_SC03_015_jr_80154C24.o: JTBL_PADS := 0,0 # §8e pads (jtbl_carve.py) tables=+0x0,+0x24 build/src/ov_SC03_015/ov_SC03_015_jr_801588CC.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x28 build/src/ov_SC03_015/ov_SC03_015_jr_80159C84.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x20 +build/src/ov_SC03_015/ov_SC03_015_jr_8015AE2C.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x20 ov_SC03_015_CHECK_SHA := config/check.ov_SC03_015.sha ov_SC03_015_SYMBOLS := config/symbols.ov_SC03_015.txt ov_SC03_015_SIG := .run/sig.ov_SC03_015.jsonl @@ -1265,6 +1305,7 @@ build/src/ov_SC03_023/ov_SC03_023_jr_8013F350.o: JTBL_PADS := 0,0 # §8e pads ( build/src/ov_SC03_023/ov_SC03_023_jr_80154C24.o: JTBL_PADS := 0,0 # §8e pads (jtbl_carve.py) tables=+0x0,+0x24 build/src/ov_SC03_023/ov_SC03_023_jr_801588CC.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x28 build/src/ov_SC03_023/ov_SC03_023_jr_80159C84.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x20 +build/src/ov_SC03_023/ov_SC03_023_jr_8015AE2C.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x20 ov_SC03_023_CHECK_SHA := config/check.ov_SC03_023.sha ov_SC03_023_SYMBOLS := config/symbols.ov_SC03_023.txt ov_SC03_023_SIG := .run/sig.ov_SC03_023.jsonl @@ -1293,6 +1334,7 @@ build/src/ov_SC03_024/ov_SC03_024_jr_8013F350.o: JTBL_PADS := 0,0 # §8e pads ( build/src/ov_SC03_024/ov_SC03_024_jr_80154C24.o: JTBL_PADS := 0,0 # §8e pads (jtbl_carve.py) tables=+0x0,+0x24 build/src/ov_SC03_024/ov_SC03_024_jr_801588CC.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x28 build/src/ov_SC03_024/ov_SC03_024_jr_80159C84.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x20 +build/src/ov_SC03_024/ov_SC03_024_jr_8015AE2C.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x20 ov_SC03_024_CHECK_SHA := config/check.ov_SC03_024.sha ov_SC03_024_SYMBOLS := config/symbols.ov_SC03_024.txt ov_SC03_024_SIG := .run/sig.ov_SC03_024.jsonl @@ -1321,6 +1363,7 @@ build/src/ov_SC03_028/ov_SC03_028_jr_8013F350.o: JTBL_PADS := 0,0 # §8e pads ( build/src/ov_SC03_028/ov_SC03_028_jr_80154C24.o: JTBL_PADS := 0,0 # §8e pads (jtbl_carve.py) tables=+0x0,+0x24 build/src/ov_SC03_028/ov_SC03_028_jr_801588CC.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x28 build/src/ov_SC03_028/ov_SC03_028_jr_80159C84.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x20 +build/src/ov_SC03_028/ov_SC03_028_jr_8015AE2C.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x20 ov_SC03_028_CHECK_SHA := config/check.ov_SC03_028.sha ov_SC03_028_SYMBOLS := config/symbols.ov_SC03_028.txt ov_SC03_028_SIG := .run/sig.ov_SC03_028.jsonl @@ -1349,6 +1392,7 @@ build/src/ov_SC03_029/ov_SC03_029_jr_8013F350.o: JTBL_PADS := 0,0 # §8e pads ( build/src/ov_SC03_029/ov_SC03_029_jr_80154C24.o: JTBL_PADS := 0,0 # §8e pads (jtbl_carve.py) tables=+0x0,+0x24 build/src/ov_SC03_029/ov_SC03_029_jr_801588CC.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x28 build/src/ov_SC03_029/ov_SC03_029_jr_80159C84.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x20 +build/src/ov_SC03_029/ov_SC03_029_jr_8015AE2C.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x20 ov_SC03_029_CHECK_SHA := config/check.ov_SC03_029.sha ov_SC03_029_SYMBOLS := config/symbols.ov_SC03_029.txt ov_SC03_029_SIG := .run/sig.ov_SC03_029.jsonl @@ -1377,6 +1421,7 @@ build/src/ov_SC03_030/ov_SC03_030_jr_8013F350.o: JTBL_PADS := 0,0 # §8e pads ( build/src/ov_SC03_030/ov_SC03_030_jr_80154C24.o: JTBL_PADS := 0,0 # §8e pads (jtbl_carve.py) tables=+0x0,+0x24 build/src/ov_SC03_030/ov_SC03_030_jr_801588CC.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x28 build/src/ov_SC03_030/ov_SC03_030_jr_80159C84.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x20 +build/src/ov_SC03_030/ov_SC03_030_jr_8015AE2C.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x20 ov_SC03_030_CHECK_SHA := config/check.ov_SC03_030.sha ov_SC03_030_SYMBOLS := config/symbols.ov_SC03_030.txt ov_SC03_030_SIG := .run/sig.ov_SC03_030.jsonl @@ -1405,6 +1450,7 @@ build/src/ov_SC03_031/ov_SC03_031_jr_8013F350.o: JTBL_PADS := 0,0 # §8e pads ( build/src/ov_SC03_031/ov_SC03_031_jr_80154C24.o: JTBL_PADS := 0,0 # §8e pads (jtbl_carve.py) tables=+0x0,+0x24 build/src/ov_SC03_031/ov_SC03_031_jr_801588CC.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x28 build/src/ov_SC03_031/ov_SC03_031_jr_80159C84.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x20 +build/src/ov_SC03_031/ov_SC03_031_jr_8015AE2C.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x20 ov_SC03_031_CHECK_SHA := config/check.ov_SC03_031.sha ov_SC03_031_SYMBOLS := config/symbols.ov_SC03_031.txt ov_SC03_031_SIG := .run/sig.ov_SC03_031.jsonl @@ -1433,6 +1479,7 @@ build/src/ov_SC03_089/ov_SC03_089_jr_8013F350.o: JTBL_PADS := 0,0 # §8e pads ( build/src/ov_SC03_089/ov_SC03_089_jr_80154C24.o: JTBL_PADS := 0,0 # §8e pads (jtbl_carve.py) tables=+0x0,+0x24 build/src/ov_SC03_089/ov_SC03_089_jr_801588CC.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x28 build/src/ov_SC03_089/ov_SC03_089_jr_80159C84.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x20 +build/src/ov_SC03_089/ov_SC03_089_jr_8015AE2C.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x20 ov_SC03_089_CHECK_SHA := config/check.ov_SC03_089.sha ov_SC03_089_SYMBOLS := config/symbols.ov_SC03_089.txt ov_SC03_089_SIG := .run/sig.ov_SC03_089.jsonl @@ -1461,6 +1508,7 @@ build/src/ov_SC03_090/ov_SC03_090_jr_8013F350.o: JTBL_PADS := 0,0 # §8e pads ( build/src/ov_SC03_090/ov_SC03_090_jr_80154C24.o: JTBL_PADS := 0,0 # §8e pads (jtbl_carve.py) tables=+0x0,+0x24 build/src/ov_SC03_090/ov_SC03_090_jr_801588CC.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x28 build/src/ov_SC03_090/ov_SC03_090_jr_80159C84.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x20 +build/src/ov_SC03_090/ov_SC03_090_jr_8015AE2C.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x20 ov_SC03_090_CHECK_SHA := config/check.ov_SC03_090.sha ov_SC03_090_SYMBOLS := config/symbols.ov_SC03_090.txt ov_SC03_090_SIG := .run/sig.ov_SC03_090.jsonl @@ -1489,6 +1537,7 @@ build/src/ov_SC03_091/ov_SC03_091_jr_8013F350.o: JTBL_PADS := 0,0 # §8e pads ( build/src/ov_SC03_091/ov_SC03_091_jr_80154C24.o: JTBL_PADS := 0,0 # §8e pads (jtbl_carve.py) tables=+0x0,+0x24 build/src/ov_SC03_091/ov_SC03_091_jr_801588CC.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x28 build/src/ov_SC03_091/ov_SC03_091_jr_80159C84.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x20 +build/src/ov_SC03_091/ov_SC03_091_jr_8015AE2C.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x20 ov_SC03_091_CHECK_SHA := config/check.ov_SC03_091.sha ov_SC03_091_SYMBOLS := config/symbols.ov_SC03_091.txt ov_SC03_091_SIG := .run/sig.ov_SC03_091.jsonl @@ -1517,6 +1566,7 @@ build/src/ov_SC03_092/ov_SC03_092_jr_8013F350.o: JTBL_PADS := 0,0 # §8e pads ( build/src/ov_SC03_092/ov_SC03_092_jr_80154C24.o: JTBL_PADS := 0,0 # §8e pads (jtbl_carve.py) tables=+0x0,+0x24 build/src/ov_SC03_092/ov_SC03_092_jr_801588CC.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x28 build/src/ov_SC03_092/ov_SC03_092_jr_80159C84.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x20 +build/src/ov_SC03_092/ov_SC03_092_jr_8015AE2C.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x20 ov_SC03_092_CHECK_SHA := config/check.ov_SC03_092.sha ov_SC03_092_SYMBOLS := config/symbols.ov_SC03_092.txt ov_SC03_092_SIG := .run/sig.ov_SC03_092.jsonl @@ -1545,6 +1595,7 @@ build/src/ov_SC03_093/ov_SC03_093_jr_8013F350.o: JTBL_PADS := 0,0 # §8e pads ( build/src/ov_SC03_093/ov_SC03_093_jr_80154C24.o: JTBL_PADS := 0,0 # §8e pads (jtbl_carve.py) tables=+0x0,+0x24 build/src/ov_SC03_093/ov_SC03_093_jr_801588CC.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x28 build/src/ov_SC03_093/ov_SC03_093_jr_80159C84.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x20 +build/src/ov_SC03_093/ov_SC03_093_jr_8015AE2C.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x20 ov_SC03_093_CHECK_SHA := config/check.ov_SC03_093.sha ov_SC03_093_SYMBOLS := config/symbols.ov_SC03_093.txt ov_SC03_093_SIG := .run/sig.ov_SC03_093.jsonl @@ -1573,6 +1624,7 @@ build/src/ov_SC03_094/ov_SC03_094_jr_8013F350.o: JTBL_PADS := 0,0 # §8e pads ( build/src/ov_SC03_094/ov_SC03_094_jr_80154C24.o: JTBL_PADS := 0,0 # §8e pads (jtbl_carve.py) tables=+0x0,+0x24 build/src/ov_SC03_094/ov_SC03_094_jr_801588CC.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x28 build/src/ov_SC03_094/ov_SC03_094_jr_80159C84.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x20 +build/src/ov_SC03_094/ov_SC03_094_jr_8015AE2C.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x20 ov_SC03_094_CHECK_SHA := config/check.ov_SC03_094.sha ov_SC03_094_SYMBOLS := config/symbols.ov_SC03_094.txt ov_SC03_094_SIG := .run/sig.ov_SC03_094.jsonl @@ -1601,6 +1653,7 @@ build/src/ov_SC03_095/ov_SC03_095_jr_8013F350.o: JTBL_PADS := 0,0 # §8e pads ( build/src/ov_SC03_095/ov_SC03_095_jr_80154C24.o: JTBL_PADS := 0,0 # §8e pads (jtbl_carve.py) tables=+0x0,+0x24 build/src/ov_SC03_095/ov_SC03_095_jr_801588CC.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x28 build/src/ov_SC03_095/ov_SC03_095_jr_80159C84.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x20 +build/src/ov_SC03_095/ov_SC03_095_jr_8015AE2C.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x20 ov_SC03_095_CHECK_SHA := config/check.ov_SC03_095.sha ov_SC03_095_SYMBOLS := config/symbols.ov_SC03_095.txt ov_SC03_095_SIG := .run/sig.ov_SC03_095.jsonl @@ -1629,6 +1682,7 @@ build/src/ov_SC03_096/ov_SC03_096_jr_8013F350.o: JTBL_PADS := 0,0 # §8e pads ( build/src/ov_SC03_096/ov_SC03_096_jr_80154C24.o: JTBL_PADS := 0,0 # §8e pads (jtbl_carve.py) tables=+0x0,+0x24 build/src/ov_SC03_096/ov_SC03_096_jr_801588CC.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x28 build/src/ov_SC03_096/ov_SC03_096_jr_80159C84.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x20 +build/src/ov_SC03_096/ov_SC03_096_jr_8015AE2C.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x20 ov_SC03_096_CHECK_SHA := config/check.ov_SC03_096.sha ov_SC03_096_SYMBOLS := config/symbols.ov_SC03_096.txt ov_SC03_096_SIG := .run/sig.ov_SC03_096.jsonl @@ -1657,6 +1711,7 @@ build/src/ov_SC03_097/ov_SC03_097_jr_8013F350.o: JTBL_PADS := 0,0 # §8e pads ( build/src/ov_SC03_097/ov_SC03_097_jr_80154C24.o: JTBL_PADS := 0,0 # §8e pads (jtbl_carve.py) tables=+0x0,+0x24 build/src/ov_SC03_097/ov_SC03_097_jr_801588CC.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x28 build/src/ov_SC03_097/ov_SC03_097_jr_80159C84.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x20 +build/src/ov_SC03_097/ov_SC03_097_jr_8015AE2C.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x20 ov_SC03_097_CHECK_SHA := config/check.ov_SC03_097.sha ov_SC03_097_SYMBOLS := config/symbols.ov_SC03_097.txt ov_SC03_097_SIG := .run/sig.ov_SC03_097.jsonl @@ -1685,6 +1740,7 @@ build/src/ov_SC03_098/ov_SC03_098_jr_8013F350.o: JTBL_PADS := 0,0 # §8e pads ( build/src/ov_SC03_098/ov_SC03_098_jr_80154C24.o: JTBL_PADS := 0,0 # §8e pads (jtbl_carve.py) tables=+0x0,+0x24 build/src/ov_SC03_098/ov_SC03_098_jr_801588CC.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x28 build/src/ov_SC03_098/ov_SC03_098_jr_80159C84.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x20 +build/src/ov_SC03_098/ov_SC03_098_jr_8015AE2C.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x20 ov_SC03_098_CHECK_SHA := config/check.ov_SC03_098.sha ov_SC03_098_SYMBOLS := config/symbols.ov_SC03_098.txt ov_SC03_098_SIG := .run/sig.ov_SC03_098.jsonl @@ -1713,6 +1769,7 @@ build/src/ov_SC03_099/ov_SC03_099_jr_8013F350.o: JTBL_PADS := 0,0 # §8e pads ( build/src/ov_SC03_099/ov_SC03_099_jr_80154C24.o: JTBL_PADS := 0,0 # §8e pads (jtbl_carve.py) tables=+0x0,+0x24 build/src/ov_SC03_099/ov_SC03_099_jr_801588CC.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x28 build/src/ov_SC03_099/ov_SC03_099_jr_80159C84.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x20 +build/src/ov_SC03_099/ov_SC03_099_jr_8015AE2C.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x20 ov_SC03_099_CHECK_SHA := config/check.ov_SC03_099.sha ov_SC03_099_SYMBOLS := config/symbols.ov_SC03_099.txt ov_SC03_099_SIG := .run/sig.ov_SC03_099.jsonl @@ -1741,6 +1798,7 @@ build/src/ov_SC03_100/ov_SC03_100_jr_8013F350.o: JTBL_PADS := 0,0 # §8e pads ( build/src/ov_SC03_100/ov_SC03_100_jr_80154C24.o: JTBL_PADS := 0,0 # §8e pads (jtbl_carve.py) tables=+0x0,+0x24 build/src/ov_SC03_100/ov_SC03_100_jr_801588CC.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x28 build/src/ov_SC03_100/ov_SC03_100_jr_80159C84.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x20 +build/src/ov_SC03_100/ov_SC03_100_jr_8015AE2C.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x20 ov_SC03_100_CHECK_SHA := config/check.ov_SC03_100.sha ov_SC03_100_SYMBOLS := config/symbols.ov_SC03_100.txt ov_SC03_100_SIG := .run/sig.ov_SC03_100.jsonl @@ -1769,6 +1827,7 @@ build/src/ov_SC03_101/ov_SC03_101_jr_8013F350.o: JTBL_PADS := 0,0 # §8e pads ( build/src/ov_SC03_101/ov_SC03_101_jr_80154C24.o: JTBL_PADS := 0,0 # §8e pads (jtbl_carve.py) tables=+0x0,+0x24 build/src/ov_SC03_101/ov_SC03_101_jr_801588CC.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x28 build/src/ov_SC03_101/ov_SC03_101_jr_80159C84.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x20 +build/src/ov_SC03_101/ov_SC03_101_jr_8015AE2C.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x20 ov_SC03_101_CHECK_SHA := config/check.ov_SC03_101.sha ov_SC03_101_SYMBOLS := config/symbols.ov_SC03_101.txt ov_SC03_101_SIG := .run/sig.ov_SC03_101.jsonl @@ -1797,6 +1856,7 @@ build/src/ov_SC03_102/ov_SC03_102_jr_8013F350.o: JTBL_PADS := 0,0 # §8e pads ( build/src/ov_SC03_102/ov_SC03_102_jr_80154C24.o: JTBL_PADS := 0,0 # §8e pads (jtbl_carve.py) tables=+0x0,+0x24 build/src/ov_SC03_102/ov_SC03_102_jr_801588CC.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x28 build/src/ov_SC03_102/ov_SC03_102_jr_80159C84.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x20 +build/src/ov_SC03_102/ov_SC03_102_jr_8015AE2C.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x20 ov_SC03_102_CHECK_SHA := config/check.ov_SC03_102.sha ov_SC03_102_SYMBOLS := config/symbols.ov_SC03_102.txt ov_SC03_102_SIG := .run/sig.ov_SC03_102.jsonl @@ -1825,6 +1885,7 @@ build/src/ov_SC03_103/ov_SC03_103_jr_8013F350.o: JTBL_PADS := 0,0 # §8e pads ( build/src/ov_SC03_103/ov_SC03_103_jr_80154C24.o: JTBL_PADS := 0,0 # §8e pads (jtbl_carve.py) tables=+0x0,+0x24 build/src/ov_SC03_103/ov_SC03_103_jr_801588CC.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x28 build/src/ov_SC03_103/ov_SC03_103_jr_80159C84.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x20 +build/src/ov_SC03_103/ov_SC03_103_jr_8015AE2C.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x20 ov_SC03_103_CHECK_SHA := config/check.ov_SC03_103.sha ov_SC03_103_SYMBOLS := config/symbols.ov_SC03_103.txt ov_SC03_103_SIG := .run/sig.ov_SC03_103.jsonl @@ -1853,6 +1914,7 @@ build/src/ov_SC03_104/ov_SC03_104_jr_8013F350.o: JTBL_PADS := 0,0 # §8e pads ( build/src/ov_SC03_104/ov_SC03_104_jr_80154C24.o: JTBL_PADS := 0,0 # §8e pads (jtbl_carve.py) tables=+0x0,+0x24 build/src/ov_SC03_104/ov_SC03_104_jr_801588CC.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x28 build/src/ov_SC03_104/ov_SC03_104_jr_80159C84.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x20 +build/src/ov_SC03_104/ov_SC03_104_jr_8015AE2C.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x20 ov_SC03_104_CHECK_SHA := config/check.ov_SC03_104.sha ov_SC03_104_SYMBOLS := config/symbols.ov_SC03_104.txt ov_SC03_104_SIG := .run/sig.ov_SC03_104.jsonl @@ -1881,6 +1943,7 @@ build/src/ov_SC03_105/ov_SC03_105_jr_8013F350.o: JTBL_PADS := 0,0 # §8e pads ( build/src/ov_SC03_105/ov_SC03_105_jr_80154C24.o: JTBL_PADS := 0,0 # §8e pads (jtbl_carve.py) tables=+0x0,+0x24 build/src/ov_SC03_105/ov_SC03_105_jr_801588CC.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x28 build/src/ov_SC03_105/ov_SC03_105_jr_80159C84.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x20 +build/src/ov_SC03_105/ov_SC03_105_jr_8015AE2C.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x20 ov_SC03_105_CHECK_SHA := config/check.ov_SC03_105.sha ov_SC03_105_SYMBOLS := config/symbols.ov_SC03_105.txt ov_SC03_105_SIG := .run/sig.ov_SC03_105.jsonl @@ -1909,6 +1972,7 @@ build/src/ov_SC03_108/ov_SC03_108_jr_8013F350.o: JTBL_PADS := 0,0 # §8e pads ( build/src/ov_SC03_108/ov_SC03_108_jr_80154C24.o: JTBL_PADS := 0,0 # §8e pads (jtbl_carve.py) tables=+0x0,+0x24 build/src/ov_SC03_108/ov_SC03_108_jr_801588CC.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x28 build/src/ov_SC03_108/ov_SC03_108_jr_80159C84.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x20 +build/src/ov_SC03_108/ov_SC03_108_jr_8015AE2C.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x20 ov_SC03_108_CHECK_SHA := config/check.ov_SC03_108.sha ov_SC03_108_SYMBOLS := config/symbols.ov_SC03_108.txt ov_SC03_108_SIG := .run/sig.ov_SC03_108.jsonl @@ -1937,6 +2001,7 @@ build/src/ov_SC03_109/ov_SC03_109_jr_8013F350.o: JTBL_PADS := 0,0 # §8e pads ( build/src/ov_SC03_109/ov_SC03_109_jr_80154C24.o: JTBL_PADS := 0,0 # §8e pads (jtbl_carve.py) tables=+0x0,+0x24 build/src/ov_SC03_109/ov_SC03_109_jr_801588CC.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x28 build/src/ov_SC03_109/ov_SC03_109_jr_80159C84.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x20 +build/src/ov_SC03_109/ov_SC03_109_jr_8015AE2C.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x20 ov_SC03_109_CHECK_SHA := config/check.ov_SC03_109.sha ov_SC03_109_SYMBOLS := config/symbols.ov_SC03_109.txt ov_SC03_109_SIG := .run/sig.ov_SC03_109.jsonl @@ -1965,6 +2030,7 @@ build/src/ov_SC03_110/ov_SC03_110_jr_8013F350.o: JTBL_PADS := 0,0 # §8e pads ( build/src/ov_SC03_110/ov_SC03_110_jr_80154C24.o: JTBL_PADS := 0,0 # §8e pads (jtbl_carve.py) tables=+0x0,+0x24 build/src/ov_SC03_110/ov_SC03_110_jr_801588CC.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x28 build/src/ov_SC03_110/ov_SC03_110_jr_80159C84.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x20 +build/src/ov_SC03_110/ov_SC03_110_jr_8015AE2C.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x20 ov_SC03_110_CHECK_SHA := config/check.ov_SC03_110.sha ov_SC03_110_SYMBOLS := config/symbols.ov_SC03_110.txt ov_SC03_110_SIG := .run/sig.ov_SC03_110.jsonl @@ -1993,6 +2059,7 @@ build/src/ov_SC03_111/ov_SC03_111_jr_8013F350.o: JTBL_PADS := 0,0 # §8e pads ( build/src/ov_SC03_111/ov_SC03_111_jr_80154C24.o: JTBL_PADS := 0,0 # §8e pads (jtbl_carve.py) tables=+0x0,+0x24 build/src/ov_SC03_111/ov_SC03_111_jr_801588CC.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x28 build/src/ov_SC03_111/ov_SC03_111_jr_80159C84.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x20 +build/src/ov_SC03_111/ov_SC03_111_jr_8015AE2C.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x20 ov_SC03_111_CHECK_SHA := config/check.ov_SC03_111.sha ov_SC03_111_SYMBOLS := config/symbols.ov_SC03_111.txt ov_SC03_111_SIG := .run/sig.ov_SC03_111.jsonl @@ -2021,6 +2088,7 @@ build/src/ov_SC03_112/ov_SC03_112_jr_8013F350.o: JTBL_PADS := 0,0 # §8e pads ( build/src/ov_SC03_112/ov_SC03_112_jr_80154C24.o: JTBL_PADS := 0,0 # §8e pads (jtbl_carve.py) tables=+0x0,+0x24 build/src/ov_SC03_112/ov_SC03_112_jr_801588CC.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x28 build/src/ov_SC03_112/ov_SC03_112_jr_80159C84.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x20 +build/src/ov_SC03_112/ov_SC03_112_jr_8015AE2C.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x20 ov_SC03_112_CHECK_SHA := config/check.ov_SC03_112.sha ov_SC03_112_SYMBOLS := config/symbols.ov_SC03_112.txt ov_SC03_112_SIG := .run/sig.ov_SC03_112.jsonl @@ -2049,6 +2117,7 @@ build/src/ov_SC03_113/ov_SC03_113_jr_8013F350.o: JTBL_PADS := 0,0 # §8e pads ( build/src/ov_SC03_113/ov_SC03_113_jr_80154C24.o: JTBL_PADS := 0,0 # §8e pads (jtbl_carve.py) tables=+0x0,+0x24 build/src/ov_SC03_113/ov_SC03_113_jr_801588CC.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x28 build/src/ov_SC03_113/ov_SC03_113_jr_80159C84.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x20 +build/src/ov_SC03_113/ov_SC03_113_jr_8015AE2C.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x20 ov_SC03_113_CHECK_SHA := config/check.ov_SC03_113.sha ov_SC03_113_SYMBOLS := config/symbols.ov_SC03_113.txt ov_SC03_113_SIG := .run/sig.ov_SC03_113.jsonl @@ -2077,6 +2146,7 @@ build/src/ov_SC03_114/ov_SC03_114_jr_8013F350.o: JTBL_PADS := 0,0 # §8e pads ( build/src/ov_SC03_114/ov_SC03_114_jr_80154C24.o: JTBL_PADS := 0,0 # §8e pads (jtbl_carve.py) tables=+0x0,+0x24 build/src/ov_SC03_114/ov_SC03_114_jr_801588CC.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x28 build/src/ov_SC03_114/ov_SC03_114_jr_80159C84.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x20 +build/src/ov_SC03_114/ov_SC03_114_jr_8015AE2C.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x20 ov_SC03_114_CHECK_SHA := config/check.ov_SC03_114.sha ov_SC03_114_SYMBOLS := config/symbols.ov_SC03_114.txt ov_SC03_114_SIG := .run/sig.ov_SC03_114.jsonl @@ -2105,6 +2175,7 @@ build/src/ov_SC03_115/ov_SC03_115_jr_8013F350.o: JTBL_PADS := 0,0 # §8e pads ( build/src/ov_SC03_115/ov_SC03_115_jr_80154C24.o: JTBL_PADS := 0,0 # §8e pads (jtbl_carve.py) tables=+0x0,+0x24 build/src/ov_SC03_115/ov_SC03_115_jr_801588CC.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x28 build/src/ov_SC03_115/ov_SC03_115_jr_80159C84.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x20 +build/src/ov_SC03_115/ov_SC03_115_jr_8015AE2C.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x20 ov_SC03_115_CHECK_SHA := config/check.ov_SC03_115.sha ov_SC03_115_SYMBOLS := config/symbols.ov_SC03_115.txt ov_SC03_115_SIG := .run/sig.ov_SC03_115.jsonl @@ -2133,6 +2204,7 @@ build/src/ov_SC03_116/ov_SC03_116_jr_8013F350.o: JTBL_PADS := 0,0 # §8e pads ( build/src/ov_SC03_116/ov_SC03_116_jr_80154C24.o: JTBL_PADS := 0,0 # §8e pads (jtbl_carve.py) tables=+0x0,+0x24 build/src/ov_SC03_116/ov_SC03_116_jr_801588CC.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x28 build/src/ov_SC03_116/ov_SC03_116_jr_80159C84.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x20 +build/src/ov_SC03_116/ov_SC03_116_jr_8015AE2C.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x20 ov_SC03_116_CHECK_SHA := config/check.ov_SC03_116.sha ov_SC03_116_SYMBOLS := config/symbols.ov_SC03_116.txt ov_SC03_116_SIG := .run/sig.ov_SC03_116.jsonl @@ -2161,6 +2233,7 @@ build/src/ov_SC03_117/ov_SC03_117_jr_8013F350.o: JTBL_PADS := 0,0 # §8e pads ( build/src/ov_SC03_117/ov_SC03_117_jr_80154C24.o: JTBL_PADS := 0,0 # §8e pads (jtbl_carve.py) tables=+0x0,+0x24 build/src/ov_SC03_117/ov_SC03_117_jr_801588CC.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x28 build/src/ov_SC03_117/ov_SC03_117_jr_80159C84.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x20 +build/src/ov_SC03_117/ov_SC03_117_jr_8015AE2C.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x20 ov_SC03_117_CHECK_SHA := config/check.ov_SC03_117.sha ov_SC03_117_SYMBOLS := config/symbols.ov_SC03_117.txt ov_SC03_117_SIG := .run/sig.ov_SC03_117.jsonl @@ -2189,6 +2262,7 @@ build/src/ov_SC03_118/ov_SC03_118_jr_8013F350.o: JTBL_PADS := 0,0 # §8e pads ( build/src/ov_SC03_118/ov_SC03_118_jr_80154C24.o: JTBL_PADS := 0,0 # §8e pads (jtbl_carve.py) tables=+0x0,+0x24 build/src/ov_SC03_118/ov_SC03_118_jr_801588CC.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x28 build/src/ov_SC03_118/ov_SC03_118_jr_80159C84.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x20 +build/src/ov_SC03_118/ov_SC03_118_jr_8015AE2C.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x20 ov_SC03_118_CHECK_SHA := config/check.ov_SC03_118.sha ov_SC03_118_SYMBOLS := config/symbols.ov_SC03_118.txt ov_SC03_118_SIG := .run/sig.ov_SC03_118.jsonl @@ -2217,6 +2291,7 @@ build/src/ov_SC03_119/ov_SC03_119_jr_8013F350.o: JTBL_PADS := 0,0 # §8e pads ( build/src/ov_SC03_119/ov_SC03_119_jr_80154C24.o: JTBL_PADS := 0,0 # §8e pads (jtbl_carve.py) tables=+0x0,+0x24 build/src/ov_SC03_119/ov_SC03_119_jr_801588CC.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x28 build/src/ov_SC03_119/ov_SC03_119_jr_80159C84.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x20 +build/src/ov_SC03_119/ov_SC03_119_jr_8015AE2C.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x20 ov_SC03_119_CHECK_SHA := config/check.ov_SC03_119.sha ov_SC03_119_SYMBOLS := config/symbols.ov_SC03_119.txt ov_SC03_119_SIG := .run/sig.ov_SC03_119.jsonl @@ -2245,6 +2320,7 @@ build/src/ov_SC03_121/ov_SC03_121_jr_8013F350.o: JTBL_PADS := 0,0 # §8e pads ( build/src/ov_SC03_121/ov_SC03_121_jr_80154C24.o: JTBL_PADS := 0,0 # §8e pads (jtbl_carve.py) tables=+0x0,+0x24 build/src/ov_SC03_121/ov_SC03_121_jr_801588CC.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x28 build/src/ov_SC03_121/ov_SC03_121_jr_80159C84.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x20 +build/src/ov_SC03_121/ov_SC03_121_jr_8015AE2C.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x20 ov_SC03_121_CHECK_SHA := config/check.ov_SC03_121.sha ov_SC03_121_SYMBOLS := config/symbols.ov_SC03_121.txt ov_SC03_121_SIG := .run/sig.ov_SC03_121.jsonl @@ -2273,6 +2349,7 @@ build/src/ov_SC03_124/ov_SC03_124_jr_8013F350.o: JTBL_PADS := 0,0 # §8e pads ( build/src/ov_SC03_124/ov_SC03_124_jr_80154C24.o: JTBL_PADS := 0,0 # §8e pads (jtbl_carve.py) tables=+0x0,+0x24 build/src/ov_SC03_124/ov_SC03_124_jr_801588CC.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x28 build/src/ov_SC03_124/ov_SC03_124_jr_80159C84.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x20 +build/src/ov_SC03_124/ov_SC03_124_jr_8015AE2C.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x20 ov_SC03_124_CHECK_SHA := config/check.ov_SC03_124.sha ov_SC03_124_SYMBOLS := config/symbols.ov_SC03_124.txt ov_SC03_124_SIG := .run/sig.ov_SC03_124.jsonl @@ -2301,6 +2378,7 @@ build/src/ov_SC03_125/ov_SC03_125_jr_8013F350.o: JTBL_PADS := 0,0 # §8e pads ( build/src/ov_SC03_125/ov_SC03_125_jr_80154C24.o: JTBL_PADS := 0,0 # §8e pads (jtbl_carve.py) tables=+0x0,+0x24 build/src/ov_SC03_125/ov_SC03_125_jr_801588CC.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x28 build/src/ov_SC03_125/ov_SC03_125_jr_80159C84.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x20 +build/src/ov_SC03_125/ov_SC03_125_jr_8015AE2C.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x20 ov_SC03_125_CHECK_SHA := config/check.ov_SC03_125.sha ov_SC03_125_SYMBOLS := config/symbols.ov_SC03_125.txt ov_SC03_125_SIG := .run/sig.ov_SC03_125.jsonl @@ -2329,6 +2407,7 @@ build/src/ov_SC03_126/ov_SC03_126_jr_8013F350.o: JTBL_PADS := 0,0 # §8e pads ( build/src/ov_SC03_126/ov_SC03_126_jr_80154C24.o: JTBL_PADS := 0,0 # §8e pads (jtbl_carve.py) tables=+0x0,+0x24 build/src/ov_SC03_126/ov_SC03_126_jr_801588CC.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x28 build/src/ov_SC03_126/ov_SC03_126_jr_80159C84.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x20 +build/src/ov_SC03_126/ov_SC03_126_jr_8015AE2C.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x20 ov_SC03_126_CHECK_SHA := config/check.ov_SC03_126.sha ov_SC03_126_SYMBOLS := config/symbols.ov_SC03_126.txt ov_SC03_126_SIG := .run/sig.ov_SC03_126.jsonl @@ -2357,6 +2436,7 @@ build/src/ov_SC04_002/ov_SC04_002_jr_8013F350.o: JTBL_PADS := 0,0 # §8e pads ( build/src/ov_SC04_002/ov_SC04_002_jr_80154C24.o: JTBL_PADS := 0,0 # §8e pads (jtbl_carve.py) tables=+0x0,+0x24 build/src/ov_SC04_002/ov_SC04_002_jr_801588CC.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x28 build/src/ov_SC04_002/ov_SC04_002_jr_80159C84.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x20 +build/src/ov_SC04_002/ov_SC04_002_jr_8015AE2C.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x20 ov_SC04_002_CHECK_SHA := config/check.ov_SC04_002.sha ov_SC04_002_SYMBOLS := config/symbols.ov_SC04_002.txt ov_SC04_002_SIG := .run/sig.ov_SC04_002.jsonl @@ -2385,6 +2465,7 @@ build/src/ov_SC04_003/ov_SC04_003_jr_8013F350.o: JTBL_PADS := 0,0 # §8e pads ( build/src/ov_SC04_003/ov_SC04_003_jr_80154C24.o: JTBL_PADS := 0,0 # §8e pads (jtbl_carve.py) tables=+0x0,+0x24 build/src/ov_SC04_003/ov_SC04_003_jr_801588CC.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x28 build/src/ov_SC04_003/ov_SC04_003_jr_80159C84.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x20 +build/src/ov_SC04_003/ov_SC04_003_jr_8015AE2C.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x20 ov_SC04_003_CHECK_SHA := config/check.ov_SC04_003.sha ov_SC04_003_SYMBOLS := config/symbols.ov_SC04_003.txt ov_SC04_003_SIG := .run/sig.ov_SC04_003.jsonl @@ -2413,6 +2494,7 @@ build/src/ov_SC04_004/ov_SC04_004_jr_8013F350.o: JTBL_PADS := 0,0 # §8e pads ( build/src/ov_SC04_004/ov_SC04_004_jr_80154C24.o: JTBL_PADS := 0,0 # §8e pads (jtbl_carve.py) tables=+0x0,+0x24 build/src/ov_SC04_004/ov_SC04_004_jr_801588CC.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x28 build/src/ov_SC04_004/ov_SC04_004_jr_80159C84.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x20 +build/src/ov_SC04_004/ov_SC04_004_jr_8015AE2C.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x20 ov_SC04_004_CHECK_SHA := config/check.ov_SC04_004.sha ov_SC04_004_SYMBOLS := config/symbols.ov_SC04_004.txt ov_SC04_004_SIG := .run/sig.ov_SC04_004.jsonl @@ -2441,6 +2523,7 @@ build/src/ov_SC04_005/ov_SC04_005_jr_8013F350.o: JTBL_PADS := 0,0 # §8e pads ( build/src/ov_SC04_005/ov_SC04_005_jr_80154C24.o: JTBL_PADS := 0,0 # §8e pads (jtbl_carve.py) tables=+0x0,+0x24 build/src/ov_SC04_005/ov_SC04_005_jr_801588CC.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x28 build/src/ov_SC04_005/ov_SC04_005_jr_80159C84.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x20 +build/src/ov_SC04_005/ov_SC04_005_jr_8015AE2C.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x20 ov_SC04_005_CHECK_SHA := config/check.ov_SC04_005.sha ov_SC04_005_SYMBOLS := config/symbols.ov_SC04_005.txt ov_SC04_005_SIG := .run/sig.ov_SC04_005.jsonl @@ -2469,6 +2552,7 @@ build/src/ov_SC04_006/ov_SC04_006_jr_8013F350.o: JTBL_PADS := 0,0 # §8e pads ( build/src/ov_SC04_006/ov_SC04_006_jr_80154C24.o: JTBL_PADS := 0,0 # §8e pads (jtbl_carve.py) tables=+0x0,+0x24 build/src/ov_SC04_006/ov_SC04_006_jr_801588CC.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x28 build/src/ov_SC04_006/ov_SC04_006_jr_80159C84.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x20 +build/src/ov_SC04_006/ov_SC04_006_jr_8015AE2C.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x20 ov_SC04_006_CHECK_SHA := config/check.ov_SC04_006.sha ov_SC04_006_SYMBOLS := config/symbols.ov_SC04_006.txt ov_SC04_006_SIG := .run/sig.ov_SC04_006.jsonl @@ -2497,6 +2581,7 @@ build/src/ov_SC04_007/ov_SC04_007_jr_8013F350.o: JTBL_PADS := 0,0 # §8e pads ( build/src/ov_SC04_007/ov_SC04_007_jr_80154C24.o: JTBL_PADS := 0,0 # §8e pads (jtbl_carve.py) tables=+0x0,+0x24 build/src/ov_SC04_007/ov_SC04_007_jr_801588CC.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x28 build/src/ov_SC04_007/ov_SC04_007_jr_80159C84.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x20 +build/src/ov_SC04_007/ov_SC04_007_jr_8015AE2C.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x20 ov_SC04_007_CHECK_SHA := config/check.ov_SC04_007.sha ov_SC04_007_SYMBOLS := config/symbols.ov_SC04_007.txt ov_SC04_007_SIG := .run/sig.ov_SC04_007.jsonl @@ -2525,6 +2610,7 @@ build/src/ov_SC04_008/ov_SC04_008_jr_8013F350.o: JTBL_PADS := 0,0 # §8e pads ( build/src/ov_SC04_008/ov_SC04_008_jr_80154C24.o: JTBL_PADS := 0,0 # §8e pads (jtbl_carve.py) tables=+0x0,+0x24 build/src/ov_SC04_008/ov_SC04_008_jr_801588CC.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x28 build/src/ov_SC04_008/ov_SC04_008_jr_80159C84.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x20 +build/src/ov_SC04_008/ov_SC04_008_jr_8015AE2C.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x20 ov_SC04_008_CHECK_SHA := config/check.ov_SC04_008.sha ov_SC04_008_SYMBOLS := config/symbols.ov_SC04_008.txt ov_SC04_008_SIG := .run/sig.ov_SC04_008.jsonl @@ -2553,6 +2639,7 @@ build/src/ov_SC04_009/ov_SC04_009_jr_8013F350.o: JTBL_PADS := 0,0 # §8e pads ( build/src/ov_SC04_009/ov_SC04_009_jr_80154C24.o: JTBL_PADS := 0,0 # §8e pads (jtbl_carve.py) tables=+0x0,+0x24 build/src/ov_SC04_009/ov_SC04_009_jr_801588CC.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x28 build/src/ov_SC04_009/ov_SC04_009_jr_80159C84.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x20 +build/src/ov_SC04_009/ov_SC04_009_jr_8015AE2C.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x20 ov_SC04_009_CHECK_SHA := config/check.ov_SC04_009.sha ov_SC04_009_SYMBOLS := config/symbols.ov_SC04_009.txt ov_SC04_009_SIG := .run/sig.ov_SC04_009.jsonl @@ -2581,6 +2668,7 @@ build/src/ov_SC04_010/ov_SC04_010_jr_8013F350.o: JTBL_PADS := 0,0 # §8e pads ( build/src/ov_SC04_010/ov_SC04_010_jr_80154C24.o: JTBL_PADS := 0,0 # §8e pads (jtbl_carve.py) tables=+0x0,+0x24 build/src/ov_SC04_010/ov_SC04_010_jr_801588CC.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x28 build/src/ov_SC04_010/ov_SC04_010_jr_80159C84.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x20 +build/src/ov_SC04_010/ov_SC04_010_jr_8015AE2C.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x20 ov_SC04_010_CHECK_SHA := config/check.ov_SC04_010.sha ov_SC04_010_SYMBOLS := config/symbols.ov_SC04_010.txt ov_SC04_010_SIG := .run/sig.ov_SC04_010.jsonl @@ -2609,6 +2697,7 @@ build/src/ov_SC04_011/ov_SC04_011_jr_8013F350.o: JTBL_PADS := 0,0 # §8e pads ( build/src/ov_SC04_011/ov_SC04_011_jr_80154C24.o: JTBL_PADS := 0,0 # §8e pads (jtbl_carve.py) tables=+0x0,+0x24 build/src/ov_SC04_011/ov_SC04_011_jr_801588CC.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x28 build/src/ov_SC04_011/ov_SC04_011_jr_80159C84.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x20 +build/src/ov_SC04_011/ov_SC04_011_jr_8015AE2C.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x20 ov_SC04_011_CHECK_SHA := config/check.ov_SC04_011.sha ov_SC04_011_SYMBOLS := config/symbols.ov_SC04_011.txt ov_SC04_011_SIG := .run/sig.ov_SC04_011.jsonl @@ -2637,6 +2726,7 @@ build/src/ov_SC04_012/ov_SC04_012_jr_8013F350.o: JTBL_PADS := 0,0 # §8e pads ( build/src/ov_SC04_012/ov_SC04_012_jr_80154C24.o: JTBL_PADS := 0,0 # §8e pads (jtbl_carve.py) tables=+0x0,+0x24 build/src/ov_SC04_012/ov_SC04_012_jr_801588CC.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x28 build/src/ov_SC04_012/ov_SC04_012_jr_80159C84.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x20 +build/src/ov_SC04_012/ov_SC04_012_jr_8015AE2C.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x20 ov_SC04_012_CHECK_SHA := config/check.ov_SC04_012.sha ov_SC04_012_SYMBOLS := config/symbols.ov_SC04_012.txt ov_SC04_012_SIG := .run/sig.ov_SC04_012.jsonl @@ -2665,6 +2755,7 @@ build/src/ov_SC04_015/ov_SC04_015_jr_8013F350.o: JTBL_PADS := 0,0 # §8e pads ( build/src/ov_SC04_015/ov_SC04_015_jr_80154C24.o: JTBL_PADS := 0,0 # §8e pads (jtbl_carve.py) tables=+0x0,+0x24 build/src/ov_SC04_015/ov_SC04_015_jr_801588CC.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x28 build/src/ov_SC04_015/ov_SC04_015_jr_80159C84.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x20 +build/src/ov_SC04_015/ov_SC04_015_jr_8015AE2C.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x20 ov_SC04_015_CHECK_SHA := config/check.ov_SC04_015.sha ov_SC04_015_SYMBOLS := config/symbols.ov_SC04_015.txt ov_SC04_015_SIG := .run/sig.ov_SC04_015.jsonl @@ -2693,6 +2784,7 @@ build/src/ov_SC04_016/ov_SC04_016_jr_8013F350.o: JTBL_PADS := 0,0 # §8e pads ( build/src/ov_SC04_016/ov_SC04_016_jr_80154C24.o: JTBL_PADS := 0,0 # §8e pads (jtbl_carve.py) tables=+0x0,+0x24 build/src/ov_SC04_016/ov_SC04_016_jr_801588CC.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x28 build/src/ov_SC04_016/ov_SC04_016_jr_80159C84.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x20 +build/src/ov_SC04_016/ov_SC04_016_jr_8015AE2C.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x20 ov_SC04_016_CHECK_SHA := config/check.ov_SC04_016.sha ov_SC04_016_SYMBOLS := config/symbols.ov_SC04_016.txt ov_SC04_016_SIG := .run/sig.ov_SC04_016.jsonl @@ -2721,6 +2813,7 @@ build/src/ov_SC04_020/ov_SC04_020_jr_8013F350.o: JTBL_PADS := 0,0 # §8e pads ( build/src/ov_SC04_020/ov_SC04_020_jr_80154C24.o: JTBL_PADS := 0,0 # §8e pads (jtbl_carve.py) tables=+0x0,+0x24 build/src/ov_SC04_020/ov_SC04_020_jr_801588CC.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x28 build/src/ov_SC04_020/ov_SC04_020_jr_80159C84.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x20 +build/src/ov_SC04_020/ov_SC04_020_jr_8015AE2C.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x20 ov_SC04_020_CHECK_SHA := config/check.ov_SC04_020.sha ov_SC04_020_SYMBOLS := config/symbols.ov_SC04_020.txt ov_SC04_020_SIG := .run/sig.ov_SC04_020.jsonl @@ -2749,6 +2842,7 @@ build/src/ov_SC04_021/ov_SC04_021_jr_8013F350.o: JTBL_PADS := 0,0 # §8e pads ( build/src/ov_SC04_021/ov_SC04_021_jr_80154C24.o: JTBL_PADS := 0,0 # §8e pads (jtbl_carve.py) tables=+0x0,+0x24 build/src/ov_SC04_021/ov_SC04_021_jr_801588CC.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x28 build/src/ov_SC04_021/ov_SC04_021_jr_80159C84.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x20 +build/src/ov_SC04_021/ov_SC04_021_jr_8015AE2C.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x20 ov_SC04_021_CHECK_SHA := config/check.ov_SC04_021.sha ov_SC04_021_SYMBOLS := config/symbols.ov_SC04_021.txt ov_SC04_021_SIG := .run/sig.ov_SC04_021.jsonl @@ -2777,6 +2871,7 @@ build/src/ov_SC05_001/ov_SC05_001_jr_8013F350.o: JTBL_PADS := 0,0 # §8e pads ( build/src/ov_SC05_001/ov_SC05_001_jr_80154C24.o: JTBL_PADS := 0,0 # §8e pads (jtbl_carve.py) tables=+0x0,+0x24 build/src/ov_SC05_001/ov_SC05_001_jr_801588CC.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x28 build/src/ov_SC05_001/ov_SC05_001_jr_80159C84.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x20 +build/src/ov_SC05_001/ov_SC05_001_jr_8015AE2C.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x20 ov_SC05_001_CHECK_SHA := config/check.ov_SC05_001.sha ov_SC05_001_SYMBOLS := config/symbols.ov_SC05_001.txt ov_SC05_001_SIG := .run/sig.ov_SC05_001.jsonl @@ -2805,6 +2900,7 @@ build/src/ov_SC05_002/ov_SC05_002_jr_8013F350.o: JTBL_PADS := 0,0 # §8e pads ( build/src/ov_SC05_002/ov_SC05_002_jr_80154C24.o: JTBL_PADS := 0,0 # §8e pads (jtbl_carve.py) tables=+0x0,+0x24 build/src/ov_SC05_002/ov_SC05_002_jr_801588CC.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x28 build/src/ov_SC05_002/ov_SC05_002_jr_80159C84.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x20 +build/src/ov_SC05_002/ov_SC05_002_jr_8015AE2C.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x20 ov_SC05_002_CHECK_SHA := config/check.ov_SC05_002.sha ov_SC05_002_SYMBOLS := config/symbols.ov_SC05_002.txt ov_SC05_002_SIG := .run/sig.ov_SC05_002.jsonl @@ -2833,6 +2929,7 @@ build/src/ov_SC05_003/ov_SC05_003_jr_8013F350.o: JTBL_PADS := 0,0 # §8e pads ( build/src/ov_SC05_003/ov_SC05_003_jr_80154C24.o: JTBL_PADS := 0,0 # §8e pads (jtbl_carve.py) tables=+0x0,+0x24 build/src/ov_SC05_003/ov_SC05_003_jr_801588CC.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x28 build/src/ov_SC05_003/ov_SC05_003_jr_80159C84.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x20 +build/src/ov_SC05_003/ov_SC05_003_jr_8015AE2C.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x20 ov_SC05_003_CHECK_SHA := config/check.ov_SC05_003.sha ov_SC05_003_SYMBOLS := config/symbols.ov_SC05_003.txt ov_SC05_003_SIG := .run/sig.ov_SC05_003.jsonl @@ -2861,6 +2958,7 @@ build/src/ov_SC05_004/ov_SC05_004_jr_8013F350.o: JTBL_PADS := 0,0 # §8e pads ( build/src/ov_SC05_004/ov_SC05_004_jr_80154C24.o: JTBL_PADS := 0,0 # §8e pads (jtbl_carve.py) tables=+0x0,+0x24 build/src/ov_SC05_004/ov_SC05_004_jr_801588CC.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x28 build/src/ov_SC05_004/ov_SC05_004_jr_80159C84.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x20 +build/src/ov_SC05_004/ov_SC05_004_jr_8015AE2C.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x20 ov_SC05_004_CHECK_SHA := config/check.ov_SC05_004.sha ov_SC05_004_SYMBOLS := config/symbols.ov_SC05_004.txt ov_SC05_004_SIG := .run/sig.ov_SC05_004.jsonl @@ -2889,6 +2987,7 @@ build/src/ov_SC05_005/ov_SC05_005_jr_8013F350.o: JTBL_PADS := 0,0 # §8e pads ( build/src/ov_SC05_005/ov_SC05_005_jr_80154C24.o: JTBL_PADS := 0,0 # §8e pads (jtbl_carve.py) tables=+0x0,+0x24 build/src/ov_SC05_005/ov_SC05_005_jr_801588CC.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x28 build/src/ov_SC05_005/ov_SC05_005_jr_80159C84.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x20 +build/src/ov_SC05_005/ov_SC05_005_jr_8015AE2C.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x20 ov_SC05_005_CHECK_SHA := config/check.ov_SC05_005.sha ov_SC05_005_SYMBOLS := config/symbols.ov_SC05_005.txt ov_SC05_005_SIG := .run/sig.ov_SC05_005.jsonl @@ -2917,6 +3016,7 @@ build/src/ov_SC05_006/ov_SC05_006_jr_8013F350.o: JTBL_PADS := 0,0 # §8e pads ( build/src/ov_SC05_006/ov_SC05_006_jr_80154C24.o: JTBL_PADS := 0,0 # §8e pads (jtbl_carve.py) tables=+0x0,+0x24 build/src/ov_SC05_006/ov_SC05_006_jr_801588CC.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x28 build/src/ov_SC05_006/ov_SC05_006_jr_80159C84.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x20 +build/src/ov_SC05_006/ov_SC05_006_jr_8015AE2C.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x20 ov_SC05_006_CHECK_SHA := config/check.ov_SC05_006.sha ov_SC05_006_SYMBOLS := config/symbols.ov_SC05_006.txt ov_SC05_006_SIG := .run/sig.ov_SC05_006.jsonl @@ -2945,6 +3045,7 @@ build/src/ov_SC05_007/ov_SC05_007_jr_8013F350.o: JTBL_PADS := 0,0 # §8e pads ( build/src/ov_SC05_007/ov_SC05_007_jr_80154C24.o: JTBL_PADS := 0,0 # §8e pads (jtbl_carve.py) tables=+0x0,+0x24 build/src/ov_SC05_007/ov_SC05_007_jr_801588CC.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x28 build/src/ov_SC05_007/ov_SC05_007_jr_80159C84.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x20 +build/src/ov_SC05_007/ov_SC05_007_jr_8015AE2C.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x20 ov_SC05_007_CHECK_SHA := config/check.ov_SC05_007.sha ov_SC05_007_SYMBOLS := config/symbols.ov_SC05_007.txt ov_SC05_007_SIG := .run/sig.ov_SC05_007.jsonl @@ -2973,6 +3074,7 @@ build/src/ov_SC05_008/ov_SC05_008_jr_8013F350.o: JTBL_PADS := 0,0 # §8e pads ( build/src/ov_SC05_008/ov_SC05_008_jr_80154C24.o: JTBL_PADS := 0,0 # §8e pads (jtbl_carve.py) tables=+0x0,+0x24 build/src/ov_SC05_008/ov_SC05_008_jr_801588CC.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x28 build/src/ov_SC05_008/ov_SC05_008_jr_80159C84.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x20 +build/src/ov_SC05_008/ov_SC05_008_jr_8015AE2C.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x20 ov_SC05_008_CHECK_SHA := config/check.ov_SC05_008.sha ov_SC05_008_SYMBOLS := config/symbols.ov_SC05_008.txt ov_SC05_008_SIG := .run/sig.ov_SC05_008.jsonl @@ -3001,6 +3103,7 @@ build/src/ov_SC05_009/ov_SC05_009_jr_8013F350.o: JTBL_PADS := 0,0 # §8e pads ( build/src/ov_SC05_009/ov_SC05_009_jr_80154C24.o: JTBL_PADS := 0,0 # §8e pads (jtbl_carve.py) tables=+0x0,+0x24 build/src/ov_SC05_009/ov_SC05_009_jr_801588CC.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x28 build/src/ov_SC05_009/ov_SC05_009_jr_80159C84.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x20 +build/src/ov_SC05_009/ov_SC05_009_jr_8015AE2C.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x20 ov_SC05_009_CHECK_SHA := config/check.ov_SC05_009.sha ov_SC05_009_SYMBOLS := config/symbols.ov_SC05_009.txt ov_SC05_009_SIG := .run/sig.ov_SC05_009.jsonl @@ -3029,6 +3132,7 @@ build/src/ov_SC05_010/ov_SC05_010_jr_8013F350.o: JTBL_PADS := 0,0 # §8e pads ( build/src/ov_SC05_010/ov_SC05_010_jr_80154C24.o: JTBL_PADS := 0,0 # §8e pads (jtbl_carve.py) tables=+0x0,+0x24 build/src/ov_SC05_010/ov_SC05_010_jr_801588CC.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x28 build/src/ov_SC05_010/ov_SC05_010_jr_80159C84.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x20 +build/src/ov_SC05_010/ov_SC05_010_jr_8015AE2C.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x20 ov_SC05_010_CHECK_SHA := config/check.ov_SC05_010.sha ov_SC05_010_SYMBOLS := config/symbols.ov_SC05_010.txt ov_SC05_010_SIG := .run/sig.ov_SC05_010.jsonl @@ -3057,6 +3161,7 @@ build/src/ov_SC05_011/ov_SC05_011_jr_8013F350.o: JTBL_PADS := 0,0 # §8e pads ( build/src/ov_SC05_011/ov_SC05_011_jr_80154C24.o: JTBL_PADS := 0,0 # §8e pads (jtbl_carve.py) tables=+0x0,+0x24 build/src/ov_SC05_011/ov_SC05_011_jr_801588CC.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x28 build/src/ov_SC05_011/ov_SC05_011_jr_80159C84.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x20 +build/src/ov_SC05_011/ov_SC05_011_jr_8015AE2C.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x20 ov_SC05_011_CHECK_SHA := config/check.ov_SC05_011.sha ov_SC05_011_SYMBOLS := config/symbols.ov_SC05_011.txt ov_SC05_011_SIG := .run/sig.ov_SC05_011.jsonl @@ -3085,6 +3190,7 @@ build/src/ov_SC05_017/ov_SC05_017_jr_8013F350.o: JTBL_PADS := 0,0 # §8e pads ( build/src/ov_SC05_017/ov_SC05_017_jr_80154C24.o: JTBL_PADS := 0,0 # §8e pads (jtbl_carve.py) tables=+0x0,+0x24 build/src/ov_SC05_017/ov_SC05_017_jr_801588CC.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x28 build/src/ov_SC05_017/ov_SC05_017_jr_80159C84.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x20 +build/src/ov_SC05_017/ov_SC05_017_jr_8015AE2C.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x20 ov_SC05_017_CHECK_SHA := config/check.ov_SC05_017.sha ov_SC05_017_SYMBOLS := config/symbols.ov_SC05_017.txt ov_SC05_017_SIG := .run/sig.ov_SC05_017.jsonl @@ -3113,6 +3219,7 @@ build/src/ov_SC05_018/ov_SC05_018_jr_8013F350.o: JTBL_PADS := 0,0 # §8e pads ( build/src/ov_SC05_018/ov_SC05_018_jr_80154C24.o: JTBL_PADS := 0,0 # §8e pads (jtbl_carve.py) tables=+0x0,+0x24 build/src/ov_SC05_018/ov_SC05_018_jr_801588CC.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x28 build/src/ov_SC05_018/ov_SC05_018_jr_80159C84.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x20 +build/src/ov_SC05_018/ov_SC05_018_jr_8015AE2C.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x20 ov_SC05_018_CHECK_SHA := config/check.ov_SC05_018.sha ov_SC05_018_SYMBOLS := config/symbols.ov_SC05_018.txt ov_SC05_018_SIG := .run/sig.ov_SC05_018.jsonl @@ -3141,6 +3248,7 @@ build/src/ov_SC05_019/ov_SC05_019_jr_8013F350.o: JTBL_PADS := 0,0 # §8e pads ( build/src/ov_SC05_019/ov_SC05_019_jr_80154C24.o: JTBL_PADS := 0,0 # §8e pads (jtbl_carve.py) tables=+0x0,+0x24 build/src/ov_SC05_019/ov_SC05_019_jr_801588CC.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x28 build/src/ov_SC05_019/ov_SC05_019_jr_80159C84.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x20 +build/src/ov_SC05_019/ov_SC05_019_jr_8015AE2C.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x20 ov_SC05_019_CHECK_SHA := config/check.ov_SC05_019.sha ov_SC05_019_SYMBOLS := config/symbols.ov_SC05_019.txt ov_SC05_019_SIG := .run/sig.ov_SC05_019.jsonl @@ -3169,6 +3277,7 @@ build/src/ov_SC06_006/ov_SC06_006_jr_8013F350.o: JTBL_PADS := 0,0 # §8e pads ( build/src/ov_SC06_006/ov_SC06_006_jr_80154C24.o: JTBL_PADS := 0,0 # §8e pads (jtbl_carve.py) tables=+0x0,+0x24 build/src/ov_SC06_006/ov_SC06_006_jr_801588CC.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x28 build/src/ov_SC06_006/ov_SC06_006_jr_80159C84.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x20 +build/src/ov_SC06_006/ov_SC06_006_jr_8015AE2C.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x20 ov_SC06_006_CHECK_SHA := config/check.ov_SC06_006.sha ov_SC06_006_SYMBOLS := config/symbols.ov_SC06_006.txt ov_SC06_006_SIG := .run/sig.ov_SC06_006.jsonl @@ -3197,6 +3306,7 @@ build/src/ov_SC06_008/ov_SC06_008_jr_8013F350.o: JTBL_PADS := 0,0 # §8e pads ( build/src/ov_SC06_008/ov_SC06_008_jr_80154C24.o: JTBL_PADS := 0,0 # §8e pads (jtbl_carve.py) tables=+0x0,+0x24 build/src/ov_SC06_008/ov_SC06_008_jr_801588CC.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x28 build/src/ov_SC06_008/ov_SC06_008_jr_80159C84.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x20 +build/src/ov_SC06_008/ov_SC06_008_jr_8015AE2C.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x20 ov_SC06_008_CHECK_SHA := config/check.ov_SC06_008.sha ov_SC06_008_SYMBOLS := config/symbols.ov_SC06_008.txt ov_SC06_008_SIG := .run/sig.ov_SC06_008.jsonl @@ -3225,6 +3335,7 @@ build/src/ov_SC06_010/ov_SC06_010_jr_8013F350.o: JTBL_PADS := 0,0 # §8e pads ( build/src/ov_SC06_010/ov_SC06_010_jr_80154C24.o: JTBL_PADS := 0,0 # §8e pads (jtbl_carve.py) tables=+0x0,+0x24 build/src/ov_SC06_010/ov_SC06_010_jr_801588CC.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x28 build/src/ov_SC06_010/ov_SC06_010_jr_80159C84.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x20 +build/src/ov_SC06_010/ov_SC06_010_jr_8015AE2C.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x20 ov_SC06_010_CHECK_SHA := config/check.ov_SC06_010.sha ov_SC06_010_SYMBOLS := config/symbols.ov_SC06_010.txt ov_SC06_010_SIG := .run/sig.ov_SC06_010.jsonl @@ -3253,6 +3364,7 @@ build/src/ov_SC06_011/ov_SC06_011_jr_8013F350.o: JTBL_PADS := 0,0 # §8e pads ( build/src/ov_SC06_011/ov_SC06_011_jr_80154C24.o: JTBL_PADS := 0,0 # §8e pads (jtbl_carve.py) tables=+0x0,+0x24 build/src/ov_SC06_011/ov_SC06_011_jr_801588CC.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x28 build/src/ov_SC06_011/ov_SC06_011_jr_80159C84.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x20 +build/src/ov_SC06_011/ov_SC06_011_jr_8015AE2C.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x20 ov_SC06_011_CHECK_SHA := config/check.ov_SC06_011.sha ov_SC06_011_SYMBOLS := config/symbols.ov_SC06_011.txt ov_SC06_011_SIG := .run/sig.ov_SC06_011.jsonl @@ -3281,6 +3393,7 @@ build/src/ov_SC06_013/ov_SC06_013_jr_8013F350.o: JTBL_PADS := 0,0 # §8e pads ( build/src/ov_SC06_013/ov_SC06_013_jr_80154C24.o: JTBL_PADS := 0,0 # §8e pads (jtbl_carve.py) tables=+0x0,+0x24 build/src/ov_SC06_013/ov_SC06_013_jr_801588CC.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x28 build/src/ov_SC06_013/ov_SC06_013_jr_80159C84.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x20 +build/src/ov_SC06_013/ov_SC06_013_jr_8015AE2C.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x20 ov_SC06_013_CHECK_SHA := config/check.ov_SC06_013.sha ov_SC06_013_SYMBOLS := config/symbols.ov_SC06_013.txt ov_SC06_013_SIG := .run/sig.ov_SC06_013.jsonl @@ -3309,6 +3422,7 @@ build/src/ov_SC06_014/ov_SC06_014_jr_8013F350.o: JTBL_PADS := 0,0 # §8e pads ( build/src/ov_SC06_014/ov_SC06_014_jr_80154C24.o: JTBL_PADS := 0,0 # §8e pads (jtbl_carve.py) tables=+0x0,+0x24 build/src/ov_SC06_014/ov_SC06_014_jr_801588CC.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x28 build/src/ov_SC06_014/ov_SC06_014_jr_80159C84.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x20 +build/src/ov_SC06_014/ov_SC06_014_jr_8015AE2C.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x20 ov_SC06_014_CHECK_SHA := config/check.ov_SC06_014.sha ov_SC06_014_SYMBOLS := config/symbols.ov_SC06_014.txt ov_SC06_014_SIG := .run/sig.ov_SC06_014.jsonl @@ -3337,6 +3451,7 @@ build/src/ov_SC06_015/ov_SC06_015_jr_8013F350.o: JTBL_PADS := 0,0 # §8e pads ( build/src/ov_SC06_015/ov_SC06_015_jr_80154C24.o: JTBL_PADS := 0,0 # §8e pads (jtbl_carve.py) tables=+0x0,+0x24 build/src/ov_SC06_015/ov_SC06_015_jr_801588CC.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x28 build/src/ov_SC06_015/ov_SC06_015_jr_80159C84.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x20 +build/src/ov_SC06_015/ov_SC06_015_jr_8015AE2C.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x20 ov_SC06_015_CHECK_SHA := config/check.ov_SC06_015.sha ov_SC06_015_SYMBOLS := config/symbols.ov_SC06_015.txt ov_SC06_015_SIG := .run/sig.ov_SC06_015.jsonl @@ -3365,6 +3480,7 @@ build/src/ov_SC06_016/ov_SC06_016_jr_8013F350.o: JTBL_PADS := 0,0 # §8e pads ( build/src/ov_SC06_016/ov_SC06_016_jr_80154C24.o: JTBL_PADS := 0,0 # §8e pads (jtbl_carve.py) tables=+0x0,+0x24 build/src/ov_SC06_016/ov_SC06_016_jr_801588CC.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x28 build/src/ov_SC06_016/ov_SC06_016_jr_80159C84.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x20 +build/src/ov_SC06_016/ov_SC06_016_jr_8015AE2C.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x20 ov_SC06_016_CHECK_SHA := config/check.ov_SC06_016.sha ov_SC06_016_SYMBOLS := config/symbols.ov_SC06_016.txt ov_SC06_016_SIG := .run/sig.ov_SC06_016.jsonl @@ -3393,6 +3509,7 @@ build/src/ov_SC06_018/ov_SC06_018_jr_8013F350.o: JTBL_PADS := 0,0 # §8e pads ( build/src/ov_SC06_018/ov_SC06_018_jr_80154C24.o: JTBL_PADS := 0,0 # §8e pads (jtbl_carve.py) tables=+0x0,+0x24 build/src/ov_SC06_018/ov_SC06_018_jr_801588CC.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x28 build/src/ov_SC06_018/ov_SC06_018_jr_80159C84.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x20 +build/src/ov_SC06_018/ov_SC06_018_jr_8015AE2C.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x20 ov_SC06_018_CHECK_SHA := config/check.ov_SC06_018.sha ov_SC06_018_SYMBOLS := config/symbols.ov_SC06_018.txt ov_SC06_018_SIG := .run/sig.ov_SC06_018.jsonl @@ -3421,6 +3538,7 @@ build/src/ov_SC06_020/ov_SC06_020_jr_8013F350.o: JTBL_PADS := 0,0 # §8e pads ( build/src/ov_SC06_020/ov_SC06_020_jr_80154C24.o: JTBL_PADS := 0,0 # §8e pads (jtbl_carve.py) tables=+0x0,+0x24 build/src/ov_SC06_020/ov_SC06_020_jr_801588CC.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x28 build/src/ov_SC06_020/ov_SC06_020_jr_80159C84.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x20 +build/src/ov_SC06_020/ov_SC06_020_jr_8015AE2C.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x20 ov_SC06_020_CHECK_SHA := config/check.ov_SC06_020.sha ov_SC06_020_SYMBOLS := config/symbols.ov_SC06_020.txt ov_SC06_020_SIG := .run/sig.ov_SC06_020.jsonl @@ -3449,6 +3567,7 @@ build/src/ov_SC06_022/ov_SC06_022_jr_8013F350.o: JTBL_PADS := 0,0 # §8e pads ( build/src/ov_SC06_022/ov_SC06_022_jr_80154C24.o: JTBL_PADS := 0,0 # §8e pads (jtbl_carve.py) tables=+0x0,+0x24 build/src/ov_SC06_022/ov_SC06_022_jr_801588CC.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x28 build/src/ov_SC06_022/ov_SC06_022_jr_80159C84.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x20 +build/src/ov_SC06_022/ov_SC06_022_jr_8015AE2C.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x20 ov_SC06_022_CHECK_SHA := config/check.ov_SC06_022.sha ov_SC06_022_SYMBOLS := config/symbols.ov_SC06_022.txt ov_SC06_022_SIG := .run/sig.ov_SC06_022.jsonl @@ -3477,6 +3596,7 @@ build/src/ov_SC06_024/ov_SC06_024_jr_8013F350.o: JTBL_PADS := 0,0 # §8e pads ( build/src/ov_SC06_024/ov_SC06_024_jr_80154C24.o: JTBL_PADS := 0,0 # §8e pads (jtbl_carve.py) tables=+0x0,+0x24 build/src/ov_SC06_024/ov_SC06_024_jr_801588CC.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x28 build/src/ov_SC06_024/ov_SC06_024_jr_80159C84.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x20 +build/src/ov_SC06_024/ov_SC06_024_jr_8015AE2C.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x20 ov_SC06_024_CHECK_SHA := config/check.ov_SC06_024.sha ov_SC06_024_SYMBOLS := config/symbols.ov_SC06_024.txt ov_SC06_024_SIG := .run/sig.ov_SC06_024.jsonl @@ -3505,6 +3625,7 @@ build/src/ov_SC06_025/ov_SC06_025_jr_8013F350.o: JTBL_PADS := 0,0 # §8e pads ( build/src/ov_SC06_025/ov_SC06_025_jr_80154C24.o: JTBL_PADS := 0,0 # §8e pads (jtbl_carve.py) tables=+0x0,+0x24 build/src/ov_SC06_025/ov_SC06_025_jr_801588CC.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x28 build/src/ov_SC06_025/ov_SC06_025_jr_80159C84.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x20 +build/src/ov_SC06_025/ov_SC06_025_jr_8015AE2C.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x20 ov_SC06_025_CHECK_SHA := config/check.ov_SC06_025.sha ov_SC06_025_SYMBOLS := config/symbols.ov_SC06_025.txt ov_SC06_025_SIG := .run/sig.ov_SC06_025.jsonl @@ -3533,6 +3654,7 @@ build/src/ov_SC06_027/ov_SC06_027_jr_8013F350.o: JTBL_PADS := 0,0 # §8e pads ( build/src/ov_SC06_027/ov_SC06_027_jr_80154C24.o: JTBL_PADS := 0,0 # §8e pads (jtbl_carve.py) tables=+0x0,+0x24 build/src/ov_SC06_027/ov_SC06_027_jr_801588CC.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x28 build/src/ov_SC06_027/ov_SC06_027_jr_80159C84.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x20 +build/src/ov_SC06_027/ov_SC06_027_jr_8015AE2C.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x20 ov_SC06_027_CHECK_SHA := config/check.ov_SC06_027.sha ov_SC06_027_SYMBOLS := config/symbols.ov_SC06_027.txt ov_SC06_027_SIG := .run/sig.ov_SC06_027.jsonl @@ -3561,6 +3683,7 @@ build/src/ov_SC06_029/ov_SC06_029_jr_8013F350.o: JTBL_PADS := 0,0 # §8e pads ( build/src/ov_SC06_029/ov_SC06_029_jr_80154C24.o: JTBL_PADS := 0,0 # §8e pads (jtbl_carve.py) tables=+0x0,+0x24 build/src/ov_SC06_029/ov_SC06_029_jr_801588CC.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x28 build/src/ov_SC06_029/ov_SC06_029_jr_80159C84.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x20 +build/src/ov_SC06_029/ov_SC06_029_jr_8015AE2C.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x20 ov_SC06_029_CHECK_SHA := config/check.ov_SC06_029.sha ov_SC06_029_SYMBOLS := config/symbols.ov_SC06_029.txt ov_SC06_029_SIG := .run/sig.ov_SC06_029.jsonl @@ -3589,6 +3712,7 @@ build/src/ov_SC06_030/ov_SC06_030_jr_8013F350.o: JTBL_PADS := 0,0 # §8e pads ( build/src/ov_SC06_030/ov_SC06_030_jr_80154C24.o: JTBL_PADS := 0,0 # §8e pads (jtbl_carve.py) tables=+0x0,+0x24 build/src/ov_SC06_030/ov_SC06_030_jr_801588CC.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x28 build/src/ov_SC06_030/ov_SC06_030_jr_80159C84.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x20 +build/src/ov_SC06_030/ov_SC06_030_jr_8015AE2C.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x20 ov_SC06_030_CHECK_SHA := config/check.ov_SC06_030.sha ov_SC06_030_SYMBOLS := config/symbols.ov_SC06_030.txt ov_SC06_030_SIG := .run/sig.ov_SC06_030.jsonl @@ -3617,6 +3741,7 @@ build/src/ov_SC06_032/ov_SC06_032_jr_8013F350.o: JTBL_PADS := 0,0 # §8e pads ( build/src/ov_SC06_032/ov_SC06_032_jr_80154C24.o: JTBL_PADS := 0,0 # §8e pads (jtbl_carve.py) tables=+0x0,+0x24 build/src/ov_SC06_032/ov_SC06_032_jr_801588CC.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x28 build/src/ov_SC06_032/ov_SC06_032_jr_80159C84.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x20 +build/src/ov_SC06_032/ov_SC06_032_jr_8015AE2C.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x20 ov_SC06_032_CHECK_SHA := config/check.ov_SC06_032.sha ov_SC06_032_SYMBOLS := config/symbols.ov_SC06_032.txt ov_SC06_032_SIG := .run/sig.ov_SC06_032.jsonl @@ -3645,6 +3770,7 @@ build/src/ov_SC06_033/ov_SC06_033_jr_8013F350.o: JTBL_PADS := 0,0 # §8e pads ( build/src/ov_SC06_033/ov_SC06_033_jr_80154C24.o: JTBL_PADS := 0,0 # §8e pads (jtbl_carve.py) tables=+0x0,+0x24 build/src/ov_SC06_033/ov_SC06_033_jr_801588CC.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x28 build/src/ov_SC06_033/ov_SC06_033_jr_80159C84.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x20 +build/src/ov_SC06_033/ov_SC06_033_jr_8015AE2C.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x20 ov_SC06_033_CHECK_SHA := config/check.ov_SC06_033.sha ov_SC06_033_SYMBOLS := config/symbols.ov_SC06_033.txt ov_SC06_033_SIG := .run/sig.ov_SC06_033.jsonl @@ -3673,6 +3799,7 @@ build/src/ov_SC07_001/ov_SC07_001_jr_8013F350.o: JTBL_PADS := 0,0 # §8e pads ( build/src/ov_SC07_001/ov_SC07_001_jr_80154C24.o: JTBL_PADS := 0,0 # §8e pads (jtbl_carve.py) tables=+0x0,+0x24 build/src/ov_SC07_001/ov_SC07_001_jr_801588CC.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x28 build/src/ov_SC07_001/ov_SC07_001_jr_80159C84.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x20 +build/src/ov_SC07_001/ov_SC07_001_jr_8015AE2C.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x20 ov_SC07_001_CHECK_SHA := config/check.ov_SC07_001.sha ov_SC07_001_SYMBOLS := config/symbols.ov_SC07_001.txt ov_SC07_001_SIG := .run/sig.ov_SC07_001.jsonl @@ -3701,6 +3828,7 @@ build/src/ov_SC07_002/ov_SC07_002_jr_8013F350.o: JTBL_PADS := 0,0 # §8e pads ( build/src/ov_SC07_002/ov_SC07_002_jr_80154C24.o: JTBL_PADS := 0,0 # §8e pads (jtbl_carve.py) tables=+0x0,+0x24 build/src/ov_SC07_002/ov_SC07_002_jr_801588CC.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x28 build/src/ov_SC07_002/ov_SC07_002_jr_80159C84.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x20 +build/src/ov_SC07_002/ov_SC07_002_jr_8015AE2C.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x20 ov_SC07_002_CHECK_SHA := config/check.ov_SC07_002.sha ov_SC07_002_SYMBOLS := config/symbols.ov_SC07_002.txt ov_SC07_002_SIG := .run/sig.ov_SC07_002.jsonl @@ -3729,6 +3857,7 @@ build/src/ov_SC07_008/ov_SC07_008_jr_8013F350.o: JTBL_PADS := 0,0 # §8e pads ( build/src/ov_SC07_008/ov_SC07_008_jr_80154C24.o: JTBL_PADS := 0,0 # §8e pads (jtbl_carve.py) tables=+0x0,+0x24 build/src/ov_SC07_008/ov_SC07_008_jr_801588CC.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x28 build/src/ov_SC07_008/ov_SC07_008_jr_80159C84.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x20 +build/src/ov_SC07_008/ov_SC07_008_jr_8015AE2C.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x20 ov_SC07_008_CHECK_SHA := config/check.ov_SC07_008.sha ov_SC07_008_SYMBOLS := config/symbols.ov_SC07_008.txt ov_SC07_008_SIG := .run/sig.ov_SC07_008.jsonl @@ -3757,6 +3886,7 @@ build/src/ov_SC07_009/ov_SC07_009_jr_8013F350.o: JTBL_PADS := 0,0 # §8e pads ( build/src/ov_SC07_009/ov_SC07_009_jr_80154C24.o: JTBL_PADS := 0,0 # §8e pads (jtbl_carve.py) tables=+0x0,+0x24 build/src/ov_SC07_009/ov_SC07_009_jr_801588CC.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x28 build/src/ov_SC07_009/ov_SC07_009_jr_80159C84.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x20 +build/src/ov_SC07_009/ov_SC07_009_jr_8015AE2C.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x20 ov_SC07_009_CHECK_SHA := config/check.ov_SC07_009.sha ov_SC07_009_SYMBOLS := config/symbols.ov_SC07_009.txt ov_SC07_009_SIG := .run/sig.ov_SC07_009.jsonl @@ -3778,7 +3908,7 @@ ov_SC07_006_ELF := $(ov_SC07_006_OUT).elf ov_SC07_006_MAPFILE := $(ov_SC07_006_OUT).map ov_SC07_006_LD_SCRIPT := $(ov_SC07_006_OUT).ld ov_SC07_006_SPLAT_YAML := config/splat.ov_SC07_006.yaml -ov_SC07_006_JTBL_INTERLEAVE := --order tail.data.o,ov_SC07_006.o,tail2.data.o,ov_SC07_006_jr_80131340.o,tail3.data.o,ov_SC07_006_jr_80135888.o,tail4.data.o,ov_SC07_006_jr_80135A4C.o,tail5.data.o,ov_SC07_006_jr_80135D20.o,tail6.data.o,ov_SC07_006_jr_8013F350.o,tail7.data.o,ov_SC07_006_jr_80140608.o,tail8.data.o,ov_SC07_006_jr_80154C24.o,ov_SC07_006_jr_801588CC.o,tail9.data.o,ov_SC07_006_jr_8015C32C.o,tail10.data.o,ov_SC07_006_jr_8017AE2C.o,ov_SC07_006_jr_8017BEBC.o,tail11.data.o,ov_SC07_006_jr_80183814.o,tail12.data.o,trailing.o # Phase-26 §8 jtbl-rodata carve +ov_SC07_006_JTBL_INTERLEAVE := --order tail.data.o,ov_SC07_006.o,tail2.data.o,ov_SC07_006_jr_80131340.o,tail3.data.o,ov_SC07_006_jr_80135888.o,tail4.data.o,ov_SC07_006_jr_80135A4C.o,tail5.data.o,ov_SC07_006_jr_80135D20.o,tail6.data.o,ov_SC07_006_jr_8013F350.o,tail7.data.o,ov_SC07_006_jr_80140608.o,tail8.data.o,ov_SC07_006_jr_80154C24.o,ov_SC07_006_jr_801588CC.o,tail9.data.o,ov_SC07_006_jr_8015B950.o,tail10.data.o,ov_SC07_006_jr_8015C32C.o,tail11.data.o,ov_SC07_006_jr_8017AE2C.o,ov_SC07_006_jr_8017BEBC.o,tail12.data.o,ov_SC07_006_jr_80183814.o,tail13.data.o,trailing.o # Phase-26 §8 jtbl-rodata carve build/src/ov_SC07_006/ov_SC07_006.o: JTBL_PADS := 0,0 # §8e pads (jtbl_carve.py) tables=+0x0,+0x14 build/src/ov_SC07_006/ov_SC07_006_jr_8013F350.o: JTBL_PADS := 0,0 # §8e pads (jtbl_carve.py) tables=+0x0,+0x20 build/src/ov_SC07_006/ov_SC07_006_jr_80154C24.o: JTBL_PADS := 0,0 # §8e pads (jtbl_carve.py) tables=+0x0,+0x24 @@ -3804,7 +3934,7 @@ ov_SC07_007_ELF := $(ov_SC07_007_OUT).elf ov_SC07_007_MAPFILE := $(ov_SC07_007_OUT).map ov_SC07_007_LD_SCRIPT := $(ov_SC07_007_OUT).ld ov_SC07_007_SPLAT_YAML := config/splat.ov_SC07_007.yaml -ov_SC07_007_JTBL_INTERLEAVE := --order tail.data.o,ov_SC07_007.o,tail2.data.o,ov_SC07_007_jr_80131340.o,tail3.data.o,ov_SC07_007_jr_80135888.o,tail4.data.o,ov_SC07_007_jr_80135A4C.o,tail5.data.o,ov_SC07_007_jr_80135D20.o,tail6.data.o,ov_SC07_007_jr_8013F350.o,tail7.data.o,ov_SC07_007_jr_80140608.o,tail8.data.o,ov_SC07_007_jr_80154C24.o,ov_SC07_007_jr_801588CC.o,tail9.data.o,ov_SC07_007_jr_8015C32C.o,tail10.data.o,ov_SC07_007_jr_8017AE2C.o,ov_SC07_007_jr_8017BEBC.o,tail11.data.o,trailing.o # Phase-26 §8 jtbl-rodata carve +ov_SC07_007_JTBL_INTERLEAVE := --order tail.data.o,ov_SC07_007.o,tail2.data.o,ov_SC07_007_jr_80131340.o,tail3.data.o,ov_SC07_007_jr_80135888.o,tail4.data.o,ov_SC07_007_jr_80135A4C.o,tail5.data.o,ov_SC07_007_jr_80135D20.o,tail6.data.o,ov_SC07_007_jr_8013F350.o,tail7.data.o,ov_SC07_007_jr_80140608.o,tail8.data.o,ov_SC07_007_jr_80154C24.o,ov_SC07_007_jr_801588CC.o,tail9.data.o,ov_SC07_007_jr_8015B950.o,tail10.data.o,ov_SC07_007_jr_8015C32C.o,tail11.data.o,ov_SC07_007_jr_8017AE2C.o,ov_SC07_007_jr_8017BEBC.o,tail12.data.o,trailing.o # Phase-26 §8 jtbl-rodata carve build/src/ov_SC07_007/ov_SC07_007.o: JTBL_PADS := 0,0 # §8e pads (jtbl_carve.py) tables=+0x0,+0x14 build/src/ov_SC07_007/ov_SC07_007_jr_8013F350.o: JTBL_PADS := 0,0 # §8e pads (jtbl_carve.py) tables=+0x0,+0x20 build/src/ov_SC07_007/ov_SC07_007_jr_80154C24.o: JTBL_PADS := 0,0 # §8e pads (jtbl_carve.py) tables=+0x0,+0x24 @@ -3830,7 +3960,7 @@ ov_SC07_010_ELF := $(ov_SC07_010_OUT).elf ov_SC07_010_MAPFILE := $(ov_SC07_010_OUT).map ov_SC07_010_LD_SCRIPT := $(ov_SC07_010_OUT).ld ov_SC07_010_SPLAT_YAML := config/splat.ov_SC07_010.yaml -ov_SC07_010_JTBL_INTERLEAVE := --order tail.data.o,ov_SC07_010.o,tail2.data.o,ov_SC07_010_jr_80131340.o,tail3.data.o,ov_SC07_010_jr_80135888.o,tail4.data.o,ov_SC07_010_jr_80135A4C.o,tail5.data.o,ov_SC07_010_jr_80135D20.o,tail6.data.o,ov_SC07_010_jr_8013F350.o,tail7.data.o,ov_SC07_010_jr_80140608.o,tail8.data.o,ov_SC07_010_jr_80154C24.o,ov_SC07_010_jr_801588CC.o,tail9.data.o,ov_SC07_010_jr_8015C32C.o,tail10.data.o,ov_SC07_010_jr_8017AE2C.o,tail11.data.o,trailing.o # Phase-26 §8 jtbl-rodata carve +ov_SC07_010_JTBL_INTERLEAVE := --order tail.data.o,ov_SC07_010.o,tail2.data.o,ov_SC07_010_jr_80131340.o,tail3.data.o,ov_SC07_010_jr_80135888.o,tail4.data.o,ov_SC07_010_jr_80135A4C.o,tail5.data.o,ov_SC07_010_jr_80135D20.o,tail6.data.o,ov_SC07_010_jr_8013F350.o,tail7.data.o,ov_SC07_010_jr_80140608.o,tail8.data.o,ov_SC07_010_jr_80154C24.o,ov_SC07_010_jr_801588CC.o,tail9.data.o,ov_SC07_010_jr_8015B950.o,tail10.data.o,ov_SC07_010_jr_8015C32C.o,tail11.data.o,ov_SC07_010_jr_8017AE2C.o,tail12.data.o,trailing.o # Phase-26 §8 jtbl-rodata carve build/src/ov_SC07_010/ov_SC07_010.o: JTBL_PADS := 0,0 # §8e pads (jtbl_carve.py) tables=+0x0,+0x14 build/src/ov_SC07_010/ov_SC07_010_jr_80154C24.o: JTBL_PADS := 0,0 # §8e pads (jtbl_carve.py) tables=+0x0,+0x24 build/src/ov_SC07_010/ov_SC07_010_jr_801588CC.o: JTBL_PADS := 0,4 # §8e pads (jtbl_carve.py) tables=+0x0,+0x28 @@ -3855,7 +3985,7 @@ ov_SC07_011_ELF := $(ov_SC07_011_OUT).elf ov_SC07_011_MAPFILE := $(ov_SC07_011_OUT).map ov_SC07_011_LD_SCRIPT := $(ov_SC07_011_OUT).ld ov_SC07_011_SPLAT_YAML := config/splat.ov_SC07_011.yaml -ov_SC07_011_JTBL_INTERLEAVE := --order tail.data.o,ov_SC07_011.o,tail2.data.o,ov_SC07_011_jr_80131340.o,tail3.data.o,ov_SC07_011_jr_80135888.o,tail4.data.o,ov_SC07_011_jr_80135A4C.o,tail5.data.o,ov_SC07_011_jr_80135D20.o,tail6.data.o,ov_SC07_011_jr_8013F350.o,tail7.data.o,ov_SC07_011_jr_80140608.o,tail8.data.o,ov_SC07_011_jr_80154C24.o,ov_SC07_011_jr_801588CC.o,tail9.data.o,ov_SC07_011_jr_8015C32C.o,tail10.data.o,ov_SC07_011_jr_8017AE2C.o,ov_SC07_011_jr_8017BEBC.o,tail11.data.o,trailing.o # Phase-26 §8 jtbl-rodata carve +ov_SC07_011_JTBL_INTERLEAVE := --order tail.data.o,ov_SC07_011.o,tail2.data.o,ov_SC07_011_jr_80131340.o,tail3.data.o,ov_SC07_011_jr_80135888.o,tail4.data.o,ov_SC07_011_jr_80135A4C.o,tail5.data.o,ov_SC07_011_jr_80135D20.o,tail6.data.o,ov_SC07_011_jr_8013F350.o,tail7.data.o,ov_SC07_011_jr_80140608.o,tail8.data.o,ov_SC07_011_jr_80154C24.o,ov_SC07_011_jr_801588CC.o,tail9.data.o,ov_SC07_011_jr_8015B950.o,tail10.data.o,ov_SC07_011_jr_8015C32C.o,tail11.data.o,ov_SC07_011_jr_8017AE2C.o,ov_SC07_011_jr_8017BEBC.o,tail12.data.o,trailing.o # Phase-26 §8 jtbl-rodata carve build/src/ov_SC07_011/ov_SC07_011.o: JTBL_PADS := 0,0 # §8e pads (jtbl_carve.py) tables=+0x0,+0x14 build/src/ov_SC07_011/ov_SC07_011_jr_8013F350.o: JTBL_PADS := 0,0 # §8e pads (jtbl_carve.py) tables=+0x0,+0x20 build/src/ov_SC07_011/ov_SC07_011_jr_80154C24.o: JTBL_PADS := 0,0 # §8e pads (jtbl_carve.py) tables=+0x0,+0x24 diff --git a/config/splat.ov_SC01_005.yaml b/config/splat.ov_SC01_005.yaml index 576240086..e2d21c3fc 100644 --- a/config/splat.ov_SC01_005.yaml +++ b/config/splat.ov_SC01_005.yaml @@ -145,7 +145,7 @@ segments: - [0xa3898, .rodata, ov_SC01_005_jr_8015A3C8] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0xa38b4, data, tail13] - [0xa38b8, .rodata, ov_SC01_005_jr_8015AE2C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - - [0xa38d4, data, tail14] + - [0xa38f4, data, tail14] - [0xa38f8, .rodata, ov_SC01_005_jr_8015C32C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0xa3914, data, tail15] - [0xa392c, .rodata, ov_SC01_005_jr_8016AB6C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) diff --git a/config/splat.ov_SC01_006.yaml b/config/splat.ov_SC01_006.yaml index c82a527fa..3c84dd256 100644 --- a/config/splat.ov_SC01_006.yaml +++ b/config/splat.ov_SC01_006.yaml @@ -145,7 +145,7 @@ segments: - [0xa3898, .rodata, ov_SC01_006_jr_8015A3C8] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0xa38b4, data, tail13] - [0xa38b8, .rodata, ov_SC01_006_jr_8015AE2C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - - [0xa38d4, data, tail14] + - [0xa38f4, data, tail14] - [0xa38f8, .rodata, ov_SC01_006_jr_8015C32C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0xa3914, data, tail15] - [0xa392c, .rodata, ov_SC01_006_jr_8016AB6C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) diff --git a/config/splat.ov_SC01_008.yaml b/config/splat.ov_SC01_008.yaml index 3a8e17b60..07c2e859e 100644 --- a/config/splat.ov_SC01_008.yaml +++ b/config/splat.ov_SC01_008.yaml @@ -145,7 +145,7 @@ segments: - [0x79348, .rodata, ov_SC01_008_jr_8015A3C8] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0x79364, data, tail13] - [0x79368, .rodata, ov_SC01_008_jr_8015AE2C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - - [0x79384, data, tail14] + - [0x793a4, data, tail14] - [0x793a8, .rodata, ov_SC01_008_jr_8015C32C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0x793c4, data, tail15] - [0x793dc, .rodata, ov_SC01_008_jr_8016AB6C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) diff --git a/config/splat.ov_SC01_009.yaml b/config/splat.ov_SC01_009.yaml index 22797cc2d..d1fbb8c17 100644 --- a/config/splat.ov_SC01_009.yaml +++ b/config/splat.ov_SC01_009.yaml @@ -145,7 +145,7 @@ segments: - [0xc910c, .rodata, ov_SC01_009_jr_8015A3C8] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0xc9128, data, tail13] - [0xc912c, .rodata, ov_SC01_009_jr_8015AE2C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - - [0xc9148, data, tail14] + - [0xc9168, data, tail14] - [0xc916c, .rodata, ov_SC01_009_jr_8015C32C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0xc9188, data, tail15] - [0xc91a0, .rodata, ov_SC01_009_jr_8016AB6C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) diff --git a/config/splat.ov_SC01_074.yaml b/config/splat.ov_SC01_074.yaml index 405a06ceb..bb82d3987 100644 --- a/config/splat.ov_SC01_074.yaml +++ b/config/splat.ov_SC01_074.yaml @@ -145,7 +145,7 @@ segments: - [0x7219c, .rodata, ov_SC01_074_jr_8015A3C8] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0x721b8, data, tail13] - [0x721bc, .rodata, ov_SC01_074_jr_8015AE2C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - - [0x721d8, data, tail14] + - [0x721f8, data, tail14] - [0x721fc, .rodata, ov_SC01_074_jr_8015C32C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0x72218, data, tail15] - [0x72230, .rodata, ov_SC01_074_jr_8016AB6C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) diff --git a/config/splat.ov_SC01_080.yaml b/config/splat.ov_SC01_080.yaml index 26eeefa78..c28e81e33 100644 --- a/config/splat.ov_SC01_080.yaml +++ b/config/splat.ov_SC01_080.yaml @@ -144,7 +144,7 @@ segments: - [0x9bfbc, .rodata, ov_SC01_080_jr_8015A3C8] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0x9bfd8, data, tail13] - [0x9bfdc, .rodata, ov_SC01_080_jr_8015AE2C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - - [0x9bff8, data, tail14] + - [0x9c018, data, tail14] - [0x9c01c, .rodata, ov_SC01_080_jr_8015C32C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0x9c038, data, tail15] - [0x9c050, .rodata, ov_SC01_080_jr_8016AB6C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) diff --git a/config/splat.ov_SC01_084.yaml b/config/splat.ov_SC01_084.yaml index 4800c91b6..f6a2fa18a 100644 --- a/config/splat.ov_SC01_084.yaml +++ b/config/splat.ov_SC01_084.yaml @@ -145,7 +145,7 @@ segments: - [0x9d98c, .rodata, ov_SC01_084_jr_8015A3C8] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0x9d9a8, data, tail13] - [0x9d9ac, .rodata, ov_SC01_084_jr_8015AE2C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - - [0x9d9c8, data, tail14] + - [0x9d9e8, data, tail14] - [0x9d9ec, .rodata, ov_SC01_084_jr_8015C32C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0x9da08, data, tail15] - [0x9da20, .rodata, ov_SC01_084_jr_8016AB6C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) diff --git a/config/splat.ov_SC02_000.yaml b/config/splat.ov_SC02_000.yaml index a9bc79ad1..e40fafed9 100644 --- a/config/splat.ov_SC02_000.yaml +++ b/config/splat.ov_SC02_000.yaml @@ -145,7 +145,7 @@ segments: - [0xbe1e0, .rodata, ov_SC02_000_jr_8015A3C8] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0xbe1fc, data, tail13] - [0xbe200, .rodata, ov_SC02_000_jr_8015AE2C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - - [0xbe21c, data, tail14] + - [0xbe23c, data, tail14] - [0xbe240, .rodata, ov_SC02_000_jr_8015C32C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0xbe25c, data, tail15] - [0xbe274, .rodata, ov_SC02_000_jr_8016AB6C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) diff --git a/config/splat.ov_SC02_003.yaml b/config/splat.ov_SC02_003.yaml index 8907918c8..55f280688 100644 --- a/config/splat.ov_SC02_003.yaml +++ b/config/splat.ov_SC02_003.yaml @@ -145,7 +145,7 @@ segments: - [0xbe1e0, .rodata, ov_SC02_003_jr_8015A3C8] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0xbe1fc, data, tail13] - [0xbe200, .rodata, ov_SC02_003_jr_8015AE2C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - - [0xbe21c, data, tail14] + - [0xbe23c, data, tail14] - [0xbe240, .rodata, ov_SC02_003_jr_8015C32C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0xbe25c, data, tail15] - [0xbe274, .rodata, ov_SC02_003_jr_8016AB6C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) diff --git a/config/splat.ov_SC02_004.yaml b/config/splat.ov_SC02_004.yaml index 160729b46..984da6527 100644 --- a/config/splat.ov_SC02_004.yaml +++ b/config/splat.ov_SC02_004.yaml @@ -144,7 +144,7 @@ segments: - [0x6c7f0, .rodata, ov_SC02_004_jr_8015A3C8] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0x6c80c, data, tail13] - [0x6c810, .rodata, ov_SC02_004_jr_8015AE2C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - - [0x6c82c, data, tail14] + - [0x6c84c, data, tail14] - [0x6c850, .rodata, ov_SC02_004_jr_8015C32C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0x6c86c, data, tail15] - [0x6c884, .rodata, ov_SC02_004_jr_8016AB6C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) diff --git a/config/splat.ov_SC02_005.yaml b/config/splat.ov_SC02_005.yaml index 7beae245b..7240639d6 100644 --- a/config/splat.ov_SC02_005.yaml +++ b/config/splat.ov_SC02_005.yaml @@ -144,7 +144,7 @@ segments: - [0xba524, .rodata, ov_SC02_005_jr_8015A3C8] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0xba540, data, tail13] - [0xba544, .rodata, ov_SC02_005_jr_8015AE2C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - - [0xba560, data, tail14] + - [0xba580, data, tail14] - [0xba584, .rodata, ov_SC02_005_jr_8015C32C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0xba5a0, data, tail15] - [0xba5b8, .rodata, ov_SC02_005_jr_8016AB6C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) diff --git a/config/splat.ov_SC02_011.yaml b/config/splat.ov_SC02_011.yaml index 0303ce140..be353ed33 100644 --- a/config/splat.ov_SC02_011.yaml +++ b/config/splat.ov_SC02_011.yaml @@ -144,7 +144,7 @@ segments: - [0xc1680, .rodata, ov_SC02_011_jr_8015A3C8] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0xc169c, data, tail13] - [0xc16a0, .rodata, ov_SC02_011_jr_8015AE2C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - - [0xc16bc, data, tail14] + - [0xc16dc, data, tail14] - [0xc16e0, .rodata, ov_SC02_011_jr_8015C32C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0xc16fc, data, tail15] - [0xc1714, .rodata, ov_SC02_011_jr_8016AB6C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) diff --git a/config/splat.ov_SC02_015.yaml b/config/splat.ov_SC02_015.yaml index b83430f55..9ff9fc7ee 100644 --- a/config/splat.ov_SC02_015.yaml +++ b/config/splat.ov_SC02_015.yaml @@ -144,7 +144,7 @@ segments: - [0x668d8, .rodata, ov_SC02_015_jr_8015A3C8] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0x668f4, data, tail13] - [0x668f8, .rodata, ov_SC02_015_jr_8015AE2C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - - [0x66914, data, tail14] + - [0x66934, data, tail14] - [0x66938, .rodata, ov_SC02_015_jr_8015C32C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0x66954, data, tail15] - [0x6696c, .rodata, ov_SC02_015_jr_8016AB6C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) diff --git a/config/splat.ov_SC02_016.yaml b/config/splat.ov_SC02_016.yaml index dd9c31f45..e7db4476e 100644 --- a/config/splat.ov_SC02_016.yaml +++ b/config/splat.ov_SC02_016.yaml @@ -145,7 +145,7 @@ segments: - [0x8a4b8, .rodata, ov_SC02_016_jr_8015A3C8] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0x8a4d4, data, tail13] - [0x8a4d8, .rodata, ov_SC02_016_jr_8015AE2C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - - [0x8a4f4, data, tail14] + - [0x8a514, data, tail14] - [0x8a518, .rodata, ov_SC02_016_jr_8015C32C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0x8a534, data, tail15] - [0x8a54c, .rodata, ov_SC02_016_jr_8016AB6C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) diff --git a/config/splat.ov_SC02_017.yaml b/config/splat.ov_SC02_017.yaml index ce549cf52..3c53b6adb 100644 --- a/config/splat.ov_SC02_017.yaml +++ b/config/splat.ov_SC02_017.yaml @@ -145,7 +145,7 @@ segments: - [0xc5cd8, .rodata, ov_SC02_017_jr_8015A3C8] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0xc5cf4, data, tail13] - [0xc5cf8, .rodata, ov_SC02_017_jr_8015AE2C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - - [0xc5d14, data, tail14] + - [0xc5d34, data, tail14] - [0xc5d38, .rodata, ov_SC02_017_jr_8015C32C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0xc5d54, data, tail15] - [0xc5d6c, .rodata, ov_SC02_017_jr_8016AB6C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) diff --git a/config/splat.ov_SC02_021.yaml b/config/splat.ov_SC02_021.yaml index ac9304fb3..93a802af3 100644 --- a/config/splat.ov_SC02_021.yaml +++ b/config/splat.ov_SC02_021.yaml @@ -145,7 +145,7 @@ segments: - [0x69254, .rodata, ov_SC02_021_jr_8015A3C8] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0x69270, data, tail13] - [0x69274, .rodata, ov_SC02_021_jr_8015AE2C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - - [0x69290, data, tail14] + - [0x692b0, data, tail14] - [0x692b4, .rodata, ov_SC02_021_jr_8015C32C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0x692d0, data, tail15] - [0x692e8, .rodata, ov_SC02_021_jr_8016AB6C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) diff --git a/config/splat.ov_SC02_026.yaml b/config/splat.ov_SC02_026.yaml index e538d31d5..dfe9be2b4 100644 --- a/config/splat.ov_SC02_026.yaml +++ b/config/splat.ov_SC02_026.yaml @@ -145,7 +145,7 @@ segments: - [0xa6688, .rodata, ov_SC02_026_jr_8015A3C8] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0xa66a4, data, tail13] - [0xa66a8, .rodata, ov_SC02_026_jr_8015AE2C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - - [0xa66c4, data, tail14] + - [0xa66e4, data, tail14] - [0xa66e8, .rodata, ov_SC02_026_jr_8015C32C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0xa6704, data, tail15] - [0xa671c, .rodata, ov_SC02_026_jr_8016AB6C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) diff --git a/config/splat.ov_SC02_027.yaml b/config/splat.ov_SC02_027.yaml index c48ad8f97..6cf6282ab 100644 --- a/config/splat.ov_SC02_027.yaml +++ b/config/splat.ov_SC02_027.yaml @@ -145,7 +145,7 @@ segments: - [0xb03f4, .rodata, ov_SC02_027_jr_8015A3C8] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0xb0410, data, tail13] - [0xb0414, .rodata, ov_SC02_027_jr_8015AE2C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - - [0xb0430, data, tail14] + - [0xb0450, data, tail14] - [0xb0454, .rodata, ov_SC02_027_jr_8015C32C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0xb0470, data, tail15] - [0xb0488, .rodata, ov_SC02_027_jr_8016AB6C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) diff --git a/config/splat.ov_SC02_028.yaml b/config/splat.ov_SC02_028.yaml index ae4385c61..271080ca2 100644 --- a/config/splat.ov_SC02_028.yaml +++ b/config/splat.ov_SC02_028.yaml @@ -145,7 +145,7 @@ segments: - [0xa9378, .rodata, ov_SC02_028_jr_8015A3C8] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0xa9394, data, tail13] - [0xa9398, .rodata, ov_SC02_028_jr_8015AE2C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - - [0xa93b4, data, tail14] + - [0xa93d4, data, tail14] - [0xa93d8, .rodata, ov_SC02_028_jr_8015C32C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0xa93f4, data, tail15] - [0xa940c, .rodata, ov_SC02_028_jr_8016AB6C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) diff --git a/config/splat.ov_SC02_031.yaml b/config/splat.ov_SC02_031.yaml index d2c162026..94756bb72 100644 --- a/config/splat.ov_SC02_031.yaml +++ b/config/splat.ov_SC02_031.yaml @@ -144,7 +144,7 @@ segments: - [0x8db74, .rodata, ov_SC02_031_jr_8015A3C8] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0x8db90, data, tail13] - [0x8db94, .rodata, ov_SC02_031_jr_8015AE2C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - - [0x8dbb0, data, tail14] + - [0x8dbd0, data, tail14] - [0x8dbd4, .rodata, ov_SC02_031_jr_8015C32C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0x8dbf0, data, tail15] - [0x8dc08, .rodata, ov_SC02_031_jr_8016AB6C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) diff --git a/config/splat.ov_SC02_035.yaml b/config/splat.ov_SC02_035.yaml index 1b1a704e4..b3c13e927 100644 --- a/config/splat.ov_SC02_035.yaml +++ b/config/splat.ov_SC02_035.yaml @@ -145,7 +145,7 @@ segments: - [0x94e3c, .rodata, ov_SC02_035_jr_8015A3C8] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0x94e58, data, tail13] - [0x94e5c, .rodata, ov_SC02_035_jr_8015AE2C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - - [0x94e78, data, tail14] + - [0x94e98, data, tail14] - [0x94e9c, .rodata, ov_SC02_035_jr_8015C32C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0x94eb8, data, tail15] - [0x94ed0, .rodata, ov_SC02_035_jr_8016AB6C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) diff --git a/config/splat.ov_SC02_039.yaml b/config/splat.ov_SC02_039.yaml index 497e18855..18cad2d8d 100644 --- a/config/splat.ov_SC02_039.yaml +++ b/config/splat.ov_SC02_039.yaml @@ -145,7 +145,7 @@ segments: - [0x77228, .rodata, ov_SC02_039_jr_8015A3C8] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0x77244, data, tail13] - [0x77248, .rodata, ov_SC02_039_jr_8015AE2C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - - [0x77264, data, tail14] + - [0x77284, data, tail14] - [0x77288, .rodata, ov_SC02_039_jr_8015C32C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0x772a4, data, tail15] - [0x772bc, .rodata, ov_SC02_039_jr_8016AB6C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) diff --git a/config/splat.ov_SC02_041.yaml b/config/splat.ov_SC02_041.yaml index 27470a7ad..6b96a5fed 100644 --- a/config/splat.ov_SC02_041.yaml +++ b/config/splat.ov_SC02_041.yaml @@ -145,7 +145,7 @@ segments: - [0x8f594, .rodata, ov_SC02_041_jr_8015A3C8] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0x8f5b0, data, tail13] - [0x8f5b4, .rodata, ov_SC02_041_jr_8015AE2C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - - [0x8f5d0, data, tail14] + - [0x8f5f0, data, tail14] - [0x8f5f4, .rodata, ov_SC02_041_jr_8015C32C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0x8f610, data, tail15] - [0x8f628, .rodata, ov_SC02_041_jr_8016AB6C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) diff --git a/config/splat.ov_SC03_001.yaml b/config/splat.ov_SC03_001.yaml index b7a175ec4..70e2ef2c7 100644 --- a/config/splat.ov_SC03_001.yaml +++ b/config/splat.ov_SC03_001.yaml @@ -144,7 +144,7 @@ segments: - [0xc46b4, .rodata, ov_SC03_001_jr_8015A3C8] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0xc46d0, data, tail13] - [0xc46d4, .rodata, ov_SC03_001_jr_8015AE2C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - - [0xc46f0, data, tail14] + - [0xc4710, data, tail14] - [0xc4714, .rodata, ov_SC03_001_jr_8015C32C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0xc4730, data, tail15] - [0xc4748, .rodata, ov_SC03_001_jr_8016AB6C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) diff --git a/config/splat.ov_SC03_002.yaml b/config/splat.ov_SC03_002.yaml index 169154dcc..0303996b3 100644 --- a/config/splat.ov_SC03_002.yaml +++ b/config/splat.ov_SC03_002.yaml @@ -145,7 +145,7 @@ segments: - [0xa1c10, .rodata, ov_SC03_002_jr_8015A3C8] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0xa1c2c, data, tail13] - [0xa1c30, .rodata, ov_SC03_002_jr_8015AE2C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - - [0xa1c4c, data, tail14] + - [0xa1c6c, data, tail14] - [0xa1c70, .rodata, ov_SC03_002_jr_8015C32C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0xa1c8c, data, tail15] - [0xa1ca4, .rodata, ov_SC03_002_jr_8016AB6C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) diff --git a/config/splat.ov_SC03_003.yaml b/config/splat.ov_SC03_003.yaml index 5626c1496..9f20be544 100644 --- a/config/splat.ov_SC03_003.yaml +++ b/config/splat.ov_SC03_003.yaml @@ -144,7 +144,7 @@ segments: - [0x65f90, .rodata, ov_SC03_003_jr_8015A3C8] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0x65fac, data, tail13] - [0x65fb0, .rodata, ov_SC03_003_jr_8015AE2C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - - [0x65fcc, data, tail14] + - [0x65fec, data, tail14] - [0x65ff0, .rodata, ov_SC03_003_jr_8015C32C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0x6600c, data, tail15] - [0x66024, .rodata, ov_SC03_003_jr_8016AB6C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) diff --git a/config/splat.ov_SC03_006.yaml b/config/splat.ov_SC03_006.yaml index 943a4f4e8..d68264a57 100644 --- a/config/splat.ov_SC03_006.yaml +++ b/config/splat.ov_SC03_006.yaml @@ -144,7 +144,7 @@ segments: - [0xcd84c, .rodata, ov_SC03_006_jr_8015A3C8] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0xcd868, data, tail13] - [0xcd86c, .rodata, ov_SC03_006_jr_8015AE2C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - - [0xcd888, data, tail14] + - [0xcd8a8, data, tail14] - [0xcd8ac, .rodata, ov_SC03_006_jr_8015C32C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0xcd8c8, data, tail15] - [0xcd8e0, .rodata, ov_SC03_006_jr_8016AB6C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) diff --git a/config/splat.ov_SC03_007.yaml b/config/splat.ov_SC03_007.yaml index 90c7af644..b7a19be8d 100644 --- a/config/splat.ov_SC03_007.yaml +++ b/config/splat.ov_SC03_007.yaml @@ -144,7 +144,7 @@ segments: - [0xc01d4, .rodata, ov_SC03_007_jr_8015A3C8] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0xc01f0, data, tail13] - [0xc01f4, .rodata, ov_SC03_007_jr_8015AE2C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - - [0xc0210, data, tail14] + - [0xc0230, data, tail14] - [0xc0234, .rodata, ov_SC03_007_jr_8015C32C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0xc0250, data, tail15] - [0xc0268, .rodata, ov_SC03_007_jr_8016AB6C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) diff --git a/config/splat.ov_SC03_010.yaml b/config/splat.ov_SC03_010.yaml index 068e4494f..cb0164a6b 100644 --- a/config/splat.ov_SC03_010.yaml +++ b/config/splat.ov_SC03_010.yaml @@ -145,7 +145,7 @@ segments: - [0x764b0, .rodata, ov_SC03_010_jr_8015A3C8] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0x764cc, data, tail13] - [0x764d0, .rodata, ov_SC03_010_jr_8015AE2C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - - [0x764ec, data, tail14] + - [0x7650c, data, tail14] - [0x76510, .rodata, ov_SC03_010_jr_8015C32C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0x7652c, data, tail15] - [0x76544, .rodata, ov_SC03_010_jr_8016AB6C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) diff --git a/config/splat.ov_SC03_011.yaml b/config/splat.ov_SC03_011.yaml index 23bece448..501744d19 100644 --- a/config/splat.ov_SC03_011.yaml +++ b/config/splat.ov_SC03_011.yaml @@ -142,7 +142,7 @@ segments: - [0x78720, .rodata, ov_SC03_011_jr_8015A3C8] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0x7873c, data, tail12] - [0x78740, .rodata, ov_SC03_011_jr_8015AE2C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - - [0x7875c, data, tail13] + - [0x7877c, data, tail13] - [0x78780, .rodata, ov_SC03_011_jr_8015C32C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0x7879c, data, tail14] - [0x787b4, .rodata, ov_SC03_011_jr_8016AB6C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) diff --git a/config/splat.ov_SC03_012.yaml b/config/splat.ov_SC03_012.yaml index ca4e042ff..c4f01f966 100644 --- a/config/splat.ov_SC03_012.yaml +++ b/config/splat.ov_SC03_012.yaml @@ -144,7 +144,7 @@ segments: - [0x6b57c, .rodata, ov_SC03_012_jr_8015A3C8] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0x6b598, data, tail13] - [0x6b59c, .rodata, ov_SC03_012_jr_8015AE2C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - - [0x6b5b8, data, tail14] + - [0x6b5d8, data, tail14] - [0x6b5dc, .rodata, ov_SC03_012_jr_8015C32C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0x6b5f8, data, tail15] - [0x6b610, .rodata, ov_SC03_012_jr_8016AB6C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) diff --git a/config/splat.ov_SC03_013.yaml b/config/splat.ov_SC03_013.yaml index 7da6c636d..3de76334e 100644 --- a/config/splat.ov_SC03_013.yaml +++ b/config/splat.ov_SC03_013.yaml @@ -145,7 +145,7 @@ segments: - [0x83814, .rodata, ov_SC03_013_jr_8015A3C8] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0x83830, data, tail13] - [0x83834, .rodata, ov_SC03_013_jr_8015AE2C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - - [0x83850, data, tail14] + - [0x83870, data, tail14] - [0x83874, .rodata, ov_SC03_013_jr_8015C32C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0x83890, data, tail15] - [0x838a8, .rodata, ov_SC03_013_jr_8016AB6C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) diff --git a/config/splat.ov_SC03_014.yaml b/config/splat.ov_SC03_014.yaml index 0f13ab29c..d9ceb7244 100644 --- a/config/splat.ov_SC03_014.yaml +++ b/config/splat.ov_SC03_014.yaml @@ -145,7 +145,7 @@ segments: - [0xc0be8, .rodata, ov_SC03_014_jr_8015A3C8] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0xc0c04, data, tail13] - [0xc0c08, .rodata, ov_SC03_014_jr_8015AE2C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - - [0xc0c24, data, tail14] + - [0xc0c44, data, tail14] - [0xc0c48, .rodata, ov_SC03_014_jr_8015C32C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0xc0c64, data, tail15] - [0xc0c7c, .rodata, ov_SC03_014_jr_8016AB6C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) diff --git a/config/splat.ov_SC03_015.yaml b/config/splat.ov_SC03_015.yaml index a5ef6d6aa..29d28867e 100644 --- a/config/splat.ov_SC03_015.yaml +++ b/config/splat.ov_SC03_015.yaml @@ -145,7 +145,7 @@ segments: - [0xc0be8, .rodata, ov_SC03_015_jr_8015A3C8] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0xc0c04, data, tail13] - [0xc0c08, .rodata, ov_SC03_015_jr_8015AE2C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - - [0xc0c24, data, tail14] + - [0xc0c44, data, tail14] - [0xc0c48, .rodata, ov_SC03_015_jr_8015C32C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0xc0c64, data, tail15] - [0xc0c7c, .rodata, ov_SC03_015_jr_8016AB6C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) diff --git a/config/splat.ov_SC03_023.yaml b/config/splat.ov_SC03_023.yaml index 6e5b3b822..22dec34a8 100644 --- a/config/splat.ov_SC03_023.yaml +++ b/config/splat.ov_SC03_023.yaml @@ -144,7 +144,7 @@ segments: - [0x6f1c0, .rodata, ov_SC03_023_jr_8015A3C8] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0x6f1dc, data, tail13] - [0x6f1e0, .rodata, ov_SC03_023_jr_8015AE2C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - - [0x6f1fc, data, tail14] + - [0x6f21c, data, tail14] - [0x6f220, .rodata, ov_SC03_023_jr_8015C32C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0x6f23c, data, tail15] - [0x6f254, .rodata, ov_SC03_023_jr_8016AB6C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) diff --git a/config/splat.ov_SC03_024.yaml b/config/splat.ov_SC03_024.yaml index d43950fb7..d0b34d758 100644 --- a/config/splat.ov_SC03_024.yaml +++ b/config/splat.ov_SC03_024.yaml @@ -145,7 +145,7 @@ segments: - [0x97648, .rodata, ov_SC03_024_jr_8015A3C8] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0x97664, data, tail13] - [0x97668, .rodata, ov_SC03_024_jr_8015AE2C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - - [0x97684, data, tail14] + - [0x976a4, data, tail14] - [0x976a8, .rodata, ov_SC03_024_jr_8015C32C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0x976c4, data, tail15] - [0x976dc, .rodata, ov_SC03_024_jr_8016AB6C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) diff --git a/config/splat.ov_SC03_028.yaml b/config/splat.ov_SC03_028.yaml index 82fb54140..20fb3ecdd 100644 --- a/config/splat.ov_SC03_028.yaml +++ b/config/splat.ov_SC03_028.yaml @@ -144,7 +144,7 @@ segments: - [0xc17d0, .rodata, ov_SC03_028_jr_8015A3C8] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0xc17ec, data, tail13] - [0xc17f0, .rodata, ov_SC03_028_jr_8015AE2C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - - [0xc180c, data, tail14] + - [0xc182c, data, tail14] - [0xc1830, .rodata, ov_SC03_028_jr_8015C32C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0xc184c, data, tail15] - [0xc1864, .rodata, ov_SC03_028_jr_8016AB6C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) diff --git a/config/splat.ov_SC03_029.yaml b/config/splat.ov_SC03_029.yaml index 321e10caa..eda2c0c92 100644 --- a/config/splat.ov_SC03_029.yaml +++ b/config/splat.ov_SC03_029.yaml @@ -145,7 +145,7 @@ segments: - [0xaf904, .rodata, ov_SC03_029_jr_8015A3C8] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0xaf920, data, tail13] - [0xaf924, .rodata, ov_SC03_029_jr_8015AE2C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - - [0xaf940, data, tail14] + - [0xaf960, data, tail14] - [0xaf964, .rodata, ov_SC03_029_jr_8015C32C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0xaf980, data, tail15] - [0xaf998, .rodata, ov_SC03_029_jr_8016AB6C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) diff --git a/config/splat.ov_SC03_030.yaml b/config/splat.ov_SC03_030.yaml index 49d049158..d650f3038 100644 --- a/config/splat.ov_SC03_030.yaml +++ b/config/splat.ov_SC03_030.yaml @@ -141,7 +141,7 @@ segments: - [0xb7fa8, .rodata, ov_SC03_030_jr_8015A3C8] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0xb7fc4, data, tail12] - [0xb7fc8, .rodata, ov_SC03_030_jr_8015AE2C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - - [0xb7fe4, data, tail13] + - [0xb8004, data, tail13] - [0xb8008, .rodata, ov_SC03_030_jr_8015C32C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0xb8024, data, tail14] - [0xb803c, .rodata, ov_SC03_030_jr_8016AB6C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) diff --git a/config/splat.ov_SC03_031.yaml b/config/splat.ov_SC03_031.yaml index 27c5d09e6..8b1ba5f6e 100644 --- a/config/splat.ov_SC03_031.yaml +++ b/config/splat.ov_SC03_031.yaml @@ -145,7 +145,7 @@ segments: - [0x9c44c, .rodata, ov_SC03_031_jr_8015A3C8] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0x9c468, data, tail13] - [0x9c46c, .rodata, ov_SC03_031_jr_8015AE2C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - - [0x9c488, data, tail14] + - [0x9c4a8, data, tail14] - [0x9c4ac, .rodata, ov_SC03_031_jr_8015C32C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0x9c4c8, data, tail15] - [0x9c4e0, .rodata, ov_SC03_031_jr_8016AB6C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) diff --git a/config/splat.ov_SC03_089.yaml b/config/splat.ov_SC03_089.yaml index bc468baa3..296124b76 100644 --- a/config/splat.ov_SC03_089.yaml +++ b/config/splat.ov_SC03_089.yaml @@ -145,7 +145,7 @@ segments: - [0x9ccb8, .rodata, ov_SC03_089_jr_8015A3C8] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0x9ccd4, data, tail13] - [0x9ccd8, .rodata, ov_SC03_089_jr_8015AE2C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - - [0x9ccf4, data, tail14] + - [0x9cd14, data, tail14] - [0x9cd18, .rodata, ov_SC03_089_jr_8015C32C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0x9cd34, data, tail15] - [0x9cd4c, .rodata, ov_SC03_089_jr_8016AB6C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) diff --git a/config/splat.ov_SC03_090.yaml b/config/splat.ov_SC03_090.yaml index ecd02a22b..ee16c0953 100644 --- a/config/splat.ov_SC03_090.yaml +++ b/config/splat.ov_SC03_090.yaml @@ -145,7 +145,7 @@ segments: - [0xa2124, .rodata, ov_SC03_090_jr_8015A3C8] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0xa2140, data, tail13] - [0xa2144, .rodata, ov_SC03_090_jr_8015AE2C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - - [0xa2160, data, tail14] + - [0xa2180, data, tail14] - [0xa2184, .rodata, ov_SC03_090_jr_8015C32C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0xa21a0, data, tail15] - [0xa21b8, .rodata, ov_SC03_090_jr_8016AB6C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) diff --git a/config/splat.ov_SC03_091.yaml b/config/splat.ov_SC03_091.yaml index dfddda704..a741e61ec 100644 --- a/config/splat.ov_SC03_091.yaml +++ b/config/splat.ov_SC03_091.yaml @@ -146,7 +146,7 @@ segments: - [0xa87f0, .rodata, ov_SC03_091_jr_8015A3C8] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0xa880c, data, tail13] - [0xa8810, .rodata, ov_SC03_091_jr_8015AE2C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - - [0xa882c, data, tail14] + - [0xa884c, data, tail14] - [0xa8850, .rodata, ov_SC03_091_jr_8015C32C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0xa886c, data, tail15] - [0xa8884, .rodata, ov_SC03_091_jr_8016AB6C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) diff --git a/config/splat.ov_SC03_092.yaml b/config/splat.ov_SC03_092.yaml index de0cfdca5..5579a6313 100644 --- a/config/splat.ov_SC03_092.yaml +++ b/config/splat.ov_SC03_092.yaml @@ -144,7 +144,7 @@ segments: - [0x893c8, .rodata, ov_SC03_092_jr_8015A3C8] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0x893e4, data, tail13] - [0x893e8, .rodata, ov_SC03_092_jr_8015AE2C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - - [0x89404, data, tail14] + - [0x89424, data, tail14] - [0x89428, .rodata, ov_SC03_092_jr_8015C32C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0x89444, data, tail15] - [0x8945c, .rodata, ov_SC03_092_jr_8016AB6C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) diff --git a/config/splat.ov_SC03_093.yaml b/config/splat.ov_SC03_093.yaml index ee77a0be2..786122f59 100644 --- a/config/splat.ov_SC03_093.yaml +++ b/config/splat.ov_SC03_093.yaml @@ -145,7 +145,7 @@ segments: - [0xa281c, .rodata, ov_SC03_093_jr_8015A3C8] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0xa2838, data, tail13] - [0xa283c, .rodata, ov_SC03_093_jr_8015AE2C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - - [0xa2858, data, tail14] + - [0xa2878, data, tail14] - [0xa287c, .rodata, ov_SC03_093_jr_8015C32C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0xa2898, data, tail15] - [0xa28b0, .rodata, ov_SC03_093_jr_8016AB6C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) diff --git a/config/splat.ov_SC03_094.yaml b/config/splat.ov_SC03_094.yaml index 56cf641e1..3fbb358f0 100644 --- a/config/splat.ov_SC03_094.yaml +++ b/config/splat.ov_SC03_094.yaml @@ -145,7 +145,7 @@ segments: - [0xa9658, .rodata, ov_SC03_094_jr_8015A3C8] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0xa9674, data, tail13] - [0xa9678, .rodata, ov_SC03_094_jr_8015AE2C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - - [0xa9694, data, tail14] + - [0xa96b4, data, tail14] - [0xa96b8, .rodata, ov_SC03_094_jr_8015C32C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0xa96d4, data, tail15] - [0xa96ec, .rodata, ov_SC03_094_jr_8016AB6C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) diff --git a/config/splat.ov_SC03_095.yaml b/config/splat.ov_SC03_095.yaml index b10270b27..130143368 100644 --- a/config/splat.ov_SC03_095.yaml +++ b/config/splat.ov_SC03_095.yaml @@ -145,7 +145,7 @@ segments: - [0x72284, .rodata, ov_SC03_095_jr_8015A3C8] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0x722a0, data, tail13] - [0x722a4, .rodata, ov_SC03_095_jr_8015AE2C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - - [0x722c0, data, tail14] + - [0x722e0, data, tail14] - [0x722e4, .rodata, ov_SC03_095_jr_8015C32C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0x72300, data, tail15] - [0x72318, .rodata, ov_SC03_095_jr_8016AB6C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) diff --git a/config/splat.ov_SC03_096.yaml b/config/splat.ov_SC03_096.yaml index 21facd7e2..c7973f0b0 100644 --- a/config/splat.ov_SC03_096.yaml +++ b/config/splat.ov_SC03_096.yaml @@ -145,7 +145,7 @@ segments: - [0x70d38, .rodata, ov_SC03_096_jr_8015A3C8] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0x70d54, data, tail13] - [0x70d58, .rodata, ov_SC03_096_jr_8015AE2C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - - [0x70d74, data, tail14] + - [0x70d94, data, tail14] - [0x70d98, .rodata, ov_SC03_096_jr_8015C32C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0x70db4, data, tail15] - [0x70dcc, .rodata, ov_SC03_096_jr_8016AB6C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) diff --git a/config/splat.ov_SC03_097.yaml b/config/splat.ov_SC03_097.yaml index a07119017..e513687d4 100644 --- a/config/splat.ov_SC03_097.yaml +++ b/config/splat.ov_SC03_097.yaml @@ -145,7 +145,7 @@ segments: - [0x80da8, .rodata, ov_SC03_097_jr_8015A3C8] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0x80dc4, data, tail13] - [0x80dc8, .rodata, ov_SC03_097_jr_8015AE2C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - - [0x80de4, data, tail14] + - [0x80e04, data, tail14] - [0x80e08, .rodata, ov_SC03_097_jr_8015C32C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0x80e24, data, tail15] - [0x80e3c, .rodata, ov_SC03_097_jr_8016AB6C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) diff --git a/config/splat.ov_SC03_098.yaml b/config/splat.ov_SC03_098.yaml index 7f4fd73de..3b35add28 100644 --- a/config/splat.ov_SC03_098.yaml +++ b/config/splat.ov_SC03_098.yaml @@ -145,7 +145,7 @@ segments: - [0x9ba2c, .rodata, ov_SC03_098_jr_8015A3C8] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0x9ba48, data, tail13] - [0x9ba4c, .rodata, ov_SC03_098_jr_8015AE2C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - - [0x9ba68, data, tail14] + - [0x9ba88, data, tail14] - [0x9ba8c, .rodata, ov_SC03_098_jr_8015C32C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0x9baa8, data, tail15] - [0x9bac0, .rodata, ov_SC03_098_jr_8016AB6C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) diff --git a/config/splat.ov_SC03_099.yaml b/config/splat.ov_SC03_099.yaml index a66ed5d67..227d405c0 100644 --- a/config/splat.ov_SC03_099.yaml +++ b/config/splat.ov_SC03_099.yaml @@ -145,7 +145,7 @@ segments: - [0x95700, .rodata, ov_SC03_099_jr_8015A3C8] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0x9571c, data, tail13] - [0x95720, .rodata, ov_SC03_099_jr_8015AE2C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - - [0x9573c, data, tail14] + - [0x9575c, data, tail14] - [0x95760, .rodata, ov_SC03_099_jr_8015C32C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0x9577c, data, tail15] - [0x95794, .rodata, ov_SC03_099_jr_8016AB6C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) diff --git a/config/splat.ov_SC03_100.yaml b/config/splat.ov_SC03_100.yaml index 251470937..68d923771 100644 --- a/config/splat.ov_SC03_100.yaml +++ b/config/splat.ov_SC03_100.yaml @@ -145,7 +145,7 @@ segments: - [0x9e984, .rodata, ov_SC03_100_jr_8015A3C8] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0x9e9a0, data, tail13] - [0x9e9a4, .rodata, ov_SC03_100_jr_8015AE2C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - - [0x9e9c0, data, tail14] + - [0x9e9e0, data, tail14] - [0x9e9e4, .rodata, ov_SC03_100_jr_8015C32C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0x9ea00, data, tail15] - [0x9ea18, .rodata, ov_SC03_100_jr_8016AB6C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) diff --git a/config/splat.ov_SC03_101.yaml b/config/splat.ov_SC03_101.yaml index 46912ed94..3d542dd67 100644 --- a/config/splat.ov_SC03_101.yaml +++ b/config/splat.ov_SC03_101.yaml @@ -145,7 +145,7 @@ segments: - [0x7424c, .rodata, ov_SC03_101_jr_8015A3C8] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0x74268, data, tail13] - [0x7426c, .rodata, ov_SC03_101_jr_8015AE2C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - - [0x74288, data, tail14] + - [0x742a8, data, tail14] - [0x742ac, .rodata, ov_SC03_101_jr_8015C32C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0x742c8, data, tail15] - [0x742e0, .rodata, ov_SC03_101_jr_8016AB6C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) diff --git a/config/splat.ov_SC03_102.yaml b/config/splat.ov_SC03_102.yaml index 4e48dbcae..5ac4a9fde 100644 --- a/config/splat.ov_SC03_102.yaml +++ b/config/splat.ov_SC03_102.yaml @@ -145,7 +145,7 @@ segments: - [0x8fec8, .rodata, ov_SC03_102_jr_8015A3C8] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0x8fee4, data, tail13] - [0x8fee8, .rodata, ov_SC03_102_jr_8015AE2C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - - [0x8ff04, data, tail14] + - [0x8ff24, data, tail14] - [0x8ff28, .rodata, ov_SC03_102_jr_8015C32C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0x8ff44, data, tail15] - [0x8ff5c, .rodata, ov_SC03_102_jr_8016AB6C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) diff --git a/config/splat.ov_SC03_103.yaml b/config/splat.ov_SC03_103.yaml index bc709f4c2..82347f8d8 100644 --- a/config/splat.ov_SC03_103.yaml +++ b/config/splat.ov_SC03_103.yaml @@ -142,7 +142,7 @@ segments: - [0x9b07c, .rodata, ov_SC03_103_jr_8015A3C8] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0x9b098, data, tail12] - [0x9b09c, .rodata, ov_SC03_103_jr_8015AE2C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - - [0x9b0b8, data, tail13] + - [0x9b0d8, data, tail13] - [0x9b0dc, .rodata, ov_SC03_103_jr_8015C32C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0x9b0f8, data, tail14] - [0x9b110, .rodata, ov_SC03_103_jr_8016AB6C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) diff --git a/config/splat.ov_SC03_104.yaml b/config/splat.ov_SC03_104.yaml index 28d19c655..9132f835a 100644 --- a/config/splat.ov_SC03_104.yaml +++ b/config/splat.ov_SC03_104.yaml @@ -145,7 +145,7 @@ segments: - [0x965dc, .rodata, ov_SC03_104_jr_8015A3C8] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0x965f8, data, tail13] - [0x965fc, .rodata, ov_SC03_104_jr_8015AE2C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - - [0x96618, data, tail14] + - [0x96638, data, tail14] - [0x9663c, .rodata, ov_SC03_104_jr_8015C32C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0x96658, data, tail15] - [0x96670, .rodata, ov_SC03_104_jr_8016AB6C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) diff --git a/config/splat.ov_SC03_105.yaml b/config/splat.ov_SC03_105.yaml index e618c16f3..7115a2a52 100644 --- a/config/splat.ov_SC03_105.yaml +++ b/config/splat.ov_SC03_105.yaml @@ -145,7 +145,7 @@ segments: - [0x8f8d4, .rodata, ov_SC03_105_jr_8015A3C8] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0x8f8f0, data, tail13] - [0x8f8f4, .rodata, ov_SC03_105_jr_8015AE2C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - - [0x8f910, data, tail14] + - [0x8f930, data, tail14] - [0x8f934, .rodata, ov_SC03_105_jr_8015C32C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0x8f950, data, tail15] - [0x8f968, .rodata, ov_SC03_105_jr_8016AB6C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) diff --git a/config/splat.ov_SC03_108.yaml b/config/splat.ov_SC03_108.yaml index 9238111dc..9aba690f1 100644 --- a/config/splat.ov_SC03_108.yaml +++ b/config/splat.ov_SC03_108.yaml @@ -145,7 +145,7 @@ segments: - [0x77ddc, .rodata, ov_SC03_108_jr_8015A3C8] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0x77df8, data, tail13] - [0x77dfc, .rodata, ov_SC03_108_jr_8015AE2C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - - [0x77e18, data, tail14] + - [0x77e38, data, tail14] - [0x77e3c, .rodata, ov_SC03_108_jr_8015C32C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0x77e58, data, tail15] - [0x77e70, .rodata, ov_SC03_108_jr_8016AB6C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) diff --git a/config/splat.ov_SC03_109.yaml b/config/splat.ov_SC03_109.yaml index 0b867dd67..8669ad50f 100644 --- a/config/splat.ov_SC03_109.yaml +++ b/config/splat.ov_SC03_109.yaml @@ -145,7 +145,7 @@ segments: - [0x708ec, .rodata, ov_SC03_109_jr_8015A3C8] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0x70908, data, tail13] - [0x7090c, .rodata, ov_SC03_109_jr_8015AE2C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - - [0x70928, data, tail14] + - [0x70948, data, tail14] - [0x7094c, .rodata, ov_SC03_109_jr_8015C32C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0x70968, data, tail15] - [0x70980, .rodata, ov_SC03_109_jr_8016AB6C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) diff --git a/config/splat.ov_SC03_110.yaml b/config/splat.ov_SC03_110.yaml index dda119e7a..0031c27a6 100644 --- a/config/splat.ov_SC03_110.yaml +++ b/config/splat.ov_SC03_110.yaml @@ -145,7 +145,7 @@ segments: - [0x78588, .rodata, ov_SC03_110_jr_8015A3C8] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0x785a4, data, tail13] - [0x785a8, .rodata, ov_SC03_110_jr_8015AE2C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - - [0x785c4, data, tail14] + - [0x785e4, data, tail14] - [0x785e8, .rodata, ov_SC03_110_jr_8015C32C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0x78604, data, tail15] - [0x7861c, .rodata, ov_SC03_110_jr_8016AB6C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) diff --git a/config/splat.ov_SC03_111.yaml b/config/splat.ov_SC03_111.yaml index e37271851..b57ae38e2 100644 --- a/config/splat.ov_SC03_111.yaml +++ b/config/splat.ov_SC03_111.yaml @@ -145,7 +145,7 @@ segments: - [0x8fb08, .rodata, ov_SC03_111_jr_8015A3C8] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0x8fb24, data, tail13] - [0x8fb28, .rodata, ov_SC03_111_jr_8015AE2C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - - [0x8fb44, data, tail14] + - [0x8fb64, data, tail14] - [0x8fb68, .rodata, ov_SC03_111_jr_8015C32C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0x8fb84, data, tail15] - [0x8fb9c, .rodata, ov_SC03_111_jr_8016AB6C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) diff --git a/config/splat.ov_SC03_112.yaml b/config/splat.ov_SC03_112.yaml index 701cdd441..16a5fd8ea 100644 --- a/config/splat.ov_SC03_112.yaml +++ b/config/splat.ov_SC03_112.yaml @@ -145,7 +145,7 @@ segments: - [0x83270, .rodata, ov_SC03_112_jr_8015A3C8] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0x8328c, data, tail13] - [0x83290, .rodata, ov_SC03_112_jr_8015AE2C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - - [0x832ac, data, tail14] + - [0x832cc, data, tail14] - [0x832d0, .rodata, ov_SC03_112_jr_8015C32C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0x832ec, data, tail15] - [0x83304, .rodata, ov_SC03_112_jr_8016AB6C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) diff --git a/config/splat.ov_SC03_113.yaml b/config/splat.ov_SC03_113.yaml index 7fa5ae10e..e6b058bca 100644 --- a/config/splat.ov_SC03_113.yaml +++ b/config/splat.ov_SC03_113.yaml @@ -145,7 +145,7 @@ segments: - [0x7bef8, .rodata, ov_SC03_113_jr_8015A3C8] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0x7bf14, data, tail13] - [0x7bf18, .rodata, ov_SC03_113_jr_8015AE2C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - - [0x7bf34, data, tail14] + - [0x7bf54, data, tail14] - [0x7bf58, .rodata, ov_SC03_113_jr_8015C32C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0x7bf74, data, tail15] - [0x7bf8c, .rodata, ov_SC03_113_jr_8016AB6C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) diff --git a/config/splat.ov_SC03_114.yaml b/config/splat.ov_SC03_114.yaml index 55398bba5..ffd25288d 100644 --- a/config/splat.ov_SC03_114.yaml +++ b/config/splat.ov_SC03_114.yaml @@ -145,7 +145,7 @@ segments: - [0x7fc04, .rodata, ov_SC03_114_jr_8015A3C8] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0x7fc20, data, tail13] - [0x7fc24, .rodata, ov_SC03_114_jr_8015AE2C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - - [0x7fc40, data, tail14] + - [0x7fc60, data, tail14] - [0x7fc64, .rodata, ov_SC03_114_jr_8015C32C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0x7fc80, data, tail15] - [0x7fc98, .rodata, ov_SC03_114_jr_8016AB6C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) diff --git a/config/splat.ov_SC03_115.yaml b/config/splat.ov_SC03_115.yaml index da06cf1c3..2457330e7 100644 --- a/config/splat.ov_SC03_115.yaml +++ b/config/splat.ov_SC03_115.yaml @@ -145,7 +145,7 @@ segments: - [0x6b578, .rodata, ov_SC03_115_jr_8015A3C8] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0x6b594, data, tail13] - [0x6b598, .rodata, ov_SC03_115_jr_8015AE2C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - - [0x6b5b4, data, tail14] + - [0x6b5d4, data, tail14] - [0x6b5d8, .rodata, ov_SC03_115_jr_8015C32C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0x6b5f4, data, tail15] - [0x6b60c, .rodata, ov_SC03_115_jr_8016AB6C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) diff --git a/config/splat.ov_SC03_116.yaml b/config/splat.ov_SC03_116.yaml index cf78b56ae..7d1e1edd3 100644 --- a/config/splat.ov_SC03_116.yaml +++ b/config/splat.ov_SC03_116.yaml @@ -144,7 +144,7 @@ segments: - [0x6e114, .rodata, ov_SC03_116_jr_8015A3C8] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0x6e130, data, tail13] - [0x6e134, .rodata, ov_SC03_116_jr_8015AE2C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - - [0x6e150, data, tail14] + - [0x6e170, data, tail14] - [0x6e174, .rodata, ov_SC03_116_jr_8015C32C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0x6e190, data, tail15] - [0x6e1a8, .rodata, ov_SC03_116_jr_8016AB6C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) diff --git a/config/splat.ov_SC03_117.yaml b/config/splat.ov_SC03_117.yaml index cef93b4b4..90eb2502c 100644 --- a/config/splat.ov_SC03_117.yaml +++ b/config/splat.ov_SC03_117.yaml @@ -145,7 +145,7 @@ segments: - [0xa47b4, .rodata, ov_SC03_117_jr_8015A3C8] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0xa47d0, data, tail13] - [0xa47d4, .rodata, ov_SC03_117_jr_8015AE2C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - - [0xa47f0, data, tail14] + - [0xa4810, data, tail14] - [0xa4814, .rodata, ov_SC03_117_jr_8015C32C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0xa4830, data, tail15] - [0xa4848, .rodata, ov_SC03_117_jr_8016AB6C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) diff --git a/config/splat.ov_SC03_118.yaml b/config/splat.ov_SC03_118.yaml index 09ab45959..418f964b3 100644 --- a/config/splat.ov_SC03_118.yaml +++ b/config/splat.ov_SC03_118.yaml @@ -145,7 +145,7 @@ segments: - [0xaa710, .rodata, ov_SC03_118_jr_8015A3C8] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0xaa72c, data, tail13] - [0xaa730, .rodata, ov_SC03_118_jr_8015AE2C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - - [0xaa74c, data, tail14] + - [0xaa76c, data, tail14] - [0xaa770, .rodata, ov_SC03_118_jr_8015C32C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0xaa78c, data, tail15] - [0xaa7a4, .rodata, ov_SC03_118_jr_8016AB6C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) diff --git a/config/splat.ov_SC03_119.yaml b/config/splat.ov_SC03_119.yaml index ec0e4b6b0..4bc284288 100644 --- a/config/splat.ov_SC03_119.yaml +++ b/config/splat.ov_SC03_119.yaml @@ -145,7 +145,7 @@ segments: - [0xaa710, .rodata, ov_SC03_119_jr_8015A3C8] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0xaa72c, data, tail13] - [0xaa730, .rodata, ov_SC03_119_jr_8015AE2C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - - [0xaa74c, data, tail14] + - [0xaa76c, data, tail14] - [0xaa770, .rodata, ov_SC03_119_jr_8015C32C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0xaa78c, data, tail15] - [0xaa7a4, .rodata, ov_SC03_119_jr_8016AB6C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) diff --git a/config/splat.ov_SC03_121.yaml b/config/splat.ov_SC03_121.yaml index 39fbc7f7c..2e0c1b11a 100644 --- a/config/splat.ov_SC03_121.yaml +++ b/config/splat.ov_SC03_121.yaml @@ -145,7 +145,7 @@ segments: - [0x85218, .rodata, ov_SC03_121_jr_8015A3C8] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0x85234, data, tail13] - [0x85238, .rodata, ov_SC03_121_jr_8015AE2C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - - [0x85254, data, tail14] + - [0x85274, data, tail14] - [0x85278, .rodata, ov_SC03_121_jr_8015C32C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0x85294, data, tail15] - [0x852ac, .rodata, ov_SC03_121_jr_8016AB6C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) diff --git a/config/splat.ov_SC03_124.yaml b/config/splat.ov_SC03_124.yaml index 5bf9dcce4..f8eeab1cf 100644 --- a/config/splat.ov_SC03_124.yaml +++ b/config/splat.ov_SC03_124.yaml @@ -144,7 +144,7 @@ segments: - [0xb796c, .rodata, ov_SC03_124_jr_8015A3C8] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0xb7988, data, tail13] - [0xb798c, .rodata, ov_SC03_124_jr_8015AE2C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - - [0xb79a8, data, tail14] + - [0xb79c8, data, tail14] - [0xb79cc, .rodata, ov_SC03_124_jr_8015C32C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0xb79e8, data, tail15] - [0xb7a00, .rodata, ov_SC03_124_jr_8016AB6C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) diff --git a/config/splat.ov_SC03_125.yaml b/config/splat.ov_SC03_125.yaml index e251c6fc0..997d5636e 100644 --- a/config/splat.ov_SC03_125.yaml +++ b/config/splat.ov_SC03_125.yaml @@ -145,7 +145,7 @@ segments: - [0x9a658, .rodata, ov_SC03_125_jr_8015A3C8] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0x9a674, data, tail13] - [0x9a678, .rodata, ov_SC03_125_jr_8015AE2C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - - [0x9a694, data, tail14] + - [0x9a6b4, data, tail14] - [0x9a6b8, .rodata, ov_SC03_125_jr_8015C32C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0x9a6d4, data, tail15] - [0x9a6ec, .rodata, ov_SC03_125_jr_8016AB6C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) diff --git a/config/splat.ov_SC03_126.yaml b/config/splat.ov_SC03_126.yaml index 9a2286504..713950d2d 100644 --- a/config/splat.ov_SC03_126.yaml +++ b/config/splat.ov_SC03_126.yaml @@ -145,7 +145,7 @@ segments: - [0x65f44, .rodata, ov_SC03_126_jr_8015A3C8] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0x65f60, data, tail13] - [0x65f64, .rodata, ov_SC03_126_jr_8015AE2C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - - [0x65f80, data, tail14] + - [0x65fa0, data, tail14] - [0x65fa4, .rodata, ov_SC03_126_jr_8015C32C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0x65fc0, data, tail15] - [0x65fd8, .rodata, ov_SC03_126_jr_8016AB6C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) diff --git a/config/splat.ov_SC04_000.yaml b/config/splat.ov_SC04_000.yaml index 4497aed17..87f0ad2d3 100644 --- a/config/splat.ov_SC04_000.yaml +++ b/config/splat.ov_SC04_000.yaml @@ -145,7 +145,7 @@ segments: - [0x7ffc0, .rodata, ov_SC04_000_jr_8015A3C8] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0x7ffdc, data, tail13] - [0x7ffe0, .rodata, ov_SC04_000_jr_8015AE2C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - - [0x7fffc, data, tail14] + - [0x8001c, data, tail14] - [0x80020, .rodata, ov_SC04_000_jr_8015C32C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0x8003c, data, tail15] - [0x80054, .rodata, ov_SC04_000_jr_8016AB6C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) diff --git a/config/splat.ov_SC04_002.yaml b/config/splat.ov_SC04_002.yaml index 3eaf1ca1c..421b486a2 100644 --- a/config/splat.ov_SC04_002.yaml +++ b/config/splat.ov_SC04_002.yaml @@ -145,7 +145,7 @@ segments: - [0x97310, .rodata, ov_SC04_002_jr_8015A3C8] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0x9732c, data, tail13] - [0x97330, .rodata, ov_SC04_002_jr_8015AE2C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - - [0x9734c, data, tail14] + - [0x9736c, data, tail14] - [0x97370, .rodata, ov_SC04_002_jr_8015C32C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0x9738c, data, tail15] - [0x973a4, .rodata, ov_SC04_002_jr_8016AB6C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) diff --git a/config/splat.ov_SC04_003.yaml b/config/splat.ov_SC04_003.yaml index 4daa1aa40..6ea29ba2f 100644 --- a/config/splat.ov_SC04_003.yaml +++ b/config/splat.ov_SC04_003.yaml @@ -145,7 +145,7 @@ segments: - [0x71f8c, .rodata, ov_SC04_003_jr_8015A3C8] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0x71fa8, data, tail13] - [0x71fac, .rodata, ov_SC04_003_jr_8015AE2C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - - [0x71fc8, data, tail14] + - [0x71fe8, data, tail14] - [0x71fec, .rodata, ov_SC04_003_jr_8015C32C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0x72008, data, tail15] - [0x72020, .rodata, ov_SC04_003_jr_8016AB6C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) diff --git a/config/splat.ov_SC04_004.yaml b/config/splat.ov_SC04_004.yaml index 259c3c0c2..4f9fc8240 100644 --- a/config/splat.ov_SC04_004.yaml +++ b/config/splat.ov_SC04_004.yaml @@ -144,7 +144,7 @@ segments: - [0x89d88, .rodata, ov_SC04_004_jr_8015A3C8] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0x89da4, data, tail13] - [0x89da8, .rodata, ov_SC04_004_jr_8015AE2C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - - [0x89dc4, data, tail14] + - [0x89de4, data, tail14] - [0x89de8, .rodata, ov_SC04_004_jr_8015C32C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0x89e04, data, tail15] - [0x89e1c, .rodata, ov_SC04_004_jr_8016AB6C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) diff --git a/config/splat.ov_SC04_005.yaml b/config/splat.ov_SC04_005.yaml index 3476ddd73..afa489de2 100644 --- a/config/splat.ov_SC04_005.yaml +++ b/config/splat.ov_SC04_005.yaml @@ -145,7 +145,7 @@ segments: - [0x97f4c, .rodata, ov_SC04_005_jr_8015A3C8] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0x97f68, data, tail13] - [0x97f6c, .rodata, ov_SC04_005_jr_8015AE2C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - - [0x97f88, data, tail14] + - [0x97fa8, data, tail14] - [0x97fac, .rodata, ov_SC04_005_jr_8015C32C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0x97fc8, data, tail15] - [0x97fe0, .rodata, ov_SC04_005_jr_8016AB6C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) diff --git a/config/splat.ov_SC04_006.yaml b/config/splat.ov_SC04_006.yaml index db09853eb..710b020a8 100644 --- a/config/splat.ov_SC04_006.yaml +++ b/config/splat.ov_SC04_006.yaml @@ -145,7 +145,7 @@ segments: - [0x741f4, .rodata, ov_SC04_006_jr_8015A3C8] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0x74210, data, tail13] - [0x74214, .rodata, ov_SC04_006_jr_8015AE2C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - - [0x74230, data, tail14] + - [0x74250, data, tail14] - [0x74254, .rodata, ov_SC04_006_jr_8015C32C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0x74270, data, tail15] - [0x74288, .rodata, ov_SC04_006_jr_8016AB6C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) diff --git a/config/splat.ov_SC04_007.yaml b/config/splat.ov_SC04_007.yaml index be9ca4311..5be386923 100644 --- a/config/splat.ov_SC04_007.yaml +++ b/config/splat.ov_SC04_007.yaml @@ -145,7 +145,7 @@ segments: - [0x8b7b0, .rodata, ov_SC04_007_jr_8015A3C8] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0x8b7cc, data, tail13] - [0x8b7d0, .rodata, ov_SC04_007_jr_8015AE2C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - - [0x8b7ec, data, tail14] + - [0x8b80c, data, tail14] - [0x8b810, .rodata, ov_SC04_007_jr_8015C32C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0x8b82c, data, tail15] - [0x8b844, .rodata, ov_SC04_007_jr_8016AB6C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) diff --git a/config/splat.ov_SC04_008.yaml b/config/splat.ov_SC04_008.yaml index f14ecc595..1ed34dea5 100644 --- a/config/splat.ov_SC04_008.yaml +++ b/config/splat.ov_SC04_008.yaml @@ -141,7 +141,7 @@ segments: - [0x68460, .rodata, ov_SC04_008_jr_80159C84] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0x68494, data, tail12] - [0x684b8, .rodata, ov_SC04_008_jr_8015AE2C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - - [0x684d4, data, tail13] + - [0x684f4, data, tail13] - [0x684f8, .rodata, ov_SC04_008_jr_8015C32C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0x68514, data, tail14] - [0x6852c, .rodata, ov_SC04_008_jr_8016AB6C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) diff --git a/config/splat.ov_SC04_009.yaml b/config/splat.ov_SC04_009.yaml index 6f4c7381d..4cae09a14 100644 --- a/config/splat.ov_SC04_009.yaml +++ b/config/splat.ov_SC04_009.yaml @@ -145,7 +145,7 @@ segments: - [0x6e6ac, .rodata, ov_SC04_009_jr_8015A3C8] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0x6e6c8, data, tail13] - [0x6e6cc, .rodata, ov_SC04_009_jr_8015AE2C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - - [0x6e6e8, data, tail14] + - [0x6e708, data, tail14] - [0x6e70c, .rodata, ov_SC04_009_jr_8015C32C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0x6e728, data, tail15] - [0x6e740, .rodata, ov_SC04_009_jr_8016AB6C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) diff --git a/config/splat.ov_SC04_010.yaml b/config/splat.ov_SC04_010.yaml index daea0ca84..8e39cfffc 100644 --- a/config/splat.ov_SC04_010.yaml +++ b/config/splat.ov_SC04_010.yaml @@ -145,7 +145,7 @@ segments: - [0x65b38, .rodata, ov_SC04_010_jr_8015A3C8] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0x65b54, data, tail13] - [0x65b58, .rodata, ov_SC04_010_jr_8015AE2C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - - [0x65b74, data, tail14] + - [0x65b94, data, tail14] - [0x65b98, .rodata, ov_SC04_010_jr_8015C32C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0x65bb4, data, tail15] - [0x65bcc, .rodata, ov_SC04_010_jr_8016AB6C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) diff --git a/config/splat.ov_SC04_011.yaml b/config/splat.ov_SC04_011.yaml index 611aca04e..cfe451527 100644 --- a/config/splat.ov_SC04_011.yaml +++ b/config/splat.ov_SC04_011.yaml @@ -145,7 +145,7 @@ segments: - [0xc50d4, .rodata, ov_SC04_011_jr_8015A3C8] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0xc50f0, data, tail13] - [0xc50f4, .rodata, ov_SC04_011_jr_8015AE2C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - - [0xc5110, data, tail14] + - [0xc5130, data, tail14] - [0xc5134, .rodata, ov_SC04_011_jr_8015C32C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0xc5150, data, tail15] - [0xc5168, .rodata, ov_SC04_011_jr_8016AB6C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) diff --git a/config/splat.ov_SC04_012.yaml b/config/splat.ov_SC04_012.yaml index 54b978112..529f0552c 100644 --- a/config/splat.ov_SC04_012.yaml +++ b/config/splat.ov_SC04_012.yaml @@ -144,7 +144,7 @@ segments: - [0x68218, .rodata, ov_SC04_012_jr_8015A3C8] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0x68234, data, tail13] - [0x68238, .rodata, ov_SC04_012_jr_8015AE2C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - - [0x68254, data, tail14] + - [0x68274, data, tail14] - [0x68278, .rodata, ov_SC04_012_jr_8015C32C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0x68294, data, tail15] - [0x682ac, .rodata, ov_SC04_012_jr_8016AB6C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) diff --git a/config/splat.ov_SC04_015.yaml b/config/splat.ov_SC04_015.yaml index f090800c6..6fd67b2b5 100644 --- a/config/splat.ov_SC04_015.yaml +++ b/config/splat.ov_SC04_015.yaml @@ -144,7 +144,7 @@ segments: - [0x9eeb0, .rodata, ov_SC04_015_jr_8015A3C8] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0x9eecc, data, tail13] - [0x9eed0, .rodata, ov_SC04_015_jr_8015AE2C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - - [0x9eeec, data, tail14] + - [0x9ef0c, data, tail14] - [0x9ef10, .rodata, ov_SC04_015_jr_8015C32C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0x9ef2c, data, tail15] - [0x9ef44, .rodata, ov_SC04_015_jr_8016AB6C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) diff --git a/config/splat.ov_SC04_016.yaml b/config/splat.ov_SC04_016.yaml index d000a9ef2..b8f176a70 100644 --- a/config/splat.ov_SC04_016.yaml +++ b/config/splat.ov_SC04_016.yaml @@ -145,7 +145,7 @@ segments: - [0x7d068, .rodata, ov_SC04_016_jr_8015A3C8] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0x7d084, data, tail13] - [0x7d088, .rodata, ov_SC04_016_jr_8015AE2C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - - [0x7d0a4, data, tail14] + - [0x7d0c4, data, tail14] - [0x7d0c8, .rodata, ov_SC04_016_jr_8015C32C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0x7d0e4, data, tail15] - [0x7d0fc, .rodata, ov_SC04_016_jr_8016AB6C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) diff --git a/config/splat.ov_SC04_018.yaml b/config/splat.ov_SC04_018.yaml index efe072623..d82e8b945 100644 --- a/config/splat.ov_SC04_018.yaml +++ b/config/splat.ov_SC04_018.yaml @@ -144,7 +144,7 @@ segments: - [0xbce80, .rodata, ov_SC04_018_jr_8015A3C8] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0xbce9c, data, tail13] - [0xbcea0, .rodata, ov_SC04_018_jr_8015AE2C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - - [0xbcebc, data, tail14] + - [0xbcedc, data, tail14] - [0xbcee0, .rodata, ov_SC04_018_jr_8015C32C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0xbcefc, data, tail15] - [0xbcf14, .rodata, ov_SC04_018_jr_8016AB6C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) diff --git a/config/splat.ov_SC04_019.yaml b/config/splat.ov_SC04_019.yaml index 674279921..b46299cbe 100644 --- a/config/splat.ov_SC04_019.yaml +++ b/config/splat.ov_SC04_019.yaml @@ -144,7 +144,7 @@ segments: - [0xbce80, .rodata, ov_SC04_019_jr_8015A3C8] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0xbce9c, data, tail13] - [0xbcea0, .rodata, ov_SC04_019_jr_8015AE2C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - - [0xbcebc, data, tail14] + - [0xbcedc, data, tail14] - [0xbcee0, .rodata, ov_SC04_019_jr_8015C32C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0xbcefc, data, tail15] - [0xbcf14, .rodata, ov_SC04_019_jr_8016AB6C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) diff --git a/config/splat.ov_SC04_020.yaml b/config/splat.ov_SC04_020.yaml index 3eb819a72..a5b42c75a 100644 --- a/config/splat.ov_SC04_020.yaml +++ b/config/splat.ov_SC04_020.yaml @@ -145,7 +145,7 @@ segments: - [0x928a8, .rodata, ov_SC04_020_jr_8015A3C8] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0x928c4, data, tail13] - [0x928c8, .rodata, ov_SC04_020_jr_8015AE2C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - - [0x928e4, data, tail14] + - [0x92904, data, tail14] - [0x92908, .rodata, ov_SC04_020_jr_8015C32C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0x92924, data, tail15] - [0x9293c, .rodata, ov_SC04_020_jr_8016AB6C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) diff --git a/config/splat.ov_SC04_021.yaml b/config/splat.ov_SC04_021.yaml index 11c6d9ec5..2fce20d0d 100644 --- a/config/splat.ov_SC04_021.yaml +++ b/config/splat.ov_SC04_021.yaml @@ -145,7 +145,7 @@ segments: - [0x65f44, .rodata, ov_SC04_021_jr_8015A3C8] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0x65f60, data, tail13] - [0x65f64, .rodata, ov_SC04_021_jr_8015AE2C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - - [0x65f80, data, tail14] + - [0x65fa0, data, tail14] - [0x65fa4, .rodata, ov_SC04_021_jr_8015C32C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0x65fc0, data, tail15] - [0x65fd8, .rodata, ov_SC04_021_jr_8016AB6C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) diff --git a/config/splat.ov_SC05_000.yaml b/config/splat.ov_SC05_000.yaml index 6f3d1be30..ffd7e08ed 100644 --- a/config/splat.ov_SC05_000.yaml +++ b/config/splat.ov_SC05_000.yaml @@ -145,7 +145,7 @@ segments: - [0x71094, .rodata, ov_SC05_000_jr_8015A3C8] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0x710b0, data, tail13] - [0x710b4, .rodata, ov_SC05_000_jr_8015AE2C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - - [0x710d0, data, tail14] + - [0x710f0, data, tail14] - [0x710f4, .rodata, ov_SC05_000_jr_8015C32C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0x71110, data, tail15] - [0x71128, .rodata, ov_SC05_000_jr_8016AB6C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) diff --git a/config/splat.ov_SC05_001.yaml b/config/splat.ov_SC05_001.yaml index 92a40e0e1..f14b10ebb 100644 --- a/config/splat.ov_SC05_001.yaml +++ b/config/splat.ov_SC05_001.yaml @@ -145,7 +145,7 @@ segments: - [0x8c048, .rodata, ov_SC05_001_jr_8015A3C8] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0x8c064, data, tail13] - [0x8c068, .rodata, ov_SC05_001_jr_8015AE2C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - - [0x8c084, data, tail14] + - [0x8c0a4, data, tail14] - [0x8c0a8, .rodata, ov_SC05_001_jr_8015C32C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0x8c0c4, data, tail15] - [0x8c0dc, .rodata, ov_SC05_001_jr_8016AB6C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) diff --git a/config/splat.ov_SC05_002.yaml b/config/splat.ov_SC05_002.yaml index 63c4b4ef3..9c3f26010 100644 --- a/config/splat.ov_SC05_002.yaml +++ b/config/splat.ov_SC05_002.yaml @@ -145,7 +145,7 @@ segments: - [0x763f4, .rodata, ov_SC05_002_jr_8015A3C8] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0x76410, data, tail13] - [0x76414, .rodata, ov_SC05_002_jr_8015AE2C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - - [0x76430, data, tail14] + - [0x76450, data, tail14] - [0x76454, .rodata, ov_SC05_002_jr_8015C32C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0x76470, data, tail15] - [0x76488, .rodata, ov_SC05_002_jr_8016AB6C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) diff --git a/config/splat.ov_SC05_003.yaml b/config/splat.ov_SC05_003.yaml index a6a954fc4..91d029bbe 100644 --- a/config/splat.ov_SC05_003.yaml +++ b/config/splat.ov_SC05_003.yaml @@ -145,7 +145,7 @@ segments: - [0x82ef0, .rodata, ov_SC05_003_jr_8015A3C8] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0x82f0c, data, tail13] - [0x82f10, .rodata, ov_SC05_003_jr_8015AE2C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - - [0x82f2c, data, tail14] + - [0x82f4c, data, tail14] - [0x82f50, .rodata, ov_SC05_003_jr_8015C32C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0x82f6c, data, tail15] - [0x82f84, .rodata, ov_SC05_003_jr_8016AB6C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) diff --git a/config/splat.ov_SC05_004.yaml b/config/splat.ov_SC05_004.yaml index c10f70c3a..7e5e0dc19 100644 --- a/config/splat.ov_SC05_004.yaml +++ b/config/splat.ov_SC05_004.yaml @@ -142,7 +142,7 @@ segments: - [0x754e4, .rodata, ov_SC05_004_jr_8015A3C8] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0x75500, data, tail12] - [0x75504, .rodata, ov_SC05_004_jr_8015AE2C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - - [0x75520, data, tail13] + - [0x75540, data, tail13] - [0x75544, .rodata, ov_SC05_004_jr_8015C32C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0x75560, data, tail14] - [0x75578, .rodata, ov_SC05_004_jr_8016AB6C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) diff --git a/config/splat.ov_SC05_005.yaml b/config/splat.ov_SC05_005.yaml index 8aeb7308b..dd02eba47 100644 --- a/config/splat.ov_SC05_005.yaml +++ b/config/splat.ov_SC05_005.yaml @@ -145,7 +145,7 @@ segments: - [0x881cc, .rodata, ov_SC05_005_jr_8015A3C8] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0x881e8, data, tail13] - [0x881ec, .rodata, ov_SC05_005_jr_8015AE2C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - - [0x88208, data, tail14] + - [0x88228, data, tail14] - [0x8822c, .rodata, ov_SC05_005_jr_8015C32C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0x88248, data, tail15] - [0x88260, .rodata, ov_SC05_005_jr_8016AB6C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) diff --git a/config/splat.ov_SC05_006.yaml b/config/splat.ov_SC05_006.yaml index 311f0fafd..81c6754cd 100644 --- a/config/splat.ov_SC05_006.yaml +++ b/config/splat.ov_SC05_006.yaml @@ -145,7 +145,7 @@ segments: - [0x6631c, .rodata, ov_SC05_006_jr_8015A3C8] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0x66338, data, tail13] - [0x6633c, .rodata, ov_SC05_006_jr_8015AE2C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - - [0x66358, data, tail14] + - [0x66378, data, tail14] - [0x6637c, .rodata, ov_SC05_006_jr_8015C32C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0x66398, data, tail15] - [0x663b0, .rodata, ov_SC05_006_jr_8016AB6C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) diff --git a/config/splat.ov_SC05_007.yaml b/config/splat.ov_SC05_007.yaml index 92ff3e31a..d90e56d1e 100644 --- a/config/splat.ov_SC05_007.yaml +++ b/config/splat.ov_SC05_007.yaml @@ -145,7 +145,7 @@ segments: - [0x732f4, .rodata, ov_SC05_007_jr_8015A3C8] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0x73310, data, tail13] - [0x73314, .rodata, ov_SC05_007_jr_8015AE2C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - - [0x73330, data, tail14] + - [0x73350, data, tail14] - [0x73354, .rodata, ov_SC05_007_jr_8015C32C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0x73370, data, tail15] - [0x73388, .rodata, ov_SC05_007_jr_8016AB6C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) diff --git a/config/splat.ov_SC05_008.yaml b/config/splat.ov_SC05_008.yaml index 8b4fca07b..9ccf112a9 100644 --- a/config/splat.ov_SC05_008.yaml +++ b/config/splat.ov_SC05_008.yaml @@ -144,7 +144,7 @@ segments: - [0x77628, .rodata, ov_SC05_008_jr_8015A3C8] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0x77644, data, tail13] - [0x77648, .rodata, ov_SC05_008_jr_8015AE2C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - - [0x77664, data, tail14] + - [0x77684, data, tail14] - [0x77688, .rodata, ov_SC05_008_jr_8015C32C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0x776a4, data, tail15] - [0x776bc, .rodata, ov_SC05_008_jr_8016AB6C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) diff --git a/config/splat.ov_SC05_009.yaml b/config/splat.ov_SC05_009.yaml index dfe6330fa..06cf10e66 100644 --- a/config/splat.ov_SC05_009.yaml +++ b/config/splat.ov_SC05_009.yaml @@ -142,7 +142,7 @@ segments: - [0x6d004, .rodata, ov_SC05_009_jr_80159C84] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0x6d038, data, tail12] - [0x6d05c, .rodata, ov_SC05_009_jr_8015AE2C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - - [0x6d078, data, tail13] + - [0x6d098, data, tail13] - [0x6d09c, .rodata, ov_SC05_009_jr_8015C32C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0x6d0b8, data, tail14] - [0x6d0d0, .rodata, ov_SC05_009_jr_8016AB6C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) diff --git a/config/splat.ov_SC05_010.yaml b/config/splat.ov_SC05_010.yaml index 1f7e2de8c..e315175ea 100644 --- a/config/splat.ov_SC05_010.yaml +++ b/config/splat.ov_SC05_010.yaml @@ -145,7 +145,7 @@ segments: - [0x9d270, .rodata, ov_SC05_010_jr_8015A3C8] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0x9d28c, data, tail13] - [0x9d290, .rodata, ov_SC05_010_jr_8015AE2C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - - [0x9d2ac, data, tail14] + - [0x9d2cc, data, tail14] - [0x9d2d0, .rodata, ov_SC05_010_jr_8015C32C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0x9d2ec, data, tail15] - [0x9d304, .rodata, ov_SC05_010_jr_8016AB6C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) diff --git a/config/splat.ov_SC05_011.yaml b/config/splat.ov_SC05_011.yaml index 306b0e3d6..b9ec3cb55 100644 --- a/config/splat.ov_SC05_011.yaml +++ b/config/splat.ov_SC05_011.yaml @@ -145,7 +145,7 @@ segments: - [0x735d4, .rodata, ov_SC05_011_jr_8015A3C8] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0x735f0, data, tail13] - [0x735f4, .rodata, ov_SC05_011_jr_8015AE2C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - - [0x73610, data, tail14] + - [0x73630, data, tail14] - [0x73634, .rodata, ov_SC05_011_jr_8015C32C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0x73650, data, tail15] - [0x73668, .rodata, ov_SC05_011_jr_8016AB6C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) diff --git a/config/splat.ov_SC05_017.yaml b/config/splat.ov_SC05_017.yaml index ea98b8e0a..4d86e7969 100644 --- a/config/splat.ov_SC05_017.yaml +++ b/config/splat.ov_SC05_017.yaml @@ -144,7 +144,7 @@ segments: - [0xc2cbc, .rodata, ov_SC05_017_jr_8015A3C8] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0xc2cd8, data, tail13] - [0xc2cdc, .rodata, ov_SC05_017_jr_8015AE2C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - - [0xc2cf8, data, tail14] + - [0xc2d18, data, tail14] - [0xc2d1c, .rodata, ov_SC05_017_jr_8015C32C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0xc2d38, data, tail15] - [0xc2d50, .rodata, ov_SC05_017_jr_8016AB6C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) diff --git a/config/splat.ov_SC05_018.yaml b/config/splat.ov_SC05_018.yaml index a485aa3d8..a92bad395 100644 --- a/config/splat.ov_SC05_018.yaml +++ b/config/splat.ov_SC05_018.yaml @@ -145,7 +145,7 @@ segments: - [0xbc830, .rodata, ov_SC05_018_jr_8015A3C8] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0xbc84c, data, tail13] - [0xbc850, .rodata, ov_SC05_018_jr_8015AE2C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - - [0xbc86c, data, tail14] + - [0xbc88c, data, tail14] - [0xbc890, .rodata, ov_SC05_018_jr_8015C32C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0xbc8ac, data, tail15] - [0xbc8c4, .rodata, ov_SC05_018_jr_8016AB6C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) diff --git a/config/splat.ov_SC05_019.yaml b/config/splat.ov_SC05_019.yaml index 8cf4f5d44..b397043d7 100644 --- a/config/splat.ov_SC05_019.yaml +++ b/config/splat.ov_SC05_019.yaml @@ -145,7 +145,7 @@ segments: - [0x65f44, .rodata, ov_SC05_019_jr_8015A3C8] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0x65f60, data, tail13] - [0x65f64, .rodata, ov_SC05_019_jr_8015AE2C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - - [0x65f80, data, tail14] + - [0x65fa0, data, tail14] - [0x65fa4, .rodata, ov_SC05_019_jr_8015C32C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0x65fc0, data, tail15] - [0x65fd8, .rodata, ov_SC05_019_jr_8016AB6C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) diff --git a/config/splat.ov_SC06_000.yaml b/config/splat.ov_SC06_000.yaml index 6b68577b4..607ee013b 100644 --- a/config/splat.ov_SC06_000.yaml +++ b/config/splat.ov_SC06_000.yaml @@ -141,7 +141,7 @@ segments: - [0x84bbc, .rodata, ov_SC06_000_jr_8015A3C8] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0x84bd8, data, tail12] - [0x84bdc, .rodata, ov_SC06_000_jr_8015AE2C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - - [0x84bf8, data, tail13] + - [0x84c18, data, tail13] - [0x84c1c, .rodata, ov_SC06_000_jr_8015C32C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0x84c38, data, tail14] - [0x84c50, .rodata, ov_SC06_000_jr_8016AB6C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) diff --git a/config/splat.ov_SC06_006.yaml b/config/splat.ov_SC06_006.yaml index f56f81684..b07545a5f 100644 --- a/config/splat.ov_SC06_006.yaml +++ b/config/splat.ov_SC06_006.yaml @@ -145,7 +145,7 @@ segments: - [0xce4c4, .rodata, ov_SC06_006_jr_8015A3C8] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0xce4e0, data, tail13] - [0xce4e4, .rodata, ov_SC06_006_jr_8015AE2C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - - [0xce500, data, tail14] + - [0xce520, data, tail14] - [0xce524, .rodata, ov_SC06_006_jr_8015C32C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0xce540, data, tail15] - [0xce558, .rodata, ov_SC06_006_jr_8016AB6C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) diff --git a/config/splat.ov_SC06_008.yaml b/config/splat.ov_SC06_008.yaml index 0edc62737..8a6af6706 100644 --- a/config/splat.ov_SC06_008.yaml +++ b/config/splat.ov_SC06_008.yaml @@ -145,7 +145,7 @@ segments: - [0x8059c, .rodata, ov_SC06_008_jr_8015A3C8] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0x805b8, data, tail13] - [0x805bc, .rodata, ov_SC06_008_jr_8015AE2C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - - [0x805d8, data, tail14] + - [0x805f8, data, tail14] - [0x805fc, .rodata, ov_SC06_008_jr_8015C32C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0x80618, data, tail15] - [0x80630, .rodata, ov_SC06_008_jr_8016AB6C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) diff --git a/config/splat.ov_SC06_010.yaml b/config/splat.ov_SC06_010.yaml index df73d6376..11b2dc8a3 100644 --- a/config/splat.ov_SC06_010.yaml +++ b/config/splat.ov_SC06_010.yaml @@ -140,7 +140,7 @@ segments: - [0x885f0, .rodata, ov_SC06_010_jr_8015A3C8] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0x8860c, data, tail12] - [0x88610, .rodata, ov_SC06_010_jr_8015AE2C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - - [0x8862c, data, tail13] + - [0x8864c, data, tail13] - [0x88650, .rodata, ov_SC06_010_jr_8015C32C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0x8866c, data, tail14] - [0x88684, .rodata, ov_SC06_010_jr_8016AB6C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) diff --git a/config/splat.ov_SC06_011.yaml b/config/splat.ov_SC06_011.yaml index bf70b4d9f..bafc3b049 100644 --- a/config/splat.ov_SC06_011.yaml +++ b/config/splat.ov_SC06_011.yaml @@ -145,7 +145,7 @@ segments: - [0x82150, .rodata, ov_SC06_011_jr_8015A3C8] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0x8216c, data, tail13] - [0x82170, .rodata, ov_SC06_011_jr_8015AE2C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - - [0x8218c, data, tail14] + - [0x821ac, data, tail14] - [0x821b0, .rodata, ov_SC06_011_jr_8015C32C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0x821cc, data, tail15] - [0x821e4, .rodata, ov_SC06_011_jr_8016AB6C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) diff --git a/config/splat.ov_SC06_013.yaml b/config/splat.ov_SC06_013.yaml index a62bbba17..9b539ef7f 100644 --- a/config/splat.ov_SC06_013.yaml +++ b/config/splat.ov_SC06_013.yaml @@ -145,7 +145,7 @@ segments: - [0x71024, .rodata, ov_SC06_013_jr_8015A3C8] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0x71040, data, tail13] - [0x71044, .rodata, ov_SC06_013_jr_8015AE2C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - - [0x71060, data, tail14] + - [0x71080, data, tail14] - [0x71084, .rodata, ov_SC06_013_jr_8015C32C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0x710a0, data, tail15] - [0x710b8, .rodata, ov_SC06_013_jr_8016AB6C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) diff --git a/config/splat.ov_SC06_014.yaml b/config/splat.ov_SC06_014.yaml index cae25766d..f31ea962f 100644 --- a/config/splat.ov_SC06_014.yaml +++ b/config/splat.ov_SC06_014.yaml @@ -145,7 +145,7 @@ segments: - [0x77a14, .rodata, ov_SC06_014_jr_8015A3C8] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0x77a30, data, tail13] - [0x77a34, .rodata, ov_SC06_014_jr_8015AE2C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - - [0x77a50, data, tail14] + - [0x77a70, data, tail14] - [0x77a74, .rodata, ov_SC06_014_jr_8015C32C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0x77a90, data, tail15] - [0x77aa8, .rodata, ov_SC06_014_jr_8016AB6C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) diff --git a/config/splat.ov_SC06_015.yaml b/config/splat.ov_SC06_015.yaml index 2666d5518..29be65aff 100644 --- a/config/splat.ov_SC06_015.yaml +++ b/config/splat.ov_SC06_015.yaml @@ -145,7 +145,7 @@ segments: - [0x6adf4, .rodata, ov_SC06_015_jr_8015A3C8] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0x6ae10, data, tail13] - [0x6ae14, .rodata, ov_SC06_015_jr_8015AE2C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - - [0x6ae30, data, tail14] + - [0x6ae50, data, tail14] - [0x6ae54, .rodata, ov_SC06_015_jr_8015C32C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0x6ae70, data, tail15] - [0x6ae88, .rodata, ov_SC06_015_jr_8016AB6C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) diff --git a/config/splat.ov_SC06_016.yaml b/config/splat.ov_SC06_016.yaml index 447c6eb1e..45fb8e69f 100644 --- a/config/splat.ov_SC06_016.yaml +++ b/config/splat.ov_SC06_016.yaml @@ -145,7 +145,7 @@ segments: - [0x75a3c, .rodata, ov_SC06_016_jr_8015A3C8] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0x75a58, data, tail13] - [0x75a5c, .rodata, ov_SC06_016_jr_8015AE2C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - - [0x75a78, data, tail14] + - [0x75a98, data, tail14] - [0x75a9c, .rodata, ov_SC06_016_jr_8015C32C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0x75ab8, data, tail15] - [0x75ad0, .rodata, ov_SC06_016_jr_8016AB6C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) diff --git a/config/splat.ov_SC06_018.yaml b/config/splat.ov_SC06_018.yaml index 54fc09da1..2e37f790a 100644 --- a/config/splat.ov_SC06_018.yaml +++ b/config/splat.ov_SC06_018.yaml @@ -146,7 +146,7 @@ segments: - [0xab2cc, .rodata, ov_SC06_018_jr_8015A3C8] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0xab2e8, data, tail13] - [0xab2ec, .rodata, ov_SC06_018_jr_8015AE2C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - - [0xab308, data, tail14] + - [0xab328, data, tail14] - [0xab32c, .rodata, ov_SC06_018_jr_8015C32C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0xab348, data, tail15] - [0xab360, .rodata, ov_SC06_018_jr_8016AB6C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) diff --git a/config/splat.ov_SC06_020.yaml b/config/splat.ov_SC06_020.yaml index 98c9fc6c3..955b131a9 100644 --- a/config/splat.ov_SC06_020.yaml +++ b/config/splat.ov_SC06_020.yaml @@ -145,7 +145,7 @@ segments: - [0x90bb4, .rodata, ov_SC06_020_jr_8015A3C8] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0x90bd0, data, tail13] - [0x90bd4, .rodata, ov_SC06_020_jr_8015AE2C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - - [0x90bf0, data, tail14] + - [0x90c10, data, tail14] - [0x90c14, .rodata, ov_SC06_020_jr_8015C32C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0x90c30, data, tail15] - [0x90c48, .rodata, ov_SC06_020_jr_8016AB6C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) diff --git a/config/splat.ov_SC06_022.yaml b/config/splat.ov_SC06_022.yaml index 0771bf35a..dc13de16d 100644 --- a/config/splat.ov_SC06_022.yaml +++ b/config/splat.ov_SC06_022.yaml @@ -145,7 +145,7 @@ segments: - [0xb83c4, .rodata, ov_SC06_022_jr_8015A3C8] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0xb83e0, data, tail13] - [0xb83e4, .rodata, ov_SC06_022_jr_8015AE2C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - - [0xb8400, data, tail14] + - [0xb8420, data, tail14] - [0xb8424, .rodata, ov_SC06_022_jr_8015C32C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0xb8440, data, tail15] - [0xb8458, .rodata, ov_SC06_022_jr_8016AB6C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) diff --git a/config/splat.ov_SC06_024.yaml b/config/splat.ov_SC06_024.yaml index ea2690341..1ab12c8c0 100644 --- a/config/splat.ov_SC06_024.yaml +++ b/config/splat.ov_SC06_024.yaml @@ -145,7 +145,7 @@ segments: - [0xb7508, .rodata, ov_SC06_024_jr_8015A3C8] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0xb7524, data, tail13] - [0xb7528, .rodata, ov_SC06_024_jr_8015AE2C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - - [0xb7544, data, tail14] + - [0xb7564, data, tail14] - [0xb7568, .rodata, ov_SC06_024_jr_8015C32C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0xb7584, data, tail15] - [0xb759c, .rodata, ov_SC06_024_jr_8016AB6C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) diff --git a/config/splat.ov_SC06_025.yaml b/config/splat.ov_SC06_025.yaml index 4b96fcb66..53249f543 100644 --- a/config/splat.ov_SC06_025.yaml +++ b/config/splat.ov_SC06_025.yaml @@ -145,7 +145,7 @@ segments: - [0x87828, .rodata, ov_SC06_025_jr_8015A3C8] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0x87844, data, tail13] - [0x87848, .rodata, ov_SC06_025_jr_8015AE2C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - - [0x87864, data, tail14] + - [0x87884, data, tail14] - [0x87888, .rodata, ov_SC06_025_jr_8015C32C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0x878a4, data, tail15] - [0x878bc, .rodata, ov_SC06_025_jr_8016AB6C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) diff --git a/config/splat.ov_SC06_027.yaml b/config/splat.ov_SC06_027.yaml index aa8d85703..7f918e846 100644 --- a/config/splat.ov_SC06_027.yaml +++ b/config/splat.ov_SC06_027.yaml @@ -145,7 +145,7 @@ segments: - [0x73864, .rodata, ov_SC06_027_jr_8015A3C8] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0x73880, data, tail13] - [0x73884, .rodata, ov_SC06_027_jr_8015AE2C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - - [0x738a0, data, tail14] + - [0x738c0, data, tail14] - [0x738c4, .rodata, ov_SC06_027_jr_8015C32C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0x738e0, data, tail15] - [0x738f8, .rodata, ov_SC06_027_jr_8016AB6C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) diff --git a/config/splat.ov_SC06_029.yaml b/config/splat.ov_SC06_029.yaml index ebd44c34c..a95aa966c 100644 --- a/config/splat.ov_SC06_029.yaml +++ b/config/splat.ov_SC06_029.yaml @@ -145,7 +145,7 @@ segments: - [0xb2ee0, .rodata, ov_SC06_029_jr_8015A3C8] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0xb2efc, data, tail13] - [0xb2f00, .rodata, ov_SC06_029_jr_8015AE2C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - - [0xb2f1c, data, tail14] + - [0xb2f3c, data, tail14] - [0xb2f40, .rodata, ov_SC06_029_jr_8015C32C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0xb2f5c, data, tail15] - [0xb2f74, .rodata, ov_SC06_029_jr_8016AB6C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) diff --git a/config/splat.ov_SC06_030.yaml b/config/splat.ov_SC06_030.yaml index f4c1221f2..92b9dbd32 100644 --- a/config/splat.ov_SC06_030.yaml +++ b/config/splat.ov_SC06_030.yaml @@ -145,7 +145,7 @@ segments: - [0x90244, .rodata, ov_SC06_030_jr_8015A3C8] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0x90260, data, tail13] - [0x90264, .rodata, ov_SC06_030_jr_8015AE2C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - - [0x90280, data, tail14] + - [0x902a0, data, tail14] - [0x902a4, .rodata, ov_SC06_030_jr_8015C32C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0x902c0, data, tail15] - [0x902d8, .rodata, ov_SC06_030_jr_8016AB6C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) diff --git a/config/splat.ov_SC06_032.yaml b/config/splat.ov_SC06_032.yaml index c6b8b953b..ca30e6c07 100644 --- a/config/splat.ov_SC06_032.yaml +++ b/config/splat.ov_SC06_032.yaml @@ -145,7 +145,7 @@ segments: - [0xa68a0, .rodata, ov_SC06_032_jr_8015A3C8] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0xa68bc, data, tail13] - [0xa68c0, .rodata, ov_SC06_032_jr_8015AE2C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - - [0xa68dc, data, tail14] + - [0xa68fc, data, tail14] - [0xa6900, .rodata, ov_SC06_032_jr_8015C32C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0xa691c, data, tail15] - [0xa6934, .rodata, ov_SC06_032_jr_8016AB6C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) diff --git a/config/splat.ov_SC06_033.yaml b/config/splat.ov_SC06_033.yaml index 39f849471..8280288a8 100644 --- a/config/splat.ov_SC06_033.yaml +++ b/config/splat.ov_SC06_033.yaml @@ -145,7 +145,7 @@ segments: - [0xa6954, .rodata, ov_SC06_033_jr_8015A3C8] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0xa6970, data, tail13] - [0xa6974, .rodata, ov_SC06_033_jr_8015AE2C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - - [0xa6990, data, tail14] + - [0xa69b0, data, tail14] - [0xa69b4, .rodata, ov_SC06_033_jr_8015C32C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0xa69d0, data, tail15] - [0xa69e8, .rodata, ov_SC06_033_jr_8016AB6C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) diff --git a/config/splat.ov_SC07_000.yaml b/config/splat.ov_SC07_000.yaml index c3bc5eae5..8334bb1e1 100644 --- a/config/splat.ov_SC07_000.yaml +++ b/config/splat.ov_SC07_000.yaml @@ -145,7 +145,7 @@ segments: - [0xa5fb0, .rodata, ov_SC07_000_jr_8015A3C8] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0xa5fcc, data, tail13] - [0xa5fd0, .rodata, ov_SC07_000_jr_8015AE2C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - - [0xa5fec, data, tail14] + - [0xa600c, data, tail14] - [0xa6010, .rodata, ov_SC07_000_jr_8015C32C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0xa602c, data, tail15] - [0xa6044, .rodata, ov_SC07_000_jr_8016AB6C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) diff --git a/config/splat.ov_SC07_001.yaml b/config/splat.ov_SC07_001.yaml index fd8720789..de9bbede3 100644 --- a/config/splat.ov_SC07_001.yaml +++ b/config/splat.ov_SC07_001.yaml @@ -145,7 +145,7 @@ segments: - [0x8114c, .rodata, ov_SC07_001_jr_8015A3C8] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0x81168, data, tail13] - [0x8116c, .rodata, ov_SC07_001_jr_8015AE2C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - - [0x81188, data, tail14] + - [0x811a8, data, tail14] - [0x811ac, .rodata, ov_SC07_001_jr_8015C32C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0x811c8, data, tail15] - [0x811e0, .rodata, ov_SC07_001_jr_8016AB6C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) diff --git a/config/splat.ov_SC07_002.yaml b/config/splat.ov_SC07_002.yaml index 5f516e96c..e8838c720 100644 --- a/config/splat.ov_SC07_002.yaml +++ b/config/splat.ov_SC07_002.yaml @@ -145,7 +145,7 @@ segments: - [0x71b34, .rodata, ov_SC07_002_jr_8015A3C8] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0x71b50, data, tail13] - [0x71b54, .rodata, ov_SC07_002_jr_8015AE2C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - - [0x71b70, data, tail14] + - [0x71b90, data, tail14] - [0x71b94, .rodata, ov_SC07_002_jr_8015C32C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0x71bb0, data, tail15] - [0x71bc8, .rodata, ov_SC07_002_jr_8016AB6C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) diff --git a/config/splat.ov_SC07_006.yaml b/config/splat.ov_SC07_006.yaml index 1ddda66b7..2ac440e03 100644 --- a/config/splat.ov_SC07_006.yaml +++ b/config/splat.ov_SC07_006.yaml @@ -102,6 +102,7 @@ segments: - [0x184b0, c, ov_SC07_006_jr_80140608] - [0x2cacc, c, ov_SC07_006_jr_80154C24] - [0x30774, c, ov_SC07_006_jr_801588CC] + - [0x337f8, c, ov_SC07_006_jr_8015B950] - [0x341d4, c, ov_SC07_006_jr_8015C32C] - [0x52cd4, c, ov_SC07_006_jr_8017AE2C] - [0x53d64, c, ov_SC07_006_jr_8017BEBC] @@ -124,13 +125,15 @@ segments: - [0xcc494, .rodata, ov_SC07_006_jr_80154C24] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0xcc4d8, .rodata, ov_SC07_006_jr_801588CC] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0xcc520, data, tail9] + - [0xcc5f8, .rodata, ov_SC07_006_jr_8015B950] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) + - [0xcc614, data, tail10] - [0xcc618, .rodata, ov_SC07_006_jr_8015C32C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - - [0xcc634, data, tail10] + - [0xcc634, data, tail11] - [0xccb40, .rodata, ov_SC07_006_jr_8017AE2C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0xccb54, .rodata, ov_SC07_006_jr_8017BEBC] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - - [0xccb74, data, tail11] + - [0xccb74, data, tail12] - [0xccb8c, .rodata, ov_SC07_006_jr_80183814] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - - [0xccbe0, data, tail12] + - [0xccbe0, data, tail13] - [0xCE214, bin, trailing] # final 3 bytes (EOF not 4-aligned; spimdisasm drops a partial word) - [0xCE217] # EOF marker = the 0.4.dec byte length # @TRAILING@ (above) is replaced by tools/new_overlay.sh: for a non-4-aligned overlay it becomes diff --git a/config/splat.ov_SC07_007.yaml b/config/splat.ov_SC07_007.yaml index f0368acc3..f0730d81e 100644 --- a/config/splat.ov_SC07_007.yaml +++ b/config/splat.ov_SC07_007.yaml @@ -102,6 +102,7 @@ segments: - [0x184b0, c, ov_SC07_007_jr_80140608] - [0x2cacc, c, ov_SC07_007_jr_80154C24] - [0x30774, c, ov_SC07_007_jr_801588CC] + - [0x337f8, c, ov_SC07_007_jr_8015B950] - [0x341d4, c, ov_SC07_007_jr_8015C32C] - [0x52cd4, c, ov_SC07_007_jr_8017AE2C] - [0x53d64, c, ov_SC07_007_jr_8017BEBC] @@ -123,11 +124,13 @@ segments: - [0x9dc70, .rodata, ov_SC07_007_jr_80154C24] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0x9dcb4, .rodata, ov_SC07_007_jr_801588CC] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0x9dcfc, data, tail9] + - [0x9ddd4, .rodata, ov_SC07_007_jr_8015B950] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) + - [0x9ddf0, data, tail10] - [0x9ddf4, .rodata, ov_SC07_007_jr_8015C32C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - - [0x9de10, data, tail10] + - [0x9de10, data, tail11] - [0x9e31c, .rodata, ov_SC07_007_jr_8017AE2C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0x9e330, .rodata, ov_SC07_007_jr_8017BEBC] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - - [0x9e350, data, tail11] + - [0x9e350, data, tail12] - [0x9F9DC, bin, trailing] # final 3 bytes (EOF not 4-aligned; spimdisasm drops a partial word) - [0x9F9DF] # EOF marker = the 0.4.dec byte length # @TRAILING@ (above) is replaced by tools/new_overlay.sh: for a non-4-aligned overlay it becomes diff --git a/config/splat.ov_SC07_008.yaml b/config/splat.ov_SC07_008.yaml index 71192abbc..e6ef1ea5f 100644 --- a/config/splat.ov_SC07_008.yaml +++ b/config/splat.ov_SC07_008.yaml @@ -145,7 +145,7 @@ segments: - [0x6cb84, .rodata, ov_SC07_008_jr_8015A3C8] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0x6cba0, data, tail13] - [0x6cba4, .rodata, ov_SC07_008_jr_8015AE2C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - - [0x6cbc0, data, tail14] + - [0x6cbe0, data, tail14] - [0x6cbe4, .rodata, ov_SC07_008_jr_8015C32C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0x6cc00, data, tail15] - [0x6cc18, .rodata, ov_SC07_008_jr_8016AB6C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) diff --git a/config/splat.ov_SC07_009.yaml b/config/splat.ov_SC07_009.yaml index e60b1a723..23f6f7d49 100644 --- a/config/splat.ov_SC07_009.yaml +++ b/config/splat.ov_SC07_009.yaml @@ -144,7 +144,7 @@ segments: - [0x7a210, .rodata, ov_SC07_009_jr_8015A3C8] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0x7a22c, data, tail13] - [0x7a230, .rodata, ov_SC07_009_jr_8015AE2C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - - [0x7a24c, data, tail14] + - [0x7a26c, data, tail14] - [0x7a270, .rodata, ov_SC07_009_jr_8015C32C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0x7a28c, data, tail15] - [0x7a2a4, .rodata, ov_SC07_009_jr_8016AB6C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) diff --git a/config/splat.ov_SC07_010.yaml b/config/splat.ov_SC07_010.yaml index acc847f49..e72f144c0 100644 --- a/config/splat.ov_SC07_010.yaml +++ b/config/splat.ov_SC07_010.yaml @@ -104,6 +104,7 @@ segments: - [0x184b0, c, ov_SC07_010_jr_80140608] - [0x2cacc, c, ov_SC07_010_jr_80154C24] - [0x30774, c, ov_SC07_010_jr_801588CC] + - [0x337f8, c, ov_SC07_010_jr_8015B950] - [0x341d4, c, ov_SC07_010_jr_8015C32C] - [0x52cd4, c, ov_SC07_010_jr_8017AE2C] - [0x59e1c, data, tail] @@ -124,10 +125,12 @@ segments: - [0x7e150, .rodata, ov_SC07_010_jr_80154C24] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0x7e194, .rodata, ov_SC07_010_jr_801588CC] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0x7e1dc, data, tail9] + - [0x7e2b4, .rodata, ov_SC07_010_jr_8015B950] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) + - [0x7e2d0, data, tail10] - [0x7e2d4, .rodata, ov_SC07_010_jr_8015C32C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - - [0x7e2f0, data, tail10] + - [0x7e2f0, data, tail11] - [0x7e7fc, .rodata, ov_SC07_010_jr_8017AE2C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - - [0x7e810, data, tail11] + - [0x7e810, data, tail12] - [0x813EC, bin, trailing] # final 3 bytes (EOF not 4-aligned; spimdisasm drops a partial word) - [0x813EF] # EOF marker = the 0.4.dec byte length # @TRAILING@ (above) is replaced by tools/new_overlay.sh: for a non-4-aligned overlay it becomes diff --git a/config/splat.ov_SC07_011.yaml b/config/splat.ov_SC07_011.yaml index b56ba79d4..fbfc29cb0 100644 --- a/config/splat.ov_SC07_011.yaml +++ b/config/splat.ov_SC07_011.yaml @@ -102,6 +102,7 @@ segments: - [0x184b0, c, ov_SC07_011_jr_80140608] - [0x2cacc, c, ov_SC07_011_jr_80154C24] - [0x30774, c, ov_SC07_011_jr_801588CC] + - [0x337f8, c, ov_SC07_011_jr_8015B950] - [0x341d4, c, ov_SC07_011_jr_8015C32C] - [0x52cd4, c, ov_SC07_011_jr_8017AE2C] - [0x53d64, c, ov_SC07_011_jr_8017BEBC] @@ -123,11 +124,13 @@ segments: - [0x66818, .rodata, ov_SC07_011_jr_80154C24] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0x6685c, .rodata, ov_SC07_011_jr_801588CC] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0x668a4, data, tail9] + - [0x6697c, .rodata, ov_SC07_011_jr_8015B950] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) + - [0x66998, data, tail10] - [0x6699c, .rodata, ov_SC07_011_jr_8015C32C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - - [0x669b8, data, tail10] + - [0x669b8, data, tail11] - [0x66ec4, .rodata, ov_SC07_011_jr_8017AE2C] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - [0x66ed8, .rodata, ov_SC07_011_jr_8017BEBC] # Phase-26 §8 jtbl-rodata carve (jtbl_carve.py) - - [0x66ef8, data, tail11] + - [0x66ef8, data, tail12] - [0x683A4, bin, trailing] # final 3 bytes (EOF not 4-aligned; spimdisasm drops a partial word) - [0x683A7] # EOF marker = the 0.4.dec byte length # @TRAILING@ (above) is replaced by tools/new_overlay.sh: for a non-4-aligned overlay it becomes diff --git a/docs/family-hseq.md b/docs/family-hseq.md index 84d5d62dd..6187b3d29 100644 --- a/docs/family-hseq.md +++ b/docs/family-hseq.md @@ -2,11 +2,11 @@ > Generated by `tools/family_hseq.py` from the 138 overlay sigs + per-overlay src stubs. Ranked by TEMPLATABLE byte-weight (PURE+IMM members × nins × 4). The byte-gate is the arbiter. -**Fleet (overlays):** 89.8% fn / 82.3% instr / 70.0% distinct-code matched. Unmatched: 35,728 instances / 2,320,807 ins (22,242 distinct classes). +**Fleet (overlays):** 89.9% fn / 82.4% instr / 70.3% distinct-code matched. Unmatched: 35,589 instances / 2,303,326 ins (22,110 distinct classes). -**Tail cross-check (Phase-25 close):** 21,830 tail fns / 1,054,519 ins → 567 h_seq families ≥2, **154 substantial (nins≥80) / 584,841 ins**. +**Tail cross-check (Phase-25 close):** 21,691 tail fns / 1,037,913 ins → 566 h_seq families ≥2, **153 substantial (nins≥80) / 568,235 ins**. -**Full frontier (all unmatched by h_seq):** 2670 target families (≥2 members or a matched sibling) + 3771 singletons (Step-D residue). Substantial: **526 families / 1,152,469 templatable ins**, 62 with a matched sibling (zero-crack). Substantial member classes: 6,500 PURE · 40 IMM · 6 STRUCT-excluded. +**Full frontier (all unmatched by h_seq):** 2669 target families (≥2 members or a matched sibling) + 3771 singletons (Step-D residue). Substantial: **525 families / 1,134,988 templatable ins**, 63 with a matched sibling (zero-crack). Substantial member classes: 6,361 PURE · 40 IMM · 6 STRUCT-excluded. ## Top substantial families (by templatable byte-weight) @@ -19,7 +19,7 @@ | 4 | 304 | 138 (138/0/0) | 1/138 | per-location | PURE | 0 | · | 0x8014d820 draft-ov077 | 41,952 | | 5 | 289 | 138 (138/0/0) | 1/138 | per-location | PURE | 0 | Y | 0x80135eb0 draft-ov077 | 39,882 | | 6 | 272 | 138 (138/0/0) | 1/138 | per-location | PURE | 0 | Y | 0x8013b83c draft-ov077 | 37,536 | -| 7 | 271 | 138 (138/0/0) | 1/138 | per-location | PURE | 0 | Y | 0x8015b950 draft-ov077 | 37,398 | +| 7 | 271 | 137 (137/0/0) | 1/137 | per-location | PURE | 1 | Y | 0x8015b950 matched-ov077 | 37,127 | | 8 | 260 | 138 (138/0/0) | 1/138 | per-location | PURE | 0 | · | 0x80140958 draft-ov077 | 35,880 | | 9 | 231 | 138 (138/0/0) | 1/138 | per-location | PURE | 0 | · | 0x80175da8 draft-ov077 | 31,878 | | 10 | 198 | 138 (138/0/0) | 1/138 | per-location | PURE | 0 | Y | 0x8013bd74 draft-ov077 | 27,324 | @@ -32,34 +32,34 @@ | 17 | 147 | 138 (138/0/0) | 1/138 | per-location | PURE | 0 | · | 0x80177b5c draft-ov077 | 20,286 | | 18 | 136 | 138 (138/0/0) | 1/138 | per-location | PURE | 0 | Y | 0x80135260 draft-ov077 | 18,768 | | 19 | 137 | 132 (132/0/0) | 1/132 | per-location | PURE | 6 | · | 0x80133ab0 matched-ov077 | 18,084 | -| 20 | 125 | 137 (137/0/0) | 1/137 | per-location | PURE | 1 | Y | 0x8012aaac matched-ov077 | 17,125 | -| 21 | 114 | 138 (138/0/0) | 1/138 | per-location | PURE | 0 | · | 0x8015d1b8 draft-ov077 | 15,732 | -| 22 | 111 | 138 (138/0/0) | 1/138 | per-location | PURE | 0 | Y | 0x80179b74 draft-ov077 | 15,318 | -| 23 | 110 | 138 (138/0/0) | 1/138 | per-location | PURE | 0 | · | 0x801330e0 draft-ov077 | 15,180 | -| 24 | 947 | 16 (16/0/0) | 6/16 | cross-address | PURE | 0 | Y | 0x8017c974 draft-ov077 | 15,152 | -| 25 | 94 | 137 (137/0/0) | 1/137 | per-location | PURE | 1 | · | 0x8016b6bc matched-ov077 | 12,878 | -| 26 | 91 | 138 (138/0/0) | 1/138 | per-location | PURE | 0 | Y | 0x801789ac draft-ov077 | 12,558 | -| 27 | 952 | 13 (7/6/0) | 5/13 | cross-address | IMM | 103 | Y | 0x8017bebc matched | 12,376 | -| 28 | 88 | 138 (138/0/0) | 1/138 | per-location | PURE | 0 | · | 0x8016ec0c draft-ov077 | 12,144 | -| 29 | 85 | 138 (138/0/0) | 1/138 | per-location | PURE | 0 | Y | 0x8016ae5c draft-ov077 | 11,730 | -| 30 | 82 | 137 (137/0/0) | 1/137 | per-location | PURE | 1 | · | 0x8014cf04 matched | 11,234 | -| 31 | 80 | 136 (136/0/0) | 1/136 | per-location | PURE | 2 | · | 0x80143d28 matched-ov077 | 10,880 | -| 32 | 195 | 36 (36/0/0) | 11/36 | scattered | PURE | 0 | · | 0x8017c218 modal | 7,020 | -| 33 | 299 | 20 (20/0/0) | 20/20 | scattered | PURE | 0 | Y | 0x8017fee0 modal | 5,980 | -| 34 | 227 | 26 (26/0/0) | 10/26 | scattered | PURE | 0 | · | 0x8017bfec modal | 5,902 | -| 35 | 236 | 20 (20/0/0) | 20/20 | scattered | PURE | 0 | · | 0x80180520 modal | 4,720 | -| 36 | 158 | 26 (26/0/0) | 10/26 | scattered | PURE | 0 | · | 0x8017c378 modal | 4,108 | -| 37 | 793 | 5 (5/0/0) | 2/5 | cross-address | PURE | 0 | · | 0x8017d174 modal | 3,965 | -| 38 | 246 | 16 (16/0/0) | 6/16 | cross-address | PURE | 0 | · | 0x8017c294 draft-ov077 | 3,936 | -| 39 | 766 | 5 (5/0/0) | 3/5 | cross-address | PURE | 0 | · | 0x8017df84 modal | 3,830 | -| 40 | 328 | 11 (11/0/0) | 11/11 | scattered | PURE | 0 | · | 0x801833f0 modal | 3,608 | -| 41 | 890 | 4 (4/0/0) | 1/4 | per-location | PURE | 134 | Y | 0x80178d40 matched-ov077 | 3,560 | -| 42 | 237 | 15 (15/0/0) | 15/15 | scattered | PURE | 0 | · | 0x801832a8 modal | 3,555 | -| 43 | 253 | 14 (14/0/0) | 10/14 | scattered | PURE | 0 | · | 0x8017c9bc modal | 3,542 | -| 44 | 491 | 7 (7/0/0) | 6/7 | cross-address | PURE | 0 | Y | 0x801863cc modal | 3,437 | -| 45 | 166 | 20 (20/0/0) | 20/20 | scattered | PURE | 0 | · | 0x8017fac0 modal | 3,320 | -| 46 | 92 | 36 (36/0/0) | 11/36 | scattered | PURE | 0 | · | 0x8017c910 modal | 3,312 | -| 47 | 90 | 36 (36/0/0) | 11/36 | scattered | PURE | 0 | · | 0x8017c064 modal | 3,240 | -| 48 | 293 | 11 (11/0/0) | 4/11 | cross-address | PURE | 0 | · | 0x8017c43c modal | 3,223 | -| 49 | 770 | 4 (4/0/0) | 1/4 | per-location | PURE | 134 | · | 0x80144b9c matched-ov077 | 3,080 | -| 50 | 611 | 5 (5/0/0) | 4/5 | cross-address | PURE | 0 | · | 0x80186e24 modal | 3,055 | +| 20 | 114 | 138 (138/0/0) | 1/138 | per-location | PURE | 0 | · | 0x8015d1b8 draft-ov077 | 15,732 | +| 21 | 111 | 138 (138/0/0) | 1/138 | per-location | PURE | 0 | Y | 0x80179b74 draft-ov077 | 15,318 | +| 22 | 110 | 138 (138/0/0) | 1/138 | per-location | PURE | 0 | · | 0x801330e0 draft-ov077 | 15,180 | +| 23 | 947 | 16 (16/0/0) | 6/16 | cross-address | PURE | 0 | Y | 0x8017c974 draft-ov077 | 15,152 | +| 24 | 94 | 137 (137/0/0) | 1/137 | per-location | PURE | 1 | · | 0x8016b6bc matched-ov077 | 12,878 | +| 25 | 91 | 138 (138/0/0) | 1/138 | per-location | PURE | 0 | Y | 0x801789ac draft-ov077 | 12,558 | +| 26 | 952 | 13 (7/6/0) | 5/13 | cross-address | IMM | 103 | Y | 0x8017bebc matched | 12,376 | +| 27 | 88 | 138 (138/0/0) | 1/138 | per-location | PURE | 0 | · | 0x8016ec0c draft-ov077 | 12,144 | +| 28 | 85 | 137 (137/0/0) | 1/137 | per-location | PURE | 1 | Y | 0x8016ae5c matched-ov077 | 11,645 | +| 29 | 82 | 137 (137/0/0) | 1/137 | per-location | PURE | 1 | · | 0x8014cf04 matched | 11,234 | +| 30 | 80 | 136 (136/0/0) | 1/136 | per-location | PURE | 2 | · | 0x80143d28 matched-ov077 | 10,880 | +| 31 | 195 | 36 (36/0/0) | 11/36 | scattered | PURE | 0 | · | 0x8017c218 modal | 7,020 | +| 32 | 299 | 20 (20/0/0) | 20/20 | scattered | PURE | 0 | Y | 0x8017fee0 modal | 5,980 | +| 33 | 227 | 26 (26/0/0) | 10/26 | scattered | PURE | 0 | · | 0x8017bfec modal | 5,902 | +| 34 | 236 | 20 (20/0/0) | 20/20 | scattered | PURE | 0 | · | 0x80180520 modal | 4,720 | +| 35 | 158 | 26 (26/0/0) | 10/26 | scattered | PURE | 0 | · | 0x8017c378 modal | 4,108 | +| 36 | 793 | 5 (5/0/0) | 2/5 | cross-address | PURE | 0 | · | 0x8017d174 modal | 3,965 | +| 37 | 246 | 16 (16/0/0) | 6/16 | cross-address | PURE | 0 | · | 0x8017c294 draft-ov077 | 3,936 | +| 38 | 766 | 5 (5/0/0) | 3/5 | cross-address | PURE | 0 | · | 0x8017df84 modal | 3,830 | +| 39 | 328 | 11 (11/0/0) | 11/11 | scattered | PURE | 0 | · | 0x801833f0 modal | 3,608 | +| 40 | 890 | 4 (4/0/0) | 1/4 | per-location | PURE | 134 | Y | 0x80178d40 matched-ov077 | 3,560 | +| 41 | 237 | 15 (15/0/0) | 15/15 | scattered | PURE | 0 | · | 0x801832a8 modal | 3,555 | +| 42 | 253 | 14 (14/0/0) | 10/14 | scattered | PURE | 0 | · | 0x8017c9bc modal | 3,542 | +| 43 | 491 | 7 (7/0/0) | 6/7 | cross-address | PURE | 0 | Y | 0x801863cc modal | 3,437 | +| 44 | 166 | 20 (20/0/0) | 20/20 | scattered | PURE | 0 | · | 0x8017fac0 modal | 3,320 | +| 45 | 92 | 36 (36/0/0) | 11/36 | scattered | PURE | 0 | · | 0x8017c910 modal | 3,312 | +| 46 | 90 | 36 (36/0/0) | 11/36 | scattered | PURE | 0 | · | 0x8017c064 modal | 3,240 | +| 47 | 293 | 11 (11/0/0) | 4/11 | cross-address | PURE | 0 | · | 0x8017c43c modal | 3,223 | +| 48 | 770 | 4 (4/0/0) | 1/4 | per-location | PURE | 134 | · | 0x80144b9c matched-ov077 | 3,080 | +| 49 | 611 | 5 (5/0/0) | 4/5 | cross-address | PURE | 0 | · | 0x80186e24 modal | 3,055 | +| 50 | 493 | 6 (6/0/0) | 1/6 | per-location | PURE | 132 | Y | 0x8015a3c8 matched-ov077 | 2,958 | diff --git a/docs/progress.fleet.md b/docs/progress.fleet.md index e965a5a24..8c61830dd 100644 --- a/docs/progress.fleet.md +++ b/docs/progress.fleet.md @@ -4,157 +4,157 @@ # cross-binary collapsible-byte leverage: docs/duplicates.cross.md. # THREE progress metrics (all matter — see the labels): -FLEET fn-count byte-ident: 317076 / 353720 = 89.64% (REAL+LINKED+empties; FUNCTION-count, ×134-inflated — one crack counts per overlay) -FLEET instr-weighted : 10777034 / 13141652 = 82.0% (shipped .text across main + resident + 138 overlays; the decomp.dev-DISPLAY number) -FLEET distinct-code(uniq): 3919258 / 5634875 = 69.6% (65335/87459 unique fns; the DISTINCT-RE number) +FLEET fn-count byte-ident: 317213 / 353720 = 89.68% (REAL+LINKED+empties; FUNCTION-count, ×134-inflated — one crack counts per overlay) +FLEET instr-weighted : 10814161 / 13141652 = 82.3% (shipped .text across main + resident + 138 overlays; the decomp.dev-DISPLAY number) +FLEET distinct-code(uniq): 3954488 / 5634875 = 70.2% (65465/87459 unique fns; the DISTINCT-RE number) MAIN game-code weighted : 436 / 60201 = 0.7% (INCLUDED in the fleet numbers above since 2026-07-22 — roadmap §1 metrics contract; LINKED-excluding Ghidra sig dated 2026-06-14; caveat is R34: no independent second oracle for a PS-X EXE, NOT drift) - (fleet EXCLUDING main, for continuity with pre-2026-07-22 readings: 10776598 / 13081451 = 82.4%) + (fleet EXCLUDING main, for continuity with pre-2026-07-22 readings: 10813725 / 13081451 = 82.7%) -FLEET REAL substantive : 315221 (of which dedup-shared 239530 via 1886 groups / 239604 instances) +FLEET REAL substantive : 315358 (of which dedup-shared 239530 via 1886 groups / 239604 instances) FLEET LINKED PsyQ objs : 959 FLEET NON_MATCHING : 7 (0 in any default build — G4) -FLEET INCLUDE_ASM stubs : 36637 +FLEET INCLUDE_ASM stubs : 36500 FLEET matchable : 353720 | binary | REAL | shared | LINKED | byte-ident | matchable | byte-ident % | |---|---:|---:|---:|---:|---:|---:| | main | 54 | 2 | 959 | 1055 | 2096 | 50.3% | | resident | 129 | 0 | 0 | 131 | 145 | 90.3% | -| ov_SC01_000 | 2258 | 1742 | 0 | 2258 | 2403 | 94.0% | -| ov_SC01_001 | 2263 | 1743 | 0 | 2265 | 2466 | 91.8% | -| ov_SC01_004 | 2253 | 1734 | 0 | 2254 | 2414 | 93.4% | -| ov_SC01_005 | 2283 | 1757 | 0 | 2283 | 2503 | 91.2% | -| ov_SC01_006 | 2283 | 1757 | 0 | 2283 | 2503 | 91.2% | -| ov_SC01_008 | 2253 | 1734 | 0 | 2255 | 2426 | 93.0% | -| ov_SC01_009 | 2279 | 1735 | 0 | 2280 | 2507 | 90.9% | -| ov_SC01_074 | 2257 | 1735 | 0 | 2259 | 2425 | 93.2% | +| ov_SC01_000 | 2259 | 1742 | 0 | 2259 | 2403 | 94.0% | +| ov_SC01_001 | 2264 | 1743 | 0 | 2266 | 2466 | 91.9% | +| ov_SC01_004 | 2254 | 1734 | 0 | 2255 | 2414 | 93.4% | +| ov_SC01_005 | 2284 | 1757 | 0 | 2284 | 2503 | 91.3% | +| ov_SC01_006 | 2284 | 1757 | 0 | 2284 | 2503 | 91.3% | +| ov_SC01_008 | 2254 | 1734 | 0 | 2256 | 2426 | 93.0% | +| ov_SC01_009 | 2280 | 1735 | 0 | 2281 | 2507 | 91.0% | +| ov_SC01_074 | 2258 | 1735 | 0 | 2260 | 2425 | 93.2% | | ov_SC01_077 | 2439 | 1702 | 0 | 2441 | 2585 | 94.4% | -| ov_SC01_080 | 2295 | 1738 | 0 | 2295 | 2512 | 91.4% | -| ov_SC01_084 | 2302 | 1738 | 0 | 2307 | 2579 | 89.5% | -| ov_SC02_000 | 2355 | 1773 | 0 | 2355 | 2683 | 87.8% | -| ov_SC02_003 | 2355 | 1773 | 0 | 2355 | 2683 | 87.8% | -| ov_SC02_004 | 2261 | 1738 | 0 | 2261 | 2401 | 94.2% | -| ov_SC02_005 | 2369 | 1734 | 0 | 2379 | 2927 | 81.3% | -| ov_SC02_011 | 2382 | 1741 | 0 | 2393 | 2893 | 82.7% | -| ov_SC02_015 | 2263 | 1740 | 0 | 2263 | 2414 | 93.7% | -| ov_SC02_016 | 2297 | 1740 | 0 | 2300 | 2545 | 90.4% | -| ov_SC02_017 | 2340 | 1740 | 0 | 2348 | 2732 | 85.9% | -| ov_SC02_021 | 2269 | 1740 | 0 | 2269 | 2437 | 93.1% | -| ov_SC02_026 | 2284 | 1738 | 0 | 2290 | 2572 | 89.0% | -| ov_SC02_027 | 2307 | 1738 | 0 | 2316 | 2692 | 86.0% | -| ov_SC02_028 | 2309 | 1738 | 0 | 2319 | 2701 | 85.9% | -| ov_SC02_031 | 2295 | 1739 | 0 | 2300 | 2562 | 89.8% | -| ov_SC02_035 | 2270 | 1738 | 0 | 2273 | 2520 | 90.2% | -| ov_SC02_039 | 2254 | 1738 | 0 | 2254 | 2416 | 93.3% | -| ov_SC02_041 | 2292 | 1738 | 0 | 2295 | 2561 | 89.6% | -| ov_SC03_001 | 2389 | 1739 | 0 | 2406 | 2869 | 83.9% | -| ov_SC03_002 | 2315 | 1743 | 0 | 2330 | 2631 | 88.6% | -| ov_SC03_003 | 2264 | 1738 | 0 | 2265 | 2423 | 93.5% | -| ov_SC03_006 | 2331 | 1744 | 0 | 2340 | 2767 | 84.6% | -| ov_SC03_007 | 2309 | 1738 | 0 | 2313 | 2623 | 88.2% | -| ov_SC03_010 | 2272 | 1738 | 0 | 2272 | 2471 | 91.9% | -| ov_SC03_011 | 2278 | 1738 | 0 | 2284 | 2527 | 90.4% | -| ov_SC03_012 | 2256 | 1738 | 0 | 2257 | 2406 | 93.8% | -| ov_SC03_013 | 2277 | 1738 | 0 | 2277 | 2493 | 91.3% | -| ov_SC03_014 | 2335 | 1763 | 0 | 2335 | 2685 | 87.0% | -| ov_SC03_015 | 2335 | 1763 | 0 | 2335 | 2685 | 87.0% | -| ov_SC03_023 | 2263 | 1738 | 0 | 2264 | 2435 | 93.0% | -| ov_SC03_024 | 2323 | 1743 | 0 | 2330 | 2641 | 88.2% | -| ov_SC03_028 | 2303 | 1738 | 0 | 2307 | 2664 | 86.6% | -| ov_SC03_029 | 2305 | 1740 | 0 | 2315 | 2644 | 87.6% | -| ov_SC03_030 | 2278 | 1743 | 0 | 2280 | 2495 | 91.4% | -| ov_SC03_031 | 2274 | 1738 | 0 | 2277 | 2514 | 90.6% | -| ov_SC03_089 | 2291 | 1738 | 0 | 2298 | 2581 | 89.0% | -| ov_SC03_090 | 2292 | 1738 | 0 | 2300 | 2625 | 87.6% | -| ov_SC03_091 | 2295 | 1738 | 0 | 2303 | 2640 | 87.2% | -| ov_SC03_092 | 2305 | 1738 | 0 | 2317 | 2587 | 89.6% | -| ov_SC03_093 | 2281 | 1738 | 0 | 2285 | 2563 | 89.2% | -| ov_SC03_094 | 2276 | 1738 | 0 | 2282 | 2577 | 88.6% | -| ov_SC03_095 | 2266 | 1738 | 0 | 2269 | 2474 | 91.7% | -| ov_SC03_096 | 2266 | 1738 | 0 | 2269 | 2465 | 92.0% | -| ov_SC03_097 | 2296 | 1738 | 0 | 2303 | 2603 | 88.5% | -| ov_SC03_098 | 2274 | 1738 | 0 | 2277 | 2541 | 89.6% | -| ov_SC03_099 | 2267 | 1738 | 0 | 2270 | 2504 | 90.7% | -| ov_SC03_100 | 2277 | 1738 | 0 | 2281 | 2539 | 89.8% | -| ov_SC03_101 | 2277 | 1738 | 0 | 2281 | 2528 | 90.2% | -| ov_SC03_102 | 2270 | 1738 | 0 | 2273 | 2492 | 91.2% | -| ov_SC03_103 | 2273 | 1740 | 0 | 2276 | 2510 | 90.7% | -| ov_SC03_104 | 2299 | 1738 | 0 | 2306 | 2616 | 88.1% | -| ov_SC03_105 | 2290 | 1738 | 0 | 2297 | 2597 | 88.4% | -| ov_SC03_108 | 2258 | 1738 | 0 | 2258 | 2443 | 92.4% | -| ov_SC03_109 | 2261 | 1738 | 0 | 2263 | 2424 | 93.4% | -| ov_SC03_110 | 2265 | 1738 | 0 | 2265 | 2468 | 91.8% | -| ov_SC03_111 | 2276 | 1738 | 0 | 2279 | 2510 | 90.8% | -| ov_SC03_112 | 2272 | 1740 | 0 | 2274 | 2526 | 90.0% | -| ov_SC03_113 | 2265 | 1740 | 0 | 2268 | 2468 | 91.9% | -| ov_SC03_114 | 2254 | 1738 | 0 | 2256 | 2415 | 93.4% | -| ov_SC03_115 | 2271 | 1738 | 0 | 2273 | 2472 | 91.9% | -| ov_SC03_116 | 2262 | 1738 | 0 | 2265 | 2438 | 92.9% | -| ov_SC03_117 | 2289 | 1738 | 0 | 2295 | 2557 | 89.8% | -| ov_SC03_118 | 2335 | 1762 | 0 | 2336 | 2685 | 87.0% | -| ov_SC03_119 | 2334 | 1762 | 0 | 2335 | 2685 | 87.0% | -| ov_SC03_121 | 2269 | 1738 | 0 | 2272 | 2459 | 92.4% | -| ov_SC03_124 | 2347 | 1734 | 0 | 2367 | 2741 | 86.4% | -| ov_SC03_125 | 2303 | 1738 | 0 | 2315 | 2588 | 89.5% | -| ov_SC03_126 | 2266 | 1740 | 0 | 2266 | 2423 | 93.5% | -| ov_SC04_000 | 2282 | 1742 | 0 | 2291 | 2546 | 90.0% | -| ov_SC04_002 | 2301 | 1738 | 0 | 2305 | 2636 | 87.4% | -| ov_SC04_003 | 2277 | 1738 | 0 | 2281 | 2502 | 91.2% | -| ov_SC04_004 | 2286 | 1738 | 0 | 2288 | 2558 | 89.4% | -| ov_SC04_005 | 2296 | 1738 | 0 | 2302 | 2612 | 88.1% | -| ov_SC04_006 | 2266 | 1738 | 0 | 2268 | 2454 | 92.4% | -| ov_SC04_007 | 2290 | 1738 | 0 | 2294 | 2569 | 89.3% | -| ov_SC04_008 | 2258 | 1738 | 0 | 2258 | 2415 | 93.5% | -| ov_SC04_009 | 2273 | 1738 | 0 | 2276 | 2441 | 93.2% | -| ov_SC04_010 | 2263 | 1738 | 0 | 2264 | 2419 | 93.6% | -| ov_SC04_011 | 2321 | 1738 | 0 | 2327 | 2803 | 83.0% | -| ov_SC04_012 | 2260 | 1738 | 0 | 2261 | 2420 | 93.4% | -| ov_SC04_015 | 2325 | 1739 | 0 | 2336 | 2611 | 89.5% | -| ov_SC04_016 | 2263 | 1738 | 0 | 2265 | 2440 | 92.8% | -| ov_SC04_018 | 2373 | 1773 | 0 | 2373 | 2857 | 83.1% | -| ov_SC04_019 | 2379 | 1773 | 0 | 2379 | 2857 | 83.3% | -| ov_SC04_020 | 2290 | 1738 | 0 | 2302 | 2567 | 89.7% | -| ov_SC04_021 | 2267 | 1740 | 0 | 2267 | 2423 | 93.6% | -| ov_SC05_000 | 2264 | 1742 | 0 | 2267 | 2422 | 93.6% | -| ov_SC05_001 | 2286 | 1738 | 0 | 2291 | 2574 | 89.0% | -| ov_SC05_002 | 2269 | 1738 | 0 | 2272 | 2442 | 93.0% | -| ov_SC05_003 | 2266 | 1738 | 0 | 2267 | 2481 | 91.4% | -| ov_SC05_004 | 2262 | 1738 | 0 | 2264 | 2464 | 91.9% | -| ov_SC05_005 | 2267 | 1738 | 0 | 2268 | 2491 | 91.0% | -| ov_SC05_006 | 2260 | 1738 | 0 | 2260 | 2430 | 93.0% | -| ov_SC05_007 | 2270 | 1738 | 0 | 2275 | 2482 | 91.7% | -| ov_SC05_008 | 2287 | 1738 | 0 | 2289 | 2543 | 90.0% | -| ov_SC05_009 | 2266 | 1738 | 0 | 2270 | 2438 | 93.1% | -| ov_SC05_010 | 2293 | 1738 | 0 | 2297 | 2588 | 88.8% | -| ov_SC05_011 | 2262 | 1738 | 0 | 2263 | 2409 | 93.9% | -| ov_SC05_017 | 2369 | 1735 | 0 | 2380 | 2842 | 83.7% | -| ov_SC05_018 | 2316 | 1738 | 0 | 2329 | 2673 | 87.1% | -| ov_SC05_019 | 2267 | 1740 | 0 | 2267 | 2423 | 93.6% | -| ov_SC06_000 | 2331 | 1747 | 0 | 2334 | 2691 | 86.7% | -| ov_SC06_006 | 2283 | 1738 | 0 | 2284 | 2511 | 91.0% | -| ov_SC06_008 | 2303 | 1740 | 0 | 2309 | 2542 | 90.8% | -| ov_SC06_010 | 2283 | 1738 | 0 | 2288 | 2517 | 90.9% | -| ov_SC06_011 | 2271 | 1738 | 0 | 2275 | 2468 | 92.2% | -| ov_SC06_013 | 2265 | 1738 | 0 | 2266 | 2425 | 93.4% | -| ov_SC06_014 | 2271 | 1738 | 0 | 2273 | 2453 | 92.7% | -| ov_SC06_015 | 2268 | 1738 | 0 | 2268 | 2421 | 93.7% | -| ov_SC06_016 | 2286 | 1738 | 0 | 2288 | 2549 | 89.8% | -| ov_SC06_018 | 2297 | 1740 | 0 | 2304 | 2665 | 86.5% | -| ov_SC06_020 | 2275 | 1740 | 0 | 2276 | 2518 | 90.4% | -| ov_SC06_022 | 2294 | 1738 | 0 | 2302 | 2642 | 87.1% | -| ov_SC06_024 | 2304 | 1738 | 0 | 2310 | 2667 | 86.6% | -| ov_SC06_025 | 2288 | 1738 | 0 | 2293 | 2572 | 89.2% | -| ov_SC06_027 | 2253 | 1738 | 0 | 2254 | 2408 | 93.6% | -| ov_SC06_029 | 2314 | 1738 | 0 | 2326 | 2662 | 87.4% | -| ov_SC06_030 | 2267 | 1738 | 0 | 2267 | 2456 | 92.3% | -| ov_SC06_032 | 2289 | 1739 | 0 | 2296 | 2658 | 86.4% | -| ov_SC06_033 | 2291 | 1739 | 0 | 2298 | 2631 | 87.3% | -| ov_SC07_000 | 2282 | 1742 | 0 | 2284 | 2521 | 90.6% | -| ov_SC07_001 | 2266 | 1738 | 0 | 2268 | 2454 | 92.4% | -| ov_SC07_002 | 2294 | 1738 | 0 | 2298 | 2579 | 89.1% | -| ov_SC07_006 | 2067 | 1555 | 0 | 2147 | 2456 | 87.4% | -| ov_SC07_007 | 2061 | 1586 | 0 | 2145 | 2613 | 82.1% | -| ov_SC07_008 | 2251 | 1738 | 0 | 2251 | 2386 | 94.3% | -| ov_SC07_009 | 2260 | 1738 | 0 | 2262 | 2430 | 93.1% | -| ov_SC07_010 | 2093 | 1608 | 0 | 2176 | 2524 | 86.2% | -| ov_SC07_011 | 2061 | 1585 | 0 | 2141 | 2449 | 87.4% | +| ov_SC01_080 | 2296 | 1738 | 0 | 2296 | 2512 | 91.4% | +| ov_SC01_084 | 2303 | 1738 | 0 | 2308 | 2579 | 89.5% | +| ov_SC02_000 | 2356 | 1773 | 0 | 2356 | 2683 | 87.8% | +| ov_SC02_003 | 2356 | 1773 | 0 | 2356 | 2683 | 87.8% | +| ov_SC02_004 | 2262 | 1738 | 0 | 2262 | 2401 | 94.2% | +| ov_SC02_005 | 2370 | 1734 | 0 | 2380 | 2927 | 81.3% | +| ov_SC02_011 | 2383 | 1741 | 0 | 2394 | 2893 | 82.8% | +| ov_SC02_015 | 2264 | 1740 | 0 | 2264 | 2414 | 93.8% | +| ov_SC02_016 | 2298 | 1740 | 0 | 2301 | 2545 | 90.4% | +| ov_SC02_017 | 2341 | 1740 | 0 | 2349 | 2732 | 86.0% | +| ov_SC02_021 | 2270 | 1740 | 0 | 2270 | 2437 | 93.1% | +| ov_SC02_026 | 2285 | 1738 | 0 | 2291 | 2572 | 89.1% | +| ov_SC02_027 | 2308 | 1738 | 0 | 2317 | 2692 | 86.1% | +| ov_SC02_028 | 2310 | 1738 | 0 | 2320 | 2701 | 85.9% | +| ov_SC02_031 | 2296 | 1739 | 0 | 2301 | 2562 | 89.8% | +| ov_SC02_035 | 2271 | 1738 | 0 | 2274 | 2520 | 90.2% | +| ov_SC02_039 | 2255 | 1738 | 0 | 2255 | 2416 | 93.3% | +| ov_SC02_041 | 2293 | 1738 | 0 | 2296 | 2561 | 89.7% | +| ov_SC03_001 | 2390 | 1739 | 0 | 2407 | 2869 | 83.9% | +| ov_SC03_002 | 2316 | 1743 | 0 | 2331 | 2631 | 88.6% | +| ov_SC03_003 | 2265 | 1738 | 0 | 2266 | 2423 | 93.5% | +| ov_SC03_006 | 2332 | 1744 | 0 | 2341 | 2767 | 84.6% | +| ov_SC03_007 | 2310 | 1738 | 0 | 2314 | 2623 | 88.2% | +| ov_SC03_010 | 2273 | 1738 | 0 | 2273 | 2471 | 92.0% | +| ov_SC03_011 | 2279 | 1738 | 0 | 2285 | 2527 | 90.4% | +| ov_SC03_012 | 2257 | 1738 | 0 | 2258 | 2406 | 93.8% | +| ov_SC03_013 | 2278 | 1738 | 0 | 2278 | 2493 | 91.4% | +| ov_SC03_014 | 2336 | 1763 | 0 | 2336 | 2685 | 87.0% | +| ov_SC03_015 | 2336 | 1763 | 0 | 2336 | 2685 | 87.0% | +| ov_SC03_023 | 2264 | 1738 | 0 | 2265 | 2435 | 93.0% | +| ov_SC03_024 | 2324 | 1743 | 0 | 2331 | 2641 | 88.3% | +| ov_SC03_028 | 2304 | 1738 | 0 | 2308 | 2664 | 86.6% | +| ov_SC03_029 | 2306 | 1740 | 0 | 2316 | 2644 | 87.6% | +| ov_SC03_030 | 2279 | 1743 | 0 | 2281 | 2495 | 91.4% | +| ov_SC03_031 | 2275 | 1738 | 0 | 2278 | 2514 | 90.6% | +| ov_SC03_089 | 2292 | 1738 | 0 | 2299 | 2581 | 89.1% | +| ov_SC03_090 | 2293 | 1738 | 0 | 2301 | 2625 | 87.7% | +| ov_SC03_091 | 2296 | 1738 | 0 | 2304 | 2640 | 87.3% | +| ov_SC03_092 | 2306 | 1738 | 0 | 2318 | 2587 | 89.6% | +| ov_SC03_093 | 2282 | 1738 | 0 | 2286 | 2563 | 89.2% | +| ov_SC03_094 | 2277 | 1738 | 0 | 2283 | 2577 | 88.6% | +| ov_SC03_095 | 2267 | 1738 | 0 | 2270 | 2474 | 91.8% | +| ov_SC03_096 | 2267 | 1738 | 0 | 2270 | 2465 | 92.1% | +| ov_SC03_097 | 2297 | 1738 | 0 | 2304 | 2603 | 88.5% | +| ov_SC03_098 | 2275 | 1738 | 0 | 2278 | 2541 | 89.6% | +| ov_SC03_099 | 2268 | 1738 | 0 | 2271 | 2504 | 90.7% | +| ov_SC03_100 | 2278 | 1738 | 0 | 2282 | 2539 | 89.9% | +| ov_SC03_101 | 2278 | 1738 | 0 | 2282 | 2528 | 90.3% | +| ov_SC03_102 | 2271 | 1738 | 0 | 2274 | 2492 | 91.3% | +| ov_SC03_103 | 2274 | 1740 | 0 | 2277 | 2510 | 90.7% | +| ov_SC03_104 | 2300 | 1738 | 0 | 2307 | 2616 | 88.2% | +| ov_SC03_105 | 2291 | 1738 | 0 | 2298 | 2597 | 88.5% | +| ov_SC03_108 | 2259 | 1738 | 0 | 2259 | 2443 | 92.5% | +| ov_SC03_109 | 2262 | 1738 | 0 | 2264 | 2424 | 93.4% | +| ov_SC03_110 | 2266 | 1738 | 0 | 2266 | 2468 | 91.8% | +| ov_SC03_111 | 2277 | 1738 | 0 | 2280 | 2510 | 90.8% | +| ov_SC03_112 | 2273 | 1740 | 0 | 2275 | 2526 | 90.1% | +| ov_SC03_113 | 2266 | 1740 | 0 | 2269 | 2468 | 91.9% | +| ov_SC03_114 | 2255 | 1738 | 0 | 2257 | 2415 | 93.5% | +| ov_SC03_115 | 2272 | 1738 | 0 | 2274 | 2472 | 92.0% | +| ov_SC03_116 | 2263 | 1738 | 0 | 2266 | 2438 | 92.9% | +| ov_SC03_117 | 2290 | 1738 | 0 | 2296 | 2557 | 89.8% | +| ov_SC03_118 | 2336 | 1762 | 0 | 2337 | 2685 | 87.0% | +| ov_SC03_119 | 2335 | 1762 | 0 | 2336 | 2685 | 87.0% | +| ov_SC03_121 | 2270 | 1738 | 0 | 2273 | 2459 | 92.4% | +| ov_SC03_124 | 2348 | 1734 | 0 | 2368 | 2741 | 86.4% | +| ov_SC03_125 | 2304 | 1738 | 0 | 2316 | 2588 | 89.5% | +| ov_SC03_126 | 2267 | 1740 | 0 | 2267 | 2423 | 93.6% | +| ov_SC04_000 | 2283 | 1742 | 0 | 2292 | 2546 | 90.0% | +| ov_SC04_002 | 2302 | 1738 | 0 | 2306 | 2636 | 87.5% | +| ov_SC04_003 | 2278 | 1738 | 0 | 2282 | 2502 | 91.2% | +| ov_SC04_004 | 2287 | 1738 | 0 | 2289 | 2558 | 89.5% | +| ov_SC04_005 | 2297 | 1738 | 0 | 2303 | 2612 | 88.2% | +| ov_SC04_006 | 2267 | 1738 | 0 | 2269 | 2454 | 92.5% | +| ov_SC04_007 | 2291 | 1738 | 0 | 2295 | 2569 | 89.3% | +| ov_SC04_008 | 2259 | 1738 | 0 | 2259 | 2415 | 93.5% | +| ov_SC04_009 | 2274 | 1738 | 0 | 2277 | 2441 | 93.3% | +| ov_SC04_010 | 2264 | 1738 | 0 | 2265 | 2419 | 93.6% | +| ov_SC04_011 | 2322 | 1738 | 0 | 2328 | 2803 | 83.1% | +| ov_SC04_012 | 2261 | 1738 | 0 | 2262 | 2420 | 93.5% | +| ov_SC04_015 | 2326 | 1739 | 0 | 2337 | 2611 | 89.5% | +| ov_SC04_016 | 2264 | 1738 | 0 | 2266 | 2440 | 92.9% | +| ov_SC04_018 | 2374 | 1773 | 0 | 2374 | 2857 | 83.1% | +| ov_SC04_019 | 2380 | 1773 | 0 | 2380 | 2857 | 83.3% | +| ov_SC04_020 | 2291 | 1738 | 0 | 2303 | 2567 | 89.7% | +| ov_SC04_021 | 2268 | 1740 | 0 | 2268 | 2423 | 93.6% | +| ov_SC05_000 | 2265 | 1742 | 0 | 2268 | 2422 | 93.6% | +| ov_SC05_001 | 2287 | 1738 | 0 | 2292 | 2574 | 89.0% | +| ov_SC05_002 | 2270 | 1738 | 0 | 2273 | 2442 | 93.1% | +| ov_SC05_003 | 2267 | 1738 | 0 | 2268 | 2481 | 91.4% | +| ov_SC05_004 | 2263 | 1738 | 0 | 2265 | 2464 | 91.9% | +| ov_SC05_005 | 2268 | 1738 | 0 | 2269 | 2491 | 91.1% | +| ov_SC05_006 | 2261 | 1738 | 0 | 2261 | 2430 | 93.0% | +| ov_SC05_007 | 2271 | 1738 | 0 | 2276 | 2482 | 91.7% | +| ov_SC05_008 | 2288 | 1738 | 0 | 2290 | 2543 | 90.1% | +| ov_SC05_009 | 2267 | 1738 | 0 | 2271 | 2438 | 93.2% | +| ov_SC05_010 | 2294 | 1738 | 0 | 2298 | 2588 | 88.8% | +| ov_SC05_011 | 2263 | 1738 | 0 | 2264 | 2409 | 94.0% | +| ov_SC05_017 | 2370 | 1735 | 0 | 2381 | 2842 | 83.8% | +| ov_SC05_018 | 2317 | 1738 | 0 | 2330 | 2673 | 87.2% | +| ov_SC05_019 | 2268 | 1740 | 0 | 2268 | 2423 | 93.6% | +| ov_SC06_000 | 2332 | 1747 | 0 | 2335 | 2691 | 86.8% | +| ov_SC06_006 | 2284 | 1738 | 0 | 2285 | 2511 | 91.0% | +| ov_SC06_008 | 2304 | 1740 | 0 | 2310 | 2542 | 90.9% | +| ov_SC06_010 | 2284 | 1738 | 0 | 2289 | 2517 | 90.9% | +| ov_SC06_011 | 2272 | 1738 | 0 | 2276 | 2468 | 92.2% | +| ov_SC06_013 | 2266 | 1738 | 0 | 2267 | 2425 | 93.5% | +| ov_SC06_014 | 2272 | 1738 | 0 | 2274 | 2453 | 92.7% | +| ov_SC06_015 | 2269 | 1738 | 0 | 2269 | 2421 | 93.7% | +| ov_SC06_016 | 2287 | 1738 | 0 | 2289 | 2549 | 89.8% | +| ov_SC06_018 | 2298 | 1740 | 0 | 2305 | 2665 | 86.5% | +| ov_SC06_020 | 2276 | 1740 | 0 | 2277 | 2518 | 90.4% | +| ov_SC06_022 | 2295 | 1738 | 0 | 2303 | 2642 | 87.2% | +| ov_SC06_024 | 2305 | 1738 | 0 | 2311 | 2667 | 86.7% | +| ov_SC06_025 | 2289 | 1738 | 0 | 2294 | 2572 | 89.2% | +| ov_SC06_027 | 2254 | 1738 | 0 | 2255 | 2408 | 93.6% | +| ov_SC06_029 | 2315 | 1738 | 0 | 2327 | 2662 | 87.4% | +| ov_SC06_030 | 2268 | 1738 | 0 | 2268 | 2456 | 92.3% | +| ov_SC06_032 | 2290 | 1739 | 0 | 2297 | 2658 | 86.4% | +| ov_SC06_033 | 2292 | 1739 | 0 | 2299 | 2631 | 87.4% | +| ov_SC07_000 | 2283 | 1742 | 0 | 2285 | 2521 | 90.6% | +| ov_SC07_001 | 2267 | 1738 | 0 | 2269 | 2454 | 92.5% | +| ov_SC07_002 | 2295 | 1738 | 0 | 2299 | 2579 | 89.1% | +| ov_SC07_006 | 2068 | 1555 | 0 | 2148 | 2456 | 87.5% | +| ov_SC07_007 | 2062 | 1586 | 0 | 2146 | 2613 | 82.1% | +| ov_SC07_008 | 2252 | 1738 | 0 | 2252 | 2386 | 94.4% | +| ov_SC07_009 | 2261 | 1738 | 0 | 2263 | 2430 | 93.1% | +| ov_SC07_010 | 2094 | 1608 | 0 | 2177 | 2524 | 86.3% | +| ov_SC07_011 | 2062 | 1585 | 0 | 2142 | 2449 | 87.5% | diff --git a/src/ov_SC01_005/ov_SC01_005_jr_8015AE2C.c b/src/ov_SC01_005/ov_SC01_005_jr_8015AE2C.c index 4f453f450..0fe95a390 100644 --- a/src/ov_SC01_005/ov_SC01_005_jr_8015AE2C.c +++ b/src/ov_SC01_005/ov_SC01_005_jr_8015AE2C.c @@ -1514,7 +1514,259 @@ DEFINE_func_8015B858() /* dedup: shared engine-core @0x8015B858 (src/shared) */ DEFINE_func_8015B8F8() /* dedup: shared engine-core @0x8015B8F8 (src/shared) */ -INCLUDE_ASM("asm/ov_SC01_005/nonmatchings/ov_SC01_005_jr_8015AE2C", func_8015B950); +extern s32 func_8015AE2C(); + +// @class: plumbing +// @stuck: none — MATCH (271/271, pin-free, zero asm). The ONLY residual is DEF-SIDE plumbing, and it is now named exactly: the in-TU instantiation `DEFINE_func_8015BEE4()` (engine_core.h:1851-1855) expands to `extern s32 func_8015B950(void);` INSIDE ov_SC01_077_jr_8015AE2C.c, ~14 lines BELOW this definition, so the 1-param def collides with a `(void)` prototype -> `conflicting types for func_8015B950` (.run/bank_func_8015B950.log). §73 PARAMS axis / T0. Surgical fix = §65b de-macroize that ONE instantiation (blast radius: this TU); the fleet-wide `(void)`->`()` header edit is §63 and must be R22-validated. +/* func_8015B950 (ov_SC01_077_jr_8015AE2C, 271 ins, jtbl_801D8B74) — SESSION-21 re-verified + * + * ── ROUND-2 INDEPENDENT RE-VERIFICATION (2026-07-27, fresh agent, §88e discipline) ───────────── + * match_one : MATCH (271 ins) against the CURRENT tree — §87 staleness re-checked today. + * .text size: compiled .text = 0x43C = 1084 B = 271 ins, EXACTLY the target's declared 0x43C + * ("nonmatching func_8015B950, 0x43C"). So this is NOT a §83a length drift hiding + * behind a zero count — the count is over equal-length streams. + * jtbl : RE-DECODED MECHANICALLY, not inherited. Compiled .rodata = 0x1C = 28 B = 7 words, + * 7x R_MIPS_32 -> .text with implicit addends [58,58,58,E0,F0,100,58]; +0x8015B950 + * = [8015B9A8, 8015B9A8, 8015B9A8, 8015BA30, 8015BA40, 8015BA50, 8015B9A8]. + * Diffed word-for-word against asm/ov_SC01_077/data/tail14.data.s:15-23 — 7/7 identical. + * symcheck : SYMS-DIFF target=35 draft=34, sole MISSING = jtbl_801D8B74. This is the §81 jr + * FALSE POSITIVE, re-confirmed here by reading the relocs: gcc emits its OWN table and + * references it with R_MIPS_HI16/LO16 against the SECTION `.rodata` (t.o +0x40/+0x48), + * so the splat's dlabel NAME can never appear in the draft object's relocation set. + * Nothing is dropped and nothing is invented: the draft's other 34 symbols are exactly + * the target's other 34. + * FAMILY : the x138 remap is clean and §84-safe. Every sibling is 271 ins with an IDENTICAL + * callee set; only THREE names vary per overlay — the two data labels and the jtbl: + * ov_SC01_077 D_801849E0 / D_80184A4C / jtbl_801D8B74 + * ov_SC03_099 D_80185A50 / D_80185ABC / jtbl_801BD898 + * ov_SC06_008 D_80187E44 / D_80187EB0 / jtbl_801A8734 + * The pair is always +0x6C apart, and NO literal in this draft encodes that distance + * (both labels are referenced by name), so there is no §84 derived-offset hazard. + * D_8011F9C4 is fleet-constant (main-EXE data) and must NOT be remapped. + * + * match_one: MATCH (271 ins) against the CURRENT tree (§87 staleness re-checked, 2026-07-27). + * PIN-FREE, zero asm, offset-pure (s32 arg0 + raw offsets) — x138 template-safe. + * Provenance: this is the Phase-26 crack (.run/phase26-cracks/func_8015B950.c) re-gated verbatim, + * with ONE deliberate change: the definition's return type void -> s32. + * - `void func_8015B950(s32 arg0)` : MATCH (271 ins) [the Phase-26 form] + * - `s32 func_8015B950(s32 arg0)` : MATCH (271 ins) [shipped — §3a-1 void->s32 is byte-neutral] + * The fleet/engine_core.h canonical decl is `extern s32 func_8015B950(void);` (engine_core.h:1852), + * and the last bank attempt (.run/bank_func_8015B950.log) died on `conflicting types for + * func_8015B950`. Shipping the s32 return kills the §73 RETURN axis for free and leaves only the + * cheap T0 PARAMS axis for the ladder (fix_header_decl.py / --fix-def-sig / cast_call_sites). + * Both forms are byte-identical, so the orchestrator may swap the return type back at zero cost. + * + * SYMBOLS (§58 rules 1/2 — all splat spellings, all verified present): + * D_80184A4C asm/ov_SC01_077/data/tail.data.s:4355 (the state-handler vtable) + * D_801849E0 asm/ov_SC01_077/data/tail.data.s:4293 + * D_8011F9C4 main-EXE data; spelled `extern s32 D_8011F9C4;` in 5+ already-banked TUs + * jtbl_801D8B74 asm/ov_SC01_077/data/tail14.data.s:15 (compiler jump table — not named in C) + * + * JTBL VERIFIED (§8a gate): compiled .rodata = exactly 0x1C B / 7 words, 7x R_MIPS_32 .text with + * addends [0x58,0x58,0x58,0xE0,0xF0,0x100,0x58] -> +0x8015B950 = [B9A8,B9A8,B9A8,BA30,BA40,BA50, + * B9A8] == the original words at 0x801D8B74..0x801D8B8C. Bound `sltiu $v0,$v1,0x7` matches. + * The raw dlabel's 8th word 0x00000000 is NOT an entry — it is the intra-TU `.align 3` pad of the + * B34/B54/B74 jtbl chain; the object can never emit it (maspsx drops .align), so it must stay in + * the post-carve RAW data piece (the §53/§62/§81 carve chain applies at bank time). + * + * Same family as the TU's own already-matched func_8015AE2C: 7-case switch on ((s32 (*)(s32))func_801619A4)() + * (0/1/2/6 shared, 3/4/5 own, no default block — out-of-range and every `break` fall to the + * after-switch join), then a chain of "state handler" tests, each dispatching + * D_80184A4C[*(u16*)arg0](arg0) and returning. + * + * THREE LEVERS (draft -> MATCH in 3 compiles): + * + * 1. PROLOGUE CONSTANT = an INITIALIZED LOCAL, not a literal in the compare. + * Target opens with `lui $s2, 0xFFF5` in the *prologue*, used once ~200 ins later in + * `slt $v0,$s2,$s1`. No gcc-2.7.2 pass hoists a (set reg const_int) across basic blocks + * (loop.c needs a loop; cse/combine/sched never move insns between BBs) — so the insn must + * have been EMITTED in the first BB, i.e. the constant is a local initialized at the top of + * the function. cse then cannot fold it back into the compare: the `slt` operand predicate is + * `arith_operand`, which rejects a CONST_INT wider than 16 bits, so validate_change fails and + * the pseudo survives. Its live range spans every call -> global.c gives it a callee-saved reg. + * Writing `z > -0xB0000` inline instead emits the `lui` into the branch delay slot next to the + * compare (caller-saved $v0) and the function is 1 insn short. => `s32 lim = -0xB0000;` at top. + * + * 2. `lh` vs `lhu`: a short->short copy is a pure HImode move and gcc emits `lhu`. The target's + * `lh $v0,0x26($s0)` means the value passed through an SImode (int) temp: expand makes + * (set (reg:SI) (sign_extend (mem:HI))) + (set (mem:HI) (subreg:HI ...)), and combine cannot + * merge them (the merged form is mem<-mem, which no movhi accepts) so the sign-extending load + * survives. => route both halfword copies through the `s32 t` temp. + * + * 3. THE `goto` LAYOUT — dodging jump.c's store-flag conversion (jump.c:1005-1065). + * An if/else chain writing 0/1 into `doit` makes gcc collapse the last pair into + * `sltiu $v0,$v0,1`. jump.c fires that conversion when the insn immediately after a + * conditional jump is a lone `SET pseudo, CONST_INT` whose following simplejump targets the + * SAME label as the branch (jump.c:1038 `reallabelprev == temp || ... JUMP_LABEL(temp4) == + * JUMP_LABEL(insn)`) — exactly the shape of `if (c) x=0; else x=1;`. + * The target instead cross-jumps ALL the `doit=0` exits into ONE shared block placed after the + * `doit=1` fall-through; reorg's fill_slots_from_thread then COPIES that single set into all + * three branch delay slots and redirects each branch past it (which is why `addu $v0,$zero, + * $zero` appears 3x in delay slots and the shared block vanishes). A `goto zero;` / `goto one;` + * chain expresses that layout directly, and each conditional jump is then followed by a + * compare/call rather than a lone const set, so the store-flag conversion never triggers. + * GENERAL RULE: multiple predicates that all assign the SAME constant to one flag => write + * them as `goto` to a shared assignment, never as an if/else ladder. + */ +extern s32 D_8011F9C4; +extern s32 D_801849E0; + +extern s32 func_80161B18(void); +extern s32 func_801619A4(s32*); +extern s32 func_80149AA8(s32*); +extern void func_80149AD4(s32*); +extern s32 func_80149B54(s32*); +extern void func_80149BAC(s32*); +extern s32 func_801498E0(s32*); +extern s32 func_80149954(s32); +extern s32 func_80149A64(s32*); +extern void func_800CCCC0(s32 a0); +extern s32 func_80149CD4(s32 a0); +extern void func_8015E880(s32*); +extern s32 func_80149744(struct S_80149744*); +extern void func_80149788(void); +extern s32 func_801496D4(void*); +extern void func_80149704(void); +extern int func_80148AFC(void*); +extern void func_80146D90(s32 a0); +extern void func_80154150(s32 a0, s32 a1); +extern void func_801541D8(u8*, s32, s32); +extern s32 func_801488A8(u8*); +extern void func_80147078(s32*, s16); +extern void func_8015A264(void*); +extern s32 func_80013294(void*, void*); +extern void func_80159B70(void*); +extern s32 func_8016F1AC(void); +extern s32 func_80029178(s32 a0); +extern void func_80146DB8(s32*, s32*); +extern s32 func_80161CD0(s32, s32); +extern s32 func_80161208(s32 a0); +extern s32 func_801725A4(u8*); + +s32 func_8015B950(s32 arg0) +{ + + extern void (*D_80184A4C[])(void *); + s16 sp10[4]; + s16 sp18[4]; + s32 t; + s32 z; + s32 doit; + s32 lim = -0xB0000; + + if (func_80161B18() != 0) { + return; + } + switch (((s32 (*)(s32))func_801619A4)(arg0)) { + case 0: + case 1: + case 2: + case 6: + if (((s32 (*)(s32))func_80149AA8)(arg0) != 0) { + D_80184A4C[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149AD4)(arg0); + return; + } + if (((s32 (*)(s32))func_80149B54)(arg0) != 0) { + D_80184A4C[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149BAC)(arg0); + return; + } + break; + case 3: + ((void (*)(s32))func_801498E0)(arg0); + break; + case 4: + ((void (*)(s32))func_80149954)(arg0); + break; + case 5: + if (((s32 (*)(s32))func_80149A64)(arg0) != 0) { + D_80184A4C[*(u16 *)arg0]((void *)arg0); + func_800CCCC0(arg0); + return; + } + break; + } + if (func_80149CD4(arg0) != 0) { + D_80184A4C[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_8015E880)(arg0); + return; + } + if (((s32 (*)(s32))func_80149744)(arg0) != 0) { + D_80184A4C[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149788)(arg0); + return; + } + if (((s32 (*)(s32))func_801496D4)(arg0) != 0) { + D_80184A4C[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149704)(arg0); + if (((u8)((s32 (*)(s32))func_80148AFC)(arg0)) == 0) { + func_80146D90(arg0); + } + if ((*(s32 *)(arg0 + 0x24) | *(s32 *)(arg0 + 0x2C)) != 0) { + func_80154150(arg0, 0xF); + } else { + ((void (*)(s32, s32, s32))func_801541D8)(arg0, 0xD, 6); + } + *(s32 *)(arg0 + 0x238) = 1; + return; + } + if (((s32 (*)(s32))func_801488A8)(arg0) != 0) { + sp10[0] = 0; + sp10[1] = 0; + sp10[2] = 0; + t = *(s16 *)(arg0 + 0x26); + sp18[0] = t; + sp18[1] = 0; + t = *(s16 *)(arg0 + 0x2E); + sp18[2] = t; + D_80184A4C[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 1); + ((void (*)(s32))func_8015A264)(arg0); + t = -(((s32 (*)(s16 *, s16 *))func_80013294)(sp10, sp18) << 0x10); + if (t < *(s32 *)(arg0 + 0x2C)) { + *(s32 *)(arg0 + 0x2C) = t; + } + return; + } + if (*(u16 *)(arg0 + 0xB8) == 0x8000) { + D_80184A4C[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 0); + ((void (*)(s32))func_80159B70)(arg0); + return; + } + z = *(s32 *)(arg0 + 0x2C); + if (func_8016F1AC() != 0) { + goto zero; + } + if (z <= lim) { + goto one; + } + if (D_8011F9C4 == 0) { + goto zero; + } + if (((u8)func_80029178(0x21)) != 0) { + goto zero; + } +one: + doit = 1; + goto join; +zero: + doit = 0; +join: + if (doit != 0) { + D_80184A4C[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 0); + ((void (*)(s32))func_80159B70)(arg0); + func_80154150(arg0, 9); + ((void (*)(s32, s32 *))func_80146DB8)(arg0, &D_801849E0); + ((void (*)(s32, s32))func_80161CD0)(arg0, *(u16 *)(arg0 + 0x16E)); + return; + } + if (func_80161208(arg0) == 0) { + ((void (*)(s32))func_801725A4)(arg0); + } +} DEFINE_func_8015BD8C() /* dedup: shared engine-core @0x8015BD8C (src/shared) */ diff --git a/src/ov_SC01_006/ov_SC01_006_jr_8015AE2C.c b/src/ov_SC01_006/ov_SC01_006_jr_8015AE2C.c index 9e7ce0daa..e47b7b37b 100644 --- a/src/ov_SC01_006/ov_SC01_006_jr_8015AE2C.c +++ b/src/ov_SC01_006/ov_SC01_006_jr_8015AE2C.c @@ -1514,7 +1514,259 @@ DEFINE_func_8015B858() /* dedup: shared engine-core @0x8015B858 (src/shared) */ DEFINE_func_8015B8F8() /* dedup: shared engine-core @0x8015B8F8 (src/shared) */ -INCLUDE_ASM("asm/ov_SC01_006/nonmatchings/ov_SC01_006_jr_8015AE2C", func_8015B950); +extern s32 func_8015AE2C(); + +// @class: plumbing +// @stuck: none — MATCH (271/271, pin-free, zero asm). The ONLY residual is DEF-SIDE plumbing, and it is now named exactly: the in-TU instantiation `DEFINE_func_8015BEE4()` (engine_core.h:1851-1855) expands to `extern s32 func_8015B950(void);` INSIDE ov_SC01_077_jr_8015AE2C.c, ~14 lines BELOW this definition, so the 1-param def collides with a `(void)` prototype -> `conflicting types for func_8015B950` (.run/bank_func_8015B950.log). §73 PARAMS axis / T0. Surgical fix = §65b de-macroize that ONE instantiation (blast radius: this TU); the fleet-wide `(void)`->`()` header edit is §63 and must be R22-validated. +/* func_8015B950 (ov_SC01_077_jr_8015AE2C, 271 ins, jtbl_801D8B74) — SESSION-21 re-verified + * + * ── ROUND-2 INDEPENDENT RE-VERIFICATION (2026-07-27, fresh agent, §88e discipline) ───────────── + * match_one : MATCH (271 ins) against the CURRENT tree — §87 staleness re-checked today. + * .text size: compiled .text = 0x43C = 1084 B = 271 ins, EXACTLY the target's declared 0x43C + * ("nonmatching func_8015B950, 0x43C"). So this is NOT a §83a length drift hiding + * behind a zero count — the count is over equal-length streams. + * jtbl : RE-DECODED MECHANICALLY, not inherited. Compiled .rodata = 0x1C = 28 B = 7 words, + * 7x R_MIPS_32 -> .text with implicit addends [58,58,58,E0,F0,100,58]; +0x8015B950 + * = [8015B9A8, 8015B9A8, 8015B9A8, 8015BA30, 8015BA40, 8015BA50, 8015B9A8]. + * Diffed word-for-word against asm/ov_SC01_077/data/tail14.data.s:15-23 — 7/7 identical. + * symcheck : SYMS-DIFF target=35 draft=34, sole MISSING = jtbl_801D8B74. This is the §81 jr + * FALSE POSITIVE, re-confirmed here by reading the relocs: gcc emits its OWN table and + * references it with R_MIPS_HI16/LO16 against the SECTION `.rodata` (t.o +0x40/+0x48), + * so the splat's dlabel NAME can never appear in the draft object's relocation set. + * Nothing is dropped and nothing is invented: the draft's other 34 symbols are exactly + * the target's other 34. + * FAMILY : the x138 remap is clean and §84-safe. Every sibling is 271 ins with an IDENTICAL + * callee set; only THREE names vary per overlay — the two data labels and the jtbl: + * ov_SC01_077 D_801849E0 / D_80184A4C / jtbl_801D8B74 + * ov_SC03_099 D_80185A50 / D_80185ABC / jtbl_801BD898 + * ov_SC06_008 D_80187E44 / D_80187EB0 / jtbl_801A8734 + * The pair is always +0x6C apart, and NO literal in this draft encodes that distance + * (both labels are referenced by name), so there is no §84 derived-offset hazard. + * D_8011F9C4 is fleet-constant (main-EXE data) and must NOT be remapped. + * + * match_one: MATCH (271 ins) against the CURRENT tree (§87 staleness re-checked, 2026-07-27). + * PIN-FREE, zero asm, offset-pure (s32 arg0 + raw offsets) — x138 template-safe. + * Provenance: this is the Phase-26 crack (.run/phase26-cracks/func_8015B950.c) re-gated verbatim, + * with ONE deliberate change: the definition's return type void -> s32. + * - `void func_8015B950(s32 arg0)` : MATCH (271 ins) [the Phase-26 form] + * - `s32 func_8015B950(s32 arg0)` : MATCH (271 ins) [shipped — §3a-1 void->s32 is byte-neutral] + * The fleet/engine_core.h canonical decl is `extern s32 func_8015B950(void);` (engine_core.h:1852), + * and the last bank attempt (.run/bank_func_8015B950.log) died on `conflicting types for + * func_8015B950`. Shipping the s32 return kills the §73 RETURN axis for free and leaves only the + * cheap T0 PARAMS axis for the ladder (fix_header_decl.py / --fix-def-sig / cast_call_sites). + * Both forms are byte-identical, so the orchestrator may swap the return type back at zero cost. + * + * SYMBOLS (§58 rules 1/2 — all splat spellings, all verified present): + * D_80184A4C asm/ov_SC01_077/data/tail.data.s:4355 (the state-handler vtable) + * D_801849E0 asm/ov_SC01_077/data/tail.data.s:4293 + * D_8011F9C4 main-EXE data; spelled `extern s32 D_8011F9C4;` in 5+ already-banked TUs + * jtbl_801D8B74 asm/ov_SC01_077/data/tail14.data.s:15 (compiler jump table — not named in C) + * + * JTBL VERIFIED (§8a gate): compiled .rodata = exactly 0x1C B / 7 words, 7x R_MIPS_32 .text with + * addends [0x58,0x58,0x58,0xE0,0xF0,0x100,0x58] -> +0x8015B950 = [B9A8,B9A8,B9A8,BA30,BA40,BA50, + * B9A8] == the original words at 0x801D8B74..0x801D8B8C. Bound `sltiu $v0,$v1,0x7` matches. + * The raw dlabel's 8th word 0x00000000 is NOT an entry — it is the intra-TU `.align 3` pad of the + * B34/B54/B74 jtbl chain; the object can never emit it (maspsx drops .align), so it must stay in + * the post-carve RAW data piece (the §53/§62/§81 carve chain applies at bank time). + * + * Same family as the TU's own already-matched func_8015AE2C: 7-case switch on ((s32 (*)(s32))func_801619A4)() + * (0/1/2/6 shared, 3/4/5 own, no default block — out-of-range and every `break` fall to the + * after-switch join), then a chain of "state handler" tests, each dispatching + * D_80184A4C[*(u16*)arg0](arg0) and returning. + * + * THREE LEVERS (draft -> MATCH in 3 compiles): + * + * 1. PROLOGUE CONSTANT = an INITIALIZED LOCAL, not a literal in the compare. + * Target opens with `lui $s2, 0xFFF5` in the *prologue*, used once ~200 ins later in + * `slt $v0,$s2,$s1`. No gcc-2.7.2 pass hoists a (set reg const_int) across basic blocks + * (loop.c needs a loop; cse/combine/sched never move insns between BBs) — so the insn must + * have been EMITTED in the first BB, i.e. the constant is a local initialized at the top of + * the function. cse then cannot fold it back into the compare: the `slt` operand predicate is + * `arith_operand`, which rejects a CONST_INT wider than 16 bits, so validate_change fails and + * the pseudo survives. Its live range spans every call -> global.c gives it a callee-saved reg. + * Writing `z > -0xB0000` inline instead emits the `lui` into the branch delay slot next to the + * compare (caller-saved $v0) and the function is 1 insn short. => `s32 lim = -0xB0000;` at top. + * + * 2. `lh` vs `lhu`: a short->short copy is a pure HImode move and gcc emits `lhu`. The target's + * `lh $v0,0x26($s0)` means the value passed through an SImode (int) temp: expand makes + * (set (reg:SI) (sign_extend (mem:HI))) + (set (mem:HI) (subreg:HI ...)), and combine cannot + * merge them (the merged form is mem<-mem, which no movhi accepts) so the sign-extending load + * survives. => route both halfword copies through the `s32 t` temp. + * + * 3. THE `goto` LAYOUT — dodging jump.c's store-flag conversion (jump.c:1005-1065). + * An if/else chain writing 0/1 into `doit` makes gcc collapse the last pair into + * `sltiu $v0,$v0,1`. jump.c fires that conversion when the insn immediately after a + * conditional jump is a lone `SET pseudo, CONST_INT` whose following simplejump targets the + * SAME label as the branch (jump.c:1038 `reallabelprev == temp || ... JUMP_LABEL(temp4) == + * JUMP_LABEL(insn)`) — exactly the shape of `if (c) x=0; else x=1;`. + * The target instead cross-jumps ALL the `doit=0` exits into ONE shared block placed after the + * `doit=1` fall-through; reorg's fill_slots_from_thread then COPIES that single set into all + * three branch delay slots and redirects each branch past it (which is why `addu $v0,$zero, + * $zero` appears 3x in delay slots and the shared block vanishes). A `goto zero;` / `goto one;` + * chain expresses that layout directly, and each conditional jump is then followed by a + * compare/call rather than a lone const set, so the store-flag conversion never triggers. + * GENERAL RULE: multiple predicates that all assign the SAME constant to one flag => write + * them as `goto` to a shared assignment, never as an if/else ladder. + */ +extern s32 D_8011F9C4; +extern s32 D_801849E0; + +extern s32 func_80161B18(void); +extern s32 func_801619A4(s32*); +extern s32 func_80149AA8(s32*); +extern void func_80149AD4(s32*); +extern s32 func_80149B54(s32*); +extern void func_80149BAC(s32*); +extern s32 func_801498E0(s32*); +extern s32 func_80149954(s32); +extern s32 func_80149A64(s32*); +extern void func_800CCCC0(s32 a0); +extern s32 func_80149CD4(s32 a0); +extern void func_8015E880(s32*); +extern s32 func_80149744(struct S_80149744*); +extern void func_80149788(void); +extern s32 func_801496D4(void*); +extern void func_80149704(void); +extern int func_80148AFC(void*); +extern void func_80146D90(s32 a0); +extern void func_80154150(s32 a0, s32 a1); +extern void func_801541D8(u8*, s32, s32); +extern s32 func_801488A8(u8*); +extern void func_80147078(s32*, s16); +extern void func_8015A264(void*); +extern s32 func_80013294(void*, void*); +extern void func_80159B70(void*); +extern s32 func_8016F1AC(void); +extern s32 func_80029178(s32 a0); +extern void func_80146DB8(s32*, s32*); +extern s32 func_80161CD0(s32, s32); +extern s32 func_80161208(s32 a0); +extern s32 func_801725A4(u8*); + +s32 func_8015B950(s32 arg0) +{ + + extern void (*D_80184A4C[])(void *); + s16 sp10[4]; + s16 sp18[4]; + s32 t; + s32 z; + s32 doit; + s32 lim = -0xB0000; + + if (func_80161B18() != 0) { + return; + } + switch (((s32 (*)(s32))func_801619A4)(arg0)) { + case 0: + case 1: + case 2: + case 6: + if (((s32 (*)(s32))func_80149AA8)(arg0) != 0) { + D_80184A4C[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149AD4)(arg0); + return; + } + if (((s32 (*)(s32))func_80149B54)(arg0) != 0) { + D_80184A4C[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149BAC)(arg0); + return; + } + break; + case 3: + ((void (*)(s32))func_801498E0)(arg0); + break; + case 4: + ((void (*)(s32))func_80149954)(arg0); + break; + case 5: + if (((s32 (*)(s32))func_80149A64)(arg0) != 0) { + D_80184A4C[*(u16 *)arg0]((void *)arg0); + func_800CCCC0(arg0); + return; + } + break; + } + if (func_80149CD4(arg0) != 0) { + D_80184A4C[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_8015E880)(arg0); + return; + } + if (((s32 (*)(s32))func_80149744)(arg0) != 0) { + D_80184A4C[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149788)(arg0); + return; + } + if (((s32 (*)(s32))func_801496D4)(arg0) != 0) { + D_80184A4C[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149704)(arg0); + if (((u8)((s32 (*)(s32))func_80148AFC)(arg0)) == 0) { + func_80146D90(arg0); + } + if ((*(s32 *)(arg0 + 0x24) | *(s32 *)(arg0 + 0x2C)) != 0) { + func_80154150(arg0, 0xF); + } else { + ((void (*)(s32, s32, s32))func_801541D8)(arg0, 0xD, 6); + } + *(s32 *)(arg0 + 0x238) = 1; + return; + } + if (((s32 (*)(s32))func_801488A8)(arg0) != 0) { + sp10[0] = 0; + sp10[1] = 0; + sp10[2] = 0; + t = *(s16 *)(arg0 + 0x26); + sp18[0] = t; + sp18[1] = 0; + t = *(s16 *)(arg0 + 0x2E); + sp18[2] = t; + D_80184A4C[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 1); + ((void (*)(s32))func_8015A264)(arg0); + t = -(((s32 (*)(s16 *, s16 *))func_80013294)(sp10, sp18) << 0x10); + if (t < *(s32 *)(arg0 + 0x2C)) { + *(s32 *)(arg0 + 0x2C) = t; + } + return; + } + if (*(u16 *)(arg0 + 0xB8) == 0x8000) { + D_80184A4C[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 0); + ((void (*)(s32))func_80159B70)(arg0); + return; + } + z = *(s32 *)(arg0 + 0x2C); + if (func_8016F1AC() != 0) { + goto zero; + } + if (z <= lim) { + goto one; + } + if (D_8011F9C4 == 0) { + goto zero; + } + if (((u8)func_80029178(0x21)) != 0) { + goto zero; + } +one: + doit = 1; + goto join; +zero: + doit = 0; +join: + if (doit != 0) { + D_80184A4C[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 0); + ((void (*)(s32))func_80159B70)(arg0); + func_80154150(arg0, 9); + ((void (*)(s32, s32 *))func_80146DB8)(arg0, &D_801849E0); + ((void (*)(s32, s32))func_80161CD0)(arg0, *(u16 *)(arg0 + 0x16E)); + return; + } + if (func_80161208(arg0) == 0) { + ((void (*)(s32))func_801725A4)(arg0); + } +} DEFINE_func_8015BD8C() /* dedup: shared engine-core @0x8015BD8C (src/shared) */ diff --git a/src/ov_SC01_008/ov_SC01_008_jr_8015AE2C.c b/src/ov_SC01_008/ov_SC01_008_jr_8015AE2C.c index 731a05333..20efbb170 100644 --- a/src/ov_SC01_008/ov_SC01_008_jr_8015AE2C.c +++ b/src/ov_SC01_008/ov_SC01_008_jr_8015AE2C.c @@ -1513,7 +1513,259 @@ DEFINE_func_8015B858() /* dedup: shared engine-core @0x8015B858 (src/shared) */ DEFINE_func_8015B8F8() /* dedup: shared engine-core @0x8015B8F8 (src/shared) */ -INCLUDE_ASM("asm/ov_SC01_008/nonmatchings/ov_SC01_008_jr_8015AE2C", func_8015B950); +extern s32 func_8015AE2C(); + +// @class: plumbing +// @stuck: none — MATCH (271/271, pin-free, zero asm). The ONLY residual is DEF-SIDE plumbing, and it is now named exactly: the in-TU instantiation `DEFINE_func_8015BEE4()` (engine_core.h:1851-1855) expands to `extern s32 func_8015B950(void);` INSIDE ov_SC01_077_jr_8015AE2C.c, ~14 lines BELOW this definition, so the 1-param def collides with a `(void)` prototype -> `conflicting types for func_8015B950` (.run/bank_func_8015B950.log). §73 PARAMS axis / T0. Surgical fix = §65b de-macroize that ONE instantiation (blast radius: this TU); the fleet-wide `(void)`->`()` header edit is §63 and must be R22-validated. +/* func_8015B950 (ov_SC01_077_jr_8015AE2C, 271 ins, jtbl_801D8B74) — SESSION-21 re-verified + * + * ── ROUND-2 INDEPENDENT RE-VERIFICATION (2026-07-27, fresh agent, §88e discipline) ───────────── + * match_one : MATCH (271 ins) against the CURRENT tree — §87 staleness re-checked today. + * .text size: compiled .text = 0x43C = 1084 B = 271 ins, EXACTLY the target's declared 0x43C + * ("nonmatching func_8015B950, 0x43C"). So this is NOT a §83a length drift hiding + * behind a zero count — the count is over equal-length streams. + * jtbl : RE-DECODED MECHANICALLY, not inherited. Compiled .rodata = 0x1C = 28 B = 7 words, + * 7x R_MIPS_32 -> .text with implicit addends [58,58,58,E0,F0,100,58]; +0x8015B950 + * = [8015B9A8, 8015B9A8, 8015B9A8, 8015BA30, 8015BA40, 8015BA50, 8015B9A8]. + * Diffed word-for-word against asm/ov_SC01_077/data/tail14.data.s:15-23 — 7/7 identical. + * symcheck : SYMS-DIFF target=35 draft=34, sole MISSING = jtbl_801D8B74. This is the §81 jr + * FALSE POSITIVE, re-confirmed here by reading the relocs: gcc emits its OWN table and + * references it with R_MIPS_HI16/LO16 against the SECTION `.rodata` (t.o +0x40/+0x48), + * so the splat's dlabel NAME can never appear in the draft object's relocation set. + * Nothing is dropped and nothing is invented: the draft's other 34 symbols are exactly + * the target's other 34. + * FAMILY : the x138 remap is clean and §84-safe. Every sibling is 271 ins with an IDENTICAL + * callee set; only THREE names vary per overlay — the two data labels and the jtbl: + * ov_SC01_077 D_80181DC0 / D_80181E2C / jtbl_801D8B74 + * ov_SC03_099 D_80185A50 / D_80185ABC / jtbl_801BD898 + * ov_SC06_008 D_80187E44 / D_80187EB0 / jtbl_801A8734 + * The pair is always +0x6C apart, and NO literal in this draft encodes that distance + * (both labels are referenced by name), so there is no §84 derived-offset hazard. + * D_8011F9C4 is fleet-constant (main-EXE data) and must NOT be remapped. + * + * match_one: MATCH (271 ins) against the CURRENT tree (§87 staleness re-checked, 2026-07-27). + * PIN-FREE, zero asm, offset-pure (s32 arg0 + raw offsets) — x138 template-safe. + * Provenance: this is the Phase-26 crack (.run/phase26-cracks/func_8015B950.c) re-gated verbatim, + * with ONE deliberate change: the definition's return type void -> s32. + * - `void func_8015B950(s32 arg0)` : MATCH (271 ins) [the Phase-26 form] + * - `s32 func_8015B950(s32 arg0)` : MATCH (271 ins) [shipped — §3a-1 void->s32 is byte-neutral] + * The fleet/engine_core.h canonical decl is `extern s32 func_8015B950(void);` (engine_core.h:1852), + * and the last bank attempt (.run/bank_func_8015B950.log) died on `conflicting types for + * func_8015B950`. Shipping the s32 return kills the §73 RETURN axis for free and leaves only the + * cheap T0 PARAMS axis for the ladder (fix_header_decl.py / --fix-def-sig / cast_call_sites). + * Both forms are byte-identical, so the orchestrator may swap the return type back at zero cost. + * + * SYMBOLS (§58 rules 1/2 — all splat spellings, all verified present): + * D_80181E2C asm/ov_SC01_077/data/tail.data.s:4355 (the state-handler vtable) + * D_80181DC0 asm/ov_SC01_077/data/tail.data.s:4293 + * D_8011F9C4 main-EXE data; spelled `extern s32 D_8011F9C4;` in 5+ already-banked TUs + * jtbl_801D8B74 asm/ov_SC01_077/data/tail14.data.s:15 (compiler jump table — not named in C) + * + * JTBL VERIFIED (§8a gate): compiled .rodata = exactly 0x1C B / 7 words, 7x R_MIPS_32 .text with + * addends [0x58,0x58,0x58,0xE0,0xF0,0x100,0x58] -> +0x8015B950 = [B9A8,B9A8,B9A8,BA30,BA40,BA50, + * B9A8] == the original words at 0x801D8B74..0x801D8B8C. Bound `sltiu $v0,$v1,0x7` matches. + * The raw dlabel's 8th word 0x00000000 is NOT an entry — it is the intra-TU `.align 3` pad of the + * B34/B54/B74 jtbl chain; the object can never emit it (maspsx drops .align), so it must stay in + * the post-carve RAW data piece (the §53/§62/§81 carve chain applies at bank time). + * + * Same family as the TU's own already-matched func_8015AE2C: 7-case switch on ((s32 (*)(s32))func_801619A4)() + * (0/1/2/6 shared, 3/4/5 own, no default block — out-of-range and every `break` fall to the + * after-switch join), then a chain of "state handler" tests, each dispatching + * D_80181E2C[*(u16*)arg0](arg0) and returning. + * + * THREE LEVERS (draft -> MATCH in 3 compiles): + * + * 1. PROLOGUE CONSTANT = an INITIALIZED LOCAL, not a literal in the compare. + * Target opens with `lui $s2, 0xFFF5` in the *prologue*, used once ~200 ins later in + * `slt $v0,$s2,$s1`. No gcc-2.7.2 pass hoists a (set reg const_int) across basic blocks + * (loop.c needs a loop; cse/combine/sched never move insns between BBs) — so the insn must + * have been EMITTED in the first BB, i.e. the constant is a local initialized at the top of + * the function. cse then cannot fold it back into the compare: the `slt` operand predicate is + * `arith_operand`, which rejects a CONST_INT wider than 16 bits, so validate_change fails and + * the pseudo survives. Its live range spans every call -> global.c gives it a callee-saved reg. + * Writing `z > -0xB0000` inline instead emits the `lui` into the branch delay slot next to the + * compare (caller-saved $v0) and the function is 1 insn short. => `s32 lim = -0xB0000;` at top. + * + * 2. `lh` vs `lhu`: a short->short copy is a pure HImode move and gcc emits `lhu`. The target's + * `lh $v0,0x26($s0)` means the value passed through an SImode (int) temp: expand makes + * (set (reg:SI) (sign_extend (mem:HI))) + (set (mem:HI) (subreg:HI ...)), and combine cannot + * merge them (the merged form is mem<-mem, which no movhi accepts) so the sign-extending load + * survives. => route both halfword copies through the `s32 t` temp. + * + * 3. THE `goto` LAYOUT — dodging jump.c's store-flag conversion (jump.c:1005-1065). + * An if/else chain writing 0/1 into `doit` makes gcc collapse the last pair into + * `sltiu $v0,$v0,1`. jump.c fires that conversion when the insn immediately after a + * conditional jump is a lone `SET pseudo, CONST_INT` whose following simplejump targets the + * SAME label as the branch (jump.c:1038 `reallabelprev == temp || ... JUMP_LABEL(temp4) == + * JUMP_LABEL(insn)`) — exactly the shape of `if (c) x=0; else x=1;`. + * The target instead cross-jumps ALL the `doit=0` exits into ONE shared block placed after the + * `doit=1` fall-through; reorg's fill_slots_from_thread then COPIES that single set into all + * three branch delay slots and redirects each branch past it (which is why `addu $v0,$zero, + * $zero` appears 3x in delay slots and the shared block vanishes). A `goto zero;` / `goto one;` + * chain expresses that layout directly, and each conditional jump is then followed by a + * compare/call rather than a lone const set, so the store-flag conversion never triggers. + * GENERAL RULE: multiple predicates that all assign the SAME constant to one flag => write + * them as `goto` to a shared assignment, never as an if/else ladder. + */ +extern s32 D_8011F9C4; +extern s32 D_80181DC0; + +extern s32 func_80161B18(void); +extern s32 func_801619A4(s32*); +extern s32 func_80149AA8(s32*); +extern void func_80149AD4(s32*); +extern s32 func_80149B54(s32*); +extern void func_80149BAC(s32*); +extern s32 func_801498E0(s32*); +extern s32 func_80149954(s32); +extern s32 func_80149A64(s32*); +extern void func_800CCCC0(s32 a0); +extern s32 func_80149CD4(s32 a0); +extern void func_8015E880(s32*); +extern s32 func_80149744(struct S_80149744*); +extern void func_80149788(void); +extern s32 func_801496D4(void*); +extern void func_80149704(void); +extern int func_80148AFC(void*); +extern void func_80146D90(s32 a0); +extern void func_80154150(s32 a0, s32 a1); +extern void func_801541D8(u8*, s32, s32); +extern s32 func_801488A8(u8*); +extern void func_80147078(s32*, s16); +extern void func_8015A264(void*); +extern s32 func_80013294(void*, void*); +extern void func_80159B70(void*); +extern s32 func_8016F1AC(void); +extern s32 func_80029178(s32 a0); +extern void func_80146DB8(s32*, s32*); +extern s32 func_80161CD0(s32, s32); +extern s32 func_80161208(s32 a0); +extern s32 func_801725A4(u8*); + +s32 func_8015B950(s32 arg0) +{ + + extern void (*D_80181E2C[])(void *); + s16 sp10[4]; + s16 sp18[4]; + s32 t; + s32 z; + s32 doit; + s32 lim = -0xB0000; + + if (func_80161B18() != 0) { + return; + } + switch (((s32 (*)(s32))func_801619A4)(arg0)) { + case 0: + case 1: + case 2: + case 6: + if (((s32 (*)(s32))func_80149AA8)(arg0) != 0) { + D_80181E2C[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149AD4)(arg0); + return; + } + if (((s32 (*)(s32))func_80149B54)(arg0) != 0) { + D_80181E2C[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149BAC)(arg0); + return; + } + break; + case 3: + ((void (*)(s32))func_801498E0)(arg0); + break; + case 4: + ((void (*)(s32))func_80149954)(arg0); + break; + case 5: + if (((s32 (*)(s32))func_80149A64)(arg0) != 0) { + D_80181E2C[*(u16 *)arg0]((void *)arg0); + func_800CCCC0(arg0); + return; + } + break; + } + if (func_80149CD4(arg0) != 0) { + D_80181E2C[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_8015E880)(arg0); + return; + } + if (((s32 (*)(s32))func_80149744)(arg0) != 0) { + D_80181E2C[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149788)(arg0); + return; + } + if (((s32 (*)(s32))func_801496D4)(arg0) != 0) { + D_80181E2C[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149704)(arg0); + if (((u8)((s32 (*)(s32))func_80148AFC)(arg0)) == 0) { + func_80146D90(arg0); + } + if ((*(s32 *)(arg0 + 0x24) | *(s32 *)(arg0 + 0x2C)) != 0) { + func_80154150(arg0, 0xF); + } else { + ((void (*)(s32, s32, s32))func_801541D8)(arg0, 0xD, 6); + } + *(s32 *)(arg0 + 0x238) = 1; + return; + } + if (((s32 (*)(s32))func_801488A8)(arg0) != 0) { + sp10[0] = 0; + sp10[1] = 0; + sp10[2] = 0; + t = *(s16 *)(arg0 + 0x26); + sp18[0] = t; + sp18[1] = 0; + t = *(s16 *)(arg0 + 0x2E); + sp18[2] = t; + D_80181E2C[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 1); + ((void (*)(s32))func_8015A264)(arg0); + t = -(((s32 (*)(s16 *, s16 *))func_80013294)(sp10, sp18) << 0x10); + if (t < *(s32 *)(arg0 + 0x2C)) { + *(s32 *)(arg0 + 0x2C) = t; + } + return; + } + if (*(u16 *)(arg0 + 0xB8) == 0x8000) { + D_80181E2C[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 0); + ((void (*)(s32))func_80159B70)(arg0); + return; + } + z = *(s32 *)(arg0 + 0x2C); + if (func_8016F1AC() != 0) { + goto zero; + } + if (z <= lim) { + goto one; + } + if (D_8011F9C4 == 0) { + goto zero; + } + if (((u8)func_80029178(0x21)) != 0) { + goto zero; + } +one: + doit = 1; + goto join; +zero: + doit = 0; +join: + if (doit != 0) { + D_80181E2C[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 0); + ((void (*)(s32))func_80159B70)(arg0); + func_80154150(arg0, 9); + ((void (*)(s32, s32 *))func_80146DB8)(arg0, &D_80181DC0); + ((void (*)(s32, s32))func_80161CD0)(arg0, *(u16 *)(arg0 + 0x16E)); + return; + } + if (func_80161208(arg0) == 0) { + ((void (*)(s32))func_801725A4)(arg0); + } +} DEFINE_func_8015BD8C() /* dedup: shared engine-core @0x8015BD8C (src/shared) */ diff --git a/src/ov_SC01_009/ov_SC01_009_jr_8015AE2C.c b/src/ov_SC01_009/ov_SC01_009_jr_8015AE2C.c index 01f87fc55..2399e8c0f 100644 --- a/src/ov_SC01_009/ov_SC01_009_jr_8015AE2C.c +++ b/src/ov_SC01_009/ov_SC01_009_jr_8015AE2C.c @@ -1513,7 +1513,259 @@ DEFINE_func_8015B858() /* dedup: shared engine-core @0x8015B858 (src/shared) */ DEFINE_func_8015B8F8() /* dedup: shared engine-core @0x8015B8F8 (src/shared) */ -INCLUDE_ASM("asm/ov_SC01_009/nonmatchings/ov_SC01_009_jr_8015AE2C", func_8015B950); +extern s32 func_8015AE2C(); + +// @class: plumbing +// @stuck: none — MATCH (271/271, pin-free, zero asm). The ONLY residual is DEF-SIDE plumbing, and it is now named exactly: the in-TU instantiation `DEFINE_func_8015BEE4()` (engine_core.h:1851-1855) expands to `extern s32 func_8015B950(void);` INSIDE ov_SC01_077_jr_8015AE2C.c, ~14 lines BELOW this definition, so the 1-param def collides with a `(void)` prototype -> `conflicting types for func_8015B950` (.run/bank_func_8015B950.log). §73 PARAMS axis / T0. Surgical fix = §65b de-macroize that ONE instantiation (blast radius: this TU); the fleet-wide `(void)`->`()` header edit is §63 and must be R22-validated. +/* func_8015B950 (ov_SC01_077_jr_8015AE2C, 271 ins, jtbl_801D8B74) — SESSION-21 re-verified + * + * ── ROUND-2 INDEPENDENT RE-VERIFICATION (2026-07-27, fresh agent, §88e discipline) ───────────── + * match_one : MATCH (271 ins) against the CURRENT tree — §87 staleness re-checked today. + * .text size: compiled .text = 0x43C = 1084 B = 271 ins, EXACTLY the target's declared 0x43C + * ("nonmatching func_8015B950, 0x43C"). So this is NOT a §83a length drift hiding + * behind a zero count — the count is over equal-length streams. + * jtbl : RE-DECODED MECHANICALLY, not inherited. Compiled .rodata = 0x1C = 28 B = 7 words, + * 7x R_MIPS_32 -> .text with implicit addends [58,58,58,E0,F0,100,58]; +0x8015B950 + * = [8015B9A8, 8015B9A8, 8015B9A8, 8015BA30, 8015BA40, 8015BA50, 8015B9A8]. + * Diffed word-for-word against asm/ov_SC01_077/data/tail14.data.s:15-23 — 7/7 identical. + * symcheck : SYMS-DIFF target=35 draft=34, sole MISSING = jtbl_801D8B74. This is the §81 jr + * FALSE POSITIVE, re-confirmed here by reading the relocs: gcc emits its OWN table and + * references it with R_MIPS_HI16/LO16 against the SECTION `.rodata` (t.o +0x40/+0x48), + * so the splat's dlabel NAME can never appear in the draft object's relocation set. + * Nothing is dropped and nothing is invented: the draft's other 34 symbols are exactly + * the target's other 34. + * FAMILY : the x138 remap is clean and §84-safe. Every sibling is 271 ins with an IDENTICAL + * callee set; only THREE names vary per overlay — the two data labels and the jtbl: + * ov_SC01_077 D_80184FA8 / D_80185014 / jtbl_801D8B74 + * ov_SC03_099 D_80185A50 / D_80185ABC / jtbl_801BD898 + * ov_SC06_008 D_80187E44 / D_80187EB0 / jtbl_801A8734 + * The pair is always +0x6C apart, and NO literal in this draft encodes that distance + * (both labels are referenced by name), so there is no §84 derived-offset hazard. + * D_8011F9C4 is fleet-constant (main-EXE data) and must NOT be remapped. + * + * match_one: MATCH (271 ins) against the CURRENT tree (§87 staleness re-checked, 2026-07-27). + * PIN-FREE, zero asm, offset-pure (s32 arg0 + raw offsets) — x138 template-safe. + * Provenance: this is the Phase-26 crack (.run/phase26-cracks/func_8015B950.c) re-gated verbatim, + * with ONE deliberate change: the definition's return type void -> s32. + * - `void func_8015B950(s32 arg0)` : MATCH (271 ins) [the Phase-26 form] + * - `s32 func_8015B950(s32 arg0)` : MATCH (271 ins) [shipped — §3a-1 void->s32 is byte-neutral] + * The fleet/engine_core.h canonical decl is `extern s32 func_8015B950(void);` (engine_core.h:1852), + * and the last bank attempt (.run/bank_func_8015B950.log) died on `conflicting types for + * func_8015B950`. Shipping the s32 return kills the §73 RETURN axis for free and leaves only the + * cheap T0 PARAMS axis for the ladder (fix_header_decl.py / --fix-def-sig / cast_call_sites). + * Both forms are byte-identical, so the orchestrator may swap the return type back at zero cost. + * + * SYMBOLS (§58 rules 1/2 — all splat spellings, all verified present): + * D_80185014 asm/ov_SC01_077/data/tail.data.s:4355 (the state-handler vtable) + * D_80184FA8 asm/ov_SC01_077/data/tail.data.s:4293 + * D_8011F9C4 main-EXE data; spelled `extern s32 D_8011F9C4;` in 5+ already-banked TUs + * jtbl_801D8B74 asm/ov_SC01_077/data/tail14.data.s:15 (compiler jump table — not named in C) + * + * JTBL VERIFIED (§8a gate): compiled .rodata = exactly 0x1C B / 7 words, 7x R_MIPS_32 .text with + * addends [0x58,0x58,0x58,0xE0,0xF0,0x100,0x58] -> +0x8015B950 = [B9A8,B9A8,B9A8,BA30,BA40,BA50, + * B9A8] == the original words at 0x801D8B74..0x801D8B8C. Bound `sltiu $v0,$v1,0x7` matches. + * The raw dlabel's 8th word 0x00000000 is NOT an entry — it is the intra-TU `.align 3` pad of the + * B34/B54/B74 jtbl chain; the object can never emit it (maspsx drops .align), so it must stay in + * the post-carve RAW data piece (the §53/§62/§81 carve chain applies at bank time). + * + * Same family as the TU's own already-matched func_8015AE2C: 7-case switch on ((s32 (*)(s32))func_801619A4)() + * (0/1/2/6 shared, 3/4/5 own, no default block — out-of-range and every `break` fall to the + * after-switch join), then a chain of "state handler" tests, each dispatching + * D_80185014[*(u16*)arg0](arg0) and returning. + * + * THREE LEVERS (draft -> MATCH in 3 compiles): + * + * 1. PROLOGUE CONSTANT = an INITIALIZED LOCAL, not a literal in the compare. + * Target opens with `lui $s2, 0xFFF5` in the *prologue*, used once ~200 ins later in + * `slt $v0,$s2,$s1`. No gcc-2.7.2 pass hoists a (set reg const_int) across basic blocks + * (loop.c needs a loop; cse/combine/sched never move insns between BBs) — so the insn must + * have been EMITTED in the first BB, i.e. the constant is a local initialized at the top of + * the function. cse then cannot fold it back into the compare: the `slt` operand predicate is + * `arith_operand`, which rejects a CONST_INT wider than 16 bits, so validate_change fails and + * the pseudo survives. Its live range spans every call -> global.c gives it a callee-saved reg. + * Writing `z > -0xB0000` inline instead emits the `lui` into the branch delay slot next to the + * compare (caller-saved $v0) and the function is 1 insn short. => `s32 lim = -0xB0000;` at top. + * + * 2. `lh` vs `lhu`: a short->short copy is a pure HImode move and gcc emits `lhu`. The target's + * `lh $v0,0x26($s0)` means the value passed through an SImode (int) temp: expand makes + * (set (reg:SI) (sign_extend (mem:HI))) + (set (mem:HI) (subreg:HI ...)), and combine cannot + * merge them (the merged form is mem<-mem, which no movhi accepts) so the sign-extending load + * survives. => route both halfword copies through the `s32 t` temp. + * + * 3. THE `goto` LAYOUT — dodging jump.c's store-flag conversion (jump.c:1005-1065). + * An if/else chain writing 0/1 into `doit` makes gcc collapse the last pair into + * `sltiu $v0,$v0,1`. jump.c fires that conversion when the insn immediately after a + * conditional jump is a lone `SET pseudo, CONST_INT` whose following simplejump targets the + * SAME label as the branch (jump.c:1038 `reallabelprev == temp || ... JUMP_LABEL(temp4) == + * JUMP_LABEL(insn)`) — exactly the shape of `if (c) x=0; else x=1;`. + * The target instead cross-jumps ALL the `doit=0` exits into ONE shared block placed after the + * `doit=1` fall-through; reorg's fill_slots_from_thread then COPIES that single set into all + * three branch delay slots and redirects each branch past it (which is why `addu $v0,$zero, + * $zero` appears 3x in delay slots and the shared block vanishes). A `goto zero;` / `goto one;` + * chain expresses that layout directly, and each conditional jump is then followed by a + * compare/call rather than a lone const set, so the store-flag conversion never triggers. + * GENERAL RULE: multiple predicates that all assign the SAME constant to one flag => write + * them as `goto` to a shared assignment, never as an if/else ladder. + */ +extern s32 D_8011F9C4; +extern s32 D_80184FA8; + +extern s32 func_80161B18(void); +extern s32 func_801619A4(s32*); +extern s32 func_80149AA8(s32*); +extern void func_80149AD4(s32*); +extern s32 func_80149B54(s32*); +extern void func_80149BAC(s32*); +extern s32 func_801498E0(s32*); +extern s32 func_80149954(s32); +extern s32 func_80149A64(s32*); +extern void func_800CCCC0(s32 a0); +extern s32 func_80149CD4(s32 a0); +extern void func_8015E880(s32*); +extern s32 func_80149744(struct S_80149744*); +extern void func_80149788(void); +extern s32 func_801496D4(void*); +extern void func_80149704(void); +extern int func_80148AFC(void*); +extern void func_80146D90(s32 a0); +extern void func_80154150(s32 a0, s32 a1); +extern void func_801541D8(u8*, s32, s32); +extern s32 func_801488A8(u8*); +extern void func_80147078(s32*, s16); +extern void func_8015A264(void*); +extern s32 func_80013294(void*, void*); +extern void func_80159B70(void*); +extern s32 func_8016F1AC(void); +extern s32 func_80029178(s32 a0); +extern void func_80146DB8(s32*, s32*); +extern s32 func_80161CD0(s32, s32); +extern s32 func_80161208(s32 a0); +extern s32 func_801725A4(u8*); + +s32 func_8015B950(s32 arg0) +{ + + extern void (*D_80185014[])(void *); + s16 sp10[4]; + s16 sp18[4]; + s32 t; + s32 z; + s32 doit; + s32 lim = -0xB0000; + + if (func_80161B18() != 0) { + return; + } + switch (((s32 (*)(s32))func_801619A4)(arg0)) { + case 0: + case 1: + case 2: + case 6: + if (((s32 (*)(s32))func_80149AA8)(arg0) != 0) { + D_80185014[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149AD4)(arg0); + return; + } + if (((s32 (*)(s32))func_80149B54)(arg0) != 0) { + D_80185014[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149BAC)(arg0); + return; + } + break; + case 3: + ((void (*)(s32))func_801498E0)(arg0); + break; + case 4: + ((void (*)(s32))func_80149954)(arg0); + break; + case 5: + if (((s32 (*)(s32))func_80149A64)(arg0) != 0) { + D_80185014[*(u16 *)arg0]((void *)arg0); + func_800CCCC0(arg0); + return; + } + break; + } + if (func_80149CD4(arg0) != 0) { + D_80185014[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_8015E880)(arg0); + return; + } + if (((s32 (*)(s32))func_80149744)(arg0) != 0) { + D_80185014[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149788)(arg0); + return; + } + if (((s32 (*)(s32))func_801496D4)(arg0) != 0) { + D_80185014[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149704)(arg0); + if (((u8)((s32 (*)(s32))func_80148AFC)(arg0)) == 0) { + func_80146D90(arg0); + } + if ((*(s32 *)(arg0 + 0x24) | *(s32 *)(arg0 + 0x2C)) != 0) { + func_80154150(arg0, 0xF); + } else { + ((void (*)(s32, s32, s32))func_801541D8)(arg0, 0xD, 6); + } + *(s32 *)(arg0 + 0x238) = 1; + return; + } + if (((s32 (*)(s32))func_801488A8)(arg0) != 0) { + sp10[0] = 0; + sp10[1] = 0; + sp10[2] = 0; + t = *(s16 *)(arg0 + 0x26); + sp18[0] = t; + sp18[1] = 0; + t = *(s16 *)(arg0 + 0x2E); + sp18[2] = t; + D_80185014[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 1); + ((void (*)(s32))func_8015A264)(arg0); + t = -(((s32 (*)(s16 *, s16 *))func_80013294)(sp10, sp18) << 0x10); + if (t < *(s32 *)(arg0 + 0x2C)) { + *(s32 *)(arg0 + 0x2C) = t; + } + return; + } + if (*(u16 *)(arg0 + 0xB8) == 0x8000) { + D_80185014[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 0); + ((void (*)(s32))func_80159B70)(arg0); + return; + } + z = *(s32 *)(arg0 + 0x2C); + if (func_8016F1AC() != 0) { + goto zero; + } + if (z <= lim) { + goto one; + } + if (D_8011F9C4 == 0) { + goto zero; + } + if (((u8)func_80029178(0x21)) != 0) { + goto zero; + } +one: + doit = 1; + goto join; +zero: + doit = 0; +join: + if (doit != 0) { + D_80185014[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 0); + ((void (*)(s32))func_80159B70)(arg0); + func_80154150(arg0, 9); + ((void (*)(s32, s32 *))func_80146DB8)(arg0, &D_80184FA8); + ((void (*)(s32, s32))func_80161CD0)(arg0, *(u16 *)(arg0 + 0x16E)); + return; + } + if (func_80161208(arg0) == 0) { + ((void (*)(s32))func_801725A4)(arg0); + } +} DEFINE_func_8015BD8C() /* dedup: shared engine-core @0x8015BD8C (src/shared) */ diff --git a/src/ov_SC01_074/ov_SC01_074_jr_8015AE2C.c b/src/ov_SC01_074/ov_SC01_074_jr_8015AE2C.c index f73325870..f1a3c0b7c 100644 --- a/src/ov_SC01_074/ov_SC01_074_jr_8015AE2C.c +++ b/src/ov_SC01_074/ov_SC01_074_jr_8015AE2C.c @@ -1513,7 +1513,259 @@ DEFINE_func_8015B858() /* dedup: shared engine-core @0x8015B858 (src/shared) */ DEFINE_func_8015B8F8() /* dedup: shared engine-core @0x8015B8F8 (src/shared) */ -INCLUDE_ASM("asm/ov_SC01_074/nonmatchings/ov_SC01_074_jr_8015AE2C", func_8015B950); +extern s32 func_8015AE2C(); + +// @class: plumbing +// @stuck: none — MATCH (271/271, pin-free, zero asm). The ONLY residual is DEF-SIDE plumbing, and it is now named exactly: the in-TU instantiation `DEFINE_func_8015BEE4()` (engine_core.h:1851-1855) expands to `extern s32 func_8015B950(void);` INSIDE ov_SC01_077_jr_8015AE2C.c, ~14 lines BELOW this definition, so the 1-param def collides with a `(void)` prototype -> `conflicting types for func_8015B950` (.run/bank_func_8015B950.log). §73 PARAMS axis / T0. Surgical fix = §65b de-macroize that ONE instantiation (blast radius: this TU); the fleet-wide `(void)`->`()` header edit is §63 and must be R22-validated. +/* func_8015B950 (ov_SC01_077_jr_8015AE2C, 271 ins, jtbl_801D8B74) — SESSION-21 re-verified + * + * ── ROUND-2 INDEPENDENT RE-VERIFICATION (2026-07-27, fresh agent, §88e discipline) ───────────── + * match_one : MATCH (271 ins) against the CURRENT tree — §87 staleness re-checked today. + * .text size: compiled .text = 0x43C = 1084 B = 271 ins, EXACTLY the target's declared 0x43C + * ("nonmatching func_8015B950, 0x43C"). So this is NOT a §83a length drift hiding + * behind a zero count — the count is over equal-length streams. + * jtbl : RE-DECODED MECHANICALLY, not inherited. Compiled .rodata = 0x1C = 28 B = 7 words, + * 7x R_MIPS_32 -> .text with implicit addends [58,58,58,E0,F0,100,58]; +0x8015B950 + * = [8015B9A8, 8015B9A8, 8015B9A8, 8015BA30, 8015BA40, 8015BA50, 8015B9A8]. + * Diffed word-for-word against asm/ov_SC01_077/data/tail14.data.s:15-23 — 7/7 identical. + * symcheck : SYMS-DIFF target=35 draft=34, sole MISSING = jtbl_801D8B74. This is the §81 jr + * FALSE POSITIVE, re-confirmed here by reading the relocs: gcc emits its OWN table and + * references it with R_MIPS_HI16/LO16 against the SECTION `.rodata` (t.o +0x40/+0x48), + * so the splat's dlabel NAME can never appear in the draft object's relocation set. + * Nothing is dropped and nothing is invented: the draft's other 34 symbols are exactly + * the target's other 34. + * FAMILY : the x138 remap is clean and §84-safe. Every sibling is 271 ins with an IDENTICAL + * callee set; only THREE names vary per overlay — the two data labels and the jtbl: + * ov_SC01_077 D_80180C28 / D_80180C94 / jtbl_801D8B74 + * ov_SC03_099 D_80185A50 / D_80185ABC / jtbl_801BD898 + * ov_SC06_008 D_80187E44 / D_80187EB0 / jtbl_801A8734 + * The pair is always +0x6C apart, and NO literal in this draft encodes that distance + * (both labels are referenced by name), so there is no §84 derived-offset hazard. + * D_8011F9C4 is fleet-constant (main-EXE data) and must NOT be remapped. + * + * match_one: MATCH (271 ins) against the CURRENT tree (§87 staleness re-checked, 2026-07-27). + * PIN-FREE, zero asm, offset-pure (s32 arg0 + raw offsets) — x138 template-safe. + * Provenance: this is the Phase-26 crack (.run/phase26-cracks/func_8015B950.c) re-gated verbatim, + * with ONE deliberate change: the definition's return type void -> s32. + * - `void func_8015B950(s32 arg0)` : MATCH (271 ins) [the Phase-26 form] + * - `s32 func_8015B950(s32 arg0)` : MATCH (271 ins) [shipped — §3a-1 void->s32 is byte-neutral] + * The fleet/engine_core.h canonical decl is `extern s32 func_8015B950(void);` (engine_core.h:1852), + * and the last bank attempt (.run/bank_func_8015B950.log) died on `conflicting types for + * func_8015B950`. Shipping the s32 return kills the §73 RETURN axis for free and leaves only the + * cheap T0 PARAMS axis for the ladder (fix_header_decl.py / --fix-def-sig / cast_call_sites). + * Both forms are byte-identical, so the orchestrator may swap the return type back at zero cost. + * + * SYMBOLS (§58 rules 1/2 — all splat spellings, all verified present): + * D_80180C94 asm/ov_SC01_077/data/tail.data.s:4355 (the state-handler vtable) + * D_80180C28 asm/ov_SC01_077/data/tail.data.s:4293 + * D_8011F9C4 main-EXE data; spelled `extern s32 D_8011F9C4;` in 5+ already-banked TUs + * jtbl_801D8B74 asm/ov_SC01_077/data/tail14.data.s:15 (compiler jump table — not named in C) + * + * JTBL VERIFIED (§8a gate): compiled .rodata = exactly 0x1C B / 7 words, 7x R_MIPS_32 .text with + * addends [0x58,0x58,0x58,0xE0,0xF0,0x100,0x58] -> +0x8015B950 = [B9A8,B9A8,B9A8,BA30,BA40,BA50, + * B9A8] == the original words at 0x801D8B74..0x801D8B8C. Bound `sltiu $v0,$v1,0x7` matches. + * The raw dlabel's 8th word 0x00000000 is NOT an entry — it is the intra-TU `.align 3` pad of the + * B34/B54/B74 jtbl chain; the object can never emit it (maspsx drops .align), so it must stay in + * the post-carve RAW data piece (the §53/§62/§81 carve chain applies at bank time). + * + * Same family as the TU's own already-matched func_8015AE2C: 7-case switch on ((s32 (*)(s32))func_801619A4)() + * (0/1/2/6 shared, 3/4/5 own, no default block — out-of-range and every `break` fall to the + * after-switch join), then a chain of "state handler" tests, each dispatching + * D_80180C94[*(u16*)arg0](arg0) and returning. + * + * THREE LEVERS (draft -> MATCH in 3 compiles): + * + * 1. PROLOGUE CONSTANT = an INITIALIZED LOCAL, not a literal in the compare. + * Target opens with `lui $s2, 0xFFF5` in the *prologue*, used once ~200 ins later in + * `slt $v0,$s2,$s1`. No gcc-2.7.2 pass hoists a (set reg const_int) across basic blocks + * (loop.c needs a loop; cse/combine/sched never move insns between BBs) — so the insn must + * have been EMITTED in the first BB, i.e. the constant is a local initialized at the top of + * the function. cse then cannot fold it back into the compare: the `slt` operand predicate is + * `arith_operand`, which rejects a CONST_INT wider than 16 bits, so validate_change fails and + * the pseudo survives. Its live range spans every call -> global.c gives it a callee-saved reg. + * Writing `z > -0xB0000` inline instead emits the `lui` into the branch delay slot next to the + * compare (caller-saved $v0) and the function is 1 insn short. => `s32 lim = -0xB0000;` at top. + * + * 2. `lh` vs `lhu`: a short->short copy is a pure HImode move and gcc emits `lhu`. The target's + * `lh $v0,0x26($s0)` means the value passed through an SImode (int) temp: expand makes + * (set (reg:SI) (sign_extend (mem:HI))) + (set (mem:HI) (subreg:HI ...)), and combine cannot + * merge them (the merged form is mem<-mem, which no movhi accepts) so the sign-extending load + * survives. => route both halfword copies through the `s32 t` temp. + * + * 3. THE `goto` LAYOUT — dodging jump.c's store-flag conversion (jump.c:1005-1065). + * An if/else chain writing 0/1 into `doit` makes gcc collapse the last pair into + * `sltiu $v0,$v0,1`. jump.c fires that conversion when the insn immediately after a + * conditional jump is a lone `SET pseudo, CONST_INT` whose following simplejump targets the + * SAME label as the branch (jump.c:1038 `reallabelprev == temp || ... JUMP_LABEL(temp4) == + * JUMP_LABEL(insn)`) — exactly the shape of `if (c) x=0; else x=1;`. + * The target instead cross-jumps ALL the `doit=0` exits into ONE shared block placed after the + * `doit=1` fall-through; reorg's fill_slots_from_thread then COPIES that single set into all + * three branch delay slots and redirects each branch past it (which is why `addu $v0,$zero, + * $zero` appears 3x in delay slots and the shared block vanishes). A `goto zero;` / `goto one;` + * chain expresses that layout directly, and each conditional jump is then followed by a + * compare/call rather than a lone const set, so the store-flag conversion never triggers. + * GENERAL RULE: multiple predicates that all assign the SAME constant to one flag => write + * them as `goto` to a shared assignment, never as an if/else ladder. + */ +extern s32 D_8011F9C4; +extern s32 D_80180C28; + +extern s32 func_80161B18(void); +extern s32 func_801619A4(s32*); +extern s32 func_80149AA8(s32*); +extern void func_80149AD4(s32*); +extern s32 func_80149B54(s32*); +extern void func_80149BAC(s32*); +extern s32 func_801498E0(s32*); +extern s32 func_80149954(s32); +extern s32 func_80149A64(s32*); +extern void func_800CCCC0(s32 a0); +extern s32 func_80149CD4(s32 a0); +extern void func_8015E880(s32*); +extern s32 func_80149744(struct S_80149744*); +extern void func_80149788(void); +extern s32 func_801496D4(void*); +extern void func_80149704(void); +extern int func_80148AFC(void*); +extern void func_80146D90(s32 a0); +extern void func_80154150(s32 a0, s32 a1); +extern void func_801541D8(u8*, s32, s32); +extern s32 func_801488A8(u8*); +extern void func_80147078(s32*, s16); +extern void func_8015A264(void*); +extern s32 func_80013294(void*, void*); +extern void func_80159B70(void*); +extern s32 func_8016F1AC(void); +extern s32 func_80029178(s32 a0); +extern void func_80146DB8(s32*, s32*); +extern s32 func_80161CD0(s32, s32); +extern s32 func_80161208(s32 a0); +extern s32 func_801725A4(u8*); + +s32 func_8015B950(s32 arg0) +{ + + extern void (*D_80180C94[])(void *); + s16 sp10[4]; + s16 sp18[4]; + s32 t; + s32 z; + s32 doit; + s32 lim = -0xB0000; + + if (func_80161B18() != 0) { + return; + } + switch (((s32 (*)(s32))func_801619A4)(arg0)) { + case 0: + case 1: + case 2: + case 6: + if (((s32 (*)(s32))func_80149AA8)(arg0) != 0) { + D_80180C94[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149AD4)(arg0); + return; + } + if (((s32 (*)(s32))func_80149B54)(arg0) != 0) { + D_80180C94[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149BAC)(arg0); + return; + } + break; + case 3: + ((void (*)(s32))func_801498E0)(arg0); + break; + case 4: + ((void (*)(s32))func_80149954)(arg0); + break; + case 5: + if (((s32 (*)(s32))func_80149A64)(arg0) != 0) { + D_80180C94[*(u16 *)arg0]((void *)arg0); + func_800CCCC0(arg0); + return; + } + break; + } + if (func_80149CD4(arg0) != 0) { + D_80180C94[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_8015E880)(arg0); + return; + } + if (((s32 (*)(s32))func_80149744)(arg0) != 0) { + D_80180C94[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149788)(arg0); + return; + } + if (((s32 (*)(s32))func_801496D4)(arg0) != 0) { + D_80180C94[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149704)(arg0); + if (((u8)((s32 (*)(s32))func_80148AFC)(arg0)) == 0) { + func_80146D90(arg0); + } + if ((*(s32 *)(arg0 + 0x24) | *(s32 *)(arg0 + 0x2C)) != 0) { + func_80154150(arg0, 0xF); + } else { + ((void (*)(s32, s32, s32))func_801541D8)(arg0, 0xD, 6); + } + *(s32 *)(arg0 + 0x238) = 1; + return; + } + if (((s32 (*)(s32))func_801488A8)(arg0) != 0) { + sp10[0] = 0; + sp10[1] = 0; + sp10[2] = 0; + t = *(s16 *)(arg0 + 0x26); + sp18[0] = t; + sp18[1] = 0; + t = *(s16 *)(arg0 + 0x2E); + sp18[2] = t; + D_80180C94[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 1); + ((void (*)(s32))func_8015A264)(arg0); + t = -(((s32 (*)(s16 *, s16 *))func_80013294)(sp10, sp18) << 0x10); + if (t < *(s32 *)(arg0 + 0x2C)) { + *(s32 *)(arg0 + 0x2C) = t; + } + return; + } + if (*(u16 *)(arg0 + 0xB8) == 0x8000) { + D_80180C94[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 0); + ((void (*)(s32))func_80159B70)(arg0); + return; + } + z = *(s32 *)(arg0 + 0x2C); + if (func_8016F1AC() != 0) { + goto zero; + } + if (z <= lim) { + goto one; + } + if (D_8011F9C4 == 0) { + goto zero; + } + if (((u8)func_80029178(0x21)) != 0) { + goto zero; + } +one: + doit = 1; + goto join; +zero: + doit = 0; +join: + if (doit != 0) { + D_80180C94[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 0); + ((void (*)(s32))func_80159B70)(arg0); + func_80154150(arg0, 9); + ((void (*)(s32, s32 *))func_80146DB8)(arg0, &D_80180C28); + ((void (*)(s32, s32))func_80161CD0)(arg0, *(u16 *)(arg0 + 0x16E)); + return; + } + if (func_80161208(arg0) == 0) { + ((void (*)(s32))func_801725A4)(arg0); + } +} DEFINE_func_8015BD8C() /* dedup: shared engine-core @0x8015BD8C (src/shared) */ diff --git a/src/ov_SC01_080/ov_SC01_080_jr_8015AE2C.c b/src/ov_SC01_080/ov_SC01_080_jr_8015AE2C.c index 116cb921b..265e725de 100644 --- a/src/ov_SC01_080/ov_SC01_080_jr_8015AE2C.c +++ b/src/ov_SC01_080/ov_SC01_080_jr_8015AE2C.c @@ -1513,7 +1513,259 @@ DEFINE_func_8015B858() /* dedup: shared engine-core @0x8015B858 (src/shared) */ DEFINE_func_8015B8F8() /* dedup: shared engine-core @0x8015B8F8 (src/shared) */ -INCLUDE_ASM("asm/ov_SC01_080/nonmatchings/ov_SC01_080_jr_8015AE2C", func_8015B950); +extern s32 func_8015AE2C(); + +// @class: plumbing +// @stuck: none — MATCH (271/271, pin-free, zero asm). The ONLY residual is DEF-SIDE plumbing, and it is now named exactly: the in-TU instantiation `DEFINE_func_8015BEE4()` (engine_core.h:1851-1855) expands to `extern s32 func_8015B950(void);` INSIDE ov_SC01_077_jr_8015AE2C.c, ~14 lines BELOW this definition, so the 1-param def collides with a `(void)` prototype -> `conflicting types for func_8015B950` (.run/bank_func_8015B950.log). §73 PARAMS axis / T0. Surgical fix = §65b de-macroize that ONE instantiation (blast radius: this TU); the fleet-wide `(void)`->`()` header edit is §63 and must be R22-validated. +/* func_8015B950 (ov_SC01_077_jr_8015AE2C, 271 ins, jtbl_801D8B74) — SESSION-21 re-verified + * + * ── ROUND-2 INDEPENDENT RE-VERIFICATION (2026-07-27, fresh agent, §88e discipline) ───────────── + * match_one : MATCH (271 ins) against the CURRENT tree — §87 staleness re-checked today. + * .text size: compiled .text = 0x43C = 1084 B = 271 ins, EXACTLY the target's declared 0x43C + * ("nonmatching func_8015B950, 0x43C"). So this is NOT a §83a length drift hiding + * behind a zero count — the count is over equal-length streams. + * jtbl : RE-DECODED MECHANICALLY, not inherited. Compiled .rodata = 0x1C = 28 B = 7 words, + * 7x R_MIPS_32 -> .text with implicit addends [58,58,58,E0,F0,100,58]; +0x8015B950 + * = [8015B9A8, 8015B9A8, 8015B9A8, 8015BA30, 8015BA40, 8015BA50, 8015B9A8]. + * Diffed word-for-word against asm/ov_SC01_077/data/tail14.data.s:15-23 — 7/7 identical. + * symcheck : SYMS-DIFF target=35 draft=34, sole MISSING = jtbl_801D8B74. This is the §81 jr + * FALSE POSITIVE, re-confirmed here by reading the relocs: gcc emits its OWN table and + * references it with R_MIPS_HI16/LO16 against the SECTION `.rodata` (t.o +0x40/+0x48), + * so the splat's dlabel NAME can never appear in the draft object's relocation set. + * Nothing is dropped and nothing is invented: the draft's other 34 symbols are exactly + * the target's other 34. + * FAMILY : the x138 remap is clean and §84-safe. Every sibling is 271 ins with an IDENTICAL + * callee set; only THREE names vary per overlay — the two data labels and the jtbl: + * ov_SC01_077 D_80185B88 / D_80185BF4 / jtbl_801D8B74 + * ov_SC03_099 D_80185A50 / D_80185ABC / jtbl_801BD898 + * ov_SC06_008 D_80187E44 / D_80187EB0 / jtbl_801A8734 + * The pair is always +0x6C apart, and NO literal in this draft encodes that distance + * (both labels are referenced by name), so there is no §84 derived-offset hazard. + * D_8011F9C4 is fleet-constant (main-EXE data) and must NOT be remapped. + * + * match_one: MATCH (271 ins) against the CURRENT tree (§87 staleness re-checked, 2026-07-27). + * PIN-FREE, zero asm, offset-pure (s32 arg0 + raw offsets) — x138 template-safe. + * Provenance: this is the Phase-26 crack (.run/phase26-cracks/func_8015B950.c) re-gated verbatim, + * with ONE deliberate change: the definition's return type void -> s32. + * - `void func_8015B950(s32 arg0)` : MATCH (271 ins) [the Phase-26 form] + * - `s32 func_8015B950(s32 arg0)` : MATCH (271 ins) [shipped — §3a-1 void->s32 is byte-neutral] + * The fleet/engine_core.h canonical decl is `extern s32 func_8015B950(void);` (engine_core.h:1852), + * and the last bank attempt (.run/bank_func_8015B950.log) died on `conflicting types for + * func_8015B950`. Shipping the s32 return kills the §73 RETURN axis for free and leaves only the + * cheap T0 PARAMS axis for the ladder (fix_header_decl.py / --fix-def-sig / cast_call_sites). + * Both forms are byte-identical, so the orchestrator may swap the return type back at zero cost. + * + * SYMBOLS (§58 rules 1/2 — all splat spellings, all verified present): + * D_80185BF4 asm/ov_SC01_077/data/tail.data.s:4355 (the state-handler vtable) + * D_80185B88 asm/ov_SC01_077/data/tail.data.s:4293 + * D_8011F9C4 main-EXE data; spelled `extern s32 D_8011F9C4;` in 5+ already-banked TUs + * jtbl_801D8B74 asm/ov_SC01_077/data/tail14.data.s:15 (compiler jump table — not named in C) + * + * JTBL VERIFIED (§8a gate): compiled .rodata = exactly 0x1C B / 7 words, 7x R_MIPS_32 .text with + * addends [0x58,0x58,0x58,0xE0,0xF0,0x100,0x58] -> +0x8015B950 = [B9A8,B9A8,B9A8,BA30,BA40,BA50, + * B9A8] == the original words at 0x801D8B74..0x801D8B8C. Bound `sltiu $v0,$v1,0x7` matches. + * The raw dlabel's 8th word 0x00000000 is NOT an entry — it is the intra-TU `.align 3` pad of the + * B34/B54/B74 jtbl chain; the object can never emit it (maspsx drops .align), so it must stay in + * the post-carve RAW data piece (the §53/§62/§81 carve chain applies at bank time). + * + * Same family as the TU's own already-matched func_8015AE2C: 7-case switch on ((s32 (*)(s32))func_801619A4)() + * (0/1/2/6 shared, 3/4/5 own, no default block — out-of-range and every `break` fall to the + * after-switch join), then a chain of "state handler" tests, each dispatching + * D_80185BF4[*(u16*)arg0](arg0) and returning. + * + * THREE LEVERS (draft -> MATCH in 3 compiles): + * + * 1. PROLOGUE CONSTANT = an INITIALIZED LOCAL, not a literal in the compare. + * Target opens with `lui $s2, 0xFFF5` in the *prologue*, used once ~200 ins later in + * `slt $v0,$s2,$s1`. No gcc-2.7.2 pass hoists a (set reg const_int) across basic blocks + * (loop.c needs a loop; cse/combine/sched never move insns between BBs) — so the insn must + * have been EMITTED in the first BB, i.e. the constant is a local initialized at the top of + * the function. cse then cannot fold it back into the compare: the `slt` operand predicate is + * `arith_operand`, which rejects a CONST_INT wider than 16 bits, so validate_change fails and + * the pseudo survives. Its live range spans every call -> global.c gives it a callee-saved reg. + * Writing `z > -0xB0000` inline instead emits the `lui` into the branch delay slot next to the + * compare (caller-saved $v0) and the function is 1 insn short. => `s32 lim = -0xB0000;` at top. + * + * 2. `lh` vs `lhu`: a short->short copy is a pure HImode move and gcc emits `lhu`. The target's + * `lh $v0,0x26($s0)` means the value passed through an SImode (int) temp: expand makes + * (set (reg:SI) (sign_extend (mem:HI))) + (set (mem:HI) (subreg:HI ...)), and combine cannot + * merge them (the merged form is mem<-mem, which no movhi accepts) so the sign-extending load + * survives. => route both halfword copies through the `s32 t` temp. + * + * 3. THE `goto` LAYOUT — dodging jump.c's store-flag conversion (jump.c:1005-1065). + * An if/else chain writing 0/1 into `doit` makes gcc collapse the last pair into + * `sltiu $v0,$v0,1`. jump.c fires that conversion when the insn immediately after a + * conditional jump is a lone `SET pseudo, CONST_INT` whose following simplejump targets the + * SAME label as the branch (jump.c:1038 `reallabelprev == temp || ... JUMP_LABEL(temp4) == + * JUMP_LABEL(insn)`) — exactly the shape of `if (c) x=0; else x=1;`. + * The target instead cross-jumps ALL the `doit=0` exits into ONE shared block placed after the + * `doit=1` fall-through; reorg's fill_slots_from_thread then COPIES that single set into all + * three branch delay slots and redirects each branch past it (which is why `addu $v0,$zero, + * $zero` appears 3x in delay slots and the shared block vanishes). A `goto zero;` / `goto one;` + * chain expresses that layout directly, and each conditional jump is then followed by a + * compare/call rather than a lone const set, so the store-flag conversion never triggers. + * GENERAL RULE: multiple predicates that all assign the SAME constant to one flag => write + * them as `goto` to a shared assignment, never as an if/else ladder. + */ +extern s32 D_8011F9C4; +extern s32 D_80185B88; + +extern s32 func_80161B18(void); +extern s32 func_801619A4(s32*); +extern s32 func_80149AA8(s32*); +extern void func_80149AD4(s32*); +extern s32 func_80149B54(s32*); +extern void func_80149BAC(s32*); +extern s32 func_801498E0(s32*); +extern s32 func_80149954(s32); +extern s32 func_80149A64(s32*); +extern void func_800CCCC0(s32 a0); +extern s32 func_80149CD4(s32 a0); +extern void func_8015E880(s32*); +extern s32 func_80149744(struct S_80149744*); +extern void func_80149788(void); +extern s32 func_801496D4(void*); +extern void func_80149704(void); +extern int func_80148AFC(void*); +extern void func_80146D90(s32 a0); +extern void func_80154150(s32 a0, s32 a1); +extern void func_801541D8(u8*, s32, s32); +extern s32 func_801488A8(u8*); +extern void func_80147078(s32*, s16); +extern void func_8015A264(void*); +extern s32 func_80013294(void*, void*); +extern void func_80159B70(void*); +extern s32 func_8016F1AC(void); +extern s32 func_80029178(s32 a0); +extern void func_80146DB8(s32*, s32*); +extern s32 func_80161CD0(s32, s32); +extern s32 func_80161208(s32 a0); +extern s32 func_801725A4(u8*); + +s32 func_8015B950(s32 arg0) +{ + + extern void (*D_80185BF4[])(void *); + s16 sp10[4]; + s16 sp18[4]; + s32 t; + s32 z; + s32 doit; + s32 lim = -0xB0000; + + if (func_80161B18() != 0) { + return; + } + switch (((s32 (*)(s32))func_801619A4)(arg0)) { + case 0: + case 1: + case 2: + case 6: + if (((s32 (*)(s32))func_80149AA8)(arg0) != 0) { + D_80185BF4[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149AD4)(arg0); + return; + } + if (((s32 (*)(s32))func_80149B54)(arg0) != 0) { + D_80185BF4[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149BAC)(arg0); + return; + } + break; + case 3: + ((void (*)(s32))func_801498E0)(arg0); + break; + case 4: + ((void (*)(s32))func_80149954)(arg0); + break; + case 5: + if (((s32 (*)(s32))func_80149A64)(arg0) != 0) { + D_80185BF4[*(u16 *)arg0]((void *)arg0); + func_800CCCC0(arg0); + return; + } + break; + } + if (func_80149CD4(arg0) != 0) { + D_80185BF4[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_8015E880)(arg0); + return; + } + if (((s32 (*)(s32))func_80149744)(arg0) != 0) { + D_80185BF4[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149788)(arg0); + return; + } + if (((s32 (*)(s32))func_801496D4)(arg0) != 0) { + D_80185BF4[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149704)(arg0); + if (((u8)((s32 (*)(s32))func_80148AFC)(arg0)) == 0) { + func_80146D90(arg0); + } + if ((*(s32 *)(arg0 + 0x24) | *(s32 *)(arg0 + 0x2C)) != 0) { + func_80154150(arg0, 0xF); + } else { + ((void (*)(s32, s32, s32))func_801541D8)(arg0, 0xD, 6); + } + *(s32 *)(arg0 + 0x238) = 1; + return; + } + if (((s32 (*)(s32))func_801488A8)(arg0) != 0) { + sp10[0] = 0; + sp10[1] = 0; + sp10[2] = 0; + t = *(s16 *)(arg0 + 0x26); + sp18[0] = t; + sp18[1] = 0; + t = *(s16 *)(arg0 + 0x2E); + sp18[2] = t; + D_80185BF4[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 1); + ((void (*)(s32))func_8015A264)(arg0); + t = -(((s32 (*)(s16 *, s16 *))func_80013294)(sp10, sp18) << 0x10); + if (t < *(s32 *)(arg0 + 0x2C)) { + *(s32 *)(arg0 + 0x2C) = t; + } + return; + } + if (*(u16 *)(arg0 + 0xB8) == 0x8000) { + D_80185BF4[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 0); + ((void (*)(s32))func_80159B70)(arg0); + return; + } + z = *(s32 *)(arg0 + 0x2C); + if (func_8016F1AC() != 0) { + goto zero; + } + if (z <= lim) { + goto one; + } + if (D_8011F9C4 == 0) { + goto zero; + } + if (((u8)func_80029178(0x21)) != 0) { + goto zero; + } +one: + doit = 1; + goto join; +zero: + doit = 0; +join: + if (doit != 0) { + D_80185BF4[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 0); + ((void (*)(s32))func_80159B70)(arg0); + func_80154150(arg0, 9); + ((void (*)(s32, s32 *))func_80146DB8)(arg0, &D_80185B88); + ((void (*)(s32, s32))func_80161CD0)(arg0, *(u16 *)(arg0 + 0x16E)); + return; + } + if (func_80161208(arg0) == 0) { + ((void (*)(s32))func_801725A4)(arg0); + } +} DEFINE_func_8015BD8C() /* dedup: shared engine-core @0x8015BD8C (src/shared) */ diff --git a/src/ov_SC01_084/ov_SC01_084_jr_8015AE2C.c b/src/ov_SC01_084/ov_SC01_084_jr_8015AE2C.c index 5024557e8..35a14d636 100644 --- a/src/ov_SC01_084/ov_SC01_084_jr_8015AE2C.c +++ b/src/ov_SC01_084/ov_SC01_084_jr_8015AE2C.c @@ -1513,7 +1513,259 @@ DEFINE_func_8015B858() /* dedup: shared engine-core @0x8015B858 (src/shared) */ DEFINE_func_8015B8F8() /* dedup: shared engine-core @0x8015B8F8 (src/shared) */ -INCLUDE_ASM("asm/ov_SC01_084/nonmatchings/ov_SC01_084_jr_8015AE2C", func_8015B950); +extern s32 func_8015AE2C(); + +// @class: plumbing +// @stuck: none — MATCH (271/271, pin-free, zero asm). The ONLY residual is DEF-SIDE plumbing, and it is now named exactly: the in-TU instantiation `DEFINE_func_8015BEE4()` (engine_core.h:1851-1855) expands to `extern s32 func_8015B950(void);` INSIDE ov_SC01_077_jr_8015AE2C.c, ~14 lines BELOW this definition, so the 1-param def collides with a `(void)` prototype -> `conflicting types for func_8015B950` (.run/bank_func_8015B950.log). §73 PARAMS axis / T0. Surgical fix = §65b de-macroize that ONE instantiation (blast radius: this TU); the fleet-wide `(void)`->`()` header edit is §63 and must be R22-validated. +/* func_8015B950 (ov_SC01_077_jr_8015AE2C, 271 ins, jtbl_801D8B74) — SESSION-21 re-verified + * + * ── ROUND-2 INDEPENDENT RE-VERIFICATION (2026-07-27, fresh agent, §88e discipline) ───────────── + * match_one : MATCH (271 ins) against the CURRENT tree — §87 staleness re-checked today. + * .text size: compiled .text = 0x43C = 1084 B = 271 ins, EXACTLY the target's declared 0x43C + * ("nonmatching func_8015B950, 0x43C"). So this is NOT a §83a length drift hiding + * behind a zero count — the count is over equal-length streams. + * jtbl : RE-DECODED MECHANICALLY, not inherited. Compiled .rodata = 0x1C = 28 B = 7 words, + * 7x R_MIPS_32 -> .text with implicit addends [58,58,58,E0,F0,100,58]; +0x8015B950 + * = [8015B9A8, 8015B9A8, 8015B9A8, 8015BA30, 8015BA40, 8015BA50, 8015B9A8]. + * Diffed word-for-word against asm/ov_SC01_077/data/tail14.data.s:15-23 — 7/7 identical. + * symcheck : SYMS-DIFF target=35 draft=34, sole MISSING = jtbl_801D8B74. This is the §81 jr + * FALSE POSITIVE, re-confirmed here by reading the relocs: gcc emits its OWN table and + * references it with R_MIPS_HI16/LO16 against the SECTION `.rodata` (t.o +0x40/+0x48), + * so the splat's dlabel NAME can never appear in the draft object's relocation set. + * Nothing is dropped and nothing is invented: the draft's other 34 symbols are exactly + * the target's other 34. + * FAMILY : the x138 remap is clean and §84-safe. Every sibling is 271 ins with an IDENTICAL + * callee set; only THREE names vary per overlay — the two data labels and the jtbl: + * ov_SC01_077 D_80188E7C / D_80188EE8 / jtbl_801D8B74 + * ov_SC03_099 D_80185A50 / D_80185ABC / jtbl_801BD898 + * ov_SC06_008 D_80187E44 / D_80187EB0 / jtbl_801A8734 + * The pair is always +0x6C apart, and NO literal in this draft encodes that distance + * (both labels are referenced by name), so there is no §84 derived-offset hazard. + * D_8011F9C4 is fleet-constant (main-EXE data) and must NOT be remapped. + * + * match_one: MATCH (271 ins) against the CURRENT tree (§87 staleness re-checked, 2026-07-27). + * PIN-FREE, zero asm, offset-pure (s32 arg0 + raw offsets) — x138 template-safe. + * Provenance: this is the Phase-26 crack (.run/phase26-cracks/func_8015B950.c) re-gated verbatim, + * with ONE deliberate change: the definition's return type void -> s32. + * - `void func_8015B950(s32 arg0)` : MATCH (271 ins) [the Phase-26 form] + * - `s32 func_8015B950(s32 arg0)` : MATCH (271 ins) [shipped — §3a-1 void->s32 is byte-neutral] + * The fleet/engine_core.h canonical decl is `extern s32 func_8015B950(void);` (engine_core.h:1852), + * and the last bank attempt (.run/bank_func_8015B950.log) died on `conflicting types for + * func_8015B950`. Shipping the s32 return kills the §73 RETURN axis for free and leaves only the + * cheap T0 PARAMS axis for the ladder (fix_header_decl.py / --fix-def-sig / cast_call_sites). + * Both forms are byte-identical, so the orchestrator may swap the return type back at zero cost. + * + * SYMBOLS (§58 rules 1/2 — all splat spellings, all verified present): + * D_80188EE8 asm/ov_SC01_077/data/tail.data.s:4355 (the state-handler vtable) + * D_80188E7C asm/ov_SC01_077/data/tail.data.s:4293 + * D_8011F9C4 main-EXE data; spelled `extern s32 D_8011F9C4;` in 5+ already-banked TUs + * jtbl_801D8B74 asm/ov_SC01_077/data/tail14.data.s:15 (compiler jump table — not named in C) + * + * JTBL VERIFIED (§8a gate): compiled .rodata = exactly 0x1C B / 7 words, 7x R_MIPS_32 .text with + * addends [0x58,0x58,0x58,0xE0,0xF0,0x100,0x58] -> +0x8015B950 = [B9A8,B9A8,B9A8,BA30,BA40,BA50, + * B9A8] == the original words at 0x801D8B74..0x801D8B8C. Bound `sltiu $v0,$v1,0x7` matches. + * The raw dlabel's 8th word 0x00000000 is NOT an entry — it is the intra-TU `.align 3` pad of the + * B34/B54/B74 jtbl chain; the object can never emit it (maspsx drops .align), so it must stay in + * the post-carve RAW data piece (the §53/§62/§81 carve chain applies at bank time). + * + * Same family as the TU's own already-matched func_8015AE2C: 7-case switch on ((s32 (*)(s32))func_801619A4)() + * (0/1/2/6 shared, 3/4/5 own, no default block — out-of-range and every `break` fall to the + * after-switch join), then a chain of "state handler" tests, each dispatching + * D_80188EE8[*(u16*)arg0](arg0) and returning. + * + * THREE LEVERS (draft -> MATCH in 3 compiles): + * + * 1. PROLOGUE CONSTANT = an INITIALIZED LOCAL, not a literal in the compare. + * Target opens with `lui $s2, 0xFFF5` in the *prologue*, used once ~200 ins later in + * `slt $v0,$s2,$s1`. No gcc-2.7.2 pass hoists a (set reg const_int) across basic blocks + * (loop.c needs a loop; cse/combine/sched never move insns between BBs) — so the insn must + * have been EMITTED in the first BB, i.e. the constant is a local initialized at the top of + * the function. cse then cannot fold it back into the compare: the `slt` operand predicate is + * `arith_operand`, which rejects a CONST_INT wider than 16 bits, so validate_change fails and + * the pseudo survives. Its live range spans every call -> global.c gives it a callee-saved reg. + * Writing `z > -0xB0000` inline instead emits the `lui` into the branch delay slot next to the + * compare (caller-saved $v0) and the function is 1 insn short. => `s32 lim = -0xB0000;` at top. + * + * 2. `lh` vs `lhu`: a short->short copy is a pure HImode move and gcc emits `lhu`. The target's + * `lh $v0,0x26($s0)` means the value passed through an SImode (int) temp: expand makes + * (set (reg:SI) (sign_extend (mem:HI))) + (set (mem:HI) (subreg:HI ...)), and combine cannot + * merge them (the merged form is mem<-mem, which no movhi accepts) so the sign-extending load + * survives. => route both halfword copies through the `s32 t` temp. + * + * 3. THE `goto` LAYOUT — dodging jump.c's store-flag conversion (jump.c:1005-1065). + * An if/else chain writing 0/1 into `doit` makes gcc collapse the last pair into + * `sltiu $v0,$v0,1`. jump.c fires that conversion when the insn immediately after a + * conditional jump is a lone `SET pseudo, CONST_INT` whose following simplejump targets the + * SAME label as the branch (jump.c:1038 `reallabelprev == temp || ... JUMP_LABEL(temp4) == + * JUMP_LABEL(insn)`) — exactly the shape of `if (c) x=0; else x=1;`. + * The target instead cross-jumps ALL the `doit=0` exits into ONE shared block placed after the + * `doit=1` fall-through; reorg's fill_slots_from_thread then COPIES that single set into all + * three branch delay slots and redirects each branch past it (which is why `addu $v0,$zero, + * $zero` appears 3x in delay slots and the shared block vanishes). A `goto zero;` / `goto one;` + * chain expresses that layout directly, and each conditional jump is then followed by a + * compare/call rather than a lone const set, so the store-flag conversion never triggers. + * GENERAL RULE: multiple predicates that all assign the SAME constant to one flag => write + * them as `goto` to a shared assignment, never as an if/else ladder. + */ +extern s32 D_8011F9C4; +extern s32 D_80188E7C; + +extern s32 func_80161B18(void); +extern s32 func_801619A4(s32*); +extern s32 func_80149AA8(s32*); +extern void func_80149AD4(s32*); +extern s32 func_80149B54(s32*); +extern void func_80149BAC(s32*); +extern s32 func_801498E0(s32*); +extern s32 func_80149954(s32); +extern s32 func_80149A64(s32*); +extern void func_800CCCC0(s32 a0); +extern s32 func_80149CD4(s32 a0); +extern void func_8015E880(s32*); +extern s32 func_80149744(struct S_80149744*); +extern void func_80149788(void); +extern s32 func_801496D4(void*); +extern void func_80149704(void); +extern int func_80148AFC(void*); +extern void func_80146D90(s32 a0); +extern void func_80154150(s32 a0, s32 a1); +extern void func_801541D8(u8*, s32, s32); +extern s32 func_801488A8(u8*); +extern void func_80147078(s32*, s16); +extern void func_8015A264(void*); +extern s32 func_80013294(void*, void*); +extern void func_80159B70(void*); +extern s32 func_8016F1AC(void); +extern s32 func_80029178(s32 a0); +extern void func_80146DB8(s32*, s32*); +extern s32 func_80161CD0(s32, s32); +extern s32 func_80161208(s32 a0); +extern s32 func_801725A4(u8*); + +s32 func_8015B950(s32 arg0) +{ + + extern void (*D_80188EE8[])(void *); + s16 sp10[4]; + s16 sp18[4]; + s32 t; + s32 z; + s32 doit; + s32 lim = -0xB0000; + + if (func_80161B18() != 0) { + return; + } + switch (((s32 (*)(s32))func_801619A4)(arg0)) { + case 0: + case 1: + case 2: + case 6: + if (((s32 (*)(s32))func_80149AA8)(arg0) != 0) { + D_80188EE8[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149AD4)(arg0); + return; + } + if (((s32 (*)(s32))func_80149B54)(arg0) != 0) { + D_80188EE8[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149BAC)(arg0); + return; + } + break; + case 3: + ((void (*)(s32))func_801498E0)(arg0); + break; + case 4: + ((void (*)(s32))func_80149954)(arg0); + break; + case 5: + if (((s32 (*)(s32))func_80149A64)(arg0) != 0) { + D_80188EE8[*(u16 *)arg0]((void *)arg0); + func_800CCCC0(arg0); + return; + } + break; + } + if (func_80149CD4(arg0) != 0) { + D_80188EE8[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_8015E880)(arg0); + return; + } + if (((s32 (*)(s32))func_80149744)(arg0) != 0) { + D_80188EE8[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149788)(arg0); + return; + } + if (((s32 (*)(s32))func_801496D4)(arg0) != 0) { + D_80188EE8[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149704)(arg0); + if (((u8)((s32 (*)(s32))func_80148AFC)(arg0)) == 0) { + func_80146D90(arg0); + } + if ((*(s32 *)(arg0 + 0x24) | *(s32 *)(arg0 + 0x2C)) != 0) { + func_80154150(arg0, 0xF); + } else { + ((void (*)(s32, s32, s32))func_801541D8)(arg0, 0xD, 6); + } + *(s32 *)(arg0 + 0x238) = 1; + return; + } + if (((s32 (*)(s32))func_801488A8)(arg0) != 0) { + sp10[0] = 0; + sp10[1] = 0; + sp10[2] = 0; + t = *(s16 *)(arg0 + 0x26); + sp18[0] = t; + sp18[1] = 0; + t = *(s16 *)(arg0 + 0x2E); + sp18[2] = t; + D_80188EE8[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 1); + ((void (*)(s32))func_8015A264)(arg0); + t = -(((s32 (*)(s16 *, s16 *))func_80013294)(sp10, sp18) << 0x10); + if (t < *(s32 *)(arg0 + 0x2C)) { + *(s32 *)(arg0 + 0x2C) = t; + } + return; + } + if (*(u16 *)(arg0 + 0xB8) == 0x8000) { + D_80188EE8[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 0); + ((void (*)(s32))func_80159B70)(arg0); + return; + } + z = *(s32 *)(arg0 + 0x2C); + if (func_8016F1AC() != 0) { + goto zero; + } + if (z <= lim) { + goto one; + } + if (D_8011F9C4 == 0) { + goto zero; + } + if (((u8)func_80029178(0x21)) != 0) { + goto zero; + } +one: + doit = 1; + goto join; +zero: + doit = 0; +join: + if (doit != 0) { + D_80188EE8[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 0); + ((void (*)(s32))func_80159B70)(arg0); + func_80154150(arg0, 9); + ((void (*)(s32, s32 *))func_80146DB8)(arg0, &D_80188E7C); + ((void (*)(s32, s32))func_80161CD0)(arg0, *(u16 *)(arg0 + 0x16E)); + return; + } + if (func_80161208(arg0) == 0) { + ((void (*)(s32))func_801725A4)(arg0); + } +} DEFINE_func_8015BD8C() /* dedup: shared engine-core @0x8015BD8C (src/shared) */ diff --git a/src/ov_SC02_000/ov_SC02_000_jr_8015AE2C.c b/src/ov_SC02_000/ov_SC02_000_jr_8015AE2C.c index ec5519b21..a833c8076 100644 --- a/src/ov_SC02_000/ov_SC02_000_jr_8015AE2C.c +++ b/src/ov_SC02_000/ov_SC02_000_jr_8015AE2C.c @@ -1513,7 +1513,259 @@ DEFINE_func_8015B858() /* dedup: shared engine-core @0x8015B858 (src/shared) */ DEFINE_func_8015B8F8() /* dedup: shared engine-core @0x8015B8F8 (src/shared) */ -INCLUDE_ASM("asm/ov_SC02_000/nonmatchings/ov_SC02_000_jr_8015AE2C", func_8015B950); +extern s32 func_8015AE2C(); + +// @class: plumbing +// @stuck: none — MATCH (271/271, pin-free, zero asm). The ONLY residual is DEF-SIDE plumbing, and it is now named exactly: the in-TU instantiation `DEFINE_func_8015BEE4()` (engine_core.h:1851-1855) expands to `extern s32 func_8015B950(void);` INSIDE ov_SC01_077_jr_8015AE2C.c, ~14 lines BELOW this definition, so the 1-param def collides with a `(void)` prototype -> `conflicting types for func_8015B950` (.run/bank_func_8015B950.log). §73 PARAMS axis / T0. Surgical fix = §65b de-macroize that ONE instantiation (blast radius: this TU); the fleet-wide `(void)`->`()` header edit is §63 and must be R22-validated. +/* func_8015B950 (ov_SC01_077_jr_8015AE2C, 271 ins, jtbl_801D8B74) — SESSION-21 re-verified + * + * ── ROUND-2 INDEPENDENT RE-VERIFICATION (2026-07-27, fresh agent, §88e discipline) ───────────── + * match_one : MATCH (271 ins) against the CURRENT tree — §87 staleness re-checked today. + * .text size: compiled .text = 0x43C = 1084 B = 271 ins, EXACTLY the target's declared 0x43C + * ("nonmatching func_8015B950, 0x43C"). So this is NOT a §83a length drift hiding + * behind a zero count — the count is over equal-length streams. + * jtbl : RE-DECODED MECHANICALLY, not inherited. Compiled .rodata = 0x1C = 28 B = 7 words, + * 7x R_MIPS_32 -> .text with implicit addends [58,58,58,E0,F0,100,58]; +0x8015B950 + * = [8015B9A8, 8015B9A8, 8015B9A8, 8015BA30, 8015BA40, 8015BA50, 8015B9A8]. + * Diffed word-for-word against asm/ov_SC01_077/data/tail14.data.s:15-23 — 7/7 identical. + * symcheck : SYMS-DIFF target=35 draft=34, sole MISSING = jtbl_801D8B74. This is the §81 jr + * FALSE POSITIVE, re-confirmed here by reading the relocs: gcc emits its OWN table and + * references it with R_MIPS_HI16/LO16 against the SECTION `.rodata` (t.o +0x40/+0x48), + * so the splat's dlabel NAME can never appear in the draft object's relocation set. + * Nothing is dropped and nothing is invented: the draft's other 34 symbols are exactly + * the target's other 34. + * FAMILY : the x138 remap is clean and §84-safe. Every sibling is 271 ins with an IDENTICAL + * callee set; only THREE names vary per overlay — the two data labels and the jtbl: + * ov_SC01_077 D_8018D22C / D_8018D298 / jtbl_801D8B74 + * ov_SC03_099 D_80185A50 / D_80185ABC / jtbl_801BD898 + * ov_SC06_008 D_80187E44 / D_80187EB0 / jtbl_801A8734 + * The pair is always +0x6C apart, and NO literal in this draft encodes that distance + * (both labels are referenced by name), so there is no §84 derived-offset hazard. + * D_8011F9C4 is fleet-constant (main-EXE data) and must NOT be remapped. + * + * match_one: MATCH (271 ins) against the CURRENT tree (§87 staleness re-checked, 2026-07-27). + * PIN-FREE, zero asm, offset-pure (s32 arg0 + raw offsets) — x138 template-safe. + * Provenance: this is the Phase-26 crack (.run/phase26-cracks/func_8015B950.c) re-gated verbatim, + * with ONE deliberate change: the definition's return type void -> s32. + * - `void func_8015B950(s32 arg0)` : MATCH (271 ins) [the Phase-26 form] + * - `s32 func_8015B950(s32 arg0)` : MATCH (271 ins) [shipped — §3a-1 void->s32 is byte-neutral] + * The fleet/engine_core.h canonical decl is `extern s32 func_8015B950(void);` (engine_core.h:1852), + * and the last bank attempt (.run/bank_func_8015B950.log) died on `conflicting types for + * func_8015B950`. Shipping the s32 return kills the §73 RETURN axis for free and leaves only the + * cheap T0 PARAMS axis for the ladder (fix_header_decl.py / --fix-def-sig / cast_call_sites). + * Both forms are byte-identical, so the orchestrator may swap the return type back at zero cost. + * + * SYMBOLS (§58 rules 1/2 — all splat spellings, all verified present): + * D_8018D298 asm/ov_SC01_077/data/tail.data.s:4355 (the state-handler vtable) + * D_8018D22C asm/ov_SC01_077/data/tail.data.s:4293 + * D_8011F9C4 main-EXE data; spelled `extern s32 D_8011F9C4;` in 5+ already-banked TUs + * jtbl_801D8B74 asm/ov_SC01_077/data/tail14.data.s:15 (compiler jump table — not named in C) + * + * JTBL VERIFIED (§8a gate): compiled .rodata = exactly 0x1C B / 7 words, 7x R_MIPS_32 .text with + * addends [0x58,0x58,0x58,0xE0,0xF0,0x100,0x58] -> +0x8015B950 = [B9A8,B9A8,B9A8,BA30,BA40,BA50, + * B9A8] == the original words at 0x801D8B74..0x801D8B8C. Bound `sltiu $v0,$v1,0x7` matches. + * The raw dlabel's 8th word 0x00000000 is NOT an entry — it is the intra-TU `.align 3` pad of the + * B34/B54/B74 jtbl chain; the object can never emit it (maspsx drops .align), so it must stay in + * the post-carve RAW data piece (the §53/§62/§81 carve chain applies at bank time). + * + * Same family as the TU's own already-matched func_8015AE2C: 7-case switch on ((s32 (*)(s32))func_801619A4)() + * (0/1/2/6 shared, 3/4/5 own, no default block — out-of-range and every `break` fall to the + * after-switch join), then a chain of "state handler" tests, each dispatching + * D_8018D298[*(u16*)arg0](arg0) and returning. + * + * THREE LEVERS (draft -> MATCH in 3 compiles): + * + * 1. PROLOGUE CONSTANT = an INITIALIZED LOCAL, not a literal in the compare. + * Target opens with `lui $s2, 0xFFF5` in the *prologue*, used once ~200 ins later in + * `slt $v0,$s2,$s1`. No gcc-2.7.2 pass hoists a (set reg const_int) across basic blocks + * (loop.c needs a loop; cse/combine/sched never move insns between BBs) — so the insn must + * have been EMITTED in the first BB, i.e. the constant is a local initialized at the top of + * the function. cse then cannot fold it back into the compare: the `slt` operand predicate is + * `arith_operand`, which rejects a CONST_INT wider than 16 bits, so validate_change fails and + * the pseudo survives. Its live range spans every call -> global.c gives it a callee-saved reg. + * Writing `z > -0xB0000` inline instead emits the `lui` into the branch delay slot next to the + * compare (caller-saved $v0) and the function is 1 insn short. => `s32 lim = -0xB0000;` at top. + * + * 2. `lh` vs `lhu`: a short->short copy is a pure HImode move and gcc emits `lhu`. The target's + * `lh $v0,0x26($s0)` means the value passed through an SImode (int) temp: expand makes + * (set (reg:SI) (sign_extend (mem:HI))) + (set (mem:HI) (subreg:HI ...)), and combine cannot + * merge them (the merged form is mem<-mem, which no movhi accepts) so the sign-extending load + * survives. => route both halfword copies through the `s32 t` temp. + * + * 3. THE `goto` LAYOUT — dodging jump.c's store-flag conversion (jump.c:1005-1065). + * An if/else chain writing 0/1 into `doit` makes gcc collapse the last pair into + * `sltiu $v0,$v0,1`. jump.c fires that conversion when the insn immediately after a + * conditional jump is a lone `SET pseudo, CONST_INT` whose following simplejump targets the + * SAME label as the branch (jump.c:1038 `reallabelprev == temp || ... JUMP_LABEL(temp4) == + * JUMP_LABEL(insn)`) — exactly the shape of `if (c) x=0; else x=1;`. + * The target instead cross-jumps ALL the `doit=0` exits into ONE shared block placed after the + * `doit=1` fall-through; reorg's fill_slots_from_thread then COPIES that single set into all + * three branch delay slots and redirects each branch past it (which is why `addu $v0,$zero, + * $zero` appears 3x in delay slots and the shared block vanishes). A `goto zero;` / `goto one;` + * chain expresses that layout directly, and each conditional jump is then followed by a + * compare/call rather than a lone const set, so the store-flag conversion never triggers. + * GENERAL RULE: multiple predicates that all assign the SAME constant to one flag => write + * them as `goto` to a shared assignment, never as an if/else ladder. + */ +extern s32 D_8011F9C4; +extern s32 D_8018D22C; + +extern s32 func_80161B18(void); +extern s32 func_801619A4(s32*); +extern s32 func_80149AA8(s32*); +extern void func_80149AD4(s32*); +extern s32 func_80149B54(s32*); +extern void func_80149BAC(s32*); +extern s32 func_801498E0(s32*); +extern s32 func_80149954(s32); +extern s32 func_80149A64(s32*); +extern void func_800CCCC0(s32 a0); +extern s32 func_80149CD4(s32 a0); +extern void func_8015E880(s32*); +extern s32 func_80149744(struct S_80149744*); +extern void func_80149788(void); +extern s32 func_801496D4(void*); +extern void func_80149704(void); +extern int func_80148AFC(void*); +extern void func_80146D90(s32 a0); +extern void func_80154150(s32 a0, s32 a1); +extern void func_801541D8(u8*, s32, s32); +extern s32 func_801488A8(u8*); +extern void func_80147078(s32*, s16); +extern void func_8015A264(void*); +extern s32 func_80013294(void*, void*); +extern void func_80159B70(void*); +extern s32 func_8016F1AC(void); +extern s32 func_80029178(s32 a0); +extern void func_80146DB8(s32*, s32*); +extern s32 func_80161CD0(s32, s32); +extern s32 func_80161208(s32 a0); +extern s32 func_801725A4(u8*); + +s32 func_8015B950(s32 arg0) +{ + + extern void (*D_8018D298[])(void *); + s16 sp10[4]; + s16 sp18[4]; + s32 t; + s32 z; + s32 doit; + s32 lim = -0xB0000; + + if (func_80161B18() != 0) { + return; + } + switch (((s32 (*)(s32))func_801619A4)(arg0)) { + case 0: + case 1: + case 2: + case 6: + if (((s32 (*)(s32))func_80149AA8)(arg0) != 0) { + D_8018D298[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149AD4)(arg0); + return; + } + if (((s32 (*)(s32))func_80149B54)(arg0) != 0) { + D_8018D298[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149BAC)(arg0); + return; + } + break; + case 3: + ((void (*)(s32))func_801498E0)(arg0); + break; + case 4: + ((void (*)(s32))func_80149954)(arg0); + break; + case 5: + if (((s32 (*)(s32))func_80149A64)(arg0) != 0) { + D_8018D298[*(u16 *)arg0]((void *)arg0); + func_800CCCC0(arg0); + return; + } + break; + } + if (func_80149CD4(arg0) != 0) { + D_8018D298[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_8015E880)(arg0); + return; + } + if (((s32 (*)(s32))func_80149744)(arg0) != 0) { + D_8018D298[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149788)(arg0); + return; + } + if (((s32 (*)(s32))func_801496D4)(arg0) != 0) { + D_8018D298[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149704)(arg0); + if (((u8)((s32 (*)(s32))func_80148AFC)(arg0)) == 0) { + func_80146D90(arg0); + } + if ((*(s32 *)(arg0 + 0x24) | *(s32 *)(arg0 + 0x2C)) != 0) { + func_80154150(arg0, 0xF); + } else { + ((void (*)(s32, s32, s32))func_801541D8)(arg0, 0xD, 6); + } + *(s32 *)(arg0 + 0x238) = 1; + return; + } + if (((s32 (*)(s32))func_801488A8)(arg0) != 0) { + sp10[0] = 0; + sp10[1] = 0; + sp10[2] = 0; + t = *(s16 *)(arg0 + 0x26); + sp18[0] = t; + sp18[1] = 0; + t = *(s16 *)(arg0 + 0x2E); + sp18[2] = t; + D_8018D298[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 1); + ((void (*)(s32))func_8015A264)(arg0); + t = -(((s32 (*)(s16 *, s16 *))func_80013294)(sp10, sp18) << 0x10); + if (t < *(s32 *)(arg0 + 0x2C)) { + *(s32 *)(arg0 + 0x2C) = t; + } + return; + } + if (*(u16 *)(arg0 + 0xB8) == 0x8000) { + D_8018D298[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 0); + ((void (*)(s32))func_80159B70)(arg0); + return; + } + z = *(s32 *)(arg0 + 0x2C); + if (func_8016F1AC() != 0) { + goto zero; + } + if (z <= lim) { + goto one; + } + if (D_8011F9C4 == 0) { + goto zero; + } + if (((u8)func_80029178(0x21)) != 0) { + goto zero; + } +one: + doit = 1; + goto join; +zero: + doit = 0; +join: + if (doit != 0) { + D_8018D298[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 0); + ((void (*)(s32))func_80159B70)(arg0); + func_80154150(arg0, 9); + ((void (*)(s32, s32 *))func_80146DB8)(arg0, &D_8018D22C); + ((void (*)(s32, s32))func_80161CD0)(arg0, *(u16 *)(arg0 + 0x16E)); + return; + } + if (func_80161208(arg0) == 0) { + ((void (*)(s32))func_801725A4)(arg0); + } +} DEFINE_func_8015BD8C() /* dedup: shared engine-core @0x8015BD8C (src/shared) */ diff --git a/src/ov_SC02_003/ov_SC02_003_jr_8015AE2C.c b/src/ov_SC02_003/ov_SC02_003_jr_8015AE2C.c index 0bea5627f..bdf056b07 100644 --- a/src/ov_SC02_003/ov_SC02_003_jr_8015AE2C.c +++ b/src/ov_SC02_003/ov_SC02_003_jr_8015AE2C.c @@ -1513,7 +1513,259 @@ DEFINE_func_8015B858() /* dedup: shared engine-core @0x8015B858 (src/shared) */ DEFINE_func_8015B8F8() /* dedup: shared engine-core @0x8015B8F8 (src/shared) */ -INCLUDE_ASM("asm/ov_SC02_003/nonmatchings/ov_SC02_003_jr_8015AE2C", func_8015B950); +extern s32 func_8015AE2C(); + +// @class: plumbing +// @stuck: none — MATCH (271/271, pin-free, zero asm). The ONLY residual is DEF-SIDE plumbing, and it is now named exactly: the in-TU instantiation `DEFINE_func_8015BEE4()` (engine_core.h:1851-1855) expands to `extern s32 func_8015B950(void);` INSIDE ov_SC01_077_jr_8015AE2C.c, ~14 lines BELOW this definition, so the 1-param def collides with a `(void)` prototype -> `conflicting types for func_8015B950` (.run/bank_func_8015B950.log). §73 PARAMS axis / T0. Surgical fix = §65b de-macroize that ONE instantiation (blast radius: this TU); the fleet-wide `(void)`->`()` header edit is §63 and must be R22-validated. +/* func_8015B950 (ov_SC01_077_jr_8015AE2C, 271 ins, jtbl_801D8B74) — SESSION-21 re-verified + * + * ── ROUND-2 INDEPENDENT RE-VERIFICATION (2026-07-27, fresh agent, §88e discipline) ───────────── + * match_one : MATCH (271 ins) against the CURRENT tree — §87 staleness re-checked today. + * .text size: compiled .text = 0x43C = 1084 B = 271 ins, EXACTLY the target's declared 0x43C + * ("nonmatching func_8015B950, 0x43C"). So this is NOT a §83a length drift hiding + * behind a zero count — the count is over equal-length streams. + * jtbl : RE-DECODED MECHANICALLY, not inherited. Compiled .rodata = 0x1C = 28 B = 7 words, + * 7x R_MIPS_32 -> .text with implicit addends [58,58,58,E0,F0,100,58]; +0x8015B950 + * = [8015B9A8, 8015B9A8, 8015B9A8, 8015BA30, 8015BA40, 8015BA50, 8015B9A8]. + * Diffed word-for-word against asm/ov_SC01_077/data/tail14.data.s:15-23 — 7/7 identical. + * symcheck : SYMS-DIFF target=35 draft=34, sole MISSING = jtbl_801D8B74. This is the §81 jr + * FALSE POSITIVE, re-confirmed here by reading the relocs: gcc emits its OWN table and + * references it with R_MIPS_HI16/LO16 against the SECTION `.rodata` (t.o +0x40/+0x48), + * so the splat's dlabel NAME can never appear in the draft object's relocation set. + * Nothing is dropped and nothing is invented: the draft's other 34 symbols are exactly + * the target's other 34. + * FAMILY : the x138 remap is clean and §84-safe. Every sibling is 271 ins with an IDENTICAL + * callee set; only THREE names vary per overlay — the two data labels and the jtbl: + * ov_SC01_077 D_8018D22C / D_8018D298 / jtbl_801D8B74 + * ov_SC03_099 D_80185A50 / D_80185ABC / jtbl_801BD898 + * ov_SC06_008 D_80187E44 / D_80187EB0 / jtbl_801A8734 + * The pair is always +0x6C apart, and NO literal in this draft encodes that distance + * (both labels are referenced by name), so there is no §84 derived-offset hazard. + * D_8011F9C4 is fleet-constant (main-EXE data) and must NOT be remapped. + * + * match_one: MATCH (271 ins) against the CURRENT tree (§87 staleness re-checked, 2026-07-27). + * PIN-FREE, zero asm, offset-pure (s32 arg0 + raw offsets) — x138 template-safe. + * Provenance: this is the Phase-26 crack (.run/phase26-cracks/func_8015B950.c) re-gated verbatim, + * with ONE deliberate change: the definition's return type void -> s32. + * - `void func_8015B950(s32 arg0)` : MATCH (271 ins) [the Phase-26 form] + * - `s32 func_8015B950(s32 arg0)` : MATCH (271 ins) [shipped — §3a-1 void->s32 is byte-neutral] + * The fleet/engine_core.h canonical decl is `extern s32 func_8015B950(void);` (engine_core.h:1852), + * and the last bank attempt (.run/bank_func_8015B950.log) died on `conflicting types for + * func_8015B950`. Shipping the s32 return kills the §73 RETURN axis for free and leaves only the + * cheap T0 PARAMS axis for the ladder (fix_header_decl.py / --fix-def-sig / cast_call_sites). + * Both forms are byte-identical, so the orchestrator may swap the return type back at zero cost. + * + * SYMBOLS (§58 rules 1/2 — all splat spellings, all verified present): + * D_8018D298 asm/ov_SC01_077/data/tail.data.s:4355 (the state-handler vtable) + * D_8018D22C asm/ov_SC01_077/data/tail.data.s:4293 + * D_8011F9C4 main-EXE data; spelled `extern s32 D_8011F9C4;` in 5+ already-banked TUs + * jtbl_801D8B74 asm/ov_SC01_077/data/tail14.data.s:15 (compiler jump table — not named in C) + * + * JTBL VERIFIED (§8a gate): compiled .rodata = exactly 0x1C B / 7 words, 7x R_MIPS_32 .text with + * addends [0x58,0x58,0x58,0xE0,0xF0,0x100,0x58] -> +0x8015B950 = [B9A8,B9A8,B9A8,BA30,BA40,BA50, + * B9A8] == the original words at 0x801D8B74..0x801D8B8C. Bound `sltiu $v0,$v1,0x7` matches. + * The raw dlabel's 8th word 0x00000000 is NOT an entry — it is the intra-TU `.align 3` pad of the + * B34/B54/B74 jtbl chain; the object can never emit it (maspsx drops .align), so it must stay in + * the post-carve RAW data piece (the §53/§62/§81 carve chain applies at bank time). + * + * Same family as the TU's own already-matched func_8015AE2C: 7-case switch on ((s32 (*)(s32))func_801619A4)() + * (0/1/2/6 shared, 3/4/5 own, no default block — out-of-range and every `break` fall to the + * after-switch join), then a chain of "state handler" tests, each dispatching + * D_8018D298[*(u16*)arg0](arg0) and returning. + * + * THREE LEVERS (draft -> MATCH in 3 compiles): + * + * 1. PROLOGUE CONSTANT = an INITIALIZED LOCAL, not a literal in the compare. + * Target opens with `lui $s2, 0xFFF5` in the *prologue*, used once ~200 ins later in + * `slt $v0,$s2,$s1`. No gcc-2.7.2 pass hoists a (set reg const_int) across basic blocks + * (loop.c needs a loop; cse/combine/sched never move insns between BBs) — so the insn must + * have been EMITTED in the first BB, i.e. the constant is a local initialized at the top of + * the function. cse then cannot fold it back into the compare: the `slt` operand predicate is + * `arith_operand`, which rejects a CONST_INT wider than 16 bits, so validate_change fails and + * the pseudo survives. Its live range spans every call -> global.c gives it a callee-saved reg. + * Writing `z > -0xB0000` inline instead emits the `lui` into the branch delay slot next to the + * compare (caller-saved $v0) and the function is 1 insn short. => `s32 lim = -0xB0000;` at top. + * + * 2. `lh` vs `lhu`: a short->short copy is a pure HImode move and gcc emits `lhu`. The target's + * `lh $v0,0x26($s0)` means the value passed through an SImode (int) temp: expand makes + * (set (reg:SI) (sign_extend (mem:HI))) + (set (mem:HI) (subreg:HI ...)), and combine cannot + * merge them (the merged form is mem<-mem, which no movhi accepts) so the sign-extending load + * survives. => route both halfword copies through the `s32 t` temp. + * + * 3. THE `goto` LAYOUT — dodging jump.c's store-flag conversion (jump.c:1005-1065). + * An if/else chain writing 0/1 into `doit` makes gcc collapse the last pair into + * `sltiu $v0,$v0,1`. jump.c fires that conversion when the insn immediately after a + * conditional jump is a lone `SET pseudo, CONST_INT` whose following simplejump targets the + * SAME label as the branch (jump.c:1038 `reallabelprev == temp || ... JUMP_LABEL(temp4) == + * JUMP_LABEL(insn)`) — exactly the shape of `if (c) x=0; else x=1;`. + * The target instead cross-jumps ALL the `doit=0` exits into ONE shared block placed after the + * `doit=1` fall-through; reorg's fill_slots_from_thread then COPIES that single set into all + * three branch delay slots and redirects each branch past it (which is why `addu $v0,$zero, + * $zero` appears 3x in delay slots and the shared block vanishes). A `goto zero;` / `goto one;` + * chain expresses that layout directly, and each conditional jump is then followed by a + * compare/call rather than a lone const set, so the store-flag conversion never triggers. + * GENERAL RULE: multiple predicates that all assign the SAME constant to one flag => write + * them as `goto` to a shared assignment, never as an if/else ladder. + */ +extern s32 D_8011F9C4; +extern s32 D_8018D22C; + +extern s32 func_80161B18(void); +extern s32 func_801619A4(s32*); +extern s32 func_80149AA8(s32*); +extern void func_80149AD4(s32*); +extern s32 func_80149B54(s32*); +extern void func_80149BAC(s32*); +extern s32 func_801498E0(s32*); +extern s32 func_80149954(s32); +extern s32 func_80149A64(s32*); +extern void func_800CCCC0(s32 a0); +extern s32 func_80149CD4(s32 a0); +extern void func_8015E880(s32*); +extern s32 func_80149744(struct S_80149744*); +extern void func_80149788(void); +extern s32 func_801496D4(void*); +extern void func_80149704(void); +extern int func_80148AFC(void*); +extern void func_80146D90(s32 a0); +extern void func_80154150(s32 a0, s32 a1); +extern void func_801541D8(u8*, s32, s32); +extern s32 func_801488A8(u8*); +extern void func_80147078(s32*, s16); +extern void func_8015A264(void*); +extern s32 func_80013294(void*, void*); +extern void func_80159B70(void*); +extern s32 func_8016F1AC(void); +extern s32 func_80029178(s32 a0); +extern void func_80146DB8(s32*, s32*); +extern s32 func_80161CD0(s32, s32); +extern s32 func_80161208(s32 a0); +extern s32 func_801725A4(u8*); + +s32 func_8015B950(s32 arg0) +{ + + extern void (*D_8018D298[])(void *); + s16 sp10[4]; + s16 sp18[4]; + s32 t; + s32 z; + s32 doit; + s32 lim = -0xB0000; + + if (func_80161B18() != 0) { + return; + } + switch (((s32 (*)(s32))func_801619A4)(arg0)) { + case 0: + case 1: + case 2: + case 6: + if (((s32 (*)(s32))func_80149AA8)(arg0) != 0) { + D_8018D298[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149AD4)(arg0); + return; + } + if (((s32 (*)(s32))func_80149B54)(arg0) != 0) { + D_8018D298[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149BAC)(arg0); + return; + } + break; + case 3: + ((void (*)(s32))func_801498E0)(arg0); + break; + case 4: + ((void (*)(s32))func_80149954)(arg0); + break; + case 5: + if (((s32 (*)(s32))func_80149A64)(arg0) != 0) { + D_8018D298[*(u16 *)arg0]((void *)arg0); + func_800CCCC0(arg0); + return; + } + break; + } + if (func_80149CD4(arg0) != 0) { + D_8018D298[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_8015E880)(arg0); + return; + } + if (((s32 (*)(s32))func_80149744)(arg0) != 0) { + D_8018D298[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149788)(arg0); + return; + } + if (((s32 (*)(s32))func_801496D4)(arg0) != 0) { + D_8018D298[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149704)(arg0); + if (((u8)((s32 (*)(s32))func_80148AFC)(arg0)) == 0) { + func_80146D90(arg0); + } + if ((*(s32 *)(arg0 + 0x24) | *(s32 *)(arg0 + 0x2C)) != 0) { + func_80154150(arg0, 0xF); + } else { + ((void (*)(s32, s32, s32))func_801541D8)(arg0, 0xD, 6); + } + *(s32 *)(arg0 + 0x238) = 1; + return; + } + if (((s32 (*)(s32))func_801488A8)(arg0) != 0) { + sp10[0] = 0; + sp10[1] = 0; + sp10[2] = 0; + t = *(s16 *)(arg0 + 0x26); + sp18[0] = t; + sp18[1] = 0; + t = *(s16 *)(arg0 + 0x2E); + sp18[2] = t; + D_8018D298[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 1); + ((void (*)(s32))func_8015A264)(arg0); + t = -(((s32 (*)(s16 *, s16 *))func_80013294)(sp10, sp18) << 0x10); + if (t < *(s32 *)(arg0 + 0x2C)) { + *(s32 *)(arg0 + 0x2C) = t; + } + return; + } + if (*(u16 *)(arg0 + 0xB8) == 0x8000) { + D_8018D298[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 0); + ((void (*)(s32))func_80159B70)(arg0); + return; + } + z = *(s32 *)(arg0 + 0x2C); + if (func_8016F1AC() != 0) { + goto zero; + } + if (z <= lim) { + goto one; + } + if (D_8011F9C4 == 0) { + goto zero; + } + if (((u8)func_80029178(0x21)) != 0) { + goto zero; + } +one: + doit = 1; + goto join; +zero: + doit = 0; +join: + if (doit != 0) { + D_8018D298[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 0); + ((void (*)(s32))func_80159B70)(arg0); + func_80154150(arg0, 9); + ((void (*)(s32, s32 *))func_80146DB8)(arg0, &D_8018D22C); + ((void (*)(s32, s32))func_80161CD0)(arg0, *(u16 *)(arg0 + 0x16E)); + return; + } + if (func_80161208(arg0) == 0) { + ((void (*)(s32))func_801725A4)(arg0); + } +} DEFINE_func_8015BD8C() /* dedup: shared engine-core @0x8015BD8C (src/shared) */ diff --git a/src/ov_SC02_004/ov_SC02_004_jr_8015AE2C.c b/src/ov_SC02_004/ov_SC02_004_jr_8015AE2C.c index 8bc515c9a..83f8dc0ad 100644 --- a/src/ov_SC02_004/ov_SC02_004_jr_8015AE2C.c +++ b/src/ov_SC02_004/ov_SC02_004_jr_8015AE2C.c @@ -1513,7 +1513,259 @@ DEFINE_func_8015B858() /* dedup: shared engine-core @0x8015B858 (src/shared) */ DEFINE_func_8015B8F8() /* dedup: shared engine-core @0x8015B8F8 (src/shared) */ -INCLUDE_ASM("asm/ov_SC02_004/nonmatchings/ov_SC02_004_jr_8015AE2C", func_8015B950); +extern s32 func_8015AE2C(); + +// @class: plumbing +// @stuck: none — MATCH (271/271, pin-free, zero asm). The ONLY residual is DEF-SIDE plumbing, and it is now named exactly: the in-TU instantiation `DEFINE_func_8015BEE4()` (engine_core.h:1851-1855) expands to `extern s32 func_8015B950(void);` INSIDE ov_SC01_077_jr_8015AE2C.c, ~14 lines BELOW this definition, so the 1-param def collides with a `(void)` prototype -> `conflicting types for func_8015B950` (.run/bank_func_8015B950.log). §73 PARAMS axis / T0. Surgical fix = §65b de-macroize that ONE instantiation (blast radius: this TU); the fleet-wide `(void)`->`()` header edit is §63 and must be R22-validated. +/* func_8015B950 (ov_SC01_077_jr_8015AE2C, 271 ins, jtbl_801D8B74) — SESSION-21 re-verified + * + * ── ROUND-2 INDEPENDENT RE-VERIFICATION (2026-07-27, fresh agent, §88e discipline) ───────────── + * match_one : MATCH (271 ins) against the CURRENT tree — §87 staleness re-checked today. + * .text size: compiled .text = 0x43C = 1084 B = 271 ins, EXACTLY the target's declared 0x43C + * ("nonmatching func_8015B950, 0x43C"). So this is NOT a §83a length drift hiding + * behind a zero count — the count is over equal-length streams. + * jtbl : RE-DECODED MECHANICALLY, not inherited. Compiled .rodata = 0x1C = 28 B = 7 words, + * 7x R_MIPS_32 -> .text with implicit addends [58,58,58,E0,F0,100,58]; +0x8015B950 + * = [8015B9A8, 8015B9A8, 8015B9A8, 8015BA30, 8015BA40, 8015BA50, 8015B9A8]. + * Diffed word-for-word against asm/ov_SC01_077/data/tail14.data.s:15-23 — 7/7 identical. + * symcheck : SYMS-DIFF target=35 draft=34, sole MISSING = jtbl_801D8B74. This is the §81 jr + * FALSE POSITIVE, re-confirmed here by reading the relocs: gcc emits its OWN table and + * references it with R_MIPS_HI16/LO16 against the SECTION `.rodata` (t.o +0x40/+0x48), + * so the splat's dlabel NAME can never appear in the draft object's relocation set. + * Nothing is dropped and nothing is invented: the draft's other 34 symbols are exactly + * the target's other 34. + * FAMILY : the x138 remap is clean and §84-safe. Every sibling is 271 ins with an IDENTICAL + * callee set; only THREE names vary per overlay — the two data labels and the jtbl: + * ov_SC01_077 D_8018030C / D_80180378 / jtbl_801D8B74 + * ov_SC03_099 D_80185A50 / D_80185ABC / jtbl_801BD898 + * ov_SC06_008 D_80187E44 / D_80187EB0 / jtbl_801A8734 + * The pair is always +0x6C apart, and NO literal in this draft encodes that distance + * (both labels are referenced by name), so there is no §84 derived-offset hazard. + * D_8011F9C4 is fleet-constant (main-EXE data) and must NOT be remapped. + * + * match_one: MATCH (271 ins) against the CURRENT tree (§87 staleness re-checked, 2026-07-27). + * PIN-FREE, zero asm, offset-pure (s32 arg0 + raw offsets) — x138 template-safe. + * Provenance: this is the Phase-26 crack (.run/phase26-cracks/func_8015B950.c) re-gated verbatim, + * with ONE deliberate change: the definition's return type void -> s32. + * - `void func_8015B950(s32 arg0)` : MATCH (271 ins) [the Phase-26 form] + * - `s32 func_8015B950(s32 arg0)` : MATCH (271 ins) [shipped — §3a-1 void->s32 is byte-neutral] + * The fleet/engine_core.h canonical decl is `extern s32 func_8015B950(void);` (engine_core.h:1852), + * and the last bank attempt (.run/bank_func_8015B950.log) died on `conflicting types for + * func_8015B950`. Shipping the s32 return kills the §73 RETURN axis for free and leaves only the + * cheap T0 PARAMS axis for the ladder (fix_header_decl.py / --fix-def-sig / cast_call_sites). + * Both forms are byte-identical, so the orchestrator may swap the return type back at zero cost. + * + * SYMBOLS (§58 rules 1/2 — all splat spellings, all verified present): + * D_80180378 asm/ov_SC01_077/data/tail.data.s:4355 (the state-handler vtable) + * D_8018030C asm/ov_SC01_077/data/tail.data.s:4293 + * D_8011F9C4 main-EXE data; spelled `extern s32 D_8011F9C4;` in 5+ already-banked TUs + * jtbl_801D8B74 asm/ov_SC01_077/data/tail14.data.s:15 (compiler jump table — not named in C) + * + * JTBL VERIFIED (§8a gate): compiled .rodata = exactly 0x1C B / 7 words, 7x R_MIPS_32 .text with + * addends [0x58,0x58,0x58,0xE0,0xF0,0x100,0x58] -> +0x8015B950 = [B9A8,B9A8,B9A8,BA30,BA40,BA50, + * B9A8] == the original words at 0x801D8B74..0x801D8B8C. Bound `sltiu $v0,$v1,0x7` matches. + * The raw dlabel's 8th word 0x00000000 is NOT an entry — it is the intra-TU `.align 3` pad of the + * B34/B54/B74 jtbl chain; the object can never emit it (maspsx drops .align), so it must stay in + * the post-carve RAW data piece (the §53/§62/§81 carve chain applies at bank time). + * + * Same family as the TU's own already-matched func_8015AE2C: 7-case switch on ((s32 (*)(s32))func_801619A4)() + * (0/1/2/6 shared, 3/4/5 own, no default block — out-of-range and every `break` fall to the + * after-switch join), then a chain of "state handler" tests, each dispatching + * D_80180378[*(u16*)arg0](arg0) and returning. + * + * THREE LEVERS (draft -> MATCH in 3 compiles): + * + * 1. PROLOGUE CONSTANT = an INITIALIZED LOCAL, not a literal in the compare. + * Target opens with `lui $s2, 0xFFF5` in the *prologue*, used once ~200 ins later in + * `slt $v0,$s2,$s1`. No gcc-2.7.2 pass hoists a (set reg const_int) across basic blocks + * (loop.c needs a loop; cse/combine/sched never move insns between BBs) — so the insn must + * have been EMITTED in the first BB, i.e. the constant is a local initialized at the top of + * the function. cse then cannot fold it back into the compare: the `slt` operand predicate is + * `arith_operand`, which rejects a CONST_INT wider than 16 bits, so validate_change fails and + * the pseudo survives. Its live range spans every call -> global.c gives it a callee-saved reg. + * Writing `z > -0xB0000` inline instead emits the `lui` into the branch delay slot next to the + * compare (caller-saved $v0) and the function is 1 insn short. => `s32 lim = -0xB0000;` at top. + * + * 2. `lh` vs `lhu`: a short->short copy is a pure HImode move and gcc emits `lhu`. The target's + * `lh $v0,0x26($s0)` means the value passed through an SImode (int) temp: expand makes + * (set (reg:SI) (sign_extend (mem:HI))) + (set (mem:HI) (subreg:HI ...)), and combine cannot + * merge them (the merged form is mem<-mem, which no movhi accepts) so the sign-extending load + * survives. => route both halfword copies through the `s32 t` temp. + * + * 3. THE `goto` LAYOUT — dodging jump.c's store-flag conversion (jump.c:1005-1065). + * An if/else chain writing 0/1 into `doit` makes gcc collapse the last pair into + * `sltiu $v0,$v0,1`. jump.c fires that conversion when the insn immediately after a + * conditional jump is a lone `SET pseudo, CONST_INT` whose following simplejump targets the + * SAME label as the branch (jump.c:1038 `reallabelprev == temp || ... JUMP_LABEL(temp4) == + * JUMP_LABEL(insn)`) — exactly the shape of `if (c) x=0; else x=1;`. + * The target instead cross-jumps ALL the `doit=0` exits into ONE shared block placed after the + * `doit=1` fall-through; reorg's fill_slots_from_thread then COPIES that single set into all + * three branch delay slots and redirects each branch past it (which is why `addu $v0,$zero, + * $zero` appears 3x in delay slots and the shared block vanishes). A `goto zero;` / `goto one;` + * chain expresses that layout directly, and each conditional jump is then followed by a + * compare/call rather than a lone const set, so the store-flag conversion never triggers. + * GENERAL RULE: multiple predicates that all assign the SAME constant to one flag => write + * them as `goto` to a shared assignment, never as an if/else ladder. + */ +extern s32 D_8011F9C4; +extern s32 D_8018030C; + +extern s32 func_80161B18(void); +extern s32 func_801619A4(s32*); +extern s32 func_80149AA8(s32*); +extern void func_80149AD4(s32*); +extern s32 func_80149B54(s32*); +extern void func_80149BAC(s32*); +extern s32 func_801498E0(s32*); +extern s32 func_80149954(s32); +extern s32 func_80149A64(s32*); +extern void func_800CCCC0(s32 a0); +extern s32 func_80149CD4(s32 a0); +extern void func_8015E880(s32*); +extern s32 func_80149744(struct S_80149744*); +extern void func_80149788(void); +extern s32 func_801496D4(void*); +extern void func_80149704(void); +extern int func_80148AFC(void*); +extern void func_80146D90(s32 a0); +extern void func_80154150(s32 a0, s32 a1); +extern void func_801541D8(u8*, s32, s32); +extern s32 func_801488A8(u8*); +extern void func_80147078(s32*, s16); +extern void func_8015A264(void*); +extern s32 func_80013294(void*, void*); +extern void func_80159B70(void*); +extern s32 func_8016F1AC(void); +extern s32 func_80029178(s32 a0); +extern void func_80146DB8(s32*, s32*); +extern s32 func_80161CD0(s32, s32); +extern s32 func_80161208(s32 a0); +extern s32 func_801725A4(u8*); + +s32 func_8015B950(s32 arg0) +{ + + extern void (*D_80180378[])(void *); + s16 sp10[4]; + s16 sp18[4]; + s32 t; + s32 z; + s32 doit; + s32 lim = -0xB0000; + + if (func_80161B18() != 0) { + return; + } + switch (((s32 (*)(s32))func_801619A4)(arg0)) { + case 0: + case 1: + case 2: + case 6: + if (((s32 (*)(s32))func_80149AA8)(arg0) != 0) { + D_80180378[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149AD4)(arg0); + return; + } + if (((s32 (*)(s32))func_80149B54)(arg0) != 0) { + D_80180378[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149BAC)(arg0); + return; + } + break; + case 3: + ((void (*)(s32))func_801498E0)(arg0); + break; + case 4: + ((void (*)(s32))func_80149954)(arg0); + break; + case 5: + if (((s32 (*)(s32))func_80149A64)(arg0) != 0) { + D_80180378[*(u16 *)arg0]((void *)arg0); + func_800CCCC0(arg0); + return; + } + break; + } + if (func_80149CD4(arg0) != 0) { + D_80180378[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_8015E880)(arg0); + return; + } + if (((s32 (*)(s32))func_80149744)(arg0) != 0) { + D_80180378[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149788)(arg0); + return; + } + if (((s32 (*)(s32))func_801496D4)(arg0) != 0) { + D_80180378[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149704)(arg0); + if (((u8)((s32 (*)(s32))func_80148AFC)(arg0)) == 0) { + func_80146D90(arg0); + } + if ((*(s32 *)(arg0 + 0x24) | *(s32 *)(arg0 + 0x2C)) != 0) { + func_80154150(arg0, 0xF); + } else { + ((void (*)(s32, s32, s32))func_801541D8)(arg0, 0xD, 6); + } + *(s32 *)(arg0 + 0x238) = 1; + return; + } + if (((s32 (*)(s32))func_801488A8)(arg0) != 0) { + sp10[0] = 0; + sp10[1] = 0; + sp10[2] = 0; + t = *(s16 *)(arg0 + 0x26); + sp18[0] = t; + sp18[1] = 0; + t = *(s16 *)(arg0 + 0x2E); + sp18[2] = t; + D_80180378[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 1); + ((void (*)(s32))func_8015A264)(arg0); + t = -(((s32 (*)(s16 *, s16 *))func_80013294)(sp10, sp18) << 0x10); + if (t < *(s32 *)(arg0 + 0x2C)) { + *(s32 *)(arg0 + 0x2C) = t; + } + return; + } + if (*(u16 *)(arg0 + 0xB8) == 0x8000) { + D_80180378[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 0); + ((void (*)(s32))func_80159B70)(arg0); + return; + } + z = *(s32 *)(arg0 + 0x2C); + if (func_8016F1AC() != 0) { + goto zero; + } + if (z <= lim) { + goto one; + } + if (D_8011F9C4 == 0) { + goto zero; + } + if (((u8)func_80029178(0x21)) != 0) { + goto zero; + } +one: + doit = 1; + goto join; +zero: + doit = 0; +join: + if (doit != 0) { + D_80180378[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 0); + ((void (*)(s32))func_80159B70)(arg0); + func_80154150(arg0, 9); + ((void (*)(s32, s32 *))func_80146DB8)(arg0, &D_8018030C); + ((void (*)(s32, s32))func_80161CD0)(arg0, *(u16 *)(arg0 + 0x16E)); + return; + } + if (func_80161208(arg0) == 0) { + ((void (*)(s32))func_801725A4)(arg0); + } +} DEFINE_func_8015BD8C() /* dedup: shared engine-core @0x8015BD8C (src/shared) */ diff --git a/src/ov_SC02_005/ov_SC02_005_jr_8015AE2C.c b/src/ov_SC02_005/ov_SC02_005_jr_8015AE2C.c index ec54e51f0..f4b77dbd0 100644 --- a/src/ov_SC02_005/ov_SC02_005_jr_8015AE2C.c +++ b/src/ov_SC02_005/ov_SC02_005_jr_8015AE2C.c @@ -1513,7 +1513,259 @@ DEFINE_func_8015B858() /* dedup: shared engine-core @0x8015B858 (src/shared) */ DEFINE_func_8015B8F8() /* dedup: shared engine-core @0x8015B8F8 (src/shared) */ -INCLUDE_ASM("asm/ov_SC02_005/nonmatchings/ov_SC02_005_jr_8015AE2C", func_8015B950); +extern s32 func_8015AE2C(); + +// @class: plumbing +// @stuck: none — MATCH (271/271, pin-free, zero asm). The ONLY residual is DEF-SIDE plumbing, and it is now named exactly: the in-TU instantiation `DEFINE_func_8015BEE4()` (engine_core.h:1851-1855) expands to `extern s32 func_8015B950(void);` INSIDE ov_SC01_077_jr_8015AE2C.c, ~14 lines BELOW this definition, so the 1-param def collides with a `(void)` prototype -> `conflicting types for func_8015B950` (.run/bank_func_8015B950.log). §73 PARAMS axis / T0. Surgical fix = §65b de-macroize that ONE instantiation (blast radius: this TU); the fleet-wide `(void)`->`()` header edit is §63 and must be R22-validated. +/* func_8015B950 (ov_SC01_077_jr_8015AE2C, 271 ins, jtbl_801D8B74) — SESSION-21 re-verified + * + * ── ROUND-2 INDEPENDENT RE-VERIFICATION (2026-07-27, fresh agent, §88e discipline) ───────────── + * match_one : MATCH (271 ins) against the CURRENT tree — §87 staleness re-checked today. + * .text size: compiled .text = 0x43C = 1084 B = 271 ins, EXACTLY the target's declared 0x43C + * ("nonmatching func_8015B950, 0x43C"). So this is NOT a §83a length drift hiding + * behind a zero count — the count is over equal-length streams. + * jtbl : RE-DECODED MECHANICALLY, not inherited. Compiled .rodata = 0x1C = 28 B = 7 words, + * 7x R_MIPS_32 -> .text with implicit addends [58,58,58,E0,F0,100,58]; +0x8015B950 + * = [8015B9A8, 8015B9A8, 8015B9A8, 8015BA30, 8015BA40, 8015BA50, 8015B9A8]. + * Diffed word-for-word against asm/ov_SC01_077/data/tail14.data.s:15-23 — 7/7 identical. + * symcheck : SYMS-DIFF target=35 draft=34, sole MISSING = jtbl_801D8B74. This is the §81 jr + * FALSE POSITIVE, re-confirmed here by reading the relocs: gcc emits its OWN table and + * references it with R_MIPS_HI16/LO16 against the SECTION `.rodata` (t.o +0x40/+0x48), + * so the splat's dlabel NAME can never appear in the draft object's relocation set. + * Nothing is dropped and nothing is invented: the draft's other 34 symbols are exactly + * the target's other 34. + * FAMILY : the x138 remap is clean and §84-safe. Every sibling is 271 ins with an IDENTICAL + * callee set; only THREE names vary per overlay — the two data labels and the jtbl: + * ov_SC01_077 D_80192F10 / D_80192F7C / jtbl_801D8B74 + * ov_SC03_099 D_80185A50 / D_80185ABC / jtbl_801BD898 + * ov_SC06_008 D_80187E44 / D_80187EB0 / jtbl_801A8734 + * The pair is always +0x6C apart, and NO literal in this draft encodes that distance + * (both labels are referenced by name), so there is no §84 derived-offset hazard. + * D_8011F9C4 is fleet-constant (main-EXE data) and must NOT be remapped. + * + * match_one: MATCH (271 ins) against the CURRENT tree (§87 staleness re-checked, 2026-07-27). + * PIN-FREE, zero asm, offset-pure (s32 arg0 + raw offsets) — x138 template-safe. + * Provenance: this is the Phase-26 crack (.run/phase26-cracks/func_8015B950.c) re-gated verbatim, + * with ONE deliberate change: the definition's return type void -> s32. + * - `void func_8015B950(s32 arg0)` : MATCH (271 ins) [the Phase-26 form] + * - `s32 func_8015B950(s32 arg0)` : MATCH (271 ins) [shipped — §3a-1 void->s32 is byte-neutral] + * The fleet/engine_core.h canonical decl is `extern s32 func_8015B950(void);` (engine_core.h:1852), + * and the last bank attempt (.run/bank_func_8015B950.log) died on `conflicting types for + * func_8015B950`. Shipping the s32 return kills the §73 RETURN axis for free and leaves only the + * cheap T0 PARAMS axis for the ladder (fix_header_decl.py / --fix-def-sig / cast_call_sites). + * Both forms are byte-identical, so the orchestrator may swap the return type back at zero cost. + * + * SYMBOLS (§58 rules 1/2 — all splat spellings, all verified present): + * D_80192F7C asm/ov_SC01_077/data/tail.data.s:4355 (the state-handler vtable) + * D_80192F10 asm/ov_SC01_077/data/tail.data.s:4293 + * D_8011F9C4 main-EXE data; spelled `extern s32 D_8011F9C4;` in 5+ already-banked TUs + * jtbl_801D8B74 asm/ov_SC01_077/data/tail14.data.s:15 (compiler jump table — not named in C) + * + * JTBL VERIFIED (§8a gate): compiled .rodata = exactly 0x1C B / 7 words, 7x R_MIPS_32 .text with + * addends [0x58,0x58,0x58,0xE0,0xF0,0x100,0x58] -> +0x8015B950 = [B9A8,B9A8,B9A8,BA30,BA40,BA50, + * B9A8] == the original words at 0x801D8B74..0x801D8B8C. Bound `sltiu $v0,$v1,0x7` matches. + * The raw dlabel's 8th word 0x00000000 is NOT an entry — it is the intra-TU `.align 3` pad of the + * B34/B54/B74 jtbl chain; the object can never emit it (maspsx drops .align), so it must stay in + * the post-carve RAW data piece (the §53/§62/§81 carve chain applies at bank time). + * + * Same family as the TU's own already-matched func_8015AE2C: 7-case switch on ((s32 (*)(s32))func_801619A4)() + * (0/1/2/6 shared, 3/4/5 own, no default block — out-of-range and every `break` fall to the + * after-switch join), then a chain of "state handler" tests, each dispatching + * D_80192F7C[*(u16*)arg0](arg0) and returning. + * + * THREE LEVERS (draft -> MATCH in 3 compiles): + * + * 1. PROLOGUE CONSTANT = an INITIALIZED LOCAL, not a literal in the compare. + * Target opens with `lui $s2, 0xFFF5` in the *prologue*, used once ~200 ins later in + * `slt $v0,$s2,$s1`. No gcc-2.7.2 pass hoists a (set reg const_int) across basic blocks + * (loop.c needs a loop; cse/combine/sched never move insns between BBs) — so the insn must + * have been EMITTED in the first BB, i.e. the constant is a local initialized at the top of + * the function. cse then cannot fold it back into the compare: the `slt` operand predicate is + * `arith_operand`, which rejects a CONST_INT wider than 16 bits, so validate_change fails and + * the pseudo survives. Its live range spans every call -> global.c gives it a callee-saved reg. + * Writing `z > -0xB0000` inline instead emits the `lui` into the branch delay slot next to the + * compare (caller-saved $v0) and the function is 1 insn short. => `s32 lim = -0xB0000;` at top. + * + * 2. `lh` vs `lhu`: a short->short copy is a pure HImode move and gcc emits `lhu`. The target's + * `lh $v0,0x26($s0)` means the value passed through an SImode (int) temp: expand makes + * (set (reg:SI) (sign_extend (mem:HI))) + (set (mem:HI) (subreg:HI ...)), and combine cannot + * merge them (the merged form is mem<-mem, which no movhi accepts) so the sign-extending load + * survives. => route both halfword copies through the `s32 t` temp. + * + * 3. THE `goto` LAYOUT — dodging jump.c's store-flag conversion (jump.c:1005-1065). + * An if/else chain writing 0/1 into `doit` makes gcc collapse the last pair into + * `sltiu $v0,$v0,1`. jump.c fires that conversion when the insn immediately after a + * conditional jump is a lone `SET pseudo, CONST_INT` whose following simplejump targets the + * SAME label as the branch (jump.c:1038 `reallabelprev == temp || ... JUMP_LABEL(temp4) == + * JUMP_LABEL(insn)`) — exactly the shape of `if (c) x=0; else x=1;`. + * The target instead cross-jumps ALL the `doit=0` exits into ONE shared block placed after the + * `doit=1` fall-through; reorg's fill_slots_from_thread then COPIES that single set into all + * three branch delay slots and redirects each branch past it (which is why `addu $v0,$zero, + * $zero` appears 3x in delay slots and the shared block vanishes). A `goto zero;` / `goto one;` + * chain expresses that layout directly, and each conditional jump is then followed by a + * compare/call rather than a lone const set, so the store-flag conversion never triggers. + * GENERAL RULE: multiple predicates that all assign the SAME constant to one flag => write + * them as `goto` to a shared assignment, never as an if/else ladder. + */ +extern s32 D_8011F9C4; +extern s32 D_80192F10; + +extern s32 func_80161B18(void); +extern s32 func_801619A4(s32*); +extern s32 func_80149AA8(s32*); +extern void func_80149AD4(s32*); +extern s32 func_80149B54(s32*); +extern void func_80149BAC(s32*); +extern s32 func_801498E0(s32*); +extern s32 func_80149954(s32); +extern s32 func_80149A64(s32*); +extern void func_800CCCC0(s32 a0); +extern s32 func_80149CD4(s32 a0); +extern void func_8015E880(s32*); +extern s32 func_80149744(struct S_80149744*); +extern void func_80149788(void); +extern s32 func_801496D4(void*); +extern void func_80149704(void); +extern int func_80148AFC(void*); +extern void func_80146D90(s32 a0); +extern void func_80154150(s32 a0, s32 a1); +extern void func_801541D8(u8*, s32, s32); +extern s32 func_801488A8(u8*); +extern void func_80147078(s32*, s16); +extern void func_8015A264(void*); +extern s32 func_80013294(void*, void*); +extern void func_80159B70(void*); +extern s32 func_8016F1AC(void); +extern s32 func_80029178(s32 a0); +extern void func_80146DB8(s32*, s32*); +extern s32 func_80161CD0(s32, s32); +extern s32 func_80161208(s32 a0); +extern s32 func_801725A4(u8*); + +s32 func_8015B950(s32 arg0) +{ + + extern void (*D_80192F7C[])(void *); + s16 sp10[4]; + s16 sp18[4]; + s32 t; + s32 z; + s32 doit; + s32 lim = -0xB0000; + + if (func_80161B18() != 0) { + return; + } + switch (((s32 (*)(s32))func_801619A4)(arg0)) { + case 0: + case 1: + case 2: + case 6: + if (((s32 (*)(s32))func_80149AA8)(arg0) != 0) { + D_80192F7C[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149AD4)(arg0); + return; + } + if (((s32 (*)(s32))func_80149B54)(arg0) != 0) { + D_80192F7C[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149BAC)(arg0); + return; + } + break; + case 3: + ((void (*)(s32))func_801498E0)(arg0); + break; + case 4: + ((void (*)(s32))func_80149954)(arg0); + break; + case 5: + if (((s32 (*)(s32))func_80149A64)(arg0) != 0) { + D_80192F7C[*(u16 *)arg0]((void *)arg0); + func_800CCCC0(arg0); + return; + } + break; + } + if (func_80149CD4(arg0) != 0) { + D_80192F7C[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_8015E880)(arg0); + return; + } + if (((s32 (*)(s32))func_80149744)(arg0) != 0) { + D_80192F7C[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149788)(arg0); + return; + } + if (((s32 (*)(s32))func_801496D4)(arg0) != 0) { + D_80192F7C[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149704)(arg0); + if (((u8)((s32 (*)(s32))func_80148AFC)(arg0)) == 0) { + func_80146D90(arg0); + } + if ((*(s32 *)(arg0 + 0x24) | *(s32 *)(arg0 + 0x2C)) != 0) { + func_80154150(arg0, 0xF); + } else { + ((void (*)(s32, s32, s32))func_801541D8)(arg0, 0xD, 6); + } + *(s32 *)(arg0 + 0x238) = 1; + return; + } + if (((s32 (*)(s32))func_801488A8)(arg0) != 0) { + sp10[0] = 0; + sp10[1] = 0; + sp10[2] = 0; + t = *(s16 *)(arg0 + 0x26); + sp18[0] = t; + sp18[1] = 0; + t = *(s16 *)(arg0 + 0x2E); + sp18[2] = t; + D_80192F7C[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 1); + ((void (*)(s32))func_8015A264)(arg0); + t = -(((s32 (*)(s16 *, s16 *))func_80013294)(sp10, sp18) << 0x10); + if (t < *(s32 *)(arg0 + 0x2C)) { + *(s32 *)(arg0 + 0x2C) = t; + } + return; + } + if (*(u16 *)(arg0 + 0xB8) == 0x8000) { + D_80192F7C[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 0); + ((void (*)(s32))func_80159B70)(arg0); + return; + } + z = *(s32 *)(arg0 + 0x2C); + if (func_8016F1AC() != 0) { + goto zero; + } + if (z <= lim) { + goto one; + } + if (D_8011F9C4 == 0) { + goto zero; + } + if (((u8)func_80029178(0x21)) != 0) { + goto zero; + } +one: + doit = 1; + goto join; +zero: + doit = 0; +join: + if (doit != 0) { + D_80192F7C[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 0); + ((void (*)(s32))func_80159B70)(arg0); + func_80154150(arg0, 9); + ((void (*)(s32, s32 *))func_80146DB8)(arg0, &D_80192F10); + ((void (*)(s32, s32))func_80161CD0)(arg0, *(u16 *)(arg0 + 0x16E)); + return; + } + if (func_80161208(arg0) == 0) { + ((void (*)(s32))func_801725A4)(arg0); + } +} DEFINE_func_8015BD8C() /* dedup: shared engine-core @0x8015BD8C (src/shared) */ diff --git a/src/ov_SC02_011/ov_SC02_011_jr_8015AE2C.c b/src/ov_SC02_011/ov_SC02_011_jr_8015AE2C.c index 2fac49f38..03d0b15bb 100644 --- a/src/ov_SC02_011/ov_SC02_011_jr_8015AE2C.c +++ b/src/ov_SC02_011/ov_SC02_011_jr_8015AE2C.c @@ -1513,7 +1513,259 @@ DEFINE_func_8015B858() /* dedup: shared engine-core @0x8015B858 (src/shared) */ DEFINE_func_8015B8F8() /* dedup: shared engine-core @0x8015B8F8 (src/shared) */ -INCLUDE_ASM("asm/ov_SC02_011/nonmatchings/ov_SC02_011_jr_8015AE2C", func_8015B950); +extern s32 func_8015AE2C(); + +// @class: plumbing +// @stuck: none — MATCH (271/271, pin-free, zero asm). The ONLY residual is DEF-SIDE plumbing, and it is now named exactly: the in-TU instantiation `DEFINE_func_8015BEE4()` (engine_core.h:1851-1855) expands to `extern s32 func_8015B950(void);` INSIDE ov_SC01_077_jr_8015AE2C.c, ~14 lines BELOW this definition, so the 1-param def collides with a `(void)` prototype -> `conflicting types for func_8015B950` (.run/bank_func_8015B950.log). §73 PARAMS axis / T0. Surgical fix = §65b de-macroize that ONE instantiation (blast radius: this TU); the fleet-wide `(void)`->`()` header edit is §63 and must be R22-validated. +/* func_8015B950 (ov_SC01_077_jr_8015AE2C, 271 ins, jtbl_801D8B74) — SESSION-21 re-verified + * + * ── ROUND-2 INDEPENDENT RE-VERIFICATION (2026-07-27, fresh agent, §88e discipline) ───────────── + * match_one : MATCH (271 ins) against the CURRENT tree — §87 staleness re-checked today. + * .text size: compiled .text = 0x43C = 1084 B = 271 ins, EXACTLY the target's declared 0x43C + * ("nonmatching func_8015B950, 0x43C"). So this is NOT a §83a length drift hiding + * behind a zero count — the count is over equal-length streams. + * jtbl : RE-DECODED MECHANICALLY, not inherited. Compiled .rodata = 0x1C = 28 B = 7 words, + * 7x R_MIPS_32 -> .text with implicit addends [58,58,58,E0,F0,100,58]; +0x8015B950 + * = [8015B9A8, 8015B9A8, 8015B9A8, 8015BA30, 8015BA40, 8015BA50, 8015B9A8]. + * Diffed word-for-word against asm/ov_SC01_077/data/tail14.data.s:15-23 — 7/7 identical. + * symcheck : SYMS-DIFF target=35 draft=34, sole MISSING = jtbl_801D8B74. This is the §81 jr + * FALSE POSITIVE, re-confirmed here by reading the relocs: gcc emits its OWN table and + * references it with R_MIPS_HI16/LO16 against the SECTION `.rodata` (t.o +0x40/+0x48), + * so the splat's dlabel NAME can never appear in the draft object's relocation set. + * Nothing is dropped and nothing is invented: the draft's other 34 symbols are exactly + * the target's other 34. + * FAMILY : the x138 remap is clean and §84-safe. Every sibling is 271 ins with an IDENTICAL + * callee set; only THREE names vary per overlay — the two data labels and the jtbl: + * ov_SC01_077 D_80193360 / D_801933CC / jtbl_801D8B74 + * ov_SC03_099 D_80185A50 / D_80185ABC / jtbl_801BD898 + * ov_SC06_008 D_80187E44 / D_80187EB0 / jtbl_801A8734 + * The pair is always +0x6C apart, and NO literal in this draft encodes that distance + * (both labels are referenced by name), so there is no §84 derived-offset hazard. + * D_8011F9C4 is fleet-constant (main-EXE data) and must NOT be remapped. + * + * match_one: MATCH (271 ins) against the CURRENT tree (§87 staleness re-checked, 2026-07-27). + * PIN-FREE, zero asm, offset-pure (s32 arg0 + raw offsets) — x138 template-safe. + * Provenance: this is the Phase-26 crack (.run/phase26-cracks/func_8015B950.c) re-gated verbatim, + * with ONE deliberate change: the definition's return type void -> s32. + * - `void func_8015B950(s32 arg0)` : MATCH (271 ins) [the Phase-26 form] + * - `s32 func_8015B950(s32 arg0)` : MATCH (271 ins) [shipped — §3a-1 void->s32 is byte-neutral] + * The fleet/engine_core.h canonical decl is `extern s32 func_8015B950(void);` (engine_core.h:1852), + * and the last bank attempt (.run/bank_func_8015B950.log) died on `conflicting types for + * func_8015B950`. Shipping the s32 return kills the §73 RETURN axis for free and leaves only the + * cheap T0 PARAMS axis for the ladder (fix_header_decl.py / --fix-def-sig / cast_call_sites). + * Both forms are byte-identical, so the orchestrator may swap the return type back at zero cost. + * + * SYMBOLS (§58 rules 1/2 — all splat spellings, all verified present): + * D_801933CC asm/ov_SC01_077/data/tail.data.s:4355 (the state-handler vtable) + * D_80193360 asm/ov_SC01_077/data/tail.data.s:4293 + * D_8011F9C4 main-EXE data; spelled `extern s32 D_8011F9C4;` in 5+ already-banked TUs + * jtbl_801D8B74 asm/ov_SC01_077/data/tail14.data.s:15 (compiler jump table — not named in C) + * + * JTBL VERIFIED (§8a gate): compiled .rodata = exactly 0x1C B / 7 words, 7x R_MIPS_32 .text with + * addends [0x58,0x58,0x58,0xE0,0xF0,0x100,0x58] -> +0x8015B950 = [B9A8,B9A8,B9A8,BA30,BA40,BA50, + * B9A8] == the original words at 0x801D8B74..0x801D8B8C. Bound `sltiu $v0,$v1,0x7` matches. + * The raw dlabel's 8th word 0x00000000 is NOT an entry — it is the intra-TU `.align 3` pad of the + * B34/B54/B74 jtbl chain; the object can never emit it (maspsx drops .align), so it must stay in + * the post-carve RAW data piece (the §53/§62/§81 carve chain applies at bank time). + * + * Same family as the TU's own already-matched func_8015AE2C: 7-case switch on ((s32 (*)(s32))func_801619A4)() + * (0/1/2/6 shared, 3/4/5 own, no default block — out-of-range and every `break` fall to the + * after-switch join), then a chain of "state handler" tests, each dispatching + * D_801933CC[*(u16*)arg0](arg0) and returning. + * + * THREE LEVERS (draft -> MATCH in 3 compiles): + * + * 1. PROLOGUE CONSTANT = an INITIALIZED LOCAL, not a literal in the compare. + * Target opens with `lui $s2, 0xFFF5` in the *prologue*, used once ~200 ins later in + * `slt $v0,$s2,$s1`. No gcc-2.7.2 pass hoists a (set reg const_int) across basic blocks + * (loop.c needs a loop; cse/combine/sched never move insns between BBs) — so the insn must + * have been EMITTED in the first BB, i.e. the constant is a local initialized at the top of + * the function. cse then cannot fold it back into the compare: the `slt` operand predicate is + * `arith_operand`, which rejects a CONST_INT wider than 16 bits, so validate_change fails and + * the pseudo survives. Its live range spans every call -> global.c gives it a callee-saved reg. + * Writing `z > -0xB0000` inline instead emits the `lui` into the branch delay slot next to the + * compare (caller-saved $v0) and the function is 1 insn short. => `s32 lim = -0xB0000;` at top. + * + * 2. `lh` vs `lhu`: a short->short copy is a pure HImode move and gcc emits `lhu`. The target's + * `lh $v0,0x26($s0)` means the value passed through an SImode (int) temp: expand makes + * (set (reg:SI) (sign_extend (mem:HI))) + (set (mem:HI) (subreg:HI ...)), and combine cannot + * merge them (the merged form is mem<-mem, which no movhi accepts) so the sign-extending load + * survives. => route both halfword copies through the `s32 t` temp. + * + * 3. THE `goto` LAYOUT — dodging jump.c's store-flag conversion (jump.c:1005-1065). + * An if/else chain writing 0/1 into `doit` makes gcc collapse the last pair into + * `sltiu $v0,$v0,1`. jump.c fires that conversion when the insn immediately after a + * conditional jump is a lone `SET pseudo, CONST_INT` whose following simplejump targets the + * SAME label as the branch (jump.c:1038 `reallabelprev == temp || ... JUMP_LABEL(temp4) == + * JUMP_LABEL(insn)`) — exactly the shape of `if (c) x=0; else x=1;`. + * The target instead cross-jumps ALL the `doit=0` exits into ONE shared block placed after the + * `doit=1` fall-through; reorg's fill_slots_from_thread then COPIES that single set into all + * three branch delay slots and redirects each branch past it (which is why `addu $v0,$zero, + * $zero` appears 3x in delay slots and the shared block vanishes). A `goto zero;` / `goto one;` + * chain expresses that layout directly, and each conditional jump is then followed by a + * compare/call rather than a lone const set, so the store-flag conversion never triggers. + * GENERAL RULE: multiple predicates that all assign the SAME constant to one flag => write + * them as `goto` to a shared assignment, never as an if/else ladder. + */ +extern s32 D_8011F9C4; +extern s32 D_80193360; + +extern s32 func_80161B18(void); +extern s32 func_801619A4(s32*); +extern s32 func_80149AA8(s32*); +extern void func_80149AD4(s32*); +extern s32 func_80149B54(s32*); +extern void func_80149BAC(s32*); +extern s32 func_801498E0(s32*); +extern s32 func_80149954(s32); +extern s32 func_80149A64(s32*); +extern void func_800CCCC0(s32 a0); +extern s32 func_80149CD4(s32 a0); +extern void func_8015E880(s32*); +extern s32 func_80149744(struct S_80149744*); +extern void func_80149788(void); +extern s32 func_801496D4(void*); +extern void func_80149704(void); +extern int func_80148AFC(void*); +extern void func_80146D90(s32 a0); +extern void func_80154150(s32 a0, s32 a1); +extern void func_801541D8(u8*, s32, s32); +extern s32 func_801488A8(u8*); +extern void func_80147078(s32*, s16); +extern void func_8015A264(void*); +extern s32 func_80013294(void*, void*); +extern void func_80159B70(void*); +extern s32 func_8016F1AC(void); +extern s32 func_80029178(s32 a0); +extern void func_80146DB8(s32*, s32*); +extern s32 func_80161CD0(s32, s32); +extern s32 func_80161208(s32 a0); +extern s32 func_801725A4(u8*); + +s32 func_8015B950(s32 arg0) +{ + + extern void (*D_801933CC[])(void *); + s16 sp10[4]; + s16 sp18[4]; + s32 t; + s32 z; + s32 doit; + s32 lim = -0xB0000; + + if (func_80161B18() != 0) { + return; + } + switch (((s32 (*)(s32))func_801619A4)(arg0)) { + case 0: + case 1: + case 2: + case 6: + if (((s32 (*)(s32))func_80149AA8)(arg0) != 0) { + D_801933CC[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149AD4)(arg0); + return; + } + if (((s32 (*)(s32))func_80149B54)(arg0) != 0) { + D_801933CC[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149BAC)(arg0); + return; + } + break; + case 3: + ((void (*)(s32))func_801498E0)(arg0); + break; + case 4: + ((void (*)(s32))func_80149954)(arg0); + break; + case 5: + if (((s32 (*)(s32))func_80149A64)(arg0) != 0) { + D_801933CC[*(u16 *)arg0]((void *)arg0); + func_800CCCC0(arg0); + return; + } + break; + } + if (func_80149CD4(arg0) != 0) { + D_801933CC[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_8015E880)(arg0); + return; + } + if (((s32 (*)(s32))func_80149744)(arg0) != 0) { + D_801933CC[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149788)(arg0); + return; + } + if (((s32 (*)(s32))func_801496D4)(arg0) != 0) { + D_801933CC[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149704)(arg0); + if (((u8)((s32 (*)(s32))func_80148AFC)(arg0)) == 0) { + func_80146D90(arg0); + } + if ((*(s32 *)(arg0 + 0x24) | *(s32 *)(arg0 + 0x2C)) != 0) { + func_80154150(arg0, 0xF); + } else { + ((void (*)(s32, s32, s32))func_801541D8)(arg0, 0xD, 6); + } + *(s32 *)(arg0 + 0x238) = 1; + return; + } + if (((s32 (*)(s32))func_801488A8)(arg0) != 0) { + sp10[0] = 0; + sp10[1] = 0; + sp10[2] = 0; + t = *(s16 *)(arg0 + 0x26); + sp18[0] = t; + sp18[1] = 0; + t = *(s16 *)(arg0 + 0x2E); + sp18[2] = t; + D_801933CC[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 1); + ((void (*)(s32))func_8015A264)(arg0); + t = -(((s32 (*)(s16 *, s16 *))func_80013294)(sp10, sp18) << 0x10); + if (t < *(s32 *)(arg0 + 0x2C)) { + *(s32 *)(arg0 + 0x2C) = t; + } + return; + } + if (*(u16 *)(arg0 + 0xB8) == 0x8000) { + D_801933CC[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 0); + ((void (*)(s32))func_80159B70)(arg0); + return; + } + z = *(s32 *)(arg0 + 0x2C); + if (func_8016F1AC() != 0) { + goto zero; + } + if (z <= lim) { + goto one; + } + if (D_8011F9C4 == 0) { + goto zero; + } + if (((u8)func_80029178(0x21)) != 0) { + goto zero; + } +one: + doit = 1; + goto join; +zero: + doit = 0; +join: + if (doit != 0) { + D_801933CC[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 0); + ((void (*)(s32))func_80159B70)(arg0); + func_80154150(arg0, 9); + ((void (*)(s32, s32 *))func_80146DB8)(arg0, &D_80193360); + ((void (*)(s32, s32))func_80161CD0)(arg0, *(u16 *)(arg0 + 0x16E)); + return; + } + if (func_80161208(arg0) == 0) { + ((void (*)(s32))func_801725A4)(arg0); + } +} DEFINE_func_8015BD8C() /* dedup: shared engine-core @0x8015BD8C (src/shared) */ diff --git a/src/ov_SC02_015/ov_SC02_015_jr_8015AE2C.c b/src/ov_SC02_015/ov_SC02_015_jr_8015AE2C.c index d0ef0f37a..7e4348098 100644 --- a/src/ov_SC02_015/ov_SC02_015_jr_8015AE2C.c +++ b/src/ov_SC02_015/ov_SC02_015_jr_8015AE2C.c @@ -1511,7 +1511,259 @@ DEFINE_func_8015B858() /* dedup: shared engine-core @0x8015B858 (src/shared) */ DEFINE_func_8015B8F8() /* dedup: shared engine-core @0x8015B8F8 (src/shared) */ -INCLUDE_ASM("asm/ov_SC02_015/nonmatchings/ov_SC02_015_jr_8015AE2C", func_8015B950); +extern s32 func_8015AE2C(); + +// @class: plumbing +// @stuck: none — MATCH (271/271, pin-free, zero asm). The ONLY residual is DEF-SIDE plumbing, and it is now named exactly: the in-TU instantiation `DEFINE_func_8015BEE4()` (engine_core.h:1851-1855) expands to `extern s32 func_8015B950(void);` INSIDE ov_SC01_077_jr_8015AE2C.c, ~14 lines BELOW this definition, so the 1-param def collides with a `(void)` prototype -> `conflicting types for func_8015B950` (.run/bank_func_8015B950.log). §73 PARAMS axis / T0. Surgical fix = §65b de-macroize that ONE instantiation (blast radius: this TU); the fleet-wide `(void)`->`()` header edit is §63 and must be R22-validated. +/* func_8015B950 (ov_SC01_077_jr_8015AE2C, 271 ins, jtbl_801D8B74) — SESSION-21 re-verified + * + * ── ROUND-2 INDEPENDENT RE-VERIFICATION (2026-07-27, fresh agent, §88e discipline) ───────────── + * match_one : MATCH (271 ins) against the CURRENT tree — §87 staleness re-checked today. + * .text size: compiled .text = 0x43C = 1084 B = 271 ins, EXACTLY the target's declared 0x43C + * ("nonmatching func_8015B950, 0x43C"). So this is NOT a §83a length drift hiding + * behind a zero count — the count is over equal-length streams. + * jtbl : RE-DECODED MECHANICALLY, not inherited. Compiled .rodata = 0x1C = 28 B = 7 words, + * 7x R_MIPS_32 -> .text with implicit addends [58,58,58,E0,F0,100,58]; +0x8015B950 + * = [8015B9A8, 8015B9A8, 8015B9A8, 8015BA30, 8015BA40, 8015BA50, 8015B9A8]. + * Diffed word-for-word against asm/ov_SC01_077/data/tail14.data.s:15-23 — 7/7 identical. + * symcheck : SYMS-DIFF target=35 draft=34, sole MISSING = jtbl_801D8B74. This is the §81 jr + * FALSE POSITIVE, re-confirmed here by reading the relocs: gcc emits its OWN table and + * references it with R_MIPS_HI16/LO16 against the SECTION `.rodata` (t.o +0x40/+0x48), + * so the splat's dlabel NAME can never appear in the draft object's relocation set. + * Nothing is dropped and nothing is invented: the draft's other 34 symbols are exactly + * the target's other 34. + * FAMILY : the x138 remap is clean and §84-safe. Every sibling is 271 ins with an IDENTICAL + * callee set; only THREE names vary per overlay — the two data labels and the jtbl: + * ov_SC01_077 D_80180874 / D_801808E0 / jtbl_801D8B74 + * ov_SC03_099 D_80185A50 / D_80185ABC / jtbl_801BD898 + * ov_SC06_008 D_80187E44 / D_80187EB0 / jtbl_801A8734 + * The pair is always +0x6C apart, and NO literal in this draft encodes that distance + * (both labels are referenced by name), so there is no §84 derived-offset hazard. + * D_8011F9C4 is fleet-constant (main-EXE data) and must NOT be remapped. + * + * match_one: MATCH (271 ins) against the CURRENT tree (§87 staleness re-checked, 2026-07-27). + * PIN-FREE, zero asm, offset-pure (s32 arg0 + raw offsets) — x138 template-safe. + * Provenance: this is the Phase-26 crack (.run/phase26-cracks/func_8015B950.c) re-gated verbatim, + * with ONE deliberate change: the definition's return type void -> s32. + * - `void func_8015B950(s32 arg0)` : MATCH (271 ins) [the Phase-26 form] + * - `s32 func_8015B950(s32 arg0)` : MATCH (271 ins) [shipped — §3a-1 void->s32 is byte-neutral] + * The fleet/engine_core.h canonical decl is `extern s32 func_8015B950(void);` (engine_core.h:1852), + * and the last bank attempt (.run/bank_func_8015B950.log) died on `conflicting types for + * func_8015B950`. Shipping the s32 return kills the §73 RETURN axis for free and leaves only the + * cheap T0 PARAMS axis for the ladder (fix_header_decl.py / --fix-def-sig / cast_call_sites). + * Both forms are byte-identical, so the orchestrator may swap the return type back at zero cost. + * + * SYMBOLS (§58 rules 1/2 — all splat spellings, all verified present): + * D_801808E0 asm/ov_SC01_077/data/tail.data.s:4355 (the state-handler vtable) + * D_80180874 asm/ov_SC01_077/data/tail.data.s:4293 + * D_8011F9C4 main-EXE data; spelled `extern s32 D_8011F9C4;` in 5+ already-banked TUs + * jtbl_801D8B74 asm/ov_SC01_077/data/tail14.data.s:15 (compiler jump table — not named in C) + * + * JTBL VERIFIED (§8a gate): compiled .rodata = exactly 0x1C B / 7 words, 7x R_MIPS_32 .text with + * addends [0x58,0x58,0x58,0xE0,0xF0,0x100,0x58] -> +0x8015B950 = [B9A8,B9A8,B9A8,BA30,BA40,BA50, + * B9A8] == the original words at 0x801D8B74..0x801D8B8C. Bound `sltiu $v0,$v1,0x7` matches. + * The raw dlabel's 8th word 0x00000000 is NOT an entry — it is the intra-TU `.align 3` pad of the + * B34/B54/B74 jtbl chain; the object can never emit it (maspsx drops .align), so it must stay in + * the post-carve RAW data piece (the §53/§62/§81 carve chain applies at bank time). + * + * Same family as the TU's own already-matched func_8015AE2C: 7-case switch on ((s32 (*)(s32))func_801619A4)() + * (0/1/2/6 shared, 3/4/5 own, no default block — out-of-range and every `break` fall to the + * after-switch join), then a chain of "state handler" tests, each dispatching + * D_801808E0[*(u16*)arg0](arg0) and returning. + * + * THREE LEVERS (draft -> MATCH in 3 compiles): + * + * 1. PROLOGUE CONSTANT = an INITIALIZED LOCAL, not a literal in the compare. + * Target opens with `lui $s2, 0xFFF5` in the *prologue*, used once ~200 ins later in + * `slt $v0,$s2,$s1`. No gcc-2.7.2 pass hoists a (set reg const_int) across basic blocks + * (loop.c needs a loop; cse/combine/sched never move insns between BBs) — so the insn must + * have been EMITTED in the first BB, i.e. the constant is a local initialized at the top of + * the function. cse then cannot fold it back into the compare: the `slt` operand predicate is + * `arith_operand`, which rejects a CONST_INT wider than 16 bits, so validate_change fails and + * the pseudo survives. Its live range spans every call -> global.c gives it a callee-saved reg. + * Writing `z > -0xB0000` inline instead emits the `lui` into the branch delay slot next to the + * compare (caller-saved $v0) and the function is 1 insn short. => `s32 lim = -0xB0000;` at top. + * + * 2. `lh` vs `lhu`: a short->short copy is a pure HImode move and gcc emits `lhu`. The target's + * `lh $v0,0x26($s0)` means the value passed through an SImode (int) temp: expand makes + * (set (reg:SI) (sign_extend (mem:HI))) + (set (mem:HI) (subreg:HI ...)), and combine cannot + * merge them (the merged form is mem<-mem, which no movhi accepts) so the sign-extending load + * survives. => route both halfword copies through the `s32 t` temp. + * + * 3. THE `goto` LAYOUT — dodging jump.c's store-flag conversion (jump.c:1005-1065). + * An if/else chain writing 0/1 into `doit` makes gcc collapse the last pair into + * `sltiu $v0,$v0,1`. jump.c fires that conversion when the insn immediately after a + * conditional jump is a lone `SET pseudo, CONST_INT` whose following simplejump targets the + * SAME label as the branch (jump.c:1038 `reallabelprev == temp || ... JUMP_LABEL(temp4) == + * JUMP_LABEL(insn)`) — exactly the shape of `if (c) x=0; else x=1;`. + * The target instead cross-jumps ALL the `doit=0` exits into ONE shared block placed after the + * `doit=1` fall-through; reorg's fill_slots_from_thread then COPIES that single set into all + * three branch delay slots and redirects each branch past it (which is why `addu $v0,$zero, + * $zero` appears 3x in delay slots and the shared block vanishes). A `goto zero;` / `goto one;` + * chain expresses that layout directly, and each conditional jump is then followed by a + * compare/call rather than a lone const set, so the store-flag conversion never triggers. + * GENERAL RULE: multiple predicates that all assign the SAME constant to one flag => write + * them as `goto` to a shared assignment, never as an if/else ladder. + */ +extern s32 D_8011F9C4; +extern s32 D_80180874; + +extern s32 func_80161B18(void); +extern s32 func_801619A4(s32*); +extern s32 func_80149AA8(s32*); +extern void func_80149AD4(s32*); +extern s32 func_80149B54(s32*); +extern void func_80149BAC(s32*); +extern s32 func_801498E0(s32*); +extern s32 func_80149954(s32); +extern s32 func_80149A64(s32*); +extern void func_800CCCC0(s32 a0); +extern s32 func_80149CD4(s32 a0); +extern void func_8015E880(s32*); +extern s32 func_80149744(struct S_80149744*); +extern void func_80149788(void); +extern s32 func_801496D4(void*); +extern void func_80149704(void); +extern int func_80148AFC(void*); +extern void func_80146D90(s32 a0); +extern void func_80154150(s32 a0, s32 a1); +extern void func_801541D8(u8*, s32, s32); +extern s32 func_801488A8(u8*); +extern void func_80147078(s32*, s16); +extern void func_8015A264(void*); +extern s32 func_80013294(void*, void*); +extern void func_80159B70(void*); +extern s32 func_8016F1AC(void); +extern s32 func_80029178(s32 a0); +extern void func_80146DB8(s32*, s32*); +extern s32 func_80161CD0(s32, s32); +extern s32 func_80161208(s32 a0); +extern s32 func_801725A4(u8*); + +s32 func_8015B950(s32 arg0) +{ + + extern void (*D_801808E0[])(void *); + s16 sp10[4]; + s16 sp18[4]; + s32 t; + s32 z; + s32 doit; + s32 lim = -0xB0000; + + if (func_80161B18() != 0) { + return; + } + switch (((s32 (*)(s32))func_801619A4)(arg0)) { + case 0: + case 1: + case 2: + case 6: + if (((s32 (*)(s32))func_80149AA8)(arg0) != 0) { + D_801808E0[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149AD4)(arg0); + return; + } + if (((s32 (*)(s32))func_80149B54)(arg0) != 0) { + D_801808E0[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149BAC)(arg0); + return; + } + break; + case 3: + ((void (*)(s32))func_801498E0)(arg0); + break; + case 4: + ((void (*)(s32))func_80149954)(arg0); + break; + case 5: + if (((s32 (*)(s32))func_80149A64)(arg0) != 0) { + D_801808E0[*(u16 *)arg0]((void *)arg0); + func_800CCCC0(arg0); + return; + } + break; + } + if (func_80149CD4(arg0) != 0) { + D_801808E0[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_8015E880)(arg0); + return; + } + if (((s32 (*)(s32))func_80149744)(arg0) != 0) { + D_801808E0[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149788)(arg0); + return; + } + if (((s32 (*)(s32))func_801496D4)(arg0) != 0) { + D_801808E0[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149704)(arg0); + if (((u8)((s32 (*)(s32))func_80148AFC)(arg0)) == 0) { + func_80146D90(arg0); + } + if ((*(s32 *)(arg0 + 0x24) | *(s32 *)(arg0 + 0x2C)) != 0) { + func_80154150(arg0, 0xF); + } else { + ((void (*)(s32, s32, s32))func_801541D8)(arg0, 0xD, 6); + } + *(s32 *)(arg0 + 0x238) = 1; + return; + } + if (((s32 (*)(s32))func_801488A8)(arg0) != 0) { + sp10[0] = 0; + sp10[1] = 0; + sp10[2] = 0; + t = *(s16 *)(arg0 + 0x26); + sp18[0] = t; + sp18[1] = 0; + t = *(s16 *)(arg0 + 0x2E); + sp18[2] = t; + D_801808E0[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 1); + ((void (*)(s32))func_8015A264)(arg0); + t = -(((s32 (*)(s16 *, s16 *))func_80013294)(sp10, sp18) << 0x10); + if (t < *(s32 *)(arg0 + 0x2C)) { + *(s32 *)(arg0 + 0x2C) = t; + } + return; + } + if (*(u16 *)(arg0 + 0xB8) == 0x8000) { + D_801808E0[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 0); + ((void (*)(s32))func_80159B70)(arg0); + return; + } + z = *(s32 *)(arg0 + 0x2C); + if (func_8016F1AC() != 0) { + goto zero; + } + if (z <= lim) { + goto one; + } + if (D_8011F9C4 == 0) { + goto zero; + } + if (((u8)func_80029178(0x21)) != 0) { + goto zero; + } +one: + doit = 1; + goto join; +zero: + doit = 0; +join: + if (doit != 0) { + D_801808E0[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 0); + ((void (*)(s32))func_80159B70)(arg0); + func_80154150(arg0, 9); + ((void (*)(s32, s32 *))func_80146DB8)(arg0, &D_80180874); + ((void (*)(s32, s32))func_80161CD0)(arg0, *(u16 *)(arg0 + 0x16E)); + return; + } + if (func_80161208(arg0) == 0) { + ((void (*)(s32))func_801725A4)(arg0); + } +} DEFINE_func_8015BD8C() /* dedup: shared engine-core @0x8015BD8C (src/shared) */ diff --git a/src/ov_SC02_016/ov_SC02_016_jr_8015AE2C.c b/src/ov_SC02_016/ov_SC02_016_jr_8015AE2C.c index f2703aace..4646e6a04 100644 --- a/src/ov_SC02_016/ov_SC02_016_jr_8015AE2C.c +++ b/src/ov_SC02_016/ov_SC02_016_jr_8015AE2C.c @@ -1513,7 +1513,259 @@ DEFINE_func_8015B858() /* dedup: shared engine-core @0x8015B858 (src/shared) */ DEFINE_func_8015B8F8() /* dedup: shared engine-core @0x8015B8F8 (src/shared) */ -INCLUDE_ASM("asm/ov_SC02_016/nonmatchings/ov_SC02_016_jr_8015AE2C", func_8015B950); +extern s32 func_8015AE2C(); + +// @class: plumbing +// @stuck: none — MATCH (271/271, pin-free, zero asm). The ONLY residual is DEF-SIDE plumbing, and it is now named exactly: the in-TU instantiation `DEFINE_func_8015BEE4()` (engine_core.h:1851-1855) expands to `extern s32 func_8015B950(void);` INSIDE ov_SC01_077_jr_8015AE2C.c, ~14 lines BELOW this definition, so the 1-param def collides with a `(void)` prototype -> `conflicting types for func_8015B950` (.run/bank_func_8015B950.log). §73 PARAMS axis / T0. Surgical fix = §65b de-macroize that ONE instantiation (blast radius: this TU); the fleet-wide `(void)`->`()` header edit is §63 and must be R22-validated. +/* func_8015B950 (ov_SC01_077_jr_8015AE2C, 271 ins, jtbl_801D8B74) — SESSION-21 re-verified + * + * ── ROUND-2 INDEPENDENT RE-VERIFICATION (2026-07-27, fresh agent, §88e discipline) ───────────── + * match_one : MATCH (271 ins) against the CURRENT tree — §87 staleness re-checked today. + * .text size: compiled .text = 0x43C = 1084 B = 271 ins, EXACTLY the target's declared 0x43C + * ("nonmatching func_8015B950, 0x43C"). So this is NOT a §83a length drift hiding + * behind a zero count — the count is over equal-length streams. + * jtbl : RE-DECODED MECHANICALLY, not inherited. Compiled .rodata = 0x1C = 28 B = 7 words, + * 7x R_MIPS_32 -> .text with implicit addends [58,58,58,E0,F0,100,58]; +0x8015B950 + * = [8015B9A8, 8015B9A8, 8015B9A8, 8015BA30, 8015BA40, 8015BA50, 8015B9A8]. + * Diffed word-for-word against asm/ov_SC01_077/data/tail14.data.s:15-23 — 7/7 identical. + * symcheck : SYMS-DIFF target=35 draft=34, sole MISSING = jtbl_801D8B74. This is the §81 jr + * FALSE POSITIVE, re-confirmed here by reading the relocs: gcc emits its OWN table and + * references it with R_MIPS_HI16/LO16 against the SECTION `.rodata` (t.o +0x40/+0x48), + * so the splat's dlabel NAME can never appear in the draft object's relocation set. + * Nothing is dropped and nothing is invented: the draft's other 34 symbols are exactly + * the target's other 34. + * FAMILY : the x138 remap is clean and §84-safe. Every sibling is 271 ins with an IDENTICAL + * callee set; only THREE names vary per overlay — the two data labels and the jtbl: + * ov_SC01_077 D_80186AAC / D_80186B18 / jtbl_801D8B74 + * ov_SC03_099 D_80185A50 / D_80185ABC / jtbl_801BD898 + * ov_SC06_008 D_80187E44 / D_80187EB0 / jtbl_801A8734 + * The pair is always +0x6C apart, and NO literal in this draft encodes that distance + * (both labels are referenced by name), so there is no §84 derived-offset hazard. + * D_8011F9C4 is fleet-constant (main-EXE data) and must NOT be remapped. + * + * match_one: MATCH (271 ins) against the CURRENT tree (§87 staleness re-checked, 2026-07-27). + * PIN-FREE, zero asm, offset-pure (s32 arg0 + raw offsets) — x138 template-safe. + * Provenance: this is the Phase-26 crack (.run/phase26-cracks/func_8015B950.c) re-gated verbatim, + * with ONE deliberate change: the definition's return type void -> s32. + * - `void func_8015B950(s32 arg0)` : MATCH (271 ins) [the Phase-26 form] + * - `s32 func_8015B950(s32 arg0)` : MATCH (271 ins) [shipped — §3a-1 void->s32 is byte-neutral] + * The fleet/engine_core.h canonical decl is `extern s32 func_8015B950(void);` (engine_core.h:1852), + * and the last bank attempt (.run/bank_func_8015B950.log) died on `conflicting types for + * func_8015B950`. Shipping the s32 return kills the §73 RETURN axis for free and leaves only the + * cheap T0 PARAMS axis for the ladder (fix_header_decl.py / --fix-def-sig / cast_call_sites). + * Both forms are byte-identical, so the orchestrator may swap the return type back at zero cost. + * + * SYMBOLS (§58 rules 1/2 — all splat spellings, all verified present): + * D_80186B18 asm/ov_SC01_077/data/tail.data.s:4355 (the state-handler vtable) + * D_80186AAC asm/ov_SC01_077/data/tail.data.s:4293 + * D_8011F9C4 main-EXE data; spelled `extern s32 D_8011F9C4;` in 5+ already-banked TUs + * jtbl_801D8B74 asm/ov_SC01_077/data/tail14.data.s:15 (compiler jump table — not named in C) + * + * JTBL VERIFIED (§8a gate): compiled .rodata = exactly 0x1C B / 7 words, 7x R_MIPS_32 .text with + * addends [0x58,0x58,0x58,0xE0,0xF0,0x100,0x58] -> +0x8015B950 = [B9A8,B9A8,B9A8,BA30,BA40,BA50, + * B9A8] == the original words at 0x801D8B74..0x801D8B8C. Bound `sltiu $v0,$v1,0x7` matches. + * The raw dlabel's 8th word 0x00000000 is NOT an entry — it is the intra-TU `.align 3` pad of the + * B34/B54/B74 jtbl chain; the object can never emit it (maspsx drops .align), so it must stay in + * the post-carve RAW data piece (the §53/§62/§81 carve chain applies at bank time). + * + * Same family as the TU's own already-matched func_8015AE2C: 7-case switch on ((s32 (*)(s32))func_801619A4)() + * (0/1/2/6 shared, 3/4/5 own, no default block — out-of-range and every `break` fall to the + * after-switch join), then a chain of "state handler" tests, each dispatching + * D_80186B18[*(u16*)arg0](arg0) and returning. + * + * THREE LEVERS (draft -> MATCH in 3 compiles): + * + * 1. PROLOGUE CONSTANT = an INITIALIZED LOCAL, not a literal in the compare. + * Target opens with `lui $s2, 0xFFF5` in the *prologue*, used once ~200 ins later in + * `slt $v0,$s2,$s1`. No gcc-2.7.2 pass hoists a (set reg const_int) across basic blocks + * (loop.c needs a loop; cse/combine/sched never move insns between BBs) — so the insn must + * have been EMITTED in the first BB, i.e. the constant is a local initialized at the top of + * the function. cse then cannot fold it back into the compare: the `slt` operand predicate is + * `arith_operand`, which rejects a CONST_INT wider than 16 bits, so validate_change fails and + * the pseudo survives. Its live range spans every call -> global.c gives it a callee-saved reg. + * Writing `z > -0xB0000` inline instead emits the `lui` into the branch delay slot next to the + * compare (caller-saved $v0) and the function is 1 insn short. => `s32 lim = -0xB0000;` at top. + * + * 2. `lh` vs `lhu`: a short->short copy is a pure HImode move and gcc emits `lhu`. The target's + * `lh $v0,0x26($s0)` means the value passed through an SImode (int) temp: expand makes + * (set (reg:SI) (sign_extend (mem:HI))) + (set (mem:HI) (subreg:HI ...)), and combine cannot + * merge them (the merged form is mem<-mem, which no movhi accepts) so the sign-extending load + * survives. => route both halfword copies through the `s32 t` temp. + * + * 3. THE `goto` LAYOUT — dodging jump.c's store-flag conversion (jump.c:1005-1065). + * An if/else chain writing 0/1 into `doit` makes gcc collapse the last pair into + * `sltiu $v0,$v0,1`. jump.c fires that conversion when the insn immediately after a + * conditional jump is a lone `SET pseudo, CONST_INT` whose following simplejump targets the + * SAME label as the branch (jump.c:1038 `reallabelprev == temp || ... JUMP_LABEL(temp4) == + * JUMP_LABEL(insn)`) — exactly the shape of `if (c) x=0; else x=1;`. + * The target instead cross-jumps ALL the `doit=0` exits into ONE shared block placed after the + * `doit=1` fall-through; reorg's fill_slots_from_thread then COPIES that single set into all + * three branch delay slots and redirects each branch past it (which is why `addu $v0,$zero, + * $zero` appears 3x in delay slots and the shared block vanishes). A `goto zero;` / `goto one;` + * chain expresses that layout directly, and each conditional jump is then followed by a + * compare/call rather than a lone const set, so the store-flag conversion never triggers. + * GENERAL RULE: multiple predicates that all assign the SAME constant to one flag => write + * them as `goto` to a shared assignment, never as an if/else ladder. + */ +extern s32 D_8011F9C4; +extern s32 D_80186AAC; + +extern s32 func_80161B18(void); +extern s32 func_801619A4(s32*); +extern s32 func_80149AA8(s32*); +extern void func_80149AD4(s32*); +extern s32 func_80149B54(s32*); +extern void func_80149BAC(s32*); +extern s32 func_801498E0(s32*); +extern s32 func_80149954(s32); +extern s32 func_80149A64(s32*); +extern void func_800CCCC0(s32 a0); +extern s32 func_80149CD4(s32 a0); +extern void func_8015E880(s32*); +extern s32 func_80149744(struct S_80149744*); +extern void func_80149788(void); +extern s32 func_801496D4(void*); +extern void func_80149704(void); +extern int func_80148AFC(void*); +extern void func_80146D90(s32 a0); +extern void func_80154150(s32 a0, s32 a1); +extern void func_801541D8(u8*, s32, s32); +extern s32 func_801488A8(u8*); +extern void func_80147078(s32*, s16); +extern void func_8015A264(void*); +extern s32 func_80013294(void*, void*); +extern void func_80159B70(void*); +extern s32 func_8016F1AC(void); +extern s32 func_80029178(s32 a0); +extern void func_80146DB8(s32*, s32*); +extern s32 func_80161CD0(s32, s32); +extern s32 func_80161208(s32 a0); +extern s32 func_801725A4(u8*); + +s32 func_8015B950(s32 arg0) +{ + + extern void (*D_80186B18[])(void *); + s16 sp10[4]; + s16 sp18[4]; + s32 t; + s32 z; + s32 doit; + s32 lim = -0xB0000; + + if (func_80161B18() != 0) { + return; + } + switch (((s32 (*)(s32))func_801619A4)(arg0)) { + case 0: + case 1: + case 2: + case 6: + if (((s32 (*)(s32))func_80149AA8)(arg0) != 0) { + D_80186B18[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149AD4)(arg0); + return; + } + if (((s32 (*)(s32))func_80149B54)(arg0) != 0) { + D_80186B18[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149BAC)(arg0); + return; + } + break; + case 3: + ((void (*)(s32))func_801498E0)(arg0); + break; + case 4: + ((void (*)(s32))func_80149954)(arg0); + break; + case 5: + if (((s32 (*)(s32))func_80149A64)(arg0) != 0) { + D_80186B18[*(u16 *)arg0]((void *)arg0); + func_800CCCC0(arg0); + return; + } + break; + } + if (func_80149CD4(arg0) != 0) { + D_80186B18[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_8015E880)(arg0); + return; + } + if (((s32 (*)(s32))func_80149744)(arg0) != 0) { + D_80186B18[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149788)(arg0); + return; + } + if (((s32 (*)(s32))func_801496D4)(arg0) != 0) { + D_80186B18[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149704)(arg0); + if (((u8)((s32 (*)(s32))func_80148AFC)(arg0)) == 0) { + func_80146D90(arg0); + } + if ((*(s32 *)(arg0 + 0x24) | *(s32 *)(arg0 + 0x2C)) != 0) { + func_80154150(arg0, 0xF); + } else { + ((void (*)(s32, s32, s32))func_801541D8)(arg0, 0xD, 6); + } + *(s32 *)(arg0 + 0x238) = 1; + return; + } + if (((s32 (*)(s32))func_801488A8)(arg0) != 0) { + sp10[0] = 0; + sp10[1] = 0; + sp10[2] = 0; + t = *(s16 *)(arg0 + 0x26); + sp18[0] = t; + sp18[1] = 0; + t = *(s16 *)(arg0 + 0x2E); + sp18[2] = t; + D_80186B18[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 1); + ((void (*)(s32))func_8015A264)(arg0); + t = -(((s32 (*)(s16 *, s16 *))func_80013294)(sp10, sp18) << 0x10); + if (t < *(s32 *)(arg0 + 0x2C)) { + *(s32 *)(arg0 + 0x2C) = t; + } + return; + } + if (*(u16 *)(arg0 + 0xB8) == 0x8000) { + D_80186B18[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 0); + ((void (*)(s32))func_80159B70)(arg0); + return; + } + z = *(s32 *)(arg0 + 0x2C); + if (func_8016F1AC() != 0) { + goto zero; + } + if (z <= lim) { + goto one; + } + if (D_8011F9C4 == 0) { + goto zero; + } + if (((u8)func_80029178(0x21)) != 0) { + goto zero; + } +one: + doit = 1; + goto join; +zero: + doit = 0; +join: + if (doit != 0) { + D_80186B18[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 0); + ((void (*)(s32))func_80159B70)(arg0); + func_80154150(arg0, 9); + ((void (*)(s32, s32 *))func_80146DB8)(arg0, &D_80186AAC); + ((void (*)(s32, s32))func_80161CD0)(arg0, *(u16 *)(arg0 + 0x16E)); + return; + } + if (func_80161208(arg0) == 0) { + ((void (*)(s32))func_801725A4)(arg0); + } +} DEFINE_func_8015BD8C() /* dedup: shared engine-core @0x8015BD8C (src/shared) */ diff --git a/src/ov_SC02_017/ov_SC02_017_jr_8015AE2C.c b/src/ov_SC02_017/ov_SC02_017_jr_8015AE2C.c index 3d62df5a7..0aec5cca9 100644 --- a/src/ov_SC02_017/ov_SC02_017_jr_8015AE2C.c +++ b/src/ov_SC02_017/ov_SC02_017_jr_8015AE2C.c @@ -1513,7 +1513,259 @@ DEFINE_func_8015B858() /* dedup: shared engine-core @0x8015B858 (src/shared) */ DEFINE_func_8015B8F8() /* dedup: shared engine-core @0x8015B8F8 (src/shared) */ -INCLUDE_ASM("asm/ov_SC02_017/nonmatchings/ov_SC02_017_jr_8015AE2C", func_8015B950); +extern s32 func_8015AE2C(); + +// @class: plumbing +// @stuck: none — MATCH (271/271, pin-free, zero asm). The ONLY residual is DEF-SIDE plumbing, and it is now named exactly: the in-TU instantiation `DEFINE_func_8015BEE4()` (engine_core.h:1851-1855) expands to `extern s32 func_8015B950(void);` INSIDE ov_SC01_077_jr_8015AE2C.c, ~14 lines BELOW this definition, so the 1-param def collides with a `(void)` prototype -> `conflicting types for func_8015B950` (.run/bank_func_8015B950.log). §73 PARAMS axis / T0. Surgical fix = §65b de-macroize that ONE instantiation (blast radius: this TU); the fleet-wide `(void)`->`()` header edit is §63 and must be R22-validated. +/* func_8015B950 (ov_SC01_077_jr_8015AE2C, 271 ins, jtbl_801D8B74) — SESSION-21 re-verified + * + * ── ROUND-2 INDEPENDENT RE-VERIFICATION (2026-07-27, fresh agent, §88e discipline) ───────────── + * match_one : MATCH (271 ins) against the CURRENT tree — §87 staleness re-checked today. + * .text size: compiled .text = 0x43C = 1084 B = 271 ins, EXACTLY the target's declared 0x43C + * ("nonmatching func_8015B950, 0x43C"). So this is NOT a §83a length drift hiding + * behind a zero count — the count is over equal-length streams. + * jtbl : RE-DECODED MECHANICALLY, not inherited. Compiled .rodata = 0x1C = 28 B = 7 words, + * 7x R_MIPS_32 -> .text with implicit addends [58,58,58,E0,F0,100,58]; +0x8015B950 + * = [8015B9A8, 8015B9A8, 8015B9A8, 8015BA30, 8015BA40, 8015BA50, 8015B9A8]. + * Diffed word-for-word against asm/ov_SC01_077/data/tail14.data.s:15-23 — 7/7 identical. + * symcheck : SYMS-DIFF target=35 draft=34, sole MISSING = jtbl_801D8B74. This is the §81 jr + * FALSE POSITIVE, re-confirmed here by reading the relocs: gcc emits its OWN table and + * references it with R_MIPS_HI16/LO16 against the SECTION `.rodata` (t.o +0x40/+0x48), + * so the splat's dlabel NAME can never appear in the draft object's relocation set. + * Nothing is dropped and nothing is invented: the draft's other 34 symbols are exactly + * the target's other 34. + * FAMILY : the x138 remap is clean and §84-safe. Every sibling is 271 ins with an IDENTICAL + * callee set; only THREE names vary per overlay — the two data labels and the jtbl: + * ov_SC01_077 D_8018CB04 / D_8018CB70 / jtbl_801D8B74 + * ov_SC03_099 D_80185A50 / D_80185ABC / jtbl_801BD898 + * ov_SC06_008 D_80187E44 / D_80187EB0 / jtbl_801A8734 + * The pair is always +0x6C apart, and NO literal in this draft encodes that distance + * (both labels are referenced by name), so there is no §84 derived-offset hazard. + * D_8011F9C4 is fleet-constant (main-EXE data) and must NOT be remapped. + * + * match_one: MATCH (271 ins) against the CURRENT tree (§87 staleness re-checked, 2026-07-27). + * PIN-FREE, zero asm, offset-pure (s32 arg0 + raw offsets) — x138 template-safe. + * Provenance: this is the Phase-26 crack (.run/phase26-cracks/func_8015B950.c) re-gated verbatim, + * with ONE deliberate change: the definition's return type void -> s32. + * - `void func_8015B950(s32 arg0)` : MATCH (271 ins) [the Phase-26 form] + * - `s32 func_8015B950(s32 arg0)` : MATCH (271 ins) [shipped — §3a-1 void->s32 is byte-neutral] + * The fleet/engine_core.h canonical decl is `extern s32 func_8015B950(void);` (engine_core.h:1852), + * and the last bank attempt (.run/bank_func_8015B950.log) died on `conflicting types for + * func_8015B950`. Shipping the s32 return kills the §73 RETURN axis for free and leaves only the + * cheap T0 PARAMS axis for the ladder (fix_header_decl.py / --fix-def-sig / cast_call_sites). + * Both forms are byte-identical, so the orchestrator may swap the return type back at zero cost. + * + * SYMBOLS (§58 rules 1/2 — all splat spellings, all verified present): + * D_8018CB70 asm/ov_SC01_077/data/tail.data.s:4355 (the state-handler vtable) + * D_8018CB04 asm/ov_SC01_077/data/tail.data.s:4293 + * D_8011F9C4 main-EXE data; spelled `extern s32 D_8011F9C4;` in 5+ already-banked TUs + * jtbl_801D8B74 asm/ov_SC01_077/data/tail14.data.s:15 (compiler jump table — not named in C) + * + * JTBL VERIFIED (§8a gate): compiled .rodata = exactly 0x1C B / 7 words, 7x R_MIPS_32 .text with + * addends [0x58,0x58,0x58,0xE0,0xF0,0x100,0x58] -> +0x8015B950 = [B9A8,B9A8,B9A8,BA30,BA40,BA50, + * B9A8] == the original words at 0x801D8B74..0x801D8B8C. Bound `sltiu $v0,$v1,0x7` matches. + * The raw dlabel's 8th word 0x00000000 is NOT an entry — it is the intra-TU `.align 3` pad of the + * B34/B54/B74 jtbl chain; the object can never emit it (maspsx drops .align), so it must stay in + * the post-carve RAW data piece (the §53/§62/§81 carve chain applies at bank time). + * + * Same family as the TU's own already-matched func_8015AE2C: 7-case switch on ((s32 (*)(s32))func_801619A4)() + * (0/1/2/6 shared, 3/4/5 own, no default block — out-of-range and every `break` fall to the + * after-switch join), then a chain of "state handler" tests, each dispatching + * D_8018CB70[*(u16*)arg0](arg0) and returning. + * + * THREE LEVERS (draft -> MATCH in 3 compiles): + * + * 1. PROLOGUE CONSTANT = an INITIALIZED LOCAL, not a literal in the compare. + * Target opens with `lui $s2, 0xFFF5` in the *prologue*, used once ~200 ins later in + * `slt $v0,$s2,$s1`. No gcc-2.7.2 pass hoists a (set reg const_int) across basic blocks + * (loop.c needs a loop; cse/combine/sched never move insns between BBs) — so the insn must + * have been EMITTED in the first BB, i.e. the constant is a local initialized at the top of + * the function. cse then cannot fold it back into the compare: the `slt` operand predicate is + * `arith_operand`, which rejects a CONST_INT wider than 16 bits, so validate_change fails and + * the pseudo survives. Its live range spans every call -> global.c gives it a callee-saved reg. + * Writing `z > -0xB0000` inline instead emits the `lui` into the branch delay slot next to the + * compare (caller-saved $v0) and the function is 1 insn short. => `s32 lim = -0xB0000;` at top. + * + * 2. `lh` vs `lhu`: a short->short copy is a pure HImode move and gcc emits `lhu`. The target's + * `lh $v0,0x26($s0)` means the value passed through an SImode (int) temp: expand makes + * (set (reg:SI) (sign_extend (mem:HI))) + (set (mem:HI) (subreg:HI ...)), and combine cannot + * merge them (the merged form is mem<-mem, which no movhi accepts) so the sign-extending load + * survives. => route both halfword copies through the `s32 t` temp. + * + * 3. THE `goto` LAYOUT — dodging jump.c's store-flag conversion (jump.c:1005-1065). + * An if/else chain writing 0/1 into `doit` makes gcc collapse the last pair into + * `sltiu $v0,$v0,1`. jump.c fires that conversion when the insn immediately after a + * conditional jump is a lone `SET pseudo, CONST_INT` whose following simplejump targets the + * SAME label as the branch (jump.c:1038 `reallabelprev == temp || ... JUMP_LABEL(temp4) == + * JUMP_LABEL(insn)`) — exactly the shape of `if (c) x=0; else x=1;`. + * The target instead cross-jumps ALL the `doit=0` exits into ONE shared block placed after the + * `doit=1` fall-through; reorg's fill_slots_from_thread then COPIES that single set into all + * three branch delay slots and redirects each branch past it (which is why `addu $v0,$zero, + * $zero` appears 3x in delay slots and the shared block vanishes). A `goto zero;` / `goto one;` + * chain expresses that layout directly, and each conditional jump is then followed by a + * compare/call rather than a lone const set, so the store-flag conversion never triggers. + * GENERAL RULE: multiple predicates that all assign the SAME constant to one flag => write + * them as `goto` to a shared assignment, never as an if/else ladder. + */ +extern s32 D_8011F9C4; +extern s32 D_8018CB04; + +extern s32 func_80161B18(void); +extern s32 func_801619A4(s32*); +extern s32 func_80149AA8(s32*); +extern void func_80149AD4(s32*); +extern s32 func_80149B54(s32*); +extern void func_80149BAC(s32*); +extern s32 func_801498E0(s32*); +extern s32 func_80149954(s32); +extern s32 func_80149A64(s32*); +extern void func_800CCCC0(s32 a0); +extern s32 func_80149CD4(s32 a0); +extern void func_8015E880(s32*); +extern s32 func_80149744(struct S_80149744*); +extern void func_80149788(void); +extern s32 func_801496D4(void*); +extern void func_80149704(void); +extern int func_80148AFC(void*); +extern void func_80146D90(s32 a0); +extern void func_80154150(s32 a0, s32 a1); +extern void func_801541D8(u8*, s32, s32); +extern s32 func_801488A8(u8*); +extern void func_80147078(s32*, s16); +extern void func_8015A264(void*); +extern s32 func_80013294(void*, void*); +extern void func_80159B70(void*); +extern s32 func_8016F1AC(void); +extern s32 func_80029178(s32 a0); +extern void func_80146DB8(s32*, s32*); +extern s32 func_80161CD0(s32, s32); +extern s32 func_80161208(s32 a0); +extern s32 func_801725A4(u8*); + +s32 func_8015B950(s32 arg0) +{ + + extern void (*D_8018CB70[])(void *); + s16 sp10[4]; + s16 sp18[4]; + s32 t; + s32 z; + s32 doit; + s32 lim = -0xB0000; + + if (func_80161B18() != 0) { + return; + } + switch (((s32 (*)(s32))func_801619A4)(arg0)) { + case 0: + case 1: + case 2: + case 6: + if (((s32 (*)(s32))func_80149AA8)(arg0) != 0) { + D_8018CB70[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149AD4)(arg0); + return; + } + if (((s32 (*)(s32))func_80149B54)(arg0) != 0) { + D_8018CB70[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149BAC)(arg0); + return; + } + break; + case 3: + ((void (*)(s32))func_801498E0)(arg0); + break; + case 4: + ((void (*)(s32))func_80149954)(arg0); + break; + case 5: + if (((s32 (*)(s32))func_80149A64)(arg0) != 0) { + D_8018CB70[*(u16 *)arg0]((void *)arg0); + func_800CCCC0(arg0); + return; + } + break; + } + if (func_80149CD4(arg0) != 0) { + D_8018CB70[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_8015E880)(arg0); + return; + } + if (((s32 (*)(s32))func_80149744)(arg0) != 0) { + D_8018CB70[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149788)(arg0); + return; + } + if (((s32 (*)(s32))func_801496D4)(arg0) != 0) { + D_8018CB70[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149704)(arg0); + if (((u8)((s32 (*)(s32))func_80148AFC)(arg0)) == 0) { + func_80146D90(arg0); + } + if ((*(s32 *)(arg0 + 0x24) | *(s32 *)(arg0 + 0x2C)) != 0) { + func_80154150(arg0, 0xF); + } else { + ((void (*)(s32, s32, s32))func_801541D8)(arg0, 0xD, 6); + } + *(s32 *)(arg0 + 0x238) = 1; + return; + } + if (((s32 (*)(s32))func_801488A8)(arg0) != 0) { + sp10[0] = 0; + sp10[1] = 0; + sp10[2] = 0; + t = *(s16 *)(arg0 + 0x26); + sp18[0] = t; + sp18[1] = 0; + t = *(s16 *)(arg0 + 0x2E); + sp18[2] = t; + D_8018CB70[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 1); + ((void (*)(s32))func_8015A264)(arg0); + t = -(((s32 (*)(s16 *, s16 *))func_80013294)(sp10, sp18) << 0x10); + if (t < *(s32 *)(arg0 + 0x2C)) { + *(s32 *)(arg0 + 0x2C) = t; + } + return; + } + if (*(u16 *)(arg0 + 0xB8) == 0x8000) { + D_8018CB70[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 0); + ((void (*)(s32))func_80159B70)(arg0); + return; + } + z = *(s32 *)(arg0 + 0x2C); + if (func_8016F1AC() != 0) { + goto zero; + } + if (z <= lim) { + goto one; + } + if (D_8011F9C4 == 0) { + goto zero; + } + if (((u8)func_80029178(0x21)) != 0) { + goto zero; + } +one: + doit = 1; + goto join; +zero: + doit = 0; +join: + if (doit != 0) { + D_8018CB70[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 0); + ((void (*)(s32))func_80159B70)(arg0); + func_80154150(arg0, 9); + ((void (*)(s32, s32 *))func_80146DB8)(arg0, &D_8018CB04); + ((void (*)(s32, s32))func_80161CD0)(arg0, *(u16 *)(arg0 + 0x16E)); + return; + } + if (func_80161208(arg0) == 0) { + ((void (*)(s32))func_801725A4)(arg0); + } +} DEFINE_func_8015BD8C() /* dedup: shared engine-core @0x8015BD8C (src/shared) */ diff --git a/src/ov_SC02_021/ov_SC02_021_jr_8015AE2C.c b/src/ov_SC02_021/ov_SC02_021_jr_8015AE2C.c index cc4b3d494..6210d24d0 100644 --- a/src/ov_SC02_021/ov_SC02_021_jr_8015AE2C.c +++ b/src/ov_SC02_021/ov_SC02_021_jr_8015AE2C.c @@ -1513,7 +1513,259 @@ DEFINE_func_8015B858() /* dedup: shared engine-core @0x8015B858 (src/shared) */ DEFINE_func_8015B8F8() /* dedup: shared engine-core @0x8015B8F8 (src/shared) */ -INCLUDE_ASM("asm/ov_SC02_021/nonmatchings/ov_SC02_021_jr_8015AE2C", func_8015B950); +extern s32 func_8015AE2C(); + +// @class: plumbing +// @stuck: none — MATCH (271/271, pin-free, zero asm). The ONLY residual is DEF-SIDE plumbing, and it is now named exactly: the in-TU instantiation `DEFINE_func_8015BEE4()` (engine_core.h:1851-1855) expands to `extern s32 func_8015B950(void);` INSIDE ov_SC01_077_jr_8015AE2C.c, ~14 lines BELOW this definition, so the 1-param def collides with a `(void)` prototype -> `conflicting types for func_8015B950` (.run/bank_func_8015B950.log). §73 PARAMS axis / T0. Surgical fix = §65b de-macroize that ONE instantiation (blast radius: this TU); the fleet-wide `(void)`->`()` header edit is §63 and must be R22-validated. +/* func_8015B950 (ov_SC01_077_jr_8015AE2C, 271 ins, jtbl_801D8B74) — SESSION-21 re-verified + * + * ── ROUND-2 INDEPENDENT RE-VERIFICATION (2026-07-27, fresh agent, §88e discipline) ───────────── + * match_one : MATCH (271 ins) against the CURRENT tree — §87 staleness re-checked today. + * .text size: compiled .text = 0x43C = 1084 B = 271 ins, EXACTLY the target's declared 0x43C + * ("nonmatching func_8015B950, 0x43C"). So this is NOT a §83a length drift hiding + * behind a zero count — the count is over equal-length streams. + * jtbl : RE-DECODED MECHANICALLY, not inherited. Compiled .rodata = 0x1C = 28 B = 7 words, + * 7x R_MIPS_32 -> .text with implicit addends [58,58,58,E0,F0,100,58]; +0x8015B950 + * = [8015B9A8, 8015B9A8, 8015B9A8, 8015BA30, 8015BA40, 8015BA50, 8015B9A8]. + * Diffed word-for-word against asm/ov_SC01_077/data/tail14.data.s:15-23 — 7/7 identical. + * symcheck : SYMS-DIFF target=35 draft=34, sole MISSING = jtbl_801D8B74. This is the §81 jr + * FALSE POSITIVE, re-confirmed here by reading the relocs: gcc emits its OWN table and + * references it with R_MIPS_HI16/LO16 against the SECTION `.rodata` (t.o +0x40/+0x48), + * so the splat's dlabel NAME can never appear in the draft object's relocation set. + * Nothing is dropped and nothing is invented: the draft's other 34 symbols are exactly + * the target's other 34. + * FAMILY : the x138 remap is clean and §84-safe. Every sibling is 271 ins with an IDENTICAL + * callee set; only THREE names vary per overlay — the two data labels and the jtbl: + * ov_SC01_077 D_801820F8 / D_80182164 / jtbl_801D8B74 + * ov_SC03_099 D_80185A50 / D_80185ABC / jtbl_801BD898 + * ov_SC06_008 D_80187E44 / D_80187EB0 / jtbl_801A8734 + * The pair is always +0x6C apart, and NO literal in this draft encodes that distance + * (both labels are referenced by name), so there is no §84 derived-offset hazard. + * D_8011F9C4 is fleet-constant (main-EXE data) and must NOT be remapped. + * + * match_one: MATCH (271 ins) against the CURRENT tree (§87 staleness re-checked, 2026-07-27). + * PIN-FREE, zero asm, offset-pure (s32 arg0 + raw offsets) — x138 template-safe. + * Provenance: this is the Phase-26 crack (.run/phase26-cracks/func_8015B950.c) re-gated verbatim, + * with ONE deliberate change: the definition's return type void -> s32. + * - `void func_8015B950(s32 arg0)` : MATCH (271 ins) [the Phase-26 form] + * - `s32 func_8015B950(s32 arg0)` : MATCH (271 ins) [shipped — §3a-1 void->s32 is byte-neutral] + * The fleet/engine_core.h canonical decl is `extern s32 func_8015B950(void);` (engine_core.h:1852), + * and the last bank attempt (.run/bank_func_8015B950.log) died on `conflicting types for + * func_8015B950`. Shipping the s32 return kills the §73 RETURN axis for free and leaves only the + * cheap T0 PARAMS axis for the ladder (fix_header_decl.py / --fix-def-sig / cast_call_sites). + * Both forms are byte-identical, so the orchestrator may swap the return type back at zero cost. + * + * SYMBOLS (§58 rules 1/2 — all splat spellings, all verified present): + * D_80182164 asm/ov_SC01_077/data/tail.data.s:4355 (the state-handler vtable) + * D_801820F8 asm/ov_SC01_077/data/tail.data.s:4293 + * D_8011F9C4 main-EXE data; spelled `extern s32 D_8011F9C4;` in 5+ already-banked TUs + * jtbl_801D8B74 asm/ov_SC01_077/data/tail14.data.s:15 (compiler jump table — not named in C) + * + * JTBL VERIFIED (§8a gate): compiled .rodata = exactly 0x1C B / 7 words, 7x R_MIPS_32 .text with + * addends [0x58,0x58,0x58,0xE0,0xF0,0x100,0x58] -> +0x8015B950 = [B9A8,B9A8,B9A8,BA30,BA40,BA50, + * B9A8] == the original words at 0x801D8B74..0x801D8B8C. Bound `sltiu $v0,$v1,0x7` matches. + * The raw dlabel's 8th word 0x00000000 is NOT an entry — it is the intra-TU `.align 3` pad of the + * B34/B54/B74 jtbl chain; the object can never emit it (maspsx drops .align), so it must stay in + * the post-carve RAW data piece (the §53/§62/§81 carve chain applies at bank time). + * + * Same family as the TU's own already-matched func_8015AE2C: 7-case switch on ((s32 (*)(s32))func_801619A4)() + * (0/1/2/6 shared, 3/4/5 own, no default block — out-of-range and every `break` fall to the + * after-switch join), then a chain of "state handler" tests, each dispatching + * D_80182164[*(u16*)arg0](arg0) and returning. + * + * THREE LEVERS (draft -> MATCH in 3 compiles): + * + * 1. PROLOGUE CONSTANT = an INITIALIZED LOCAL, not a literal in the compare. + * Target opens with `lui $s2, 0xFFF5` in the *prologue*, used once ~200 ins later in + * `slt $v0,$s2,$s1`. No gcc-2.7.2 pass hoists a (set reg const_int) across basic blocks + * (loop.c needs a loop; cse/combine/sched never move insns between BBs) — so the insn must + * have been EMITTED in the first BB, i.e. the constant is a local initialized at the top of + * the function. cse then cannot fold it back into the compare: the `slt` operand predicate is + * `arith_operand`, which rejects a CONST_INT wider than 16 bits, so validate_change fails and + * the pseudo survives. Its live range spans every call -> global.c gives it a callee-saved reg. + * Writing `z > -0xB0000` inline instead emits the `lui` into the branch delay slot next to the + * compare (caller-saved $v0) and the function is 1 insn short. => `s32 lim = -0xB0000;` at top. + * + * 2. `lh` vs `lhu`: a short->short copy is a pure HImode move and gcc emits `lhu`. The target's + * `lh $v0,0x26($s0)` means the value passed through an SImode (int) temp: expand makes + * (set (reg:SI) (sign_extend (mem:HI))) + (set (mem:HI) (subreg:HI ...)), and combine cannot + * merge them (the merged form is mem<-mem, which no movhi accepts) so the sign-extending load + * survives. => route both halfword copies through the `s32 t` temp. + * + * 3. THE `goto` LAYOUT — dodging jump.c's store-flag conversion (jump.c:1005-1065). + * An if/else chain writing 0/1 into `doit` makes gcc collapse the last pair into + * `sltiu $v0,$v0,1`. jump.c fires that conversion when the insn immediately after a + * conditional jump is a lone `SET pseudo, CONST_INT` whose following simplejump targets the + * SAME label as the branch (jump.c:1038 `reallabelprev == temp || ... JUMP_LABEL(temp4) == + * JUMP_LABEL(insn)`) — exactly the shape of `if (c) x=0; else x=1;`. + * The target instead cross-jumps ALL the `doit=0` exits into ONE shared block placed after the + * `doit=1` fall-through; reorg's fill_slots_from_thread then COPIES that single set into all + * three branch delay slots and redirects each branch past it (which is why `addu $v0,$zero, + * $zero` appears 3x in delay slots and the shared block vanishes). A `goto zero;` / `goto one;` + * chain expresses that layout directly, and each conditional jump is then followed by a + * compare/call rather than a lone const set, so the store-flag conversion never triggers. + * GENERAL RULE: multiple predicates that all assign the SAME constant to one flag => write + * them as `goto` to a shared assignment, never as an if/else ladder. + */ +extern s32 D_8011F9C4; +extern s32 D_801820F8; + +extern s32 func_80161B18(void); +extern s32 func_801619A4(s32*); +extern s32 func_80149AA8(s32*); +extern void func_80149AD4(s32*); +extern s32 func_80149B54(s32*); +extern void func_80149BAC(s32*); +extern s32 func_801498E0(s32*); +extern s32 func_80149954(s32); +extern s32 func_80149A64(s32*); +extern void func_800CCCC0(s32 a0); +extern s32 func_80149CD4(s32 a0); +extern void func_8015E880(s32*); +extern s32 func_80149744(struct S_80149744*); +extern void func_80149788(void); +extern s32 func_801496D4(void*); +extern void func_80149704(void); +extern int func_80148AFC(void*); +extern void func_80146D90(s32 a0); +extern void func_80154150(s32 a0, s32 a1); +extern void func_801541D8(u8*, s32, s32); +extern s32 func_801488A8(u8*); +extern void func_80147078(s32*, s16); +extern void func_8015A264(void*); +extern s32 func_80013294(void*, void*); +extern void func_80159B70(void*); +extern s32 func_8016F1AC(void); +extern s32 func_80029178(s32 a0); +extern void func_80146DB8(s32*, s32*); +extern s32 func_80161CD0(s32, s32); +extern s32 func_80161208(s32 a0); +extern s32 func_801725A4(u8*); + +s32 func_8015B950(s32 arg0) +{ + + extern void (*D_80182164[])(void *); + s16 sp10[4]; + s16 sp18[4]; + s32 t; + s32 z; + s32 doit; + s32 lim = -0xB0000; + + if (func_80161B18() != 0) { + return; + } + switch (((s32 (*)(s32))func_801619A4)(arg0)) { + case 0: + case 1: + case 2: + case 6: + if (((s32 (*)(s32))func_80149AA8)(arg0) != 0) { + D_80182164[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149AD4)(arg0); + return; + } + if (((s32 (*)(s32))func_80149B54)(arg0) != 0) { + D_80182164[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149BAC)(arg0); + return; + } + break; + case 3: + ((void (*)(s32))func_801498E0)(arg0); + break; + case 4: + ((void (*)(s32))func_80149954)(arg0); + break; + case 5: + if (((s32 (*)(s32))func_80149A64)(arg0) != 0) { + D_80182164[*(u16 *)arg0]((void *)arg0); + func_800CCCC0(arg0); + return; + } + break; + } + if (func_80149CD4(arg0) != 0) { + D_80182164[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_8015E880)(arg0); + return; + } + if (((s32 (*)(s32))func_80149744)(arg0) != 0) { + D_80182164[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149788)(arg0); + return; + } + if (((s32 (*)(s32))func_801496D4)(arg0) != 0) { + D_80182164[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149704)(arg0); + if (((u8)((s32 (*)(s32))func_80148AFC)(arg0)) == 0) { + func_80146D90(arg0); + } + if ((*(s32 *)(arg0 + 0x24) | *(s32 *)(arg0 + 0x2C)) != 0) { + func_80154150(arg0, 0xF); + } else { + ((void (*)(s32, s32, s32))func_801541D8)(arg0, 0xD, 6); + } + *(s32 *)(arg0 + 0x238) = 1; + return; + } + if (((s32 (*)(s32))func_801488A8)(arg0) != 0) { + sp10[0] = 0; + sp10[1] = 0; + sp10[2] = 0; + t = *(s16 *)(arg0 + 0x26); + sp18[0] = t; + sp18[1] = 0; + t = *(s16 *)(arg0 + 0x2E); + sp18[2] = t; + D_80182164[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 1); + ((void (*)(s32))func_8015A264)(arg0); + t = -(((s32 (*)(s16 *, s16 *))func_80013294)(sp10, sp18) << 0x10); + if (t < *(s32 *)(arg0 + 0x2C)) { + *(s32 *)(arg0 + 0x2C) = t; + } + return; + } + if (*(u16 *)(arg0 + 0xB8) == 0x8000) { + D_80182164[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 0); + ((void (*)(s32))func_80159B70)(arg0); + return; + } + z = *(s32 *)(arg0 + 0x2C); + if (func_8016F1AC() != 0) { + goto zero; + } + if (z <= lim) { + goto one; + } + if (D_8011F9C4 == 0) { + goto zero; + } + if (((u8)func_80029178(0x21)) != 0) { + goto zero; + } +one: + doit = 1; + goto join; +zero: + doit = 0; +join: + if (doit != 0) { + D_80182164[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 0); + ((void (*)(s32))func_80159B70)(arg0); + func_80154150(arg0, 9); + ((void (*)(s32, s32 *))func_80146DB8)(arg0, &D_801820F8); + ((void (*)(s32, s32))func_80161CD0)(arg0, *(u16 *)(arg0 + 0x16E)); + return; + } + if (func_80161208(arg0) == 0) { + ((void (*)(s32))func_801725A4)(arg0); + } +} DEFINE_func_8015BD8C() /* dedup: shared engine-core @0x8015BD8C (src/shared) */ diff --git a/src/ov_SC02_026/ov_SC02_026_jr_8015AE2C.c b/src/ov_SC02_026/ov_SC02_026_jr_8015AE2C.c index 151c3fe95..8914291ad 100644 --- a/src/ov_SC02_026/ov_SC02_026_jr_8015AE2C.c +++ b/src/ov_SC02_026/ov_SC02_026_jr_8015AE2C.c @@ -1513,7 +1513,259 @@ DEFINE_func_8015B858() /* dedup: shared engine-core @0x8015B858 (src/shared) */ DEFINE_func_8015B8F8() /* dedup: shared engine-core @0x8015B8F8 (src/shared) */ -INCLUDE_ASM("asm/ov_SC02_026/nonmatchings/ov_SC02_026_jr_8015AE2C", func_8015B950); +extern s32 func_8015AE2C(); + +// @class: plumbing +// @stuck: none — MATCH (271/271, pin-free, zero asm). The ONLY residual is DEF-SIDE plumbing, and it is now named exactly: the in-TU instantiation `DEFINE_func_8015BEE4()` (engine_core.h:1851-1855) expands to `extern s32 func_8015B950(void);` INSIDE ov_SC01_077_jr_8015AE2C.c, ~14 lines BELOW this definition, so the 1-param def collides with a `(void)` prototype -> `conflicting types for func_8015B950` (.run/bank_func_8015B950.log). §73 PARAMS axis / T0. Surgical fix = §65b de-macroize that ONE instantiation (blast radius: this TU); the fleet-wide `(void)`->`()` header edit is §63 and must be R22-validated. +/* func_8015B950 (ov_SC01_077_jr_8015AE2C, 271 ins, jtbl_801D8B74) — SESSION-21 re-verified + * + * ── ROUND-2 INDEPENDENT RE-VERIFICATION (2026-07-27, fresh agent, §88e discipline) ───────────── + * match_one : MATCH (271 ins) against the CURRENT tree — §87 staleness re-checked today. + * .text size: compiled .text = 0x43C = 1084 B = 271 ins, EXACTLY the target's declared 0x43C + * ("nonmatching func_8015B950, 0x43C"). So this is NOT a §83a length drift hiding + * behind a zero count — the count is over equal-length streams. + * jtbl : RE-DECODED MECHANICALLY, not inherited. Compiled .rodata = 0x1C = 28 B = 7 words, + * 7x R_MIPS_32 -> .text with implicit addends [58,58,58,E0,F0,100,58]; +0x8015B950 + * = [8015B9A8, 8015B9A8, 8015B9A8, 8015BA30, 8015BA40, 8015BA50, 8015B9A8]. + * Diffed word-for-word against asm/ov_SC01_077/data/tail14.data.s:15-23 — 7/7 identical. + * symcheck : SYMS-DIFF target=35 draft=34, sole MISSING = jtbl_801D8B74. This is the §81 jr + * FALSE POSITIVE, re-confirmed here by reading the relocs: gcc emits its OWN table and + * references it with R_MIPS_HI16/LO16 against the SECTION `.rodata` (t.o +0x40/+0x48), + * so the splat's dlabel NAME can never appear in the draft object's relocation set. + * Nothing is dropped and nothing is invented: the draft's other 34 symbols are exactly + * the target's other 34. + * FAMILY : the x138 remap is clean and §84-safe. Every sibling is 271 ins with an IDENTICAL + * callee set; only THREE names vary per overlay — the two data labels and the jtbl: + * ov_SC01_077 D_8018874C / D_801887B8 / jtbl_801D8B74 + * ov_SC03_099 D_80185A50 / D_80185ABC / jtbl_801BD898 + * ov_SC06_008 D_80187E44 / D_80187EB0 / jtbl_801A8734 + * The pair is always +0x6C apart, and NO literal in this draft encodes that distance + * (both labels are referenced by name), so there is no §84 derived-offset hazard. + * D_8011F9C4 is fleet-constant (main-EXE data) and must NOT be remapped. + * + * match_one: MATCH (271 ins) against the CURRENT tree (§87 staleness re-checked, 2026-07-27). + * PIN-FREE, zero asm, offset-pure (s32 arg0 + raw offsets) — x138 template-safe. + * Provenance: this is the Phase-26 crack (.run/phase26-cracks/func_8015B950.c) re-gated verbatim, + * with ONE deliberate change: the definition's return type void -> s32. + * - `void func_8015B950(s32 arg0)` : MATCH (271 ins) [the Phase-26 form] + * - `s32 func_8015B950(s32 arg0)` : MATCH (271 ins) [shipped — §3a-1 void->s32 is byte-neutral] + * The fleet/engine_core.h canonical decl is `extern s32 func_8015B950(void);` (engine_core.h:1852), + * and the last bank attempt (.run/bank_func_8015B950.log) died on `conflicting types for + * func_8015B950`. Shipping the s32 return kills the §73 RETURN axis for free and leaves only the + * cheap T0 PARAMS axis for the ladder (fix_header_decl.py / --fix-def-sig / cast_call_sites). + * Both forms are byte-identical, so the orchestrator may swap the return type back at zero cost. + * + * SYMBOLS (§58 rules 1/2 — all splat spellings, all verified present): + * D_801887B8 asm/ov_SC01_077/data/tail.data.s:4355 (the state-handler vtable) + * D_8018874C asm/ov_SC01_077/data/tail.data.s:4293 + * D_8011F9C4 main-EXE data; spelled `extern s32 D_8011F9C4;` in 5+ already-banked TUs + * jtbl_801D8B74 asm/ov_SC01_077/data/tail14.data.s:15 (compiler jump table — not named in C) + * + * JTBL VERIFIED (§8a gate): compiled .rodata = exactly 0x1C B / 7 words, 7x R_MIPS_32 .text with + * addends [0x58,0x58,0x58,0xE0,0xF0,0x100,0x58] -> +0x8015B950 = [B9A8,B9A8,B9A8,BA30,BA40,BA50, + * B9A8] == the original words at 0x801D8B74..0x801D8B8C. Bound `sltiu $v0,$v1,0x7` matches. + * The raw dlabel's 8th word 0x00000000 is NOT an entry — it is the intra-TU `.align 3` pad of the + * B34/B54/B74 jtbl chain; the object can never emit it (maspsx drops .align), so it must stay in + * the post-carve RAW data piece (the §53/§62/§81 carve chain applies at bank time). + * + * Same family as the TU's own already-matched func_8015AE2C: 7-case switch on ((s32 (*)(s32))func_801619A4)() + * (0/1/2/6 shared, 3/4/5 own, no default block — out-of-range and every `break` fall to the + * after-switch join), then a chain of "state handler" tests, each dispatching + * D_801887B8[*(u16*)arg0](arg0) and returning. + * + * THREE LEVERS (draft -> MATCH in 3 compiles): + * + * 1. PROLOGUE CONSTANT = an INITIALIZED LOCAL, not a literal in the compare. + * Target opens with `lui $s2, 0xFFF5` in the *prologue*, used once ~200 ins later in + * `slt $v0,$s2,$s1`. No gcc-2.7.2 pass hoists a (set reg const_int) across basic blocks + * (loop.c needs a loop; cse/combine/sched never move insns between BBs) — so the insn must + * have been EMITTED in the first BB, i.e. the constant is a local initialized at the top of + * the function. cse then cannot fold it back into the compare: the `slt` operand predicate is + * `arith_operand`, which rejects a CONST_INT wider than 16 bits, so validate_change fails and + * the pseudo survives. Its live range spans every call -> global.c gives it a callee-saved reg. + * Writing `z > -0xB0000` inline instead emits the `lui` into the branch delay slot next to the + * compare (caller-saved $v0) and the function is 1 insn short. => `s32 lim = -0xB0000;` at top. + * + * 2. `lh` vs `lhu`: a short->short copy is a pure HImode move and gcc emits `lhu`. The target's + * `lh $v0,0x26($s0)` means the value passed through an SImode (int) temp: expand makes + * (set (reg:SI) (sign_extend (mem:HI))) + (set (mem:HI) (subreg:HI ...)), and combine cannot + * merge them (the merged form is mem<-mem, which no movhi accepts) so the sign-extending load + * survives. => route both halfword copies through the `s32 t` temp. + * + * 3. THE `goto` LAYOUT — dodging jump.c's store-flag conversion (jump.c:1005-1065). + * An if/else chain writing 0/1 into `doit` makes gcc collapse the last pair into + * `sltiu $v0,$v0,1`. jump.c fires that conversion when the insn immediately after a + * conditional jump is a lone `SET pseudo, CONST_INT` whose following simplejump targets the + * SAME label as the branch (jump.c:1038 `reallabelprev == temp || ... JUMP_LABEL(temp4) == + * JUMP_LABEL(insn)`) — exactly the shape of `if (c) x=0; else x=1;`. + * The target instead cross-jumps ALL the `doit=0` exits into ONE shared block placed after the + * `doit=1` fall-through; reorg's fill_slots_from_thread then COPIES that single set into all + * three branch delay slots and redirects each branch past it (which is why `addu $v0,$zero, + * $zero` appears 3x in delay slots and the shared block vanishes). A `goto zero;` / `goto one;` + * chain expresses that layout directly, and each conditional jump is then followed by a + * compare/call rather than a lone const set, so the store-flag conversion never triggers. + * GENERAL RULE: multiple predicates that all assign the SAME constant to one flag => write + * them as `goto` to a shared assignment, never as an if/else ladder. + */ +extern s32 D_8011F9C4; +extern s32 D_8018874C; + +extern s32 func_80161B18(void); +extern s32 func_801619A4(s32*); +extern s32 func_80149AA8(s32*); +extern void func_80149AD4(s32*); +extern s32 func_80149B54(s32*); +extern void func_80149BAC(s32*); +extern s32 func_801498E0(s32*); +extern s32 func_80149954(s32); +extern s32 func_80149A64(s32*); +extern void func_800CCCC0(s32 a0); +extern s32 func_80149CD4(s32 a0); +extern void func_8015E880(s32*); +extern s32 func_80149744(struct S_80149744*); +extern void func_80149788(void); +extern s32 func_801496D4(void*); +extern void func_80149704(void); +extern int func_80148AFC(void*); +extern void func_80146D90(s32 a0); +extern void func_80154150(s32 a0, s32 a1); +extern void func_801541D8(u8*, s32, s32); +extern s32 func_801488A8(u8*); +extern void func_80147078(s32*, s16); +extern void func_8015A264(void*); +extern s32 func_80013294(void*, void*); +extern void func_80159B70(void*); +extern s32 func_8016F1AC(void); +extern s32 func_80029178(s32 a0); +extern void func_80146DB8(s32*, s32*); +extern s32 func_80161CD0(s32, s32); +extern s32 func_80161208(s32 a0); +extern s32 func_801725A4(u8*); + +s32 func_8015B950(s32 arg0) +{ + + extern void (*D_801887B8[])(void *); + s16 sp10[4]; + s16 sp18[4]; + s32 t; + s32 z; + s32 doit; + s32 lim = -0xB0000; + + if (func_80161B18() != 0) { + return; + } + switch (((s32 (*)(s32))func_801619A4)(arg0)) { + case 0: + case 1: + case 2: + case 6: + if (((s32 (*)(s32))func_80149AA8)(arg0) != 0) { + D_801887B8[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149AD4)(arg0); + return; + } + if (((s32 (*)(s32))func_80149B54)(arg0) != 0) { + D_801887B8[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149BAC)(arg0); + return; + } + break; + case 3: + ((void (*)(s32))func_801498E0)(arg0); + break; + case 4: + ((void (*)(s32))func_80149954)(arg0); + break; + case 5: + if (((s32 (*)(s32))func_80149A64)(arg0) != 0) { + D_801887B8[*(u16 *)arg0]((void *)arg0); + func_800CCCC0(arg0); + return; + } + break; + } + if (func_80149CD4(arg0) != 0) { + D_801887B8[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_8015E880)(arg0); + return; + } + if (((s32 (*)(s32))func_80149744)(arg0) != 0) { + D_801887B8[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149788)(arg0); + return; + } + if (((s32 (*)(s32))func_801496D4)(arg0) != 0) { + D_801887B8[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149704)(arg0); + if (((u8)((s32 (*)(s32))func_80148AFC)(arg0)) == 0) { + func_80146D90(arg0); + } + if ((*(s32 *)(arg0 + 0x24) | *(s32 *)(arg0 + 0x2C)) != 0) { + func_80154150(arg0, 0xF); + } else { + ((void (*)(s32, s32, s32))func_801541D8)(arg0, 0xD, 6); + } + *(s32 *)(arg0 + 0x238) = 1; + return; + } + if (((s32 (*)(s32))func_801488A8)(arg0) != 0) { + sp10[0] = 0; + sp10[1] = 0; + sp10[2] = 0; + t = *(s16 *)(arg0 + 0x26); + sp18[0] = t; + sp18[1] = 0; + t = *(s16 *)(arg0 + 0x2E); + sp18[2] = t; + D_801887B8[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 1); + ((void (*)(s32))func_8015A264)(arg0); + t = -(((s32 (*)(s16 *, s16 *))func_80013294)(sp10, sp18) << 0x10); + if (t < *(s32 *)(arg0 + 0x2C)) { + *(s32 *)(arg0 + 0x2C) = t; + } + return; + } + if (*(u16 *)(arg0 + 0xB8) == 0x8000) { + D_801887B8[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 0); + ((void (*)(s32))func_80159B70)(arg0); + return; + } + z = *(s32 *)(arg0 + 0x2C); + if (func_8016F1AC() != 0) { + goto zero; + } + if (z <= lim) { + goto one; + } + if (D_8011F9C4 == 0) { + goto zero; + } + if (((u8)func_80029178(0x21)) != 0) { + goto zero; + } +one: + doit = 1; + goto join; +zero: + doit = 0; +join: + if (doit != 0) { + D_801887B8[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 0); + ((void (*)(s32))func_80159B70)(arg0); + func_80154150(arg0, 9); + ((void (*)(s32, s32 *))func_80146DB8)(arg0, &D_8018874C); + ((void (*)(s32, s32))func_80161CD0)(arg0, *(u16 *)(arg0 + 0x16E)); + return; + } + if (func_80161208(arg0) == 0) { + ((void (*)(s32))func_801725A4)(arg0); + } +} DEFINE_func_8015BD8C() /* dedup: shared engine-core @0x8015BD8C (src/shared) */ diff --git a/src/ov_SC02_027/ov_SC02_027_jr_8015AE2C.c b/src/ov_SC02_027/ov_SC02_027_jr_8015AE2C.c index 55d7e8ed1..2a5dcc45b 100644 --- a/src/ov_SC02_027/ov_SC02_027_jr_8015AE2C.c +++ b/src/ov_SC02_027/ov_SC02_027_jr_8015AE2C.c @@ -1513,7 +1513,259 @@ DEFINE_func_8015B858() /* dedup: shared engine-core @0x8015B858 (src/shared) */ DEFINE_func_8015B8F8() /* dedup: shared engine-core @0x8015B8F8 (src/shared) */ -INCLUDE_ASM("asm/ov_SC02_027/nonmatchings/ov_SC02_027_jr_8015AE2C", func_8015B950); +extern s32 func_8015AE2C(); + +// @class: plumbing +// @stuck: none — MATCH (271/271, pin-free, zero asm). The ONLY residual is DEF-SIDE plumbing, and it is now named exactly: the in-TU instantiation `DEFINE_func_8015BEE4()` (engine_core.h:1851-1855) expands to `extern s32 func_8015B950(void);` INSIDE ov_SC01_077_jr_8015AE2C.c, ~14 lines BELOW this definition, so the 1-param def collides with a `(void)` prototype -> `conflicting types for func_8015B950` (.run/bank_func_8015B950.log). §73 PARAMS axis / T0. Surgical fix = §65b de-macroize that ONE instantiation (blast radius: this TU); the fleet-wide `(void)`->`()` header edit is §63 and must be R22-validated. +/* func_8015B950 (ov_SC01_077_jr_8015AE2C, 271 ins, jtbl_801D8B74) — SESSION-21 re-verified + * + * ── ROUND-2 INDEPENDENT RE-VERIFICATION (2026-07-27, fresh agent, §88e discipline) ───────────── + * match_one : MATCH (271 ins) against the CURRENT tree — §87 staleness re-checked today. + * .text size: compiled .text = 0x43C = 1084 B = 271 ins, EXACTLY the target's declared 0x43C + * ("nonmatching func_8015B950, 0x43C"). So this is NOT a §83a length drift hiding + * behind a zero count — the count is over equal-length streams. + * jtbl : RE-DECODED MECHANICALLY, not inherited. Compiled .rodata = 0x1C = 28 B = 7 words, + * 7x R_MIPS_32 -> .text with implicit addends [58,58,58,E0,F0,100,58]; +0x8015B950 + * = [8015B9A8, 8015B9A8, 8015B9A8, 8015BA30, 8015BA40, 8015BA50, 8015B9A8]. + * Diffed word-for-word against asm/ov_SC01_077/data/tail14.data.s:15-23 — 7/7 identical. + * symcheck : SYMS-DIFF target=35 draft=34, sole MISSING = jtbl_801D8B74. This is the §81 jr + * FALSE POSITIVE, re-confirmed here by reading the relocs: gcc emits its OWN table and + * references it with R_MIPS_HI16/LO16 against the SECTION `.rodata` (t.o +0x40/+0x48), + * so the splat's dlabel NAME can never appear in the draft object's relocation set. + * Nothing is dropped and nothing is invented: the draft's other 34 symbols are exactly + * the target's other 34. + * FAMILY : the x138 remap is clean and §84-safe. Every sibling is 271 ins with an IDENTICAL + * callee set; only THREE names vary per overlay — the two data labels and the jtbl: + * ov_SC01_077 D_8018D870 / D_8018D8DC / jtbl_801D8B74 + * ov_SC03_099 D_80185A50 / D_80185ABC / jtbl_801BD898 + * ov_SC06_008 D_80187E44 / D_80187EB0 / jtbl_801A8734 + * The pair is always +0x6C apart, and NO literal in this draft encodes that distance + * (both labels are referenced by name), so there is no §84 derived-offset hazard. + * D_8011F9C4 is fleet-constant (main-EXE data) and must NOT be remapped. + * + * match_one: MATCH (271 ins) against the CURRENT tree (§87 staleness re-checked, 2026-07-27). + * PIN-FREE, zero asm, offset-pure (s32 arg0 + raw offsets) — x138 template-safe. + * Provenance: this is the Phase-26 crack (.run/phase26-cracks/func_8015B950.c) re-gated verbatim, + * with ONE deliberate change: the definition's return type void -> s32. + * - `void func_8015B950(s32 arg0)` : MATCH (271 ins) [the Phase-26 form] + * - `s32 func_8015B950(s32 arg0)` : MATCH (271 ins) [shipped — §3a-1 void->s32 is byte-neutral] + * The fleet/engine_core.h canonical decl is `extern s32 func_8015B950(void);` (engine_core.h:1852), + * and the last bank attempt (.run/bank_func_8015B950.log) died on `conflicting types for + * func_8015B950`. Shipping the s32 return kills the §73 RETURN axis for free and leaves only the + * cheap T0 PARAMS axis for the ladder (fix_header_decl.py / --fix-def-sig / cast_call_sites). + * Both forms are byte-identical, so the orchestrator may swap the return type back at zero cost. + * + * SYMBOLS (§58 rules 1/2 — all splat spellings, all verified present): + * D_8018D8DC asm/ov_SC01_077/data/tail.data.s:4355 (the state-handler vtable) + * D_8018D870 asm/ov_SC01_077/data/tail.data.s:4293 + * D_8011F9C4 main-EXE data; spelled `extern s32 D_8011F9C4;` in 5+ already-banked TUs + * jtbl_801D8B74 asm/ov_SC01_077/data/tail14.data.s:15 (compiler jump table — not named in C) + * + * JTBL VERIFIED (§8a gate): compiled .rodata = exactly 0x1C B / 7 words, 7x R_MIPS_32 .text with + * addends [0x58,0x58,0x58,0xE0,0xF0,0x100,0x58] -> +0x8015B950 = [B9A8,B9A8,B9A8,BA30,BA40,BA50, + * B9A8] == the original words at 0x801D8B74..0x801D8B8C. Bound `sltiu $v0,$v1,0x7` matches. + * The raw dlabel's 8th word 0x00000000 is NOT an entry — it is the intra-TU `.align 3` pad of the + * B34/B54/B74 jtbl chain; the object can never emit it (maspsx drops .align), so it must stay in + * the post-carve RAW data piece (the §53/§62/§81 carve chain applies at bank time). + * + * Same family as the TU's own already-matched func_8015AE2C: 7-case switch on ((s32 (*)(s32))func_801619A4)() + * (0/1/2/6 shared, 3/4/5 own, no default block — out-of-range and every `break` fall to the + * after-switch join), then a chain of "state handler" tests, each dispatching + * D_8018D8DC[*(u16*)arg0](arg0) and returning. + * + * THREE LEVERS (draft -> MATCH in 3 compiles): + * + * 1. PROLOGUE CONSTANT = an INITIALIZED LOCAL, not a literal in the compare. + * Target opens with `lui $s2, 0xFFF5` in the *prologue*, used once ~200 ins later in + * `slt $v0,$s2,$s1`. No gcc-2.7.2 pass hoists a (set reg const_int) across basic blocks + * (loop.c needs a loop; cse/combine/sched never move insns between BBs) — so the insn must + * have been EMITTED in the first BB, i.e. the constant is a local initialized at the top of + * the function. cse then cannot fold it back into the compare: the `slt` operand predicate is + * `arith_operand`, which rejects a CONST_INT wider than 16 bits, so validate_change fails and + * the pseudo survives. Its live range spans every call -> global.c gives it a callee-saved reg. + * Writing `z > -0xB0000` inline instead emits the `lui` into the branch delay slot next to the + * compare (caller-saved $v0) and the function is 1 insn short. => `s32 lim = -0xB0000;` at top. + * + * 2. `lh` vs `lhu`: a short->short copy is a pure HImode move and gcc emits `lhu`. The target's + * `lh $v0,0x26($s0)` means the value passed through an SImode (int) temp: expand makes + * (set (reg:SI) (sign_extend (mem:HI))) + (set (mem:HI) (subreg:HI ...)), and combine cannot + * merge them (the merged form is mem<-mem, which no movhi accepts) so the sign-extending load + * survives. => route both halfword copies through the `s32 t` temp. + * + * 3. THE `goto` LAYOUT — dodging jump.c's store-flag conversion (jump.c:1005-1065). + * An if/else chain writing 0/1 into `doit` makes gcc collapse the last pair into + * `sltiu $v0,$v0,1`. jump.c fires that conversion when the insn immediately after a + * conditional jump is a lone `SET pseudo, CONST_INT` whose following simplejump targets the + * SAME label as the branch (jump.c:1038 `reallabelprev == temp || ... JUMP_LABEL(temp4) == + * JUMP_LABEL(insn)`) — exactly the shape of `if (c) x=0; else x=1;`. + * The target instead cross-jumps ALL the `doit=0` exits into ONE shared block placed after the + * `doit=1` fall-through; reorg's fill_slots_from_thread then COPIES that single set into all + * three branch delay slots and redirects each branch past it (which is why `addu $v0,$zero, + * $zero` appears 3x in delay slots and the shared block vanishes). A `goto zero;` / `goto one;` + * chain expresses that layout directly, and each conditional jump is then followed by a + * compare/call rather than a lone const set, so the store-flag conversion never triggers. + * GENERAL RULE: multiple predicates that all assign the SAME constant to one flag => write + * them as `goto` to a shared assignment, never as an if/else ladder. + */ +extern s32 D_8011F9C4; +extern s32 D_8018D870; + +extern s32 func_80161B18(void); +extern s32 func_801619A4(s32*); +extern s32 func_80149AA8(s32*); +extern void func_80149AD4(s32*); +extern s32 func_80149B54(s32*); +extern void func_80149BAC(s32*); +extern s32 func_801498E0(s32*); +extern s32 func_80149954(s32); +extern s32 func_80149A64(s32*); +extern void func_800CCCC0(s32 a0); +extern s32 func_80149CD4(s32 a0); +extern void func_8015E880(s32*); +extern s32 func_80149744(struct S_80149744*); +extern void func_80149788(void); +extern s32 func_801496D4(void*); +extern void func_80149704(void); +extern int func_80148AFC(void*); +extern void func_80146D90(s32 a0); +extern void func_80154150(s32 a0, s32 a1); +extern void func_801541D8(u8*, s32, s32); +extern s32 func_801488A8(u8*); +extern void func_80147078(s32*, s16); +extern void func_8015A264(void*); +extern s32 func_80013294(void*, void*); +extern void func_80159B70(void*); +extern s32 func_8016F1AC(void); +extern s32 func_80029178(s32 a0); +extern void func_80146DB8(s32*, s32*); +extern s32 func_80161CD0(s32, s32); +extern s32 func_80161208(s32 a0); +extern s32 func_801725A4(u8*); + +s32 func_8015B950(s32 arg0) +{ + + extern void (*D_8018D8DC[])(void *); + s16 sp10[4]; + s16 sp18[4]; + s32 t; + s32 z; + s32 doit; + s32 lim = -0xB0000; + + if (func_80161B18() != 0) { + return; + } + switch (((s32 (*)(s32))func_801619A4)(arg0)) { + case 0: + case 1: + case 2: + case 6: + if (((s32 (*)(s32))func_80149AA8)(arg0) != 0) { + D_8018D8DC[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149AD4)(arg0); + return; + } + if (((s32 (*)(s32))func_80149B54)(arg0) != 0) { + D_8018D8DC[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149BAC)(arg0); + return; + } + break; + case 3: + ((void (*)(s32))func_801498E0)(arg0); + break; + case 4: + ((void (*)(s32))func_80149954)(arg0); + break; + case 5: + if (((s32 (*)(s32))func_80149A64)(arg0) != 0) { + D_8018D8DC[*(u16 *)arg0]((void *)arg0); + func_800CCCC0(arg0); + return; + } + break; + } + if (func_80149CD4(arg0) != 0) { + D_8018D8DC[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_8015E880)(arg0); + return; + } + if (((s32 (*)(s32))func_80149744)(arg0) != 0) { + D_8018D8DC[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149788)(arg0); + return; + } + if (((s32 (*)(s32))func_801496D4)(arg0) != 0) { + D_8018D8DC[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149704)(arg0); + if (((u8)((s32 (*)(s32))func_80148AFC)(arg0)) == 0) { + func_80146D90(arg0); + } + if ((*(s32 *)(arg0 + 0x24) | *(s32 *)(arg0 + 0x2C)) != 0) { + func_80154150(arg0, 0xF); + } else { + ((void (*)(s32, s32, s32))func_801541D8)(arg0, 0xD, 6); + } + *(s32 *)(arg0 + 0x238) = 1; + return; + } + if (((s32 (*)(s32))func_801488A8)(arg0) != 0) { + sp10[0] = 0; + sp10[1] = 0; + sp10[2] = 0; + t = *(s16 *)(arg0 + 0x26); + sp18[0] = t; + sp18[1] = 0; + t = *(s16 *)(arg0 + 0x2E); + sp18[2] = t; + D_8018D8DC[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 1); + ((void (*)(s32))func_8015A264)(arg0); + t = -(((s32 (*)(s16 *, s16 *))func_80013294)(sp10, sp18) << 0x10); + if (t < *(s32 *)(arg0 + 0x2C)) { + *(s32 *)(arg0 + 0x2C) = t; + } + return; + } + if (*(u16 *)(arg0 + 0xB8) == 0x8000) { + D_8018D8DC[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 0); + ((void (*)(s32))func_80159B70)(arg0); + return; + } + z = *(s32 *)(arg0 + 0x2C); + if (func_8016F1AC() != 0) { + goto zero; + } + if (z <= lim) { + goto one; + } + if (D_8011F9C4 == 0) { + goto zero; + } + if (((u8)func_80029178(0x21)) != 0) { + goto zero; + } +one: + doit = 1; + goto join; +zero: + doit = 0; +join: + if (doit != 0) { + D_8018D8DC[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 0); + ((void (*)(s32))func_80159B70)(arg0); + func_80154150(arg0, 9); + ((void (*)(s32, s32 *))func_80146DB8)(arg0, &D_8018D870); + ((void (*)(s32, s32))func_80161CD0)(arg0, *(u16 *)(arg0 + 0x16E)); + return; + } + if (func_80161208(arg0) == 0) { + ((void (*)(s32))func_801725A4)(arg0); + } +} DEFINE_func_8015BD8C() /* dedup: shared engine-core @0x8015BD8C (src/shared) */ diff --git a/src/ov_SC02_028/ov_SC02_028_jr_8015AE2C.c b/src/ov_SC02_028/ov_SC02_028_jr_8015AE2C.c index 35036af77..b81f5c0aa 100644 --- a/src/ov_SC02_028/ov_SC02_028_jr_8015AE2C.c +++ b/src/ov_SC02_028/ov_SC02_028_jr_8015AE2C.c @@ -1513,7 +1513,259 @@ DEFINE_func_8015B858() /* dedup: shared engine-core @0x8015B858 (src/shared) */ DEFINE_func_8015B8F8() /* dedup: shared engine-core @0x8015B8F8 (src/shared) */ -INCLUDE_ASM("asm/ov_SC02_028/nonmatchings/ov_SC02_028_jr_8015AE2C", func_8015B950); +extern s32 func_8015AE2C(); + +// @class: plumbing +// @stuck: none — MATCH (271/271, pin-free, zero asm). The ONLY residual is DEF-SIDE plumbing, and it is now named exactly: the in-TU instantiation `DEFINE_func_8015BEE4()` (engine_core.h:1851-1855) expands to `extern s32 func_8015B950(void);` INSIDE ov_SC01_077_jr_8015AE2C.c, ~14 lines BELOW this definition, so the 1-param def collides with a `(void)` prototype -> `conflicting types for func_8015B950` (.run/bank_func_8015B950.log). §73 PARAMS axis / T0. Surgical fix = §65b de-macroize that ONE instantiation (blast radius: this TU); the fleet-wide `(void)`->`()` header edit is §63 and must be R22-validated. +/* func_8015B950 (ov_SC01_077_jr_8015AE2C, 271 ins, jtbl_801D8B74) — SESSION-21 re-verified + * + * ── ROUND-2 INDEPENDENT RE-VERIFICATION (2026-07-27, fresh agent, §88e discipline) ───────────── + * match_one : MATCH (271 ins) against the CURRENT tree — §87 staleness re-checked today. + * .text size: compiled .text = 0x43C = 1084 B = 271 ins, EXACTLY the target's declared 0x43C + * ("nonmatching func_8015B950, 0x43C"). So this is NOT a §83a length drift hiding + * behind a zero count — the count is over equal-length streams. + * jtbl : RE-DECODED MECHANICALLY, not inherited. Compiled .rodata = 0x1C = 28 B = 7 words, + * 7x R_MIPS_32 -> .text with implicit addends [58,58,58,E0,F0,100,58]; +0x8015B950 + * = [8015B9A8, 8015B9A8, 8015B9A8, 8015BA30, 8015BA40, 8015BA50, 8015B9A8]. + * Diffed word-for-word against asm/ov_SC01_077/data/tail14.data.s:15-23 — 7/7 identical. + * symcheck : SYMS-DIFF target=35 draft=34, sole MISSING = jtbl_801D8B74. This is the §81 jr + * FALSE POSITIVE, re-confirmed here by reading the relocs: gcc emits its OWN table and + * references it with R_MIPS_HI16/LO16 against the SECTION `.rodata` (t.o +0x40/+0x48), + * so the splat's dlabel NAME can never appear in the draft object's relocation set. + * Nothing is dropped and nothing is invented: the draft's other 34 symbols are exactly + * the target's other 34. + * FAMILY : the x138 remap is clean and §84-safe. Every sibling is 271 ins with an IDENTICAL + * callee set; only THREE names vary per overlay — the two data labels and the jtbl: + * ov_SC01_077 D_8018DA74 / D_8018DAE0 / jtbl_801D8B74 + * ov_SC03_099 D_80185A50 / D_80185ABC / jtbl_801BD898 + * ov_SC06_008 D_80187E44 / D_80187EB0 / jtbl_801A8734 + * The pair is always +0x6C apart, and NO literal in this draft encodes that distance + * (both labels are referenced by name), so there is no §84 derived-offset hazard. + * D_8011F9C4 is fleet-constant (main-EXE data) and must NOT be remapped. + * + * match_one: MATCH (271 ins) against the CURRENT tree (§87 staleness re-checked, 2026-07-27). + * PIN-FREE, zero asm, offset-pure (s32 arg0 + raw offsets) — x138 template-safe. + * Provenance: this is the Phase-26 crack (.run/phase26-cracks/func_8015B950.c) re-gated verbatim, + * with ONE deliberate change: the definition's return type void -> s32. + * - `void func_8015B950(s32 arg0)` : MATCH (271 ins) [the Phase-26 form] + * - `s32 func_8015B950(s32 arg0)` : MATCH (271 ins) [shipped — §3a-1 void->s32 is byte-neutral] + * The fleet/engine_core.h canonical decl is `extern s32 func_8015B950(void);` (engine_core.h:1852), + * and the last bank attempt (.run/bank_func_8015B950.log) died on `conflicting types for + * func_8015B950`. Shipping the s32 return kills the §73 RETURN axis for free and leaves only the + * cheap T0 PARAMS axis for the ladder (fix_header_decl.py / --fix-def-sig / cast_call_sites). + * Both forms are byte-identical, so the orchestrator may swap the return type back at zero cost. + * + * SYMBOLS (§58 rules 1/2 — all splat spellings, all verified present): + * D_8018DAE0 asm/ov_SC01_077/data/tail.data.s:4355 (the state-handler vtable) + * D_8018DA74 asm/ov_SC01_077/data/tail.data.s:4293 + * D_8011F9C4 main-EXE data; spelled `extern s32 D_8011F9C4;` in 5+ already-banked TUs + * jtbl_801D8B74 asm/ov_SC01_077/data/tail14.data.s:15 (compiler jump table — not named in C) + * + * JTBL VERIFIED (§8a gate): compiled .rodata = exactly 0x1C B / 7 words, 7x R_MIPS_32 .text with + * addends [0x58,0x58,0x58,0xE0,0xF0,0x100,0x58] -> +0x8015B950 = [B9A8,B9A8,B9A8,BA30,BA40,BA50, + * B9A8] == the original words at 0x801D8B74..0x801D8B8C. Bound `sltiu $v0,$v1,0x7` matches. + * The raw dlabel's 8th word 0x00000000 is NOT an entry — it is the intra-TU `.align 3` pad of the + * B34/B54/B74 jtbl chain; the object can never emit it (maspsx drops .align), so it must stay in + * the post-carve RAW data piece (the §53/§62/§81 carve chain applies at bank time). + * + * Same family as the TU's own already-matched func_8015AE2C: 7-case switch on ((s32 (*)(s32))func_801619A4)() + * (0/1/2/6 shared, 3/4/5 own, no default block — out-of-range and every `break` fall to the + * after-switch join), then a chain of "state handler" tests, each dispatching + * D_8018DAE0[*(u16*)arg0](arg0) and returning. + * + * THREE LEVERS (draft -> MATCH in 3 compiles): + * + * 1. PROLOGUE CONSTANT = an INITIALIZED LOCAL, not a literal in the compare. + * Target opens with `lui $s2, 0xFFF5` in the *prologue*, used once ~200 ins later in + * `slt $v0,$s2,$s1`. No gcc-2.7.2 pass hoists a (set reg const_int) across basic blocks + * (loop.c needs a loop; cse/combine/sched never move insns between BBs) — so the insn must + * have been EMITTED in the first BB, i.e. the constant is a local initialized at the top of + * the function. cse then cannot fold it back into the compare: the `slt` operand predicate is + * `arith_operand`, which rejects a CONST_INT wider than 16 bits, so validate_change fails and + * the pseudo survives. Its live range spans every call -> global.c gives it a callee-saved reg. + * Writing `z > -0xB0000` inline instead emits the `lui` into the branch delay slot next to the + * compare (caller-saved $v0) and the function is 1 insn short. => `s32 lim = -0xB0000;` at top. + * + * 2. `lh` vs `lhu`: a short->short copy is a pure HImode move and gcc emits `lhu`. The target's + * `lh $v0,0x26($s0)` means the value passed through an SImode (int) temp: expand makes + * (set (reg:SI) (sign_extend (mem:HI))) + (set (mem:HI) (subreg:HI ...)), and combine cannot + * merge them (the merged form is mem<-mem, which no movhi accepts) so the sign-extending load + * survives. => route both halfword copies through the `s32 t` temp. + * + * 3. THE `goto` LAYOUT — dodging jump.c's store-flag conversion (jump.c:1005-1065). + * An if/else chain writing 0/1 into `doit` makes gcc collapse the last pair into + * `sltiu $v0,$v0,1`. jump.c fires that conversion when the insn immediately after a + * conditional jump is a lone `SET pseudo, CONST_INT` whose following simplejump targets the + * SAME label as the branch (jump.c:1038 `reallabelprev == temp || ... JUMP_LABEL(temp4) == + * JUMP_LABEL(insn)`) — exactly the shape of `if (c) x=0; else x=1;`. + * The target instead cross-jumps ALL the `doit=0` exits into ONE shared block placed after the + * `doit=1` fall-through; reorg's fill_slots_from_thread then COPIES that single set into all + * three branch delay slots and redirects each branch past it (which is why `addu $v0,$zero, + * $zero` appears 3x in delay slots and the shared block vanishes). A `goto zero;` / `goto one;` + * chain expresses that layout directly, and each conditional jump is then followed by a + * compare/call rather than a lone const set, so the store-flag conversion never triggers. + * GENERAL RULE: multiple predicates that all assign the SAME constant to one flag => write + * them as `goto` to a shared assignment, never as an if/else ladder. + */ +extern s32 D_8011F9C4; +extern s32 D_8018DA74; + +extern s32 func_80161B18(void); +extern s32 func_801619A4(s32*); +extern s32 func_80149AA8(s32*); +extern void func_80149AD4(s32*); +extern s32 func_80149B54(s32*); +extern void func_80149BAC(s32*); +extern s32 func_801498E0(s32*); +extern s32 func_80149954(s32); +extern s32 func_80149A64(s32*); +extern void func_800CCCC0(s32 a0); +extern s32 func_80149CD4(s32 a0); +extern void func_8015E880(s32*); +extern s32 func_80149744(struct S_80149744*); +extern void func_80149788(void); +extern s32 func_801496D4(void*); +extern void func_80149704(void); +extern int func_80148AFC(void*); +extern void func_80146D90(s32 a0); +extern void func_80154150(s32 a0, s32 a1); +extern void func_801541D8(u8*, s32, s32); +extern s32 func_801488A8(u8*); +extern void func_80147078(s32*, s16); +extern void func_8015A264(void*); +extern s32 func_80013294(void*, void*); +extern void func_80159B70(void*); +extern s32 func_8016F1AC(void); +extern s32 func_80029178(s32 a0); +extern void func_80146DB8(s32*, s32*); +extern s32 func_80161CD0(s32, s32); +extern s32 func_80161208(s32 a0); +extern s32 func_801725A4(u8*); + +s32 func_8015B950(s32 arg0) +{ + + extern void (*D_8018DAE0[])(void *); + s16 sp10[4]; + s16 sp18[4]; + s32 t; + s32 z; + s32 doit; + s32 lim = -0xB0000; + + if (func_80161B18() != 0) { + return; + } + switch (((s32 (*)(s32))func_801619A4)(arg0)) { + case 0: + case 1: + case 2: + case 6: + if (((s32 (*)(s32))func_80149AA8)(arg0) != 0) { + D_8018DAE0[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149AD4)(arg0); + return; + } + if (((s32 (*)(s32))func_80149B54)(arg0) != 0) { + D_8018DAE0[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149BAC)(arg0); + return; + } + break; + case 3: + ((void (*)(s32))func_801498E0)(arg0); + break; + case 4: + ((void (*)(s32))func_80149954)(arg0); + break; + case 5: + if (((s32 (*)(s32))func_80149A64)(arg0) != 0) { + D_8018DAE0[*(u16 *)arg0]((void *)arg0); + func_800CCCC0(arg0); + return; + } + break; + } + if (func_80149CD4(arg0) != 0) { + D_8018DAE0[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_8015E880)(arg0); + return; + } + if (((s32 (*)(s32))func_80149744)(arg0) != 0) { + D_8018DAE0[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149788)(arg0); + return; + } + if (((s32 (*)(s32))func_801496D4)(arg0) != 0) { + D_8018DAE0[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149704)(arg0); + if (((u8)((s32 (*)(s32))func_80148AFC)(arg0)) == 0) { + func_80146D90(arg0); + } + if ((*(s32 *)(arg0 + 0x24) | *(s32 *)(arg0 + 0x2C)) != 0) { + func_80154150(arg0, 0xF); + } else { + ((void (*)(s32, s32, s32))func_801541D8)(arg0, 0xD, 6); + } + *(s32 *)(arg0 + 0x238) = 1; + return; + } + if (((s32 (*)(s32))func_801488A8)(arg0) != 0) { + sp10[0] = 0; + sp10[1] = 0; + sp10[2] = 0; + t = *(s16 *)(arg0 + 0x26); + sp18[0] = t; + sp18[1] = 0; + t = *(s16 *)(arg0 + 0x2E); + sp18[2] = t; + D_8018DAE0[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 1); + ((void (*)(s32))func_8015A264)(arg0); + t = -(((s32 (*)(s16 *, s16 *))func_80013294)(sp10, sp18) << 0x10); + if (t < *(s32 *)(arg0 + 0x2C)) { + *(s32 *)(arg0 + 0x2C) = t; + } + return; + } + if (*(u16 *)(arg0 + 0xB8) == 0x8000) { + D_8018DAE0[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 0); + ((void (*)(s32))func_80159B70)(arg0); + return; + } + z = *(s32 *)(arg0 + 0x2C); + if (func_8016F1AC() != 0) { + goto zero; + } + if (z <= lim) { + goto one; + } + if (D_8011F9C4 == 0) { + goto zero; + } + if (((u8)func_80029178(0x21)) != 0) { + goto zero; + } +one: + doit = 1; + goto join; +zero: + doit = 0; +join: + if (doit != 0) { + D_8018DAE0[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 0); + ((void (*)(s32))func_80159B70)(arg0); + func_80154150(arg0, 9); + ((void (*)(s32, s32 *))func_80146DB8)(arg0, &D_8018DA74); + ((void (*)(s32, s32))func_80161CD0)(arg0, *(u16 *)(arg0 + 0x16E)); + return; + } + if (func_80161208(arg0) == 0) { + ((void (*)(s32))func_801725A4)(arg0); + } +} DEFINE_func_8015BD8C() /* dedup: shared engine-core @0x8015BD8C (src/shared) */ diff --git a/src/ov_SC02_031/ov_SC02_031_jr_8015AE2C.c b/src/ov_SC02_031/ov_SC02_031_jr_8015AE2C.c index c95531124..d6e42a13a 100644 --- a/src/ov_SC02_031/ov_SC02_031_jr_8015AE2C.c +++ b/src/ov_SC02_031/ov_SC02_031_jr_8015AE2C.c @@ -1513,7 +1513,259 @@ DEFINE_func_8015B858() /* dedup: shared engine-core @0x8015B858 (src/shared) */ DEFINE_func_8015B8F8() /* dedup: shared engine-core @0x8015B8F8 (src/shared) */ -INCLUDE_ASM("asm/ov_SC02_031/nonmatchings/ov_SC02_031_jr_8015AE2C", func_8015B950); +extern s32 func_8015AE2C(); + +// @class: plumbing +// @stuck: none — MATCH (271/271, pin-free, zero asm). The ONLY residual is DEF-SIDE plumbing, and it is now named exactly: the in-TU instantiation `DEFINE_func_8015BEE4()` (engine_core.h:1851-1855) expands to `extern s32 func_8015B950(void);` INSIDE ov_SC01_077_jr_8015AE2C.c, ~14 lines BELOW this definition, so the 1-param def collides with a `(void)` prototype -> `conflicting types for func_8015B950` (.run/bank_func_8015B950.log). §73 PARAMS axis / T0. Surgical fix = §65b de-macroize that ONE instantiation (blast radius: this TU); the fleet-wide `(void)`->`()` header edit is §63 and must be R22-validated. +/* func_8015B950 (ov_SC01_077_jr_8015AE2C, 271 ins, jtbl_801D8B74) — SESSION-21 re-verified + * + * ── ROUND-2 INDEPENDENT RE-VERIFICATION (2026-07-27, fresh agent, §88e discipline) ───────────── + * match_one : MATCH (271 ins) against the CURRENT tree — §87 staleness re-checked today. + * .text size: compiled .text = 0x43C = 1084 B = 271 ins, EXACTLY the target's declared 0x43C + * ("nonmatching func_8015B950, 0x43C"). So this is NOT a §83a length drift hiding + * behind a zero count — the count is over equal-length streams. + * jtbl : RE-DECODED MECHANICALLY, not inherited. Compiled .rodata = 0x1C = 28 B = 7 words, + * 7x R_MIPS_32 -> .text with implicit addends [58,58,58,E0,F0,100,58]; +0x8015B950 + * = [8015B9A8, 8015B9A8, 8015B9A8, 8015BA30, 8015BA40, 8015BA50, 8015B9A8]. + * Diffed word-for-word against asm/ov_SC01_077/data/tail14.data.s:15-23 — 7/7 identical. + * symcheck : SYMS-DIFF target=35 draft=34, sole MISSING = jtbl_801D8B74. This is the §81 jr + * FALSE POSITIVE, re-confirmed here by reading the relocs: gcc emits its OWN table and + * references it with R_MIPS_HI16/LO16 against the SECTION `.rodata` (t.o +0x40/+0x48), + * so the splat's dlabel NAME can never appear in the draft object's relocation set. + * Nothing is dropped and nothing is invented: the draft's other 34 symbols are exactly + * the target's other 34. + * FAMILY : the x138 remap is clean and §84-safe. Every sibling is 271 ins with an IDENTICAL + * callee set; only THREE names vary per overlay — the two data labels and the jtbl: + * ov_SC01_077 D_801872A0 / D_8018730C / jtbl_801D8B74 + * ov_SC03_099 D_80185A50 / D_80185ABC / jtbl_801BD898 + * ov_SC06_008 D_80187E44 / D_80187EB0 / jtbl_801A8734 + * The pair is always +0x6C apart, and NO literal in this draft encodes that distance + * (both labels are referenced by name), so there is no §84 derived-offset hazard. + * D_8011F9C4 is fleet-constant (main-EXE data) and must NOT be remapped. + * + * match_one: MATCH (271 ins) against the CURRENT tree (§87 staleness re-checked, 2026-07-27). + * PIN-FREE, zero asm, offset-pure (s32 arg0 + raw offsets) — x138 template-safe. + * Provenance: this is the Phase-26 crack (.run/phase26-cracks/func_8015B950.c) re-gated verbatim, + * with ONE deliberate change: the definition's return type void -> s32. + * - `void func_8015B950(s32 arg0)` : MATCH (271 ins) [the Phase-26 form] + * - `s32 func_8015B950(s32 arg0)` : MATCH (271 ins) [shipped — §3a-1 void->s32 is byte-neutral] + * The fleet/engine_core.h canonical decl is `extern s32 func_8015B950(void);` (engine_core.h:1852), + * and the last bank attempt (.run/bank_func_8015B950.log) died on `conflicting types for + * func_8015B950`. Shipping the s32 return kills the §73 RETURN axis for free and leaves only the + * cheap T0 PARAMS axis for the ladder (fix_header_decl.py / --fix-def-sig / cast_call_sites). + * Both forms are byte-identical, so the orchestrator may swap the return type back at zero cost. + * + * SYMBOLS (§58 rules 1/2 — all splat spellings, all verified present): + * D_8018730C asm/ov_SC01_077/data/tail.data.s:4355 (the state-handler vtable) + * D_801872A0 asm/ov_SC01_077/data/tail.data.s:4293 + * D_8011F9C4 main-EXE data; spelled `extern s32 D_8011F9C4;` in 5+ already-banked TUs + * jtbl_801D8B74 asm/ov_SC01_077/data/tail14.data.s:15 (compiler jump table — not named in C) + * + * JTBL VERIFIED (§8a gate): compiled .rodata = exactly 0x1C B / 7 words, 7x R_MIPS_32 .text with + * addends [0x58,0x58,0x58,0xE0,0xF0,0x100,0x58] -> +0x8015B950 = [B9A8,B9A8,B9A8,BA30,BA40,BA50, + * B9A8] == the original words at 0x801D8B74..0x801D8B8C. Bound `sltiu $v0,$v1,0x7` matches. + * The raw dlabel's 8th word 0x00000000 is NOT an entry — it is the intra-TU `.align 3` pad of the + * B34/B54/B74 jtbl chain; the object can never emit it (maspsx drops .align), so it must stay in + * the post-carve RAW data piece (the §53/§62/§81 carve chain applies at bank time). + * + * Same family as the TU's own already-matched func_8015AE2C: 7-case switch on ((s32 (*)(s32))func_801619A4)() + * (0/1/2/6 shared, 3/4/5 own, no default block — out-of-range and every `break` fall to the + * after-switch join), then a chain of "state handler" tests, each dispatching + * D_8018730C[*(u16*)arg0](arg0) and returning. + * + * THREE LEVERS (draft -> MATCH in 3 compiles): + * + * 1. PROLOGUE CONSTANT = an INITIALIZED LOCAL, not a literal in the compare. + * Target opens with `lui $s2, 0xFFF5` in the *prologue*, used once ~200 ins later in + * `slt $v0,$s2,$s1`. No gcc-2.7.2 pass hoists a (set reg const_int) across basic blocks + * (loop.c needs a loop; cse/combine/sched never move insns between BBs) — so the insn must + * have been EMITTED in the first BB, i.e. the constant is a local initialized at the top of + * the function. cse then cannot fold it back into the compare: the `slt` operand predicate is + * `arith_operand`, which rejects a CONST_INT wider than 16 bits, so validate_change fails and + * the pseudo survives. Its live range spans every call -> global.c gives it a callee-saved reg. + * Writing `z > -0xB0000` inline instead emits the `lui` into the branch delay slot next to the + * compare (caller-saved $v0) and the function is 1 insn short. => `s32 lim = -0xB0000;` at top. + * + * 2. `lh` vs `lhu`: a short->short copy is a pure HImode move and gcc emits `lhu`. The target's + * `lh $v0,0x26($s0)` means the value passed through an SImode (int) temp: expand makes + * (set (reg:SI) (sign_extend (mem:HI))) + (set (mem:HI) (subreg:HI ...)), and combine cannot + * merge them (the merged form is mem<-mem, which no movhi accepts) so the sign-extending load + * survives. => route both halfword copies through the `s32 t` temp. + * + * 3. THE `goto` LAYOUT — dodging jump.c's store-flag conversion (jump.c:1005-1065). + * An if/else chain writing 0/1 into `doit` makes gcc collapse the last pair into + * `sltiu $v0,$v0,1`. jump.c fires that conversion when the insn immediately after a + * conditional jump is a lone `SET pseudo, CONST_INT` whose following simplejump targets the + * SAME label as the branch (jump.c:1038 `reallabelprev == temp || ... JUMP_LABEL(temp4) == + * JUMP_LABEL(insn)`) — exactly the shape of `if (c) x=0; else x=1;`. + * The target instead cross-jumps ALL the `doit=0` exits into ONE shared block placed after the + * `doit=1` fall-through; reorg's fill_slots_from_thread then COPIES that single set into all + * three branch delay slots and redirects each branch past it (which is why `addu $v0,$zero, + * $zero` appears 3x in delay slots and the shared block vanishes). A `goto zero;` / `goto one;` + * chain expresses that layout directly, and each conditional jump is then followed by a + * compare/call rather than a lone const set, so the store-flag conversion never triggers. + * GENERAL RULE: multiple predicates that all assign the SAME constant to one flag => write + * them as `goto` to a shared assignment, never as an if/else ladder. + */ +extern s32 D_8011F9C4; +extern s32 D_801872A0; + +extern s32 func_80161B18(void); +extern s32 func_801619A4(s32*); +extern s32 func_80149AA8(s32*); +extern void func_80149AD4(s32*); +extern s32 func_80149B54(s32*); +extern void func_80149BAC(s32*); +extern s32 func_801498E0(s32*); +extern s32 func_80149954(s32); +extern s32 func_80149A64(s32*); +extern void func_800CCCC0(s32 a0); +extern s32 func_80149CD4(s32 a0); +extern void func_8015E880(s32*); +extern s32 func_80149744(struct S_80149744*); +extern void func_80149788(void); +extern s32 func_801496D4(void*); +extern void func_80149704(void); +extern int func_80148AFC(void*); +extern void func_80146D90(s32 a0); +extern void func_80154150(s32 a0, s32 a1); +extern void func_801541D8(u8*, s32, s32); +extern s32 func_801488A8(u8*); +extern void func_80147078(s32*, s16); +extern void func_8015A264(void*); +extern s32 func_80013294(void*, void*); +extern void func_80159B70(void*); +extern s32 func_8016F1AC(void); +extern s32 func_80029178(s32 a0); +extern void func_80146DB8(s32*, s32*); +extern s32 func_80161CD0(s32, s32); +extern s32 func_80161208(s32 a0); +extern s32 func_801725A4(u8*); + +s32 func_8015B950(s32 arg0) +{ + + extern void (*D_8018730C[])(void *); + s16 sp10[4]; + s16 sp18[4]; + s32 t; + s32 z; + s32 doit; + s32 lim = -0xB0000; + + if (func_80161B18() != 0) { + return; + } + switch (((s32 (*)(s32))func_801619A4)(arg0)) { + case 0: + case 1: + case 2: + case 6: + if (((s32 (*)(s32))func_80149AA8)(arg0) != 0) { + D_8018730C[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149AD4)(arg0); + return; + } + if (((s32 (*)(s32))func_80149B54)(arg0) != 0) { + D_8018730C[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149BAC)(arg0); + return; + } + break; + case 3: + ((void (*)(s32))func_801498E0)(arg0); + break; + case 4: + ((void (*)(s32))func_80149954)(arg0); + break; + case 5: + if (((s32 (*)(s32))func_80149A64)(arg0) != 0) { + D_8018730C[*(u16 *)arg0]((void *)arg0); + func_800CCCC0(arg0); + return; + } + break; + } + if (func_80149CD4(arg0) != 0) { + D_8018730C[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_8015E880)(arg0); + return; + } + if (((s32 (*)(s32))func_80149744)(arg0) != 0) { + D_8018730C[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149788)(arg0); + return; + } + if (((s32 (*)(s32))func_801496D4)(arg0) != 0) { + D_8018730C[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149704)(arg0); + if (((u8)((s32 (*)(s32))func_80148AFC)(arg0)) == 0) { + func_80146D90(arg0); + } + if ((*(s32 *)(arg0 + 0x24) | *(s32 *)(arg0 + 0x2C)) != 0) { + func_80154150(arg0, 0xF); + } else { + ((void (*)(s32, s32, s32))func_801541D8)(arg0, 0xD, 6); + } + *(s32 *)(arg0 + 0x238) = 1; + return; + } + if (((s32 (*)(s32))func_801488A8)(arg0) != 0) { + sp10[0] = 0; + sp10[1] = 0; + sp10[2] = 0; + t = *(s16 *)(arg0 + 0x26); + sp18[0] = t; + sp18[1] = 0; + t = *(s16 *)(arg0 + 0x2E); + sp18[2] = t; + D_8018730C[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 1); + ((void (*)(s32))func_8015A264)(arg0); + t = -(((s32 (*)(s16 *, s16 *))func_80013294)(sp10, sp18) << 0x10); + if (t < *(s32 *)(arg0 + 0x2C)) { + *(s32 *)(arg0 + 0x2C) = t; + } + return; + } + if (*(u16 *)(arg0 + 0xB8) == 0x8000) { + D_8018730C[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 0); + ((void (*)(s32))func_80159B70)(arg0); + return; + } + z = *(s32 *)(arg0 + 0x2C); + if (func_8016F1AC() != 0) { + goto zero; + } + if (z <= lim) { + goto one; + } + if (D_8011F9C4 == 0) { + goto zero; + } + if (((u8)func_80029178(0x21)) != 0) { + goto zero; + } +one: + doit = 1; + goto join; +zero: + doit = 0; +join: + if (doit != 0) { + D_8018730C[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 0); + ((void (*)(s32))func_80159B70)(arg0); + func_80154150(arg0, 9); + ((void (*)(s32, s32 *))func_80146DB8)(arg0, &D_801872A0); + ((void (*)(s32, s32))func_80161CD0)(arg0, *(u16 *)(arg0 + 0x16E)); + return; + } + if (func_80161208(arg0) == 0) { + ((void (*)(s32))func_801725A4)(arg0); + } +} DEFINE_func_8015BD8C() /* dedup: shared engine-core @0x8015BD8C (src/shared) */ diff --git a/src/ov_SC02_035/ov_SC02_035_jr_8015AE2C.c b/src/ov_SC02_035/ov_SC02_035_jr_8015AE2C.c index 12be16f16..3e0f08384 100644 --- a/src/ov_SC02_035/ov_SC02_035_jr_8015AE2C.c +++ b/src/ov_SC02_035/ov_SC02_035_jr_8015AE2C.c @@ -1513,7 +1513,259 @@ DEFINE_func_8015B858() /* dedup: shared engine-core @0x8015B858 (src/shared) */ DEFINE_func_8015B8F8() /* dedup: shared engine-core @0x8015B8F8 (src/shared) */ -INCLUDE_ASM("asm/ov_SC02_035/nonmatchings/ov_SC02_035_jr_8015AE2C", func_8015B950); +extern s32 func_8015AE2C(); + +// @class: plumbing +// @stuck: none — MATCH (271/271, pin-free, zero asm). The ONLY residual is DEF-SIDE plumbing, and it is now named exactly: the in-TU instantiation `DEFINE_func_8015BEE4()` (engine_core.h:1851-1855) expands to `extern s32 func_8015B950(void);` INSIDE ov_SC01_077_jr_8015AE2C.c, ~14 lines BELOW this definition, so the 1-param def collides with a `(void)` prototype -> `conflicting types for func_8015B950` (.run/bank_func_8015B950.log). §73 PARAMS axis / T0. Surgical fix = §65b de-macroize that ONE instantiation (blast radius: this TU); the fleet-wide `(void)`->`()` header edit is §63 and must be R22-validated. +/* func_8015B950 (ov_SC01_077_jr_8015AE2C, 271 ins, jtbl_801D8B74) — SESSION-21 re-verified + * + * ── ROUND-2 INDEPENDENT RE-VERIFICATION (2026-07-27, fresh agent, §88e discipline) ───────────── + * match_one : MATCH (271 ins) against the CURRENT tree — §87 staleness re-checked today. + * .text size: compiled .text = 0x43C = 1084 B = 271 ins, EXACTLY the target's declared 0x43C + * ("nonmatching func_8015B950, 0x43C"). So this is NOT a §83a length drift hiding + * behind a zero count — the count is over equal-length streams. + * jtbl : RE-DECODED MECHANICALLY, not inherited. Compiled .rodata = 0x1C = 28 B = 7 words, + * 7x R_MIPS_32 -> .text with implicit addends [58,58,58,E0,F0,100,58]; +0x8015B950 + * = [8015B9A8, 8015B9A8, 8015B9A8, 8015BA30, 8015BA40, 8015BA50, 8015B9A8]. + * Diffed word-for-word against asm/ov_SC01_077/data/tail14.data.s:15-23 — 7/7 identical. + * symcheck : SYMS-DIFF target=35 draft=34, sole MISSING = jtbl_801D8B74. This is the §81 jr + * FALSE POSITIVE, re-confirmed here by reading the relocs: gcc emits its OWN table and + * references it with R_MIPS_HI16/LO16 against the SECTION `.rodata` (t.o +0x40/+0x48), + * so the splat's dlabel NAME can never appear in the draft object's relocation set. + * Nothing is dropped and nothing is invented: the draft's other 34 symbols are exactly + * the target's other 34. + * FAMILY : the x138 remap is clean and §84-safe. Every sibling is 271 ins with an IDENTICAL + * callee set; only THREE names vary per overlay — the two data labels and the jtbl: + * ov_SC01_077 D_80186B00 / D_80186B6C / jtbl_801D8B74 + * ov_SC03_099 D_80185A50 / D_80185ABC / jtbl_801BD898 + * ov_SC06_008 D_80187E44 / D_80187EB0 / jtbl_801A8734 + * The pair is always +0x6C apart, and NO literal in this draft encodes that distance + * (both labels are referenced by name), so there is no §84 derived-offset hazard. + * D_8011F9C4 is fleet-constant (main-EXE data) and must NOT be remapped. + * + * match_one: MATCH (271 ins) against the CURRENT tree (§87 staleness re-checked, 2026-07-27). + * PIN-FREE, zero asm, offset-pure (s32 arg0 + raw offsets) — x138 template-safe. + * Provenance: this is the Phase-26 crack (.run/phase26-cracks/func_8015B950.c) re-gated verbatim, + * with ONE deliberate change: the definition's return type void -> s32. + * - `void func_8015B950(s32 arg0)` : MATCH (271 ins) [the Phase-26 form] + * - `s32 func_8015B950(s32 arg0)` : MATCH (271 ins) [shipped — §3a-1 void->s32 is byte-neutral] + * The fleet/engine_core.h canonical decl is `extern s32 func_8015B950(void);` (engine_core.h:1852), + * and the last bank attempt (.run/bank_func_8015B950.log) died on `conflicting types for + * func_8015B950`. Shipping the s32 return kills the §73 RETURN axis for free and leaves only the + * cheap T0 PARAMS axis for the ladder (fix_header_decl.py / --fix-def-sig / cast_call_sites). + * Both forms are byte-identical, so the orchestrator may swap the return type back at zero cost. + * + * SYMBOLS (§58 rules 1/2 — all splat spellings, all verified present): + * D_80186B6C asm/ov_SC01_077/data/tail.data.s:4355 (the state-handler vtable) + * D_80186B00 asm/ov_SC01_077/data/tail.data.s:4293 + * D_8011F9C4 main-EXE data; spelled `extern s32 D_8011F9C4;` in 5+ already-banked TUs + * jtbl_801D8B74 asm/ov_SC01_077/data/tail14.data.s:15 (compiler jump table — not named in C) + * + * JTBL VERIFIED (§8a gate): compiled .rodata = exactly 0x1C B / 7 words, 7x R_MIPS_32 .text with + * addends [0x58,0x58,0x58,0xE0,0xF0,0x100,0x58] -> +0x8015B950 = [B9A8,B9A8,B9A8,BA30,BA40,BA50, + * B9A8] == the original words at 0x801D8B74..0x801D8B8C. Bound `sltiu $v0,$v1,0x7` matches. + * The raw dlabel's 8th word 0x00000000 is NOT an entry — it is the intra-TU `.align 3` pad of the + * B34/B54/B74 jtbl chain; the object can never emit it (maspsx drops .align), so it must stay in + * the post-carve RAW data piece (the §53/§62/§81 carve chain applies at bank time). + * + * Same family as the TU's own already-matched func_8015AE2C: 7-case switch on ((s32 (*)(s32))func_801619A4)() + * (0/1/2/6 shared, 3/4/5 own, no default block — out-of-range and every `break` fall to the + * after-switch join), then a chain of "state handler" tests, each dispatching + * D_80186B6C[*(u16*)arg0](arg0) and returning. + * + * THREE LEVERS (draft -> MATCH in 3 compiles): + * + * 1. PROLOGUE CONSTANT = an INITIALIZED LOCAL, not a literal in the compare. + * Target opens with `lui $s2, 0xFFF5` in the *prologue*, used once ~200 ins later in + * `slt $v0,$s2,$s1`. No gcc-2.7.2 pass hoists a (set reg const_int) across basic blocks + * (loop.c needs a loop; cse/combine/sched never move insns between BBs) — so the insn must + * have been EMITTED in the first BB, i.e. the constant is a local initialized at the top of + * the function. cse then cannot fold it back into the compare: the `slt` operand predicate is + * `arith_operand`, which rejects a CONST_INT wider than 16 bits, so validate_change fails and + * the pseudo survives. Its live range spans every call -> global.c gives it a callee-saved reg. + * Writing `z > -0xB0000` inline instead emits the `lui` into the branch delay slot next to the + * compare (caller-saved $v0) and the function is 1 insn short. => `s32 lim = -0xB0000;` at top. + * + * 2. `lh` vs `lhu`: a short->short copy is a pure HImode move and gcc emits `lhu`. The target's + * `lh $v0,0x26($s0)` means the value passed through an SImode (int) temp: expand makes + * (set (reg:SI) (sign_extend (mem:HI))) + (set (mem:HI) (subreg:HI ...)), and combine cannot + * merge them (the merged form is mem<-mem, which no movhi accepts) so the sign-extending load + * survives. => route both halfword copies through the `s32 t` temp. + * + * 3. THE `goto` LAYOUT — dodging jump.c's store-flag conversion (jump.c:1005-1065). + * An if/else chain writing 0/1 into `doit` makes gcc collapse the last pair into + * `sltiu $v0,$v0,1`. jump.c fires that conversion when the insn immediately after a + * conditional jump is a lone `SET pseudo, CONST_INT` whose following simplejump targets the + * SAME label as the branch (jump.c:1038 `reallabelprev == temp || ... JUMP_LABEL(temp4) == + * JUMP_LABEL(insn)`) — exactly the shape of `if (c) x=0; else x=1;`. + * The target instead cross-jumps ALL the `doit=0` exits into ONE shared block placed after the + * `doit=1` fall-through; reorg's fill_slots_from_thread then COPIES that single set into all + * three branch delay slots and redirects each branch past it (which is why `addu $v0,$zero, + * $zero` appears 3x in delay slots and the shared block vanishes). A `goto zero;` / `goto one;` + * chain expresses that layout directly, and each conditional jump is then followed by a + * compare/call rather than a lone const set, so the store-flag conversion never triggers. + * GENERAL RULE: multiple predicates that all assign the SAME constant to one flag => write + * them as `goto` to a shared assignment, never as an if/else ladder. + */ +extern s32 D_8011F9C4; +extern s32 D_80186B00; + +extern s32 func_80161B18(void); +extern s32 func_801619A4(s32*); +extern s32 func_80149AA8(s32*); +extern void func_80149AD4(s32*); +extern s32 func_80149B54(s32*); +extern void func_80149BAC(s32*); +extern s32 func_801498E0(s32*); +extern s32 func_80149954(s32); +extern s32 func_80149A64(s32*); +extern void func_800CCCC0(s32 a0); +extern s32 func_80149CD4(s32 a0); +extern void func_8015E880(s32*); +extern s32 func_80149744(struct S_80149744*); +extern void func_80149788(void); +extern s32 func_801496D4(void*); +extern void func_80149704(void); +extern int func_80148AFC(void*); +extern void func_80146D90(s32 a0); +extern void func_80154150(s32 a0, s32 a1); +extern void func_801541D8(u8*, s32, s32); +extern s32 func_801488A8(u8*); +extern void func_80147078(s32*, s16); +extern void func_8015A264(void*); +extern s32 func_80013294(void*, void*); +extern void func_80159B70(void*); +extern s32 func_8016F1AC(void); +extern s32 func_80029178(s32 a0); +extern void func_80146DB8(s32*, s32*); +extern s32 func_80161CD0(s32, s32); +extern s32 func_80161208(s32 a0); +extern s32 func_801725A4(u8*); + +s32 func_8015B950(s32 arg0) +{ + + extern void (*D_80186B6C[])(void *); + s16 sp10[4]; + s16 sp18[4]; + s32 t; + s32 z; + s32 doit; + s32 lim = -0xB0000; + + if (func_80161B18() != 0) { + return; + } + switch (((s32 (*)(s32))func_801619A4)(arg0)) { + case 0: + case 1: + case 2: + case 6: + if (((s32 (*)(s32))func_80149AA8)(arg0) != 0) { + D_80186B6C[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149AD4)(arg0); + return; + } + if (((s32 (*)(s32))func_80149B54)(arg0) != 0) { + D_80186B6C[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149BAC)(arg0); + return; + } + break; + case 3: + ((void (*)(s32))func_801498E0)(arg0); + break; + case 4: + ((void (*)(s32))func_80149954)(arg0); + break; + case 5: + if (((s32 (*)(s32))func_80149A64)(arg0) != 0) { + D_80186B6C[*(u16 *)arg0]((void *)arg0); + func_800CCCC0(arg0); + return; + } + break; + } + if (func_80149CD4(arg0) != 0) { + D_80186B6C[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_8015E880)(arg0); + return; + } + if (((s32 (*)(s32))func_80149744)(arg0) != 0) { + D_80186B6C[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149788)(arg0); + return; + } + if (((s32 (*)(s32))func_801496D4)(arg0) != 0) { + D_80186B6C[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149704)(arg0); + if (((u8)((s32 (*)(s32))func_80148AFC)(arg0)) == 0) { + func_80146D90(arg0); + } + if ((*(s32 *)(arg0 + 0x24) | *(s32 *)(arg0 + 0x2C)) != 0) { + func_80154150(arg0, 0xF); + } else { + ((void (*)(s32, s32, s32))func_801541D8)(arg0, 0xD, 6); + } + *(s32 *)(arg0 + 0x238) = 1; + return; + } + if (((s32 (*)(s32))func_801488A8)(arg0) != 0) { + sp10[0] = 0; + sp10[1] = 0; + sp10[2] = 0; + t = *(s16 *)(arg0 + 0x26); + sp18[0] = t; + sp18[1] = 0; + t = *(s16 *)(arg0 + 0x2E); + sp18[2] = t; + D_80186B6C[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 1); + ((void (*)(s32))func_8015A264)(arg0); + t = -(((s32 (*)(s16 *, s16 *))func_80013294)(sp10, sp18) << 0x10); + if (t < *(s32 *)(arg0 + 0x2C)) { + *(s32 *)(arg0 + 0x2C) = t; + } + return; + } + if (*(u16 *)(arg0 + 0xB8) == 0x8000) { + D_80186B6C[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 0); + ((void (*)(s32))func_80159B70)(arg0); + return; + } + z = *(s32 *)(arg0 + 0x2C); + if (func_8016F1AC() != 0) { + goto zero; + } + if (z <= lim) { + goto one; + } + if (D_8011F9C4 == 0) { + goto zero; + } + if (((u8)func_80029178(0x21)) != 0) { + goto zero; + } +one: + doit = 1; + goto join; +zero: + doit = 0; +join: + if (doit != 0) { + D_80186B6C[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 0); + ((void (*)(s32))func_80159B70)(arg0); + func_80154150(arg0, 9); + ((void (*)(s32, s32 *))func_80146DB8)(arg0, &D_80186B00); + ((void (*)(s32, s32))func_80161CD0)(arg0, *(u16 *)(arg0 + 0x16E)); + return; + } + if (func_80161208(arg0) == 0) { + ((void (*)(s32))func_801725A4)(arg0); + } +} DEFINE_func_8015BD8C() /* dedup: shared engine-core @0x8015BD8C (src/shared) */ diff --git a/src/ov_SC02_039/ov_SC02_039_jr_8015AE2C.c b/src/ov_SC02_039/ov_SC02_039_jr_8015AE2C.c index 8d6b18cde..2428c1aa2 100644 --- a/src/ov_SC02_039/ov_SC02_039_jr_8015AE2C.c +++ b/src/ov_SC02_039/ov_SC02_039_jr_8015AE2C.c @@ -1513,7 +1513,259 @@ DEFINE_func_8015B858() /* dedup: shared engine-core @0x8015B858 (src/shared) */ DEFINE_func_8015B8F8() /* dedup: shared engine-core @0x8015B8F8 (src/shared) */ -INCLUDE_ASM("asm/ov_SC02_039/nonmatchings/ov_SC02_039_jr_8015AE2C", func_8015B950); +extern s32 func_8015AE2C(); + +// @class: plumbing +// @stuck: none — MATCH (271/271, pin-free, zero asm). The ONLY residual is DEF-SIDE plumbing, and it is now named exactly: the in-TU instantiation `DEFINE_func_8015BEE4()` (engine_core.h:1851-1855) expands to `extern s32 func_8015B950(void);` INSIDE ov_SC01_077_jr_8015AE2C.c, ~14 lines BELOW this definition, so the 1-param def collides with a `(void)` prototype -> `conflicting types for func_8015B950` (.run/bank_func_8015B950.log). §73 PARAMS axis / T0. Surgical fix = §65b de-macroize that ONE instantiation (blast radius: this TU); the fleet-wide `(void)`->`()` header edit is §63 and must be R22-validated. +/* func_8015B950 (ov_SC01_077_jr_8015AE2C, 271 ins, jtbl_801D8B74) — SESSION-21 re-verified + * + * ── ROUND-2 INDEPENDENT RE-VERIFICATION (2026-07-27, fresh agent, §88e discipline) ───────────── + * match_one : MATCH (271 ins) against the CURRENT tree — §87 staleness re-checked today. + * .text size: compiled .text = 0x43C = 1084 B = 271 ins, EXACTLY the target's declared 0x43C + * ("nonmatching func_8015B950, 0x43C"). So this is NOT a §83a length drift hiding + * behind a zero count — the count is over equal-length streams. + * jtbl : RE-DECODED MECHANICALLY, not inherited. Compiled .rodata = 0x1C = 28 B = 7 words, + * 7x R_MIPS_32 -> .text with implicit addends [58,58,58,E0,F0,100,58]; +0x8015B950 + * = [8015B9A8, 8015B9A8, 8015B9A8, 8015BA30, 8015BA40, 8015BA50, 8015B9A8]. + * Diffed word-for-word against asm/ov_SC01_077/data/tail14.data.s:15-23 — 7/7 identical. + * symcheck : SYMS-DIFF target=35 draft=34, sole MISSING = jtbl_801D8B74. This is the §81 jr + * FALSE POSITIVE, re-confirmed here by reading the relocs: gcc emits its OWN table and + * references it with R_MIPS_HI16/LO16 against the SECTION `.rodata` (t.o +0x40/+0x48), + * so the splat's dlabel NAME can never appear in the draft object's relocation set. + * Nothing is dropped and nothing is invented: the draft's other 34 symbols are exactly + * the target's other 34. + * FAMILY : the x138 remap is clean and §84-safe. Every sibling is 271 ins with an IDENTICAL + * callee set; only THREE names vary per overlay — the two data labels and the jtbl: + * ov_SC01_077 D_8018172C / D_80181798 / jtbl_801D8B74 + * ov_SC03_099 D_80185A50 / D_80185ABC / jtbl_801BD898 + * ov_SC06_008 D_80187E44 / D_80187EB0 / jtbl_801A8734 + * The pair is always +0x6C apart, and NO literal in this draft encodes that distance + * (both labels are referenced by name), so there is no §84 derived-offset hazard. + * D_8011F9C4 is fleet-constant (main-EXE data) and must NOT be remapped. + * + * match_one: MATCH (271 ins) against the CURRENT tree (§87 staleness re-checked, 2026-07-27). + * PIN-FREE, zero asm, offset-pure (s32 arg0 + raw offsets) — x138 template-safe. + * Provenance: this is the Phase-26 crack (.run/phase26-cracks/func_8015B950.c) re-gated verbatim, + * with ONE deliberate change: the definition's return type void -> s32. + * - `void func_8015B950(s32 arg0)` : MATCH (271 ins) [the Phase-26 form] + * - `s32 func_8015B950(s32 arg0)` : MATCH (271 ins) [shipped — §3a-1 void->s32 is byte-neutral] + * The fleet/engine_core.h canonical decl is `extern s32 func_8015B950(void);` (engine_core.h:1852), + * and the last bank attempt (.run/bank_func_8015B950.log) died on `conflicting types for + * func_8015B950`. Shipping the s32 return kills the §73 RETURN axis for free and leaves only the + * cheap T0 PARAMS axis for the ladder (fix_header_decl.py / --fix-def-sig / cast_call_sites). + * Both forms are byte-identical, so the orchestrator may swap the return type back at zero cost. + * + * SYMBOLS (§58 rules 1/2 — all splat spellings, all verified present): + * D_80181798 asm/ov_SC01_077/data/tail.data.s:4355 (the state-handler vtable) + * D_8018172C asm/ov_SC01_077/data/tail.data.s:4293 + * D_8011F9C4 main-EXE data; spelled `extern s32 D_8011F9C4;` in 5+ already-banked TUs + * jtbl_801D8B74 asm/ov_SC01_077/data/tail14.data.s:15 (compiler jump table — not named in C) + * + * JTBL VERIFIED (§8a gate): compiled .rodata = exactly 0x1C B / 7 words, 7x R_MIPS_32 .text with + * addends [0x58,0x58,0x58,0xE0,0xF0,0x100,0x58] -> +0x8015B950 = [B9A8,B9A8,B9A8,BA30,BA40,BA50, + * B9A8] == the original words at 0x801D8B74..0x801D8B8C. Bound `sltiu $v0,$v1,0x7` matches. + * The raw dlabel's 8th word 0x00000000 is NOT an entry — it is the intra-TU `.align 3` pad of the + * B34/B54/B74 jtbl chain; the object can never emit it (maspsx drops .align), so it must stay in + * the post-carve RAW data piece (the §53/§62/§81 carve chain applies at bank time). + * + * Same family as the TU's own already-matched func_8015AE2C: 7-case switch on ((s32 (*)(s32))func_801619A4)() + * (0/1/2/6 shared, 3/4/5 own, no default block — out-of-range and every `break` fall to the + * after-switch join), then a chain of "state handler" tests, each dispatching + * D_80181798[*(u16*)arg0](arg0) and returning. + * + * THREE LEVERS (draft -> MATCH in 3 compiles): + * + * 1. PROLOGUE CONSTANT = an INITIALIZED LOCAL, not a literal in the compare. + * Target opens with `lui $s2, 0xFFF5` in the *prologue*, used once ~200 ins later in + * `slt $v0,$s2,$s1`. No gcc-2.7.2 pass hoists a (set reg const_int) across basic blocks + * (loop.c needs a loop; cse/combine/sched never move insns between BBs) — so the insn must + * have been EMITTED in the first BB, i.e. the constant is a local initialized at the top of + * the function. cse then cannot fold it back into the compare: the `slt` operand predicate is + * `arith_operand`, which rejects a CONST_INT wider than 16 bits, so validate_change fails and + * the pseudo survives. Its live range spans every call -> global.c gives it a callee-saved reg. + * Writing `z > -0xB0000` inline instead emits the `lui` into the branch delay slot next to the + * compare (caller-saved $v0) and the function is 1 insn short. => `s32 lim = -0xB0000;` at top. + * + * 2. `lh` vs `lhu`: a short->short copy is a pure HImode move and gcc emits `lhu`. The target's + * `lh $v0,0x26($s0)` means the value passed through an SImode (int) temp: expand makes + * (set (reg:SI) (sign_extend (mem:HI))) + (set (mem:HI) (subreg:HI ...)), and combine cannot + * merge them (the merged form is mem<-mem, which no movhi accepts) so the sign-extending load + * survives. => route both halfword copies through the `s32 t` temp. + * + * 3. THE `goto` LAYOUT — dodging jump.c's store-flag conversion (jump.c:1005-1065). + * An if/else chain writing 0/1 into `doit` makes gcc collapse the last pair into + * `sltiu $v0,$v0,1`. jump.c fires that conversion when the insn immediately after a + * conditional jump is a lone `SET pseudo, CONST_INT` whose following simplejump targets the + * SAME label as the branch (jump.c:1038 `reallabelprev == temp || ... JUMP_LABEL(temp4) == + * JUMP_LABEL(insn)`) — exactly the shape of `if (c) x=0; else x=1;`. + * The target instead cross-jumps ALL the `doit=0` exits into ONE shared block placed after the + * `doit=1` fall-through; reorg's fill_slots_from_thread then COPIES that single set into all + * three branch delay slots and redirects each branch past it (which is why `addu $v0,$zero, + * $zero` appears 3x in delay slots and the shared block vanishes). A `goto zero;` / `goto one;` + * chain expresses that layout directly, and each conditional jump is then followed by a + * compare/call rather than a lone const set, so the store-flag conversion never triggers. + * GENERAL RULE: multiple predicates that all assign the SAME constant to one flag => write + * them as `goto` to a shared assignment, never as an if/else ladder. + */ +extern s32 D_8011F9C4; +extern s32 D_8018172C; + +extern s32 func_80161B18(void); +extern s32 func_801619A4(s32*); +extern s32 func_80149AA8(s32*); +extern void func_80149AD4(s32*); +extern s32 func_80149B54(s32*); +extern void func_80149BAC(s32*); +extern s32 func_801498E0(s32*); +extern s32 func_80149954(s32); +extern s32 func_80149A64(s32*); +extern void func_800CCCC0(s32 a0); +extern s32 func_80149CD4(s32 a0); +extern void func_8015E880(s32*); +extern s32 func_80149744(struct S_80149744*); +extern void func_80149788(void); +extern s32 func_801496D4(void*); +extern void func_80149704(void); +extern int func_80148AFC(void*); +extern void func_80146D90(s32 a0); +extern void func_80154150(s32 a0, s32 a1); +extern void func_801541D8(u8*, s32, s32); +extern s32 func_801488A8(u8*); +extern void func_80147078(s32*, s16); +extern void func_8015A264(void*); +extern s32 func_80013294(void*, void*); +extern void func_80159B70(void*); +extern s32 func_8016F1AC(void); +extern s32 func_80029178(s32 a0); +extern void func_80146DB8(s32*, s32*); +extern s32 func_80161CD0(s32, s32); +extern s32 func_80161208(s32 a0); +extern s32 func_801725A4(u8*); + +s32 func_8015B950(s32 arg0) +{ + + extern void (*D_80181798[])(void *); + s16 sp10[4]; + s16 sp18[4]; + s32 t; + s32 z; + s32 doit; + s32 lim = -0xB0000; + + if (func_80161B18() != 0) { + return; + } + switch (((s32 (*)(s32))func_801619A4)(arg0)) { + case 0: + case 1: + case 2: + case 6: + if (((s32 (*)(s32))func_80149AA8)(arg0) != 0) { + D_80181798[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149AD4)(arg0); + return; + } + if (((s32 (*)(s32))func_80149B54)(arg0) != 0) { + D_80181798[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149BAC)(arg0); + return; + } + break; + case 3: + ((void (*)(s32))func_801498E0)(arg0); + break; + case 4: + ((void (*)(s32))func_80149954)(arg0); + break; + case 5: + if (((s32 (*)(s32))func_80149A64)(arg0) != 0) { + D_80181798[*(u16 *)arg0]((void *)arg0); + func_800CCCC0(arg0); + return; + } + break; + } + if (func_80149CD4(arg0) != 0) { + D_80181798[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_8015E880)(arg0); + return; + } + if (((s32 (*)(s32))func_80149744)(arg0) != 0) { + D_80181798[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149788)(arg0); + return; + } + if (((s32 (*)(s32))func_801496D4)(arg0) != 0) { + D_80181798[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149704)(arg0); + if (((u8)((s32 (*)(s32))func_80148AFC)(arg0)) == 0) { + func_80146D90(arg0); + } + if ((*(s32 *)(arg0 + 0x24) | *(s32 *)(arg0 + 0x2C)) != 0) { + func_80154150(arg0, 0xF); + } else { + ((void (*)(s32, s32, s32))func_801541D8)(arg0, 0xD, 6); + } + *(s32 *)(arg0 + 0x238) = 1; + return; + } + if (((s32 (*)(s32))func_801488A8)(arg0) != 0) { + sp10[0] = 0; + sp10[1] = 0; + sp10[2] = 0; + t = *(s16 *)(arg0 + 0x26); + sp18[0] = t; + sp18[1] = 0; + t = *(s16 *)(arg0 + 0x2E); + sp18[2] = t; + D_80181798[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 1); + ((void (*)(s32))func_8015A264)(arg0); + t = -(((s32 (*)(s16 *, s16 *))func_80013294)(sp10, sp18) << 0x10); + if (t < *(s32 *)(arg0 + 0x2C)) { + *(s32 *)(arg0 + 0x2C) = t; + } + return; + } + if (*(u16 *)(arg0 + 0xB8) == 0x8000) { + D_80181798[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 0); + ((void (*)(s32))func_80159B70)(arg0); + return; + } + z = *(s32 *)(arg0 + 0x2C); + if (func_8016F1AC() != 0) { + goto zero; + } + if (z <= lim) { + goto one; + } + if (D_8011F9C4 == 0) { + goto zero; + } + if (((u8)func_80029178(0x21)) != 0) { + goto zero; + } +one: + doit = 1; + goto join; +zero: + doit = 0; +join: + if (doit != 0) { + D_80181798[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 0); + ((void (*)(s32))func_80159B70)(arg0); + func_80154150(arg0, 9); + ((void (*)(s32, s32 *))func_80146DB8)(arg0, &D_8018172C); + ((void (*)(s32, s32))func_80161CD0)(arg0, *(u16 *)(arg0 + 0x16E)); + return; + } + if (func_80161208(arg0) == 0) { + ((void (*)(s32))func_801725A4)(arg0); + } +} DEFINE_func_8015BD8C() /* dedup: shared engine-core @0x8015BD8C (src/shared) */ diff --git a/src/ov_SC02_041/ov_SC02_041_jr_8015AE2C.c b/src/ov_SC02_041/ov_SC02_041_jr_8015AE2C.c index 0b02e2702..ec03f51bc 100644 --- a/src/ov_SC02_041/ov_SC02_041_jr_8015AE2C.c +++ b/src/ov_SC02_041/ov_SC02_041_jr_8015AE2C.c @@ -1513,7 +1513,259 @@ DEFINE_func_8015B858() /* dedup: shared engine-core @0x8015B858 (src/shared) */ DEFINE_func_8015B8F8() /* dedup: shared engine-core @0x8015B8F8 (src/shared) */ -INCLUDE_ASM("asm/ov_SC02_041/nonmatchings/ov_SC02_041_jr_8015AE2C", func_8015B950); +extern s32 func_8015AE2C(); + +// @class: plumbing +// @stuck: none — MATCH (271/271, pin-free, zero asm). The ONLY residual is DEF-SIDE plumbing, and it is now named exactly: the in-TU instantiation `DEFINE_func_8015BEE4()` (engine_core.h:1851-1855) expands to `extern s32 func_8015B950(void);` INSIDE ov_SC01_077_jr_8015AE2C.c, ~14 lines BELOW this definition, so the 1-param def collides with a `(void)` prototype -> `conflicting types for func_8015B950` (.run/bank_func_8015B950.log). §73 PARAMS axis / T0. Surgical fix = §65b de-macroize that ONE instantiation (blast radius: this TU); the fleet-wide `(void)`->`()` header edit is §63 and must be R22-validated. +/* func_8015B950 (ov_SC01_077_jr_8015AE2C, 271 ins, jtbl_801D8B74) — SESSION-21 re-verified + * + * ── ROUND-2 INDEPENDENT RE-VERIFICATION (2026-07-27, fresh agent, §88e discipline) ───────────── + * match_one : MATCH (271 ins) against the CURRENT tree — §87 staleness re-checked today. + * .text size: compiled .text = 0x43C = 1084 B = 271 ins, EXACTLY the target's declared 0x43C + * ("nonmatching func_8015B950, 0x43C"). So this is NOT a §83a length drift hiding + * behind a zero count — the count is over equal-length streams. + * jtbl : RE-DECODED MECHANICALLY, not inherited. Compiled .rodata = 0x1C = 28 B = 7 words, + * 7x R_MIPS_32 -> .text with implicit addends [58,58,58,E0,F0,100,58]; +0x8015B950 + * = [8015B9A8, 8015B9A8, 8015B9A8, 8015BA30, 8015BA40, 8015BA50, 8015B9A8]. + * Diffed word-for-word against asm/ov_SC01_077/data/tail14.data.s:15-23 — 7/7 identical. + * symcheck : SYMS-DIFF target=35 draft=34, sole MISSING = jtbl_801D8B74. This is the §81 jr + * FALSE POSITIVE, re-confirmed here by reading the relocs: gcc emits its OWN table and + * references it with R_MIPS_HI16/LO16 against the SECTION `.rodata` (t.o +0x40/+0x48), + * so the splat's dlabel NAME can never appear in the draft object's relocation set. + * Nothing is dropped and nothing is invented: the draft's other 34 symbols are exactly + * the target's other 34. + * FAMILY : the x138 remap is clean and §84-safe. Every sibling is 271 ins with an IDENTICAL + * callee set; only THREE names vary per overlay — the two data labels and the jtbl: + * ov_SC01_077 D_801873FC / D_80187468 / jtbl_801D8B74 + * ov_SC03_099 D_80185A50 / D_80185ABC / jtbl_801BD898 + * ov_SC06_008 D_80187E44 / D_80187EB0 / jtbl_801A8734 + * The pair is always +0x6C apart, and NO literal in this draft encodes that distance + * (both labels are referenced by name), so there is no §84 derived-offset hazard. + * D_8011F9C4 is fleet-constant (main-EXE data) and must NOT be remapped. + * + * match_one: MATCH (271 ins) against the CURRENT tree (§87 staleness re-checked, 2026-07-27). + * PIN-FREE, zero asm, offset-pure (s32 arg0 + raw offsets) — x138 template-safe. + * Provenance: this is the Phase-26 crack (.run/phase26-cracks/func_8015B950.c) re-gated verbatim, + * with ONE deliberate change: the definition's return type void -> s32. + * - `void func_8015B950(s32 arg0)` : MATCH (271 ins) [the Phase-26 form] + * - `s32 func_8015B950(s32 arg0)` : MATCH (271 ins) [shipped — §3a-1 void->s32 is byte-neutral] + * The fleet/engine_core.h canonical decl is `extern s32 func_8015B950(void);` (engine_core.h:1852), + * and the last bank attempt (.run/bank_func_8015B950.log) died on `conflicting types for + * func_8015B950`. Shipping the s32 return kills the §73 RETURN axis for free and leaves only the + * cheap T0 PARAMS axis for the ladder (fix_header_decl.py / --fix-def-sig / cast_call_sites). + * Both forms are byte-identical, so the orchestrator may swap the return type back at zero cost. + * + * SYMBOLS (§58 rules 1/2 — all splat spellings, all verified present): + * D_80187468 asm/ov_SC01_077/data/tail.data.s:4355 (the state-handler vtable) + * D_801873FC asm/ov_SC01_077/data/tail.data.s:4293 + * D_8011F9C4 main-EXE data; spelled `extern s32 D_8011F9C4;` in 5+ already-banked TUs + * jtbl_801D8B74 asm/ov_SC01_077/data/tail14.data.s:15 (compiler jump table — not named in C) + * + * JTBL VERIFIED (§8a gate): compiled .rodata = exactly 0x1C B / 7 words, 7x R_MIPS_32 .text with + * addends [0x58,0x58,0x58,0xE0,0xF0,0x100,0x58] -> +0x8015B950 = [B9A8,B9A8,B9A8,BA30,BA40,BA50, + * B9A8] == the original words at 0x801D8B74..0x801D8B8C. Bound `sltiu $v0,$v1,0x7` matches. + * The raw dlabel's 8th word 0x00000000 is NOT an entry — it is the intra-TU `.align 3` pad of the + * B34/B54/B74 jtbl chain; the object can never emit it (maspsx drops .align), so it must stay in + * the post-carve RAW data piece (the §53/§62/§81 carve chain applies at bank time). + * + * Same family as the TU's own already-matched func_8015AE2C: 7-case switch on ((s32 (*)(s32))func_801619A4)() + * (0/1/2/6 shared, 3/4/5 own, no default block — out-of-range and every `break` fall to the + * after-switch join), then a chain of "state handler" tests, each dispatching + * D_80187468[*(u16*)arg0](arg0) and returning. + * + * THREE LEVERS (draft -> MATCH in 3 compiles): + * + * 1. PROLOGUE CONSTANT = an INITIALIZED LOCAL, not a literal in the compare. + * Target opens with `lui $s2, 0xFFF5` in the *prologue*, used once ~200 ins later in + * `slt $v0,$s2,$s1`. No gcc-2.7.2 pass hoists a (set reg const_int) across basic blocks + * (loop.c needs a loop; cse/combine/sched never move insns between BBs) — so the insn must + * have been EMITTED in the first BB, i.e. the constant is a local initialized at the top of + * the function. cse then cannot fold it back into the compare: the `slt` operand predicate is + * `arith_operand`, which rejects a CONST_INT wider than 16 bits, so validate_change fails and + * the pseudo survives. Its live range spans every call -> global.c gives it a callee-saved reg. + * Writing `z > -0xB0000` inline instead emits the `lui` into the branch delay slot next to the + * compare (caller-saved $v0) and the function is 1 insn short. => `s32 lim = -0xB0000;` at top. + * + * 2. `lh` vs `lhu`: a short->short copy is a pure HImode move and gcc emits `lhu`. The target's + * `lh $v0,0x26($s0)` means the value passed through an SImode (int) temp: expand makes + * (set (reg:SI) (sign_extend (mem:HI))) + (set (mem:HI) (subreg:HI ...)), and combine cannot + * merge them (the merged form is mem<-mem, which no movhi accepts) so the sign-extending load + * survives. => route both halfword copies through the `s32 t` temp. + * + * 3. THE `goto` LAYOUT — dodging jump.c's store-flag conversion (jump.c:1005-1065). + * An if/else chain writing 0/1 into `doit` makes gcc collapse the last pair into + * `sltiu $v0,$v0,1`. jump.c fires that conversion when the insn immediately after a + * conditional jump is a lone `SET pseudo, CONST_INT` whose following simplejump targets the + * SAME label as the branch (jump.c:1038 `reallabelprev == temp || ... JUMP_LABEL(temp4) == + * JUMP_LABEL(insn)`) — exactly the shape of `if (c) x=0; else x=1;`. + * The target instead cross-jumps ALL the `doit=0` exits into ONE shared block placed after the + * `doit=1` fall-through; reorg's fill_slots_from_thread then COPIES that single set into all + * three branch delay slots and redirects each branch past it (which is why `addu $v0,$zero, + * $zero` appears 3x in delay slots and the shared block vanishes). A `goto zero;` / `goto one;` + * chain expresses that layout directly, and each conditional jump is then followed by a + * compare/call rather than a lone const set, so the store-flag conversion never triggers. + * GENERAL RULE: multiple predicates that all assign the SAME constant to one flag => write + * them as `goto` to a shared assignment, never as an if/else ladder. + */ +extern s32 D_8011F9C4; +extern s32 D_801873FC; + +extern s32 func_80161B18(void); +extern s32 func_801619A4(s32*); +extern s32 func_80149AA8(s32*); +extern void func_80149AD4(s32*); +extern s32 func_80149B54(s32*); +extern void func_80149BAC(s32*); +extern s32 func_801498E0(s32*); +extern s32 func_80149954(s32); +extern s32 func_80149A64(s32*); +extern void func_800CCCC0(s32 a0); +extern s32 func_80149CD4(s32 a0); +extern void func_8015E880(s32*); +extern s32 func_80149744(struct S_80149744*); +extern void func_80149788(void); +extern s32 func_801496D4(void*); +extern void func_80149704(void); +extern int func_80148AFC(void*); +extern void func_80146D90(s32 a0); +extern void func_80154150(s32 a0, s32 a1); +extern void func_801541D8(u8*, s32, s32); +extern s32 func_801488A8(u8*); +extern void func_80147078(s32*, s16); +extern void func_8015A264(void*); +extern s32 func_80013294(void*, void*); +extern void func_80159B70(void*); +extern s32 func_8016F1AC(void); +extern s32 func_80029178(s32 a0); +extern void func_80146DB8(s32*, s32*); +extern s32 func_80161CD0(s32, s32); +extern s32 func_80161208(s32 a0); +extern s32 func_801725A4(u8*); + +s32 func_8015B950(s32 arg0) +{ + + extern void (*D_80187468[])(void *); + s16 sp10[4]; + s16 sp18[4]; + s32 t; + s32 z; + s32 doit; + s32 lim = -0xB0000; + + if (func_80161B18() != 0) { + return; + } + switch (((s32 (*)(s32))func_801619A4)(arg0)) { + case 0: + case 1: + case 2: + case 6: + if (((s32 (*)(s32))func_80149AA8)(arg0) != 0) { + D_80187468[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149AD4)(arg0); + return; + } + if (((s32 (*)(s32))func_80149B54)(arg0) != 0) { + D_80187468[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149BAC)(arg0); + return; + } + break; + case 3: + ((void (*)(s32))func_801498E0)(arg0); + break; + case 4: + ((void (*)(s32))func_80149954)(arg0); + break; + case 5: + if (((s32 (*)(s32))func_80149A64)(arg0) != 0) { + D_80187468[*(u16 *)arg0]((void *)arg0); + func_800CCCC0(arg0); + return; + } + break; + } + if (func_80149CD4(arg0) != 0) { + D_80187468[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_8015E880)(arg0); + return; + } + if (((s32 (*)(s32))func_80149744)(arg0) != 0) { + D_80187468[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149788)(arg0); + return; + } + if (((s32 (*)(s32))func_801496D4)(arg0) != 0) { + D_80187468[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149704)(arg0); + if (((u8)((s32 (*)(s32))func_80148AFC)(arg0)) == 0) { + func_80146D90(arg0); + } + if ((*(s32 *)(arg0 + 0x24) | *(s32 *)(arg0 + 0x2C)) != 0) { + func_80154150(arg0, 0xF); + } else { + ((void (*)(s32, s32, s32))func_801541D8)(arg0, 0xD, 6); + } + *(s32 *)(arg0 + 0x238) = 1; + return; + } + if (((s32 (*)(s32))func_801488A8)(arg0) != 0) { + sp10[0] = 0; + sp10[1] = 0; + sp10[2] = 0; + t = *(s16 *)(arg0 + 0x26); + sp18[0] = t; + sp18[1] = 0; + t = *(s16 *)(arg0 + 0x2E); + sp18[2] = t; + D_80187468[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 1); + ((void (*)(s32))func_8015A264)(arg0); + t = -(((s32 (*)(s16 *, s16 *))func_80013294)(sp10, sp18) << 0x10); + if (t < *(s32 *)(arg0 + 0x2C)) { + *(s32 *)(arg0 + 0x2C) = t; + } + return; + } + if (*(u16 *)(arg0 + 0xB8) == 0x8000) { + D_80187468[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 0); + ((void (*)(s32))func_80159B70)(arg0); + return; + } + z = *(s32 *)(arg0 + 0x2C); + if (func_8016F1AC() != 0) { + goto zero; + } + if (z <= lim) { + goto one; + } + if (D_8011F9C4 == 0) { + goto zero; + } + if (((u8)func_80029178(0x21)) != 0) { + goto zero; + } +one: + doit = 1; + goto join; +zero: + doit = 0; +join: + if (doit != 0) { + D_80187468[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 0); + ((void (*)(s32))func_80159B70)(arg0); + func_80154150(arg0, 9); + ((void (*)(s32, s32 *))func_80146DB8)(arg0, &D_801873FC); + ((void (*)(s32, s32))func_80161CD0)(arg0, *(u16 *)(arg0 + 0x16E)); + return; + } + if (func_80161208(arg0) == 0) { + ((void (*)(s32))func_801725A4)(arg0); + } +} DEFINE_func_8015BD8C() /* dedup: shared engine-core @0x8015BD8C (src/shared) */ diff --git a/src/ov_SC03_001/ov_SC03_001_jr_8015AE2C.c b/src/ov_SC03_001/ov_SC03_001_jr_8015AE2C.c index 202a38501..69c280b61 100644 --- a/src/ov_SC03_001/ov_SC03_001_jr_8015AE2C.c +++ b/src/ov_SC03_001/ov_SC03_001_jr_8015AE2C.c @@ -1513,7 +1513,259 @@ DEFINE_func_8015B858() /* dedup: shared engine-core @0x8015B858 (src/shared) */ DEFINE_func_8015B8F8() /* dedup: shared engine-core @0x8015B8F8 (src/shared) */ -INCLUDE_ASM("asm/ov_SC03_001/nonmatchings/ov_SC03_001_jr_8015AE2C", func_8015B950); +extern s32 func_8015AE2C(); + +// @class: plumbing +// @stuck: none — MATCH (271/271, pin-free, zero asm). The ONLY residual is DEF-SIDE plumbing, and it is now named exactly: the in-TU instantiation `DEFINE_func_8015BEE4()` (engine_core.h:1851-1855) expands to `extern s32 func_8015B950(void);` INSIDE ov_SC01_077_jr_8015AE2C.c, ~14 lines BELOW this definition, so the 1-param def collides with a `(void)` prototype -> `conflicting types for func_8015B950` (.run/bank_func_8015B950.log). §73 PARAMS axis / T0. Surgical fix = §65b de-macroize that ONE instantiation (blast radius: this TU); the fleet-wide `(void)`->`()` header edit is §63 and must be R22-validated. +/* func_8015B950 (ov_SC01_077_jr_8015AE2C, 271 ins, jtbl_801D8B74) — SESSION-21 re-verified + * + * ── ROUND-2 INDEPENDENT RE-VERIFICATION (2026-07-27, fresh agent, §88e discipline) ───────────── + * match_one : MATCH (271 ins) against the CURRENT tree — §87 staleness re-checked today. + * .text size: compiled .text = 0x43C = 1084 B = 271 ins, EXACTLY the target's declared 0x43C + * ("nonmatching func_8015B950, 0x43C"). So this is NOT a §83a length drift hiding + * behind a zero count — the count is over equal-length streams. + * jtbl : RE-DECODED MECHANICALLY, not inherited. Compiled .rodata = 0x1C = 28 B = 7 words, + * 7x R_MIPS_32 -> .text with implicit addends [58,58,58,E0,F0,100,58]; +0x8015B950 + * = [8015B9A8, 8015B9A8, 8015B9A8, 8015BA30, 8015BA40, 8015BA50, 8015B9A8]. + * Diffed word-for-word against asm/ov_SC01_077/data/tail14.data.s:15-23 — 7/7 identical. + * symcheck : SYMS-DIFF target=35 draft=34, sole MISSING = jtbl_801D8B74. This is the §81 jr + * FALSE POSITIVE, re-confirmed here by reading the relocs: gcc emits its OWN table and + * references it with R_MIPS_HI16/LO16 against the SECTION `.rodata` (t.o +0x40/+0x48), + * so the splat's dlabel NAME can never appear in the draft object's relocation set. + * Nothing is dropped and nothing is invented: the draft's other 34 symbols are exactly + * the target's other 34. + * FAMILY : the x138 remap is clean and §84-safe. Every sibling is 271 ins with an IDENTICAL + * callee set; only THREE names vary per overlay — the two data labels and the jtbl: + * ov_SC01_077 D_8018FB3C / D_8018FBA8 / jtbl_801D8B74 + * ov_SC03_099 D_80185A50 / D_80185ABC / jtbl_801BD898 + * ov_SC06_008 D_80187E44 / D_80187EB0 / jtbl_801A8734 + * The pair is always +0x6C apart, and NO literal in this draft encodes that distance + * (both labels are referenced by name), so there is no §84 derived-offset hazard. + * D_8011F9C4 is fleet-constant (main-EXE data) and must NOT be remapped. + * + * match_one: MATCH (271 ins) against the CURRENT tree (§87 staleness re-checked, 2026-07-27). + * PIN-FREE, zero asm, offset-pure (s32 arg0 + raw offsets) — x138 template-safe. + * Provenance: this is the Phase-26 crack (.run/phase26-cracks/func_8015B950.c) re-gated verbatim, + * with ONE deliberate change: the definition's return type void -> s32. + * - `void func_8015B950(s32 arg0)` : MATCH (271 ins) [the Phase-26 form] + * - `s32 func_8015B950(s32 arg0)` : MATCH (271 ins) [shipped — §3a-1 void->s32 is byte-neutral] + * The fleet/engine_core.h canonical decl is `extern s32 func_8015B950(void);` (engine_core.h:1852), + * and the last bank attempt (.run/bank_func_8015B950.log) died on `conflicting types for + * func_8015B950`. Shipping the s32 return kills the §73 RETURN axis for free and leaves only the + * cheap T0 PARAMS axis for the ladder (fix_header_decl.py / --fix-def-sig / cast_call_sites). + * Both forms are byte-identical, so the orchestrator may swap the return type back at zero cost. + * + * SYMBOLS (§58 rules 1/2 — all splat spellings, all verified present): + * D_8018FBA8 asm/ov_SC01_077/data/tail.data.s:4355 (the state-handler vtable) + * D_8018FB3C asm/ov_SC01_077/data/tail.data.s:4293 + * D_8011F9C4 main-EXE data; spelled `extern s32 D_8011F9C4;` in 5+ already-banked TUs + * jtbl_801D8B74 asm/ov_SC01_077/data/tail14.data.s:15 (compiler jump table — not named in C) + * + * JTBL VERIFIED (§8a gate): compiled .rodata = exactly 0x1C B / 7 words, 7x R_MIPS_32 .text with + * addends [0x58,0x58,0x58,0xE0,0xF0,0x100,0x58] -> +0x8015B950 = [B9A8,B9A8,B9A8,BA30,BA40,BA50, + * B9A8] == the original words at 0x801D8B74..0x801D8B8C. Bound `sltiu $v0,$v1,0x7` matches. + * The raw dlabel's 8th word 0x00000000 is NOT an entry — it is the intra-TU `.align 3` pad of the + * B34/B54/B74 jtbl chain; the object can never emit it (maspsx drops .align), so it must stay in + * the post-carve RAW data piece (the §53/§62/§81 carve chain applies at bank time). + * + * Same family as the TU's own already-matched func_8015AE2C: 7-case switch on ((s32 (*)(s32))func_801619A4)() + * (0/1/2/6 shared, 3/4/5 own, no default block — out-of-range and every `break` fall to the + * after-switch join), then a chain of "state handler" tests, each dispatching + * D_8018FBA8[*(u16*)arg0](arg0) and returning. + * + * THREE LEVERS (draft -> MATCH in 3 compiles): + * + * 1. PROLOGUE CONSTANT = an INITIALIZED LOCAL, not a literal in the compare. + * Target opens with `lui $s2, 0xFFF5` in the *prologue*, used once ~200 ins later in + * `slt $v0,$s2,$s1`. No gcc-2.7.2 pass hoists a (set reg const_int) across basic blocks + * (loop.c needs a loop; cse/combine/sched never move insns between BBs) — so the insn must + * have been EMITTED in the first BB, i.e. the constant is a local initialized at the top of + * the function. cse then cannot fold it back into the compare: the `slt` operand predicate is + * `arith_operand`, which rejects a CONST_INT wider than 16 bits, so validate_change fails and + * the pseudo survives. Its live range spans every call -> global.c gives it a callee-saved reg. + * Writing `z > -0xB0000` inline instead emits the `lui` into the branch delay slot next to the + * compare (caller-saved $v0) and the function is 1 insn short. => `s32 lim = -0xB0000;` at top. + * + * 2. `lh` vs `lhu`: a short->short copy is a pure HImode move and gcc emits `lhu`. The target's + * `lh $v0,0x26($s0)` means the value passed through an SImode (int) temp: expand makes + * (set (reg:SI) (sign_extend (mem:HI))) + (set (mem:HI) (subreg:HI ...)), and combine cannot + * merge them (the merged form is mem<-mem, which no movhi accepts) so the sign-extending load + * survives. => route both halfword copies through the `s32 t` temp. + * + * 3. THE `goto` LAYOUT — dodging jump.c's store-flag conversion (jump.c:1005-1065). + * An if/else chain writing 0/1 into `doit` makes gcc collapse the last pair into + * `sltiu $v0,$v0,1`. jump.c fires that conversion when the insn immediately after a + * conditional jump is a lone `SET pseudo, CONST_INT` whose following simplejump targets the + * SAME label as the branch (jump.c:1038 `reallabelprev == temp || ... JUMP_LABEL(temp4) == + * JUMP_LABEL(insn)`) — exactly the shape of `if (c) x=0; else x=1;`. + * The target instead cross-jumps ALL the `doit=0` exits into ONE shared block placed after the + * `doit=1` fall-through; reorg's fill_slots_from_thread then COPIES that single set into all + * three branch delay slots and redirects each branch past it (which is why `addu $v0,$zero, + * $zero` appears 3x in delay slots and the shared block vanishes). A `goto zero;` / `goto one;` + * chain expresses that layout directly, and each conditional jump is then followed by a + * compare/call rather than a lone const set, so the store-flag conversion never triggers. + * GENERAL RULE: multiple predicates that all assign the SAME constant to one flag => write + * them as `goto` to a shared assignment, never as an if/else ladder. + */ +extern s32 D_8011F9C4; +extern s32 D_8018FB3C; + +extern s32 func_80161B18(void); +extern s32 func_801619A4(s32*); +extern s32 func_80149AA8(s32*); +extern void func_80149AD4(s32*); +extern s32 func_80149B54(s32*); +extern void func_80149BAC(s32*); +extern s32 func_801498E0(s32*); +extern s32 func_80149954(s32); +extern s32 func_80149A64(s32*); +extern void func_800CCCC0(s32 a0); +extern s32 func_80149CD4(s32 a0); +extern void func_8015E880(s32*); +extern s32 func_80149744(struct S_80149744*); +extern void func_80149788(void); +extern s32 func_801496D4(void*); +extern void func_80149704(void); +extern int func_80148AFC(void*); +extern void func_80146D90(s32 a0); +extern void func_80154150(s32 a0, s32 a1); +extern void func_801541D8(u8*, s32, s32); +extern s32 func_801488A8(u8*); +extern void func_80147078(s32*, s16); +extern void func_8015A264(void*); +extern s32 func_80013294(void*, void*); +extern void func_80159B70(void*); +extern s32 func_8016F1AC(void); +extern s32 func_80029178(s32 a0); +extern void func_80146DB8(s32*, s32*); +extern s32 func_80161CD0(s32, s32); +extern s32 func_80161208(s32 a0); +extern s32 func_801725A4(u8*); + +s32 func_8015B950(s32 arg0) +{ + + extern void (*D_8018FBA8[])(void *); + s16 sp10[4]; + s16 sp18[4]; + s32 t; + s32 z; + s32 doit; + s32 lim = -0xB0000; + + if (func_80161B18() != 0) { + return; + } + switch (((s32 (*)(s32))func_801619A4)(arg0)) { + case 0: + case 1: + case 2: + case 6: + if (((s32 (*)(s32))func_80149AA8)(arg0) != 0) { + D_8018FBA8[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149AD4)(arg0); + return; + } + if (((s32 (*)(s32))func_80149B54)(arg0) != 0) { + D_8018FBA8[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149BAC)(arg0); + return; + } + break; + case 3: + ((void (*)(s32))func_801498E0)(arg0); + break; + case 4: + ((void (*)(s32))func_80149954)(arg0); + break; + case 5: + if (((s32 (*)(s32))func_80149A64)(arg0) != 0) { + D_8018FBA8[*(u16 *)arg0]((void *)arg0); + func_800CCCC0(arg0); + return; + } + break; + } + if (func_80149CD4(arg0) != 0) { + D_8018FBA8[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_8015E880)(arg0); + return; + } + if (((s32 (*)(s32))func_80149744)(arg0) != 0) { + D_8018FBA8[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149788)(arg0); + return; + } + if (((s32 (*)(s32))func_801496D4)(arg0) != 0) { + D_8018FBA8[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149704)(arg0); + if (((u8)((s32 (*)(s32))func_80148AFC)(arg0)) == 0) { + func_80146D90(arg0); + } + if ((*(s32 *)(arg0 + 0x24) | *(s32 *)(arg0 + 0x2C)) != 0) { + func_80154150(arg0, 0xF); + } else { + ((void (*)(s32, s32, s32))func_801541D8)(arg0, 0xD, 6); + } + *(s32 *)(arg0 + 0x238) = 1; + return; + } + if (((s32 (*)(s32))func_801488A8)(arg0) != 0) { + sp10[0] = 0; + sp10[1] = 0; + sp10[2] = 0; + t = *(s16 *)(arg0 + 0x26); + sp18[0] = t; + sp18[1] = 0; + t = *(s16 *)(arg0 + 0x2E); + sp18[2] = t; + D_8018FBA8[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 1); + ((void (*)(s32))func_8015A264)(arg0); + t = -(((s32 (*)(s16 *, s16 *))func_80013294)(sp10, sp18) << 0x10); + if (t < *(s32 *)(arg0 + 0x2C)) { + *(s32 *)(arg0 + 0x2C) = t; + } + return; + } + if (*(u16 *)(arg0 + 0xB8) == 0x8000) { + D_8018FBA8[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 0); + ((void (*)(s32))func_80159B70)(arg0); + return; + } + z = *(s32 *)(arg0 + 0x2C); + if (func_8016F1AC() != 0) { + goto zero; + } + if (z <= lim) { + goto one; + } + if (D_8011F9C4 == 0) { + goto zero; + } + if (((u8)func_80029178(0x21)) != 0) { + goto zero; + } +one: + doit = 1; + goto join; +zero: + doit = 0; +join: + if (doit != 0) { + D_8018FBA8[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 0); + ((void (*)(s32))func_80159B70)(arg0); + func_80154150(arg0, 9); + ((void (*)(s32, s32 *))func_80146DB8)(arg0, &D_8018FB3C); + ((void (*)(s32, s32))func_80161CD0)(arg0, *(u16 *)(arg0 + 0x16E)); + return; + } + if (func_80161208(arg0) == 0) { + ((void (*)(s32))func_801725A4)(arg0); + } +} DEFINE_func_8015BD8C() /* dedup: shared engine-core @0x8015BD8C (src/shared) */ diff --git a/src/ov_SC03_002/ov_SC03_002_jr_8015AE2C.c b/src/ov_SC03_002/ov_SC03_002_jr_8015AE2C.c index f1de1dd93..f3dfe708b 100644 --- a/src/ov_SC03_002/ov_SC03_002_jr_8015AE2C.c +++ b/src/ov_SC03_002/ov_SC03_002_jr_8015AE2C.c @@ -1513,7 +1513,259 @@ DEFINE_func_8015B858() /* dedup: shared engine-core @0x8015B858 (src/shared) */ DEFINE_func_8015B8F8() /* dedup: shared engine-core @0x8015B8F8 (src/shared) */ -INCLUDE_ASM("asm/ov_SC03_002/nonmatchings/ov_SC03_002_jr_8015AE2C", func_8015B950); +extern s32 func_8015AE2C(); + +// @class: plumbing +// @stuck: none — MATCH (271/271, pin-free, zero asm). The ONLY residual is DEF-SIDE plumbing, and it is now named exactly: the in-TU instantiation `DEFINE_func_8015BEE4()` (engine_core.h:1851-1855) expands to `extern s32 func_8015B950(void);` INSIDE ov_SC01_077_jr_8015AE2C.c, ~14 lines BELOW this definition, so the 1-param def collides with a `(void)` prototype -> `conflicting types for func_8015B950` (.run/bank_func_8015B950.log). §73 PARAMS axis / T0. Surgical fix = §65b de-macroize that ONE instantiation (blast radius: this TU); the fleet-wide `(void)`->`()` header edit is §63 and must be R22-validated. +/* func_8015B950 (ov_SC01_077_jr_8015AE2C, 271 ins, jtbl_801D8B74) — SESSION-21 re-verified + * + * ── ROUND-2 INDEPENDENT RE-VERIFICATION (2026-07-27, fresh agent, §88e discipline) ───────────── + * match_one : MATCH (271 ins) against the CURRENT tree — §87 staleness re-checked today. + * .text size: compiled .text = 0x43C = 1084 B = 271 ins, EXACTLY the target's declared 0x43C + * ("nonmatching func_8015B950, 0x43C"). So this is NOT a §83a length drift hiding + * behind a zero count — the count is over equal-length streams. + * jtbl : RE-DECODED MECHANICALLY, not inherited. Compiled .rodata = 0x1C = 28 B = 7 words, + * 7x R_MIPS_32 -> .text with implicit addends [58,58,58,E0,F0,100,58]; +0x8015B950 + * = [8015B9A8, 8015B9A8, 8015B9A8, 8015BA30, 8015BA40, 8015BA50, 8015B9A8]. + * Diffed word-for-word against asm/ov_SC01_077/data/tail14.data.s:15-23 — 7/7 identical. + * symcheck : SYMS-DIFF target=35 draft=34, sole MISSING = jtbl_801D8B74. This is the §81 jr + * FALSE POSITIVE, re-confirmed here by reading the relocs: gcc emits its OWN table and + * references it with R_MIPS_HI16/LO16 against the SECTION `.rodata` (t.o +0x40/+0x48), + * so the splat's dlabel NAME can never appear in the draft object's relocation set. + * Nothing is dropped and nothing is invented: the draft's other 34 symbols are exactly + * the target's other 34. + * FAMILY : the x138 remap is clean and §84-safe. Every sibling is 271 ins with an IDENTICAL + * callee set; only THREE names vary per overlay — the two data labels and the jtbl: + * ov_SC01_077 D_80187B2C / D_80187B98 / jtbl_801D8B74 + * ov_SC03_099 D_80185A50 / D_80185ABC / jtbl_801BD898 + * ov_SC06_008 D_80187E44 / D_80187EB0 / jtbl_801A8734 + * The pair is always +0x6C apart, and NO literal in this draft encodes that distance + * (both labels are referenced by name), so there is no §84 derived-offset hazard. + * D_8011F9C4 is fleet-constant (main-EXE data) and must NOT be remapped. + * + * match_one: MATCH (271 ins) against the CURRENT tree (§87 staleness re-checked, 2026-07-27). + * PIN-FREE, zero asm, offset-pure (s32 arg0 + raw offsets) — x138 template-safe. + * Provenance: this is the Phase-26 crack (.run/phase26-cracks/func_8015B950.c) re-gated verbatim, + * with ONE deliberate change: the definition's return type void -> s32. + * - `void func_8015B950(s32 arg0)` : MATCH (271 ins) [the Phase-26 form] + * - `s32 func_8015B950(s32 arg0)` : MATCH (271 ins) [shipped — §3a-1 void->s32 is byte-neutral] + * The fleet/engine_core.h canonical decl is `extern s32 func_8015B950(void);` (engine_core.h:1852), + * and the last bank attempt (.run/bank_func_8015B950.log) died on `conflicting types for + * func_8015B950`. Shipping the s32 return kills the §73 RETURN axis for free and leaves only the + * cheap T0 PARAMS axis for the ladder (fix_header_decl.py / --fix-def-sig / cast_call_sites). + * Both forms are byte-identical, so the orchestrator may swap the return type back at zero cost. + * + * SYMBOLS (§58 rules 1/2 — all splat spellings, all verified present): + * D_80187B98 asm/ov_SC01_077/data/tail.data.s:4355 (the state-handler vtable) + * D_80187B2C asm/ov_SC01_077/data/tail.data.s:4293 + * D_8011F9C4 main-EXE data; spelled `extern s32 D_8011F9C4;` in 5+ already-banked TUs + * jtbl_801D8B74 asm/ov_SC01_077/data/tail14.data.s:15 (compiler jump table — not named in C) + * + * JTBL VERIFIED (§8a gate): compiled .rodata = exactly 0x1C B / 7 words, 7x R_MIPS_32 .text with + * addends [0x58,0x58,0x58,0xE0,0xF0,0x100,0x58] -> +0x8015B950 = [B9A8,B9A8,B9A8,BA30,BA40,BA50, + * B9A8] == the original words at 0x801D8B74..0x801D8B8C. Bound `sltiu $v0,$v1,0x7` matches. + * The raw dlabel's 8th word 0x00000000 is NOT an entry — it is the intra-TU `.align 3` pad of the + * B34/B54/B74 jtbl chain; the object can never emit it (maspsx drops .align), so it must stay in + * the post-carve RAW data piece (the §53/§62/§81 carve chain applies at bank time). + * + * Same family as the TU's own already-matched func_8015AE2C: 7-case switch on ((s32 (*)(s32))func_801619A4)() + * (0/1/2/6 shared, 3/4/5 own, no default block — out-of-range and every `break` fall to the + * after-switch join), then a chain of "state handler" tests, each dispatching + * D_80187B98[*(u16*)arg0](arg0) and returning. + * + * THREE LEVERS (draft -> MATCH in 3 compiles): + * + * 1. PROLOGUE CONSTANT = an INITIALIZED LOCAL, not a literal in the compare. + * Target opens with `lui $s2, 0xFFF5` in the *prologue*, used once ~200 ins later in + * `slt $v0,$s2,$s1`. No gcc-2.7.2 pass hoists a (set reg const_int) across basic blocks + * (loop.c needs a loop; cse/combine/sched never move insns between BBs) — so the insn must + * have been EMITTED in the first BB, i.e. the constant is a local initialized at the top of + * the function. cse then cannot fold it back into the compare: the `slt` operand predicate is + * `arith_operand`, which rejects a CONST_INT wider than 16 bits, so validate_change fails and + * the pseudo survives. Its live range spans every call -> global.c gives it a callee-saved reg. + * Writing `z > -0xB0000` inline instead emits the `lui` into the branch delay slot next to the + * compare (caller-saved $v0) and the function is 1 insn short. => `s32 lim = -0xB0000;` at top. + * + * 2. `lh` vs `lhu`: a short->short copy is a pure HImode move and gcc emits `lhu`. The target's + * `lh $v0,0x26($s0)` means the value passed through an SImode (int) temp: expand makes + * (set (reg:SI) (sign_extend (mem:HI))) + (set (mem:HI) (subreg:HI ...)), and combine cannot + * merge them (the merged form is mem<-mem, which no movhi accepts) so the sign-extending load + * survives. => route both halfword copies through the `s32 t` temp. + * + * 3. THE `goto` LAYOUT — dodging jump.c's store-flag conversion (jump.c:1005-1065). + * An if/else chain writing 0/1 into `doit` makes gcc collapse the last pair into + * `sltiu $v0,$v0,1`. jump.c fires that conversion when the insn immediately after a + * conditional jump is a lone `SET pseudo, CONST_INT` whose following simplejump targets the + * SAME label as the branch (jump.c:1038 `reallabelprev == temp || ... JUMP_LABEL(temp4) == + * JUMP_LABEL(insn)`) — exactly the shape of `if (c) x=0; else x=1;`. + * The target instead cross-jumps ALL the `doit=0` exits into ONE shared block placed after the + * `doit=1` fall-through; reorg's fill_slots_from_thread then COPIES that single set into all + * three branch delay slots and redirects each branch past it (which is why `addu $v0,$zero, + * $zero` appears 3x in delay slots and the shared block vanishes). A `goto zero;` / `goto one;` + * chain expresses that layout directly, and each conditional jump is then followed by a + * compare/call rather than a lone const set, so the store-flag conversion never triggers. + * GENERAL RULE: multiple predicates that all assign the SAME constant to one flag => write + * them as `goto` to a shared assignment, never as an if/else ladder. + */ +extern s32 D_8011F9C4; +extern s32 D_80187B2C; + +extern s32 func_80161B18(void); +extern s32 func_801619A4(s32*); +extern s32 func_80149AA8(s32*); +extern void func_80149AD4(s32*); +extern s32 func_80149B54(s32*); +extern void func_80149BAC(s32*); +extern s32 func_801498E0(s32*); +extern s32 func_80149954(s32); +extern s32 func_80149A64(s32*); +extern void func_800CCCC0(s32 a0); +extern s32 func_80149CD4(s32 a0); +extern void func_8015E880(s32*); +extern s32 func_80149744(struct S_80149744*); +extern void func_80149788(void); +extern s32 func_801496D4(void*); +extern void func_80149704(void); +extern int func_80148AFC(void*); +extern void func_80146D90(s32 a0); +extern void func_80154150(s32 a0, s32 a1); +extern void func_801541D8(u8*, s32, s32); +extern s32 func_801488A8(u8*); +extern void func_80147078(s32*, s16); +extern void func_8015A264(void*); +extern s32 func_80013294(void*, void*); +extern void func_80159B70(void*); +extern s32 func_8016F1AC(void); +extern s32 func_80029178(s32 a0); +extern void func_80146DB8(s32*, s32*); +extern s32 func_80161CD0(s32, s32); +extern s32 func_80161208(s32 a0); +extern s32 func_801725A4(u8*); + +s32 func_8015B950(s32 arg0) +{ + + extern void (*D_80187B98[])(void *); + s16 sp10[4]; + s16 sp18[4]; + s32 t; + s32 z; + s32 doit; + s32 lim = -0xB0000; + + if (func_80161B18() != 0) { + return; + } + switch (((s32 (*)(s32))func_801619A4)(arg0)) { + case 0: + case 1: + case 2: + case 6: + if (((s32 (*)(s32))func_80149AA8)(arg0) != 0) { + D_80187B98[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149AD4)(arg0); + return; + } + if (((s32 (*)(s32))func_80149B54)(arg0) != 0) { + D_80187B98[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149BAC)(arg0); + return; + } + break; + case 3: + ((void (*)(s32))func_801498E0)(arg0); + break; + case 4: + ((void (*)(s32))func_80149954)(arg0); + break; + case 5: + if (((s32 (*)(s32))func_80149A64)(arg0) != 0) { + D_80187B98[*(u16 *)arg0]((void *)arg0); + func_800CCCC0(arg0); + return; + } + break; + } + if (func_80149CD4(arg0) != 0) { + D_80187B98[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_8015E880)(arg0); + return; + } + if (((s32 (*)(s32))func_80149744)(arg0) != 0) { + D_80187B98[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149788)(arg0); + return; + } + if (((s32 (*)(s32))func_801496D4)(arg0) != 0) { + D_80187B98[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149704)(arg0); + if (((u8)((s32 (*)(s32))func_80148AFC)(arg0)) == 0) { + func_80146D90(arg0); + } + if ((*(s32 *)(arg0 + 0x24) | *(s32 *)(arg0 + 0x2C)) != 0) { + func_80154150(arg0, 0xF); + } else { + ((void (*)(s32, s32, s32))func_801541D8)(arg0, 0xD, 6); + } + *(s32 *)(arg0 + 0x238) = 1; + return; + } + if (((s32 (*)(s32))func_801488A8)(arg0) != 0) { + sp10[0] = 0; + sp10[1] = 0; + sp10[2] = 0; + t = *(s16 *)(arg0 + 0x26); + sp18[0] = t; + sp18[1] = 0; + t = *(s16 *)(arg0 + 0x2E); + sp18[2] = t; + D_80187B98[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 1); + ((void (*)(s32))func_8015A264)(arg0); + t = -(((s32 (*)(s16 *, s16 *))func_80013294)(sp10, sp18) << 0x10); + if (t < *(s32 *)(arg0 + 0x2C)) { + *(s32 *)(arg0 + 0x2C) = t; + } + return; + } + if (*(u16 *)(arg0 + 0xB8) == 0x8000) { + D_80187B98[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 0); + ((void (*)(s32))func_80159B70)(arg0); + return; + } + z = *(s32 *)(arg0 + 0x2C); + if (func_8016F1AC() != 0) { + goto zero; + } + if (z <= lim) { + goto one; + } + if (D_8011F9C4 == 0) { + goto zero; + } + if (((u8)func_80029178(0x21)) != 0) { + goto zero; + } +one: + doit = 1; + goto join; +zero: + doit = 0; +join: + if (doit != 0) { + D_80187B98[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 0); + ((void (*)(s32))func_80159B70)(arg0); + func_80154150(arg0, 9); + ((void (*)(s32, s32 *))func_80146DB8)(arg0, &D_80187B2C); + ((void (*)(s32, s32))func_80161CD0)(arg0, *(u16 *)(arg0 + 0x16E)); + return; + } + if (func_80161208(arg0) == 0) { + ((void (*)(s32))func_801725A4)(arg0); + } +} DEFINE_func_8015BD8C() /* dedup: shared engine-core @0x8015BD8C (src/shared) */ diff --git a/src/ov_SC03_003/ov_SC03_003_jr_8015AE2C.c b/src/ov_SC03_003/ov_SC03_003_jr_8015AE2C.c index 675d36a65..73e5f3f29 100644 --- a/src/ov_SC03_003/ov_SC03_003_jr_8015AE2C.c +++ b/src/ov_SC03_003/ov_SC03_003_jr_8015AE2C.c @@ -1513,7 +1513,259 @@ DEFINE_func_8015B858() /* dedup: shared engine-core @0x8015B858 (src/shared) */ DEFINE_func_8015B8F8() /* dedup: shared engine-core @0x8015B8F8 (src/shared) */ -INCLUDE_ASM("asm/ov_SC03_003/nonmatchings/ov_SC03_003_jr_8015AE2C", func_8015B950); +extern s32 func_8015AE2C(); + +// @class: plumbing +// @stuck: none — MATCH (271/271, pin-free, zero asm). The ONLY residual is DEF-SIDE plumbing, and it is now named exactly: the in-TU instantiation `DEFINE_func_8015BEE4()` (engine_core.h:1851-1855) expands to `extern s32 func_8015B950(void);` INSIDE ov_SC01_077_jr_8015AE2C.c, ~14 lines BELOW this definition, so the 1-param def collides with a `(void)` prototype -> `conflicting types for func_8015B950` (.run/bank_func_8015B950.log). §73 PARAMS axis / T0. Surgical fix = §65b de-macroize that ONE instantiation (blast radius: this TU); the fleet-wide `(void)`->`()` header edit is §63 and must be R22-validated. +/* func_8015B950 (ov_SC01_077_jr_8015AE2C, 271 ins, jtbl_801D8B74) — SESSION-21 re-verified + * + * ── ROUND-2 INDEPENDENT RE-VERIFICATION (2026-07-27, fresh agent, §88e discipline) ───────────── + * match_one : MATCH (271 ins) against the CURRENT tree — §87 staleness re-checked today. + * .text size: compiled .text = 0x43C = 1084 B = 271 ins, EXACTLY the target's declared 0x43C + * ("nonmatching func_8015B950, 0x43C"). So this is NOT a §83a length drift hiding + * behind a zero count — the count is over equal-length streams. + * jtbl : RE-DECODED MECHANICALLY, not inherited. Compiled .rodata = 0x1C = 28 B = 7 words, + * 7x R_MIPS_32 -> .text with implicit addends [58,58,58,E0,F0,100,58]; +0x8015B950 + * = [8015B9A8, 8015B9A8, 8015B9A8, 8015BA30, 8015BA40, 8015BA50, 8015B9A8]. + * Diffed word-for-word against asm/ov_SC01_077/data/tail14.data.s:15-23 — 7/7 identical. + * symcheck : SYMS-DIFF target=35 draft=34, sole MISSING = jtbl_801D8B74. This is the §81 jr + * FALSE POSITIVE, re-confirmed here by reading the relocs: gcc emits its OWN table and + * references it with R_MIPS_HI16/LO16 against the SECTION `.rodata` (t.o +0x40/+0x48), + * so the splat's dlabel NAME can never appear in the draft object's relocation set. + * Nothing is dropped and nothing is invented: the draft's other 34 symbols are exactly + * the target's other 34. + * FAMILY : the x138 remap is clean and §84-safe. Every sibling is 271 ins with an IDENTICAL + * callee set; only THREE names vary per overlay — the two data labels and the jtbl: + * ov_SC01_077 D_801818F4 / D_80181960 / jtbl_801D8B74 + * ov_SC03_099 D_80185A50 / D_80185ABC / jtbl_801BD898 + * ov_SC06_008 D_80187E44 / D_80187EB0 / jtbl_801A8734 + * The pair is always +0x6C apart, and NO literal in this draft encodes that distance + * (both labels are referenced by name), so there is no §84 derived-offset hazard. + * D_8011F9C4 is fleet-constant (main-EXE data) and must NOT be remapped. + * + * match_one: MATCH (271 ins) against the CURRENT tree (§87 staleness re-checked, 2026-07-27). + * PIN-FREE, zero asm, offset-pure (s32 arg0 + raw offsets) — x138 template-safe. + * Provenance: this is the Phase-26 crack (.run/phase26-cracks/func_8015B950.c) re-gated verbatim, + * with ONE deliberate change: the definition's return type void -> s32. + * - `void func_8015B950(s32 arg0)` : MATCH (271 ins) [the Phase-26 form] + * - `s32 func_8015B950(s32 arg0)` : MATCH (271 ins) [shipped — §3a-1 void->s32 is byte-neutral] + * The fleet/engine_core.h canonical decl is `extern s32 func_8015B950(void);` (engine_core.h:1852), + * and the last bank attempt (.run/bank_func_8015B950.log) died on `conflicting types for + * func_8015B950`. Shipping the s32 return kills the §73 RETURN axis for free and leaves only the + * cheap T0 PARAMS axis for the ladder (fix_header_decl.py / --fix-def-sig / cast_call_sites). + * Both forms are byte-identical, so the orchestrator may swap the return type back at zero cost. + * + * SYMBOLS (§58 rules 1/2 — all splat spellings, all verified present): + * D_80181960 asm/ov_SC01_077/data/tail.data.s:4355 (the state-handler vtable) + * D_801818F4 asm/ov_SC01_077/data/tail.data.s:4293 + * D_8011F9C4 main-EXE data; spelled `extern s32 D_8011F9C4;` in 5+ already-banked TUs + * jtbl_801D8B74 asm/ov_SC01_077/data/tail14.data.s:15 (compiler jump table — not named in C) + * + * JTBL VERIFIED (§8a gate): compiled .rodata = exactly 0x1C B / 7 words, 7x R_MIPS_32 .text with + * addends [0x58,0x58,0x58,0xE0,0xF0,0x100,0x58] -> +0x8015B950 = [B9A8,B9A8,B9A8,BA30,BA40,BA50, + * B9A8] == the original words at 0x801D8B74..0x801D8B8C. Bound `sltiu $v0,$v1,0x7` matches. + * The raw dlabel's 8th word 0x00000000 is NOT an entry — it is the intra-TU `.align 3` pad of the + * B34/B54/B74 jtbl chain; the object can never emit it (maspsx drops .align), so it must stay in + * the post-carve RAW data piece (the §53/§62/§81 carve chain applies at bank time). + * + * Same family as the TU's own already-matched func_8015AE2C: 7-case switch on ((s32 (*)(s32))func_801619A4)() + * (0/1/2/6 shared, 3/4/5 own, no default block — out-of-range and every `break` fall to the + * after-switch join), then a chain of "state handler" tests, each dispatching + * D_80181960[*(u16*)arg0](arg0) and returning. + * + * THREE LEVERS (draft -> MATCH in 3 compiles): + * + * 1. PROLOGUE CONSTANT = an INITIALIZED LOCAL, not a literal in the compare. + * Target opens with `lui $s2, 0xFFF5` in the *prologue*, used once ~200 ins later in + * `slt $v0,$s2,$s1`. No gcc-2.7.2 pass hoists a (set reg const_int) across basic blocks + * (loop.c needs a loop; cse/combine/sched never move insns between BBs) — so the insn must + * have been EMITTED in the first BB, i.e. the constant is a local initialized at the top of + * the function. cse then cannot fold it back into the compare: the `slt` operand predicate is + * `arith_operand`, which rejects a CONST_INT wider than 16 bits, so validate_change fails and + * the pseudo survives. Its live range spans every call -> global.c gives it a callee-saved reg. + * Writing `z > -0xB0000` inline instead emits the `lui` into the branch delay slot next to the + * compare (caller-saved $v0) and the function is 1 insn short. => `s32 lim = -0xB0000;` at top. + * + * 2. `lh` vs `lhu`: a short->short copy is a pure HImode move and gcc emits `lhu`. The target's + * `lh $v0,0x26($s0)` means the value passed through an SImode (int) temp: expand makes + * (set (reg:SI) (sign_extend (mem:HI))) + (set (mem:HI) (subreg:HI ...)), and combine cannot + * merge them (the merged form is mem<-mem, which no movhi accepts) so the sign-extending load + * survives. => route both halfword copies through the `s32 t` temp. + * + * 3. THE `goto` LAYOUT — dodging jump.c's store-flag conversion (jump.c:1005-1065). + * An if/else chain writing 0/1 into `doit` makes gcc collapse the last pair into + * `sltiu $v0,$v0,1`. jump.c fires that conversion when the insn immediately after a + * conditional jump is a lone `SET pseudo, CONST_INT` whose following simplejump targets the + * SAME label as the branch (jump.c:1038 `reallabelprev == temp || ... JUMP_LABEL(temp4) == + * JUMP_LABEL(insn)`) — exactly the shape of `if (c) x=0; else x=1;`. + * The target instead cross-jumps ALL the `doit=0` exits into ONE shared block placed after the + * `doit=1` fall-through; reorg's fill_slots_from_thread then COPIES that single set into all + * three branch delay slots and redirects each branch past it (which is why `addu $v0,$zero, + * $zero` appears 3x in delay slots and the shared block vanishes). A `goto zero;` / `goto one;` + * chain expresses that layout directly, and each conditional jump is then followed by a + * compare/call rather than a lone const set, so the store-flag conversion never triggers. + * GENERAL RULE: multiple predicates that all assign the SAME constant to one flag => write + * them as `goto` to a shared assignment, never as an if/else ladder. + */ +extern s32 D_8011F9C4; +extern s32 D_801818F4; + +extern s32 func_80161B18(void); +extern s32 func_801619A4(s32*); +extern s32 func_80149AA8(s32*); +extern void func_80149AD4(s32*); +extern s32 func_80149B54(s32*); +extern void func_80149BAC(s32*); +extern s32 func_801498E0(s32*); +extern s32 func_80149954(s32); +extern s32 func_80149A64(s32*); +extern void func_800CCCC0(s32 a0); +extern s32 func_80149CD4(s32 a0); +extern void func_8015E880(s32*); +extern s32 func_80149744(struct S_80149744*); +extern void func_80149788(void); +extern s32 func_801496D4(void*); +extern void func_80149704(void); +extern int func_80148AFC(void*); +extern void func_80146D90(s32 a0); +extern void func_80154150(s32 a0, s32 a1); +extern void func_801541D8(u8*, s32, s32); +extern s32 func_801488A8(u8*); +extern void func_80147078(s32*, s16); +extern void func_8015A264(void*); +extern s32 func_80013294(void*, void*); +extern void func_80159B70(void*); +extern s32 func_8016F1AC(void); +extern s32 func_80029178(s32 a0); +extern void func_80146DB8(s32*, s32*); +extern s32 func_80161CD0(s32, s32); +extern s32 func_80161208(s32 a0); +extern s32 func_801725A4(u8*); + +s32 func_8015B950(s32 arg0) +{ + + extern void (*D_80181960[])(void *); + s16 sp10[4]; + s16 sp18[4]; + s32 t; + s32 z; + s32 doit; + s32 lim = -0xB0000; + + if (func_80161B18() != 0) { + return; + } + switch (((s32 (*)(s32))func_801619A4)(arg0)) { + case 0: + case 1: + case 2: + case 6: + if (((s32 (*)(s32))func_80149AA8)(arg0) != 0) { + D_80181960[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149AD4)(arg0); + return; + } + if (((s32 (*)(s32))func_80149B54)(arg0) != 0) { + D_80181960[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149BAC)(arg0); + return; + } + break; + case 3: + ((void (*)(s32))func_801498E0)(arg0); + break; + case 4: + ((void (*)(s32))func_80149954)(arg0); + break; + case 5: + if (((s32 (*)(s32))func_80149A64)(arg0) != 0) { + D_80181960[*(u16 *)arg0]((void *)arg0); + func_800CCCC0(arg0); + return; + } + break; + } + if (func_80149CD4(arg0) != 0) { + D_80181960[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_8015E880)(arg0); + return; + } + if (((s32 (*)(s32))func_80149744)(arg0) != 0) { + D_80181960[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149788)(arg0); + return; + } + if (((s32 (*)(s32))func_801496D4)(arg0) != 0) { + D_80181960[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149704)(arg0); + if (((u8)((s32 (*)(s32))func_80148AFC)(arg0)) == 0) { + func_80146D90(arg0); + } + if ((*(s32 *)(arg0 + 0x24) | *(s32 *)(arg0 + 0x2C)) != 0) { + func_80154150(arg0, 0xF); + } else { + ((void (*)(s32, s32, s32))func_801541D8)(arg0, 0xD, 6); + } + *(s32 *)(arg0 + 0x238) = 1; + return; + } + if (((s32 (*)(s32))func_801488A8)(arg0) != 0) { + sp10[0] = 0; + sp10[1] = 0; + sp10[2] = 0; + t = *(s16 *)(arg0 + 0x26); + sp18[0] = t; + sp18[1] = 0; + t = *(s16 *)(arg0 + 0x2E); + sp18[2] = t; + D_80181960[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 1); + ((void (*)(s32))func_8015A264)(arg0); + t = -(((s32 (*)(s16 *, s16 *))func_80013294)(sp10, sp18) << 0x10); + if (t < *(s32 *)(arg0 + 0x2C)) { + *(s32 *)(arg0 + 0x2C) = t; + } + return; + } + if (*(u16 *)(arg0 + 0xB8) == 0x8000) { + D_80181960[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 0); + ((void (*)(s32))func_80159B70)(arg0); + return; + } + z = *(s32 *)(arg0 + 0x2C); + if (func_8016F1AC() != 0) { + goto zero; + } + if (z <= lim) { + goto one; + } + if (D_8011F9C4 == 0) { + goto zero; + } + if (((u8)func_80029178(0x21)) != 0) { + goto zero; + } +one: + doit = 1; + goto join; +zero: + doit = 0; +join: + if (doit != 0) { + D_80181960[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 0); + ((void (*)(s32))func_80159B70)(arg0); + func_80154150(arg0, 9); + ((void (*)(s32, s32 *))func_80146DB8)(arg0, &D_801818F4); + ((void (*)(s32, s32))func_80161CD0)(arg0, *(u16 *)(arg0 + 0x16E)); + return; + } + if (func_80161208(arg0) == 0) { + ((void (*)(s32))func_801725A4)(arg0); + } +} DEFINE_func_8015BD8C() /* dedup: shared engine-core @0x8015BD8C (src/shared) */ diff --git a/src/ov_SC03_006/ov_SC03_006_jr_8015AE2C.c b/src/ov_SC03_006/ov_SC03_006_jr_8015AE2C.c index bbd66976e..62de4eb7a 100644 --- a/src/ov_SC03_006/ov_SC03_006_jr_8015AE2C.c +++ b/src/ov_SC03_006/ov_SC03_006_jr_8015AE2C.c @@ -1513,7 +1513,259 @@ DEFINE_func_8015B858() /* dedup: shared engine-core @0x8015B858 (src/shared) */ DEFINE_func_8015B8F8() /* dedup: shared engine-core @0x8015B8F8 (src/shared) */ -INCLUDE_ASM("asm/ov_SC03_006/nonmatchings/ov_SC03_006_jr_8015AE2C", func_8015B950); +extern s32 func_8015AE2C(); + +// @class: plumbing +// @stuck: none — MATCH (271/271, pin-free, zero asm). The ONLY residual is DEF-SIDE plumbing, and it is now named exactly: the in-TU instantiation `DEFINE_func_8015BEE4()` (engine_core.h:1851-1855) expands to `extern s32 func_8015B950(void);` INSIDE ov_SC01_077_jr_8015AE2C.c, ~14 lines BELOW this definition, so the 1-param def collides with a `(void)` prototype -> `conflicting types for func_8015B950` (.run/bank_func_8015B950.log). §73 PARAMS axis / T0. Surgical fix = §65b de-macroize that ONE instantiation (blast radius: this TU); the fleet-wide `(void)`->`()` header edit is §63 and must be R22-validated. +/* func_8015B950 (ov_SC01_077_jr_8015AE2C, 271 ins, jtbl_801D8B74) — SESSION-21 re-verified + * + * ── ROUND-2 INDEPENDENT RE-VERIFICATION (2026-07-27, fresh agent, §88e discipline) ───────────── + * match_one : MATCH (271 ins) against the CURRENT tree — §87 staleness re-checked today. + * .text size: compiled .text = 0x43C = 1084 B = 271 ins, EXACTLY the target's declared 0x43C + * ("nonmatching func_8015B950, 0x43C"). So this is NOT a §83a length drift hiding + * behind a zero count — the count is over equal-length streams. + * jtbl : RE-DECODED MECHANICALLY, not inherited. Compiled .rodata = 0x1C = 28 B = 7 words, + * 7x R_MIPS_32 -> .text with implicit addends [58,58,58,E0,F0,100,58]; +0x8015B950 + * = [8015B9A8, 8015B9A8, 8015B9A8, 8015BA30, 8015BA40, 8015BA50, 8015B9A8]. + * Diffed word-for-word against asm/ov_SC01_077/data/tail14.data.s:15-23 — 7/7 identical. + * symcheck : SYMS-DIFF target=35 draft=34, sole MISSING = jtbl_801D8B74. This is the §81 jr + * FALSE POSITIVE, re-confirmed here by reading the relocs: gcc emits its OWN table and + * references it with R_MIPS_HI16/LO16 against the SECTION `.rodata` (t.o +0x40/+0x48), + * so the splat's dlabel NAME can never appear in the draft object's relocation set. + * Nothing is dropped and nothing is invented: the draft's other 34 symbols are exactly + * the target's other 34. + * FAMILY : the x138 remap is clean and §84-safe. Every sibling is 271 ins with an IDENTICAL + * callee set; only THREE names vary per overlay — the two data labels and the jtbl: + * ov_SC01_077 D_8018EC10 / D_8018EC7C / jtbl_801D8B74 + * ov_SC03_099 D_80185A50 / D_80185ABC / jtbl_801BD898 + * ov_SC06_008 D_80187E44 / D_80187EB0 / jtbl_801A8734 + * The pair is always +0x6C apart, and NO literal in this draft encodes that distance + * (both labels are referenced by name), so there is no §84 derived-offset hazard. + * D_8011F9C4 is fleet-constant (main-EXE data) and must NOT be remapped. + * + * match_one: MATCH (271 ins) against the CURRENT tree (§87 staleness re-checked, 2026-07-27). + * PIN-FREE, zero asm, offset-pure (s32 arg0 + raw offsets) — x138 template-safe. + * Provenance: this is the Phase-26 crack (.run/phase26-cracks/func_8015B950.c) re-gated verbatim, + * with ONE deliberate change: the definition's return type void -> s32. + * - `void func_8015B950(s32 arg0)` : MATCH (271 ins) [the Phase-26 form] + * - `s32 func_8015B950(s32 arg0)` : MATCH (271 ins) [shipped — §3a-1 void->s32 is byte-neutral] + * The fleet/engine_core.h canonical decl is `extern s32 func_8015B950(void);` (engine_core.h:1852), + * and the last bank attempt (.run/bank_func_8015B950.log) died on `conflicting types for + * func_8015B950`. Shipping the s32 return kills the §73 RETURN axis for free and leaves only the + * cheap T0 PARAMS axis for the ladder (fix_header_decl.py / --fix-def-sig / cast_call_sites). + * Both forms are byte-identical, so the orchestrator may swap the return type back at zero cost. + * + * SYMBOLS (§58 rules 1/2 — all splat spellings, all verified present): + * D_8018EC7C asm/ov_SC01_077/data/tail.data.s:4355 (the state-handler vtable) + * D_8018EC10 asm/ov_SC01_077/data/tail.data.s:4293 + * D_8011F9C4 main-EXE data; spelled `extern s32 D_8011F9C4;` in 5+ already-banked TUs + * jtbl_801D8B74 asm/ov_SC01_077/data/tail14.data.s:15 (compiler jump table — not named in C) + * + * JTBL VERIFIED (§8a gate): compiled .rodata = exactly 0x1C B / 7 words, 7x R_MIPS_32 .text with + * addends [0x58,0x58,0x58,0xE0,0xF0,0x100,0x58] -> +0x8015B950 = [B9A8,B9A8,B9A8,BA30,BA40,BA50, + * B9A8] == the original words at 0x801D8B74..0x801D8B8C. Bound `sltiu $v0,$v1,0x7` matches. + * The raw dlabel's 8th word 0x00000000 is NOT an entry — it is the intra-TU `.align 3` pad of the + * B34/B54/B74 jtbl chain; the object can never emit it (maspsx drops .align), so it must stay in + * the post-carve RAW data piece (the §53/§62/§81 carve chain applies at bank time). + * + * Same family as the TU's own already-matched func_8015AE2C: 7-case switch on ((s32 (*)(s32))func_801619A4)() + * (0/1/2/6 shared, 3/4/5 own, no default block — out-of-range and every `break` fall to the + * after-switch join), then a chain of "state handler" tests, each dispatching + * D_8018EC7C[*(u16*)arg0](arg0) and returning. + * + * THREE LEVERS (draft -> MATCH in 3 compiles): + * + * 1. PROLOGUE CONSTANT = an INITIALIZED LOCAL, not a literal in the compare. + * Target opens with `lui $s2, 0xFFF5` in the *prologue*, used once ~200 ins later in + * `slt $v0,$s2,$s1`. No gcc-2.7.2 pass hoists a (set reg const_int) across basic blocks + * (loop.c needs a loop; cse/combine/sched never move insns between BBs) — so the insn must + * have been EMITTED in the first BB, i.e. the constant is a local initialized at the top of + * the function. cse then cannot fold it back into the compare: the `slt` operand predicate is + * `arith_operand`, which rejects a CONST_INT wider than 16 bits, so validate_change fails and + * the pseudo survives. Its live range spans every call -> global.c gives it a callee-saved reg. + * Writing `z > -0xB0000` inline instead emits the `lui` into the branch delay slot next to the + * compare (caller-saved $v0) and the function is 1 insn short. => `s32 lim = -0xB0000;` at top. + * + * 2. `lh` vs `lhu`: a short->short copy is a pure HImode move and gcc emits `lhu`. The target's + * `lh $v0,0x26($s0)` means the value passed through an SImode (int) temp: expand makes + * (set (reg:SI) (sign_extend (mem:HI))) + (set (mem:HI) (subreg:HI ...)), and combine cannot + * merge them (the merged form is mem<-mem, which no movhi accepts) so the sign-extending load + * survives. => route both halfword copies through the `s32 t` temp. + * + * 3. THE `goto` LAYOUT — dodging jump.c's store-flag conversion (jump.c:1005-1065). + * An if/else chain writing 0/1 into `doit` makes gcc collapse the last pair into + * `sltiu $v0,$v0,1`. jump.c fires that conversion when the insn immediately after a + * conditional jump is a lone `SET pseudo, CONST_INT` whose following simplejump targets the + * SAME label as the branch (jump.c:1038 `reallabelprev == temp || ... JUMP_LABEL(temp4) == + * JUMP_LABEL(insn)`) — exactly the shape of `if (c) x=0; else x=1;`. + * The target instead cross-jumps ALL the `doit=0` exits into ONE shared block placed after the + * `doit=1` fall-through; reorg's fill_slots_from_thread then COPIES that single set into all + * three branch delay slots and redirects each branch past it (which is why `addu $v0,$zero, + * $zero` appears 3x in delay slots and the shared block vanishes). A `goto zero;` / `goto one;` + * chain expresses that layout directly, and each conditional jump is then followed by a + * compare/call rather than a lone const set, so the store-flag conversion never triggers. + * GENERAL RULE: multiple predicates that all assign the SAME constant to one flag => write + * them as `goto` to a shared assignment, never as an if/else ladder. + */ +extern s32 D_8011F9C4; +extern s32 D_8018EC10; + +extern s32 func_80161B18(void); +extern s32 func_801619A4(s32*); +extern s32 func_80149AA8(s32*); +extern void func_80149AD4(s32*); +extern s32 func_80149B54(s32*); +extern void func_80149BAC(s32*); +extern s32 func_801498E0(s32*); +extern s32 func_80149954(s32); +extern s32 func_80149A64(s32*); +extern void func_800CCCC0(s32 a0); +extern s32 func_80149CD4(s32 a0); +extern void func_8015E880(s32*); +extern s32 func_80149744(struct S_80149744*); +extern void func_80149788(void); +extern s32 func_801496D4(void*); +extern void func_80149704(void); +extern int func_80148AFC(void*); +extern void func_80146D90(s32 a0); +extern void func_80154150(s32 a0, s32 a1); +extern void func_801541D8(u8*, s32, s32); +extern s32 func_801488A8(u8*); +extern void func_80147078(s32*, s16); +extern void func_8015A264(void*); +extern s32 func_80013294(void*, void*); +extern void func_80159B70(void*); +extern s32 func_8016F1AC(void); +extern s32 func_80029178(s32 a0); +extern void func_80146DB8(s32*, s32*); +extern s32 func_80161CD0(s32, s32); +extern s32 func_80161208(s32 a0); +extern s32 func_801725A4(u8*); + +s32 func_8015B950(s32 arg0) +{ + + extern void (*D_8018EC7C[])(void *); + s16 sp10[4]; + s16 sp18[4]; + s32 t; + s32 z; + s32 doit; + s32 lim = -0xB0000; + + if (func_80161B18() != 0) { + return; + } + switch (((s32 (*)(s32))func_801619A4)(arg0)) { + case 0: + case 1: + case 2: + case 6: + if (((s32 (*)(s32))func_80149AA8)(arg0) != 0) { + D_8018EC7C[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149AD4)(arg0); + return; + } + if (((s32 (*)(s32))func_80149B54)(arg0) != 0) { + D_8018EC7C[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149BAC)(arg0); + return; + } + break; + case 3: + ((void (*)(s32))func_801498E0)(arg0); + break; + case 4: + ((void (*)(s32))func_80149954)(arg0); + break; + case 5: + if (((s32 (*)(s32))func_80149A64)(arg0) != 0) { + D_8018EC7C[*(u16 *)arg0]((void *)arg0); + func_800CCCC0(arg0); + return; + } + break; + } + if (func_80149CD4(arg0) != 0) { + D_8018EC7C[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_8015E880)(arg0); + return; + } + if (((s32 (*)(s32))func_80149744)(arg0) != 0) { + D_8018EC7C[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149788)(arg0); + return; + } + if (((s32 (*)(s32))func_801496D4)(arg0) != 0) { + D_8018EC7C[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149704)(arg0); + if (((u8)((s32 (*)(s32))func_80148AFC)(arg0)) == 0) { + func_80146D90(arg0); + } + if ((*(s32 *)(arg0 + 0x24) | *(s32 *)(arg0 + 0x2C)) != 0) { + func_80154150(arg0, 0xF); + } else { + ((void (*)(s32, s32, s32))func_801541D8)(arg0, 0xD, 6); + } + *(s32 *)(arg0 + 0x238) = 1; + return; + } + if (((s32 (*)(s32))func_801488A8)(arg0) != 0) { + sp10[0] = 0; + sp10[1] = 0; + sp10[2] = 0; + t = *(s16 *)(arg0 + 0x26); + sp18[0] = t; + sp18[1] = 0; + t = *(s16 *)(arg0 + 0x2E); + sp18[2] = t; + D_8018EC7C[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 1); + ((void (*)(s32))func_8015A264)(arg0); + t = -(((s32 (*)(s16 *, s16 *))func_80013294)(sp10, sp18) << 0x10); + if (t < *(s32 *)(arg0 + 0x2C)) { + *(s32 *)(arg0 + 0x2C) = t; + } + return; + } + if (*(u16 *)(arg0 + 0xB8) == 0x8000) { + D_8018EC7C[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 0); + ((void (*)(s32))func_80159B70)(arg0); + return; + } + z = *(s32 *)(arg0 + 0x2C); + if (func_8016F1AC() != 0) { + goto zero; + } + if (z <= lim) { + goto one; + } + if (D_8011F9C4 == 0) { + goto zero; + } + if (((u8)func_80029178(0x21)) != 0) { + goto zero; + } +one: + doit = 1; + goto join; +zero: + doit = 0; +join: + if (doit != 0) { + D_8018EC7C[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 0); + ((void (*)(s32))func_80159B70)(arg0); + func_80154150(arg0, 9); + ((void (*)(s32, s32 *))func_80146DB8)(arg0, &D_8018EC10); + ((void (*)(s32, s32))func_80161CD0)(arg0, *(u16 *)(arg0 + 0x16E)); + return; + } + if (func_80161208(arg0) == 0) { + ((void (*)(s32))func_801725A4)(arg0); + } +} DEFINE_func_8015BD8C() /* dedup: shared engine-core @0x8015BD8C (src/shared) */ diff --git a/src/ov_SC03_007/ov_SC03_007_jr_8015AE2C.c b/src/ov_SC03_007/ov_SC03_007_jr_8015AE2C.c index 5878e3e2d..e04c2ce47 100644 --- a/src/ov_SC03_007/ov_SC03_007_jr_8015AE2C.c +++ b/src/ov_SC03_007/ov_SC03_007_jr_8015AE2C.c @@ -1513,7 +1513,259 @@ DEFINE_func_8015B858() /* dedup: shared engine-core @0x8015B858 (src/shared) */ DEFINE_func_8015B8F8() /* dedup: shared engine-core @0x8015B8F8 (src/shared) */ -INCLUDE_ASM("asm/ov_SC03_007/nonmatchings/ov_SC03_007_jr_8015AE2C", func_8015B950); +extern s32 func_8015AE2C(); + +// @class: plumbing +// @stuck: none — MATCH (271/271, pin-free, zero asm). The ONLY residual is DEF-SIDE plumbing, and it is now named exactly: the in-TU instantiation `DEFINE_func_8015BEE4()` (engine_core.h:1851-1855) expands to `extern s32 func_8015B950(void);` INSIDE ov_SC01_077_jr_8015AE2C.c, ~14 lines BELOW this definition, so the 1-param def collides with a `(void)` prototype -> `conflicting types for func_8015B950` (.run/bank_func_8015B950.log). §73 PARAMS axis / T0. Surgical fix = §65b de-macroize that ONE instantiation (blast radius: this TU); the fleet-wide `(void)`->`()` header edit is §63 and must be R22-validated. +/* func_8015B950 (ov_SC01_077_jr_8015AE2C, 271 ins, jtbl_801D8B74) — SESSION-21 re-verified + * + * ── ROUND-2 INDEPENDENT RE-VERIFICATION (2026-07-27, fresh agent, §88e discipline) ───────────── + * match_one : MATCH (271 ins) against the CURRENT tree — §87 staleness re-checked today. + * .text size: compiled .text = 0x43C = 1084 B = 271 ins, EXACTLY the target's declared 0x43C + * ("nonmatching func_8015B950, 0x43C"). So this is NOT a §83a length drift hiding + * behind a zero count — the count is over equal-length streams. + * jtbl : RE-DECODED MECHANICALLY, not inherited. Compiled .rodata = 0x1C = 28 B = 7 words, + * 7x R_MIPS_32 -> .text with implicit addends [58,58,58,E0,F0,100,58]; +0x8015B950 + * = [8015B9A8, 8015B9A8, 8015B9A8, 8015BA30, 8015BA40, 8015BA50, 8015B9A8]. + * Diffed word-for-word against asm/ov_SC01_077/data/tail14.data.s:15-23 — 7/7 identical. + * symcheck : SYMS-DIFF target=35 draft=34, sole MISSING = jtbl_801D8B74. This is the §81 jr + * FALSE POSITIVE, re-confirmed here by reading the relocs: gcc emits its OWN table and + * references it with R_MIPS_HI16/LO16 against the SECTION `.rodata` (t.o +0x40/+0x48), + * so the splat's dlabel NAME can never appear in the draft object's relocation set. + * Nothing is dropped and nothing is invented: the draft's other 34 symbols are exactly + * the target's other 34. + * FAMILY : the x138 remap is clean and §84-safe. Every sibling is 271 ins with an IDENTICAL + * callee set; only THREE names vary per overlay — the two data labels and the jtbl: + * ov_SC01_077 D_80189A08 / D_80189A74 / jtbl_801D8B74 + * ov_SC03_099 D_80185A50 / D_80185ABC / jtbl_801BD898 + * ov_SC06_008 D_80187E44 / D_80187EB0 / jtbl_801A8734 + * The pair is always +0x6C apart, and NO literal in this draft encodes that distance + * (both labels are referenced by name), so there is no §84 derived-offset hazard. + * D_8011F9C4 is fleet-constant (main-EXE data) and must NOT be remapped. + * + * match_one: MATCH (271 ins) against the CURRENT tree (§87 staleness re-checked, 2026-07-27). + * PIN-FREE, zero asm, offset-pure (s32 arg0 + raw offsets) — x138 template-safe. + * Provenance: this is the Phase-26 crack (.run/phase26-cracks/func_8015B950.c) re-gated verbatim, + * with ONE deliberate change: the definition's return type void -> s32. + * - `void func_8015B950(s32 arg0)` : MATCH (271 ins) [the Phase-26 form] + * - `s32 func_8015B950(s32 arg0)` : MATCH (271 ins) [shipped — §3a-1 void->s32 is byte-neutral] + * The fleet/engine_core.h canonical decl is `extern s32 func_8015B950(void);` (engine_core.h:1852), + * and the last bank attempt (.run/bank_func_8015B950.log) died on `conflicting types for + * func_8015B950`. Shipping the s32 return kills the §73 RETURN axis for free and leaves only the + * cheap T0 PARAMS axis for the ladder (fix_header_decl.py / --fix-def-sig / cast_call_sites). + * Both forms are byte-identical, so the orchestrator may swap the return type back at zero cost. + * + * SYMBOLS (§58 rules 1/2 — all splat spellings, all verified present): + * D_80189A74 asm/ov_SC01_077/data/tail.data.s:4355 (the state-handler vtable) + * D_80189A08 asm/ov_SC01_077/data/tail.data.s:4293 + * D_8011F9C4 main-EXE data; spelled `extern s32 D_8011F9C4;` in 5+ already-banked TUs + * jtbl_801D8B74 asm/ov_SC01_077/data/tail14.data.s:15 (compiler jump table — not named in C) + * + * JTBL VERIFIED (§8a gate): compiled .rodata = exactly 0x1C B / 7 words, 7x R_MIPS_32 .text with + * addends [0x58,0x58,0x58,0xE0,0xF0,0x100,0x58] -> +0x8015B950 = [B9A8,B9A8,B9A8,BA30,BA40,BA50, + * B9A8] == the original words at 0x801D8B74..0x801D8B8C. Bound `sltiu $v0,$v1,0x7` matches. + * The raw dlabel's 8th word 0x00000000 is NOT an entry — it is the intra-TU `.align 3` pad of the + * B34/B54/B74 jtbl chain; the object can never emit it (maspsx drops .align), so it must stay in + * the post-carve RAW data piece (the §53/§62/§81 carve chain applies at bank time). + * + * Same family as the TU's own already-matched func_8015AE2C: 7-case switch on ((s32 (*)(s32))func_801619A4)() + * (0/1/2/6 shared, 3/4/5 own, no default block — out-of-range and every `break` fall to the + * after-switch join), then a chain of "state handler" tests, each dispatching + * D_80189A74[*(u16*)arg0](arg0) and returning. + * + * THREE LEVERS (draft -> MATCH in 3 compiles): + * + * 1. PROLOGUE CONSTANT = an INITIALIZED LOCAL, not a literal in the compare. + * Target opens with `lui $s2, 0xFFF5` in the *prologue*, used once ~200 ins later in + * `slt $v0,$s2,$s1`. No gcc-2.7.2 pass hoists a (set reg const_int) across basic blocks + * (loop.c needs a loop; cse/combine/sched never move insns between BBs) — so the insn must + * have been EMITTED in the first BB, i.e. the constant is a local initialized at the top of + * the function. cse then cannot fold it back into the compare: the `slt` operand predicate is + * `arith_operand`, which rejects a CONST_INT wider than 16 bits, so validate_change fails and + * the pseudo survives. Its live range spans every call -> global.c gives it a callee-saved reg. + * Writing `z > -0xB0000` inline instead emits the `lui` into the branch delay slot next to the + * compare (caller-saved $v0) and the function is 1 insn short. => `s32 lim = -0xB0000;` at top. + * + * 2. `lh` vs `lhu`: a short->short copy is a pure HImode move and gcc emits `lhu`. The target's + * `lh $v0,0x26($s0)` means the value passed through an SImode (int) temp: expand makes + * (set (reg:SI) (sign_extend (mem:HI))) + (set (mem:HI) (subreg:HI ...)), and combine cannot + * merge them (the merged form is mem<-mem, which no movhi accepts) so the sign-extending load + * survives. => route both halfword copies through the `s32 t` temp. + * + * 3. THE `goto` LAYOUT — dodging jump.c's store-flag conversion (jump.c:1005-1065). + * An if/else chain writing 0/1 into `doit` makes gcc collapse the last pair into + * `sltiu $v0,$v0,1`. jump.c fires that conversion when the insn immediately after a + * conditional jump is a lone `SET pseudo, CONST_INT` whose following simplejump targets the + * SAME label as the branch (jump.c:1038 `reallabelprev == temp || ... JUMP_LABEL(temp4) == + * JUMP_LABEL(insn)`) — exactly the shape of `if (c) x=0; else x=1;`. + * The target instead cross-jumps ALL the `doit=0` exits into ONE shared block placed after the + * `doit=1` fall-through; reorg's fill_slots_from_thread then COPIES that single set into all + * three branch delay slots and redirects each branch past it (which is why `addu $v0,$zero, + * $zero` appears 3x in delay slots and the shared block vanishes). A `goto zero;` / `goto one;` + * chain expresses that layout directly, and each conditional jump is then followed by a + * compare/call rather than a lone const set, so the store-flag conversion never triggers. + * GENERAL RULE: multiple predicates that all assign the SAME constant to one flag => write + * them as `goto` to a shared assignment, never as an if/else ladder. + */ +extern s32 D_8011F9C4; +extern s32 D_80189A08; + +extern s32 func_80161B18(void); +extern s32 func_801619A4(s32*); +extern s32 func_80149AA8(s32*); +extern void func_80149AD4(s32*); +extern s32 func_80149B54(s32*); +extern void func_80149BAC(s32*); +extern s32 func_801498E0(s32*); +extern s32 func_80149954(s32); +extern s32 func_80149A64(s32*); +extern void func_800CCCC0(s32 a0); +extern s32 func_80149CD4(s32 a0); +extern void func_8015E880(s32*); +extern s32 func_80149744(struct S_80149744*); +extern void func_80149788(void); +extern s32 func_801496D4(void*); +extern void func_80149704(void); +extern int func_80148AFC(void*); +extern void func_80146D90(s32 a0); +extern void func_80154150(s32 a0, s32 a1); +extern void func_801541D8(u8*, s32, s32); +extern s32 func_801488A8(u8*); +extern void func_80147078(s32*, s16); +extern void func_8015A264(void*); +extern s32 func_80013294(void*, void*); +extern void func_80159B70(void*); +extern s32 func_8016F1AC(void); +extern s32 func_80029178(s32 a0); +extern void func_80146DB8(s32*, s32*); +extern s32 func_80161CD0(s32, s32); +extern s32 func_80161208(s32 a0); +extern s32 func_801725A4(u8*); + +s32 func_8015B950(s32 arg0) +{ + + extern void (*D_80189A74[])(void *); + s16 sp10[4]; + s16 sp18[4]; + s32 t; + s32 z; + s32 doit; + s32 lim = -0xB0000; + + if (func_80161B18() != 0) { + return; + } + switch (((s32 (*)(s32))func_801619A4)(arg0)) { + case 0: + case 1: + case 2: + case 6: + if (((s32 (*)(s32))func_80149AA8)(arg0) != 0) { + D_80189A74[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149AD4)(arg0); + return; + } + if (((s32 (*)(s32))func_80149B54)(arg0) != 0) { + D_80189A74[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149BAC)(arg0); + return; + } + break; + case 3: + ((void (*)(s32))func_801498E0)(arg0); + break; + case 4: + ((void (*)(s32))func_80149954)(arg0); + break; + case 5: + if (((s32 (*)(s32))func_80149A64)(arg0) != 0) { + D_80189A74[*(u16 *)arg0]((void *)arg0); + func_800CCCC0(arg0); + return; + } + break; + } + if (func_80149CD4(arg0) != 0) { + D_80189A74[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_8015E880)(arg0); + return; + } + if (((s32 (*)(s32))func_80149744)(arg0) != 0) { + D_80189A74[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149788)(arg0); + return; + } + if (((s32 (*)(s32))func_801496D4)(arg0) != 0) { + D_80189A74[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149704)(arg0); + if (((u8)((s32 (*)(s32))func_80148AFC)(arg0)) == 0) { + func_80146D90(arg0); + } + if ((*(s32 *)(arg0 + 0x24) | *(s32 *)(arg0 + 0x2C)) != 0) { + func_80154150(arg0, 0xF); + } else { + ((void (*)(s32, s32, s32))func_801541D8)(arg0, 0xD, 6); + } + *(s32 *)(arg0 + 0x238) = 1; + return; + } + if (((s32 (*)(s32))func_801488A8)(arg0) != 0) { + sp10[0] = 0; + sp10[1] = 0; + sp10[2] = 0; + t = *(s16 *)(arg0 + 0x26); + sp18[0] = t; + sp18[1] = 0; + t = *(s16 *)(arg0 + 0x2E); + sp18[2] = t; + D_80189A74[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 1); + ((void (*)(s32))func_8015A264)(arg0); + t = -(((s32 (*)(s16 *, s16 *))func_80013294)(sp10, sp18) << 0x10); + if (t < *(s32 *)(arg0 + 0x2C)) { + *(s32 *)(arg0 + 0x2C) = t; + } + return; + } + if (*(u16 *)(arg0 + 0xB8) == 0x8000) { + D_80189A74[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 0); + ((void (*)(s32))func_80159B70)(arg0); + return; + } + z = *(s32 *)(arg0 + 0x2C); + if (func_8016F1AC() != 0) { + goto zero; + } + if (z <= lim) { + goto one; + } + if (D_8011F9C4 == 0) { + goto zero; + } + if (((u8)func_80029178(0x21)) != 0) { + goto zero; + } +one: + doit = 1; + goto join; +zero: + doit = 0; +join: + if (doit != 0) { + D_80189A74[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 0); + ((void (*)(s32))func_80159B70)(arg0); + func_80154150(arg0, 9); + ((void (*)(s32, s32 *))func_80146DB8)(arg0, &D_80189A08); + ((void (*)(s32, s32))func_80161CD0)(arg0, *(u16 *)(arg0 + 0x16E)); + return; + } + if (func_80161208(arg0) == 0) { + ((void (*)(s32))func_801725A4)(arg0); + } +} DEFINE_func_8015BD8C() /* dedup: shared engine-core @0x8015BD8C (src/shared) */ diff --git a/src/ov_SC03_010/ov_SC03_010_jr_8015AE2C.c b/src/ov_SC03_010/ov_SC03_010_jr_8015AE2C.c index c7810c3c6..10259a1d6 100644 --- a/src/ov_SC03_010/ov_SC03_010_jr_8015AE2C.c +++ b/src/ov_SC03_010/ov_SC03_010_jr_8015AE2C.c @@ -1513,7 +1513,259 @@ DEFINE_func_8015B858() /* dedup: shared engine-core @0x8015B858 (src/shared) */ DEFINE_func_8015B8F8() /* dedup: shared engine-core @0x8015B8F8 (src/shared) */ -INCLUDE_ASM("asm/ov_SC03_010/nonmatchings/ov_SC03_010_jr_8015AE2C", func_8015B950); +extern s32 func_8015AE2C(); + +// @class: plumbing +// @stuck: none — MATCH (271/271, pin-free, zero asm). The ONLY residual is DEF-SIDE plumbing, and it is now named exactly: the in-TU instantiation `DEFINE_func_8015BEE4()` (engine_core.h:1851-1855) expands to `extern s32 func_8015B950(void);` INSIDE ov_SC01_077_jr_8015AE2C.c, ~14 lines BELOW this definition, so the 1-param def collides with a `(void)` prototype -> `conflicting types for func_8015B950` (.run/bank_func_8015B950.log). §73 PARAMS axis / T0. Surgical fix = §65b de-macroize that ONE instantiation (blast radius: this TU); the fleet-wide `(void)`->`()` header edit is §63 and must be R22-validated. +/* func_8015B950 (ov_SC01_077_jr_8015AE2C, 271 ins, jtbl_801D8B74) — SESSION-21 re-verified + * + * ── ROUND-2 INDEPENDENT RE-VERIFICATION (2026-07-27, fresh agent, §88e discipline) ───────────── + * match_one : MATCH (271 ins) against the CURRENT tree — §87 staleness re-checked today. + * .text size: compiled .text = 0x43C = 1084 B = 271 ins, EXACTLY the target's declared 0x43C + * ("nonmatching func_8015B950, 0x43C"). So this is NOT a §83a length drift hiding + * behind a zero count — the count is over equal-length streams. + * jtbl : RE-DECODED MECHANICALLY, not inherited. Compiled .rodata = 0x1C = 28 B = 7 words, + * 7x R_MIPS_32 -> .text with implicit addends [58,58,58,E0,F0,100,58]; +0x8015B950 + * = [8015B9A8, 8015B9A8, 8015B9A8, 8015BA30, 8015BA40, 8015BA50, 8015B9A8]. + * Diffed word-for-word against asm/ov_SC01_077/data/tail14.data.s:15-23 — 7/7 identical. + * symcheck : SYMS-DIFF target=35 draft=34, sole MISSING = jtbl_801D8B74. This is the §81 jr + * FALSE POSITIVE, re-confirmed here by reading the relocs: gcc emits its OWN table and + * references it with R_MIPS_HI16/LO16 against the SECTION `.rodata` (t.o +0x40/+0x48), + * so the splat's dlabel NAME can never appear in the draft object's relocation set. + * Nothing is dropped and nothing is invented: the draft's other 34 symbols are exactly + * the target's other 34. + * FAMILY : the x138 remap is clean and §84-safe. Every sibling is 271 ins with an IDENTICAL + * callee set; only THREE names vary per overlay — the two data labels and the jtbl: + * ov_SC01_077 D_80182528 / D_80182594 / jtbl_801D8B74 + * ov_SC03_099 D_80185A50 / D_80185ABC / jtbl_801BD898 + * ov_SC06_008 D_80187E44 / D_80187EB0 / jtbl_801A8734 + * The pair is always +0x6C apart, and NO literal in this draft encodes that distance + * (both labels are referenced by name), so there is no §84 derived-offset hazard. + * D_8011F9C4 is fleet-constant (main-EXE data) and must NOT be remapped. + * + * match_one: MATCH (271 ins) against the CURRENT tree (§87 staleness re-checked, 2026-07-27). + * PIN-FREE, zero asm, offset-pure (s32 arg0 + raw offsets) — x138 template-safe. + * Provenance: this is the Phase-26 crack (.run/phase26-cracks/func_8015B950.c) re-gated verbatim, + * with ONE deliberate change: the definition's return type void -> s32. + * - `void func_8015B950(s32 arg0)` : MATCH (271 ins) [the Phase-26 form] + * - `s32 func_8015B950(s32 arg0)` : MATCH (271 ins) [shipped — §3a-1 void->s32 is byte-neutral] + * The fleet/engine_core.h canonical decl is `extern s32 func_8015B950(void);` (engine_core.h:1852), + * and the last bank attempt (.run/bank_func_8015B950.log) died on `conflicting types for + * func_8015B950`. Shipping the s32 return kills the §73 RETURN axis for free and leaves only the + * cheap T0 PARAMS axis for the ladder (fix_header_decl.py / --fix-def-sig / cast_call_sites). + * Both forms are byte-identical, so the orchestrator may swap the return type back at zero cost. + * + * SYMBOLS (§58 rules 1/2 — all splat spellings, all verified present): + * D_80182594 asm/ov_SC01_077/data/tail.data.s:4355 (the state-handler vtable) + * D_80182528 asm/ov_SC01_077/data/tail.data.s:4293 + * D_8011F9C4 main-EXE data; spelled `extern s32 D_8011F9C4;` in 5+ already-banked TUs + * jtbl_801D8B74 asm/ov_SC01_077/data/tail14.data.s:15 (compiler jump table — not named in C) + * + * JTBL VERIFIED (§8a gate): compiled .rodata = exactly 0x1C B / 7 words, 7x R_MIPS_32 .text with + * addends [0x58,0x58,0x58,0xE0,0xF0,0x100,0x58] -> +0x8015B950 = [B9A8,B9A8,B9A8,BA30,BA40,BA50, + * B9A8] == the original words at 0x801D8B74..0x801D8B8C. Bound `sltiu $v0,$v1,0x7` matches. + * The raw dlabel's 8th word 0x00000000 is NOT an entry — it is the intra-TU `.align 3` pad of the + * B34/B54/B74 jtbl chain; the object can never emit it (maspsx drops .align), so it must stay in + * the post-carve RAW data piece (the §53/§62/§81 carve chain applies at bank time). + * + * Same family as the TU's own already-matched func_8015AE2C: 7-case switch on ((s32 (*)(s32))func_801619A4)() + * (0/1/2/6 shared, 3/4/5 own, no default block — out-of-range and every `break` fall to the + * after-switch join), then a chain of "state handler" tests, each dispatching + * D_80182594[*(u16*)arg0](arg0) and returning. + * + * THREE LEVERS (draft -> MATCH in 3 compiles): + * + * 1. PROLOGUE CONSTANT = an INITIALIZED LOCAL, not a literal in the compare. + * Target opens with `lui $s2, 0xFFF5` in the *prologue*, used once ~200 ins later in + * `slt $v0,$s2,$s1`. No gcc-2.7.2 pass hoists a (set reg const_int) across basic blocks + * (loop.c needs a loop; cse/combine/sched never move insns between BBs) — so the insn must + * have been EMITTED in the first BB, i.e. the constant is a local initialized at the top of + * the function. cse then cannot fold it back into the compare: the `slt` operand predicate is + * `arith_operand`, which rejects a CONST_INT wider than 16 bits, so validate_change fails and + * the pseudo survives. Its live range spans every call -> global.c gives it a callee-saved reg. + * Writing `z > -0xB0000` inline instead emits the `lui` into the branch delay slot next to the + * compare (caller-saved $v0) and the function is 1 insn short. => `s32 lim = -0xB0000;` at top. + * + * 2. `lh` vs `lhu`: a short->short copy is a pure HImode move and gcc emits `lhu`. The target's + * `lh $v0,0x26($s0)` means the value passed through an SImode (int) temp: expand makes + * (set (reg:SI) (sign_extend (mem:HI))) + (set (mem:HI) (subreg:HI ...)), and combine cannot + * merge them (the merged form is mem<-mem, which no movhi accepts) so the sign-extending load + * survives. => route both halfword copies through the `s32 t` temp. + * + * 3. THE `goto` LAYOUT — dodging jump.c's store-flag conversion (jump.c:1005-1065). + * An if/else chain writing 0/1 into `doit` makes gcc collapse the last pair into + * `sltiu $v0,$v0,1`. jump.c fires that conversion when the insn immediately after a + * conditional jump is a lone `SET pseudo, CONST_INT` whose following simplejump targets the + * SAME label as the branch (jump.c:1038 `reallabelprev == temp || ... JUMP_LABEL(temp4) == + * JUMP_LABEL(insn)`) — exactly the shape of `if (c) x=0; else x=1;`. + * The target instead cross-jumps ALL the `doit=0` exits into ONE shared block placed after the + * `doit=1` fall-through; reorg's fill_slots_from_thread then COPIES that single set into all + * three branch delay slots and redirects each branch past it (which is why `addu $v0,$zero, + * $zero` appears 3x in delay slots and the shared block vanishes). A `goto zero;` / `goto one;` + * chain expresses that layout directly, and each conditional jump is then followed by a + * compare/call rather than a lone const set, so the store-flag conversion never triggers. + * GENERAL RULE: multiple predicates that all assign the SAME constant to one flag => write + * them as `goto` to a shared assignment, never as an if/else ladder. + */ +extern s32 D_8011F9C4; +extern s32 D_80182528; + +extern s32 func_80161B18(void); +extern s32 func_801619A4(s32*); +extern s32 func_80149AA8(s32*); +extern void func_80149AD4(s32*); +extern s32 func_80149B54(s32*); +extern void func_80149BAC(s32*); +extern s32 func_801498E0(s32*); +extern s32 func_80149954(s32); +extern s32 func_80149A64(s32*); +extern void func_800CCCC0(s32 a0); +extern s32 func_80149CD4(s32 a0); +extern void func_8015E880(s32*); +extern s32 func_80149744(struct S_80149744*); +extern void func_80149788(void); +extern s32 func_801496D4(void*); +extern void func_80149704(void); +extern int func_80148AFC(void*); +extern void func_80146D90(s32 a0); +extern void func_80154150(s32 a0, s32 a1); +extern void func_801541D8(u8*, s32, s32); +extern s32 func_801488A8(u8*); +extern void func_80147078(s32*, s16); +extern void func_8015A264(void*); +extern s32 func_80013294(void*, void*); +extern void func_80159B70(void*); +extern s32 func_8016F1AC(void); +extern s32 func_80029178(s32 a0); +extern void func_80146DB8(s32*, s32*); +extern s32 func_80161CD0(s32, s32); +extern s32 func_80161208(s32 a0); +extern s32 func_801725A4(u8*); + +s32 func_8015B950(s32 arg0) +{ + + extern void (*D_80182594[])(void *); + s16 sp10[4]; + s16 sp18[4]; + s32 t; + s32 z; + s32 doit; + s32 lim = -0xB0000; + + if (func_80161B18() != 0) { + return; + } + switch (((s32 (*)(s32))func_801619A4)(arg0)) { + case 0: + case 1: + case 2: + case 6: + if (((s32 (*)(s32))func_80149AA8)(arg0) != 0) { + D_80182594[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149AD4)(arg0); + return; + } + if (((s32 (*)(s32))func_80149B54)(arg0) != 0) { + D_80182594[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149BAC)(arg0); + return; + } + break; + case 3: + ((void (*)(s32))func_801498E0)(arg0); + break; + case 4: + ((void (*)(s32))func_80149954)(arg0); + break; + case 5: + if (((s32 (*)(s32))func_80149A64)(arg0) != 0) { + D_80182594[*(u16 *)arg0]((void *)arg0); + func_800CCCC0(arg0); + return; + } + break; + } + if (func_80149CD4(arg0) != 0) { + D_80182594[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_8015E880)(arg0); + return; + } + if (((s32 (*)(s32))func_80149744)(arg0) != 0) { + D_80182594[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149788)(arg0); + return; + } + if (((s32 (*)(s32))func_801496D4)(arg0) != 0) { + D_80182594[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149704)(arg0); + if (((u8)((s32 (*)(s32))func_80148AFC)(arg0)) == 0) { + func_80146D90(arg0); + } + if ((*(s32 *)(arg0 + 0x24) | *(s32 *)(arg0 + 0x2C)) != 0) { + func_80154150(arg0, 0xF); + } else { + ((void (*)(s32, s32, s32))func_801541D8)(arg0, 0xD, 6); + } + *(s32 *)(arg0 + 0x238) = 1; + return; + } + if (((s32 (*)(s32))func_801488A8)(arg0) != 0) { + sp10[0] = 0; + sp10[1] = 0; + sp10[2] = 0; + t = *(s16 *)(arg0 + 0x26); + sp18[0] = t; + sp18[1] = 0; + t = *(s16 *)(arg0 + 0x2E); + sp18[2] = t; + D_80182594[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 1); + ((void (*)(s32))func_8015A264)(arg0); + t = -(((s32 (*)(s16 *, s16 *))func_80013294)(sp10, sp18) << 0x10); + if (t < *(s32 *)(arg0 + 0x2C)) { + *(s32 *)(arg0 + 0x2C) = t; + } + return; + } + if (*(u16 *)(arg0 + 0xB8) == 0x8000) { + D_80182594[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 0); + ((void (*)(s32))func_80159B70)(arg0); + return; + } + z = *(s32 *)(arg0 + 0x2C); + if (func_8016F1AC() != 0) { + goto zero; + } + if (z <= lim) { + goto one; + } + if (D_8011F9C4 == 0) { + goto zero; + } + if (((u8)func_80029178(0x21)) != 0) { + goto zero; + } +one: + doit = 1; + goto join; +zero: + doit = 0; +join: + if (doit != 0) { + D_80182594[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 0); + ((void (*)(s32))func_80159B70)(arg0); + func_80154150(arg0, 9); + ((void (*)(s32, s32 *))func_80146DB8)(arg0, &D_80182528); + ((void (*)(s32, s32))func_80161CD0)(arg0, *(u16 *)(arg0 + 0x16E)); + return; + } + if (func_80161208(arg0) == 0) { + ((void (*)(s32))func_801725A4)(arg0); + } +} DEFINE_func_8015BD8C() /* dedup: shared engine-core @0x8015BD8C (src/shared) */ diff --git a/src/ov_SC03_011/ov_SC03_011_jr_8015AE2C.c b/src/ov_SC03_011/ov_SC03_011_jr_8015AE2C.c index dddcadfae..8a4366263 100644 --- a/src/ov_SC03_011/ov_SC03_011_jr_8015AE2C.c +++ b/src/ov_SC03_011/ov_SC03_011_jr_8015AE2C.c @@ -1513,7 +1513,259 @@ DEFINE_func_8015B858() /* dedup: shared engine-core @0x8015B858 (src/shared) */ DEFINE_func_8015B8F8() /* dedup: shared engine-core @0x8015B8F8 (src/shared) */ -INCLUDE_ASM("asm/ov_SC03_011/nonmatchings/ov_SC03_011_jr_8015AE2C", func_8015B950); +extern s32 func_8015AE2C(); + +// @class: plumbing +// @stuck: none — MATCH (271/271, pin-free, zero asm). The ONLY residual is DEF-SIDE plumbing, and it is now named exactly: the in-TU instantiation `DEFINE_func_8015BEE4()` (engine_core.h:1851-1855) expands to `extern s32 func_8015B950(void);` INSIDE ov_SC01_077_jr_8015AE2C.c, ~14 lines BELOW this definition, so the 1-param def collides with a `(void)` prototype -> `conflicting types for func_8015B950` (.run/bank_func_8015B950.log). §73 PARAMS axis / T0. Surgical fix = §65b de-macroize that ONE instantiation (blast radius: this TU); the fleet-wide `(void)`->`()` header edit is §63 and must be R22-validated. +/* func_8015B950 (ov_SC01_077_jr_8015AE2C, 271 ins, jtbl_801D8B74) — SESSION-21 re-verified + * + * ── ROUND-2 INDEPENDENT RE-VERIFICATION (2026-07-27, fresh agent, §88e discipline) ───────────── + * match_one : MATCH (271 ins) against the CURRENT tree — §87 staleness re-checked today. + * .text size: compiled .text = 0x43C = 1084 B = 271 ins, EXACTLY the target's declared 0x43C + * ("nonmatching func_8015B950, 0x43C"). So this is NOT a §83a length drift hiding + * behind a zero count — the count is over equal-length streams. + * jtbl : RE-DECODED MECHANICALLY, not inherited. Compiled .rodata = 0x1C = 28 B = 7 words, + * 7x R_MIPS_32 -> .text with implicit addends [58,58,58,E0,F0,100,58]; +0x8015B950 + * = [8015B9A8, 8015B9A8, 8015B9A8, 8015BA30, 8015BA40, 8015BA50, 8015B9A8]. + * Diffed word-for-word against asm/ov_SC01_077/data/tail14.data.s:15-23 — 7/7 identical. + * symcheck : SYMS-DIFF target=35 draft=34, sole MISSING = jtbl_801D8B74. This is the §81 jr + * FALSE POSITIVE, re-confirmed here by reading the relocs: gcc emits its OWN table and + * references it with R_MIPS_HI16/LO16 against the SECTION `.rodata` (t.o +0x40/+0x48), + * so the splat's dlabel NAME can never appear in the draft object's relocation set. + * Nothing is dropped and nothing is invented: the draft's other 34 symbols are exactly + * the target's other 34. + * FAMILY : the x138 remap is clean and §84-safe. Every sibling is 271 ins with an IDENTICAL + * callee set; only THREE names vary per overlay — the two data labels and the jtbl: + * ov_SC01_077 D_80183898 / D_80183904 / jtbl_801D8B74 + * ov_SC03_099 D_80185A50 / D_80185ABC / jtbl_801BD898 + * ov_SC06_008 D_80187E44 / D_80187EB0 / jtbl_801A8734 + * The pair is always +0x6C apart, and NO literal in this draft encodes that distance + * (both labels are referenced by name), so there is no §84 derived-offset hazard. + * D_8011F9C4 is fleet-constant (main-EXE data) and must NOT be remapped. + * + * match_one: MATCH (271 ins) against the CURRENT tree (§87 staleness re-checked, 2026-07-27). + * PIN-FREE, zero asm, offset-pure (s32 arg0 + raw offsets) — x138 template-safe. + * Provenance: this is the Phase-26 crack (.run/phase26-cracks/func_8015B950.c) re-gated verbatim, + * with ONE deliberate change: the definition's return type void -> s32. + * - `void func_8015B950(s32 arg0)` : MATCH (271 ins) [the Phase-26 form] + * - `s32 func_8015B950(s32 arg0)` : MATCH (271 ins) [shipped — §3a-1 void->s32 is byte-neutral] + * The fleet/engine_core.h canonical decl is `extern s32 func_8015B950(void);` (engine_core.h:1852), + * and the last bank attempt (.run/bank_func_8015B950.log) died on `conflicting types for + * func_8015B950`. Shipping the s32 return kills the §73 RETURN axis for free and leaves only the + * cheap T0 PARAMS axis for the ladder (fix_header_decl.py / --fix-def-sig / cast_call_sites). + * Both forms are byte-identical, so the orchestrator may swap the return type back at zero cost. + * + * SYMBOLS (§58 rules 1/2 — all splat spellings, all verified present): + * D_80183904 asm/ov_SC01_077/data/tail.data.s:4355 (the state-handler vtable) + * D_80183898 asm/ov_SC01_077/data/tail.data.s:4293 + * D_8011F9C4 main-EXE data; spelled `extern s32 D_8011F9C4;` in 5+ already-banked TUs + * jtbl_801D8B74 asm/ov_SC01_077/data/tail14.data.s:15 (compiler jump table — not named in C) + * + * JTBL VERIFIED (§8a gate): compiled .rodata = exactly 0x1C B / 7 words, 7x R_MIPS_32 .text with + * addends [0x58,0x58,0x58,0xE0,0xF0,0x100,0x58] -> +0x8015B950 = [B9A8,B9A8,B9A8,BA30,BA40,BA50, + * B9A8] == the original words at 0x801D8B74..0x801D8B8C. Bound `sltiu $v0,$v1,0x7` matches. + * The raw dlabel's 8th word 0x00000000 is NOT an entry — it is the intra-TU `.align 3` pad of the + * B34/B54/B74 jtbl chain; the object can never emit it (maspsx drops .align), so it must stay in + * the post-carve RAW data piece (the §53/§62/§81 carve chain applies at bank time). + * + * Same family as the TU's own already-matched func_8015AE2C: 7-case switch on ((s32 (*)(s32))func_801619A4)() + * (0/1/2/6 shared, 3/4/5 own, no default block — out-of-range and every `break` fall to the + * after-switch join), then a chain of "state handler" tests, each dispatching + * D_80183904[*(u16*)arg0](arg0) and returning. + * + * THREE LEVERS (draft -> MATCH in 3 compiles): + * + * 1. PROLOGUE CONSTANT = an INITIALIZED LOCAL, not a literal in the compare. + * Target opens with `lui $s2, 0xFFF5` in the *prologue*, used once ~200 ins later in + * `slt $v0,$s2,$s1`. No gcc-2.7.2 pass hoists a (set reg const_int) across basic blocks + * (loop.c needs a loop; cse/combine/sched never move insns between BBs) — so the insn must + * have been EMITTED in the first BB, i.e. the constant is a local initialized at the top of + * the function. cse then cannot fold it back into the compare: the `slt` operand predicate is + * `arith_operand`, which rejects a CONST_INT wider than 16 bits, so validate_change fails and + * the pseudo survives. Its live range spans every call -> global.c gives it a callee-saved reg. + * Writing `z > -0xB0000` inline instead emits the `lui` into the branch delay slot next to the + * compare (caller-saved $v0) and the function is 1 insn short. => `s32 lim = -0xB0000;` at top. + * + * 2. `lh` vs `lhu`: a short->short copy is a pure HImode move and gcc emits `lhu`. The target's + * `lh $v0,0x26($s0)` means the value passed through an SImode (int) temp: expand makes + * (set (reg:SI) (sign_extend (mem:HI))) + (set (mem:HI) (subreg:HI ...)), and combine cannot + * merge them (the merged form is mem<-mem, which no movhi accepts) so the sign-extending load + * survives. => route both halfword copies through the `s32 t` temp. + * + * 3. THE `goto` LAYOUT — dodging jump.c's store-flag conversion (jump.c:1005-1065). + * An if/else chain writing 0/1 into `doit` makes gcc collapse the last pair into + * `sltiu $v0,$v0,1`. jump.c fires that conversion when the insn immediately after a + * conditional jump is a lone `SET pseudo, CONST_INT` whose following simplejump targets the + * SAME label as the branch (jump.c:1038 `reallabelprev == temp || ... JUMP_LABEL(temp4) == + * JUMP_LABEL(insn)`) — exactly the shape of `if (c) x=0; else x=1;`. + * The target instead cross-jumps ALL the `doit=0` exits into ONE shared block placed after the + * `doit=1` fall-through; reorg's fill_slots_from_thread then COPIES that single set into all + * three branch delay slots and redirects each branch past it (which is why `addu $v0,$zero, + * $zero` appears 3x in delay slots and the shared block vanishes). A `goto zero;` / `goto one;` + * chain expresses that layout directly, and each conditional jump is then followed by a + * compare/call rather than a lone const set, so the store-flag conversion never triggers. + * GENERAL RULE: multiple predicates that all assign the SAME constant to one flag => write + * them as `goto` to a shared assignment, never as an if/else ladder. + */ +extern s32 D_8011F9C4; +extern s32 D_80183898; + +extern s32 func_80161B18(void); +extern s32 func_801619A4(s32*); +extern s32 func_80149AA8(s32*); +extern void func_80149AD4(s32*); +extern s32 func_80149B54(s32*); +extern void func_80149BAC(s32*); +extern s32 func_801498E0(s32*); +extern s32 func_80149954(s32); +extern s32 func_80149A64(s32*); +extern void func_800CCCC0(s32 a0); +extern s32 func_80149CD4(s32 a0); +extern void func_8015E880(s32*); +extern s32 func_80149744(struct S_80149744*); +extern void func_80149788(void); +extern s32 func_801496D4(void*); +extern void func_80149704(void); +extern int func_80148AFC(void*); +extern void func_80146D90(s32 a0); +extern void func_80154150(s32 a0, s32 a1); +extern void func_801541D8(u8*, s32, s32); +extern s32 func_801488A8(u8*); +extern void func_80147078(s32*, s16); +extern void func_8015A264(void*); +extern s32 func_80013294(void*, void*); +extern void func_80159B70(void*); +extern s32 func_8016F1AC(void); +extern s32 func_80029178(s32 a0); +extern void func_80146DB8(s32*, s32*); +extern s32 func_80161CD0(s32, s32); +extern s32 func_80161208(s32 a0); +extern s32 func_801725A4(u8*); + +s32 func_8015B950(s32 arg0) +{ + + extern void (*D_80183904[])(void *); + s16 sp10[4]; + s16 sp18[4]; + s32 t; + s32 z; + s32 doit; + s32 lim = -0xB0000; + + if (func_80161B18() != 0) { + return; + } + switch (((s32 (*)(s32))func_801619A4)(arg0)) { + case 0: + case 1: + case 2: + case 6: + if (((s32 (*)(s32))func_80149AA8)(arg0) != 0) { + D_80183904[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149AD4)(arg0); + return; + } + if (((s32 (*)(s32))func_80149B54)(arg0) != 0) { + D_80183904[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149BAC)(arg0); + return; + } + break; + case 3: + ((void (*)(s32))func_801498E0)(arg0); + break; + case 4: + ((void (*)(s32))func_80149954)(arg0); + break; + case 5: + if (((s32 (*)(s32))func_80149A64)(arg0) != 0) { + D_80183904[*(u16 *)arg0]((void *)arg0); + func_800CCCC0(arg0); + return; + } + break; + } + if (func_80149CD4(arg0) != 0) { + D_80183904[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_8015E880)(arg0); + return; + } + if (((s32 (*)(s32))func_80149744)(arg0) != 0) { + D_80183904[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149788)(arg0); + return; + } + if (((s32 (*)(s32))func_801496D4)(arg0) != 0) { + D_80183904[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149704)(arg0); + if (((u8)((s32 (*)(s32))func_80148AFC)(arg0)) == 0) { + func_80146D90(arg0); + } + if ((*(s32 *)(arg0 + 0x24) | *(s32 *)(arg0 + 0x2C)) != 0) { + func_80154150(arg0, 0xF); + } else { + ((void (*)(s32, s32, s32))func_801541D8)(arg0, 0xD, 6); + } + *(s32 *)(arg0 + 0x238) = 1; + return; + } + if (((s32 (*)(s32))func_801488A8)(arg0) != 0) { + sp10[0] = 0; + sp10[1] = 0; + sp10[2] = 0; + t = *(s16 *)(arg0 + 0x26); + sp18[0] = t; + sp18[1] = 0; + t = *(s16 *)(arg0 + 0x2E); + sp18[2] = t; + D_80183904[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 1); + ((void (*)(s32))func_8015A264)(arg0); + t = -(((s32 (*)(s16 *, s16 *))func_80013294)(sp10, sp18) << 0x10); + if (t < *(s32 *)(arg0 + 0x2C)) { + *(s32 *)(arg0 + 0x2C) = t; + } + return; + } + if (*(u16 *)(arg0 + 0xB8) == 0x8000) { + D_80183904[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 0); + ((void (*)(s32))func_80159B70)(arg0); + return; + } + z = *(s32 *)(arg0 + 0x2C); + if (func_8016F1AC() != 0) { + goto zero; + } + if (z <= lim) { + goto one; + } + if (D_8011F9C4 == 0) { + goto zero; + } + if (((u8)func_80029178(0x21)) != 0) { + goto zero; + } +one: + doit = 1; + goto join; +zero: + doit = 0; +join: + if (doit != 0) { + D_80183904[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 0); + ((void (*)(s32))func_80159B70)(arg0); + func_80154150(arg0, 9); + ((void (*)(s32, s32 *))func_80146DB8)(arg0, &D_80183898); + ((void (*)(s32, s32))func_80161CD0)(arg0, *(u16 *)(arg0 + 0x16E)); + return; + } + if (func_80161208(arg0) == 0) { + ((void (*)(s32))func_801725A4)(arg0); + } +} DEFINE_func_8015BD8C() /* dedup: shared engine-core @0x8015BD8C (src/shared) */ diff --git a/src/ov_SC03_012/ov_SC03_012_jr_8015AE2C.c b/src/ov_SC03_012/ov_SC03_012_jr_8015AE2C.c index b6a78ebfc..9d7c38441 100644 --- a/src/ov_SC03_012/ov_SC03_012_jr_8015AE2C.c +++ b/src/ov_SC03_012/ov_SC03_012_jr_8015AE2C.c @@ -1513,7 +1513,259 @@ DEFINE_func_8015B858() /* dedup: shared engine-core @0x8015B858 (src/shared) */ DEFINE_func_8015B8F8() /* dedup: shared engine-core @0x8015B8F8 (src/shared) */ -INCLUDE_ASM("asm/ov_SC03_012/nonmatchings/ov_SC03_012_jr_8015AE2C", func_8015B950); +extern s32 func_8015AE2C(); + +// @class: plumbing +// @stuck: none — MATCH (271/271, pin-free, zero asm). The ONLY residual is DEF-SIDE plumbing, and it is now named exactly: the in-TU instantiation `DEFINE_func_8015BEE4()` (engine_core.h:1851-1855) expands to `extern s32 func_8015B950(void);` INSIDE ov_SC01_077_jr_8015AE2C.c, ~14 lines BELOW this definition, so the 1-param def collides with a `(void)` prototype -> `conflicting types for func_8015B950` (.run/bank_func_8015B950.log). §73 PARAMS axis / T0. Surgical fix = §65b de-macroize that ONE instantiation (blast radius: this TU); the fleet-wide `(void)`->`()` header edit is §63 and must be R22-validated. +/* func_8015B950 (ov_SC01_077_jr_8015AE2C, 271 ins, jtbl_801D8B74) — SESSION-21 re-verified + * + * ── ROUND-2 INDEPENDENT RE-VERIFICATION (2026-07-27, fresh agent, §88e discipline) ───────────── + * match_one : MATCH (271 ins) against the CURRENT tree — §87 staleness re-checked today. + * .text size: compiled .text = 0x43C = 1084 B = 271 ins, EXACTLY the target's declared 0x43C + * ("nonmatching func_8015B950, 0x43C"). So this is NOT a §83a length drift hiding + * behind a zero count — the count is over equal-length streams. + * jtbl : RE-DECODED MECHANICALLY, not inherited. Compiled .rodata = 0x1C = 28 B = 7 words, + * 7x R_MIPS_32 -> .text with implicit addends [58,58,58,E0,F0,100,58]; +0x8015B950 + * = [8015B9A8, 8015B9A8, 8015B9A8, 8015BA30, 8015BA40, 8015BA50, 8015B9A8]. + * Diffed word-for-word against asm/ov_SC01_077/data/tail14.data.s:15-23 — 7/7 identical. + * symcheck : SYMS-DIFF target=35 draft=34, sole MISSING = jtbl_801D8B74. This is the §81 jr + * FALSE POSITIVE, re-confirmed here by reading the relocs: gcc emits its OWN table and + * references it with R_MIPS_HI16/LO16 against the SECTION `.rodata` (t.o +0x40/+0x48), + * so the splat's dlabel NAME can never appear in the draft object's relocation set. + * Nothing is dropped and nothing is invented: the draft's other 34 symbols are exactly + * the target's other 34. + * FAMILY : the x138 remap is clean and §84-safe. Every sibling is 271 ins with an IDENTICAL + * callee set; only THREE names vary per overlay — the two data labels and the jtbl: + * ov_SC01_077 D_80180778 / D_801807E4 / jtbl_801D8B74 + * ov_SC03_099 D_80185A50 / D_80185ABC / jtbl_801BD898 + * ov_SC06_008 D_80187E44 / D_80187EB0 / jtbl_801A8734 + * The pair is always +0x6C apart, and NO literal in this draft encodes that distance + * (both labels are referenced by name), so there is no §84 derived-offset hazard. + * D_8011F9C4 is fleet-constant (main-EXE data) and must NOT be remapped. + * + * match_one: MATCH (271 ins) against the CURRENT tree (§87 staleness re-checked, 2026-07-27). + * PIN-FREE, zero asm, offset-pure (s32 arg0 + raw offsets) — x138 template-safe. + * Provenance: this is the Phase-26 crack (.run/phase26-cracks/func_8015B950.c) re-gated verbatim, + * with ONE deliberate change: the definition's return type void -> s32. + * - `void func_8015B950(s32 arg0)` : MATCH (271 ins) [the Phase-26 form] + * - `s32 func_8015B950(s32 arg0)` : MATCH (271 ins) [shipped — §3a-1 void->s32 is byte-neutral] + * The fleet/engine_core.h canonical decl is `extern s32 func_8015B950(void);` (engine_core.h:1852), + * and the last bank attempt (.run/bank_func_8015B950.log) died on `conflicting types for + * func_8015B950`. Shipping the s32 return kills the §73 RETURN axis for free and leaves only the + * cheap T0 PARAMS axis for the ladder (fix_header_decl.py / --fix-def-sig / cast_call_sites). + * Both forms are byte-identical, so the orchestrator may swap the return type back at zero cost. + * + * SYMBOLS (§58 rules 1/2 — all splat spellings, all verified present): + * D_801807E4 asm/ov_SC01_077/data/tail.data.s:4355 (the state-handler vtable) + * D_80180778 asm/ov_SC01_077/data/tail.data.s:4293 + * D_8011F9C4 main-EXE data; spelled `extern s32 D_8011F9C4;` in 5+ already-banked TUs + * jtbl_801D8B74 asm/ov_SC01_077/data/tail14.data.s:15 (compiler jump table — not named in C) + * + * JTBL VERIFIED (§8a gate): compiled .rodata = exactly 0x1C B / 7 words, 7x R_MIPS_32 .text with + * addends [0x58,0x58,0x58,0xE0,0xF0,0x100,0x58] -> +0x8015B950 = [B9A8,B9A8,B9A8,BA30,BA40,BA50, + * B9A8] == the original words at 0x801D8B74..0x801D8B8C. Bound `sltiu $v0,$v1,0x7` matches. + * The raw dlabel's 8th word 0x00000000 is NOT an entry — it is the intra-TU `.align 3` pad of the + * B34/B54/B74 jtbl chain; the object can never emit it (maspsx drops .align), so it must stay in + * the post-carve RAW data piece (the §53/§62/§81 carve chain applies at bank time). + * + * Same family as the TU's own already-matched func_8015AE2C: 7-case switch on ((s32 (*)(s32))func_801619A4)() + * (0/1/2/6 shared, 3/4/5 own, no default block — out-of-range and every `break` fall to the + * after-switch join), then a chain of "state handler" tests, each dispatching + * D_801807E4[*(u16*)arg0](arg0) and returning. + * + * THREE LEVERS (draft -> MATCH in 3 compiles): + * + * 1. PROLOGUE CONSTANT = an INITIALIZED LOCAL, not a literal in the compare. + * Target opens with `lui $s2, 0xFFF5` in the *prologue*, used once ~200 ins later in + * `slt $v0,$s2,$s1`. No gcc-2.7.2 pass hoists a (set reg const_int) across basic blocks + * (loop.c needs a loop; cse/combine/sched never move insns between BBs) — so the insn must + * have been EMITTED in the first BB, i.e. the constant is a local initialized at the top of + * the function. cse then cannot fold it back into the compare: the `slt` operand predicate is + * `arith_operand`, which rejects a CONST_INT wider than 16 bits, so validate_change fails and + * the pseudo survives. Its live range spans every call -> global.c gives it a callee-saved reg. + * Writing `z > -0xB0000` inline instead emits the `lui` into the branch delay slot next to the + * compare (caller-saved $v0) and the function is 1 insn short. => `s32 lim = -0xB0000;` at top. + * + * 2. `lh` vs `lhu`: a short->short copy is a pure HImode move and gcc emits `lhu`. The target's + * `lh $v0,0x26($s0)` means the value passed through an SImode (int) temp: expand makes + * (set (reg:SI) (sign_extend (mem:HI))) + (set (mem:HI) (subreg:HI ...)), and combine cannot + * merge them (the merged form is mem<-mem, which no movhi accepts) so the sign-extending load + * survives. => route both halfword copies through the `s32 t` temp. + * + * 3. THE `goto` LAYOUT — dodging jump.c's store-flag conversion (jump.c:1005-1065). + * An if/else chain writing 0/1 into `doit` makes gcc collapse the last pair into + * `sltiu $v0,$v0,1`. jump.c fires that conversion when the insn immediately after a + * conditional jump is a lone `SET pseudo, CONST_INT` whose following simplejump targets the + * SAME label as the branch (jump.c:1038 `reallabelprev == temp || ... JUMP_LABEL(temp4) == + * JUMP_LABEL(insn)`) — exactly the shape of `if (c) x=0; else x=1;`. + * The target instead cross-jumps ALL the `doit=0` exits into ONE shared block placed after the + * `doit=1` fall-through; reorg's fill_slots_from_thread then COPIES that single set into all + * three branch delay slots and redirects each branch past it (which is why `addu $v0,$zero, + * $zero` appears 3x in delay slots and the shared block vanishes). A `goto zero;` / `goto one;` + * chain expresses that layout directly, and each conditional jump is then followed by a + * compare/call rather than a lone const set, so the store-flag conversion never triggers. + * GENERAL RULE: multiple predicates that all assign the SAME constant to one flag => write + * them as `goto` to a shared assignment, never as an if/else ladder. + */ +extern s32 D_8011F9C4; +extern s32 D_80180778; + +extern s32 func_80161B18(void); +extern s32 func_801619A4(s32*); +extern s32 func_80149AA8(s32*); +extern void func_80149AD4(s32*); +extern s32 func_80149B54(s32*); +extern void func_80149BAC(s32*); +extern s32 func_801498E0(s32*); +extern s32 func_80149954(s32); +extern s32 func_80149A64(s32*); +extern void func_800CCCC0(s32 a0); +extern s32 func_80149CD4(s32 a0); +extern void func_8015E880(s32*); +extern s32 func_80149744(struct S_80149744*); +extern void func_80149788(void); +extern s32 func_801496D4(void*); +extern void func_80149704(void); +extern int func_80148AFC(void*); +extern void func_80146D90(s32 a0); +extern void func_80154150(s32 a0, s32 a1); +extern void func_801541D8(u8*, s32, s32); +extern s32 func_801488A8(u8*); +extern void func_80147078(s32*, s16); +extern void func_8015A264(void*); +extern s32 func_80013294(void*, void*); +extern void func_80159B70(void*); +extern s32 func_8016F1AC(void); +extern s32 func_80029178(s32 a0); +extern void func_80146DB8(s32*, s32*); +extern s32 func_80161CD0(s32, s32); +extern s32 func_80161208(s32 a0); +extern s32 func_801725A4(u8*); + +s32 func_8015B950(s32 arg0) +{ + + extern void (*D_801807E4[])(void *); + s16 sp10[4]; + s16 sp18[4]; + s32 t; + s32 z; + s32 doit; + s32 lim = -0xB0000; + + if (func_80161B18() != 0) { + return; + } + switch (((s32 (*)(s32))func_801619A4)(arg0)) { + case 0: + case 1: + case 2: + case 6: + if (((s32 (*)(s32))func_80149AA8)(arg0) != 0) { + D_801807E4[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149AD4)(arg0); + return; + } + if (((s32 (*)(s32))func_80149B54)(arg0) != 0) { + D_801807E4[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149BAC)(arg0); + return; + } + break; + case 3: + ((void (*)(s32))func_801498E0)(arg0); + break; + case 4: + ((void (*)(s32))func_80149954)(arg0); + break; + case 5: + if (((s32 (*)(s32))func_80149A64)(arg0) != 0) { + D_801807E4[*(u16 *)arg0]((void *)arg0); + func_800CCCC0(arg0); + return; + } + break; + } + if (func_80149CD4(arg0) != 0) { + D_801807E4[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_8015E880)(arg0); + return; + } + if (((s32 (*)(s32))func_80149744)(arg0) != 0) { + D_801807E4[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149788)(arg0); + return; + } + if (((s32 (*)(s32))func_801496D4)(arg0) != 0) { + D_801807E4[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149704)(arg0); + if (((u8)((s32 (*)(s32))func_80148AFC)(arg0)) == 0) { + func_80146D90(arg0); + } + if ((*(s32 *)(arg0 + 0x24) | *(s32 *)(arg0 + 0x2C)) != 0) { + func_80154150(arg0, 0xF); + } else { + ((void (*)(s32, s32, s32))func_801541D8)(arg0, 0xD, 6); + } + *(s32 *)(arg0 + 0x238) = 1; + return; + } + if (((s32 (*)(s32))func_801488A8)(arg0) != 0) { + sp10[0] = 0; + sp10[1] = 0; + sp10[2] = 0; + t = *(s16 *)(arg0 + 0x26); + sp18[0] = t; + sp18[1] = 0; + t = *(s16 *)(arg0 + 0x2E); + sp18[2] = t; + D_801807E4[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 1); + ((void (*)(s32))func_8015A264)(arg0); + t = -(((s32 (*)(s16 *, s16 *))func_80013294)(sp10, sp18) << 0x10); + if (t < *(s32 *)(arg0 + 0x2C)) { + *(s32 *)(arg0 + 0x2C) = t; + } + return; + } + if (*(u16 *)(arg0 + 0xB8) == 0x8000) { + D_801807E4[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 0); + ((void (*)(s32))func_80159B70)(arg0); + return; + } + z = *(s32 *)(arg0 + 0x2C); + if (func_8016F1AC() != 0) { + goto zero; + } + if (z <= lim) { + goto one; + } + if (D_8011F9C4 == 0) { + goto zero; + } + if (((u8)func_80029178(0x21)) != 0) { + goto zero; + } +one: + doit = 1; + goto join; +zero: + doit = 0; +join: + if (doit != 0) { + D_801807E4[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 0); + ((void (*)(s32))func_80159B70)(arg0); + func_80154150(arg0, 9); + ((void (*)(s32, s32 *))func_80146DB8)(arg0, &D_80180778); + ((void (*)(s32, s32))func_80161CD0)(arg0, *(u16 *)(arg0 + 0x16E)); + return; + } + if (func_80161208(arg0) == 0) { + ((void (*)(s32))func_801725A4)(arg0); + } +} DEFINE_func_8015BD8C() /* dedup: shared engine-core @0x8015BD8C (src/shared) */ diff --git a/src/ov_SC03_013/ov_SC03_013_jr_8015AE2C.c b/src/ov_SC03_013/ov_SC03_013_jr_8015AE2C.c index e462ea870..d7cb5d9e6 100644 --- a/src/ov_SC03_013/ov_SC03_013_jr_8015AE2C.c +++ b/src/ov_SC03_013/ov_SC03_013_jr_8015AE2C.c @@ -1513,7 +1513,259 @@ DEFINE_func_8015B858() /* dedup: shared engine-core @0x8015B858 (src/shared) */ DEFINE_func_8015B8F8() /* dedup: shared engine-core @0x8015B8F8 (src/shared) */ -INCLUDE_ASM("asm/ov_SC03_013/nonmatchings/ov_SC03_013_jr_8015AE2C", func_8015B950); +extern s32 func_8015AE2C(); + +// @class: plumbing +// @stuck: none — MATCH (271/271, pin-free, zero asm). The ONLY residual is DEF-SIDE plumbing, and it is now named exactly: the in-TU instantiation `DEFINE_func_8015BEE4()` (engine_core.h:1851-1855) expands to `extern s32 func_8015B950(void);` INSIDE ov_SC01_077_jr_8015AE2C.c, ~14 lines BELOW this definition, so the 1-param def collides with a `(void)` prototype -> `conflicting types for func_8015B950` (.run/bank_func_8015B950.log). §73 PARAMS axis / T0. Surgical fix = §65b de-macroize that ONE instantiation (blast radius: this TU); the fleet-wide `(void)`->`()` header edit is §63 and must be R22-validated. +/* func_8015B950 (ov_SC01_077_jr_8015AE2C, 271 ins, jtbl_801D8B74) — SESSION-21 re-verified + * + * ── ROUND-2 INDEPENDENT RE-VERIFICATION (2026-07-27, fresh agent, §88e discipline) ───────────── + * match_one : MATCH (271 ins) against the CURRENT tree — §87 staleness re-checked today. + * .text size: compiled .text = 0x43C = 1084 B = 271 ins, EXACTLY the target's declared 0x43C + * ("nonmatching func_8015B950, 0x43C"). So this is NOT a §83a length drift hiding + * behind a zero count — the count is over equal-length streams. + * jtbl : RE-DECODED MECHANICALLY, not inherited. Compiled .rodata = 0x1C = 28 B = 7 words, + * 7x R_MIPS_32 -> .text with implicit addends [58,58,58,E0,F0,100,58]; +0x8015B950 + * = [8015B9A8, 8015B9A8, 8015B9A8, 8015BA30, 8015BA40, 8015BA50, 8015B9A8]. + * Diffed word-for-word against asm/ov_SC01_077/data/tail14.data.s:15-23 — 7/7 identical. + * symcheck : SYMS-DIFF target=35 draft=34, sole MISSING = jtbl_801D8B74. This is the §81 jr + * FALSE POSITIVE, re-confirmed here by reading the relocs: gcc emits its OWN table and + * references it with R_MIPS_HI16/LO16 against the SECTION `.rodata` (t.o +0x40/+0x48), + * so the splat's dlabel NAME can never appear in the draft object's relocation set. + * Nothing is dropped and nothing is invented: the draft's other 34 symbols are exactly + * the target's other 34. + * FAMILY : the x138 remap is clean and §84-safe. Every sibling is 271 ins with an IDENTICAL + * callee set; only THREE names vary per overlay — the two data labels and the jtbl: + * ov_SC01_077 D_80183560 / D_801835CC / jtbl_801D8B74 + * ov_SC03_099 D_80185A50 / D_80185ABC / jtbl_801BD898 + * ov_SC06_008 D_80187E44 / D_80187EB0 / jtbl_801A8734 + * The pair is always +0x6C apart, and NO literal in this draft encodes that distance + * (both labels are referenced by name), so there is no §84 derived-offset hazard. + * D_8011F9C4 is fleet-constant (main-EXE data) and must NOT be remapped. + * + * match_one: MATCH (271 ins) against the CURRENT tree (§87 staleness re-checked, 2026-07-27). + * PIN-FREE, zero asm, offset-pure (s32 arg0 + raw offsets) — x138 template-safe. + * Provenance: this is the Phase-26 crack (.run/phase26-cracks/func_8015B950.c) re-gated verbatim, + * with ONE deliberate change: the definition's return type void -> s32. + * - `void func_8015B950(s32 arg0)` : MATCH (271 ins) [the Phase-26 form] + * - `s32 func_8015B950(s32 arg0)` : MATCH (271 ins) [shipped — §3a-1 void->s32 is byte-neutral] + * The fleet/engine_core.h canonical decl is `extern s32 func_8015B950(void);` (engine_core.h:1852), + * and the last bank attempt (.run/bank_func_8015B950.log) died on `conflicting types for + * func_8015B950`. Shipping the s32 return kills the §73 RETURN axis for free and leaves only the + * cheap T0 PARAMS axis for the ladder (fix_header_decl.py / --fix-def-sig / cast_call_sites). + * Both forms are byte-identical, so the orchestrator may swap the return type back at zero cost. + * + * SYMBOLS (§58 rules 1/2 — all splat spellings, all verified present): + * D_801835CC asm/ov_SC01_077/data/tail.data.s:4355 (the state-handler vtable) + * D_80183560 asm/ov_SC01_077/data/tail.data.s:4293 + * D_8011F9C4 main-EXE data; spelled `extern s32 D_8011F9C4;` in 5+ already-banked TUs + * jtbl_801D8B74 asm/ov_SC01_077/data/tail14.data.s:15 (compiler jump table — not named in C) + * + * JTBL VERIFIED (§8a gate): compiled .rodata = exactly 0x1C B / 7 words, 7x R_MIPS_32 .text with + * addends [0x58,0x58,0x58,0xE0,0xF0,0x100,0x58] -> +0x8015B950 = [B9A8,B9A8,B9A8,BA30,BA40,BA50, + * B9A8] == the original words at 0x801D8B74..0x801D8B8C. Bound `sltiu $v0,$v1,0x7` matches. + * The raw dlabel's 8th word 0x00000000 is NOT an entry — it is the intra-TU `.align 3` pad of the + * B34/B54/B74 jtbl chain; the object can never emit it (maspsx drops .align), so it must stay in + * the post-carve RAW data piece (the §53/§62/§81 carve chain applies at bank time). + * + * Same family as the TU's own already-matched func_8015AE2C: 7-case switch on ((s32 (*)(s32))func_801619A4)() + * (0/1/2/6 shared, 3/4/5 own, no default block — out-of-range and every `break` fall to the + * after-switch join), then a chain of "state handler" tests, each dispatching + * D_801835CC[*(u16*)arg0](arg0) and returning. + * + * THREE LEVERS (draft -> MATCH in 3 compiles): + * + * 1. PROLOGUE CONSTANT = an INITIALIZED LOCAL, not a literal in the compare. + * Target opens with `lui $s2, 0xFFF5` in the *prologue*, used once ~200 ins later in + * `slt $v0,$s2,$s1`. No gcc-2.7.2 pass hoists a (set reg const_int) across basic blocks + * (loop.c needs a loop; cse/combine/sched never move insns between BBs) — so the insn must + * have been EMITTED in the first BB, i.e. the constant is a local initialized at the top of + * the function. cse then cannot fold it back into the compare: the `slt` operand predicate is + * `arith_operand`, which rejects a CONST_INT wider than 16 bits, so validate_change fails and + * the pseudo survives. Its live range spans every call -> global.c gives it a callee-saved reg. + * Writing `z > -0xB0000` inline instead emits the `lui` into the branch delay slot next to the + * compare (caller-saved $v0) and the function is 1 insn short. => `s32 lim = -0xB0000;` at top. + * + * 2. `lh` vs `lhu`: a short->short copy is a pure HImode move and gcc emits `lhu`. The target's + * `lh $v0,0x26($s0)` means the value passed through an SImode (int) temp: expand makes + * (set (reg:SI) (sign_extend (mem:HI))) + (set (mem:HI) (subreg:HI ...)), and combine cannot + * merge them (the merged form is mem<-mem, which no movhi accepts) so the sign-extending load + * survives. => route both halfword copies through the `s32 t` temp. + * + * 3. THE `goto` LAYOUT — dodging jump.c's store-flag conversion (jump.c:1005-1065). + * An if/else chain writing 0/1 into `doit` makes gcc collapse the last pair into + * `sltiu $v0,$v0,1`. jump.c fires that conversion when the insn immediately after a + * conditional jump is a lone `SET pseudo, CONST_INT` whose following simplejump targets the + * SAME label as the branch (jump.c:1038 `reallabelprev == temp || ... JUMP_LABEL(temp4) == + * JUMP_LABEL(insn)`) — exactly the shape of `if (c) x=0; else x=1;`. + * The target instead cross-jumps ALL the `doit=0` exits into ONE shared block placed after the + * `doit=1` fall-through; reorg's fill_slots_from_thread then COPIES that single set into all + * three branch delay slots and redirects each branch past it (which is why `addu $v0,$zero, + * $zero` appears 3x in delay slots and the shared block vanishes). A `goto zero;` / `goto one;` + * chain expresses that layout directly, and each conditional jump is then followed by a + * compare/call rather than a lone const set, so the store-flag conversion never triggers. + * GENERAL RULE: multiple predicates that all assign the SAME constant to one flag => write + * them as `goto` to a shared assignment, never as an if/else ladder. + */ +extern s32 D_8011F9C4; +extern s32 D_80183560; + +extern s32 func_80161B18(void); +extern s32 func_801619A4(s32*); +extern s32 func_80149AA8(s32*); +extern void func_80149AD4(s32*); +extern s32 func_80149B54(s32*); +extern void func_80149BAC(s32*); +extern s32 func_801498E0(s32*); +extern s32 func_80149954(s32); +extern s32 func_80149A64(s32*); +extern void func_800CCCC0(s32 a0); +extern s32 func_80149CD4(s32 a0); +extern void func_8015E880(s32*); +extern s32 func_80149744(struct S_80149744*); +extern void func_80149788(void); +extern s32 func_801496D4(void*); +extern void func_80149704(void); +extern int func_80148AFC(void*); +extern void func_80146D90(s32 a0); +extern void func_80154150(s32 a0, s32 a1); +extern void func_801541D8(u8*, s32, s32); +extern s32 func_801488A8(u8*); +extern void func_80147078(s32*, s16); +extern void func_8015A264(void*); +extern s32 func_80013294(void*, void*); +extern void func_80159B70(void*); +extern s32 func_8016F1AC(void); +extern s32 func_80029178(s32 a0); +extern void func_80146DB8(s32*, s32*); +extern s32 func_80161CD0(s32, s32); +extern s32 func_80161208(s32 a0); +extern s32 func_801725A4(u8*); + +s32 func_8015B950(s32 arg0) +{ + + extern void (*D_801835CC[])(void *); + s16 sp10[4]; + s16 sp18[4]; + s32 t; + s32 z; + s32 doit; + s32 lim = -0xB0000; + + if (func_80161B18() != 0) { + return; + } + switch (((s32 (*)(s32))func_801619A4)(arg0)) { + case 0: + case 1: + case 2: + case 6: + if (((s32 (*)(s32))func_80149AA8)(arg0) != 0) { + D_801835CC[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149AD4)(arg0); + return; + } + if (((s32 (*)(s32))func_80149B54)(arg0) != 0) { + D_801835CC[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149BAC)(arg0); + return; + } + break; + case 3: + ((void (*)(s32))func_801498E0)(arg0); + break; + case 4: + ((void (*)(s32))func_80149954)(arg0); + break; + case 5: + if (((s32 (*)(s32))func_80149A64)(arg0) != 0) { + D_801835CC[*(u16 *)arg0]((void *)arg0); + func_800CCCC0(arg0); + return; + } + break; + } + if (func_80149CD4(arg0) != 0) { + D_801835CC[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_8015E880)(arg0); + return; + } + if (((s32 (*)(s32))func_80149744)(arg0) != 0) { + D_801835CC[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149788)(arg0); + return; + } + if (((s32 (*)(s32))func_801496D4)(arg0) != 0) { + D_801835CC[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149704)(arg0); + if (((u8)((s32 (*)(s32))func_80148AFC)(arg0)) == 0) { + func_80146D90(arg0); + } + if ((*(s32 *)(arg0 + 0x24) | *(s32 *)(arg0 + 0x2C)) != 0) { + func_80154150(arg0, 0xF); + } else { + ((void (*)(s32, s32, s32))func_801541D8)(arg0, 0xD, 6); + } + *(s32 *)(arg0 + 0x238) = 1; + return; + } + if (((s32 (*)(s32))func_801488A8)(arg0) != 0) { + sp10[0] = 0; + sp10[1] = 0; + sp10[2] = 0; + t = *(s16 *)(arg0 + 0x26); + sp18[0] = t; + sp18[1] = 0; + t = *(s16 *)(arg0 + 0x2E); + sp18[2] = t; + D_801835CC[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 1); + ((void (*)(s32))func_8015A264)(arg0); + t = -(((s32 (*)(s16 *, s16 *))func_80013294)(sp10, sp18) << 0x10); + if (t < *(s32 *)(arg0 + 0x2C)) { + *(s32 *)(arg0 + 0x2C) = t; + } + return; + } + if (*(u16 *)(arg0 + 0xB8) == 0x8000) { + D_801835CC[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 0); + ((void (*)(s32))func_80159B70)(arg0); + return; + } + z = *(s32 *)(arg0 + 0x2C); + if (func_8016F1AC() != 0) { + goto zero; + } + if (z <= lim) { + goto one; + } + if (D_8011F9C4 == 0) { + goto zero; + } + if (((u8)func_80029178(0x21)) != 0) { + goto zero; + } +one: + doit = 1; + goto join; +zero: + doit = 0; +join: + if (doit != 0) { + D_801835CC[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 0); + ((void (*)(s32))func_80159B70)(arg0); + func_80154150(arg0, 9); + ((void (*)(s32, s32 *))func_80146DB8)(arg0, &D_80183560); + ((void (*)(s32, s32))func_80161CD0)(arg0, *(u16 *)(arg0 + 0x16E)); + return; + } + if (func_80161208(arg0) == 0) { + ((void (*)(s32))func_801725A4)(arg0); + } +} DEFINE_func_8015BD8C() /* dedup: shared engine-core @0x8015BD8C (src/shared) */ diff --git a/src/ov_SC03_014/ov_SC03_014_jr_8015AE2C.c b/src/ov_SC03_014/ov_SC03_014_jr_8015AE2C.c index 5eb57a0b4..d18d4a2d0 100644 --- a/src/ov_SC03_014/ov_SC03_014_jr_8015AE2C.c +++ b/src/ov_SC03_014/ov_SC03_014_jr_8015AE2C.c @@ -1513,7 +1513,259 @@ DEFINE_func_8015B858() /* dedup: shared engine-core @0x8015B858 (src/shared) */ DEFINE_func_8015B8F8() /* dedup: shared engine-core @0x8015B8F8 (src/shared) */ -INCLUDE_ASM("asm/ov_SC03_014/nonmatchings/ov_SC03_014_jr_8015AE2C", func_8015B950); +extern s32 func_8015AE2C(); + +// @class: plumbing +// @stuck: none — MATCH (271/271, pin-free, zero asm). The ONLY residual is DEF-SIDE plumbing, and it is now named exactly: the in-TU instantiation `DEFINE_func_8015BEE4()` (engine_core.h:1851-1855) expands to `extern s32 func_8015B950(void);` INSIDE ov_SC01_077_jr_8015AE2C.c, ~14 lines BELOW this definition, so the 1-param def collides with a `(void)` prototype -> `conflicting types for func_8015B950` (.run/bank_func_8015B950.log). §73 PARAMS axis / T0. Surgical fix = §65b de-macroize that ONE instantiation (blast radius: this TU); the fleet-wide `(void)`->`()` header edit is §63 and must be R22-validated. +/* func_8015B950 (ov_SC01_077_jr_8015AE2C, 271 ins, jtbl_801D8B74) — SESSION-21 re-verified + * + * ── ROUND-2 INDEPENDENT RE-VERIFICATION (2026-07-27, fresh agent, §88e discipline) ───────────── + * match_one : MATCH (271 ins) against the CURRENT tree — §87 staleness re-checked today. + * .text size: compiled .text = 0x43C = 1084 B = 271 ins, EXACTLY the target's declared 0x43C + * ("nonmatching func_8015B950, 0x43C"). So this is NOT a §83a length drift hiding + * behind a zero count — the count is over equal-length streams. + * jtbl : RE-DECODED MECHANICALLY, not inherited. Compiled .rodata = 0x1C = 28 B = 7 words, + * 7x R_MIPS_32 -> .text with implicit addends [58,58,58,E0,F0,100,58]; +0x8015B950 + * = [8015B9A8, 8015B9A8, 8015B9A8, 8015BA30, 8015BA40, 8015BA50, 8015B9A8]. + * Diffed word-for-word against asm/ov_SC01_077/data/tail14.data.s:15-23 — 7/7 identical. + * symcheck : SYMS-DIFF target=35 draft=34, sole MISSING = jtbl_801D8B74. This is the §81 jr + * FALSE POSITIVE, re-confirmed here by reading the relocs: gcc emits its OWN table and + * references it with R_MIPS_HI16/LO16 against the SECTION `.rodata` (t.o +0x40/+0x48), + * so the splat's dlabel NAME can never appear in the draft object's relocation set. + * Nothing is dropped and nothing is invented: the draft's other 34 symbols are exactly + * the target's other 34. + * FAMILY : the x138 remap is clean and §84-safe. Every sibling is 271 ins with an IDENTICAL + * callee set; only THREE names vary per overlay — the two data labels and the jtbl: + * ov_SC01_077 D_8018DB9C / D_8018DC08 / jtbl_801D8B74 + * ov_SC03_099 D_80185A50 / D_80185ABC / jtbl_801BD898 + * ov_SC06_008 D_80187E44 / D_80187EB0 / jtbl_801A8734 + * The pair is always +0x6C apart, and NO literal in this draft encodes that distance + * (both labels are referenced by name), so there is no §84 derived-offset hazard. + * D_8011F9C4 is fleet-constant (main-EXE data) and must NOT be remapped. + * + * match_one: MATCH (271 ins) against the CURRENT tree (§87 staleness re-checked, 2026-07-27). + * PIN-FREE, zero asm, offset-pure (s32 arg0 + raw offsets) — x138 template-safe. + * Provenance: this is the Phase-26 crack (.run/phase26-cracks/func_8015B950.c) re-gated verbatim, + * with ONE deliberate change: the definition's return type void -> s32. + * - `void func_8015B950(s32 arg0)` : MATCH (271 ins) [the Phase-26 form] + * - `s32 func_8015B950(s32 arg0)` : MATCH (271 ins) [shipped — §3a-1 void->s32 is byte-neutral] + * The fleet/engine_core.h canonical decl is `extern s32 func_8015B950(void);` (engine_core.h:1852), + * and the last bank attempt (.run/bank_func_8015B950.log) died on `conflicting types for + * func_8015B950`. Shipping the s32 return kills the §73 RETURN axis for free and leaves only the + * cheap T0 PARAMS axis for the ladder (fix_header_decl.py / --fix-def-sig / cast_call_sites). + * Both forms are byte-identical, so the orchestrator may swap the return type back at zero cost. + * + * SYMBOLS (§58 rules 1/2 — all splat spellings, all verified present): + * D_8018DC08 asm/ov_SC01_077/data/tail.data.s:4355 (the state-handler vtable) + * D_8018DB9C asm/ov_SC01_077/data/tail.data.s:4293 + * D_8011F9C4 main-EXE data; spelled `extern s32 D_8011F9C4;` in 5+ already-banked TUs + * jtbl_801D8B74 asm/ov_SC01_077/data/tail14.data.s:15 (compiler jump table — not named in C) + * + * JTBL VERIFIED (§8a gate): compiled .rodata = exactly 0x1C B / 7 words, 7x R_MIPS_32 .text with + * addends [0x58,0x58,0x58,0xE0,0xF0,0x100,0x58] -> +0x8015B950 = [B9A8,B9A8,B9A8,BA30,BA40,BA50, + * B9A8] == the original words at 0x801D8B74..0x801D8B8C. Bound `sltiu $v0,$v1,0x7` matches. + * The raw dlabel's 8th word 0x00000000 is NOT an entry — it is the intra-TU `.align 3` pad of the + * B34/B54/B74 jtbl chain; the object can never emit it (maspsx drops .align), so it must stay in + * the post-carve RAW data piece (the §53/§62/§81 carve chain applies at bank time). + * + * Same family as the TU's own already-matched func_8015AE2C: 7-case switch on ((s32 (*)(s32))func_801619A4)() + * (0/1/2/6 shared, 3/4/5 own, no default block — out-of-range and every `break` fall to the + * after-switch join), then a chain of "state handler" tests, each dispatching + * D_8018DC08[*(u16*)arg0](arg0) and returning. + * + * THREE LEVERS (draft -> MATCH in 3 compiles): + * + * 1. PROLOGUE CONSTANT = an INITIALIZED LOCAL, not a literal in the compare. + * Target opens with `lui $s2, 0xFFF5` in the *prologue*, used once ~200 ins later in + * `slt $v0,$s2,$s1`. No gcc-2.7.2 pass hoists a (set reg const_int) across basic blocks + * (loop.c needs a loop; cse/combine/sched never move insns between BBs) — so the insn must + * have been EMITTED in the first BB, i.e. the constant is a local initialized at the top of + * the function. cse then cannot fold it back into the compare: the `slt` operand predicate is + * `arith_operand`, which rejects a CONST_INT wider than 16 bits, so validate_change fails and + * the pseudo survives. Its live range spans every call -> global.c gives it a callee-saved reg. + * Writing `z > -0xB0000` inline instead emits the `lui` into the branch delay slot next to the + * compare (caller-saved $v0) and the function is 1 insn short. => `s32 lim = -0xB0000;` at top. + * + * 2. `lh` vs `lhu`: a short->short copy is a pure HImode move and gcc emits `lhu`. The target's + * `lh $v0,0x26($s0)` means the value passed through an SImode (int) temp: expand makes + * (set (reg:SI) (sign_extend (mem:HI))) + (set (mem:HI) (subreg:HI ...)), and combine cannot + * merge them (the merged form is mem<-mem, which no movhi accepts) so the sign-extending load + * survives. => route both halfword copies through the `s32 t` temp. + * + * 3. THE `goto` LAYOUT — dodging jump.c's store-flag conversion (jump.c:1005-1065). + * An if/else chain writing 0/1 into `doit` makes gcc collapse the last pair into + * `sltiu $v0,$v0,1`. jump.c fires that conversion when the insn immediately after a + * conditional jump is a lone `SET pseudo, CONST_INT` whose following simplejump targets the + * SAME label as the branch (jump.c:1038 `reallabelprev == temp || ... JUMP_LABEL(temp4) == + * JUMP_LABEL(insn)`) — exactly the shape of `if (c) x=0; else x=1;`. + * The target instead cross-jumps ALL the `doit=0` exits into ONE shared block placed after the + * `doit=1` fall-through; reorg's fill_slots_from_thread then COPIES that single set into all + * three branch delay slots and redirects each branch past it (which is why `addu $v0,$zero, + * $zero` appears 3x in delay slots and the shared block vanishes). A `goto zero;` / `goto one;` + * chain expresses that layout directly, and each conditional jump is then followed by a + * compare/call rather than a lone const set, so the store-flag conversion never triggers. + * GENERAL RULE: multiple predicates that all assign the SAME constant to one flag => write + * them as `goto` to a shared assignment, never as an if/else ladder. + */ +extern s32 D_8011F9C4; +extern s32 D_8018DB9C; + +extern s32 func_80161B18(void); +extern s32 func_801619A4(s32*); +extern s32 func_80149AA8(s32*); +extern void func_80149AD4(s32*); +extern s32 func_80149B54(s32*); +extern void func_80149BAC(s32*); +extern s32 func_801498E0(s32*); +extern s32 func_80149954(s32); +extern s32 func_80149A64(s32*); +extern void func_800CCCC0(s32 a0); +extern s32 func_80149CD4(s32 a0); +extern void func_8015E880(s32*); +extern s32 func_80149744(struct S_80149744*); +extern void func_80149788(void); +extern s32 func_801496D4(void*); +extern void func_80149704(void); +extern int func_80148AFC(void*); +extern void func_80146D90(s32 a0); +extern void func_80154150(s32 a0, s32 a1); +extern void func_801541D8(u8*, s32, s32); +extern s32 func_801488A8(u8*); +extern void func_80147078(s32*, s16); +extern void func_8015A264(void*); +extern s32 func_80013294(void*, void*); +extern void func_80159B70(void*); +extern s32 func_8016F1AC(void); +extern s32 func_80029178(s32 a0); +extern void func_80146DB8(s32*, s32*); +extern s32 func_80161CD0(s32, s32); +extern s32 func_80161208(s32 a0); +extern s32 func_801725A4(u8*); + +s32 func_8015B950(s32 arg0) +{ + + extern void (*D_8018DC08[])(void *); + s16 sp10[4]; + s16 sp18[4]; + s32 t; + s32 z; + s32 doit; + s32 lim = -0xB0000; + + if (func_80161B18() != 0) { + return; + } + switch (((s32 (*)(s32))func_801619A4)(arg0)) { + case 0: + case 1: + case 2: + case 6: + if (((s32 (*)(s32))func_80149AA8)(arg0) != 0) { + D_8018DC08[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149AD4)(arg0); + return; + } + if (((s32 (*)(s32))func_80149B54)(arg0) != 0) { + D_8018DC08[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149BAC)(arg0); + return; + } + break; + case 3: + ((void (*)(s32))func_801498E0)(arg0); + break; + case 4: + ((void (*)(s32))func_80149954)(arg0); + break; + case 5: + if (((s32 (*)(s32))func_80149A64)(arg0) != 0) { + D_8018DC08[*(u16 *)arg0]((void *)arg0); + func_800CCCC0(arg0); + return; + } + break; + } + if (func_80149CD4(arg0) != 0) { + D_8018DC08[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_8015E880)(arg0); + return; + } + if (((s32 (*)(s32))func_80149744)(arg0) != 0) { + D_8018DC08[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149788)(arg0); + return; + } + if (((s32 (*)(s32))func_801496D4)(arg0) != 0) { + D_8018DC08[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149704)(arg0); + if (((u8)((s32 (*)(s32))func_80148AFC)(arg0)) == 0) { + func_80146D90(arg0); + } + if ((*(s32 *)(arg0 + 0x24) | *(s32 *)(arg0 + 0x2C)) != 0) { + func_80154150(arg0, 0xF); + } else { + ((void (*)(s32, s32, s32))func_801541D8)(arg0, 0xD, 6); + } + *(s32 *)(arg0 + 0x238) = 1; + return; + } + if (((s32 (*)(s32))func_801488A8)(arg0) != 0) { + sp10[0] = 0; + sp10[1] = 0; + sp10[2] = 0; + t = *(s16 *)(arg0 + 0x26); + sp18[0] = t; + sp18[1] = 0; + t = *(s16 *)(arg0 + 0x2E); + sp18[2] = t; + D_8018DC08[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 1); + ((void (*)(s32))func_8015A264)(arg0); + t = -(((s32 (*)(s16 *, s16 *))func_80013294)(sp10, sp18) << 0x10); + if (t < *(s32 *)(arg0 + 0x2C)) { + *(s32 *)(arg0 + 0x2C) = t; + } + return; + } + if (*(u16 *)(arg0 + 0xB8) == 0x8000) { + D_8018DC08[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 0); + ((void (*)(s32))func_80159B70)(arg0); + return; + } + z = *(s32 *)(arg0 + 0x2C); + if (func_8016F1AC() != 0) { + goto zero; + } + if (z <= lim) { + goto one; + } + if (D_8011F9C4 == 0) { + goto zero; + } + if (((u8)func_80029178(0x21)) != 0) { + goto zero; + } +one: + doit = 1; + goto join; +zero: + doit = 0; +join: + if (doit != 0) { + D_8018DC08[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 0); + ((void (*)(s32))func_80159B70)(arg0); + func_80154150(arg0, 9); + ((void (*)(s32, s32 *))func_80146DB8)(arg0, &D_8018DB9C); + ((void (*)(s32, s32))func_80161CD0)(arg0, *(u16 *)(arg0 + 0x16E)); + return; + } + if (func_80161208(arg0) == 0) { + ((void (*)(s32))func_801725A4)(arg0); + } +} DEFINE_func_8015BD8C() /* dedup: shared engine-core @0x8015BD8C (src/shared) */ diff --git a/src/ov_SC03_015/ov_SC03_015_jr_8015AE2C.c b/src/ov_SC03_015/ov_SC03_015_jr_8015AE2C.c index c9dd7b24b..0de1bb6e1 100644 --- a/src/ov_SC03_015/ov_SC03_015_jr_8015AE2C.c +++ b/src/ov_SC03_015/ov_SC03_015_jr_8015AE2C.c @@ -1513,7 +1513,259 @@ DEFINE_func_8015B858() /* dedup: shared engine-core @0x8015B858 (src/shared) */ DEFINE_func_8015B8F8() /* dedup: shared engine-core @0x8015B8F8 (src/shared) */ -INCLUDE_ASM("asm/ov_SC03_015/nonmatchings/ov_SC03_015_jr_8015AE2C", func_8015B950); +extern s32 func_8015AE2C(); + +// @class: plumbing +// @stuck: none — MATCH (271/271, pin-free, zero asm). The ONLY residual is DEF-SIDE plumbing, and it is now named exactly: the in-TU instantiation `DEFINE_func_8015BEE4()` (engine_core.h:1851-1855) expands to `extern s32 func_8015B950(void);` INSIDE ov_SC01_077_jr_8015AE2C.c, ~14 lines BELOW this definition, so the 1-param def collides with a `(void)` prototype -> `conflicting types for func_8015B950` (.run/bank_func_8015B950.log). §73 PARAMS axis / T0. Surgical fix = §65b de-macroize that ONE instantiation (blast radius: this TU); the fleet-wide `(void)`->`()` header edit is §63 and must be R22-validated. +/* func_8015B950 (ov_SC01_077_jr_8015AE2C, 271 ins, jtbl_801D8B74) — SESSION-21 re-verified + * + * ── ROUND-2 INDEPENDENT RE-VERIFICATION (2026-07-27, fresh agent, §88e discipline) ───────────── + * match_one : MATCH (271 ins) against the CURRENT tree — §87 staleness re-checked today. + * .text size: compiled .text = 0x43C = 1084 B = 271 ins, EXACTLY the target's declared 0x43C + * ("nonmatching func_8015B950, 0x43C"). So this is NOT a §83a length drift hiding + * behind a zero count — the count is over equal-length streams. + * jtbl : RE-DECODED MECHANICALLY, not inherited. Compiled .rodata = 0x1C = 28 B = 7 words, + * 7x R_MIPS_32 -> .text with implicit addends [58,58,58,E0,F0,100,58]; +0x8015B950 + * = [8015B9A8, 8015B9A8, 8015B9A8, 8015BA30, 8015BA40, 8015BA50, 8015B9A8]. + * Diffed word-for-word against asm/ov_SC01_077/data/tail14.data.s:15-23 — 7/7 identical. + * symcheck : SYMS-DIFF target=35 draft=34, sole MISSING = jtbl_801D8B74. This is the §81 jr + * FALSE POSITIVE, re-confirmed here by reading the relocs: gcc emits its OWN table and + * references it with R_MIPS_HI16/LO16 against the SECTION `.rodata` (t.o +0x40/+0x48), + * so the splat's dlabel NAME can never appear in the draft object's relocation set. + * Nothing is dropped and nothing is invented: the draft's other 34 symbols are exactly + * the target's other 34. + * FAMILY : the x138 remap is clean and §84-safe. Every sibling is 271 ins with an IDENTICAL + * callee set; only THREE names vary per overlay — the two data labels and the jtbl: + * ov_SC01_077 D_8018DB9C / D_8018DC08 / jtbl_801D8B74 + * ov_SC03_099 D_80185A50 / D_80185ABC / jtbl_801BD898 + * ov_SC06_008 D_80187E44 / D_80187EB0 / jtbl_801A8734 + * The pair is always +0x6C apart, and NO literal in this draft encodes that distance + * (both labels are referenced by name), so there is no §84 derived-offset hazard. + * D_8011F9C4 is fleet-constant (main-EXE data) and must NOT be remapped. + * + * match_one: MATCH (271 ins) against the CURRENT tree (§87 staleness re-checked, 2026-07-27). + * PIN-FREE, zero asm, offset-pure (s32 arg0 + raw offsets) — x138 template-safe. + * Provenance: this is the Phase-26 crack (.run/phase26-cracks/func_8015B950.c) re-gated verbatim, + * with ONE deliberate change: the definition's return type void -> s32. + * - `void func_8015B950(s32 arg0)` : MATCH (271 ins) [the Phase-26 form] + * - `s32 func_8015B950(s32 arg0)` : MATCH (271 ins) [shipped — §3a-1 void->s32 is byte-neutral] + * The fleet/engine_core.h canonical decl is `extern s32 func_8015B950(void);` (engine_core.h:1852), + * and the last bank attempt (.run/bank_func_8015B950.log) died on `conflicting types for + * func_8015B950`. Shipping the s32 return kills the §73 RETURN axis for free and leaves only the + * cheap T0 PARAMS axis for the ladder (fix_header_decl.py / --fix-def-sig / cast_call_sites). + * Both forms are byte-identical, so the orchestrator may swap the return type back at zero cost. + * + * SYMBOLS (§58 rules 1/2 — all splat spellings, all verified present): + * D_8018DC08 asm/ov_SC01_077/data/tail.data.s:4355 (the state-handler vtable) + * D_8018DB9C asm/ov_SC01_077/data/tail.data.s:4293 + * D_8011F9C4 main-EXE data; spelled `extern s32 D_8011F9C4;` in 5+ already-banked TUs + * jtbl_801D8B74 asm/ov_SC01_077/data/tail14.data.s:15 (compiler jump table — not named in C) + * + * JTBL VERIFIED (§8a gate): compiled .rodata = exactly 0x1C B / 7 words, 7x R_MIPS_32 .text with + * addends [0x58,0x58,0x58,0xE0,0xF0,0x100,0x58] -> +0x8015B950 = [B9A8,B9A8,B9A8,BA30,BA40,BA50, + * B9A8] == the original words at 0x801D8B74..0x801D8B8C. Bound `sltiu $v0,$v1,0x7` matches. + * The raw dlabel's 8th word 0x00000000 is NOT an entry — it is the intra-TU `.align 3` pad of the + * B34/B54/B74 jtbl chain; the object can never emit it (maspsx drops .align), so it must stay in + * the post-carve RAW data piece (the §53/§62/§81 carve chain applies at bank time). + * + * Same family as the TU's own already-matched func_8015AE2C: 7-case switch on ((s32 (*)(s32))func_801619A4)() + * (0/1/2/6 shared, 3/4/5 own, no default block — out-of-range and every `break` fall to the + * after-switch join), then a chain of "state handler" tests, each dispatching + * D_8018DC08[*(u16*)arg0](arg0) and returning. + * + * THREE LEVERS (draft -> MATCH in 3 compiles): + * + * 1. PROLOGUE CONSTANT = an INITIALIZED LOCAL, not a literal in the compare. + * Target opens with `lui $s2, 0xFFF5` in the *prologue*, used once ~200 ins later in + * `slt $v0,$s2,$s1`. No gcc-2.7.2 pass hoists a (set reg const_int) across basic blocks + * (loop.c needs a loop; cse/combine/sched never move insns between BBs) — so the insn must + * have been EMITTED in the first BB, i.e. the constant is a local initialized at the top of + * the function. cse then cannot fold it back into the compare: the `slt` operand predicate is + * `arith_operand`, which rejects a CONST_INT wider than 16 bits, so validate_change fails and + * the pseudo survives. Its live range spans every call -> global.c gives it a callee-saved reg. + * Writing `z > -0xB0000` inline instead emits the `lui` into the branch delay slot next to the + * compare (caller-saved $v0) and the function is 1 insn short. => `s32 lim = -0xB0000;` at top. + * + * 2. `lh` vs `lhu`: a short->short copy is a pure HImode move and gcc emits `lhu`. The target's + * `lh $v0,0x26($s0)` means the value passed through an SImode (int) temp: expand makes + * (set (reg:SI) (sign_extend (mem:HI))) + (set (mem:HI) (subreg:HI ...)), and combine cannot + * merge them (the merged form is mem<-mem, which no movhi accepts) so the sign-extending load + * survives. => route both halfword copies through the `s32 t` temp. + * + * 3. THE `goto` LAYOUT — dodging jump.c's store-flag conversion (jump.c:1005-1065). + * An if/else chain writing 0/1 into `doit` makes gcc collapse the last pair into + * `sltiu $v0,$v0,1`. jump.c fires that conversion when the insn immediately after a + * conditional jump is a lone `SET pseudo, CONST_INT` whose following simplejump targets the + * SAME label as the branch (jump.c:1038 `reallabelprev == temp || ... JUMP_LABEL(temp4) == + * JUMP_LABEL(insn)`) — exactly the shape of `if (c) x=0; else x=1;`. + * The target instead cross-jumps ALL the `doit=0` exits into ONE shared block placed after the + * `doit=1` fall-through; reorg's fill_slots_from_thread then COPIES that single set into all + * three branch delay slots and redirects each branch past it (which is why `addu $v0,$zero, + * $zero` appears 3x in delay slots and the shared block vanishes). A `goto zero;` / `goto one;` + * chain expresses that layout directly, and each conditional jump is then followed by a + * compare/call rather than a lone const set, so the store-flag conversion never triggers. + * GENERAL RULE: multiple predicates that all assign the SAME constant to one flag => write + * them as `goto` to a shared assignment, never as an if/else ladder. + */ +extern s32 D_8011F9C4; +extern s32 D_8018DB9C; + +extern s32 func_80161B18(void); +extern s32 func_801619A4(s32*); +extern s32 func_80149AA8(s32*); +extern void func_80149AD4(s32*); +extern s32 func_80149B54(s32*); +extern void func_80149BAC(s32*); +extern s32 func_801498E0(s32*); +extern s32 func_80149954(s32); +extern s32 func_80149A64(s32*); +extern void func_800CCCC0(s32 a0); +extern s32 func_80149CD4(s32 a0); +extern void func_8015E880(s32*); +extern s32 func_80149744(struct S_80149744*); +extern void func_80149788(void); +extern s32 func_801496D4(void*); +extern void func_80149704(void); +extern int func_80148AFC(void*); +extern void func_80146D90(s32 a0); +extern void func_80154150(s32 a0, s32 a1); +extern void func_801541D8(u8*, s32, s32); +extern s32 func_801488A8(u8*); +extern void func_80147078(s32*, s16); +extern void func_8015A264(void*); +extern s32 func_80013294(void*, void*); +extern void func_80159B70(void*); +extern s32 func_8016F1AC(void); +extern s32 func_80029178(s32 a0); +extern void func_80146DB8(s32*, s32*); +extern s32 func_80161CD0(s32, s32); +extern s32 func_80161208(s32 a0); +extern s32 func_801725A4(u8*); + +s32 func_8015B950(s32 arg0) +{ + + extern void (*D_8018DC08[])(void *); + s16 sp10[4]; + s16 sp18[4]; + s32 t; + s32 z; + s32 doit; + s32 lim = -0xB0000; + + if (func_80161B18() != 0) { + return; + } + switch (((s32 (*)(s32))func_801619A4)(arg0)) { + case 0: + case 1: + case 2: + case 6: + if (((s32 (*)(s32))func_80149AA8)(arg0) != 0) { + D_8018DC08[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149AD4)(arg0); + return; + } + if (((s32 (*)(s32))func_80149B54)(arg0) != 0) { + D_8018DC08[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149BAC)(arg0); + return; + } + break; + case 3: + ((void (*)(s32))func_801498E0)(arg0); + break; + case 4: + ((void (*)(s32))func_80149954)(arg0); + break; + case 5: + if (((s32 (*)(s32))func_80149A64)(arg0) != 0) { + D_8018DC08[*(u16 *)arg0]((void *)arg0); + func_800CCCC0(arg0); + return; + } + break; + } + if (func_80149CD4(arg0) != 0) { + D_8018DC08[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_8015E880)(arg0); + return; + } + if (((s32 (*)(s32))func_80149744)(arg0) != 0) { + D_8018DC08[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149788)(arg0); + return; + } + if (((s32 (*)(s32))func_801496D4)(arg0) != 0) { + D_8018DC08[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149704)(arg0); + if (((u8)((s32 (*)(s32))func_80148AFC)(arg0)) == 0) { + func_80146D90(arg0); + } + if ((*(s32 *)(arg0 + 0x24) | *(s32 *)(arg0 + 0x2C)) != 0) { + func_80154150(arg0, 0xF); + } else { + ((void (*)(s32, s32, s32))func_801541D8)(arg0, 0xD, 6); + } + *(s32 *)(arg0 + 0x238) = 1; + return; + } + if (((s32 (*)(s32))func_801488A8)(arg0) != 0) { + sp10[0] = 0; + sp10[1] = 0; + sp10[2] = 0; + t = *(s16 *)(arg0 + 0x26); + sp18[0] = t; + sp18[1] = 0; + t = *(s16 *)(arg0 + 0x2E); + sp18[2] = t; + D_8018DC08[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 1); + ((void (*)(s32))func_8015A264)(arg0); + t = -(((s32 (*)(s16 *, s16 *))func_80013294)(sp10, sp18) << 0x10); + if (t < *(s32 *)(arg0 + 0x2C)) { + *(s32 *)(arg0 + 0x2C) = t; + } + return; + } + if (*(u16 *)(arg0 + 0xB8) == 0x8000) { + D_8018DC08[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 0); + ((void (*)(s32))func_80159B70)(arg0); + return; + } + z = *(s32 *)(arg0 + 0x2C); + if (func_8016F1AC() != 0) { + goto zero; + } + if (z <= lim) { + goto one; + } + if (D_8011F9C4 == 0) { + goto zero; + } + if (((u8)func_80029178(0x21)) != 0) { + goto zero; + } +one: + doit = 1; + goto join; +zero: + doit = 0; +join: + if (doit != 0) { + D_8018DC08[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 0); + ((void (*)(s32))func_80159B70)(arg0); + func_80154150(arg0, 9); + ((void (*)(s32, s32 *))func_80146DB8)(arg0, &D_8018DB9C); + ((void (*)(s32, s32))func_80161CD0)(arg0, *(u16 *)(arg0 + 0x16E)); + return; + } + if (func_80161208(arg0) == 0) { + ((void (*)(s32))func_801725A4)(arg0); + } +} DEFINE_func_8015BD8C() /* dedup: shared engine-core @0x8015BD8C (src/shared) */ diff --git a/src/ov_SC03_023/ov_SC03_023_jr_8015AE2C.c b/src/ov_SC03_023/ov_SC03_023_jr_8015AE2C.c index eec61bd9d..1da2af5e2 100644 --- a/src/ov_SC03_023/ov_SC03_023_jr_8015AE2C.c +++ b/src/ov_SC03_023/ov_SC03_023_jr_8015AE2C.c @@ -1513,7 +1513,259 @@ DEFINE_func_8015B858() /* dedup: shared engine-core @0x8015B858 (src/shared) */ DEFINE_func_8015B8F8() /* dedup: shared engine-core @0x8015B8F8 (src/shared) */ -INCLUDE_ASM("asm/ov_SC03_023/nonmatchings/ov_SC03_023_jr_8015AE2C", func_8015B950); +extern s32 func_8015AE2C(); + +// @class: plumbing +// @stuck: none — MATCH (271/271, pin-free, zero asm). The ONLY residual is DEF-SIDE plumbing, and it is now named exactly: the in-TU instantiation `DEFINE_func_8015BEE4()` (engine_core.h:1851-1855) expands to `extern s32 func_8015B950(void);` INSIDE ov_SC01_077_jr_8015AE2C.c, ~14 lines BELOW this definition, so the 1-param def collides with a `(void)` prototype -> `conflicting types for func_8015B950` (.run/bank_func_8015B950.log). §73 PARAMS axis / T0. Surgical fix = §65b de-macroize that ONE instantiation (blast radius: this TU); the fleet-wide `(void)`->`()` header edit is §63 and must be R22-validated. +/* func_8015B950 (ov_SC01_077_jr_8015AE2C, 271 ins, jtbl_801D8B74) — SESSION-21 re-verified + * + * ── ROUND-2 INDEPENDENT RE-VERIFICATION (2026-07-27, fresh agent, §88e discipline) ───────────── + * match_one : MATCH (271 ins) against the CURRENT tree — §87 staleness re-checked today. + * .text size: compiled .text = 0x43C = 1084 B = 271 ins, EXACTLY the target's declared 0x43C + * ("nonmatching func_8015B950, 0x43C"). So this is NOT a §83a length drift hiding + * behind a zero count — the count is over equal-length streams. + * jtbl : RE-DECODED MECHANICALLY, not inherited. Compiled .rodata = 0x1C = 28 B = 7 words, + * 7x R_MIPS_32 -> .text with implicit addends [58,58,58,E0,F0,100,58]; +0x8015B950 + * = [8015B9A8, 8015B9A8, 8015B9A8, 8015BA30, 8015BA40, 8015BA50, 8015B9A8]. + * Diffed word-for-word against asm/ov_SC01_077/data/tail14.data.s:15-23 — 7/7 identical. + * symcheck : SYMS-DIFF target=35 draft=34, sole MISSING = jtbl_801D8B74. This is the §81 jr + * FALSE POSITIVE, re-confirmed here by reading the relocs: gcc emits its OWN table and + * references it with R_MIPS_HI16/LO16 against the SECTION `.rodata` (t.o +0x40/+0x48), + * so the splat's dlabel NAME can never appear in the draft object's relocation set. + * Nothing is dropped and nothing is invented: the draft's other 34 symbols are exactly + * the target's other 34. + * FAMILY : the x138 remap is clean and §84-safe. Every sibling is 271 ins with an IDENTICAL + * callee set; only THREE names vary per overlay — the two data labels and the jtbl: + * ov_SC01_077 D_80181518 / D_80181584 / jtbl_801D8B74 + * ov_SC03_099 D_80185A50 / D_80185ABC / jtbl_801BD898 + * ov_SC06_008 D_80187E44 / D_80187EB0 / jtbl_801A8734 + * The pair is always +0x6C apart, and NO literal in this draft encodes that distance + * (both labels are referenced by name), so there is no §84 derived-offset hazard. + * D_8011F9C4 is fleet-constant (main-EXE data) and must NOT be remapped. + * + * match_one: MATCH (271 ins) against the CURRENT tree (§87 staleness re-checked, 2026-07-27). + * PIN-FREE, zero asm, offset-pure (s32 arg0 + raw offsets) — x138 template-safe. + * Provenance: this is the Phase-26 crack (.run/phase26-cracks/func_8015B950.c) re-gated verbatim, + * with ONE deliberate change: the definition's return type void -> s32. + * - `void func_8015B950(s32 arg0)` : MATCH (271 ins) [the Phase-26 form] + * - `s32 func_8015B950(s32 arg0)` : MATCH (271 ins) [shipped — §3a-1 void->s32 is byte-neutral] + * The fleet/engine_core.h canonical decl is `extern s32 func_8015B950(void);` (engine_core.h:1852), + * and the last bank attempt (.run/bank_func_8015B950.log) died on `conflicting types for + * func_8015B950`. Shipping the s32 return kills the §73 RETURN axis for free and leaves only the + * cheap T0 PARAMS axis for the ladder (fix_header_decl.py / --fix-def-sig / cast_call_sites). + * Both forms are byte-identical, so the orchestrator may swap the return type back at zero cost. + * + * SYMBOLS (§58 rules 1/2 — all splat spellings, all verified present): + * D_80181584 asm/ov_SC01_077/data/tail.data.s:4355 (the state-handler vtable) + * D_80181518 asm/ov_SC01_077/data/tail.data.s:4293 + * D_8011F9C4 main-EXE data; spelled `extern s32 D_8011F9C4;` in 5+ already-banked TUs + * jtbl_801D8B74 asm/ov_SC01_077/data/tail14.data.s:15 (compiler jump table — not named in C) + * + * JTBL VERIFIED (§8a gate): compiled .rodata = exactly 0x1C B / 7 words, 7x R_MIPS_32 .text with + * addends [0x58,0x58,0x58,0xE0,0xF0,0x100,0x58] -> +0x8015B950 = [B9A8,B9A8,B9A8,BA30,BA40,BA50, + * B9A8] == the original words at 0x801D8B74..0x801D8B8C. Bound `sltiu $v0,$v1,0x7` matches. + * The raw dlabel's 8th word 0x00000000 is NOT an entry — it is the intra-TU `.align 3` pad of the + * B34/B54/B74 jtbl chain; the object can never emit it (maspsx drops .align), so it must stay in + * the post-carve RAW data piece (the §53/§62/§81 carve chain applies at bank time). + * + * Same family as the TU's own already-matched func_8015AE2C: 7-case switch on ((s32 (*)(s32))func_801619A4)() + * (0/1/2/6 shared, 3/4/5 own, no default block — out-of-range and every `break` fall to the + * after-switch join), then a chain of "state handler" tests, each dispatching + * D_80181584[*(u16*)arg0](arg0) and returning. + * + * THREE LEVERS (draft -> MATCH in 3 compiles): + * + * 1. PROLOGUE CONSTANT = an INITIALIZED LOCAL, not a literal in the compare. + * Target opens with `lui $s2, 0xFFF5` in the *prologue*, used once ~200 ins later in + * `slt $v0,$s2,$s1`. No gcc-2.7.2 pass hoists a (set reg const_int) across basic blocks + * (loop.c needs a loop; cse/combine/sched never move insns between BBs) — so the insn must + * have been EMITTED in the first BB, i.e. the constant is a local initialized at the top of + * the function. cse then cannot fold it back into the compare: the `slt` operand predicate is + * `arith_operand`, which rejects a CONST_INT wider than 16 bits, so validate_change fails and + * the pseudo survives. Its live range spans every call -> global.c gives it a callee-saved reg. + * Writing `z > -0xB0000` inline instead emits the `lui` into the branch delay slot next to the + * compare (caller-saved $v0) and the function is 1 insn short. => `s32 lim = -0xB0000;` at top. + * + * 2. `lh` vs `lhu`: a short->short copy is a pure HImode move and gcc emits `lhu`. The target's + * `lh $v0,0x26($s0)` means the value passed through an SImode (int) temp: expand makes + * (set (reg:SI) (sign_extend (mem:HI))) + (set (mem:HI) (subreg:HI ...)), and combine cannot + * merge them (the merged form is mem<-mem, which no movhi accepts) so the sign-extending load + * survives. => route both halfword copies through the `s32 t` temp. + * + * 3. THE `goto` LAYOUT — dodging jump.c's store-flag conversion (jump.c:1005-1065). + * An if/else chain writing 0/1 into `doit` makes gcc collapse the last pair into + * `sltiu $v0,$v0,1`. jump.c fires that conversion when the insn immediately after a + * conditional jump is a lone `SET pseudo, CONST_INT` whose following simplejump targets the + * SAME label as the branch (jump.c:1038 `reallabelprev == temp || ... JUMP_LABEL(temp4) == + * JUMP_LABEL(insn)`) — exactly the shape of `if (c) x=0; else x=1;`. + * The target instead cross-jumps ALL the `doit=0` exits into ONE shared block placed after the + * `doit=1` fall-through; reorg's fill_slots_from_thread then COPIES that single set into all + * three branch delay slots and redirects each branch past it (which is why `addu $v0,$zero, + * $zero` appears 3x in delay slots and the shared block vanishes). A `goto zero;` / `goto one;` + * chain expresses that layout directly, and each conditional jump is then followed by a + * compare/call rather than a lone const set, so the store-flag conversion never triggers. + * GENERAL RULE: multiple predicates that all assign the SAME constant to one flag => write + * them as `goto` to a shared assignment, never as an if/else ladder. + */ +extern s32 D_8011F9C4; +extern s32 D_80181518; + +extern s32 func_80161B18(void); +extern s32 func_801619A4(s32*); +extern s32 func_80149AA8(s32*); +extern void func_80149AD4(s32*); +extern s32 func_80149B54(s32*); +extern void func_80149BAC(s32*); +extern s32 func_801498E0(s32*); +extern s32 func_80149954(s32); +extern s32 func_80149A64(s32*); +extern void func_800CCCC0(s32 a0); +extern s32 func_80149CD4(s32 a0); +extern void func_8015E880(s32*); +extern s32 func_80149744(struct S_80149744*); +extern void func_80149788(void); +extern s32 func_801496D4(void*); +extern void func_80149704(void); +extern int func_80148AFC(void*); +extern void func_80146D90(s32 a0); +extern void func_80154150(s32 a0, s32 a1); +extern void func_801541D8(u8*, s32, s32); +extern s32 func_801488A8(u8*); +extern void func_80147078(s32*, s16); +extern void func_8015A264(void*); +extern s32 func_80013294(void*, void*); +extern void func_80159B70(void*); +extern s32 func_8016F1AC(void); +extern s32 func_80029178(s32 a0); +extern void func_80146DB8(s32*, s32*); +extern s32 func_80161CD0(s32, s32); +extern s32 func_80161208(s32 a0); +extern s32 func_801725A4(u8*); + +s32 func_8015B950(s32 arg0) +{ + + extern void (*D_80181584[])(void *); + s16 sp10[4]; + s16 sp18[4]; + s32 t; + s32 z; + s32 doit; + s32 lim = -0xB0000; + + if (func_80161B18() != 0) { + return; + } + switch (((s32 (*)(s32))func_801619A4)(arg0)) { + case 0: + case 1: + case 2: + case 6: + if (((s32 (*)(s32))func_80149AA8)(arg0) != 0) { + D_80181584[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149AD4)(arg0); + return; + } + if (((s32 (*)(s32))func_80149B54)(arg0) != 0) { + D_80181584[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149BAC)(arg0); + return; + } + break; + case 3: + ((void (*)(s32))func_801498E0)(arg0); + break; + case 4: + ((void (*)(s32))func_80149954)(arg0); + break; + case 5: + if (((s32 (*)(s32))func_80149A64)(arg0) != 0) { + D_80181584[*(u16 *)arg0]((void *)arg0); + func_800CCCC0(arg0); + return; + } + break; + } + if (func_80149CD4(arg0) != 0) { + D_80181584[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_8015E880)(arg0); + return; + } + if (((s32 (*)(s32))func_80149744)(arg0) != 0) { + D_80181584[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149788)(arg0); + return; + } + if (((s32 (*)(s32))func_801496D4)(arg0) != 0) { + D_80181584[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149704)(arg0); + if (((u8)((s32 (*)(s32))func_80148AFC)(arg0)) == 0) { + func_80146D90(arg0); + } + if ((*(s32 *)(arg0 + 0x24) | *(s32 *)(arg0 + 0x2C)) != 0) { + func_80154150(arg0, 0xF); + } else { + ((void (*)(s32, s32, s32))func_801541D8)(arg0, 0xD, 6); + } + *(s32 *)(arg0 + 0x238) = 1; + return; + } + if (((s32 (*)(s32))func_801488A8)(arg0) != 0) { + sp10[0] = 0; + sp10[1] = 0; + sp10[2] = 0; + t = *(s16 *)(arg0 + 0x26); + sp18[0] = t; + sp18[1] = 0; + t = *(s16 *)(arg0 + 0x2E); + sp18[2] = t; + D_80181584[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 1); + ((void (*)(s32))func_8015A264)(arg0); + t = -(((s32 (*)(s16 *, s16 *))func_80013294)(sp10, sp18) << 0x10); + if (t < *(s32 *)(arg0 + 0x2C)) { + *(s32 *)(arg0 + 0x2C) = t; + } + return; + } + if (*(u16 *)(arg0 + 0xB8) == 0x8000) { + D_80181584[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 0); + ((void (*)(s32))func_80159B70)(arg0); + return; + } + z = *(s32 *)(arg0 + 0x2C); + if (func_8016F1AC() != 0) { + goto zero; + } + if (z <= lim) { + goto one; + } + if (D_8011F9C4 == 0) { + goto zero; + } + if (((u8)func_80029178(0x21)) != 0) { + goto zero; + } +one: + doit = 1; + goto join; +zero: + doit = 0; +join: + if (doit != 0) { + D_80181584[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 0); + ((void (*)(s32))func_80159B70)(arg0); + func_80154150(arg0, 9); + ((void (*)(s32, s32 *))func_80146DB8)(arg0, &D_80181518); + ((void (*)(s32, s32))func_80161CD0)(arg0, *(u16 *)(arg0 + 0x16E)); + return; + } + if (func_80161208(arg0) == 0) { + ((void (*)(s32))func_801725A4)(arg0); + } +} DEFINE_func_8015BD8C() /* dedup: shared engine-core @0x8015BD8C (src/shared) */ diff --git a/src/ov_SC03_024/ov_SC03_024_jr_8015AE2C.c b/src/ov_SC03_024/ov_SC03_024_jr_8015AE2C.c index ba598e4ee..3dd14343c 100644 --- a/src/ov_SC03_024/ov_SC03_024_jr_8015AE2C.c +++ b/src/ov_SC03_024/ov_SC03_024_jr_8015AE2C.c @@ -1513,7 +1513,259 @@ DEFINE_func_8015B858() /* dedup: shared engine-core @0x8015B858 (src/shared) */ DEFINE_func_8015B8F8() /* dedup: shared engine-core @0x8015B8F8 (src/shared) */ -INCLUDE_ASM("asm/ov_SC03_024/nonmatchings/ov_SC03_024_jr_8015AE2C", func_8015B950); +extern s32 func_8015AE2C(); + +// @class: plumbing +// @stuck: none — MATCH (271/271, pin-free, zero asm). The ONLY residual is DEF-SIDE plumbing, and it is now named exactly: the in-TU instantiation `DEFINE_func_8015BEE4()` (engine_core.h:1851-1855) expands to `extern s32 func_8015B950(void);` INSIDE ov_SC01_077_jr_8015AE2C.c, ~14 lines BELOW this definition, so the 1-param def collides with a `(void)` prototype -> `conflicting types for func_8015B950` (.run/bank_func_8015B950.log). §73 PARAMS axis / T0. Surgical fix = §65b de-macroize that ONE instantiation (blast radius: this TU); the fleet-wide `(void)`->`()` header edit is §63 and must be R22-validated. +/* func_8015B950 (ov_SC01_077_jr_8015AE2C, 271 ins, jtbl_801D8B74) — SESSION-21 re-verified + * + * ── ROUND-2 INDEPENDENT RE-VERIFICATION (2026-07-27, fresh agent, §88e discipline) ───────────── + * match_one : MATCH (271 ins) against the CURRENT tree — §87 staleness re-checked today. + * .text size: compiled .text = 0x43C = 1084 B = 271 ins, EXACTLY the target's declared 0x43C + * ("nonmatching func_8015B950, 0x43C"). So this is NOT a §83a length drift hiding + * behind a zero count — the count is over equal-length streams. + * jtbl : RE-DECODED MECHANICALLY, not inherited. Compiled .rodata = 0x1C = 28 B = 7 words, + * 7x R_MIPS_32 -> .text with implicit addends [58,58,58,E0,F0,100,58]; +0x8015B950 + * = [8015B9A8, 8015B9A8, 8015B9A8, 8015BA30, 8015BA40, 8015BA50, 8015B9A8]. + * Diffed word-for-word against asm/ov_SC01_077/data/tail14.data.s:15-23 — 7/7 identical. + * symcheck : SYMS-DIFF target=35 draft=34, sole MISSING = jtbl_801D8B74. This is the §81 jr + * FALSE POSITIVE, re-confirmed here by reading the relocs: gcc emits its OWN table and + * references it with R_MIPS_HI16/LO16 against the SECTION `.rodata` (t.o +0x40/+0x48), + * so the splat's dlabel NAME can never appear in the draft object's relocation set. + * Nothing is dropped and nothing is invented: the draft's other 34 symbols are exactly + * the target's other 34. + * FAMILY : the x138 remap is clean and §84-safe. Every sibling is 271 ins with an IDENTICAL + * callee set; only THREE names vary per overlay — the two data labels and the jtbl: + * ov_SC01_077 D_8018953C / D_801895A8 / jtbl_801D8B74 + * ov_SC03_099 D_80185A50 / D_80185ABC / jtbl_801BD898 + * ov_SC06_008 D_80187E44 / D_80187EB0 / jtbl_801A8734 + * The pair is always +0x6C apart, and NO literal in this draft encodes that distance + * (both labels are referenced by name), so there is no §84 derived-offset hazard. + * D_8011F9C4 is fleet-constant (main-EXE data) and must NOT be remapped. + * + * match_one: MATCH (271 ins) against the CURRENT tree (§87 staleness re-checked, 2026-07-27). + * PIN-FREE, zero asm, offset-pure (s32 arg0 + raw offsets) — x138 template-safe. + * Provenance: this is the Phase-26 crack (.run/phase26-cracks/func_8015B950.c) re-gated verbatim, + * with ONE deliberate change: the definition's return type void -> s32. + * - `void func_8015B950(s32 arg0)` : MATCH (271 ins) [the Phase-26 form] + * - `s32 func_8015B950(s32 arg0)` : MATCH (271 ins) [shipped — §3a-1 void->s32 is byte-neutral] + * The fleet/engine_core.h canonical decl is `extern s32 func_8015B950(void);` (engine_core.h:1852), + * and the last bank attempt (.run/bank_func_8015B950.log) died on `conflicting types for + * func_8015B950`. Shipping the s32 return kills the §73 RETURN axis for free and leaves only the + * cheap T0 PARAMS axis for the ladder (fix_header_decl.py / --fix-def-sig / cast_call_sites). + * Both forms are byte-identical, so the orchestrator may swap the return type back at zero cost. + * + * SYMBOLS (§58 rules 1/2 — all splat spellings, all verified present): + * D_801895A8 asm/ov_SC01_077/data/tail.data.s:4355 (the state-handler vtable) + * D_8018953C asm/ov_SC01_077/data/tail.data.s:4293 + * D_8011F9C4 main-EXE data; spelled `extern s32 D_8011F9C4;` in 5+ already-banked TUs + * jtbl_801D8B74 asm/ov_SC01_077/data/tail14.data.s:15 (compiler jump table — not named in C) + * + * JTBL VERIFIED (§8a gate): compiled .rodata = exactly 0x1C B / 7 words, 7x R_MIPS_32 .text with + * addends [0x58,0x58,0x58,0xE0,0xF0,0x100,0x58] -> +0x8015B950 = [B9A8,B9A8,B9A8,BA30,BA40,BA50, + * B9A8] == the original words at 0x801D8B74..0x801D8B8C. Bound `sltiu $v0,$v1,0x7` matches. + * The raw dlabel's 8th word 0x00000000 is NOT an entry — it is the intra-TU `.align 3` pad of the + * B34/B54/B74 jtbl chain; the object can never emit it (maspsx drops .align), so it must stay in + * the post-carve RAW data piece (the §53/§62/§81 carve chain applies at bank time). + * + * Same family as the TU's own already-matched func_8015AE2C: 7-case switch on ((s32 (*)(s32))func_801619A4)() + * (0/1/2/6 shared, 3/4/5 own, no default block — out-of-range and every `break` fall to the + * after-switch join), then a chain of "state handler" tests, each dispatching + * D_801895A8[*(u16*)arg0](arg0) and returning. + * + * THREE LEVERS (draft -> MATCH in 3 compiles): + * + * 1. PROLOGUE CONSTANT = an INITIALIZED LOCAL, not a literal in the compare. + * Target opens with `lui $s2, 0xFFF5` in the *prologue*, used once ~200 ins later in + * `slt $v0,$s2,$s1`. No gcc-2.7.2 pass hoists a (set reg const_int) across basic blocks + * (loop.c needs a loop; cse/combine/sched never move insns between BBs) — so the insn must + * have been EMITTED in the first BB, i.e. the constant is a local initialized at the top of + * the function. cse then cannot fold it back into the compare: the `slt` operand predicate is + * `arith_operand`, which rejects a CONST_INT wider than 16 bits, so validate_change fails and + * the pseudo survives. Its live range spans every call -> global.c gives it a callee-saved reg. + * Writing `z > -0xB0000` inline instead emits the `lui` into the branch delay slot next to the + * compare (caller-saved $v0) and the function is 1 insn short. => `s32 lim = -0xB0000;` at top. + * + * 2. `lh` vs `lhu`: a short->short copy is a pure HImode move and gcc emits `lhu`. The target's + * `lh $v0,0x26($s0)` means the value passed through an SImode (int) temp: expand makes + * (set (reg:SI) (sign_extend (mem:HI))) + (set (mem:HI) (subreg:HI ...)), and combine cannot + * merge them (the merged form is mem<-mem, which no movhi accepts) so the sign-extending load + * survives. => route both halfword copies through the `s32 t` temp. + * + * 3. THE `goto` LAYOUT — dodging jump.c's store-flag conversion (jump.c:1005-1065). + * An if/else chain writing 0/1 into `doit` makes gcc collapse the last pair into + * `sltiu $v0,$v0,1`. jump.c fires that conversion when the insn immediately after a + * conditional jump is a lone `SET pseudo, CONST_INT` whose following simplejump targets the + * SAME label as the branch (jump.c:1038 `reallabelprev == temp || ... JUMP_LABEL(temp4) == + * JUMP_LABEL(insn)`) — exactly the shape of `if (c) x=0; else x=1;`. + * The target instead cross-jumps ALL the `doit=0` exits into ONE shared block placed after the + * `doit=1` fall-through; reorg's fill_slots_from_thread then COPIES that single set into all + * three branch delay slots and redirects each branch past it (which is why `addu $v0,$zero, + * $zero` appears 3x in delay slots and the shared block vanishes). A `goto zero;` / `goto one;` + * chain expresses that layout directly, and each conditional jump is then followed by a + * compare/call rather than a lone const set, so the store-flag conversion never triggers. + * GENERAL RULE: multiple predicates that all assign the SAME constant to one flag => write + * them as `goto` to a shared assignment, never as an if/else ladder. + */ +extern s32 D_8011F9C4; +extern s32 D_8018953C; + +extern s32 func_80161B18(void); +extern s32 func_801619A4(s32*); +extern s32 func_80149AA8(s32*); +extern void func_80149AD4(s32*); +extern s32 func_80149B54(s32*); +extern void func_80149BAC(s32*); +extern s32 func_801498E0(s32*); +extern s32 func_80149954(s32); +extern s32 func_80149A64(s32*); +extern void func_800CCCC0(s32 a0); +extern s32 func_80149CD4(s32 a0); +extern void func_8015E880(s32*); +extern s32 func_80149744(struct S_80149744*); +extern void func_80149788(void); +extern s32 func_801496D4(void*); +extern void func_80149704(void); +extern int func_80148AFC(void*); +extern void func_80146D90(s32 a0); +extern void func_80154150(s32 a0, s32 a1); +extern void func_801541D8(u8*, s32, s32); +extern s32 func_801488A8(u8*); +extern void func_80147078(s32*, s16); +extern void func_8015A264(void*); +extern s32 func_80013294(void*, void*); +extern void func_80159B70(void*); +extern s32 func_8016F1AC(void); +extern s32 func_80029178(s32 a0); +extern void func_80146DB8(s32*, s32*); +extern s32 func_80161CD0(s32, s32); +extern s32 func_80161208(s32 a0); +extern s32 func_801725A4(u8*); + +s32 func_8015B950(s32 arg0) +{ + + extern void (*D_801895A8[])(void *); + s16 sp10[4]; + s16 sp18[4]; + s32 t; + s32 z; + s32 doit; + s32 lim = -0xB0000; + + if (func_80161B18() != 0) { + return; + } + switch (((s32 (*)(s32))func_801619A4)(arg0)) { + case 0: + case 1: + case 2: + case 6: + if (((s32 (*)(s32))func_80149AA8)(arg0) != 0) { + D_801895A8[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149AD4)(arg0); + return; + } + if (((s32 (*)(s32))func_80149B54)(arg0) != 0) { + D_801895A8[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149BAC)(arg0); + return; + } + break; + case 3: + ((void (*)(s32))func_801498E0)(arg0); + break; + case 4: + ((void (*)(s32))func_80149954)(arg0); + break; + case 5: + if (((s32 (*)(s32))func_80149A64)(arg0) != 0) { + D_801895A8[*(u16 *)arg0]((void *)arg0); + func_800CCCC0(arg0); + return; + } + break; + } + if (func_80149CD4(arg0) != 0) { + D_801895A8[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_8015E880)(arg0); + return; + } + if (((s32 (*)(s32))func_80149744)(arg0) != 0) { + D_801895A8[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149788)(arg0); + return; + } + if (((s32 (*)(s32))func_801496D4)(arg0) != 0) { + D_801895A8[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149704)(arg0); + if (((u8)((s32 (*)(s32))func_80148AFC)(arg0)) == 0) { + func_80146D90(arg0); + } + if ((*(s32 *)(arg0 + 0x24) | *(s32 *)(arg0 + 0x2C)) != 0) { + func_80154150(arg0, 0xF); + } else { + ((void (*)(s32, s32, s32))func_801541D8)(arg0, 0xD, 6); + } + *(s32 *)(arg0 + 0x238) = 1; + return; + } + if (((s32 (*)(s32))func_801488A8)(arg0) != 0) { + sp10[0] = 0; + sp10[1] = 0; + sp10[2] = 0; + t = *(s16 *)(arg0 + 0x26); + sp18[0] = t; + sp18[1] = 0; + t = *(s16 *)(arg0 + 0x2E); + sp18[2] = t; + D_801895A8[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 1); + ((void (*)(s32))func_8015A264)(arg0); + t = -(((s32 (*)(s16 *, s16 *))func_80013294)(sp10, sp18) << 0x10); + if (t < *(s32 *)(arg0 + 0x2C)) { + *(s32 *)(arg0 + 0x2C) = t; + } + return; + } + if (*(u16 *)(arg0 + 0xB8) == 0x8000) { + D_801895A8[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 0); + ((void (*)(s32))func_80159B70)(arg0); + return; + } + z = *(s32 *)(arg0 + 0x2C); + if (func_8016F1AC() != 0) { + goto zero; + } + if (z <= lim) { + goto one; + } + if (D_8011F9C4 == 0) { + goto zero; + } + if (((u8)func_80029178(0x21)) != 0) { + goto zero; + } +one: + doit = 1; + goto join; +zero: + doit = 0; +join: + if (doit != 0) { + D_801895A8[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 0); + ((void (*)(s32))func_80159B70)(arg0); + func_80154150(arg0, 9); + ((void (*)(s32, s32 *))func_80146DB8)(arg0, &D_8018953C); + ((void (*)(s32, s32))func_80161CD0)(arg0, *(u16 *)(arg0 + 0x16E)); + return; + } + if (func_80161208(arg0) == 0) { + ((void (*)(s32))func_801725A4)(arg0); + } +} DEFINE_func_8015BD8C() /* dedup: shared engine-core @0x8015BD8C (src/shared) */ diff --git a/src/ov_SC03_028/ov_SC03_028_jr_8015AE2C.c b/src/ov_SC03_028/ov_SC03_028_jr_8015AE2C.c index ec18c2ca6..3a94b73ce 100644 --- a/src/ov_SC03_028/ov_SC03_028_jr_8015AE2C.c +++ b/src/ov_SC03_028/ov_SC03_028_jr_8015AE2C.c @@ -1513,7 +1513,259 @@ DEFINE_func_8015B858() /* dedup: shared engine-core @0x8015B858 (src/shared) */ DEFINE_func_8015B8F8() /* dedup: shared engine-core @0x8015B8F8 (src/shared) */ -INCLUDE_ASM("asm/ov_SC03_028/nonmatchings/ov_SC03_028_jr_8015AE2C", func_8015B950); +extern s32 func_8015AE2C(); + +// @class: plumbing +// @stuck: none — MATCH (271/271, pin-free, zero asm). The ONLY residual is DEF-SIDE plumbing, and it is now named exactly: the in-TU instantiation `DEFINE_func_8015BEE4()` (engine_core.h:1851-1855) expands to `extern s32 func_8015B950(void);` INSIDE ov_SC01_077_jr_8015AE2C.c, ~14 lines BELOW this definition, so the 1-param def collides with a `(void)` prototype -> `conflicting types for func_8015B950` (.run/bank_func_8015B950.log). §73 PARAMS axis / T0. Surgical fix = §65b de-macroize that ONE instantiation (blast radius: this TU); the fleet-wide `(void)`->`()` header edit is §63 and must be R22-validated. +/* func_8015B950 (ov_SC01_077_jr_8015AE2C, 271 ins, jtbl_801D8B74) — SESSION-21 re-verified + * + * ── ROUND-2 INDEPENDENT RE-VERIFICATION (2026-07-27, fresh agent, §88e discipline) ───────────── + * match_one : MATCH (271 ins) against the CURRENT tree — §87 staleness re-checked today. + * .text size: compiled .text = 0x43C = 1084 B = 271 ins, EXACTLY the target's declared 0x43C + * ("nonmatching func_8015B950, 0x43C"). So this is NOT a §83a length drift hiding + * behind a zero count — the count is over equal-length streams. + * jtbl : RE-DECODED MECHANICALLY, not inherited. Compiled .rodata = 0x1C = 28 B = 7 words, + * 7x R_MIPS_32 -> .text with implicit addends [58,58,58,E0,F0,100,58]; +0x8015B950 + * = [8015B9A8, 8015B9A8, 8015B9A8, 8015BA30, 8015BA40, 8015BA50, 8015B9A8]. + * Diffed word-for-word against asm/ov_SC01_077/data/tail14.data.s:15-23 — 7/7 identical. + * symcheck : SYMS-DIFF target=35 draft=34, sole MISSING = jtbl_801D8B74. This is the §81 jr + * FALSE POSITIVE, re-confirmed here by reading the relocs: gcc emits its OWN table and + * references it with R_MIPS_HI16/LO16 against the SECTION `.rodata` (t.o +0x40/+0x48), + * so the splat's dlabel NAME can never appear in the draft object's relocation set. + * Nothing is dropped and nothing is invented: the draft's other 34 symbols are exactly + * the target's other 34. + * FAMILY : the x138 remap is clean and §84-safe. Every sibling is 271 ins with an IDENTICAL + * callee set; only THREE names vary per overlay — the two data labels and the jtbl: + * ov_SC01_077 D_8018E008 / D_8018E074 / jtbl_801D8B74 + * ov_SC03_099 D_80185A50 / D_80185ABC / jtbl_801BD898 + * ov_SC06_008 D_80187E44 / D_80187EB0 / jtbl_801A8734 + * The pair is always +0x6C apart, and NO literal in this draft encodes that distance + * (both labels are referenced by name), so there is no §84 derived-offset hazard. + * D_8011F9C4 is fleet-constant (main-EXE data) and must NOT be remapped. + * + * match_one: MATCH (271 ins) against the CURRENT tree (§87 staleness re-checked, 2026-07-27). + * PIN-FREE, zero asm, offset-pure (s32 arg0 + raw offsets) — x138 template-safe. + * Provenance: this is the Phase-26 crack (.run/phase26-cracks/func_8015B950.c) re-gated verbatim, + * with ONE deliberate change: the definition's return type void -> s32. + * - `void func_8015B950(s32 arg0)` : MATCH (271 ins) [the Phase-26 form] + * - `s32 func_8015B950(s32 arg0)` : MATCH (271 ins) [shipped — §3a-1 void->s32 is byte-neutral] + * The fleet/engine_core.h canonical decl is `extern s32 func_8015B950(void);` (engine_core.h:1852), + * and the last bank attempt (.run/bank_func_8015B950.log) died on `conflicting types for + * func_8015B950`. Shipping the s32 return kills the §73 RETURN axis for free and leaves only the + * cheap T0 PARAMS axis for the ladder (fix_header_decl.py / --fix-def-sig / cast_call_sites). + * Both forms are byte-identical, so the orchestrator may swap the return type back at zero cost. + * + * SYMBOLS (§58 rules 1/2 — all splat spellings, all verified present): + * D_8018E074 asm/ov_SC01_077/data/tail.data.s:4355 (the state-handler vtable) + * D_8018E008 asm/ov_SC01_077/data/tail.data.s:4293 + * D_8011F9C4 main-EXE data; spelled `extern s32 D_8011F9C4;` in 5+ already-banked TUs + * jtbl_801D8B74 asm/ov_SC01_077/data/tail14.data.s:15 (compiler jump table — not named in C) + * + * JTBL VERIFIED (§8a gate): compiled .rodata = exactly 0x1C B / 7 words, 7x R_MIPS_32 .text with + * addends [0x58,0x58,0x58,0xE0,0xF0,0x100,0x58] -> +0x8015B950 = [B9A8,B9A8,B9A8,BA30,BA40,BA50, + * B9A8] == the original words at 0x801D8B74..0x801D8B8C. Bound `sltiu $v0,$v1,0x7` matches. + * The raw dlabel's 8th word 0x00000000 is NOT an entry — it is the intra-TU `.align 3` pad of the + * B34/B54/B74 jtbl chain; the object can never emit it (maspsx drops .align), so it must stay in + * the post-carve RAW data piece (the §53/§62/§81 carve chain applies at bank time). + * + * Same family as the TU's own already-matched func_8015AE2C: 7-case switch on ((s32 (*)(s32))func_801619A4)() + * (0/1/2/6 shared, 3/4/5 own, no default block — out-of-range and every `break` fall to the + * after-switch join), then a chain of "state handler" tests, each dispatching + * D_8018E074[*(u16*)arg0](arg0) and returning. + * + * THREE LEVERS (draft -> MATCH in 3 compiles): + * + * 1. PROLOGUE CONSTANT = an INITIALIZED LOCAL, not a literal in the compare. + * Target opens with `lui $s2, 0xFFF5` in the *prologue*, used once ~200 ins later in + * `slt $v0,$s2,$s1`. No gcc-2.7.2 pass hoists a (set reg const_int) across basic blocks + * (loop.c needs a loop; cse/combine/sched never move insns between BBs) — so the insn must + * have been EMITTED in the first BB, i.e. the constant is a local initialized at the top of + * the function. cse then cannot fold it back into the compare: the `slt` operand predicate is + * `arith_operand`, which rejects a CONST_INT wider than 16 bits, so validate_change fails and + * the pseudo survives. Its live range spans every call -> global.c gives it a callee-saved reg. + * Writing `z > -0xB0000` inline instead emits the `lui` into the branch delay slot next to the + * compare (caller-saved $v0) and the function is 1 insn short. => `s32 lim = -0xB0000;` at top. + * + * 2. `lh` vs `lhu`: a short->short copy is a pure HImode move and gcc emits `lhu`. The target's + * `lh $v0,0x26($s0)` means the value passed through an SImode (int) temp: expand makes + * (set (reg:SI) (sign_extend (mem:HI))) + (set (mem:HI) (subreg:HI ...)), and combine cannot + * merge them (the merged form is mem<-mem, which no movhi accepts) so the sign-extending load + * survives. => route both halfword copies through the `s32 t` temp. + * + * 3. THE `goto` LAYOUT — dodging jump.c's store-flag conversion (jump.c:1005-1065). + * An if/else chain writing 0/1 into `doit` makes gcc collapse the last pair into + * `sltiu $v0,$v0,1`. jump.c fires that conversion when the insn immediately after a + * conditional jump is a lone `SET pseudo, CONST_INT` whose following simplejump targets the + * SAME label as the branch (jump.c:1038 `reallabelprev == temp || ... JUMP_LABEL(temp4) == + * JUMP_LABEL(insn)`) — exactly the shape of `if (c) x=0; else x=1;`. + * The target instead cross-jumps ALL the `doit=0` exits into ONE shared block placed after the + * `doit=1` fall-through; reorg's fill_slots_from_thread then COPIES that single set into all + * three branch delay slots and redirects each branch past it (which is why `addu $v0,$zero, + * $zero` appears 3x in delay slots and the shared block vanishes). A `goto zero;` / `goto one;` + * chain expresses that layout directly, and each conditional jump is then followed by a + * compare/call rather than a lone const set, so the store-flag conversion never triggers. + * GENERAL RULE: multiple predicates that all assign the SAME constant to one flag => write + * them as `goto` to a shared assignment, never as an if/else ladder. + */ +extern s32 D_8011F9C4; +extern s32 D_8018E008; + +extern s32 func_80161B18(void); +extern s32 func_801619A4(s32*); +extern s32 func_80149AA8(s32*); +extern void func_80149AD4(s32*); +extern s32 func_80149B54(s32*); +extern void func_80149BAC(s32*); +extern s32 func_801498E0(s32*); +extern s32 func_80149954(s32); +extern s32 func_80149A64(s32*); +extern void func_800CCCC0(s32 a0); +extern s32 func_80149CD4(s32 a0); +extern void func_8015E880(s32*); +extern s32 func_80149744(struct S_80149744*); +extern void func_80149788(void); +extern s32 func_801496D4(void*); +extern void func_80149704(void); +extern int func_80148AFC(void*); +extern void func_80146D90(s32 a0); +extern void func_80154150(s32 a0, s32 a1); +extern void func_801541D8(u8*, s32, s32); +extern s32 func_801488A8(u8*); +extern void func_80147078(s32*, s16); +extern void func_8015A264(void*); +extern s32 func_80013294(void*, void*); +extern void func_80159B70(void*); +extern s32 func_8016F1AC(void); +extern s32 func_80029178(s32 a0); +extern void func_80146DB8(s32*, s32*); +extern s32 func_80161CD0(s32, s32); +extern s32 func_80161208(s32 a0); +extern s32 func_801725A4(u8*); + +s32 func_8015B950(s32 arg0) +{ + + extern void (*D_8018E074[])(void *); + s16 sp10[4]; + s16 sp18[4]; + s32 t; + s32 z; + s32 doit; + s32 lim = -0xB0000; + + if (func_80161B18() != 0) { + return; + } + switch (((s32 (*)(s32))func_801619A4)(arg0)) { + case 0: + case 1: + case 2: + case 6: + if (((s32 (*)(s32))func_80149AA8)(arg0) != 0) { + D_8018E074[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149AD4)(arg0); + return; + } + if (((s32 (*)(s32))func_80149B54)(arg0) != 0) { + D_8018E074[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149BAC)(arg0); + return; + } + break; + case 3: + ((void (*)(s32))func_801498E0)(arg0); + break; + case 4: + ((void (*)(s32))func_80149954)(arg0); + break; + case 5: + if (((s32 (*)(s32))func_80149A64)(arg0) != 0) { + D_8018E074[*(u16 *)arg0]((void *)arg0); + func_800CCCC0(arg0); + return; + } + break; + } + if (func_80149CD4(arg0) != 0) { + D_8018E074[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_8015E880)(arg0); + return; + } + if (((s32 (*)(s32))func_80149744)(arg0) != 0) { + D_8018E074[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149788)(arg0); + return; + } + if (((s32 (*)(s32))func_801496D4)(arg0) != 0) { + D_8018E074[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149704)(arg0); + if (((u8)((s32 (*)(s32))func_80148AFC)(arg0)) == 0) { + func_80146D90(arg0); + } + if ((*(s32 *)(arg0 + 0x24) | *(s32 *)(arg0 + 0x2C)) != 0) { + func_80154150(arg0, 0xF); + } else { + ((void (*)(s32, s32, s32))func_801541D8)(arg0, 0xD, 6); + } + *(s32 *)(arg0 + 0x238) = 1; + return; + } + if (((s32 (*)(s32))func_801488A8)(arg0) != 0) { + sp10[0] = 0; + sp10[1] = 0; + sp10[2] = 0; + t = *(s16 *)(arg0 + 0x26); + sp18[0] = t; + sp18[1] = 0; + t = *(s16 *)(arg0 + 0x2E); + sp18[2] = t; + D_8018E074[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 1); + ((void (*)(s32))func_8015A264)(arg0); + t = -(((s32 (*)(s16 *, s16 *))func_80013294)(sp10, sp18) << 0x10); + if (t < *(s32 *)(arg0 + 0x2C)) { + *(s32 *)(arg0 + 0x2C) = t; + } + return; + } + if (*(u16 *)(arg0 + 0xB8) == 0x8000) { + D_8018E074[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 0); + ((void (*)(s32))func_80159B70)(arg0); + return; + } + z = *(s32 *)(arg0 + 0x2C); + if (func_8016F1AC() != 0) { + goto zero; + } + if (z <= lim) { + goto one; + } + if (D_8011F9C4 == 0) { + goto zero; + } + if (((u8)func_80029178(0x21)) != 0) { + goto zero; + } +one: + doit = 1; + goto join; +zero: + doit = 0; +join: + if (doit != 0) { + D_8018E074[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 0); + ((void (*)(s32))func_80159B70)(arg0); + func_80154150(arg0, 9); + ((void (*)(s32, s32 *))func_80146DB8)(arg0, &D_8018E008); + ((void (*)(s32, s32))func_80161CD0)(arg0, *(u16 *)(arg0 + 0x16E)); + return; + } + if (func_80161208(arg0) == 0) { + ((void (*)(s32))func_801725A4)(arg0); + } +} DEFINE_func_8015BD8C() /* dedup: shared engine-core @0x8015BD8C (src/shared) */ diff --git a/src/ov_SC03_029/ov_SC03_029_jr_8015AE2C.c b/src/ov_SC03_029/ov_SC03_029_jr_8015AE2C.c index 693505550..70671002c 100644 --- a/src/ov_SC03_029/ov_SC03_029_jr_8015AE2C.c +++ b/src/ov_SC03_029/ov_SC03_029_jr_8015AE2C.c @@ -1513,7 +1513,259 @@ DEFINE_func_8015B858() /* dedup: shared engine-core @0x8015B858 (src/shared) */ DEFINE_func_8015B8F8() /* dedup: shared engine-core @0x8015B8F8 (src/shared) */ -INCLUDE_ASM("asm/ov_SC03_029/nonmatchings/ov_SC03_029_jr_8015AE2C", func_8015B950); +extern s32 func_8015AE2C(); + +// @class: plumbing +// @stuck: none — MATCH (271/271, pin-free, zero asm). The ONLY residual is DEF-SIDE plumbing, and it is now named exactly: the in-TU instantiation `DEFINE_func_8015BEE4()` (engine_core.h:1851-1855) expands to `extern s32 func_8015B950(void);` INSIDE ov_SC01_077_jr_8015AE2C.c, ~14 lines BELOW this definition, so the 1-param def collides with a `(void)` prototype -> `conflicting types for func_8015B950` (.run/bank_func_8015B950.log). §73 PARAMS axis / T0. Surgical fix = §65b de-macroize that ONE instantiation (blast radius: this TU); the fleet-wide `(void)`->`()` header edit is §63 and must be R22-validated. +/* func_8015B950 (ov_SC01_077_jr_8015AE2C, 271 ins, jtbl_801D8B74) — SESSION-21 re-verified + * + * ── ROUND-2 INDEPENDENT RE-VERIFICATION (2026-07-27, fresh agent, §88e discipline) ───────────── + * match_one : MATCH (271 ins) against the CURRENT tree — §87 staleness re-checked today. + * .text size: compiled .text = 0x43C = 1084 B = 271 ins, EXACTLY the target's declared 0x43C + * ("nonmatching func_8015B950, 0x43C"). So this is NOT a §83a length drift hiding + * behind a zero count — the count is over equal-length streams. + * jtbl : RE-DECODED MECHANICALLY, not inherited. Compiled .rodata = 0x1C = 28 B = 7 words, + * 7x R_MIPS_32 -> .text with implicit addends [58,58,58,E0,F0,100,58]; +0x8015B950 + * = [8015B9A8, 8015B9A8, 8015B9A8, 8015BA30, 8015BA40, 8015BA50, 8015B9A8]. + * Diffed word-for-word against asm/ov_SC01_077/data/tail14.data.s:15-23 — 7/7 identical. + * symcheck : SYMS-DIFF target=35 draft=34, sole MISSING = jtbl_801D8B74. This is the §81 jr + * FALSE POSITIVE, re-confirmed here by reading the relocs: gcc emits its OWN table and + * references it with R_MIPS_HI16/LO16 against the SECTION `.rodata` (t.o +0x40/+0x48), + * so the splat's dlabel NAME can never appear in the draft object's relocation set. + * Nothing is dropped and nothing is invented: the draft's other 34 symbols are exactly + * the target's other 34. + * FAMILY : the x138 remap is clean and §84-safe. Every sibling is 271 ins with an IDENTICAL + * callee set; only THREE names vary per overlay — the two data labels and the jtbl: + * ov_SC01_077 D_80189E40 / D_80189EAC / jtbl_801D8B74 + * ov_SC03_099 D_80185A50 / D_80185ABC / jtbl_801BD898 + * ov_SC06_008 D_80187E44 / D_80187EB0 / jtbl_801A8734 + * The pair is always +0x6C apart, and NO literal in this draft encodes that distance + * (both labels are referenced by name), so there is no §84 derived-offset hazard. + * D_8011F9C4 is fleet-constant (main-EXE data) and must NOT be remapped. + * + * match_one: MATCH (271 ins) against the CURRENT tree (§87 staleness re-checked, 2026-07-27). + * PIN-FREE, zero asm, offset-pure (s32 arg0 + raw offsets) — x138 template-safe. + * Provenance: this is the Phase-26 crack (.run/phase26-cracks/func_8015B950.c) re-gated verbatim, + * with ONE deliberate change: the definition's return type void -> s32. + * - `void func_8015B950(s32 arg0)` : MATCH (271 ins) [the Phase-26 form] + * - `s32 func_8015B950(s32 arg0)` : MATCH (271 ins) [shipped — §3a-1 void->s32 is byte-neutral] + * The fleet/engine_core.h canonical decl is `extern s32 func_8015B950(void);` (engine_core.h:1852), + * and the last bank attempt (.run/bank_func_8015B950.log) died on `conflicting types for + * func_8015B950`. Shipping the s32 return kills the §73 RETURN axis for free and leaves only the + * cheap T0 PARAMS axis for the ladder (fix_header_decl.py / --fix-def-sig / cast_call_sites). + * Both forms are byte-identical, so the orchestrator may swap the return type back at zero cost. + * + * SYMBOLS (§58 rules 1/2 — all splat spellings, all verified present): + * D_80189EAC asm/ov_SC01_077/data/tail.data.s:4355 (the state-handler vtable) + * D_80189E40 asm/ov_SC01_077/data/tail.data.s:4293 + * D_8011F9C4 main-EXE data; spelled `extern s32 D_8011F9C4;` in 5+ already-banked TUs + * jtbl_801D8B74 asm/ov_SC01_077/data/tail14.data.s:15 (compiler jump table — not named in C) + * + * JTBL VERIFIED (§8a gate): compiled .rodata = exactly 0x1C B / 7 words, 7x R_MIPS_32 .text with + * addends [0x58,0x58,0x58,0xE0,0xF0,0x100,0x58] -> +0x8015B950 = [B9A8,B9A8,B9A8,BA30,BA40,BA50, + * B9A8] == the original words at 0x801D8B74..0x801D8B8C. Bound `sltiu $v0,$v1,0x7` matches. + * The raw dlabel's 8th word 0x00000000 is NOT an entry — it is the intra-TU `.align 3` pad of the + * B34/B54/B74 jtbl chain; the object can never emit it (maspsx drops .align), so it must stay in + * the post-carve RAW data piece (the §53/§62/§81 carve chain applies at bank time). + * + * Same family as the TU's own already-matched func_8015AE2C: 7-case switch on ((s32 (*)(s32))func_801619A4)() + * (0/1/2/6 shared, 3/4/5 own, no default block — out-of-range and every `break` fall to the + * after-switch join), then a chain of "state handler" tests, each dispatching + * D_80189EAC[*(u16*)arg0](arg0) and returning. + * + * THREE LEVERS (draft -> MATCH in 3 compiles): + * + * 1. PROLOGUE CONSTANT = an INITIALIZED LOCAL, not a literal in the compare. + * Target opens with `lui $s2, 0xFFF5` in the *prologue*, used once ~200 ins later in + * `slt $v0,$s2,$s1`. No gcc-2.7.2 pass hoists a (set reg const_int) across basic blocks + * (loop.c needs a loop; cse/combine/sched never move insns between BBs) — so the insn must + * have been EMITTED in the first BB, i.e. the constant is a local initialized at the top of + * the function. cse then cannot fold it back into the compare: the `slt` operand predicate is + * `arith_operand`, which rejects a CONST_INT wider than 16 bits, so validate_change fails and + * the pseudo survives. Its live range spans every call -> global.c gives it a callee-saved reg. + * Writing `z > -0xB0000` inline instead emits the `lui` into the branch delay slot next to the + * compare (caller-saved $v0) and the function is 1 insn short. => `s32 lim = -0xB0000;` at top. + * + * 2. `lh` vs `lhu`: a short->short copy is a pure HImode move and gcc emits `lhu`. The target's + * `lh $v0,0x26($s0)` means the value passed through an SImode (int) temp: expand makes + * (set (reg:SI) (sign_extend (mem:HI))) + (set (mem:HI) (subreg:HI ...)), and combine cannot + * merge them (the merged form is mem<-mem, which no movhi accepts) so the sign-extending load + * survives. => route both halfword copies through the `s32 t` temp. + * + * 3. THE `goto` LAYOUT — dodging jump.c's store-flag conversion (jump.c:1005-1065). + * An if/else chain writing 0/1 into `doit` makes gcc collapse the last pair into + * `sltiu $v0,$v0,1`. jump.c fires that conversion when the insn immediately after a + * conditional jump is a lone `SET pseudo, CONST_INT` whose following simplejump targets the + * SAME label as the branch (jump.c:1038 `reallabelprev == temp || ... JUMP_LABEL(temp4) == + * JUMP_LABEL(insn)`) — exactly the shape of `if (c) x=0; else x=1;`. + * The target instead cross-jumps ALL the `doit=0` exits into ONE shared block placed after the + * `doit=1` fall-through; reorg's fill_slots_from_thread then COPIES that single set into all + * three branch delay slots and redirects each branch past it (which is why `addu $v0,$zero, + * $zero` appears 3x in delay slots and the shared block vanishes). A `goto zero;` / `goto one;` + * chain expresses that layout directly, and each conditional jump is then followed by a + * compare/call rather than a lone const set, so the store-flag conversion never triggers. + * GENERAL RULE: multiple predicates that all assign the SAME constant to one flag => write + * them as `goto` to a shared assignment, never as an if/else ladder. + */ +extern s32 D_8011F9C4; +extern s32 D_80189E40; + +extern s32 func_80161B18(void); +extern s32 func_801619A4(s32*); +extern s32 func_80149AA8(s32*); +extern void func_80149AD4(s32*); +extern s32 func_80149B54(s32*); +extern void func_80149BAC(s32*); +extern s32 func_801498E0(s32*); +extern s32 func_80149954(s32); +extern s32 func_80149A64(s32*); +extern void func_800CCCC0(s32 a0); +extern s32 func_80149CD4(s32 a0); +extern void func_8015E880(s32*); +extern s32 func_80149744(struct S_80149744*); +extern void func_80149788(void); +extern s32 func_801496D4(void*); +extern void func_80149704(void); +extern int func_80148AFC(void*); +extern void func_80146D90(s32 a0); +extern void func_80154150(s32 a0, s32 a1); +extern void func_801541D8(u8*, s32, s32); +extern s32 func_801488A8(u8*); +extern void func_80147078(s32*, s16); +extern void func_8015A264(void*); +extern s32 func_80013294(void*, void*); +extern void func_80159B70(void*); +extern s32 func_8016F1AC(void); +extern s32 func_80029178(s32 a0); +extern void func_80146DB8(s32*, s32*); +extern s32 func_80161CD0(s32, s32); +extern s32 func_80161208(s32 a0); +extern s32 func_801725A4(u8*); + +s32 func_8015B950(s32 arg0) +{ + + extern void (*D_80189EAC[])(void *); + s16 sp10[4]; + s16 sp18[4]; + s32 t; + s32 z; + s32 doit; + s32 lim = -0xB0000; + + if (func_80161B18() != 0) { + return; + } + switch (((s32 (*)(s32))func_801619A4)(arg0)) { + case 0: + case 1: + case 2: + case 6: + if (((s32 (*)(s32))func_80149AA8)(arg0) != 0) { + D_80189EAC[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149AD4)(arg0); + return; + } + if (((s32 (*)(s32))func_80149B54)(arg0) != 0) { + D_80189EAC[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149BAC)(arg0); + return; + } + break; + case 3: + ((void (*)(s32))func_801498E0)(arg0); + break; + case 4: + ((void (*)(s32))func_80149954)(arg0); + break; + case 5: + if (((s32 (*)(s32))func_80149A64)(arg0) != 0) { + D_80189EAC[*(u16 *)arg0]((void *)arg0); + func_800CCCC0(arg0); + return; + } + break; + } + if (func_80149CD4(arg0) != 0) { + D_80189EAC[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_8015E880)(arg0); + return; + } + if (((s32 (*)(s32))func_80149744)(arg0) != 0) { + D_80189EAC[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149788)(arg0); + return; + } + if (((s32 (*)(s32))func_801496D4)(arg0) != 0) { + D_80189EAC[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149704)(arg0); + if (((u8)((s32 (*)(s32))func_80148AFC)(arg0)) == 0) { + func_80146D90(arg0); + } + if ((*(s32 *)(arg0 + 0x24) | *(s32 *)(arg0 + 0x2C)) != 0) { + func_80154150(arg0, 0xF); + } else { + ((void (*)(s32, s32, s32))func_801541D8)(arg0, 0xD, 6); + } + *(s32 *)(arg0 + 0x238) = 1; + return; + } + if (((s32 (*)(s32))func_801488A8)(arg0) != 0) { + sp10[0] = 0; + sp10[1] = 0; + sp10[2] = 0; + t = *(s16 *)(arg0 + 0x26); + sp18[0] = t; + sp18[1] = 0; + t = *(s16 *)(arg0 + 0x2E); + sp18[2] = t; + D_80189EAC[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 1); + ((void (*)(s32))func_8015A264)(arg0); + t = -(((s32 (*)(s16 *, s16 *))func_80013294)(sp10, sp18) << 0x10); + if (t < *(s32 *)(arg0 + 0x2C)) { + *(s32 *)(arg0 + 0x2C) = t; + } + return; + } + if (*(u16 *)(arg0 + 0xB8) == 0x8000) { + D_80189EAC[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 0); + ((void (*)(s32))func_80159B70)(arg0); + return; + } + z = *(s32 *)(arg0 + 0x2C); + if (func_8016F1AC() != 0) { + goto zero; + } + if (z <= lim) { + goto one; + } + if (D_8011F9C4 == 0) { + goto zero; + } + if (((u8)func_80029178(0x21)) != 0) { + goto zero; + } +one: + doit = 1; + goto join; +zero: + doit = 0; +join: + if (doit != 0) { + D_80189EAC[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 0); + ((void (*)(s32))func_80159B70)(arg0); + func_80154150(arg0, 9); + ((void (*)(s32, s32 *))func_80146DB8)(arg0, &D_80189E40); + ((void (*)(s32, s32))func_80161CD0)(arg0, *(u16 *)(arg0 + 0x16E)); + return; + } + if (func_80161208(arg0) == 0) { + ((void (*)(s32))func_801725A4)(arg0); + } +} DEFINE_func_8015BD8C() /* dedup: shared engine-core @0x8015BD8C (src/shared) */ diff --git a/src/ov_SC03_030/ov_SC03_030_jr_8015AE2C.c b/src/ov_SC03_030/ov_SC03_030_jr_8015AE2C.c index 11c434ba8..12f6d67b3 100644 --- a/src/ov_SC03_030/ov_SC03_030_jr_8015AE2C.c +++ b/src/ov_SC03_030/ov_SC03_030_jr_8015AE2C.c @@ -1513,7 +1513,259 @@ DEFINE_func_8015B858() /* dedup: shared engine-core @0x8015B858 (src/shared) */ DEFINE_func_8015B8F8() /* dedup: shared engine-core @0x8015B8F8 (src/shared) */ -INCLUDE_ASM("asm/ov_SC03_030/nonmatchings/ov_SC03_030_jr_8015AE2C", func_8015B950); +extern s32 func_8015AE2C(); + +// @class: plumbing +// @stuck: none — MATCH (271/271, pin-free, zero asm). The ONLY residual is DEF-SIDE plumbing, and it is now named exactly: the in-TU instantiation `DEFINE_func_8015BEE4()` (engine_core.h:1851-1855) expands to `extern s32 func_8015B950(void);` INSIDE ov_SC01_077_jr_8015AE2C.c, ~14 lines BELOW this definition, so the 1-param def collides with a `(void)` prototype -> `conflicting types for func_8015B950` (.run/bank_func_8015B950.log). §73 PARAMS axis / T0. Surgical fix = §65b de-macroize that ONE instantiation (blast radius: this TU); the fleet-wide `(void)`->`()` header edit is §63 and must be R22-validated. +/* func_8015B950 (ov_SC01_077_jr_8015AE2C, 271 ins, jtbl_801D8B74) — SESSION-21 re-verified + * + * ── ROUND-2 INDEPENDENT RE-VERIFICATION (2026-07-27, fresh agent, §88e discipline) ───────────── + * match_one : MATCH (271 ins) against the CURRENT tree — §87 staleness re-checked today. + * .text size: compiled .text = 0x43C = 1084 B = 271 ins, EXACTLY the target's declared 0x43C + * ("nonmatching func_8015B950, 0x43C"). So this is NOT a §83a length drift hiding + * behind a zero count — the count is over equal-length streams. + * jtbl : RE-DECODED MECHANICALLY, not inherited. Compiled .rodata = 0x1C = 28 B = 7 words, + * 7x R_MIPS_32 -> .text with implicit addends [58,58,58,E0,F0,100,58]; +0x8015B950 + * = [8015B9A8, 8015B9A8, 8015B9A8, 8015BA30, 8015BA40, 8015BA50, 8015B9A8]. + * Diffed word-for-word against asm/ov_SC01_077/data/tail14.data.s:15-23 — 7/7 identical. + * symcheck : SYMS-DIFF target=35 draft=34, sole MISSING = jtbl_801D8B74. This is the §81 jr + * FALSE POSITIVE, re-confirmed here by reading the relocs: gcc emits its OWN table and + * references it with R_MIPS_HI16/LO16 against the SECTION `.rodata` (t.o +0x40/+0x48), + * so the splat's dlabel NAME can never appear in the draft object's relocation set. + * Nothing is dropped and nothing is invented: the draft's other 34 symbols are exactly + * the target's other 34. + * FAMILY : the x138 remap is clean and §84-safe. Every sibling is 271 ins with an IDENTICAL + * callee set; only THREE names vary per overlay — the two data labels and the jtbl: + * ov_SC01_077 D_8018447C / D_801844E8 / jtbl_801D8B74 + * ov_SC03_099 D_80185A50 / D_80185ABC / jtbl_801BD898 + * ov_SC06_008 D_80187E44 / D_80187EB0 / jtbl_801A8734 + * The pair is always +0x6C apart, and NO literal in this draft encodes that distance + * (both labels are referenced by name), so there is no §84 derived-offset hazard. + * D_8011F9C4 is fleet-constant (main-EXE data) and must NOT be remapped. + * + * match_one: MATCH (271 ins) against the CURRENT tree (§87 staleness re-checked, 2026-07-27). + * PIN-FREE, zero asm, offset-pure (s32 arg0 + raw offsets) — x138 template-safe. + * Provenance: this is the Phase-26 crack (.run/phase26-cracks/func_8015B950.c) re-gated verbatim, + * with ONE deliberate change: the definition's return type void -> s32. + * - `void func_8015B950(s32 arg0)` : MATCH (271 ins) [the Phase-26 form] + * - `s32 func_8015B950(s32 arg0)` : MATCH (271 ins) [shipped — §3a-1 void->s32 is byte-neutral] + * The fleet/engine_core.h canonical decl is `extern s32 func_8015B950(void);` (engine_core.h:1852), + * and the last bank attempt (.run/bank_func_8015B950.log) died on `conflicting types for + * func_8015B950`. Shipping the s32 return kills the §73 RETURN axis for free and leaves only the + * cheap T0 PARAMS axis for the ladder (fix_header_decl.py / --fix-def-sig / cast_call_sites). + * Both forms are byte-identical, so the orchestrator may swap the return type back at zero cost. + * + * SYMBOLS (§58 rules 1/2 — all splat spellings, all verified present): + * D_801844E8 asm/ov_SC01_077/data/tail.data.s:4355 (the state-handler vtable) + * D_8018447C asm/ov_SC01_077/data/tail.data.s:4293 + * D_8011F9C4 main-EXE data; spelled `extern s32 D_8011F9C4;` in 5+ already-banked TUs + * jtbl_801D8B74 asm/ov_SC01_077/data/tail14.data.s:15 (compiler jump table — not named in C) + * + * JTBL VERIFIED (§8a gate): compiled .rodata = exactly 0x1C B / 7 words, 7x R_MIPS_32 .text with + * addends [0x58,0x58,0x58,0xE0,0xF0,0x100,0x58] -> +0x8015B950 = [B9A8,B9A8,B9A8,BA30,BA40,BA50, + * B9A8] == the original words at 0x801D8B74..0x801D8B8C. Bound `sltiu $v0,$v1,0x7` matches. + * The raw dlabel's 8th word 0x00000000 is NOT an entry — it is the intra-TU `.align 3` pad of the + * B34/B54/B74 jtbl chain; the object can never emit it (maspsx drops .align), so it must stay in + * the post-carve RAW data piece (the §53/§62/§81 carve chain applies at bank time). + * + * Same family as the TU's own already-matched func_8015AE2C: 7-case switch on ((s32 (*)(s32))func_801619A4)() + * (0/1/2/6 shared, 3/4/5 own, no default block — out-of-range and every `break` fall to the + * after-switch join), then a chain of "state handler" tests, each dispatching + * D_801844E8[*(u16*)arg0](arg0) and returning. + * + * THREE LEVERS (draft -> MATCH in 3 compiles): + * + * 1. PROLOGUE CONSTANT = an INITIALIZED LOCAL, not a literal in the compare. + * Target opens with `lui $s2, 0xFFF5` in the *prologue*, used once ~200 ins later in + * `slt $v0,$s2,$s1`. No gcc-2.7.2 pass hoists a (set reg const_int) across basic blocks + * (loop.c needs a loop; cse/combine/sched never move insns between BBs) — so the insn must + * have been EMITTED in the first BB, i.e. the constant is a local initialized at the top of + * the function. cse then cannot fold it back into the compare: the `slt` operand predicate is + * `arith_operand`, which rejects a CONST_INT wider than 16 bits, so validate_change fails and + * the pseudo survives. Its live range spans every call -> global.c gives it a callee-saved reg. + * Writing `z > -0xB0000` inline instead emits the `lui` into the branch delay slot next to the + * compare (caller-saved $v0) and the function is 1 insn short. => `s32 lim = -0xB0000;` at top. + * + * 2. `lh` vs `lhu`: a short->short copy is a pure HImode move and gcc emits `lhu`. The target's + * `lh $v0,0x26($s0)` means the value passed through an SImode (int) temp: expand makes + * (set (reg:SI) (sign_extend (mem:HI))) + (set (mem:HI) (subreg:HI ...)), and combine cannot + * merge them (the merged form is mem<-mem, which no movhi accepts) so the sign-extending load + * survives. => route both halfword copies through the `s32 t` temp. + * + * 3. THE `goto` LAYOUT — dodging jump.c's store-flag conversion (jump.c:1005-1065). + * An if/else chain writing 0/1 into `doit` makes gcc collapse the last pair into + * `sltiu $v0,$v0,1`. jump.c fires that conversion when the insn immediately after a + * conditional jump is a lone `SET pseudo, CONST_INT` whose following simplejump targets the + * SAME label as the branch (jump.c:1038 `reallabelprev == temp || ... JUMP_LABEL(temp4) == + * JUMP_LABEL(insn)`) — exactly the shape of `if (c) x=0; else x=1;`. + * The target instead cross-jumps ALL the `doit=0` exits into ONE shared block placed after the + * `doit=1` fall-through; reorg's fill_slots_from_thread then COPIES that single set into all + * three branch delay slots and redirects each branch past it (which is why `addu $v0,$zero, + * $zero` appears 3x in delay slots and the shared block vanishes). A `goto zero;` / `goto one;` + * chain expresses that layout directly, and each conditional jump is then followed by a + * compare/call rather than a lone const set, so the store-flag conversion never triggers. + * GENERAL RULE: multiple predicates that all assign the SAME constant to one flag => write + * them as `goto` to a shared assignment, never as an if/else ladder. + */ +extern s32 D_8011F9C4; +extern s32 D_8018447C; + +extern s32 func_80161B18(void); +extern s32 func_801619A4(s32*); +extern s32 func_80149AA8(s32*); +extern void func_80149AD4(s32*); +extern s32 func_80149B54(s32*); +extern void func_80149BAC(s32*); +extern s32 func_801498E0(s32*); +extern s32 func_80149954(s32); +extern s32 func_80149A64(s32*); +extern void func_800CCCC0(s32 a0); +extern s32 func_80149CD4(s32 a0); +extern void func_8015E880(s32*); +extern s32 func_80149744(struct S_80149744*); +extern void func_80149788(void); +extern s32 func_801496D4(void*); +extern void func_80149704(void); +extern int func_80148AFC(void*); +extern void func_80146D90(s32 a0); +extern void func_80154150(s32 a0, s32 a1); +extern void func_801541D8(u8*, s32, s32); +extern s32 func_801488A8(u8*); +extern void func_80147078(s32*, s16); +extern void func_8015A264(void*); +extern s32 func_80013294(void*, void*); +extern void func_80159B70(void*); +extern s32 func_8016F1AC(void); +extern s32 func_80029178(s32 a0); +extern void func_80146DB8(s32*, s32*); +extern s32 func_80161CD0(s32, s32); +extern s32 func_80161208(s32 a0); +extern s32 func_801725A4(u8*); + +s32 func_8015B950(s32 arg0) +{ + + extern void (*D_801844E8[])(void *); + s16 sp10[4]; + s16 sp18[4]; + s32 t; + s32 z; + s32 doit; + s32 lim = -0xB0000; + + if (func_80161B18() != 0) { + return; + } + switch (((s32 (*)(s32))func_801619A4)(arg0)) { + case 0: + case 1: + case 2: + case 6: + if (((s32 (*)(s32))func_80149AA8)(arg0) != 0) { + D_801844E8[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149AD4)(arg0); + return; + } + if (((s32 (*)(s32))func_80149B54)(arg0) != 0) { + D_801844E8[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149BAC)(arg0); + return; + } + break; + case 3: + ((void (*)(s32))func_801498E0)(arg0); + break; + case 4: + ((void (*)(s32))func_80149954)(arg0); + break; + case 5: + if (((s32 (*)(s32))func_80149A64)(arg0) != 0) { + D_801844E8[*(u16 *)arg0]((void *)arg0); + func_800CCCC0(arg0); + return; + } + break; + } + if (func_80149CD4(arg0) != 0) { + D_801844E8[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_8015E880)(arg0); + return; + } + if (((s32 (*)(s32))func_80149744)(arg0) != 0) { + D_801844E8[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149788)(arg0); + return; + } + if (((s32 (*)(s32))func_801496D4)(arg0) != 0) { + D_801844E8[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149704)(arg0); + if (((u8)((s32 (*)(s32))func_80148AFC)(arg0)) == 0) { + func_80146D90(arg0); + } + if ((*(s32 *)(arg0 + 0x24) | *(s32 *)(arg0 + 0x2C)) != 0) { + func_80154150(arg0, 0xF); + } else { + ((void (*)(s32, s32, s32))func_801541D8)(arg0, 0xD, 6); + } + *(s32 *)(arg0 + 0x238) = 1; + return; + } + if (((s32 (*)(s32))func_801488A8)(arg0) != 0) { + sp10[0] = 0; + sp10[1] = 0; + sp10[2] = 0; + t = *(s16 *)(arg0 + 0x26); + sp18[0] = t; + sp18[1] = 0; + t = *(s16 *)(arg0 + 0x2E); + sp18[2] = t; + D_801844E8[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 1); + ((void (*)(s32))func_8015A264)(arg0); + t = -(((s32 (*)(s16 *, s16 *))func_80013294)(sp10, sp18) << 0x10); + if (t < *(s32 *)(arg0 + 0x2C)) { + *(s32 *)(arg0 + 0x2C) = t; + } + return; + } + if (*(u16 *)(arg0 + 0xB8) == 0x8000) { + D_801844E8[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 0); + ((void (*)(s32))func_80159B70)(arg0); + return; + } + z = *(s32 *)(arg0 + 0x2C); + if (func_8016F1AC() != 0) { + goto zero; + } + if (z <= lim) { + goto one; + } + if (D_8011F9C4 == 0) { + goto zero; + } + if (((u8)func_80029178(0x21)) != 0) { + goto zero; + } +one: + doit = 1; + goto join; +zero: + doit = 0; +join: + if (doit != 0) { + D_801844E8[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 0); + ((void (*)(s32))func_80159B70)(arg0); + func_80154150(arg0, 9); + ((void (*)(s32, s32 *))func_80146DB8)(arg0, &D_8018447C); + ((void (*)(s32, s32))func_80161CD0)(arg0, *(u16 *)(arg0 + 0x16E)); + return; + } + if (func_80161208(arg0) == 0) { + ((void (*)(s32))func_801725A4)(arg0); + } +} DEFINE_func_8015BD8C() /* dedup: shared engine-core @0x8015BD8C (src/shared) */ diff --git a/src/ov_SC03_031/ov_SC03_031_jr_8015AE2C.c b/src/ov_SC03_031/ov_SC03_031_jr_8015AE2C.c index 8bb2a0753..5ba4381a0 100644 --- a/src/ov_SC03_031/ov_SC03_031_jr_8015AE2C.c +++ b/src/ov_SC03_031/ov_SC03_031_jr_8015AE2C.c @@ -1513,7 +1513,259 @@ DEFINE_func_8015B858() /* dedup: shared engine-core @0x8015B858 (src/shared) */ DEFINE_func_8015B8F8() /* dedup: shared engine-core @0x8015B8F8 (src/shared) */ -INCLUDE_ASM("asm/ov_SC03_031/nonmatchings/ov_SC03_031_jr_8015AE2C", func_8015B950); +extern s32 func_8015AE2C(); + +// @class: plumbing +// @stuck: none — MATCH (271/271, pin-free, zero asm). The ONLY residual is DEF-SIDE plumbing, and it is now named exactly: the in-TU instantiation `DEFINE_func_8015BEE4()` (engine_core.h:1851-1855) expands to `extern s32 func_8015B950(void);` INSIDE ov_SC01_077_jr_8015AE2C.c, ~14 lines BELOW this definition, so the 1-param def collides with a `(void)` prototype -> `conflicting types for func_8015B950` (.run/bank_func_8015B950.log). §73 PARAMS axis / T0. Surgical fix = §65b de-macroize that ONE instantiation (blast radius: this TU); the fleet-wide `(void)`->`()` header edit is §63 and must be R22-validated. +/* func_8015B950 (ov_SC01_077_jr_8015AE2C, 271 ins, jtbl_801D8B74) — SESSION-21 re-verified + * + * ── ROUND-2 INDEPENDENT RE-VERIFICATION (2026-07-27, fresh agent, §88e discipline) ───────────── + * match_one : MATCH (271 ins) against the CURRENT tree — §87 staleness re-checked today. + * .text size: compiled .text = 0x43C = 1084 B = 271 ins, EXACTLY the target's declared 0x43C + * ("nonmatching func_8015B950, 0x43C"). So this is NOT a §83a length drift hiding + * behind a zero count — the count is over equal-length streams. + * jtbl : RE-DECODED MECHANICALLY, not inherited. Compiled .rodata = 0x1C = 28 B = 7 words, + * 7x R_MIPS_32 -> .text with implicit addends [58,58,58,E0,F0,100,58]; +0x8015B950 + * = [8015B9A8, 8015B9A8, 8015B9A8, 8015BA30, 8015BA40, 8015BA50, 8015B9A8]. + * Diffed word-for-word against asm/ov_SC01_077/data/tail14.data.s:15-23 — 7/7 identical. + * symcheck : SYMS-DIFF target=35 draft=34, sole MISSING = jtbl_801D8B74. This is the §81 jr + * FALSE POSITIVE, re-confirmed here by reading the relocs: gcc emits its OWN table and + * references it with R_MIPS_HI16/LO16 against the SECTION `.rodata` (t.o +0x40/+0x48), + * so the splat's dlabel NAME can never appear in the draft object's relocation set. + * Nothing is dropped and nothing is invented: the draft's other 34 symbols are exactly + * the target's other 34. + * FAMILY : the x138 remap is clean and §84-safe. Every sibling is 271 ins with an IDENTICAL + * callee set; only THREE names vary per overlay — the two data labels and the jtbl: + * ov_SC01_077 D_80184998 / D_80184A04 / jtbl_801D8B74 + * ov_SC03_099 D_80185A50 / D_80185ABC / jtbl_801BD898 + * ov_SC06_008 D_80187E44 / D_80187EB0 / jtbl_801A8734 + * The pair is always +0x6C apart, and NO literal in this draft encodes that distance + * (both labels are referenced by name), so there is no §84 derived-offset hazard. + * D_8011F9C4 is fleet-constant (main-EXE data) and must NOT be remapped. + * + * match_one: MATCH (271 ins) against the CURRENT tree (§87 staleness re-checked, 2026-07-27). + * PIN-FREE, zero asm, offset-pure (s32 arg0 + raw offsets) — x138 template-safe. + * Provenance: this is the Phase-26 crack (.run/phase26-cracks/func_8015B950.c) re-gated verbatim, + * with ONE deliberate change: the definition's return type void -> s32. + * - `void func_8015B950(s32 arg0)` : MATCH (271 ins) [the Phase-26 form] + * - `s32 func_8015B950(s32 arg0)` : MATCH (271 ins) [shipped — §3a-1 void->s32 is byte-neutral] + * The fleet/engine_core.h canonical decl is `extern s32 func_8015B950(void);` (engine_core.h:1852), + * and the last bank attempt (.run/bank_func_8015B950.log) died on `conflicting types for + * func_8015B950`. Shipping the s32 return kills the §73 RETURN axis for free and leaves only the + * cheap T0 PARAMS axis for the ladder (fix_header_decl.py / --fix-def-sig / cast_call_sites). + * Both forms are byte-identical, so the orchestrator may swap the return type back at zero cost. + * + * SYMBOLS (§58 rules 1/2 — all splat spellings, all verified present): + * D_80184A04 asm/ov_SC01_077/data/tail.data.s:4355 (the state-handler vtable) + * D_80184998 asm/ov_SC01_077/data/tail.data.s:4293 + * D_8011F9C4 main-EXE data; spelled `extern s32 D_8011F9C4;` in 5+ already-banked TUs + * jtbl_801D8B74 asm/ov_SC01_077/data/tail14.data.s:15 (compiler jump table — not named in C) + * + * JTBL VERIFIED (§8a gate): compiled .rodata = exactly 0x1C B / 7 words, 7x R_MIPS_32 .text with + * addends [0x58,0x58,0x58,0xE0,0xF0,0x100,0x58] -> +0x8015B950 = [B9A8,B9A8,B9A8,BA30,BA40,BA50, + * B9A8] == the original words at 0x801D8B74..0x801D8B8C. Bound `sltiu $v0,$v1,0x7` matches. + * The raw dlabel's 8th word 0x00000000 is NOT an entry — it is the intra-TU `.align 3` pad of the + * B34/B54/B74 jtbl chain; the object can never emit it (maspsx drops .align), so it must stay in + * the post-carve RAW data piece (the §53/§62/§81 carve chain applies at bank time). + * + * Same family as the TU's own already-matched func_8015AE2C: 7-case switch on ((s32 (*)(s32))func_801619A4)() + * (0/1/2/6 shared, 3/4/5 own, no default block — out-of-range and every `break` fall to the + * after-switch join), then a chain of "state handler" tests, each dispatching + * D_80184A04[*(u16*)arg0](arg0) and returning. + * + * THREE LEVERS (draft -> MATCH in 3 compiles): + * + * 1. PROLOGUE CONSTANT = an INITIALIZED LOCAL, not a literal in the compare. + * Target opens with `lui $s2, 0xFFF5` in the *prologue*, used once ~200 ins later in + * `slt $v0,$s2,$s1`. No gcc-2.7.2 pass hoists a (set reg const_int) across basic blocks + * (loop.c needs a loop; cse/combine/sched never move insns between BBs) — so the insn must + * have been EMITTED in the first BB, i.e. the constant is a local initialized at the top of + * the function. cse then cannot fold it back into the compare: the `slt` operand predicate is + * `arith_operand`, which rejects a CONST_INT wider than 16 bits, so validate_change fails and + * the pseudo survives. Its live range spans every call -> global.c gives it a callee-saved reg. + * Writing `z > -0xB0000` inline instead emits the `lui` into the branch delay slot next to the + * compare (caller-saved $v0) and the function is 1 insn short. => `s32 lim = -0xB0000;` at top. + * + * 2. `lh` vs `lhu`: a short->short copy is a pure HImode move and gcc emits `lhu`. The target's + * `lh $v0,0x26($s0)` means the value passed through an SImode (int) temp: expand makes + * (set (reg:SI) (sign_extend (mem:HI))) + (set (mem:HI) (subreg:HI ...)), and combine cannot + * merge them (the merged form is mem<-mem, which no movhi accepts) so the sign-extending load + * survives. => route both halfword copies through the `s32 t` temp. + * + * 3. THE `goto` LAYOUT — dodging jump.c's store-flag conversion (jump.c:1005-1065). + * An if/else chain writing 0/1 into `doit` makes gcc collapse the last pair into + * `sltiu $v0,$v0,1`. jump.c fires that conversion when the insn immediately after a + * conditional jump is a lone `SET pseudo, CONST_INT` whose following simplejump targets the + * SAME label as the branch (jump.c:1038 `reallabelprev == temp || ... JUMP_LABEL(temp4) == + * JUMP_LABEL(insn)`) — exactly the shape of `if (c) x=0; else x=1;`. + * The target instead cross-jumps ALL the `doit=0` exits into ONE shared block placed after the + * `doit=1` fall-through; reorg's fill_slots_from_thread then COPIES that single set into all + * three branch delay slots and redirects each branch past it (which is why `addu $v0,$zero, + * $zero` appears 3x in delay slots and the shared block vanishes). A `goto zero;` / `goto one;` + * chain expresses that layout directly, and each conditional jump is then followed by a + * compare/call rather than a lone const set, so the store-flag conversion never triggers. + * GENERAL RULE: multiple predicates that all assign the SAME constant to one flag => write + * them as `goto` to a shared assignment, never as an if/else ladder. + */ +extern s32 D_8011F9C4; +extern s32 D_80184998; + +extern s32 func_80161B18(void); +extern s32 func_801619A4(s32*); +extern s32 func_80149AA8(s32*); +extern void func_80149AD4(s32*); +extern s32 func_80149B54(s32*); +extern void func_80149BAC(s32*); +extern s32 func_801498E0(s32*); +extern s32 func_80149954(s32); +extern s32 func_80149A64(s32*); +extern void func_800CCCC0(s32 a0); +extern s32 func_80149CD4(s32 a0); +extern void func_8015E880(s32*); +extern s32 func_80149744(struct S_80149744*); +extern void func_80149788(void); +extern s32 func_801496D4(void*); +extern void func_80149704(void); +extern int func_80148AFC(void*); +extern void func_80146D90(s32 a0); +extern void func_80154150(s32 a0, s32 a1); +extern void func_801541D8(u8*, s32, s32); +extern s32 func_801488A8(u8*); +extern void func_80147078(s32*, s16); +extern void func_8015A264(void*); +extern s32 func_80013294(void*, void*); +extern void func_80159B70(void*); +extern s32 func_8016F1AC(void); +extern s32 func_80029178(s32 a0); +extern void func_80146DB8(s32*, s32*); +extern s32 func_80161CD0(s32, s32); +extern s32 func_80161208(s32 a0); +extern s32 func_801725A4(u8*); + +s32 func_8015B950(s32 arg0) +{ + + extern void (*D_80184A04[])(void *); + s16 sp10[4]; + s16 sp18[4]; + s32 t; + s32 z; + s32 doit; + s32 lim = -0xB0000; + + if (func_80161B18() != 0) { + return; + } + switch (((s32 (*)(s32))func_801619A4)(arg0)) { + case 0: + case 1: + case 2: + case 6: + if (((s32 (*)(s32))func_80149AA8)(arg0) != 0) { + D_80184A04[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149AD4)(arg0); + return; + } + if (((s32 (*)(s32))func_80149B54)(arg0) != 0) { + D_80184A04[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149BAC)(arg0); + return; + } + break; + case 3: + ((void (*)(s32))func_801498E0)(arg0); + break; + case 4: + ((void (*)(s32))func_80149954)(arg0); + break; + case 5: + if (((s32 (*)(s32))func_80149A64)(arg0) != 0) { + D_80184A04[*(u16 *)arg0]((void *)arg0); + func_800CCCC0(arg0); + return; + } + break; + } + if (func_80149CD4(arg0) != 0) { + D_80184A04[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_8015E880)(arg0); + return; + } + if (((s32 (*)(s32))func_80149744)(arg0) != 0) { + D_80184A04[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149788)(arg0); + return; + } + if (((s32 (*)(s32))func_801496D4)(arg0) != 0) { + D_80184A04[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149704)(arg0); + if (((u8)((s32 (*)(s32))func_80148AFC)(arg0)) == 0) { + func_80146D90(arg0); + } + if ((*(s32 *)(arg0 + 0x24) | *(s32 *)(arg0 + 0x2C)) != 0) { + func_80154150(arg0, 0xF); + } else { + ((void (*)(s32, s32, s32))func_801541D8)(arg0, 0xD, 6); + } + *(s32 *)(arg0 + 0x238) = 1; + return; + } + if (((s32 (*)(s32))func_801488A8)(arg0) != 0) { + sp10[0] = 0; + sp10[1] = 0; + sp10[2] = 0; + t = *(s16 *)(arg0 + 0x26); + sp18[0] = t; + sp18[1] = 0; + t = *(s16 *)(arg0 + 0x2E); + sp18[2] = t; + D_80184A04[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 1); + ((void (*)(s32))func_8015A264)(arg0); + t = -(((s32 (*)(s16 *, s16 *))func_80013294)(sp10, sp18) << 0x10); + if (t < *(s32 *)(arg0 + 0x2C)) { + *(s32 *)(arg0 + 0x2C) = t; + } + return; + } + if (*(u16 *)(arg0 + 0xB8) == 0x8000) { + D_80184A04[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 0); + ((void (*)(s32))func_80159B70)(arg0); + return; + } + z = *(s32 *)(arg0 + 0x2C); + if (func_8016F1AC() != 0) { + goto zero; + } + if (z <= lim) { + goto one; + } + if (D_8011F9C4 == 0) { + goto zero; + } + if (((u8)func_80029178(0x21)) != 0) { + goto zero; + } +one: + doit = 1; + goto join; +zero: + doit = 0; +join: + if (doit != 0) { + D_80184A04[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 0); + ((void (*)(s32))func_80159B70)(arg0); + func_80154150(arg0, 9); + ((void (*)(s32, s32 *))func_80146DB8)(arg0, &D_80184998); + ((void (*)(s32, s32))func_80161CD0)(arg0, *(u16 *)(arg0 + 0x16E)); + return; + } + if (func_80161208(arg0) == 0) { + ((void (*)(s32))func_801725A4)(arg0); + } +} DEFINE_func_8015BD8C() /* dedup: shared engine-core @0x8015BD8C (src/shared) */ diff --git a/src/ov_SC03_089/ov_SC03_089_jr_8015AE2C.c b/src/ov_SC03_089/ov_SC03_089_jr_8015AE2C.c index 648cc22fc..849fa3f9b 100644 --- a/src/ov_SC03_089/ov_SC03_089_jr_8015AE2C.c +++ b/src/ov_SC03_089/ov_SC03_089_jr_8015AE2C.c @@ -1513,7 +1513,259 @@ DEFINE_func_8015B858() /* dedup: shared engine-core @0x8015B858 (src/shared) */ DEFINE_func_8015B8F8() /* dedup: shared engine-core @0x8015B8F8 (src/shared) */ -INCLUDE_ASM("asm/ov_SC03_089/nonmatchings/ov_SC03_089_jr_8015AE2C", func_8015B950); +extern s32 func_8015AE2C(); + +// @class: plumbing +// @stuck: none — MATCH (271/271, pin-free, zero asm). The ONLY residual is DEF-SIDE plumbing, and it is now named exactly: the in-TU instantiation `DEFINE_func_8015BEE4()` (engine_core.h:1851-1855) expands to `extern s32 func_8015B950(void);` INSIDE ov_SC01_077_jr_8015AE2C.c, ~14 lines BELOW this definition, so the 1-param def collides with a `(void)` prototype -> `conflicting types for func_8015B950` (.run/bank_func_8015B950.log). §73 PARAMS axis / T0. Surgical fix = §65b de-macroize that ONE instantiation (blast radius: this TU); the fleet-wide `(void)`->`()` header edit is §63 and must be R22-validated. +/* func_8015B950 (ov_SC01_077_jr_8015AE2C, 271 ins, jtbl_801D8B74) — SESSION-21 re-verified + * + * ── ROUND-2 INDEPENDENT RE-VERIFICATION (2026-07-27, fresh agent, §88e discipline) ───────────── + * match_one : MATCH (271 ins) against the CURRENT tree — §87 staleness re-checked today. + * .text size: compiled .text = 0x43C = 1084 B = 271 ins, EXACTLY the target's declared 0x43C + * ("nonmatching func_8015B950, 0x43C"). So this is NOT a §83a length drift hiding + * behind a zero count — the count is over equal-length streams. + * jtbl : RE-DECODED MECHANICALLY, not inherited. Compiled .rodata = 0x1C = 28 B = 7 words, + * 7x R_MIPS_32 -> .text with implicit addends [58,58,58,E0,F0,100,58]; +0x8015B950 + * = [8015B9A8, 8015B9A8, 8015B9A8, 8015BA30, 8015BA40, 8015BA50, 8015B9A8]. + * Diffed word-for-word against asm/ov_SC01_077/data/tail14.data.s:15-23 — 7/7 identical. + * symcheck : SYMS-DIFF target=35 draft=34, sole MISSING = jtbl_801D8B74. This is the §81 jr + * FALSE POSITIVE, re-confirmed here by reading the relocs: gcc emits its OWN table and + * references it with R_MIPS_HI16/LO16 against the SECTION `.rodata` (t.o +0x40/+0x48), + * so the splat's dlabel NAME can never appear in the draft object's relocation set. + * Nothing is dropped and nothing is invented: the draft's other 34 symbols are exactly + * the target's other 34. + * FAMILY : the x138 remap is clean and §84-safe. Every sibling is 271 ins with an IDENTICAL + * callee set; only THREE names vary per overlay — the two data labels and the jtbl: + * ov_SC01_077 D_8018BC94 / D_8018BD00 / jtbl_801D8B74 + * ov_SC03_099 D_80185A50 / D_80185ABC / jtbl_801BD898 + * ov_SC06_008 D_80187E44 / D_80187EB0 / jtbl_801A8734 + * The pair is always +0x6C apart, and NO literal in this draft encodes that distance + * (both labels are referenced by name), so there is no §84 derived-offset hazard. + * D_8011F9C4 is fleet-constant (main-EXE data) and must NOT be remapped. + * + * match_one: MATCH (271 ins) against the CURRENT tree (§87 staleness re-checked, 2026-07-27). + * PIN-FREE, zero asm, offset-pure (s32 arg0 + raw offsets) — x138 template-safe. + * Provenance: this is the Phase-26 crack (.run/phase26-cracks/func_8015B950.c) re-gated verbatim, + * with ONE deliberate change: the definition's return type void -> s32. + * - `void func_8015B950(s32 arg0)` : MATCH (271 ins) [the Phase-26 form] + * - `s32 func_8015B950(s32 arg0)` : MATCH (271 ins) [shipped — §3a-1 void->s32 is byte-neutral] + * The fleet/engine_core.h canonical decl is `extern s32 func_8015B950(void);` (engine_core.h:1852), + * and the last bank attempt (.run/bank_func_8015B950.log) died on `conflicting types for + * func_8015B950`. Shipping the s32 return kills the §73 RETURN axis for free and leaves only the + * cheap T0 PARAMS axis for the ladder (fix_header_decl.py / --fix-def-sig / cast_call_sites). + * Both forms are byte-identical, so the orchestrator may swap the return type back at zero cost. + * + * SYMBOLS (§58 rules 1/2 — all splat spellings, all verified present): + * D_8018BD00 asm/ov_SC01_077/data/tail.data.s:4355 (the state-handler vtable) + * D_8018BC94 asm/ov_SC01_077/data/tail.data.s:4293 + * D_8011F9C4 main-EXE data; spelled `extern s32 D_8011F9C4;` in 5+ already-banked TUs + * jtbl_801D8B74 asm/ov_SC01_077/data/tail14.data.s:15 (compiler jump table — not named in C) + * + * JTBL VERIFIED (§8a gate): compiled .rodata = exactly 0x1C B / 7 words, 7x R_MIPS_32 .text with + * addends [0x58,0x58,0x58,0xE0,0xF0,0x100,0x58] -> +0x8015B950 = [B9A8,B9A8,B9A8,BA30,BA40,BA50, + * B9A8] == the original words at 0x801D8B74..0x801D8B8C. Bound `sltiu $v0,$v1,0x7` matches. + * The raw dlabel's 8th word 0x00000000 is NOT an entry — it is the intra-TU `.align 3` pad of the + * B34/B54/B74 jtbl chain; the object can never emit it (maspsx drops .align), so it must stay in + * the post-carve RAW data piece (the §53/§62/§81 carve chain applies at bank time). + * + * Same family as the TU's own already-matched func_8015AE2C: 7-case switch on ((s32 (*)(s32))func_801619A4)() + * (0/1/2/6 shared, 3/4/5 own, no default block — out-of-range and every `break` fall to the + * after-switch join), then a chain of "state handler" tests, each dispatching + * D_8018BD00[*(u16*)arg0](arg0) and returning. + * + * THREE LEVERS (draft -> MATCH in 3 compiles): + * + * 1. PROLOGUE CONSTANT = an INITIALIZED LOCAL, not a literal in the compare. + * Target opens with `lui $s2, 0xFFF5` in the *prologue*, used once ~200 ins later in + * `slt $v0,$s2,$s1`. No gcc-2.7.2 pass hoists a (set reg const_int) across basic blocks + * (loop.c needs a loop; cse/combine/sched never move insns between BBs) — so the insn must + * have been EMITTED in the first BB, i.e. the constant is a local initialized at the top of + * the function. cse then cannot fold it back into the compare: the `slt` operand predicate is + * `arith_operand`, which rejects a CONST_INT wider than 16 bits, so validate_change fails and + * the pseudo survives. Its live range spans every call -> global.c gives it a callee-saved reg. + * Writing `z > -0xB0000` inline instead emits the `lui` into the branch delay slot next to the + * compare (caller-saved $v0) and the function is 1 insn short. => `s32 lim = -0xB0000;` at top. + * + * 2. `lh` vs `lhu`: a short->short copy is a pure HImode move and gcc emits `lhu`. The target's + * `lh $v0,0x26($s0)` means the value passed through an SImode (int) temp: expand makes + * (set (reg:SI) (sign_extend (mem:HI))) + (set (mem:HI) (subreg:HI ...)), and combine cannot + * merge them (the merged form is mem<-mem, which no movhi accepts) so the sign-extending load + * survives. => route both halfword copies through the `s32 t` temp. + * + * 3. THE `goto` LAYOUT — dodging jump.c's store-flag conversion (jump.c:1005-1065). + * An if/else chain writing 0/1 into `doit` makes gcc collapse the last pair into + * `sltiu $v0,$v0,1`. jump.c fires that conversion when the insn immediately after a + * conditional jump is a lone `SET pseudo, CONST_INT` whose following simplejump targets the + * SAME label as the branch (jump.c:1038 `reallabelprev == temp || ... JUMP_LABEL(temp4) == + * JUMP_LABEL(insn)`) — exactly the shape of `if (c) x=0; else x=1;`. + * The target instead cross-jumps ALL the `doit=0` exits into ONE shared block placed after the + * `doit=1` fall-through; reorg's fill_slots_from_thread then COPIES that single set into all + * three branch delay slots and redirects each branch past it (which is why `addu $v0,$zero, + * $zero` appears 3x in delay slots and the shared block vanishes). A `goto zero;` / `goto one;` + * chain expresses that layout directly, and each conditional jump is then followed by a + * compare/call rather than a lone const set, so the store-flag conversion never triggers. + * GENERAL RULE: multiple predicates that all assign the SAME constant to one flag => write + * them as `goto` to a shared assignment, never as an if/else ladder. + */ +extern s32 D_8011F9C4; +extern s32 D_8018BC94; + +extern s32 func_80161B18(void); +extern s32 func_801619A4(s32*); +extern s32 func_80149AA8(s32*); +extern void func_80149AD4(s32*); +extern s32 func_80149B54(s32*); +extern void func_80149BAC(s32*); +extern s32 func_801498E0(s32*); +extern s32 func_80149954(s32); +extern s32 func_80149A64(s32*); +extern void func_800CCCC0(s32 a0); +extern s32 func_80149CD4(s32 a0); +extern void func_8015E880(s32*); +extern s32 func_80149744(struct S_80149744*); +extern void func_80149788(void); +extern s32 func_801496D4(void*); +extern void func_80149704(void); +extern int func_80148AFC(void*); +extern void func_80146D90(s32 a0); +extern void func_80154150(s32 a0, s32 a1); +extern void func_801541D8(u8*, s32, s32); +extern s32 func_801488A8(u8*); +extern void func_80147078(s32*, s16); +extern void func_8015A264(void*); +extern s32 func_80013294(void*, void*); +extern void func_80159B70(void*); +extern s32 func_8016F1AC(void); +extern s32 func_80029178(s32 a0); +extern void func_80146DB8(s32*, s32*); +extern s32 func_80161CD0(s32, s32); +extern s32 func_80161208(s32 a0); +extern s32 func_801725A4(u8*); + +s32 func_8015B950(s32 arg0) +{ + + extern void (*D_8018BD00[])(void *); + s16 sp10[4]; + s16 sp18[4]; + s32 t; + s32 z; + s32 doit; + s32 lim = -0xB0000; + + if (func_80161B18() != 0) { + return; + } + switch (((s32 (*)(s32))func_801619A4)(arg0)) { + case 0: + case 1: + case 2: + case 6: + if (((s32 (*)(s32))func_80149AA8)(arg0) != 0) { + D_8018BD00[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149AD4)(arg0); + return; + } + if (((s32 (*)(s32))func_80149B54)(arg0) != 0) { + D_8018BD00[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149BAC)(arg0); + return; + } + break; + case 3: + ((void (*)(s32))func_801498E0)(arg0); + break; + case 4: + ((void (*)(s32))func_80149954)(arg0); + break; + case 5: + if (((s32 (*)(s32))func_80149A64)(arg0) != 0) { + D_8018BD00[*(u16 *)arg0]((void *)arg0); + func_800CCCC0(arg0); + return; + } + break; + } + if (func_80149CD4(arg0) != 0) { + D_8018BD00[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_8015E880)(arg0); + return; + } + if (((s32 (*)(s32))func_80149744)(arg0) != 0) { + D_8018BD00[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149788)(arg0); + return; + } + if (((s32 (*)(s32))func_801496D4)(arg0) != 0) { + D_8018BD00[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149704)(arg0); + if (((u8)((s32 (*)(s32))func_80148AFC)(arg0)) == 0) { + func_80146D90(arg0); + } + if ((*(s32 *)(arg0 + 0x24) | *(s32 *)(arg0 + 0x2C)) != 0) { + func_80154150(arg0, 0xF); + } else { + ((void (*)(s32, s32, s32))func_801541D8)(arg0, 0xD, 6); + } + *(s32 *)(arg0 + 0x238) = 1; + return; + } + if (((s32 (*)(s32))func_801488A8)(arg0) != 0) { + sp10[0] = 0; + sp10[1] = 0; + sp10[2] = 0; + t = *(s16 *)(arg0 + 0x26); + sp18[0] = t; + sp18[1] = 0; + t = *(s16 *)(arg0 + 0x2E); + sp18[2] = t; + D_8018BD00[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 1); + ((void (*)(s32))func_8015A264)(arg0); + t = -(((s32 (*)(s16 *, s16 *))func_80013294)(sp10, sp18) << 0x10); + if (t < *(s32 *)(arg0 + 0x2C)) { + *(s32 *)(arg0 + 0x2C) = t; + } + return; + } + if (*(u16 *)(arg0 + 0xB8) == 0x8000) { + D_8018BD00[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 0); + ((void (*)(s32))func_80159B70)(arg0); + return; + } + z = *(s32 *)(arg0 + 0x2C); + if (func_8016F1AC() != 0) { + goto zero; + } + if (z <= lim) { + goto one; + } + if (D_8011F9C4 == 0) { + goto zero; + } + if (((u8)func_80029178(0x21)) != 0) { + goto zero; + } +one: + doit = 1; + goto join; +zero: + doit = 0; +join: + if (doit != 0) { + D_8018BD00[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 0); + ((void (*)(s32))func_80159B70)(arg0); + func_80154150(arg0, 9); + ((void (*)(s32, s32 *))func_80146DB8)(arg0, &D_8018BC94); + ((void (*)(s32, s32))func_80161CD0)(arg0, *(u16 *)(arg0 + 0x16E)); + return; + } + if (func_80161208(arg0) == 0) { + ((void (*)(s32))func_801725A4)(arg0); + } +} DEFINE_func_8015BD8C() /* dedup: shared engine-core @0x8015BD8C (src/shared) */ diff --git a/src/ov_SC03_090/ov_SC03_090_jr_8015AE2C.c b/src/ov_SC03_090/ov_SC03_090_jr_8015AE2C.c index d7f56920f..26ac9ff5b 100644 --- a/src/ov_SC03_090/ov_SC03_090_jr_8015AE2C.c +++ b/src/ov_SC03_090/ov_SC03_090_jr_8015AE2C.c @@ -1513,7 +1513,259 @@ DEFINE_func_8015B858() /* dedup: shared engine-core @0x8015B858 (src/shared) */ DEFINE_func_8015B8F8() /* dedup: shared engine-core @0x8015B8F8 (src/shared) */ -INCLUDE_ASM("asm/ov_SC03_090/nonmatchings/ov_SC03_090_jr_8015AE2C", func_8015B950); +extern s32 func_8015AE2C(); + +// @class: plumbing +// @stuck: none — MATCH (271/271, pin-free, zero asm). The ONLY residual is DEF-SIDE plumbing, and it is now named exactly: the in-TU instantiation `DEFINE_func_8015BEE4()` (engine_core.h:1851-1855) expands to `extern s32 func_8015B950(void);` INSIDE ov_SC01_077_jr_8015AE2C.c, ~14 lines BELOW this definition, so the 1-param def collides with a `(void)` prototype -> `conflicting types for func_8015B950` (.run/bank_func_8015B950.log). §73 PARAMS axis / T0. Surgical fix = §65b de-macroize that ONE instantiation (blast radius: this TU); the fleet-wide `(void)`->`()` header edit is §63 and must be R22-validated. +/* func_8015B950 (ov_SC01_077_jr_8015AE2C, 271 ins, jtbl_801D8B74) — SESSION-21 re-verified + * + * ── ROUND-2 INDEPENDENT RE-VERIFICATION (2026-07-27, fresh agent, §88e discipline) ───────────── + * match_one : MATCH (271 ins) against the CURRENT tree — §87 staleness re-checked today. + * .text size: compiled .text = 0x43C = 1084 B = 271 ins, EXACTLY the target's declared 0x43C + * ("nonmatching func_8015B950, 0x43C"). So this is NOT a §83a length drift hiding + * behind a zero count — the count is over equal-length streams. + * jtbl : RE-DECODED MECHANICALLY, not inherited. Compiled .rodata = 0x1C = 28 B = 7 words, + * 7x R_MIPS_32 -> .text with implicit addends [58,58,58,E0,F0,100,58]; +0x8015B950 + * = [8015B9A8, 8015B9A8, 8015B9A8, 8015BA30, 8015BA40, 8015BA50, 8015B9A8]. + * Diffed word-for-word against asm/ov_SC01_077/data/tail14.data.s:15-23 — 7/7 identical. + * symcheck : SYMS-DIFF target=35 draft=34, sole MISSING = jtbl_801D8B74. This is the §81 jr + * FALSE POSITIVE, re-confirmed here by reading the relocs: gcc emits its OWN table and + * references it with R_MIPS_HI16/LO16 against the SECTION `.rodata` (t.o +0x40/+0x48), + * so the splat's dlabel NAME can never appear in the draft object's relocation set. + * Nothing is dropped and nothing is invented: the draft's other 34 symbols are exactly + * the target's other 34. + * FAMILY : the x138 remap is clean and §84-safe. Every sibling is 271 ins with an IDENTICAL + * callee set; only THREE names vary per overlay — the two data labels and the jtbl: + * ov_SC01_077 D_8018E0B8 / D_8018E124 / jtbl_801D8B74 + * ov_SC03_099 D_80185A50 / D_80185ABC / jtbl_801BD898 + * ov_SC06_008 D_80187E44 / D_80187EB0 / jtbl_801A8734 + * The pair is always +0x6C apart, and NO literal in this draft encodes that distance + * (both labels are referenced by name), so there is no §84 derived-offset hazard. + * D_8011F9C4 is fleet-constant (main-EXE data) and must NOT be remapped. + * + * match_one: MATCH (271 ins) against the CURRENT tree (§87 staleness re-checked, 2026-07-27). + * PIN-FREE, zero asm, offset-pure (s32 arg0 + raw offsets) — x138 template-safe. + * Provenance: this is the Phase-26 crack (.run/phase26-cracks/func_8015B950.c) re-gated verbatim, + * with ONE deliberate change: the definition's return type void -> s32. + * - `void func_8015B950(s32 arg0)` : MATCH (271 ins) [the Phase-26 form] + * - `s32 func_8015B950(s32 arg0)` : MATCH (271 ins) [shipped — §3a-1 void->s32 is byte-neutral] + * The fleet/engine_core.h canonical decl is `extern s32 func_8015B950(void);` (engine_core.h:1852), + * and the last bank attempt (.run/bank_func_8015B950.log) died on `conflicting types for + * func_8015B950`. Shipping the s32 return kills the §73 RETURN axis for free and leaves only the + * cheap T0 PARAMS axis for the ladder (fix_header_decl.py / --fix-def-sig / cast_call_sites). + * Both forms are byte-identical, so the orchestrator may swap the return type back at zero cost. + * + * SYMBOLS (§58 rules 1/2 — all splat spellings, all verified present): + * D_8018E124 asm/ov_SC01_077/data/tail.data.s:4355 (the state-handler vtable) + * D_8018E0B8 asm/ov_SC01_077/data/tail.data.s:4293 + * D_8011F9C4 main-EXE data; spelled `extern s32 D_8011F9C4;` in 5+ already-banked TUs + * jtbl_801D8B74 asm/ov_SC01_077/data/tail14.data.s:15 (compiler jump table — not named in C) + * + * JTBL VERIFIED (§8a gate): compiled .rodata = exactly 0x1C B / 7 words, 7x R_MIPS_32 .text with + * addends [0x58,0x58,0x58,0xE0,0xF0,0x100,0x58] -> +0x8015B950 = [B9A8,B9A8,B9A8,BA30,BA40,BA50, + * B9A8] == the original words at 0x801D8B74..0x801D8B8C. Bound `sltiu $v0,$v1,0x7` matches. + * The raw dlabel's 8th word 0x00000000 is NOT an entry — it is the intra-TU `.align 3` pad of the + * B34/B54/B74 jtbl chain; the object can never emit it (maspsx drops .align), so it must stay in + * the post-carve RAW data piece (the §53/§62/§81 carve chain applies at bank time). + * + * Same family as the TU's own already-matched func_8015AE2C: 7-case switch on ((s32 (*)(s32))func_801619A4)() + * (0/1/2/6 shared, 3/4/5 own, no default block — out-of-range and every `break` fall to the + * after-switch join), then a chain of "state handler" tests, each dispatching + * D_8018E124[*(u16*)arg0](arg0) and returning. + * + * THREE LEVERS (draft -> MATCH in 3 compiles): + * + * 1. PROLOGUE CONSTANT = an INITIALIZED LOCAL, not a literal in the compare. + * Target opens with `lui $s2, 0xFFF5` in the *prologue*, used once ~200 ins later in + * `slt $v0,$s2,$s1`. No gcc-2.7.2 pass hoists a (set reg const_int) across basic blocks + * (loop.c needs a loop; cse/combine/sched never move insns between BBs) — so the insn must + * have been EMITTED in the first BB, i.e. the constant is a local initialized at the top of + * the function. cse then cannot fold it back into the compare: the `slt` operand predicate is + * `arith_operand`, which rejects a CONST_INT wider than 16 bits, so validate_change fails and + * the pseudo survives. Its live range spans every call -> global.c gives it a callee-saved reg. + * Writing `z > -0xB0000` inline instead emits the `lui` into the branch delay slot next to the + * compare (caller-saved $v0) and the function is 1 insn short. => `s32 lim = -0xB0000;` at top. + * + * 2. `lh` vs `lhu`: a short->short copy is a pure HImode move and gcc emits `lhu`. The target's + * `lh $v0,0x26($s0)` means the value passed through an SImode (int) temp: expand makes + * (set (reg:SI) (sign_extend (mem:HI))) + (set (mem:HI) (subreg:HI ...)), and combine cannot + * merge them (the merged form is mem<-mem, which no movhi accepts) so the sign-extending load + * survives. => route both halfword copies through the `s32 t` temp. + * + * 3. THE `goto` LAYOUT — dodging jump.c's store-flag conversion (jump.c:1005-1065). + * An if/else chain writing 0/1 into `doit` makes gcc collapse the last pair into + * `sltiu $v0,$v0,1`. jump.c fires that conversion when the insn immediately after a + * conditional jump is a lone `SET pseudo, CONST_INT` whose following simplejump targets the + * SAME label as the branch (jump.c:1038 `reallabelprev == temp || ... JUMP_LABEL(temp4) == + * JUMP_LABEL(insn)`) — exactly the shape of `if (c) x=0; else x=1;`. + * The target instead cross-jumps ALL the `doit=0` exits into ONE shared block placed after the + * `doit=1` fall-through; reorg's fill_slots_from_thread then COPIES that single set into all + * three branch delay slots and redirects each branch past it (which is why `addu $v0,$zero, + * $zero` appears 3x in delay slots and the shared block vanishes). A `goto zero;` / `goto one;` + * chain expresses that layout directly, and each conditional jump is then followed by a + * compare/call rather than a lone const set, so the store-flag conversion never triggers. + * GENERAL RULE: multiple predicates that all assign the SAME constant to one flag => write + * them as `goto` to a shared assignment, never as an if/else ladder. + */ +extern s32 D_8011F9C4; +extern s32 D_8018E0B8; + +extern s32 func_80161B18(void); +extern s32 func_801619A4(s32*); +extern s32 func_80149AA8(s32*); +extern void func_80149AD4(s32*); +extern s32 func_80149B54(s32*); +extern void func_80149BAC(s32*); +extern s32 func_801498E0(s32*); +extern s32 func_80149954(s32); +extern s32 func_80149A64(s32*); +extern void func_800CCCC0(s32 a0); +extern s32 func_80149CD4(s32 a0); +extern void func_8015E880(s32*); +extern s32 func_80149744(struct S_80149744*); +extern void func_80149788(void); +extern s32 func_801496D4(void*); +extern void func_80149704(void); +extern int func_80148AFC(void*); +extern void func_80146D90(s32 a0); +extern void func_80154150(s32 a0, s32 a1); +extern void func_801541D8(u8*, s32, s32); +extern s32 func_801488A8(u8*); +extern void func_80147078(s32*, s16); +extern void func_8015A264(void*); +extern s32 func_80013294(void*, void*); +extern void func_80159B70(void*); +extern s32 func_8016F1AC(void); +extern s32 func_80029178(s32 a0); +extern void func_80146DB8(s32*, s32*); +extern s32 func_80161CD0(s32, s32); +extern s32 func_80161208(s32 a0); +extern s32 func_801725A4(u8*); + +s32 func_8015B950(s32 arg0) +{ + + extern void (*D_8018E124[])(void *); + s16 sp10[4]; + s16 sp18[4]; + s32 t; + s32 z; + s32 doit; + s32 lim = -0xB0000; + + if (func_80161B18() != 0) { + return; + } + switch (((s32 (*)(s32))func_801619A4)(arg0)) { + case 0: + case 1: + case 2: + case 6: + if (((s32 (*)(s32))func_80149AA8)(arg0) != 0) { + D_8018E124[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149AD4)(arg0); + return; + } + if (((s32 (*)(s32))func_80149B54)(arg0) != 0) { + D_8018E124[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149BAC)(arg0); + return; + } + break; + case 3: + ((void (*)(s32))func_801498E0)(arg0); + break; + case 4: + ((void (*)(s32))func_80149954)(arg0); + break; + case 5: + if (((s32 (*)(s32))func_80149A64)(arg0) != 0) { + D_8018E124[*(u16 *)arg0]((void *)arg0); + func_800CCCC0(arg0); + return; + } + break; + } + if (func_80149CD4(arg0) != 0) { + D_8018E124[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_8015E880)(arg0); + return; + } + if (((s32 (*)(s32))func_80149744)(arg0) != 0) { + D_8018E124[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149788)(arg0); + return; + } + if (((s32 (*)(s32))func_801496D4)(arg0) != 0) { + D_8018E124[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149704)(arg0); + if (((u8)((s32 (*)(s32))func_80148AFC)(arg0)) == 0) { + func_80146D90(arg0); + } + if ((*(s32 *)(arg0 + 0x24) | *(s32 *)(arg0 + 0x2C)) != 0) { + func_80154150(arg0, 0xF); + } else { + ((void (*)(s32, s32, s32))func_801541D8)(arg0, 0xD, 6); + } + *(s32 *)(arg0 + 0x238) = 1; + return; + } + if (((s32 (*)(s32))func_801488A8)(arg0) != 0) { + sp10[0] = 0; + sp10[1] = 0; + sp10[2] = 0; + t = *(s16 *)(arg0 + 0x26); + sp18[0] = t; + sp18[1] = 0; + t = *(s16 *)(arg0 + 0x2E); + sp18[2] = t; + D_8018E124[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 1); + ((void (*)(s32))func_8015A264)(arg0); + t = -(((s32 (*)(s16 *, s16 *))func_80013294)(sp10, sp18) << 0x10); + if (t < *(s32 *)(arg0 + 0x2C)) { + *(s32 *)(arg0 + 0x2C) = t; + } + return; + } + if (*(u16 *)(arg0 + 0xB8) == 0x8000) { + D_8018E124[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 0); + ((void (*)(s32))func_80159B70)(arg0); + return; + } + z = *(s32 *)(arg0 + 0x2C); + if (func_8016F1AC() != 0) { + goto zero; + } + if (z <= lim) { + goto one; + } + if (D_8011F9C4 == 0) { + goto zero; + } + if (((u8)func_80029178(0x21)) != 0) { + goto zero; + } +one: + doit = 1; + goto join; +zero: + doit = 0; +join: + if (doit != 0) { + D_8018E124[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 0); + ((void (*)(s32))func_80159B70)(arg0); + func_80154150(arg0, 9); + ((void (*)(s32, s32 *))func_80146DB8)(arg0, &D_8018E0B8); + ((void (*)(s32, s32))func_80161CD0)(arg0, *(u16 *)(arg0 + 0x16E)); + return; + } + if (func_80161208(arg0) == 0) { + ((void (*)(s32))func_801725A4)(arg0); + } +} DEFINE_func_8015BD8C() /* dedup: shared engine-core @0x8015BD8C (src/shared) */ diff --git a/src/ov_SC03_091/ov_SC03_091_jr_8015AE2C.c b/src/ov_SC03_091/ov_SC03_091_jr_8015AE2C.c index 940c388f7..a5bc03bad 100644 --- a/src/ov_SC03_091/ov_SC03_091_jr_8015AE2C.c +++ b/src/ov_SC03_091/ov_SC03_091_jr_8015AE2C.c @@ -1513,7 +1513,259 @@ DEFINE_func_8015B858() /* dedup: shared engine-core @0x8015B858 (src/shared) */ DEFINE_func_8015B8F8() /* dedup: shared engine-core @0x8015B8F8 (src/shared) */ -INCLUDE_ASM("asm/ov_SC03_091/nonmatchings/ov_SC03_091_jr_8015AE2C", func_8015B950); +extern s32 func_8015AE2C(); + +// @class: plumbing +// @stuck: none — MATCH (271/271, pin-free, zero asm). The ONLY residual is DEF-SIDE plumbing, and it is now named exactly: the in-TU instantiation `DEFINE_func_8015BEE4()` (engine_core.h:1851-1855) expands to `extern s32 func_8015B950(void);` INSIDE ov_SC01_077_jr_8015AE2C.c, ~14 lines BELOW this definition, so the 1-param def collides with a `(void)` prototype -> `conflicting types for func_8015B950` (.run/bank_func_8015B950.log). §73 PARAMS axis / T0. Surgical fix = §65b de-macroize that ONE instantiation (blast radius: this TU); the fleet-wide `(void)`->`()` header edit is §63 and must be R22-validated. +/* func_8015B950 (ov_SC01_077_jr_8015AE2C, 271 ins, jtbl_801D8B74) — SESSION-21 re-verified + * + * ── ROUND-2 INDEPENDENT RE-VERIFICATION (2026-07-27, fresh agent, §88e discipline) ───────────── + * match_one : MATCH (271 ins) against the CURRENT tree — §87 staleness re-checked today. + * .text size: compiled .text = 0x43C = 1084 B = 271 ins, EXACTLY the target's declared 0x43C + * ("nonmatching func_8015B950, 0x43C"). So this is NOT a §83a length drift hiding + * behind a zero count — the count is over equal-length streams. + * jtbl : RE-DECODED MECHANICALLY, not inherited. Compiled .rodata = 0x1C = 28 B = 7 words, + * 7x R_MIPS_32 -> .text with implicit addends [58,58,58,E0,F0,100,58]; +0x8015B950 + * = [8015B9A8, 8015B9A8, 8015B9A8, 8015BA30, 8015BA40, 8015BA50, 8015B9A8]. + * Diffed word-for-word against asm/ov_SC01_077/data/tail14.data.s:15-23 — 7/7 identical. + * symcheck : SYMS-DIFF target=35 draft=34, sole MISSING = jtbl_801D8B74. This is the §81 jr + * FALSE POSITIVE, re-confirmed here by reading the relocs: gcc emits its OWN table and + * references it with R_MIPS_HI16/LO16 against the SECTION `.rodata` (t.o +0x40/+0x48), + * so the splat's dlabel NAME can never appear in the draft object's relocation set. + * Nothing is dropped and nothing is invented: the draft's other 34 symbols are exactly + * the target's other 34. + * FAMILY : the x138 remap is clean and §84-safe. Every sibling is 271 ins with an IDENTICAL + * callee set; only THREE names vary per overlay — the two data labels and the jtbl: + * ov_SC01_077 D_8018EF60 / D_8018EFCC / jtbl_801D8B74 + * ov_SC03_099 D_80185A50 / D_80185ABC / jtbl_801BD898 + * ov_SC06_008 D_80187E44 / D_80187EB0 / jtbl_801A8734 + * The pair is always +0x6C apart, and NO literal in this draft encodes that distance + * (both labels are referenced by name), so there is no §84 derived-offset hazard. + * D_8011F9C4 is fleet-constant (main-EXE data) and must NOT be remapped. + * + * match_one: MATCH (271 ins) against the CURRENT tree (§87 staleness re-checked, 2026-07-27). + * PIN-FREE, zero asm, offset-pure (s32 arg0 + raw offsets) — x138 template-safe. + * Provenance: this is the Phase-26 crack (.run/phase26-cracks/func_8015B950.c) re-gated verbatim, + * with ONE deliberate change: the definition's return type void -> s32. + * - `void func_8015B950(s32 arg0)` : MATCH (271 ins) [the Phase-26 form] + * - `s32 func_8015B950(s32 arg0)` : MATCH (271 ins) [shipped — §3a-1 void->s32 is byte-neutral] + * The fleet/engine_core.h canonical decl is `extern s32 func_8015B950(void);` (engine_core.h:1852), + * and the last bank attempt (.run/bank_func_8015B950.log) died on `conflicting types for + * func_8015B950`. Shipping the s32 return kills the §73 RETURN axis for free and leaves only the + * cheap T0 PARAMS axis for the ladder (fix_header_decl.py / --fix-def-sig / cast_call_sites). + * Both forms are byte-identical, so the orchestrator may swap the return type back at zero cost. + * + * SYMBOLS (§58 rules 1/2 — all splat spellings, all verified present): + * D_8018EFCC asm/ov_SC01_077/data/tail.data.s:4355 (the state-handler vtable) + * D_8018EF60 asm/ov_SC01_077/data/tail.data.s:4293 + * D_8011F9C4 main-EXE data; spelled `extern s32 D_8011F9C4;` in 5+ already-banked TUs + * jtbl_801D8B74 asm/ov_SC01_077/data/tail14.data.s:15 (compiler jump table — not named in C) + * + * JTBL VERIFIED (§8a gate): compiled .rodata = exactly 0x1C B / 7 words, 7x R_MIPS_32 .text with + * addends [0x58,0x58,0x58,0xE0,0xF0,0x100,0x58] -> +0x8015B950 = [B9A8,B9A8,B9A8,BA30,BA40,BA50, + * B9A8] == the original words at 0x801D8B74..0x801D8B8C. Bound `sltiu $v0,$v1,0x7` matches. + * The raw dlabel's 8th word 0x00000000 is NOT an entry — it is the intra-TU `.align 3` pad of the + * B34/B54/B74 jtbl chain; the object can never emit it (maspsx drops .align), so it must stay in + * the post-carve RAW data piece (the §53/§62/§81 carve chain applies at bank time). + * + * Same family as the TU's own already-matched func_8015AE2C: 7-case switch on ((s32 (*)(s32))func_801619A4)() + * (0/1/2/6 shared, 3/4/5 own, no default block — out-of-range and every `break` fall to the + * after-switch join), then a chain of "state handler" tests, each dispatching + * D_8018EFCC[*(u16*)arg0](arg0) and returning. + * + * THREE LEVERS (draft -> MATCH in 3 compiles): + * + * 1. PROLOGUE CONSTANT = an INITIALIZED LOCAL, not a literal in the compare. + * Target opens with `lui $s2, 0xFFF5` in the *prologue*, used once ~200 ins later in + * `slt $v0,$s2,$s1`. No gcc-2.7.2 pass hoists a (set reg const_int) across basic blocks + * (loop.c needs a loop; cse/combine/sched never move insns between BBs) — so the insn must + * have been EMITTED in the first BB, i.e. the constant is a local initialized at the top of + * the function. cse then cannot fold it back into the compare: the `slt` operand predicate is + * `arith_operand`, which rejects a CONST_INT wider than 16 bits, so validate_change fails and + * the pseudo survives. Its live range spans every call -> global.c gives it a callee-saved reg. + * Writing `z > -0xB0000` inline instead emits the `lui` into the branch delay slot next to the + * compare (caller-saved $v0) and the function is 1 insn short. => `s32 lim = -0xB0000;` at top. + * + * 2. `lh` vs `lhu`: a short->short copy is a pure HImode move and gcc emits `lhu`. The target's + * `lh $v0,0x26($s0)` means the value passed through an SImode (int) temp: expand makes + * (set (reg:SI) (sign_extend (mem:HI))) + (set (mem:HI) (subreg:HI ...)), and combine cannot + * merge them (the merged form is mem<-mem, which no movhi accepts) so the sign-extending load + * survives. => route both halfword copies through the `s32 t` temp. + * + * 3. THE `goto` LAYOUT — dodging jump.c's store-flag conversion (jump.c:1005-1065). + * An if/else chain writing 0/1 into `doit` makes gcc collapse the last pair into + * `sltiu $v0,$v0,1`. jump.c fires that conversion when the insn immediately after a + * conditional jump is a lone `SET pseudo, CONST_INT` whose following simplejump targets the + * SAME label as the branch (jump.c:1038 `reallabelprev == temp || ... JUMP_LABEL(temp4) == + * JUMP_LABEL(insn)`) — exactly the shape of `if (c) x=0; else x=1;`. + * The target instead cross-jumps ALL the `doit=0` exits into ONE shared block placed after the + * `doit=1` fall-through; reorg's fill_slots_from_thread then COPIES that single set into all + * three branch delay slots and redirects each branch past it (which is why `addu $v0,$zero, + * $zero` appears 3x in delay slots and the shared block vanishes). A `goto zero;` / `goto one;` + * chain expresses that layout directly, and each conditional jump is then followed by a + * compare/call rather than a lone const set, so the store-flag conversion never triggers. + * GENERAL RULE: multiple predicates that all assign the SAME constant to one flag => write + * them as `goto` to a shared assignment, never as an if/else ladder. + */ +extern s32 D_8011F9C4; +extern s32 D_8018EF60; + +extern s32 func_80161B18(void); +extern s32 func_801619A4(s32*); +extern s32 func_80149AA8(s32*); +extern void func_80149AD4(s32*); +extern s32 func_80149B54(s32*); +extern void func_80149BAC(s32*); +extern s32 func_801498E0(s32*); +extern s32 func_80149954(s32); +extern s32 func_80149A64(s32*); +extern void func_800CCCC0(s32 a0); +extern s32 func_80149CD4(s32 a0); +extern void func_8015E880(s32*); +extern s32 func_80149744(struct S_80149744*); +extern void func_80149788(void); +extern s32 func_801496D4(void*); +extern void func_80149704(void); +extern int func_80148AFC(void*); +extern void func_80146D90(s32 a0); +extern void func_80154150(s32 a0, s32 a1); +extern void func_801541D8(u8*, s32, s32); +extern s32 func_801488A8(u8*); +extern void func_80147078(s32*, s16); +extern void func_8015A264(void*); +extern s32 func_80013294(void*, void*); +extern void func_80159B70(void*); +extern s32 func_8016F1AC(void); +extern s32 func_80029178(s32 a0); +extern void func_80146DB8(s32*, s32*); +extern s32 func_80161CD0(s32, s32); +extern s32 func_80161208(s32 a0); +extern s32 func_801725A4(u8*); + +s32 func_8015B950(s32 arg0) +{ + + extern void (*D_8018EFCC[])(void *); + s16 sp10[4]; + s16 sp18[4]; + s32 t; + s32 z; + s32 doit; + s32 lim = -0xB0000; + + if (func_80161B18() != 0) { + return; + } + switch (((s32 (*)(s32))func_801619A4)(arg0)) { + case 0: + case 1: + case 2: + case 6: + if (((s32 (*)(s32))func_80149AA8)(arg0) != 0) { + D_8018EFCC[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149AD4)(arg0); + return; + } + if (((s32 (*)(s32))func_80149B54)(arg0) != 0) { + D_8018EFCC[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149BAC)(arg0); + return; + } + break; + case 3: + ((void (*)(s32))func_801498E0)(arg0); + break; + case 4: + ((void (*)(s32))func_80149954)(arg0); + break; + case 5: + if (((s32 (*)(s32))func_80149A64)(arg0) != 0) { + D_8018EFCC[*(u16 *)arg0]((void *)arg0); + func_800CCCC0(arg0); + return; + } + break; + } + if (func_80149CD4(arg0) != 0) { + D_8018EFCC[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_8015E880)(arg0); + return; + } + if (((s32 (*)(s32))func_80149744)(arg0) != 0) { + D_8018EFCC[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149788)(arg0); + return; + } + if (((s32 (*)(s32))func_801496D4)(arg0) != 0) { + D_8018EFCC[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149704)(arg0); + if (((u8)((s32 (*)(s32))func_80148AFC)(arg0)) == 0) { + func_80146D90(arg0); + } + if ((*(s32 *)(arg0 + 0x24) | *(s32 *)(arg0 + 0x2C)) != 0) { + func_80154150(arg0, 0xF); + } else { + ((void (*)(s32, s32, s32))func_801541D8)(arg0, 0xD, 6); + } + *(s32 *)(arg0 + 0x238) = 1; + return; + } + if (((s32 (*)(s32))func_801488A8)(arg0) != 0) { + sp10[0] = 0; + sp10[1] = 0; + sp10[2] = 0; + t = *(s16 *)(arg0 + 0x26); + sp18[0] = t; + sp18[1] = 0; + t = *(s16 *)(arg0 + 0x2E); + sp18[2] = t; + D_8018EFCC[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 1); + ((void (*)(s32))func_8015A264)(arg0); + t = -(((s32 (*)(s16 *, s16 *))func_80013294)(sp10, sp18) << 0x10); + if (t < *(s32 *)(arg0 + 0x2C)) { + *(s32 *)(arg0 + 0x2C) = t; + } + return; + } + if (*(u16 *)(arg0 + 0xB8) == 0x8000) { + D_8018EFCC[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 0); + ((void (*)(s32))func_80159B70)(arg0); + return; + } + z = *(s32 *)(arg0 + 0x2C); + if (func_8016F1AC() != 0) { + goto zero; + } + if (z <= lim) { + goto one; + } + if (D_8011F9C4 == 0) { + goto zero; + } + if (((u8)func_80029178(0x21)) != 0) { + goto zero; + } +one: + doit = 1; + goto join; +zero: + doit = 0; +join: + if (doit != 0) { + D_8018EFCC[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 0); + ((void (*)(s32))func_80159B70)(arg0); + func_80154150(arg0, 9); + ((void (*)(s32, s32 *))func_80146DB8)(arg0, &D_8018EF60); + ((void (*)(s32, s32))func_80161CD0)(arg0, *(u16 *)(arg0 + 0x16E)); + return; + } + if (func_80161208(arg0) == 0) { + ((void (*)(s32))func_801725A4)(arg0); + } +} DEFINE_func_8015BD8C() /* dedup: shared engine-core @0x8015BD8C (src/shared) */ diff --git a/src/ov_SC03_092/ov_SC03_092_jr_8015AE2C.c b/src/ov_SC03_092/ov_SC03_092_jr_8015AE2C.c index e188dca7e..47fb09a18 100644 --- a/src/ov_SC03_092/ov_SC03_092_jr_8015AE2C.c +++ b/src/ov_SC03_092/ov_SC03_092_jr_8015AE2C.c @@ -1513,7 +1513,259 @@ DEFINE_func_8015B858() /* dedup: shared engine-core @0x8015B858 (src/shared) */ DEFINE_func_8015B8F8() /* dedup: shared engine-core @0x8015B8F8 (src/shared) */ -INCLUDE_ASM("asm/ov_SC03_092/nonmatchings/ov_SC03_092_jr_8015AE2C", func_8015B950); +extern s32 func_8015AE2C(); + +// @class: plumbing +// @stuck: none — MATCH (271/271, pin-free, zero asm). The ONLY residual is DEF-SIDE plumbing, and it is now named exactly: the in-TU instantiation `DEFINE_func_8015BEE4()` (engine_core.h:1851-1855) expands to `extern s32 func_8015B950(void);` INSIDE ov_SC01_077_jr_8015AE2C.c, ~14 lines BELOW this definition, so the 1-param def collides with a `(void)` prototype -> `conflicting types for func_8015B950` (.run/bank_func_8015B950.log). §73 PARAMS axis / T0. Surgical fix = §65b de-macroize that ONE instantiation (blast radius: this TU); the fleet-wide `(void)`->`()` header edit is §63 and must be R22-validated. +/* func_8015B950 (ov_SC01_077_jr_8015AE2C, 271 ins, jtbl_801D8B74) — SESSION-21 re-verified + * + * ── ROUND-2 INDEPENDENT RE-VERIFICATION (2026-07-27, fresh agent, §88e discipline) ───────────── + * match_one : MATCH (271 ins) against the CURRENT tree — §87 staleness re-checked today. + * .text size: compiled .text = 0x43C = 1084 B = 271 ins, EXACTLY the target's declared 0x43C + * ("nonmatching func_8015B950, 0x43C"). So this is NOT a §83a length drift hiding + * behind a zero count — the count is over equal-length streams. + * jtbl : RE-DECODED MECHANICALLY, not inherited. Compiled .rodata = 0x1C = 28 B = 7 words, + * 7x R_MIPS_32 -> .text with implicit addends [58,58,58,E0,F0,100,58]; +0x8015B950 + * = [8015B9A8, 8015B9A8, 8015B9A8, 8015BA30, 8015BA40, 8015BA50, 8015B9A8]. + * Diffed word-for-word against asm/ov_SC01_077/data/tail14.data.s:15-23 — 7/7 identical. + * symcheck : SYMS-DIFF target=35 draft=34, sole MISSING = jtbl_801D8B74. This is the §81 jr + * FALSE POSITIVE, re-confirmed here by reading the relocs: gcc emits its OWN table and + * references it with R_MIPS_HI16/LO16 against the SECTION `.rodata` (t.o +0x40/+0x48), + * so the splat's dlabel NAME can never appear in the draft object's relocation set. + * Nothing is dropped and nothing is invented: the draft's other 34 symbols are exactly + * the target's other 34. + * FAMILY : the x138 remap is clean and §84-safe. Every sibling is 271 ins with an IDENTICAL + * callee set; only THREE names vary per overlay — the two data labels and the jtbl: + * ov_SC01_077 D_80187330 / D_8018739C / jtbl_801D8B74 + * ov_SC03_099 D_80185A50 / D_80185ABC / jtbl_801BD898 + * ov_SC06_008 D_80187E44 / D_80187EB0 / jtbl_801A8734 + * The pair is always +0x6C apart, and NO literal in this draft encodes that distance + * (both labels are referenced by name), so there is no §84 derived-offset hazard. + * D_8011F9C4 is fleet-constant (main-EXE data) and must NOT be remapped. + * + * match_one: MATCH (271 ins) against the CURRENT tree (§87 staleness re-checked, 2026-07-27). + * PIN-FREE, zero asm, offset-pure (s32 arg0 + raw offsets) — x138 template-safe. + * Provenance: this is the Phase-26 crack (.run/phase26-cracks/func_8015B950.c) re-gated verbatim, + * with ONE deliberate change: the definition's return type void -> s32. + * - `void func_8015B950(s32 arg0)` : MATCH (271 ins) [the Phase-26 form] + * - `s32 func_8015B950(s32 arg0)` : MATCH (271 ins) [shipped — §3a-1 void->s32 is byte-neutral] + * The fleet/engine_core.h canonical decl is `extern s32 func_8015B950(void);` (engine_core.h:1852), + * and the last bank attempt (.run/bank_func_8015B950.log) died on `conflicting types for + * func_8015B950`. Shipping the s32 return kills the §73 RETURN axis for free and leaves only the + * cheap T0 PARAMS axis for the ladder (fix_header_decl.py / --fix-def-sig / cast_call_sites). + * Both forms are byte-identical, so the orchestrator may swap the return type back at zero cost. + * + * SYMBOLS (§58 rules 1/2 — all splat spellings, all verified present): + * D_8018739C asm/ov_SC01_077/data/tail.data.s:4355 (the state-handler vtable) + * D_80187330 asm/ov_SC01_077/data/tail.data.s:4293 + * D_8011F9C4 main-EXE data; spelled `extern s32 D_8011F9C4;` in 5+ already-banked TUs + * jtbl_801D8B74 asm/ov_SC01_077/data/tail14.data.s:15 (compiler jump table — not named in C) + * + * JTBL VERIFIED (§8a gate): compiled .rodata = exactly 0x1C B / 7 words, 7x R_MIPS_32 .text with + * addends [0x58,0x58,0x58,0xE0,0xF0,0x100,0x58] -> +0x8015B950 = [B9A8,B9A8,B9A8,BA30,BA40,BA50, + * B9A8] == the original words at 0x801D8B74..0x801D8B8C. Bound `sltiu $v0,$v1,0x7` matches. + * The raw dlabel's 8th word 0x00000000 is NOT an entry — it is the intra-TU `.align 3` pad of the + * B34/B54/B74 jtbl chain; the object can never emit it (maspsx drops .align), so it must stay in + * the post-carve RAW data piece (the §53/§62/§81 carve chain applies at bank time). + * + * Same family as the TU's own already-matched func_8015AE2C: 7-case switch on ((s32 (*)(s32))func_801619A4)() + * (0/1/2/6 shared, 3/4/5 own, no default block — out-of-range and every `break` fall to the + * after-switch join), then a chain of "state handler" tests, each dispatching + * D_8018739C[*(u16*)arg0](arg0) and returning. + * + * THREE LEVERS (draft -> MATCH in 3 compiles): + * + * 1. PROLOGUE CONSTANT = an INITIALIZED LOCAL, not a literal in the compare. + * Target opens with `lui $s2, 0xFFF5` in the *prologue*, used once ~200 ins later in + * `slt $v0,$s2,$s1`. No gcc-2.7.2 pass hoists a (set reg const_int) across basic blocks + * (loop.c needs a loop; cse/combine/sched never move insns between BBs) — so the insn must + * have been EMITTED in the first BB, i.e. the constant is a local initialized at the top of + * the function. cse then cannot fold it back into the compare: the `slt` operand predicate is + * `arith_operand`, which rejects a CONST_INT wider than 16 bits, so validate_change fails and + * the pseudo survives. Its live range spans every call -> global.c gives it a callee-saved reg. + * Writing `z > -0xB0000` inline instead emits the `lui` into the branch delay slot next to the + * compare (caller-saved $v0) and the function is 1 insn short. => `s32 lim = -0xB0000;` at top. + * + * 2. `lh` vs `lhu`: a short->short copy is a pure HImode move and gcc emits `lhu`. The target's + * `lh $v0,0x26($s0)` means the value passed through an SImode (int) temp: expand makes + * (set (reg:SI) (sign_extend (mem:HI))) + (set (mem:HI) (subreg:HI ...)), and combine cannot + * merge them (the merged form is mem<-mem, which no movhi accepts) so the sign-extending load + * survives. => route both halfword copies through the `s32 t` temp. + * + * 3. THE `goto` LAYOUT — dodging jump.c's store-flag conversion (jump.c:1005-1065). + * An if/else chain writing 0/1 into `doit` makes gcc collapse the last pair into + * `sltiu $v0,$v0,1`. jump.c fires that conversion when the insn immediately after a + * conditional jump is a lone `SET pseudo, CONST_INT` whose following simplejump targets the + * SAME label as the branch (jump.c:1038 `reallabelprev == temp || ... JUMP_LABEL(temp4) == + * JUMP_LABEL(insn)`) — exactly the shape of `if (c) x=0; else x=1;`. + * The target instead cross-jumps ALL the `doit=0` exits into ONE shared block placed after the + * `doit=1` fall-through; reorg's fill_slots_from_thread then COPIES that single set into all + * three branch delay slots and redirects each branch past it (which is why `addu $v0,$zero, + * $zero` appears 3x in delay slots and the shared block vanishes). A `goto zero;` / `goto one;` + * chain expresses that layout directly, and each conditional jump is then followed by a + * compare/call rather than a lone const set, so the store-flag conversion never triggers. + * GENERAL RULE: multiple predicates that all assign the SAME constant to one flag => write + * them as `goto` to a shared assignment, never as an if/else ladder. + */ +extern s32 D_8011F9C4; +extern s32 D_80187330; + +extern s32 func_80161B18(void); +extern s32 func_801619A4(s32*); +extern s32 func_80149AA8(s32*); +extern void func_80149AD4(s32*); +extern s32 func_80149B54(s32*); +extern void func_80149BAC(s32*); +extern s32 func_801498E0(s32*); +extern s32 func_80149954(s32); +extern s32 func_80149A64(s32*); +extern void func_800CCCC0(s32 a0); +extern s32 func_80149CD4(s32 a0); +extern void func_8015E880(s32*); +extern s32 func_80149744(struct S_80149744*); +extern void func_80149788(void); +extern s32 func_801496D4(void*); +extern void func_80149704(void); +extern int func_80148AFC(void*); +extern void func_80146D90(s32 a0); +extern void func_80154150(s32 a0, s32 a1); +extern void func_801541D8(u8*, s32, s32); +extern s32 func_801488A8(u8*); +extern void func_80147078(s32*, s16); +extern void func_8015A264(void*); +extern s32 func_80013294(void*, void*); +extern void func_80159B70(void*); +extern s32 func_8016F1AC(void); +extern s32 func_80029178(s32 a0); +extern void func_80146DB8(s32*, s32*); +extern s32 func_80161CD0(s32, s32); +extern s32 func_80161208(s32 a0); +extern s32 func_801725A4(u8*); + +s32 func_8015B950(s32 arg0) +{ + + extern void (*D_8018739C[])(void *); + s16 sp10[4]; + s16 sp18[4]; + s32 t; + s32 z; + s32 doit; + s32 lim = -0xB0000; + + if (func_80161B18() != 0) { + return; + } + switch (((s32 (*)(s32))func_801619A4)(arg0)) { + case 0: + case 1: + case 2: + case 6: + if (((s32 (*)(s32))func_80149AA8)(arg0) != 0) { + D_8018739C[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149AD4)(arg0); + return; + } + if (((s32 (*)(s32))func_80149B54)(arg0) != 0) { + D_8018739C[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149BAC)(arg0); + return; + } + break; + case 3: + ((void (*)(s32))func_801498E0)(arg0); + break; + case 4: + ((void (*)(s32))func_80149954)(arg0); + break; + case 5: + if (((s32 (*)(s32))func_80149A64)(arg0) != 0) { + D_8018739C[*(u16 *)arg0]((void *)arg0); + func_800CCCC0(arg0); + return; + } + break; + } + if (func_80149CD4(arg0) != 0) { + D_8018739C[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_8015E880)(arg0); + return; + } + if (((s32 (*)(s32))func_80149744)(arg0) != 0) { + D_8018739C[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149788)(arg0); + return; + } + if (((s32 (*)(s32))func_801496D4)(arg0) != 0) { + D_8018739C[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149704)(arg0); + if (((u8)((s32 (*)(s32))func_80148AFC)(arg0)) == 0) { + func_80146D90(arg0); + } + if ((*(s32 *)(arg0 + 0x24) | *(s32 *)(arg0 + 0x2C)) != 0) { + func_80154150(arg0, 0xF); + } else { + ((void (*)(s32, s32, s32))func_801541D8)(arg0, 0xD, 6); + } + *(s32 *)(arg0 + 0x238) = 1; + return; + } + if (((s32 (*)(s32))func_801488A8)(arg0) != 0) { + sp10[0] = 0; + sp10[1] = 0; + sp10[2] = 0; + t = *(s16 *)(arg0 + 0x26); + sp18[0] = t; + sp18[1] = 0; + t = *(s16 *)(arg0 + 0x2E); + sp18[2] = t; + D_8018739C[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 1); + ((void (*)(s32))func_8015A264)(arg0); + t = -(((s32 (*)(s16 *, s16 *))func_80013294)(sp10, sp18) << 0x10); + if (t < *(s32 *)(arg0 + 0x2C)) { + *(s32 *)(arg0 + 0x2C) = t; + } + return; + } + if (*(u16 *)(arg0 + 0xB8) == 0x8000) { + D_8018739C[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 0); + ((void (*)(s32))func_80159B70)(arg0); + return; + } + z = *(s32 *)(arg0 + 0x2C); + if (func_8016F1AC() != 0) { + goto zero; + } + if (z <= lim) { + goto one; + } + if (D_8011F9C4 == 0) { + goto zero; + } + if (((u8)func_80029178(0x21)) != 0) { + goto zero; + } +one: + doit = 1; + goto join; +zero: + doit = 0; +join: + if (doit != 0) { + D_8018739C[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 0); + ((void (*)(s32))func_80159B70)(arg0); + func_80154150(arg0, 9); + ((void (*)(s32, s32 *))func_80146DB8)(arg0, &D_80187330); + ((void (*)(s32, s32))func_80161CD0)(arg0, *(u16 *)(arg0 + 0x16E)); + return; + } + if (func_80161208(arg0) == 0) { + ((void (*)(s32))func_801725A4)(arg0); + } +} DEFINE_func_8015BD8C() /* dedup: shared engine-core @0x8015BD8C (src/shared) */ diff --git a/src/ov_SC03_093/ov_SC03_093_jr_8015AE2C.c b/src/ov_SC03_093/ov_SC03_093_jr_8015AE2C.c index 490e81973..770da99b8 100644 --- a/src/ov_SC03_093/ov_SC03_093_jr_8015AE2C.c +++ b/src/ov_SC03_093/ov_SC03_093_jr_8015AE2C.c @@ -1513,7 +1513,259 @@ DEFINE_func_8015B858() /* dedup: shared engine-core @0x8015B858 (src/shared) */ DEFINE_func_8015B8F8() /* dedup: shared engine-core @0x8015B8F8 (src/shared) */ -INCLUDE_ASM("asm/ov_SC03_093/nonmatchings/ov_SC03_093_jr_8015AE2C", func_8015B950); +extern s32 func_8015AE2C(); + +// @class: plumbing +// @stuck: none — MATCH (271/271, pin-free, zero asm). The ONLY residual is DEF-SIDE plumbing, and it is now named exactly: the in-TU instantiation `DEFINE_func_8015BEE4()` (engine_core.h:1851-1855) expands to `extern s32 func_8015B950(void);` INSIDE ov_SC01_077_jr_8015AE2C.c, ~14 lines BELOW this definition, so the 1-param def collides with a `(void)` prototype -> `conflicting types for func_8015B950` (.run/bank_func_8015B950.log). §73 PARAMS axis / T0. Surgical fix = §65b de-macroize that ONE instantiation (blast radius: this TU); the fleet-wide `(void)`->`()` header edit is §63 and must be R22-validated. +/* func_8015B950 (ov_SC01_077_jr_8015AE2C, 271 ins, jtbl_801D8B74) — SESSION-21 re-verified + * + * ── ROUND-2 INDEPENDENT RE-VERIFICATION (2026-07-27, fresh agent, §88e discipline) ───────────── + * match_one : MATCH (271 ins) against the CURRENT tree — §87 staleness re-checked today. + * .text size: compiled .text = 0x43C = 1084 B = 271 ins, EXACTLY the target's declared 0x43C + * ("nonmatching func_8015B950, 0x43C"). So this is NOT a §83a length drift hiding + * behind a zero count — the count is over equal-length streams. + * jtbl : RE-DECODED MECHANICALLY, not inherited. Compiled .rodata = 0x1C = 28 B = 7 words, + * 7x R_MIPS_32 -> .text with implicit addends [58,58,58,E0,F0,100,58]; +0x8015B950 + * = [8015B9A8, 8015B9A8, 8015B9A8, 8015BA30, 8015BA40, 8015BA50, 8015B9A8]. + * Diffed word-for-word against asm/ov_SC01_077/data/tail14.data.s:15-23 — 7/7 identical. + * symcheck : SYMS-DIFF target=35 draft=34, sole MISSING = jtbl_801D8B74. This is the §81 jr + * FALSE POSITIVE, re-confirmed here by reading the relocs: gcc emits its OWN table and + * references it with R_MIPS_HI16/LO16 against the SECTION `.rodata` (t.o +0x40/+0x48), + * so the splat's dlabel NAME can never appear in the draft object's relocation set. + * Nothing is dropped and nothing is invented: the draft's other 34 symbols are exactly + * the target's other 34. + * FAMILY : the x138 remap is clean and §84-safe. Every sibling is 271 ins with an IDENTICAL + * callee set; only THREE names vary per overlay — the two data labels and the jtbl: + * ov_SC01_077 D_80188508 / D_80188574 / jtbl_801D8B74 + * ov_SC03_099 D_80185A50 / D_80185ABC / jtbl_801BD898 + * ov_SC06_008 D_80187E44 / D_80187EB0 / jtbl_801A8734 + * The pair is always +0x6C apart, and NO literal in this draft encodes that distance + * (both labels are referenced by name), so there is no §84 derived-offset hazard. + * D_8011F9C4 is fleet-constant (main-EXE data) and must NOT be remapped. + * + * match_one: MATCH (271 ins) against the CURRENT tree (§87 staleness re-checked, 2026-07-27). + * PIN-FREE, zero asm, offset-pure (s32 arg0 + raw offsets) — x138 template-safe. + * Provenance: this is the Phase-26 crack (.run/phase26-cracks/func_8015B950.c) re-gated verbatim, + * with ONE deliberate change: the definition's return type void -> s32. + * - `void func_8015B950(s32 arg0)` : MATCH (271 ins) [the Phase-26 form] + * - `s32 func_8015B950(s32 arg0)` : MATCH (271 ins) [shipped — §3a-1 void->s32 is byte-neutral] + * The fleet/engine_core.h canonical decl is `extern s32 func_8015B950(void);` (engine_core.h:1852), + * and the last bank attempt (.run/bank_func_8015B950.log) died on `conflicting types for + * func_8015B950`. Shipping the s32 return kills the §73 RETURN axis for free and leaves only the + * cheap T0 PARAMS axis for the ladder (fix_header_decl.py / --fix-def-sig / cast_call_sites). + * Both forms are byte-identical, so the orchestrator may swap the return type back at zero cost. + * + * SYMBOLS (§58 rules 1/2 — all splat spellings, all verified present): + * D_80188574 asm/ov_SC01_077/data/tail.data.s:4355 (the state-handler vtable) + * D_80188508 asm/ov_SC01_077/data/tail.data.s:4293 + * D_8011F9C4 main-EXE data; spelled `extern s32 D_8011F9C4;` in 5+ already-banked TUs + * jtbl_801D8B74 asm/ov_SC01_077/data/tail14.data.s:15 (compiler jump table — not named in C) + * + * JTBL VERIFIED (§8a gate): compiled .rodata = exactly 0x1C B / 7 words, 7x R_MIPS_32 .text with + * addends [0x58,0x58,0x58,0xE0,0xF0,0x100,0x58] -> +0x8015B950 = [B9A8,B9A8,B9A8,BA30,BA40,BA50, + * B9A8] == the original words at 0x801D8B74..0x801D8B8C. Bound `sltiu $v0,$v1,0x7` matches. + * The raw dlabel's 8th word 0x00000000 is NOT an entry — it is the intra-TU `.align 3` pad of the + * B34/B54/B74 jtbl chain; the object can never emit it (maspsx drops .align), so it must stay in + * the post-carve RAW data piece (the §53/§62/§81 carve chain applies at bank time). + * + * Same family as the TU's own already-matched func_8015AE2C: 7-case switch on ((s32 (*)(s32))func_801619A4)() + * (0/1/2/6 shared, 3/4/5 own, no default block — out-of-range and every `break` fall to the + * after-switch join), then a chain of "state handler" tests, each dispatching + * D_80188574[*(u16*)arg0](arg0) and returning. + * + * THREE LEVERS (draft -> MATCH in 3 compiles): + * + * 1. PROLOGUE CONSTANT = an INITIALIZED LOCAL, not a literal in the compare. + * Target opens with `lui $s2, 0xFFF5` in the *prologue*, used once ~200 ins later in + * `slt $v0,$s2,$s1`. No gcc-2.7.2 pass hoists a (set reg const_int) across basic blocks + * (loop.c needs a loop; cse/combine/sched never move insns between BBs) — so the insn must + * have been EMITTED in the first BB, i.e. the constant is a local initialized at the top of + * the function. cse then cannot fold it back into the compare: the `slt` operand predicate is + * `arith_operand`, which rejects a CONST_INT wider than 16 bits, so validate_change fails and + * the pseudo survives. Its live range spans every call -> global.c gives it a callee-saved reg. + * Writing `z > -0xB0000` inline instead emits the `lui` into the branch delay slot next to the + * compare (caller-saved $v0) and the function is 1 insn short. => `s32 lim = -0xB0000;` at top. + * + * 2. `lh` vs `lhu`: a short->short copy is a pure HImode move and gcc emits `lhu`. The target's + * `lh $v0,0x26($s0)` means the value passed through an SImode (int) temp: expand makes + * (set (reg:SI) (sign_extend (mem:HI))) + (set (mem:HI) (subreg:HI ...)), and combine cannot + * merge them (the merged form is mem<-mem, which no movhi accepts) so the sign-extending load + * survives. => route both halfword copies through the `s32 t` temp. + * + * 3. THE `goto` LAYOUT — dodging jump.c's store-flag conversion (jump.c:1005-1065). + * An if/else chain writing 0/1 into `doit` makes gcc collapse the last pair into + * `sltiu $v0,$v0,1`. jump.c fires that conversion when the insn immediately after a + * conditional jump is a lone `SET pseudo, CONST_INT` whose following simplejump targets the + * SAME label as the branch (jump.c:1038 `reallabelprev == temp || ... JUMP_LABEL(temp4) == + * JUMP_LABEL(insn)`) — exactly the shape of `if (c) x=0; else x=1;`. + * The target instead cross-jumps ALL the `doit=0` exits into ONE shared block placed after the + * `doit=1` fall-through; reorg's fill_slots_from_thread then COPIES that single set into all + * three branch delay slots and redirects each branch past it (which is why `addu $v0,$zero, + * $zero` appears 3x in delay slots and the shared block vanishes). A `goto zero;` / `goto one;` + * chain expresses that layout directly, and each conditional jump is then followed by a + * compare/call rather than a lone const set, so the store-flag conversion never triggers. + * GENERAL RULE: multiple predicates that all assign the SAME constant to one flag => write + * them as `goto` to a shared assignment, never as an if/else ladder. + */ +extern s32 D_8011F9C4; +extern s32 D_80188508; + +extern s32 func_80161B18(void); +extern s32 func_801619A4(s32*); +extern s32 func_80149AA8(s32*); +extern void func_80149AD4(s32*); +extern s32 func_80149B54(s32*); +extern void func_80149BAC(s32*); +extern s32 func_801498E0(s32*); +extern s32 func_80149954(s32); +extern s32 func_80149A64(s32*); +extern void func_800CCCC0(s32 a0); +extern s32 func_80149CD4(s32 a0); +extern void func_8015E880(s32*); +extern s32 func_80149744(struct S_80149744*); +extern void func_80149788(void); +extern s32 func_801496D4(void*); +extern void func_80149704(void); +extern int func_80148AFC(void*); +extern void func_80146D90(s32 a0); +extern void func_80154150(s32 a0, s32 a1); +extern void func_801541D8(u8*, s32, s32); +extern s32 func_801488A8(u8*); +extern void func_80147078(s32*, s16); +extern void func_8015A264(void*); +extern s32 func_80013294(void*, void*); +extern void func_80159B70(void*); +extern s32 func_8016F1AC(void); +extern s32 func_80029178(s32 a0); +extern void func_80146DB8(s32*, s32*); +extern s32 func_80161CD0(s32, s32); +extern s32 func_80161208(s32 a0); +extern s32 func_801725A4(u8*); + +s32 func_8015B950(s32 arg0) +{ + + extern void (*D_80188574[])(void *); + s16 sp10[4]; + s16 sp18[4]; + s32 t; + s32 z; + s32 doit; + s32 lim = -0xB0000; + + if (func_80161B18() != 0) { + return; + } + switch (((s32 (*)(s32))func_801619A4)(arg0)) { + case 0: + case 1: + case 2: + case 6: + if (((s32 (*)(s32))func_80149AA8)(arg0) != 0) { + D_80188574[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149AD4)(arg0); + return; + } + if (((s32 (*)(s32))func_80149B54)(arg0) != 0) { + D_80188574[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149BAC)(arg0); + return; + } + break; + case 3: + ((void (*)(s32))func_801498E0)(arg0); + break; + case 4: + ((void (*)(s32))func_80149954)(arg0); + break; + case 5: + if (((s32 (*)(s32))func_80149A64)(arg0) != 0) { + D_80188574[*(u16 *)arg0]((void *)arg0); + func_800CCCC0(arg0); + return; + } + break; + } + if (func_80149CD4(arg0) != 0) { + D_80188574[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_8015E880)(arg0); + return; + } + if (((s32 (*)(s32))func_80149744)(arg0) != 0) { + D_80188574[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149788)(arg0); + return; + } + if (((s32 (*)(s32))func_801496D4)(arg0) != 0) { + D_80188574[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149704)(arg0); + if (((u8)((s32 (*)(s32))func_80148AFC)(arg0)) == 0) { + func_80146D90(arg0); + } + if ((*(s32 *)(arg0 + 0x24) | *(s32 *)(arg0 + 0x2C)) != 0) { + func_80154150(arg0, 0xF); + } else { + ((void (*)(s32, s32, s32))func_801541D8)(arg0, 0xD, 6); + } + *(s32 *)(arg0 + 0x238) = 1; + return; + } + if (((s32 (*)(s32))func_801488A8)(arg0) != 0) { + sp10[0] = 0; + sp10[1] = 0; + sp10[2] = 0; + t = *(s16 *)(arg0 + 0x26); + sp18[0] = t; + sp18[1] = 0; + t = *(s16 *)(arg0 + 0x2E); + sp18[2] = t; + D_80188574[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 1); + ((void (*)(s32))func_8015A264)(arg0); + t = -(((s32 (*)(s16 *, s16 *))func_80013294)(sp10, sp18) << 0x10); + if (t < *(s32 *)(arg0 + 0x2C)) { + *(s32 *)(arg0 + 0x2C) = t; + } + return; + } + if (*(u16 *)(arg0 + 0xB8) == 0x8000) { + D_80188574[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 0); + ((void (*)(s32))func_80159B70)(arg0); + return; + } + z = *(s32 *)(arg0 + 0x2C); + if (func_8016F1AC() != 0) { + goto zero; + } + if (z <= lim) { + goto one; + } + if (D_8011F9C4 == 0) { + goto zero; + } + if (((u8)func_80029178(0x21)) != 0) { + goto zero; + } +one: + doit = 1; + goto join; +zero: + doit = 0; +join: + if (doit != 0) { + D_80188574[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 0); + ((void (*)(s32))func_80159B70)(arg0); + func_80154150(arg0, 9); + ((void (*)(s32, s32 *))func_80146DB8)(arg0, &D_80188508); + ((void (*)(s32, s32))func_80161CD0)(arg0, *(u16 *)(arg0 + 0x16E)); + return; + } + if (func_80161208(arg0) == 0) { + ((void (*)(s32))func_801725A4)(arg0); + } +} DEFINE_func_8015BD8C() /* dedup: shared engine-core @0x8015BD8C (src/shared) */ diff --git a/src/ov_SC03_094/ov_SC03_094_jr_8015AE2C.c b/src/ov_SC03_094/ov_SC03_094_jr_8015AE2C.c index df17ed488..7ae39d0fd 100644 --- a/src/ov_SC03_094/ov_SC03_094_jr_8015AE2C.c +++ b/src/ov_SC03_094/ov_SC03_094_jr_8015AE2C.c @@ -1513,7 +1513,259 @@ DEFINE_func_8015B858() /* dedup: shared engine-core @0x8015B858 (src/shared) */ DEFINE_func_8015B8F8() /* dedup: shared engine-core @0x8015B8F8 (src/shared) */ -INCLUDE_ASM("asm/ov_SC03_094/nonmatchings/ov_SC03_094_jr_8015AE2C", func_8015B950); +extern s32 func_8015AE2C(); + +// @class: plumbing +// @stuck: none — MATCH (271/271, pin-free, zero asm). The ONLY residual is DEF-SIDE plumbing, and it is now named exactly: the in-TU instantiation `DEFINE_func_8015BEE4()` (engine_core.h:1851-1855) expands to `extern s32 func_8015B950(void);` INSIDE ov_SC01_077_jr_8015AE2C.c, ~14 lines BELOW this definition, so the 1-param def collides with a `(void)` prototype -> `conflicting types for func_8015B950` (.run/bank_func_8015B950.log). §73 PARAMS axis / T0. Surgical fix = §65b de-macroize that ONE instantiation (blast radius: this TU); the fleet-wide `(void)`->`()` header edit is §63 and must be R22-validated. +/* func_8015B950 (ov_SC01_077_jr_8015AE2C, 271 ins, jtbl_801D8B74) — SESSION-21 re-verified + * + * ── ROUND-2 INDEPENDENT RE-VERIFICATION (2026-07-27, fresh agent, §88e discipline) ───────────── + * match_one : MATCH (271 ins) against the CURRENT tree — §87 staleness re-checked today. + * .text size: compiled .text = 0x43C = 1084 B = 271 ins, EXACTLY the target's declared 0x43C + * ("nonmatching func_8015B950, 0x43C"). So this is NOT a §83a length drift hiding + * behind a zero count — the count is over equal-length streams. + * jtbl : RE-DECODED MECHANICALLY, not inherited. Compiled .rodata = 0x1C = 28 B = 7 words, + * 7x R_MIPS_32 -> .text with implicit addends [58,58,58,E0,F0,100,58]; +0x8015B950 + * = [8015B9A8, 8015B9A8, 8015B9A8, 8015BA30, 8015BA40, 8015BA50, 8015B9A8]. + * Diffed word-for-word against asm/ov_SC01_077/data/tail14.data.s:15-23 — 7/7 identical. + * symcheck : SYMS-DIFF target=35 draft=34, sole MISSING = jtbl_801D8B74. This is the §81 jr + * FALSE POSITIVE, re-confirmed here by reading the relocs: gcc emits its OWN table and + * references it with R_MIPS_HI16/LO16 against the SECTION `.rodata` (t.o +0x40/+0x48), + * so the splat's dlabel NAME can never appear in the draft object's relocation set. + * Nothing is dropped and nothing is invented: the draft's other 34 symbols are exactly + * the target's other 34. + * FAMILY : the x138 remap is clean and §84-safe. Every sibling is 271 ins with an IDENTICAL + * callee set; only THREE names vary per overlay — the two data labels and the jtbl: + * ov_SC01_077 D_80189F04 / D_80189F70 / jtbl_801D8B74 + * ov_SC03_099 D_80185A50 / D_80185ABC / jtbl_801BD898 + * ov_SC06_008 D_80187E44 / D_80187EB0 / jtbl_801A8734 + * The pair is always +0x6C apart, and NO literal in this draft encodes that distance + * (both labels are referenced by name), so there is no §84 derived-offset hazard. + * D_8011F9C4 is fleet-constant (main-EXE data) and must NOT be remapped. + * + * match_one: MATCH (271 ins) against the CURRENT tree (§87 staleness re-checked, 2026-07-27). + * PIN-FREE, zero asm, offset-pure (s32 arg0 + raw offsets) — x138 template-safe. + * Provenance: this is the Phase-26 crack (.run/phase26-cracks/func_8015B950.c) re-gated verbatim, + * with ONE deliberate change: the definition's return type void -> s32. + * - `void func_8015B950(s32 arg0)` : MATCH (271 ins) [the Phase-26 form] + * - `s32 func_8015B950(s32 arg0)` : MATCH (271 ins) [shipped — §3a-1 void->s32 is byte-neutral] + * The fleet/engine_core.h canonical decl is `extern s32 func_8015B950(void);` (engine_core.h:1852), + * and the last bank attempt (.run/bank_func_8015B950.log) died on `conflicting types for + * func_8015B950`. Shipping the s32 return kills the §73 RETURN axis for free and leaves only the + * cheap T0 PARAMS axis for the ladder (fix_header_decl.py / --fix-def-sig / cast_call_sites). + * Both forms are byte-identical, so the orchestrator may swap the return type back at zero cost. + * + * SYMBOLS (§58 rules 1/2 — all splat spellings, all verified present): + * D_80189F70 asm/ov_SC01_077/data/tail.data.s:4355 (the state-handler vtable) + * D_80189F04 asm/ov_SC01_077/data/tail.data.s:4293 + * D_8011F9C4 main-EXE data; spelled `extern s32 D_8011F9C4;` in 5+ already-banked TUs + * jtbl_801D8B74 asm/ov_SC01_077/data/tail14.data.s:15 (compiler jump table — not named in C) + * + * JTBL VERIFIED (§8a gate): compiled .rodata = exactly 0x1C B / 7 words, 7x R_MIPS_32 .text with + * addends [0x58,0x58,0x58,0xE0,0xF0,0x100,0x58] -> +0x8015B950 = [B9A8,B9A8,B9A8,BA30,BA40,BA50, + * B9A8] == the original words at 0x801D8B74..0x801D8B8C. Bound `sltiu $v0,$v1,0x7` matches. + * The raw dlabel's 8th word 0x00000000 is NOT an entry — it is the intra-TU `.align 3` pad of the + * B34/B54/B74 jtbl chain; the object can never emit it (maspsx drops .align), so it must stay in + * the post-carve RAW data piece (the §53/§62/§81 carve chain applies at bank time). + * + * Same family as the TU's own already-matched func_8015AE2C: 7-case switch on ((s32 (*)(s32))func_801619A4)() + * (0/1/2/6 shared, 3/4/5 own, no default block — out-of-range and every `break` fall to the + * after-switch join), then a chain of "state handler" tests, each dispatching + * D_80189F70[*(u16*)arg0](arg0) and returning. + * + * THREE LEVERS (draft -> MATCH in 3 compiles): + * + * 1. PROLOGUE CONSTANT = an INITIALIZED LOCAL, not a literal in the compare. + * Target opens with `lui $s2, 0xFFF5` in the *prologue*, used once ~200 ins later in + * `slt $v0,$s2,$s1`. No gcc-2.7.2 pass hoists a (set reg const_int) across basic blocks + * (loop.c needs a loop; cse/combine/sched never move insns between BBs) — so the insn must + * have been EMITTED in the first BB, i.e. the constant is a local initialized at the top of + * the function. cse then cannot fold it back into the compare: the `slt` operand predicate is + * `arith_operand`, which rejects a CONST_INT wider than 16 bits, so validate_change fails and + * the pseudo survives. Its live range spans every call -> global.c gives it a callee-saved reg. + * Writing `z > -0xB0000` inline instead emits the `lui` into the branch delay slot next to the + * compare (caller-saved $v0) and the function is 1 insn short. => `s32 lim = -0xB0000;` at top. + * + * 2. `lh` vs `lhu`: a short->short copy is a pure HImode move and gcc emits `lhu`. The target's + * `lh $v0,0x26($s0)` means the value passed through an SImode (int) temp: expand makes + * (set (reg:SI) (sign_extend (mem:HI))) + (set (mem:HI) (subreg:HI ...)), and combine cannot + * merge them (the merged form is mem<-mem, which no movhi accepts) so the sign-extending load + * survives. => route both halfword copies through the `s32 t` temp. + * + * 3. THE `goto` LAYOUT — dodging jump.c's store-flag conversion (jump.c:1005-1065). + * An if/else chain writing 0/1 into `doit` makes gcc collapse the last pair into + * `sltiu $v0,$v0,1`. jump.c fires that conversion when the insn immediately after a + * conditional jump is a lone `SET pseudo, CONST_INT` whose following simplejump targets the + * SAME label as the branch (jump.c:1038 `reallabelprev == temp || ... JUMP_LABEL(temp4) == + * JUMP_LABEL(insn)`) — exactly the shape of `if (c) x=0; else x=1;`. + * The target instead cross-jumps ALL the `doit=0` exits into ONE shared block placed after the + * `doit=1` fall-through; reorg's fill_slots_from_thread then COPIES that single set into all + * three branch delay slots and redirects each branch past it (which is why `addu $v0,$zero, + * $zero` appears 3x in delay slots and the shared block vanishes). A `goto zero;` / `goto one;` + * chain expresses that layout directly, and each conditional jump is then followed by a + * compare/call rather than a lone const set, so the store-flag conversion never triggers. + * GENERAL RULE: multiple predicates that all assign the SAME constant to one flag => write + * them as `goto` to a shared assignment, never as an if/else ladder. + */ +extern s32 D_8011F9C4; +extern s32 D_80189F04; + +extern s32 func_80161B18(void); +extern s32 func_801619A4(s32*); +extern s32 func_80149AA8(s32*); +extern void func_80149AD4(s32*); +extern s32 func_80149B54(s32*); +extern void func_80149BAC(s32*); +extern s32 func_801498E0(s32*); +extern s32 func_80149954(s32); +extern s32 func_80149A64(s32*); +extern void func_800CCCC0(s32 a0); +extern s32 func_80149CD4(s32 a0); +extern void func_8015E880(s32*); +extern s32 func_80149744(struct S_80149744*); +extern void func_80149788(void); +extern s32 func_801496D4(void*); +extern void func_80149704(void); +extern int func_80148AFC(void*); +extern void func_80146D90(s32 a0); +extern void func_80154150(s32 a0, s32 a1); +extern void func_801541D8(u8*, s32, s32); +extern s32 func_801488A8(u8*); +extern void func_80147078(s32*, s16); +extern void func_8015A264(void*); +extern s32 func_80013294(void*, void*); +extern void func_80159B70(void*); +extern s32 func_8016F1AC(void); +extern s32 func_80029178(s32 a0); +extern void func_80146DB8(s32*, s32*); +extern s32 func_80161CD0(s32, s32); +extern s32 func_80161208(s32 a0); +extern s32 func_801725A4(u8*); + +s32 func_8015B950(s32 arg0) +{ + + extern void (*D_80189F70[])(void *); + s16 sp10[4]; + s16 sp18[4]; + s32 t; + s32 z; + s32 doit; + s32 lim = -0xB0000; + + if (func_80161B18() != 0) { + return; + } + switch (((s32 (*)(s32))func_801619A4)(arg0)) { + case 0: + case 1: + case 2: + case 6: + if (((s32 (*)(s32))func_80149AA8)(arg0) != 0) { + D_80189F70[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149AD4)(arg0); + return; + } + if (((s32 (*)(s32))func_80149B54)(arg0) != 0) { + D_80189F70[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149BAC)(arg0); + return; + } + break; + case 3: + ((void (*)(s32))func_801498E0)(arg0); + break; + case 4: + ((void (*)(s32))func_80149954)(arg0); + break; + case 5: + if (((s32 (*)(s32))func_80149A64)(arg0) != 0) { + D_80189F70[*(u16 *)arg0]((void *)arg0); + func_800CCCC0(arg0); + return; + } + break; + } + if (func_80149CD4(arg0) != 0) { + D_80189F70[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_8015E880)(arg0); + return; + } + if (((s32 (*)(s32))func_80149744)(arg0) != 0) { + D_80189F70[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149788)(arg0); + return; + } + if (((s32 (*)(s32))func_801496D4)(arg0) != 0) { + D_80189F70[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149704)(arg0); + if (((u8)((s32 (*)(s32))func_80148AFC)(arg0)) == 0) { + func_80146D90(arg0); + } + if ((*(s32 *)(arg0 + 0x24) | *(s32 *)(arg0 + 0x2C)) != 0) { + func_80154150(arg0, 0xF); + } else { + ((void (*)(s32, s32, s32))func_801541D8)(arg0, 0xD, 6); + } + *(s32 *)(arg0 + 0x238) = 1; + return; + } + if (((s32 (*)(s32))func_801488A8)(arg0) != 0) { + sp10[0] = 0; + sp10[1] = 0; + sp10[2] = 0; + t = *(s16 *)(arg0 + 0x26); + sp18[0] = t; + sp18[1] = 0; + t = *(s16 *)(arg0 + 0x2E); + sp18[2] = t; + D_80189F70[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 1); + ((void (*)(s32))func_8015A264)(arg0); + t = -(((s32 (*)(s16 *, s16 *))func_80013294)(sp10, sp18) << 0x10); + if (t < *(s32 *)(arg0 + 0x2C)) { + *(s32 *)(arg0 + 0x2C) = t; + } + return; + } + if (*(u16 *)(arg0 + 0xB8) == 0x8000) { + D_80189F70[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 0); + ((void (*)(s32))func_80159B70)(arg0); + return; + } + z = *(s32 *)(arg0 + 0x2C); + if (func_8016F1AC() != 0) { + goto zero; + } + if (z <= lim) { + goto one; + } + if (D_8011F9C4 == 0) { + goto zero; + } + if (((u8)func_80029178(0x21)) != 0) { + goto zero; + } +one: + doit = 1; + goto join; +zero: + doit = 0; +join: + if (doit != 0) { + D_80189F70[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 0); + ((void (*)(s32))func_80159B70)(arg0); + func_80154150(arg0, 9); + ((void (*)(s32, s32 *))func_80146DB8)(arg0, &D_80189F04); + ((void (*)(s32, s32))func_80161CD0)(arg0, *(u16 *)(arg0 + 0x16E)); + return; + } + if (func_80161208(arg0) == 0) { + ((void (*)(s32))func_801725A4)(arg0); + } +} DEFINE_func_8015BD8C() /* dedup: shared engine-core @0x8015BD8C (src/shared) */ diff --git a/src/ov_SC03_095/ov_SC03_095_jr_8015AE2C.c b/src/ov_SC03_095/ov_SC03_095_jr_8015AE2C.c index 81d5593c7..23be3f522 100644 --- a/src/ov_SC03_095/ov_SC03_095_jr_8015AE2C.c +++ b/src/ov_SC03_095/ov_SC03_095_jr_8015AE2C.c @@ -1513,7 +1513,259 @@ DEFINE_func_8015B858() /* dedup: shared engine-core @0x8015B858 (src/shared) */ DEFINE_func_8015B8F8() /* dedup: shared engine-core @0x8015B8F8 (src/shared) */ -INCLUDE_ASM("asm/ov_SC03_095/nonmatchings/ov_SC03_095_jr_8015AE2C", func_8015B950); +extern s32 func_8015AE2C(); + +// @class: plumbing +// @stuck: none — MATCH (271/271, pin-free, zero asm). The ONLY residual is DEF-SIDE plumbing, and it is now named exactly: the in-TU instantiation `DEFINE_func_8015BEE4()` (engine_core.h:1851-1855) expands to `extern s32 func_8015B950(void);` INSIDE ov_SC01_077_jr_8015AE2C.c, ~14 lines BELOW this definition, so the 1-param def collides with a `(void)` prototype -> `conflicting types for func_8015B950` (.run/bank_func_8015B950.log). §73 PARAMS axis / T0. Surgical fix = §65b de-macroize that ONE instantiation (blast radius: this TU); the fleet-wide `(void)`->`()` header edit is §63 and must be R22-validated. +/* func_8015B950 (ov_SC01_077_jr_8015AE2C, 271 ins, jtbl_801D8B74) — SESSION-21 re-verified + * + * ── ROUND-2 INDEPENDENT RE-VERIFICATION (2026-07-27, fresh agent, §88e discipline) ───────────── + * match_one : MATCH (271 ins) against the CURRENT tree — §87 staleness re-checked today. + * .text size: compiled .text = 0x43C = 1084 B = 271 ins, EXACTLY the target's declared 0x43C + * ("nonmatching func_8015B950, 0x43C"). So this is NOT a §83a length drift hiding + * behind a zero count — the count is over equal-length streams. + * jtbl : RE-DECODED MECHANICALLY, not inherited. Compiled .rodata = 0x1C = 28 B = 7 words, + * 7x R_MIPS_32 -> .text with implicit addends [58,58,58,E0,F0,100,58]; +0x8015B950 + * = [8015B9A8, 8015B9A8, 8015B9A8, 8015BA30, 8015BA40, 8015BA50, 8015B9A8]. + * Diffed word-for-word against asm/ov_SC01_077/data/tail14.data.s:15-23 — 7/7 identical. + * symcheck : SYMS-DIFF target=35 draft=34, sole MISSING = jtbl_801D8B74. This is the §81 jr + * FALSE POSITIVE, re-confirmed here by reading the relocs: gcc emits its OWN table and + * references it with R_MIPS_HI16/LO16 against the SECTION `.rodata` (t.o +0x40/+0x48), + * so the splat's dlabel NAME can never appear in the draft object's relocation set. + * Nothing is dropped and nothing is invented: the draft's other 34 symbols are exactly + * the target's other 34. + * FAMILY : the x138 remap is clean and §84-safe. Every sibling is 271 ins with an IDENTICAL + * callee set; only THREE names vary per overlay — the two data labels and the jtbl: + * ov_SC01_077 D_80183564 / D_801835D0 / jtbl_801D8B74 + * ov_SC03_099 D_80185A50 / D_80185ABC / jtbl_801BD898 + * ov_SC06_008 D_80187E44 / D_80187EB0 / jtbl_801A8734 + * The pair is always +0x6C apart, and NO literal in this draft encodes that distance + * (both labels are referenced by name), so there is no §84 derived-offset hazard. + * D_8011F9C4 is fleet-constant (main-EXE data) and must NOT be remapped. + * + * match_one: MATCH (271 ins) against the CURRENT tree (§87 staleness re-checked, 2026-07-27). + * PIN-FREE, zero asm, offset-pure (s32 arg0 + raw offsets) — x138 template-safe. + * Provenance: this is the Phase-26 crack (.run/phase26-cracks/func_8015B950.c) re-gated verbatim, + * with ONE deliberate change: the definition's return type void -> s32. + * - `void func_8015B950(s32 arg0)` : MATCH (271 ins) [the Phase-26 form] + * - `s32 func_8015B950(s32 arg0)` : MATCH (271 ins) [shipped — §3a-1 void->s32 is byte-neutral] + * The fleet/engine_core.h canonical decl is `extern s32 func_8015B950(void);` (engine_core.h:1852), + * and the last bank attempt (.run/bank_func_8015B950.log) died on `conflicting types for + * func_8015B950`. Shipping the s32 return kills the §73 RETURN axis for free and leaves only the + * cheap T0 PARAMS axis for the ladder (fix_header_decl.py / --fix-def-sig / cast_call_sites). + * Both forms are byte-identical, so the orchestrator may swap the return type back at zero cost. + * + * SYMBOLS (§58 rules 1/2 — all splat spellings, all verified present): + * D_801835D0 asm/ov_SC01_077/data/tail.data.s:4355 (the state-handler vtable) + * D_80183564 asm/ov_SC01_077/data/tail.data.s:4293 + * D_8011F9C4 main-EXE data; spelled `extern s32 D_8011F9C4;` in 5+ already-banked TUs + * jtbl_801D8B74 asm/ov_SC01_077/data/tail14.data.s:15 (compiler jump table — not named in C) + * + * JTBL VERIFIED (§8a gate): compiled .rodata = exactly 0x1C B / 7 words, 7x R_MIPS_32 .text with + * addends [0x58,0x58,0x58,0xE0,0xF0,0x100,0x58] -> +0x8015B950 = [B9A8,B9A8,B9A8,BA30,BA40,BA50, + * B9A8] == the original words at 0x801D8B74..0x801D8B8C. Bound `sltiu $v0,$v1,0x7` matches. + * The raw dlabel's 8th word 0x00000000 is NOT an entry — it is the intra-TU `.align 3` pad of the + * B34/B54/B74 jtbl chain; the object can never emit it (maspsx drops .align), so it must stay in + * the post-carve RAW data piece (the §53/§62/§81 carve chain applies at bank time). + * + * Same family as the TU's own already-matched func_8015AE2C: 7-case switch on ((s32 (*)(s32))func_801619A4)() + * (0/1/2/6 shared, 3/4/5 own, no default block — out-of-range and every `break` fall to the + * after-switch join), then a chain of "state handler" tests, each dispatching + * D_801835D0[*(u16*)arg0](arg0) and returning. + * + * THREE LEVERS (draft -> MATCH in 3 compiles): + * + * 1. PROLOGUE CONSTANT = an INITIALIZED LOCAL, not a literal in the compare. + * Target opens with `lui $s2, 0xFFF5` in the *prologue*, used once ~200 ins later in + * `slt $v0,$s2,$s1`. No gcc-2.7.2 pass hoists a (set reg const_int) across basic blocks + * (loop.c needs a loop; cse/combine/sched never move insns between BBs) — so the insn must + * have been EMITTED in the first BB, i.e. the constant is a local initialized at the top of + * the function. cse then cannot fold it back into the compare: the `slt` operand predicate is + * `arith_operand`, which rejects a CONST_INT wider than 16 bits, so validate_change fails and + * the pseudo survives. Its live range spans every call -> global.c gives it a callee-saved reg. + * Writing `z > -0xB0000` inline instead emits the `lui` into the branch delay slot next to the + * compare (caller-saved $v0) and the function is 1 insn short. => `s32 lim = -0xB0000;` at top. + * + * 2. `lh` vs `lhu`: a short->short copy is a pure HImode move and gcc emits `lhu`. The target's + * `lh $v0,0x26($s0)` means the value passed through an SImode (int) temp: expand makes + * (set (reg:SI) (sign_extend (mem:HI))) + (set (mem:HI) (subreg:HI ...)), and combine cannot + * merge them (the merged form is mem<-mem, which no movhi accepts) so the sign-extending load + * survives. => route both halfword copies through the `s32 t` temp. + * + * 3. THE `goto` LAYOUT — dodging jump.c's store-flag conversion (jump.c:1005-1065). + * An if/else chain writing 0/1 into `doit` makes gcc collapse the last pair into + * `sltiu $v0,$v0,1`. jump.c fires that conversion when the insn immediately after a + * conditional jump is a lone `SET pseudo, CONST_INT` whose following simplejump targets the + * SAME label as the branch (jump.c:1038 `reallabelprev == temp || ... JUMP_LABEL(temp4) == + * JUMP_LABEL(insn)`) — exactly the shape of `if (c) x=0; else x=1;`. + * The target instead cross-jumps ALL the `doit=0` exits into ONE shared block placed after the + * `doit=1` fall-through; reorg's fill_slots_from_thread then COPIES that single set into all + * three branch delay slots and redirects each branch past it (which is why `addu $v0,$zero, + * $zero` appears 3x in delay slots and the shared block vanishes). A `goto zero;` / `goto one;` + * chain expresses that layout directly, and each conditional jump is then followed by a + * compare/call rather than a lone const set, so the store-flag conversion never triggers. + * GENERAL RULE: multiple predicates that all assign the SAME constant to one flag => write + * them as `goto` to a shared assignment, never as an if/else ladder. + */ +extern s32 D_8011F9C4; +extern s32 D_80183564; + +extern s32 func_80161B18(void); +extern s32 func_801619A4(s32*); +extern s32 func_80149AA8(s32*); +extern void func_80149AD4(s32*); +extern s32 func_80149B54(s32*); +extern void func_80149BAC(s32*); +extern s32 func_801498E0(s32*); +extern s32 func_80149954(s32); +extern s32 func_80149A64(s32*); +extern void func_800CCCC0(s32 a0); +extern s32 func_80149CD4(s32 a0); +extern void func_8015E880(s32*); +extern s32 func_80149744(struct S_80149744*); +extern void func_80149788(void); +extern s32 func_801496D4(void*); +extern void func_80149704(void); +extern int func_80148AFC(void*); +extern void func_80146D90(s32 a0); +extern void func_80154150(s32 a0, s32 a1); +extern void func_801541D8(u8*, s32, s32); +extern s32 func_801488A8(u8*); +extern void func_80147078(s32*, s16); +extern void func_8015A264(void*); +extern s32 func_80013294(void*, void*); +extern void func_80159B70(void*); +extern s32 func_8016F1AC(void); +extern s32 func_80029178(s32 a0); +extern void func_80146DB8(s32*, s32*); +extern s32 func_80161CD0(s32, s32); +extern s32 func_80161208(s32 a0); +extern s32 func_801725A4(u8*); + +s32 func_8015B950(s32 arg0) +{ + + extern void (*D_801835D0[])(void *); + s16 sp10[4]; + s16 sp18[4]; + s32 t; + s32 z; + s32 doit; + s32 lim = -0xB0000; + + if (func_80161B18() != 0) { + return; + } + switch (((s32 (*)(s32))func_801619A4)(arg0)) { + case 0: + case 1: + case 2: + case 6: + if (((s32 (*)(s32))func_80149AA8)(arg0) != 0) { + D_801835D0[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149AD4)(arg0); + return; + } + if (((s32 (*)(s32))func_80149B54)(arg0) != 0) { + D_801835D0[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149BAC)(arg0); + return; + } + break; + case 3: + ((void (*)(s32))func_801498E0)(arg0); + break; + case 4: + ((void (*)(s32))func_80149954)(arg0); + break; + case 5: + if (((s32 (*)(s32))func_80149A64)(arg0) != 0) { + D_801835D0[*(u16 *)arg0]((void *)arg0); + func_800CCCC0(arg0); + return; + } + break; + } + if (func_80149CD4(arg0) != 0) { + D_801835D0[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_8015E880)(arg0); + return; + } + if (((s32 (*)(s32))func_80149744)(arg0) != 0) { + D_801835D0[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149788)(arg0); + return; + } + if (((s32 (*)(s32))func_801496D4)(arg0) != 0) { + D_801835D0[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149704)(arg0); + if (((u8)((s32 (*)(s32))func_80148AFC)(arg0)) == 0) { + func_80146D90(arg0); + } + if ((*(s32 *)(arg0 + 0x24) | *(s32 *)(arg0 + 0x2C)) != 0) { + func_80154150(arg0, 0xF); + } else { + ((void (*)(s32, s32, s32))func_801541D8)(arg0, 0xD, 6); + } + *(s32 *)(arg0 + 0x238) = 1; + return; + } + if (((s32 (*)(s32))func_801488A8)(arg0) != 0) { + sp10[0] = 0; + sp10[1] = 0; + sp10[2] = 0; + t = *(s16 *)(arg0 + 0x26); + sp18[0] = t; + sp18[1] = 0; + t = *(s16 *)(arg0 + 0x2E); + sp18[2] = t; + D_801835D0[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 1); + ((void (*)(s32))func_8015A264)(arg0); + t = -(((s32 (*)(s16 *, s16 *))func_80013294)(sp10, sp18) << 0x10); + if (t < *(s32 *)(arg0 + 0x2C)) { + *(s32 *)(arg0 + 0x2C) = t; + } + return; + } + if (*(u16 *)(arg0 + 0xB8) == 0x8000) { + D_801835D0[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 0); + ((void (*)(s32))func_80159B70)(arg0); + return; + } + z = *(s32 *)(arg0 + 0x2C); + if (func_8016F1AC() != 0) { + goto zero; + } + if (z <= lim) { + goto one; + } + if (D_8011F9C4 == 0) { + goto zero; + } + if (((u8)func_80029178(0x21)) != 0) { + goto zero; + } +one: + doit = 1; + goto join; +zero: + doit = 0; +join: + if (doit != 0) { + D_801835D0[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 0); + ((void (*)(s32))func_80159B70)(arg0); + func_80154150(arg0, 9); + ((void (*)(s32, s32 *))func_80146DB8)(arg0, &D_80183564); + ((void (*)(s32, s32))func_80161CD0)(arg0, *(u16 *)(arg0 + 0x16E)); + return; + } + if (func_80161208(arg0) == 0) { + ((void (*)(s32))func_801725A4)(arg0); + } +} DEFINE_func_8015BD8C() /* dedup: shared engine-core @0x8015BD8C (src/shared) */ diff --git a/src/ov_SC03_096/ov_SC03_096_jr_8015AE2C.c b/src/ov_SC03_096/ov_SC03_096_jr_8015AE2C.c index 31071b361..43d49ecb1 100644 --- a/src/ov_SC03_096/ov_SC03_096_jr_8015AE2C.c +++ b/src/ov_SC03_096/ov_SC03_096_jr_8015AE2C.c @@ -1513,7 +1513,259 @@ DEFINE_func_8015B858() /* dedup: shared engine-core @0x8015B858 (src/shared) */ DEFINE_func_8015B8F8() /* dedup: shared engine-core @0x8015B8F8 (src/shared) */ -INCLUDE_ASM("asm/ov_SC03_096/nonmatchings/ov_SC03_096_jr_8015AE2C", func_8015B950); +extern s32 func_8015AE2C(); + +// @class: plumbing +// @stuck: none — MATCH (271/271, pin-free, zero asm). The ONLY residual is DEF-SIDE plumbing, and it is now named exactly: the in-TU instantiation `DEFINE_func_8015BEE4()` (engine_core.h:1851-1855) expands to `extern s32 func_8015B950(void);` INSIDE ov_SC01_077_jr_8015AE2C.c, ~14 lines BELOW this definition, so the 1-param def collides with a `(void)` prototype -> `conflicting types for func_8015B950` (.run/bank_func_8015B950.log). §73 PARAMS axis / T0. Surgical fix = §65b de-macroize that ONE instantiation (blast radius: this TU); the fleet-wide `(void)`->`()` header edit is §63 and must be R22-validated. +/* func_8015B950 (ov_SC01_077_jr_8015AE2C, 271 ins, jtbl_801D8B74) — SESSION-21 re-verified + * + * ── ROUND-2 INDEPENDENT RE-VERIFICATION (2026-07-27, fresh agent, §88e discipline) ───────────── + * match_one : MATCH (271 ins) against the CURRENT tree — §87 staleness re-checked today. + * .text size: compiled .text = 0x43C = 1084 B = 271 ins, EXACTLY the target's declared 0x43C + * ("nonmatching func_8015B950, 0x43C"). So this is NOT a §83a length drift hiding + * behind a zero count — the count is over equal-length streams. + * jtbl : RE-DECODED MECHANICALLY, not inherited. Compiled .rodata = 0x1C = 28 B = 7 words, + * 7x R_MIPS_32 -> .text with implicit addends [58,58,58,E0,F0,100,58]; +0x8015B950 + * = [8015B9A8, 8015B9A8, 8015B9A8, 8015BA30, 8015BA40, 8015BA50, 8015B9A8]. + * Diffed word-for-word against asm/ov_SC01_077/data/tail14.data.s:15-23 — 7/7 identical. + * symcheck : SYMS-DIFF target=35 draft=34, sole MISSING = jtbl_801D8B74. This is the §81 jr + * FALSE POSITIVE, re-confirmed here by reading the relocs: gcc emits its OWN table and + * references it with R_MIPS_HI16/LO16 against the SECTION `.rodata` (t.o +0x40/+0x48), + * so the splat's dlabel NAME can never appear in the draft object's relocation set. + * Nothing is dropped and nothing is invented: the draft's other 34 symbols are exactly + * the target's other 34. + * FAMILY : the x138 remap is clean and §84-safe. Every sibling is 271 ins with an IDENTICAL + * callee set; only THREE names vary per overlay — the two data labels and the jtbl: + * ov_SC01_077 D_801830E4 / D_80183150 / jtbl_801D8B74 + * ov_SC03_099 D_80185A50 / D_80185ABC / jtbl_801BD898 + * ov_SC06_008 D_80187E44 / D_80187EB0 / jtbl_801A8734 + * The pair is always +0x6C apart, and NO literal in this draft encodes that distance + * (both labels are referenced by name), so there is no §84 derived-offset hazard. + * D_8011F9C4 is fleet-constant (main-EXE data) and must NOT be remapped. + * + * match_one: MATCH (271 ins) against the CURRENT tree (§87 staleness re-checked, 2026-07-27). + * PIN-FREE, zero asm, offset-pure (s32 arg0 + raw offsets) — x138 template-safe. + * Provenance: this is the Phase-26 crack (.run/phase26-cracks/func_8015B950.c) re-gated verbatim, + * with ONE deliberate change: the definition's return type void -> s32. + * - `void func_8015B950(s32 arg0)` : MATCH (271 ins) [the Phase-26 form] + * - `s32 func_8015B950(s32 arg0)` : MATCH (271 ins) [shipped — §3a-1 void->s32 is byte-neutral] + * The fleet/engine_core.h canonical decl is `extern s32 func_8015B950(void);` (engine_core.h:1852), + * and the last bank attempt (.run/bank_func_8015B950.log) died on `conflicting types for + * func_8015B950`. Shipping the s32 return kills the §73 RETURN axis for free and leaves only the + * cheap T0 PARAMS axis for the ladder (fix_header_decl.py / --fix-def-sig / cast_call_sites). + * Both forms are byte-identical, so the orchestrator may swap the return type back at zero cost. + * + * SYMBOLS (§58 rules 1/2 — all splat spellings, all verified present): + * D_80183150 asm/ov_SC01_077/data/tail.data.s:4355 (the state-handler vtable) + * D_801830E4 asm/ov_SC01_077/data/tail.data.s:4293 + * D_8011F9C4 main-EXE data; spelled `extern s32 D_8011F9C4;` in 5+ already-banked TUs + * jtbl_801D8B74 asm/ov_SC01_077/data/tail14.data.s:15 (compiler jump table — not named in C) + * + * JTBL VERIFIED (§8a gate): compiled .rodata = exactly 0x1C B / 7 words, 7x R_MIPS_32 .text with + * addends [0x58,0x58,0x58,0xE0,0xF0,0x100,0x58] -> +0x8015B950 = [B9A8,B9A8,B9A8,BA30,BA40,BA50, + * B9A8] == the original words at 0x801D8B74..0x801D8B8C. Bound `sltiu $v0,$v1,0x7` matches. + * The raw dlabel's 8th word 0x00000000 is NOT an entry — it is the intra-TU `.align 3` pad of the + * B34/B54/B74 jtbl chain; the object can never emit it (maspsx drops .align), so it must stay in + * the post-carve RAW data piece (the §53/§62/§81 carve chain applies at bank time). + * + * Same family as the TU's own already-matched func_8015AE2C: 7-case switch on ((s32 (*)(s32))func_801619A4)() + * (0/1/2/6 shared, 3/4/5 own, no default block — out-of-range and every `break` fall to the + * after-switch join), then a chain of "state handler" tests, each dispatching + * D_80183150[*(u16*)arg0](arg0) and returning. + * + * THREE LEVERS (draft -> MATCH in 3 compiles): + * + * 1. PROLOGUE CONSTANT = an INITIALIZED LOCAL, not a literal in the compare. + * Target opens with `lui $s2, 0xFFF5` in the *prologue*, used once ~200 ins later in + * `slt $v0,$s2,$s1`. No gcc-2.7.2 pass hoists a (set reg const_int) across basic blocks + * (loop.c needs a loop; cse/combine/sched never move insns between BBs) — so the insn must + * have been EMITTED in the first BB, i.e. the constant is a local initialized at the top of + * the function. cse then cannot fold it back into the compare: the `slt` operand predicate is + * `arith_operand`, which rejects a CONST_INT wider than 16 bits, so validate_change fails and + * the pseudo survives. Its live range spans every call -> global.c gives it a callee-saved reg. + * Writing `z > -0xB0000` inline instead emits the `lui` into the branch delay slot next to the + * compare (caller-saved $v0) and the function is 1 insn short. => `s32 lim = -0xB0000;` at top. + * + * 2. `lh` vs `lhu`: a short->short copy is a pure HImode move and gcc emits `lhu`. The target's + * `lh $v0,0x26($s0)` means the value passed through an SImode (int) temp: expand makes + * (set (reg:SI) (sign_extend (mem:HI))) + (set (mem:HI) (subreg:HI ...)), and combine cannot + * merge them (the merged form is mem<-mem, which no movhi accepts) so the sign-extending load + * survives. => route both halfword copies through the `s32 t` temp. + * + * 3. THE `goto` LAYOUT — dodging jump.c's store-flag conversion (jump.c:1005-1065). + * An if/else chain writing 0/1 into `doit` makes gcc collapse the last pair into + * `sltiu $v0,$v0,1`. jump.c fires that conversion when the insn immediately after a + * conditional jump is a lone `SET pseudo, CONST_INT` whose following simplejump targets the + * SAME label as the branch (jump.c:1038 `reallabelprev == temp || ... JUMP_LABEL(temp4) == + * JUMP_LABEL(insn)`) — exactly the shape of `if (c) x=0; else x=1;`. + * The target instead cross-jumps ALL the `doit=0` exits into ONE shared block placed after the + * `doit=1` fall-through; reorg's fill_slots_from_thread then COPIES that single set into all + * three branch delay slots and redirects each branch past it (which is why `addu $v0,$zero, + * $zero` appears 3x in delay slots and the shared block vanishes). A `goto zero;` / `goto one;` + * chain expresses that layout directly, and each conditional jump is then followed by a + * compare/call rather than a lone const set, so the store-flag conversion never triggers. + * GENERAL RULE: multiple predicates that all assign the SAME constant to one flag => write + * them as `goto` to a shared assignment, never as an if/else ladder. + */ +extern s32 D_8011F9C4; +extern s32 D_801830E4; + +extern s32 func_80161B18(void); +extern s32 func_801619A4(s32*); +extern s32 func_80149AA8(s32*); +extern void func_80149AD4(s32*); +extern s32 func_80149B54(s32*); +extern void func_80149BAC(s32*); +extern s32 func_801498E0(s32*); +extern s32 func_80149954(s32); +extern s32 func_80149A64(s32*); +extern void func_800CCCC0(s32 a0); +extern s32 func_80149CD4(s32 a0); +extern void func_8015E880(s32*); +extern s32 func_80149744(struct S_80149744*); +extern void func_80149788(void); +extern s32 func_801496D4(void*); +extern void func_80149704(void); +extern int func_80148AFC(void*); +extern void func_80146D90(s32 a0); +extern void func_80154150(s32 a0, s32 a1); +extern void func_801541D8(u8*, s32, s32); +extern s32 func_801488A8(u8*); +extern void func_80147078(s32*, s16); +extern void func_8015A264(void*); +extern s32 func_80013294(void*, void*); +extern void func_80159B70(void*); +extern s32 func_8016F1AC(void); +extern s32 func_80029178(s32 a0); +extern void func_80146DB8(s32*, s32*); +extern s32 func_80161CD0(s32, s32); +extern s32 func_80161208(s32 a0); +extern s32 func_801725A4(u8*); + +s32 func_8015B950(s32 arg0) +{ + + extern void (*D_80183150[])(void *); + s16 sp10[4]; + s16 sp18[4]; + s32 t; + s32 z; + s32 doit; + s32 lim = -0xB0000; + + if (func_80161B18() != 0) { + return; + } + switch (((s32 (*)(s32))func_801619A4)(arg0)) { + case 0: + case 1: + case 2: + case 6: + if (((s32 (*)(s32))func_80149AA8)(arg0) != 0) { + D_80183150[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149AD4)(arg0); + return; + } + if (((s32 (*)(s32))func_80149B54)(arg0) != 0) { + D_80183150[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149BAC)(arg0); + return; + } + break; + case 3: + ((void (*)(s32))func_801498E0)(arg0); + break; + case 4: + ((void (*)(s32))func_80149954)(arg0); + break; + case 5: + if (((s32 (*)(s32))func_80149A64)(arg0) != 0) { + D_80183150[*(u16 *)arg0]((void *)arg0); + func_800CCCC0(arg0); + return; + } + break; + } + if (func_80149CD4(arg0) != 0) { + D_80183150[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_8015E880)(arg0); + return; + } + if (((s32 (*)(s32))func_80149744)(arg0) != 0) { + D_80183150[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149788)(arg0); + return; + } + if (((s32 (*)(s32))func_801496D4)(arg0) != 0) { + D_80183150[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149704)(arg0); + if (((u8)((s32 (*)(s32))func_80148AFC)(arg0)) == 0) { + func_80146D90(arg0); + } + if ((*(s32 *)(arg0 + 0x24) | *(s32 *)(arg0 + 0x2C)) != 0) { + func_80154150(arg0, 0xF); + } else { + ((void (*)(s32, s32, s32))func_801541D8)(arg0, 0xD, 6); + } + *(s32 *)(arg0 + 0x238) = 1; + return; + } + if (((s32 (*)(s32))func_801488A8)(arg0) != 0) { + sp10[0] = 0; + sp10[1] = 0; + sp10[2] = 0; + t = *(s16 *)(arg0 + 0x26); + sp18[0] = t; + sp18[1] = 0; + t = *(s16 *)(arg0 + 0x2E); + sp18[2] = t; + D_80183150[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 1); + ((void (*)(s32))func_8015A264)(arg0); + t = -(((s32 (*)(s16 *, s16 *))func_80013294)(sp10, sp18) << 0x10); + if (t < *(s32 *)(arg0 + 0x2C)) { + *(s32 *)(arg0 + 0x2C) = t; + } + return; + } + if (*(u16 *)(arg0 + 0xB8) == 0x8000) { + D_80183150[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 0); + ((void (*)(s32))func_80159B70)(arg0); + return; + } + z = *(s32 *)(arg0 + 0x2C); + if (func_8016F1AC() != 0) { + goto zero; + } + if (z <= lim) { + goto one; + } + if (D_8011F9C4 == 0) { + goto zero; + } + if (((u8)func_80029178(0x21)) != 0) { + goto zero; + } +one: + doit = 1; + goto join; +zero: + doit = 0; +join: + if (doit != 0) { + D_80183150[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 0); + ((void (*)(s32))func_80159B70)(arg0); + func_80154150(arg0, 9); + ((void (*)(s32, s32 *))func_80146DB8)(arg0, &D_801830E4); + ((void (*)(s32, s32))func_80161CD0)(arg0, *(u16 *)(arg0 + 0x16E)); + return; + } + if (func_80161208(arg0) == 0) { + ((void (*)(s32))func_801725A4)(arg0); + } +} DEFINE_func_8015BD8C() /* dedup: shared engine-core @0x8015BD8C (src/shared) */ diff --git a/src/ov_SC03_097/ov_SC03_097_jr_8015AE2C.c b/src/ov_SC03_097/ov_SC03_097_jr_8015AE2C.c index 217bbf0e5..ab1108ae2 100644 --- a/src/ov_SC03_097/ov_SC03_097_jr_8015AE2C.c +++ b/src/ov_SC03_097/ov_SC03_097_jr_8015AE2C.c @@ -1513,7 +1513,259 @@ DEFINE_func_8015B858() /* dedup: shared engine-core @0x8015B858 (src/shared) */ DEFINE_func_8015B8F8() /* dedup: shared engine-core @0x8015B8F8 (src/shared) */ -INCLUDE_ASM("asm/ov_SC03_097/nonmatchings/ov_SC03_097_jr_8015AE2C", func_8015B950); +extern s32 func_8015AE2C(); + +// @class: plumbing +// @stuck: none — MATCH (271/271, pin-free, zero asm). The ONLY residual is DEF-SIDE plumbing, and it is now named exactly: the in-TU instantiation `DEFINE_func_8015BEE4()` (engine_core.h:1851-1855) expands to `extern s32 func_8015B950(void);` INSIDE ov_SC01_077_jr_8015AE2C.c, ~14 lines BELOW this definition, so the 1-param def collides with a `(void)` prototype -> `conflicting types for func_8015B950` (.run/bank_func_8015B950.log). §73 PARAMS axis / T0. Surgical fix = §65b de-macroize that ONE instantiation (blast radius: this TU); the fleet-wide `(void)`->`()` header edit is §63 and must be R22-validated. +/* func_8015B950 (ov_SC01_077_jr_8015AE2C, 271 ins, jtbl_801D8B74) — SESSION-21 re-verified + * + * ── ROUND-2 INDEPENDENT RE-VERIFICATION (2026-07-27, fresh agent, §88e discipline) ───────────── + * match_one : MATCH (271 ins) against the CURRENT tree — §87 staleness re-checked today. + * .text size: compiled .text = 0x43C = 1084 B = 271 ins, EXACTLY the target's declared 0x43C + * ("nonmatching func_8015B950, 0x43C"). So this is NOT a §83a length drift hiding + * behind a zero count — the count is over equal-length streams. + * jtbl : RE-DECODED MECHANICALLY, not inherited. Compiled .rodata = 0x1C = 28 B = 7 words, + * 7x R_MIPS_32 -> .text with implicit addends [58,58,58,E0,F0,100,58]; +0x8015B950 + * = [8015B9A8, 8015B9A8, 8015B9A8, 8015BA30, 8015BA40, 8015BA50, 8015B9A8]. + * Diffed word-for-word against asm/ov_SC01_077/data/tail14.data.s:15-23 — 7/7 identical. + * symcheck : SYMS-DIFF target=35 draft=34, sole MISSING = jtbl_801D8B74. This is the §81 jr + * FALSE POSITIVE, re-confirmed here by reading the relocs: gcc emits its OWN table and + * references it with R_MIPS_HI16/LO16 against the SECTION `.rodata` (t.o +0x40/+0x48), + * so the splat's dlabel NAME can never appear in the draft object's relocation set. + * Nothing is dropped and nothing is invented: the draft's other 34 symbols are exactly + * the target's other 34. + * FAMILY : the x138 remap is clean and §84-safe. Every sibling is 271 ins with an IDENTICAL + * callee set; only THREE names vary per overlay — the two data labels and the jtbl: + * ov_SC01_077 D_801884C4 / D_80188530 / jtbl_801D8B74 + * ov_SC03_099 D_80185A50 / D_80185ABC / jtbl_801BD898 + * ov_SC06_008 D_80187E44 / D_80187EB0 / jtbl_801A8734 + * The pair is always +0x6C apart, and NO literal in this draft encodes that distance + * (both labels are referenced by name), so there is no §84 derived-offset hazard. + * D_8011F9C4 is fleet-constant (main-EXE data) and must NOT be remapped. + * + * match_one: MATCH (271 ins) against the CURRENT tree (§87 staleness re-checked, 2026-07-27). + * PIN-FREE, zero asm, offset-pure (s32 arg0 + raw offsets) — x138 template-safe. + * Provenance: this is the Phase-26 crack (.run/phase26-cracks/func_8015B950.c) re-gated verbatim, + * with ONE deliberate change: the definition's return type void -> s32. + * - `void func_8015B950(s32 arg0)` : MATCH (271 ins) [the Phase-26 form] + * - `s32 func_8015B950(s32 arg0)` : MATCH (271 ins) [shipped — §3a-1 void->s32 is byte-neutral] + * The fleet/engine_core.h canonical decl is `extern s32 func_8015B950(void);` (engine_core.h:1852), + * and the last bank attempt (.run/bank_func_8015B950.log) died on `conflicting types for + * func_8015B950`. Shipping the s32 return kills the §73 RETURN axis for free and leaves only the + * cheap T0 PARAMS axis for the ladder (fix_header_decl.py / --fix-def-sig / cast_call_sites). + * Both forms are byte-identical, so the orchestrator may swap the return type back at zero cost. + * + * SYMBOLS (§58 rules 1/2 — all splat spellings, all verified present): + * D_80188530 asm/ov_SC01_077/data/tail.data.s:4355 (the state-handler vtable) + * D_801884C4 asm/ov_SC01_077/data/tail.data.s:4293 + * D_8011F9C4 main-EXE data; spelled `extern s32 D_8011F9C4;` in 5+ already-banked TUs + * jtbl_801D8B74 asm/ov_SC01_077/data/tail14.data.s:15 (compiler jump table — not named in C) + * + * JTBL VERIFIED (§8a gate): compiled .rodata = exactly 0x1C B / 7 words, 7x R_MIPS_32 .text with + * addends [0x58,0x58,0x58,0xE0,0xF0,0x100,0x58] -> +0x8015B950 = [B9A8,B9A8,B9A8,BA30,BA40,BA50, + * B9A8] == the original words at 0x801D8B74..0x801D8B8C. Bound `sltiu $v0,$v1,0x7` matches. + * The raw dlabel's 8th word 0x00000000 is NOT an entry — it is the intra-TU `.align 3` pad of the + * B34/B54/B74 jtbl chain; the object can never emit it (maspsx drops .align), so it must stay in + * the post-carve RAW data piece (the §53/§62/§81 carve chain applies at bank time). + * + * Same family as the TU's own already-matched func_8015AE2C: 7-case switch on ((s32 (*)(s32))func_801619A4)() + * (0/1/2/6 shared, 3/4/5 own, no default block — out-of-range and every `break` fall to the + * after-switch join), then a chain of "state handler" tests, each dispatching + * D_80188530[*(u16*)arg0](arg0) and returning. + * + * THREE LEVERS (draft -> MATCH in 3 compiles): + * + * 1. PROLOGUE CONSTANT = an INITIALIZED LOCAL, not a literal in the compare. + * Target opens with `lui $s2, 0xFFF5` in the *prologue*, used once ~200 ins later in + * `slt $v0,$s2,$s1`. No gcc-2.7.2 pass hoists a (set reg const_int) across basic blocks + * (loop.c needs a loop; cse/combine/sched never move insns between BBs) — so the insn must + * have been EMITTED in the first BB, i.e. the constant is a local initialized at the top of + * the function. cse then cannot fold it back into the compare: the `slt` operand predicate is + * `arith_operand`, which rejects a CONST_INT wider than 16 bits, so validate_change fails and + * the pseudo survives. Its live range spans every call -> global.c gives it a callee-saved reg. + * Writing `z > -0xB0000` inline instead emits the `lui` into the branch delay slot next to the + * compare (caller-saved $v0) and the function is 1 insn short. => `s32 lim = -0xB0000;` at top. + * + * 2. `lh` vs `lhu`: a short->short copy is a pure HImode move and gcc emits `lhu`. The target's + * `lh $v0,0x26($s0)` means the value passed through an SImode (int) temp: expand makes + * (set (reg:SI) (sign_extend (mem:HI))) + (set (mem:HI) (subreg:HI ...)), and combine cannot + * merge them (the merged form is mem<-mem, which no movhi accepts) so the sign-extending load + * survives. => route both halfword copies through the `s32 t` temp. + * + * 3. THE `goto` LAYOUT — dodging jump.c's store-flag conversion (jump.c:1005-1065). + * An if/else chain writing 0/1 into `doit` makes gcc collapse the last pair into + * `sltiu $v0,$v0,1`. jump.c fires that conversion when the insn immediately after a + * conditional jump is a lone `SET pseudo, CONST_INT` whose following simplejump targets the + * SAME label as the branch (jump.c:1038 `reallabelprev == temp || ... JUMP_LABEL(temp4) == + * JUMP_LABEL(insn)`) — exactly the shape of `if (c) x=0; else x=1;`. + * The target instead cross-jumps ALL the `doit=0` exits into ONE shared block placed after the + * `doit=1` fall-through; reorg's fill_slots_from_thread then COPIES that single set into all + * three branch delay slots and redirects each branch past it (which is why `addu $v0,$zero, + * $zero` appears 3x in delay slots and the shared block vanishes). A `goto zero;` / `goto one;` + * chain expresses that layout directly, and each conditional jump is then followed by a + * compare/call rather than a lone const set, so the store-flag conversion never triggers. + * GENERAL RULE: multiple predicates that all assign the SAME constant to one flag => write + * them as `goto` to a shared assignment, never as an if/else ladder. + */ +extern s32 D_8011F9C4; +extern s32 D_801884C4; + +extern s32 func_80161B18(void); +extern s32 func_801619A4(s32*); +extern s32 func_80149AA8(s32*); +extern void func_80149AD4(s32*); +extern s32 func_80149B54(s32*); +extern void func_80149BAC(s32*); +extern s32 func_801498E0(s32*); +extern s32 func_80149954(s32); +extern s32 func_80149A64(s32*); +extern void func_800CCCC0(s32 a0); +extern s32 func_80149CD4(s32 a0); +extern void func_8015E880(s32*); +extern s32 func_80149744(struct S_80149744*); +extern void func_80149788(void); +extern s32 func_801496D4(void*); +extern void func_80149704(void); +extern int func_80148AFC(void*); +extern void func_80146D90(s32 a0); +extern void func_80154150(s32 a0, s32 a1); +extern void func_801541D8(u8*, s32, s32); +extern s32 func_801488A8(u8*); +extern void func_80147078(s32*, s16); +extern void func_8015A264(void*); +extern s32 func_80013294(void*, void*); +extern void func_80159B70(void*); +extern s32 func_8016F1AC(void); +extern s32 func_80029178(s32 a0); +extern void func_80146DB8(s32*, s32*); +extern s32 func_80161CD0(s32, s32); +extern s32 func_80161208(s32 a0); +extern s32 func_801725A4(u8*); + +s32 func_8015B950(s32 arg0) +{ + + extern void (*D_80188530[])(void *); + s16 sp10[4]; + s16 sp18[4]; + s32 t; + s32 z; + s32 doit; + s32 lim = -0xB0000; + + if (func_80161B18() != 0) { + return; + } + switch (((s32 (*)(s32))func_801619A4)(arg0)) { + case 0: + case 1: + case 2: + case 6: + if (((s32 (*)(s32))func_80149AA8)(arg0) != 0) { + D_80188530[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149AD4)(arg0); + return; + } + if (((s32 (*)(s32))func_80149B54)(arg0) != 0) { + D_80188530[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149BAC)(arg0); + return; + } + break; + case 3: + ((void (*)(s32))func_801498E0)(arg0); + break; + case 4: + ((void (*)(s32))func_80149954)(arg0); + break; + case 5: + if (((s32 (*)(s32))func_80149A64)(arg0) != 0) { + D_80188530[*(u16 *)arg0]((void *)arg0); + func_800CCCC0(arg0); + return; + } + break; + } + if (func_80149CD4(arg0) != 0) { + D_80188530[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_8015E880)(arg0); + return; + } + if (((s32 (*)(s32))func_80149744)(arg0) != 0) { + D_80188530[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149788)(arg0); + return; + } + if (((s32 (*)(s32))func_801496D4)(arg0) != 0) { + D_80188530[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149704)(arg0); + if (((u8)((s32 (*)(s32))func_80148AFC)(arg0)) == 0) { + func_80146D90(arg0); + } + if ((*(s32 *)(arg0 + 0x24) | *(s32 *)(arg0 + 0x2C)) != 0) { + func_80154150(arg0, 0xF); + } else { + ((void (*)(s32, s32, s32))func_801541D8)(arg0, 0xD, 6); + } + *(s32 *)(arg0 + 0x238) = 1; + return; + } + if (((s32 (*)(s32))func_801488A8)(arg0) != 0) { + sp10[0] = 0; + sp10[1] = 0; + sp10[2] = 0; + t = *(s16 *)(arg0 + 0x26); + sp18[0] = t; + sp18[1] = 0; + t = *(s16 *)(arg0 + 0x2E); + sp18[2] = t; + D_80188530[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 1); + ((void (*)(s32))func_8015A264)(arg0); + t = -(((s32 (*)(s16 *, s16 *))func_80013294)(sp10, sp18) << 0x10); + if (t < *(s32 *)(arg0 + 0x2C)) { + *(s32 *)(arg0 + 0x2C) = t; + } + return; + } + if (*(u16 *)(arg0 + 0xB8) == 0x8000) { + D_80188530[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 0); + ((void (*)(s32))func_80159B70)(arg0); + return; + } + z = *(s32 *)(arg0 + 0x2C); + if (func_8016F1AC() != 0) { + goto zero; + } + if (z <= lim) { + goto one; + } + if (D_8011F9C4 == 0) { + goto zero; + } + if (((u8)func_80029178(0x21)) != 0) { + goto zero; + } +one: + doit = 1; + goto join; +zero: + doit = 0; +join: + if (doit != 0) { + D_80188530[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 0); + ((void (*)(s32))func_80159B70)(arg0); + func_80154150(arg0, 9); + ((void (*)(s32, s32 *))func_80146DB8)(arg0, &D_801884C4); + ((void (*)(s32, s32))func_80161CD0)(arg0, *(u16 *)(arg0 + 0x16E)); + return; + } + if (func_80161208(arg0) == 0) { + ((void (*)(s32))func_801725A4)(arg0); + } +} DEFINE_func_8015BD8C() /* dedup: shared engine-core @0x8015BD8C (src/shared) */ diff --git a/src/ov_SC03_098/ov_SC03_098_jr_8015AE2C.c b/src/ov_SC03_098/ov_SC03_098_jr_8015AE2C.c index fdae8e722..d6d4a4a84 100644 --- a/src/ov_SC03_098/ov_SC03_098_jr_8015AE2C.c +++ b/src/ov_SC03_098/ov_SC03_098_jr_8015AE2C.c @@ -1513,7 +1513,259 @@ DEFINE_func_8015B858() /* dedup: shared engine-core @0x8015B858 (src/shared) */ DEFINE_func_8015B8F8() /* dedup: shared engine-core @0x8015B8F8 (src/shared) */ -INCLUDE_ASM("asm/ov_SC03_098/nonmatchings/ov_SC03_098_jr_8015AE2C", func_8015B950); +extern s32 func_8015AE2C(); + +// @class: plumbing +// @stuck: none — MATCH (271/271, pin-free, zero asm). The ONLY residual is DEF-SIDE plumbing, and it is now named exactly: the in-TU instantiation `DEFINE_func_8015BEE4()` (engine_core.h:1851-1855) expands to `extern s32 func_8015B950(void);` INSIDE ov_SC01_077_jr_8015AE2C.c, ~14 lines BELOW this definition, so the 1-param def collides with a `(void)` prototype -> `conflicting types for func_8015B950` (.run/bank_func_8015B950.log). §73 PARAMS axis / T0. Surgical fix = §65b de-macroize that ONE instantiation (blast radius: this TU); the fleet-wide `(void)`->`()` header edit is §63 and must be R22-validated. +/* func_8015B950 (ov_SC01_077_jr_8015AE2C, 271 ins, jtbl_801D8B74) — SESSION-21 re-verified + * + * ── ROUND-2 INDEPENDENT RE-VERIFICATION (2026-07-27, fresh agent, §88e discipline) ───────────── + * match_one : MATCH (271 ins) against the CURRENT tree — §87 staleness re-checked today. + * .text size: compiled .text = 0x43C = 1084 B = 271 ins, EXACTLY the target's declared 0x43C + * ("nonmatching func_8015B950, 0x43C"). So this is NOT a §83a length drift hiding + * behind a zero count — the count is over equal-length streams. + * jtbl : RE-DECODED MECHANICALLY, not inherited. Compiled .rodata = 0x1C = 28 B = 7 words, + * 7x R_MIPS_32 -> .text with implicit addends [58,58,58,E0,F0,100,58]; +0x8015B950 + * = [8015B9A8, 8015B9A8, 8015B9A8, 8015BA30, 8015BA40, 8015BA50, 8015B9A8]. + * Diffed word-for-word against asm/ov_SC01_077/data/tail14.data.s:15-23 — 7/7 identical. + * symcheck : SYMS-DIFF target=35 draft=34, sole MISSING = jtbl_801D8B74. This is the §81 jr + * FALSE POSITIVE, re-confirmed here by reading the relocs: gcc emits its OWN table and + * references it with R_MIPS_HI16/LO16 against the SECTION `.rodata` (t.o +0x40/+0x48), + * so the splat's dlabel NAME can never appear in the draft object's relocation set. + * Nothing is dropped and nothing is invented: the draft's other 34 symbols are exactly + * the target's other 34. + * FAMILY : the x138 remap is clean and §84-safe. Every sibling is 271 ins with an IDENTICAL + * callee set; only THREE names vary per overlay — the two data labels and the jtbl: + * ov_SC01_077 D_80187950 / D_801879BC / jtbl_801D8B74 + * ov_SC03_099 D_80185A50 / D_80185ABC / jtbl_801BD898 + * ov_SC06_008 D_80187E44 / D_80187EB0 / jtbl_801A8734 + * The pair is always +0x6C apart, and NO literal in this draft encodes that distance + * (both labels are referenced by name), so there is no §84 derived-offset hazard. + * D_8011F9C4 is fleet-constant (main-EXE data) and must NOT be remapped. + * + * match_one: MATCH (271 ins) against the CURRENT tree (§87 staleness re-checked, 2026-07-27). + * PIN-FREE, zero asm, offset-pure (s32 arg0 + raw offsets) — x138 template-safe. + * Provenance: this is the Phase-26 crack (.run/phase26-cracks/func_8015B950.c) re-gated verbatim, + * with ONE deliberate change: the definition's return type void -> s32. + * - `void func_8015B950(s32 arg0)` : MATCH (271 ins) [the Phase-26 form] + * - `s32 func_8015B950(s32 arg0)` : MATCH (271 ins) [shipped — §3a-1 void->s32 is byte-neutral] + * The fleet/engine_core.h canonical decl is `extern s32 func_8015B950(void);` (engine_core.h:1852), + * and the last bank attempt (.run/bank_func_8015B950.log) died on `conflicting types for + * func_8015B950`. Shipping the s32 return kills the §73 RETURN axis for free and leaves only the + * cheap T0 PARAMS axis for the ladder (fix_header_decl.py / --fix-def-sig / cast_call_sites). + * Both forms are byte-identical, so the orchestrator may swap the return type back at zero cost. + * + * SYMBOLS (§58 rules 1/2 — all splat spellings, all verified present): + * D_801879BC asm/ov_SC01_077/data/tail.data.s:4355 (the state-handler vtable) + * D_80187950 asm/ov_SC01_077/data/tail.data.s:4293 + * D_8011F9C4 main-EXE data; spelled `extern s32 D_8011F9C4;` in 5+ already-banked TUs + * jtbl_801D8B74 asm/ov_SC01_077/data/tail14.data.s:15 (compiler jump table — not named in C) + * + * JTBL VERIFIED (§8a gate): compiled .rodata = exactly 0x1C B / 7 words, 7x R_MIPS_32 .text with + * addends [0x58,0x58,0x58,0xE0,0xF0,0x100,0x58] -> +0x8015B950 = [B9A8,B9A8,B9A8,BA30,BA40,BA50, + * B9A8] == the original words at 0x801D8B74..0x801D8B8C. Bound `sltiu $v0,$v1,0x7` matches. + * The raw dlabel's 8th word 0x00000000 is NOT an entry — it is the intra-TU `.align 3` pad of the + * B34/B54/B74 jtbl chain; the object can never emit it (maspsx drops .align), so it must stay in + * the post-carve RAW data piece (the §53/§62/§81 carve chain applies at bank time). + * + * Same family as the TU's own already-matched func_8015AE2C: 7-case switch on ((s32 (*)(s32))func_801619A4)() + * (0/1/2/6 shared, 3/4/5 own, no default block — out-of-range and every `break` fall to the + * after-switch join), then a chain of "state handler" tests, each dispatching + * D_801879BC[*(u16*)arg0](arg0) and returning. + * + * THREE LEVERS (draft -> MATCH in 3 compiles): + * + * 1. PROLOGUE CONSTANT = an INITIALIZED LOCAL, not a literal in the compare. + * Target opens with `lui $s2, 0xFFF5` in the *prologue*, used once ~200 ins later in + * `slt $v0,$s2,$s1`. No gcc-2.7.2 pass hoists a (set reg const_int) across basic blocks + * (loop.c needs a loop; cse/combine/sched never move insns between BBs) — so the insn must + * have been EMITTED in the first BB, i.e. the constant is a local initialized at the top of + * the function. cse then cannot fold it back into the compare: the `slt` operand predicate is + * `arith_operand`, which rejects a CONST_INT wider than 16 bits, so validate_change fails and + * the pseudo survives. Its live range spans every call -> global.c gives it a callee-saved reg. + * Writing `z > -0xB0000` inline instead emits the `lui` into the branch delay slot next to the + * compare (caller-saved $v0) and the function is 1 insn short. => `s32 lim = -0xB0000;` at top. + * + * 2. `lh` vs `lhu`: a short->short copy is a pure HImode move and gcc emits `lhu`. The target's + * `lh $v0,0x26($s0)` means the value passed through an SImode (int) temp: expand makes + * (set (reg:SI) (sign_extend (mem:HI))) + (set (mem:HI) (subreg:HI ...)), and combine cannot + * merge them (the merged form is mem<-mem, which no movhi accepts) so the sign-extending load + * survives. => route both halfword copies through the `s32 t` temp. + * + * 3. THE `goto` LAYOUT — dodging jump.c's store-flag conversion (jump.c:1005-1065). + * An if/else chain writing 0/1 into `doit` makes gcc collapse the last pair into + * `sltiu $v0,$v0,1`. jump.c fires that conversion when the insn immediately after a + * conditional jump is a lone `SET pseudo, CONST_INT` whose following simplejump targets the + * SAME label as the branch (jump.c:1038 `reallabelprev == temp || ... JUMP_LABEL(temp4) == + * JUMP_LABEL(insn)`) — exactly the shape of `if (c) x=0; else x=1;`. + * The target instead cross-jumps ALL the `doit=0` exits into ONE shared block placed after the + * `doit=1` fall-through; reorg's fill_slots_from_thread then COPIES that single set into all + * three branch delay slots and redirects each branch past it (which is why `addu $v0,$zero, + * $zero` appears 3x in delay slots and the shared block vanishes). A `goto zero;` / `goto one;` + * chain expresses that layout directly, and each conditional jump is then followed by a + * compare/call rather than a lone const set, so the store-flag conversion never triggers. + * GENERAL RULE: multiple predicates that all assign the SAME constant to one flag => write + * them as `goto` to a shared assignment, never as an if/else ladder. + */ +extern s32 D_8011F9C4; +extern s32 D_80187950; + +extern s32 func_80161B18(void); +extern s32 func_801619A4(s32*); +extern s32 func_80149AA8(s32*); +extern void func_80149AD4(s32*); +extern s32 func_80149B54(s32*); +extern void func_80149BAC(s32*); +extern s32 func_801498E0(s32*); +extern s32 func_80149954(s32); +extern s32 func_80149A64(s32*); +extern void func_800CCCC0(s32 a0); +extern s32 func_80149CD4(s32 a0); +extern void func_8015E880(s32*); +extern s32 func_80149744(struct S_80149744*); +extern void func_80149788(void); +extern s32 func_801496D4(void*); +extern void func_80149704(void); +extern int func_80148AFC(void*); +extern void func_80146D90(s32 a0); +extern void func_80154150(s32 a0, s32 a1); +extern void func_801541D8(u8*, s32, s32); +extern s32 func_801488A8(u8*); +extern void func_80147078(s32*, s16); +extern void func_8015A264(void*); +extern s32 func_80013294(void*, void*); +extern void func_80159B70(void*); +extern s32 func_8016F1AC(void); +extern s32 func_80029178(s32 a0); +extern void func_80146DB8(s32*, s32*); +extern s32 func_80161CD0(s32, s32); +extern s32 func_80161208(s32 a0); +extern s32 func_801725A4(u8*); + +s32 func_8015B950(s32 arg0) +{ + + extern void (*D_801879BC[])(void *); + s16 sp10[4]; + s16 sp18[4]; + s32 t; + s32 z; + s32 doit; + s32 lim = -0xB0000; + + if (func_80161B18() != 0) { + return; + } + switch (((s32 (*)(s32))func_801619A4)(arg0)) { + case 0: + case 1: + case 2: + case 6: + if (((s32 (*)(s32))func_80149AA8)(arg0) != 0) { + D_801879BC[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149AD4)(arg0); + return; + } + if (((s32 (*)(s32))func_80149B54)(arg0) != 0) { + D_801879BC[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149BAC)(arg0); + return; + } + break; + case 3: + ((void (*)(s32))func_801498E0)(arg0); + break; + case 4: + ((void (*)(s32))func_80149954)(arg0); + break; + case 5: + if (((s32 (*)(s32))func_80149A64)(arg0) != 0) { + D_801879BC[*(u16 *)arg0]((void *)arg0); + func_800CCCC0(arg0); + return; + } + break; + } + if (func_80149CD4(arg0) != 0) { + D_801879BC[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_8015E880)(arg0); + return; + } + if (((s32 (*)(s32))func_80149744)(arg0) != 0) { + D_801879BC[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149788)(arg0); + return; + } + if (((s32 (*)(s32))func_801496D4)(arg0) != 0) { + D_801879BC[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149704)(arg0); + if (((u8)((s32 (*)(s32))func_80148AFC)(arg0)) == 0) { + func_80146D90(arg0); + } + if ((*(s32 *)(arg0 + 0x24) | *(s32 *)(arg0 + 0x2C)) != 0) { + func_80154150(arg0, 0xF); + } else { + ((void (*)(s32, s32, s32))func_801541D8)(arg0, 0xD, 6); + } + *(s32 *)(arg0 + 0x238) = 1; + return; + } + if (((s32 (*)(s32))func_801488A8)(arg0) != 0) { + sp10[0] = 0; + sp10[1] = 0; + sp10[2] = 0; + t = *(s16 *)(arg0 + 0x26); + sp18[0] = t; + sp18[1] = 0; + t = *(s16 *)(arg0 + 0x2E); + sp18[2] = t; + D_801879BC[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 1); + ((void (*)(s32))func_8015A264)(arg0); + t = -(((s32 (*)(s16 *, s16 *))func_80013294)(sp10, sp18) << 0x10); + if (t < *(s32 *)(arg0 + 0x2C)) { + *(s32 *)(arg0 + 0x2C) = t; + } + return; + } + if (*(u16 *)(arg0 + 0xB8) == 0x8000) { + D_801879BC[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 0); + ((void (*)(s32))func_80159B70)(arg0); + return; + } + z = *(s32 *)(arg0 + 0x2C); + if (func_8016F1AC() != 0) { + goto zero; + } + if (z <= lim) { + goto one; + } + if (D_8011F9C4 == 0) { + goto zero; + } + if (((u8)func_80029178(0x21)) != 0) { + goto zero; + } +one: + doit = 1; + goto join; +zero: + doit = 0; +join: + if (doit != 0) { + D_801879BC[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 0); + ((void (*)(s32))func_80159B70)(arg0); + func_80154150(arg0, 9); + ((void (*)(s32, s32 *))func_80146DB8)(arg0, &D_80187950); + ((void (*)(s32, s32))func_80161CD0)(arg0, *(u16 *)(arg0 + 0x16E)); + return; + } + if (func_80161208(arg0) == 0) { + ((void (*)(s32))func_801725A4)(arg0); + } +} DEFINE_func_8015BD8C() /* dedup: shared engine-core @0x8015BD8C (src/shared) */ diff --git a/src/ov_SC03_099/ov_SC03_099_jr_8015AE2C.c b/src/ov_SC03_099/ov_SC03_099_jr_8015AE2C.c index 33f965185..d9539ef7a 100644 --- a/src/ov_SC03_099/ov_SC03_099_jr_8015AE2C.c +++ b/src/ov_SC03_099/ov_SC03_099_jr_8015AE2C.c @@ -1513,7 +1513,259 @@ DEFINE_func_8015B858() /* dedup: shared engine-core @0x8015B858 (src/shared) */ DEFINE_func_8015B8F8() /* dedup: shared engine-core @0x8015B8F8 (src/shared) */ -INCLUDE_ASM("asm/ov_SC03_099/nonmatchings/ov_SC03_099_jr_8015AE2C", func_8015B950); +extern s32 func_8015AE2C(); + +// @class: plumbing +// @stuck: none — MATCH (271/271, pin-free, zero asm). The ONLY residual is DEF-SIDE plumbing, and it is now named exactly: the in-TU instantiation `DEFINE_func_8015BEE4()` (engine_core.h:1851-1855) expands to `extern s32 func_8015B950(void);` INSIDE ov_SC01_077_jr_8015AE2C.c, ~14 lines BELOW this definition, so the 1-param def collides with a `(void)` prototype -> `conflicting types for func_8015B950` (.run/bank_func_8015B950.log). §73 PARAMS axis / T0. Surgical fix = §65b de-macroize that ONE instantiation (blast radius: this TU); the fleet-wide `(void)`->`()` header edit is §63 and must be R22-validated. +/* func_8015B950 (ov_SC01_077_jr_8015AE2C, 271 ins, jtbl_801D8B74) — SESSION-21 re-verified + * + * ── ROUND-2 INDEPENDENT RE-VERIFICATION (2026-07-27, fresh agent, §88e discipline) ───────────── + * match_one : MATCH (271 ins) against the CURRENT tree — §87 staleness re-checked today. + * .text size: compiled .text = 0x43C = 1084 B = 271 ins, EXACTLY the target's declared 0x43C + * ("nonmatching func_8015B950, 0x43C"). So this is NOT a §83a length drift hiding + * behind a zero count — the count is over equal-length streams. + * jtbl : RE-DECODED MECHANICALLY, not inherited. Compiled .rodata = 0x1C = 28 B = 7 words, + * 7x R_MIPS_32 -> .text with implicit addends [58,58,58,E0,F0,100,58]; +0x8015B950 + * = [8015B9A8, 8015B9A8, 8015B9A8, 8015BA30, 8015BA40, 8015BA50, 8015B9A8]. + * Diffed word-for-word against asm/ov_SC01_077/data/tail14.data.s:15-23 — 7/7 identical. + * symcheck : SYMS-DIFF target=35 draft=34, sole MISSING = jtbl_801D8B74. This is the §81 jr + * FALSE POSITIVE, re-confirmed here by reading the relocs: gcc emits its OWN table and + * references it with R_MIPS_HI16/LO16 against the SECTION `.rodata` (t.o +0x40/+0x48), + * so the splat's dlabel NAME can never appear in the draft object's relocation set. + * Nothing is dropped and nothing is invented: the draft's other 34 symbols are exactly + * the target's other 34. + * FAMILY : the x138 remap is clean and §84-safe. Every sibling is 271 ins with an IDENTICAL + * callee set; only THREE names vary per overlay — the two data labels and the jtbl: + * ov_SC01_077 D_80185A50 / D_80185ABC / jtbl_801D8B74 + * ov_SC03_099 D_80185A50 / D_80185ABC / jtbl_801BD898 + * ov_SC06_008 D_80187E44 / D_80187EB0 / jtbl_801A8734 + * The pair is always +0x6C apart, and NO literal in this draft encodes that distance + * (both labels are referenced by name), so there is no §84 derived-offset hazard. + * D_8011F9C4 is fleet-constant (main-EXE data) and must NOT be remapped. + * + * match_one: MATCH (271 ins) against the CURRENT tree (§87 staleness re-checked, 2026-07-27). + * PIN-FREE, zero asm, offset-pure (s32 arg0 + raw offsets) — x138 template-safe. + * Provenance: this is the Phase-26 crack (.run/phase26-cracks/func_8015B950.c) re-gated verbatim, + * with ONE deliberate change: the definition's return type void -> s32. + * - `void func_8015B950(s32 arg0)` : MATCH (271 ins) [the Phase-26 form] + * - `s32 func_8015B950(s32 arg0)` : MATCH (271 ins) [shipped — §3a-1 void->s32 is byte-neutral] + * The fleet/engine_core.h canonical decl is `extern s32 func_8015B950(void);` (engine_core.h:1852), + * and the last bank attempt (.run/bank_func_8015B950.log) died on `conflicting types for + * func_8015B950`. Shipping the s32 return kills the §73 RETURN axis for free and leaves only the + * cheap T0 PARAMS axis for the ladder (fix_header_decl.py / --fix-def-sig / cast_call_sites). + * Both forms are byte-identical, so the orchestrator may swap the return type back at zero cost. + * + * SYMBOLS (§58 rules 1/2 — all splat spellings, all verified present): + * D_80185ABC asm/ov_SC01_077/data/tail.data.s:4355 (the state-handler vtable) + * D_80185A50 asm/ov_SC01_077/data/tail.data.s:4293 + * D_8011F9C4 main-EXE data; spelled `extern s32 D_8011F9C4;` in 5+ already-banked TUs + * jtbl_801D8B74 asm/ov_SC01_077/data/tail14.data.s:15 (compiler jump table — not named in C) + * + * JTBL VERIFIED (§8a gate): compiled .rodata = exactly 0x1C B / 7 words, 7x R_MIPS_32 .text with + * addends [0x58,0x58,0x58,0xE0,0xF0,0x100,0x58] -> +0x8015B950 = [B9A8,B9A8,B9A8,BA30,BA40,BA50, + * B9A8] == the original words at 0x801D8B74..0x801D8B8C. Bound `sltiu $v0,$v1,0x7` matches. + * The raw dlabel's 8th word 0x00000000 is NOT an entry — it is the intra-TU `.align 3` pad of the + * B34/B54/B74 jtbl chain; the object can never emit it (maspsx drops .align), so it must stay in + * the post-carve RAW data piece (the §53/§62/§81 carve chain applies at bank time). + * + * Same family as the TU's own already-matched func_8015AE2C: 7-case switch on ((s32 (*)(s32))func_801619A4)() + * (0/1/2/6 shared, 3/4/5 own, no default block — out-of-range and every `break` fall to the + * after-switch join), then a chain of "state handler" tests, each dispatching + * D_80185ABC[*(u16*)arg0](arg0) and returning. + * + * THREE LEVERS (draft -> MATCH in 3 compiles): + * + * 1. PROLOGUE CONSTANT = an INITIALIZED LOCAL, not a literal in the compare. + * Target opens with `lui $s2, 0xFFF5` in the *prologue*, used once ~200 ins later in + * `slt $v0,$s2,$s1`. No gcc-2.7.2 pass hoists a (set reg const_int) across basic blocks + * (loop.c needs a loop; cse/combine/sched never move insns between BBs) — so the insn must + * have been EMITTED in the first BB, i.e. the constant is a local initialized at the top of + * the function. cse then cannot fold it back into the compare: the `slt` operand predicate is + * `arith_operand`, which rejects a CONST_INT wider than 16 bits, so validate_change fails and + * the pseudo survives. Its live range spans every call -> global.c gives it a callee-saved reg. + * Writing `z > -0xB0000` inline instead emits the `lui` into the branch delay slot next to the + * compare (caller-saved $v0) and the function is 1 insn short. => `s32 lim = -0xB0000;` at top. + * + * 2. `lh` vs `lhu`: a short->short copy is a pure HImode move and gcc emits `lhu`. The target's + * `lh $v0,0x26($s0)` means the value passed through an SImode (int) temp: expand makes + * (set (reg:SI) (sign_extend (mem:HI))) + (set (mem:HI) (subreg:HI ...)), and combine cannot + * merge them (the merged form is mem<-mem, which no movhi accepts) so the sign-extending load + * survives. => route both halfword copies through the `s32 t` temp. + * + * 3. THE `goto` LAYOUT — dodging jump.c's store-flag conversion (jump.c:1005-1065). + * An if/else chain writing 0/1 into `doit` makes gcc collapse the last pair into + * `sltiu $v0,$v0,1`. jump.c fires that conversion when the insn immediately after a + * conditional jump is a lone `SET pseudo, CONST_INT` whose following simplejump targets the + * SAME label as the branch (jump.c:1038 `reallabelprev == temp || ... JUMP_LABEL(temp4) == + * JUMP_LABEL(insn)`) — exactly the shape of `if (c) x=0; else x=1;`. + * The target instead cross-jumps ALL the `doit=0` exits into ONE shared block placed after the + * `doit=1` fall-through; reorg's fill_slots_from_thread then COPIES that single set into all + * three branch delay slots and redirects each branch past it (which is why `addu $v0,$zero, + * $zero` appears 3x in delay slots and the shared block vanishes). A `goto zero;` / `goto one;` + * chain expresses that layout directly, and each conditional jump is then followed by a + * compare/call rather than a lone const set, so the store-flag conversion never triggers. + * GENERAL RULE: multiple predicates that all assign the SAME constant to one flag => write + * them as `goto` to a shared assignment, never as an if/else ladder. + */ +extern s32 D_8011F9C4; +extern s32 D_80185A50; + +extern s32 func_80161B18(void); +extern s32 func_801619A4(s32*); +extern s32 func_80149AA8(s32*); +extern void func_80149AD4(s32*); +extern s32 func_80149B54(s32*); +extern void func_80149BAC(s32*); +extern s32 func_801498E0(s32*); +extern s32 func_80149954(s32); +extern s32 func_80149A64(s32*); +extern void func_800CCCC0(s32 a0); +extern s32 func_80149CD4(s32 a0); +extern void func_8015E880(s32*); +extern s32 func_80149744(struct S_80149744*); +extern void func_80149788(void); +extern s32 func_801496D4(void*); +extern void func_80149704(void); +extern int func_80148AFC(void*); +extern void func_80146D90(s32 a0); +extern void func_80154150(s32 a0, s32 a1); +extern void func_801541D8(u8*, s32, s32); +extern s32 func_801488A8(u8*); +extern void func_80147078(s32*, s16); +extern void func_8015A264(void*); +extern s32 func_80013294(void*, void*); +extern void func_80159B70(void*); +extern s32 func_8016F1AC(void); +extern s32 func_80029178(s32 a0); +extern void func_80146DB8(s32*, s32*); +extern s32 func_80161CD0(s32, s32); +extern s32 func_80161208(s32 a0); +extern s32 func_801725A4(u8*); + +s32 func_8015B950(s32 arg0) +{ + + extern void (*D_80185ABC[])(void *); + s16 sp10[4]; + s16 sp18[4]; + s32 t; + s32 z; + s32 doit; + s32 lim = -0xB0000; + + if (func_80161B18() != 0) { + return; + } + switch (((s32 (*)(s32))func_801619A4)(arg0)) { + case 0: + case 1: + case 2: + case 6: + if (((s32 (*)(s32))func_80149AA8)(arg0) != 0) { + D_80185ABC[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149AD4)(arg0); + return; + } + if (((s32 (*)(s32))func_80149B54)(arg0) != 0) { + D_80185ABC[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149BAC)(arg0); + return; + } + break; + case 3: + ((void (*)(s32))func_801498E0)(arg0); + break; + case 4: + ((void (*)(s32))func_80149954)(arg0); + break; + case 5: + if (((s32 (*)(s32))func_80149A64)(arg0) != 0) { + D_80185ABC[*(u16 *)arg0]((void *)arg0); + func_800CCCC0(arg0); + return; + } + break; + } + if (func_80149CD4(arg0) != 0) { + D_80185ABC[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_8015E880)(arg0); + return; + } + if (((s32 (*)(s32))func_80149744)(arg0) != 0) { + D_80185ABC[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149788)(arg0); + return; + } + if (((s32 (*)(s32))func_801496D4)(arg0) != 0) { + D_80185ABC[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149704)(arg0); + if (((u8)((s32 (*)(s32))func_80148AFC)(arg0)) == 0) { + func_80146D90(arg0); + } + if ((*(s32 *)(arg0 + 0x24) | *(s32 *)(arg0 + 0x2C)) != 0) { + func_80154150(arg0, 0xF); + } else { + ((void (*)(s32, s32, s32))func_801541D8)(arg0, 0xD, 6); + } + *(s32 *)(arg0 + 0x238) = 1; + return; + } + if (((s32 (*)(s32))func_801488A8)(arg0) != 0) { + sp10[0] = 0; + sp10[1] = 0; + sp10[2] = 0; + t = *(s16 *)(arg0 + 0x26); + sp18[0] = t; + sp18[1] = 0; + t = *(s16 *)(arg0 + 0x2E); + sp18[2] = t; + D_80185ABC[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 1); + ((void (*)(s32))func_8015A264)(arg0); + t = -(((s32 (*)(s16 *, s16 *))func_80013294)(sp10, sp18) << 0x10); + if (t < *(s32 *)(arg0 + 0x2C)) { + *(s32 *)(arg0 + 0x2C) = t; + } + return; + } + if (*(u16 *)(arg0 + 0xB8) == 0x8000) { + D_80185ABC[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 0); + ((void (*)(s32))func_80159B70)(arg0); + return; + } + z = *(s32 *)(arg0 + 0x2C); + if (func_8016F1AC() != 0) { + goto zero; + } + if (z <= lim) { + goto one; + } + if (D_8011F9C4 == 0) { + goto zero; + } + if (((u8)func_80029178(0x21)) != 0) { + goto zero; + } +one: + doit = 1; + goto join; +zero: + doit = 0; +join: + if (doit != 0) { + D_80185ABC[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 0); + ((void (*)(s32))func_80159B70)(arg0); + func_80154150(arg0, 9); + ((void (*)(s32, s32 *))func_80146DB8)(arg0, &D_80185A50); + ((void (*)(s32, s32))func_80161CD0)(arg0, *(u16 *)(arg0 + 0x16E)); + return; + } + if (func_80161208(arg0) == 0) { + ((void (*)(s32))func_801725A4)(arg0); + } +} DEFINE_func_8015BD8C() /* dedup: shared engine-core @0x8015BD8C (src/shared) */ diff --git a/src/ov_SC03_100/ov_SC03_100_jr_8015AE2C.c b/src/ov_SC03_100/ov_SC03_100_jr_8015AE2C.c index 584e2632f..0a4c0b3a8 100644 --- a/src/ov_SC03_100/ov_SC03_100_jr_8015AE2C.c +++ b/src/ov_SC03_100/ov_SC03_100_jr_8015AE2C.c @@ -1513,7 +1513,259 @@ DEFINE_func_8015B858() /* dedup: shared engine-core @0x8015B858 (src/shared) */ DEFINE_func_8015B8F8() /* dedup: shared engine-core @0x8015B8F8 (src/shared) */ -INCLUDE_ASM("asm/ov_SC03_100/nonmatchings/ov_SC03_100_jr_8015AE2C", func_8015B950); +extern s32 func_8015AE2C(); + +// @class: plumbing +// @stuck: none — MATCH (271/271, pin-free, zero asm). The ONLY residual is DEF-SIDE plumbing, and it is now named exactly: the in-TU instantiation `DEFINE_func_8015BEE4()` (engine_core.h:1851-1855) expands to `extern s32 func_8015B950(void);` INSIDE ov_SC01_077_jr_8015AE2C.c, ~14 lines BELOW this definition, so the 1-param def collides with a `(void)` prototype -> `conflicting types for func_8015B950` (.run/bank_func_8015B950.log). §73 PARAMS axis / T0. Surgical fix = §65b de-macroize that ONE instantiation (blast radius: this TU); the fleet-wide `(void)`->`()` header edit is §63 and must be R22-validated. +/* func_8015B950 (ov_SC01_077_jr_8015AE2C, 271 ins, jtbl_801D8B74) — SESSION-21 re-verified + * + * ── ROUND-2 INDEPENDENT RE-VERIFICATION (2026-07-27, fresh agent, §88e discipline) ───────────── + * match_one : MATCH (271 ins) against the CURRENT tree — §87 staleness re-checked today. + * .text size: compiled .text = 0x43C = 1084 B = 271 ins, EXACTLY the target's declared 0x43C + * ("nonmatching func_8015B950, 0x43C"). So this is NOT a §83a length drift hiding + * behind a zero count — the count is over equal-length streams. + * jtbl : RE-DECODED MECHANICALLY, not inherited. Compiled .rodata = 0x1C = 28 B = 7 words, + * 7x R_MIPS_32 -> .text with implicit addends [58,58,58,E0,F0,100,58]; +0x8015B950 + * = [8015B9A8, 8015B9A8, 8015B9A8, 8015BA30, 8015BA40, 8015BA50, 8015B9A8]. + * Diffed word-for-word against asm/ov_SC01_077/data/tail14.data.s:15-23 — 7/7 identical. + * symcheck : SYMS-DIFF target=35 draft=34, sole MISSING = jtbl_801D8B74. This is the §81 jr + * FALSE POSITIVE, re-confirmed here by reading the relocs: gcc emits its OWN table and + * references it with R_MIPS_HI16/LO16 against the SECTION `.rodata` (t.o +0x40/+0x48), + * so the splat's dlabel NAME can never appear in the draft object's relocation set. + * Nothing is dropped and nothing is invented: the draft's other 34 symbols are exactly + * the target's other 34. + * FAMILY : the x138 remap is clean and §84-safe. Every sibling is 271 ins with an IDENTICAL + * callee set; only THREE names vary per overlay — the two data labels and the jtbl: + * ov_SC01_077 D_80186F1C / D_80186F88 / jtbl_801D8B74 + * ov_SC03_099 D_80185A50 / D_80185ABC / jtbl_801BD898 + * ov_SC06_008 D_80187E44 / D_80187EB0 / jtbl_801A8734 + * The pair is always +0x6C apart, and NO literal in this draft encodes that distance + * (both labels are referenced by name), so there is no §84 derived-offset hazard. + * D_8011F9C4 is fleet-constant (main-EXE data) and must NOT be remapped. + * + * match_one: MATCH (271 ins) against the CURRENT tree (§87 staleness re-checked, 2026-07-27). + * PIN-FREE, zero asm, offset-pure (s32 arg0 + raw offsets) — x138 template-safe. + * Provenance: this is the Phase-26 crack (.run/phase26-cracks/func_8015B950.c) re-gated verbatim, + * with ONE deliberate change: the definition's return type void -> s32. + * - `void func_8015B950(s32 arg0)` : MATCH (271 ins) [the Phase-26 form] + * - `s32 func_8015B950(s32 arg0)` : MATCH (271 ins) [shipped — §3a-1 void->s32 is byte-neutral] + * The fleet/engine_core.h canonical decl is `extern s32 func_8015B950(void);` (engine_core.h:1852), + * and the last bank attempt (.run/bank_func_8015B950.log) died on `conflicting types for + * func_8015B950`. Shipping the s32 return kills the §73 RETURN axis for free and leaves only the + * cheap T0 PARAMS axis for the ladder (fix_header_decl.py / --fix-def-sig / cast_call_sites). + * Both forms are byte-identical, so the orchestrator may swap the return type back at zero cost. + * + * SYMBOLS (§58 rules 1/2 — all splat spellings, all verified present): + * D_80186F88 asm/ov_SC01_077/data/tail.data.s:4355 (the state-handler vtable) + * D_80186F1C asm/ov_SC01_077/data/tail.data.s:4293 + * D_8011F9C4 main-EXE data; spelled `extern s32 D_8011F9C4;` in 5+ already-banked TUs + * jtbl_801D8B74 asm/ov_SC01_077/data/tail14.data.s:15 (compiler jump table — not named in C) + * + * JTBL VERIFIED (§8a gate): compiled .rodata = exactly 0x1C B / 7 words, 7x R_MIPS_32 .text with + * addends [0x58,0x58,0x58,0xE0,0xF0,0x100,0x58] -> +0x8015B950 = [B9A8,B9A8,B9A8,BA30,BA40,BA50, + * B9A8] == the original words at 0x801D8B74..0x801D8B8C. Bound `sltiu $v0,$v1,0x7` matches. + * The raw dlabel's 8th word 0x00000000 is NOT an entry — it is the intra-TU `.align 3` pad of the + * B34/B54/B74 jtbl chain; the object can never emit it (maspsx drops .align), so it must stay in + * the post-carve RAW data piece (the §53/§62/§81 carve chain applies at bank time). + * + * Same family as the TU's own already-matched func_8015AE2C: 7-case switch on ((s32 (*)(s32))func_801619A4)() + * (0/1/2/6 shared, 3/4/5 own, no default block — out-of-range and every `break` fall to the + * after-switch join), then a chain of "state handler" tests, each dispatching + * D_80186F88[*(u16*)arg0](arg0) and returning. + * + * THREE LEVERS (draft -> MATCH in 3 compiles): + * + * 1. PROLOGUE CONSTANT = an INITIALIZED LOCAL, not a literal in the compare. + * Target opens with `lui $s2, 0xFFF5` in the *prologue*, used once ~200 ins later in + * `slt $v0,$s2,$s1`. No gcc-2.7.2 pass hoists a (set reg const_int) across basic blocks + * (loop.c needs a loop; cse/combine/sched never move insns between BBs) — so the insn must + * have been EMITTED in the first BB, i.e. the constant is a local initialized at the top of + * the function. cse then cannot fold it back into the compare: the `slt` operand predicate is + * `arith_operand`, which rejects a CONST_INT wider than 16 bits, so validate_change fails and + * the pseudo survives. Its live range spans every call -> global.c gives it a callee-saved reg. + * Writing `z > -0xB0000` inline instead emits the `lui` into the branch delay slot next to the + * compare (caller-saved $v0) and the function is 1 insn short. => `s32 lim = -0xB0000;` at top. + * + * 2. `lh` vs `lhu`: a short->short copy is a pure HImode move and gcc emits `lhu`. The target's + * `lh $v0,0x26($s0)` means the value passed through an SImode (int) temp: expand makes + * (set (reg:SI) (sign_extend (mem:HI))) + (set (mem:HI) (subreg:HI ...)), and combine cannot + * merge them (the merged form is mem<-mem, which no movhi accepts) so the sign-extending load + * survives. => route both halfword copies through the `s32 t` temp. + * + * 3. THE `goto` LAYOUT — dodging jump.c's store-flag conversion (jump.c:1005-1065). + * An if/else chain writing 0/1 into `doit` makes gcc collapse the last pair into + * `sltiu $v0,$v0,1`. jump.c fires that conversion when the insn immediately after a + * conditional jump is a lone `SET pseudo, CONST_INT` whose following simplejump targets the + * SAME label as the branch (jump.c:1038 `reallabelprev == temp || ... JUMP_LABEL(temp4) == + * JUMP_LABEL(insn)`) — exactly the shape of `if (c) x=0; else x=1;`. + * The target instead cross-jumps ALL the `doit=0` exits into ONE shared block placed after the + * `doit=1` fall-through; reorg's fill_slots_from_thread then COPIES that single set into all + * three branch delay slots and redirects each branch past it (which is why `addu $v0,$zero, + * $zero` appears 3x in delay slots and the shared block vanishes). A `goto zero;` / `goto one;` + * chain expresses that layout directly, and each conditional jump is then followed by a + * compare/call rather than a lone const set, so the store-flag conversion never triggers. + * GENERAL RULE: multiple predicates that all assign the SAME constant to one flag => write + * them as `goto` to a shared assignment, never as an if/else ladder. + */ +extern s32 D_8011F9C4; +extern s32 D_80186F1C; + +extern s32 func_80161B18(void); +extern s32 func_801619A4(s32*); +extern s32 func_80149AA8(s32*); +extern void func_80149AD4(s32*); +extern s32 func_80149B54(s32*); +extern void func_80149BAC(s32*); +extern s32 func_801498E0(s32*); +extern s32 func_80149954(s32); +extern s32 func_80149A64(s32*); +extern void func_800CCCC0(s32 a0); +extern s32 func_80149CD4(s32 a0); +extern void func_8015E880(s32*); +extern s32 func_80149744(struct S_80149744*); +extern void func_80149788(void); +extern s32 func_801496D4(void*); +extern void func_80149704(void); +extern int func_80148AFC(void*); +extern void func_80146D90(s32 a0); +extern void func_80154150(s32 a0, s32 a1); +extern void func_801541D8(u8*, s32, s32); +extern s32 func_801488A8(u8*); +extern void func_80147078(s32*, s16); +extern void func_8015A264(void*); +extern s32 func_80013294(void*, void*); +extern void func_80159B70(void*); +extern s32 func_8016F1AC(void); +extern s32 func_80029178(s32 a0); +extern void func_80146DB8(s32*, s32*); +extern s32 func_80161CD0(s32, s32); +extern s32 func_80161208(s32 a0); +extern s32 func_801725A4(u8*); + +s32 func_8015B950(s32 arg0) +{ + + extern void (*D_80186F88[])(void *); + s16 sp10[4]; + s16 sp18[4]; + s32 t; + s32 z; + s32 doit; + s32 lim = -0xB0000; + + if (func_80161B18() != 0) { + return; + } + switch (((s32 (*)(s32))func_801619A4)(arg0)) { + case 0: + case 1: + case 2: + case 6: + if (((s32 (*)(s32))func_80149AA8)(arg0) != 0) { + D_80186F88[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149AD4)(arg0); + return; + } + if (((s32 (*)(s32))func_80149B54)(arg0) != 0) { + D_80186F88[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149BAC)(arg0); + return; + } + break; + case 3: + ((void (*)(s32))func_801498E0)(arg0); + break; + case 4: + ((void (*)(s32))func_80149954)(arg0); + break; + case 5: + if (((s32 (*)(s32))func_80149A64)(arg0) != 0) { + D_80186F88[*(u16 *)arg0]((void *)arg0); + func_800CCCC0(arg0); + return; + } + break; + } + if (func_80149CD4(arg0) != 0) { + D_80186F88[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_8015E880)(arg0); + return; + } + if (((s32 (*)(s32))func_80149744)(arg0) != 0) { + D_80186F88[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149788)(arg0); + return; + } + if (((s32 (*)(s32))func_801496D4)(arg0) != 0) { + D_80186F88[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149704)(arg0); + if (((u8)((s32 (*)(s32))func_80148AFC)(arg0)) == 0) { + func_80146D90(arg0); + } + if ((*(s32 *)(arg0 + 0x24) | *(s32 *)(arg0 + 0x2C)) != 0) { + func_80154150(arg0, 0xF); + } else { + ((void (*)(s32, s32, s32))func_801541D8)(arg0, 0xD, 6); + } + *(s32 *)(arg0 + 0x238) = 1; + return; + } + if (((s32 (*)(s32))func_801488A8)(arg0) != 0) { + sp10[0] = 0; + sp10[1] = 0; + sp10[2] = 0; + t = *(s16 *)(arg0 + 0x26); + sp18[0] = t; + sp18[1] = 0; + t = *(s16 *)(arg0 + 0x2E); + sp18[2] = t; + D_80186F88[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 1); + ((void (*)(s32))func_8015A264)(arg0); + t = -(((s32 (*)(s16 *, s16 *))func_80013294)(sp10, sp18) << 0x10); + if (t < *(s32 *)(arg0 + 0x2C)) { + *(s32 *)(arg0 + 0x2C) = t; + } + return; + } + if (*(u16 *)(arg0 + 0xB8) == 0x8000) { + D_80186F88[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 0); + ((void (*)(s32))func_80159B70)(arg0); + return; + } + z = *(s32 *)(arg0 + 0x2C); + if (func_8016F1AC() != 0) { + goto zero; + } + if (z <= lim) { + goto one; + } + if (D_8011F9C4 == 0) { + goto zero; + } + if (((u8)func_80029178(0x21)) != 0) { + goto zero; + } +one: + doit = 1; + goto join; +zero: + doit = 0; +join: + if (doit != 0) { + D_80186F88[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 0); + ((void (*)(s32))func_80159B70)(arg0); + func_80154150(arg0, 9); + ((void (*)(s32, s32 *))func_80146DB8)(arg0, &D_80186F1C); + ((void (*)(s32, s32))func_80161CD0)(arg0, *(u16 *)(arg0 + 0x16E)); + return; + } + if (func_80161208(arg0) == 0) { + ((void (*)(s32))func_801725A4)(arg0); + } +} DEFINE_func_8015BD8C() /* dedup: shared engine-core @0x8015BD8C (src/shared) */ diff --git a/src/ov_SC03_101/ov_SC03_101_jr_8015AE2C.c b/src/ov_SC03_101/ov_SC03_101_jr_8015AE2C.c index 9d6952549..73cfa43d6 100644 --- a/src/ov_SC03_101/ov_SC03_101_jr_8015AE2C.c +++ b/src/ov_SC03_101/ov_SC03_101_jr_8015AE2C.c @@ -1513,7 +1513,259 @@ DEFINE_func_8015B858() /* dedup: shared engine-core @0x8015B858 (src/shared) */ DEFINE_func_8015B8F8() /* dedup: shared engine-core @0x8015B8F8 (src/shared) */ -INCLUDE_ASM("asm/ov_SC03_101/nonmatchings/ov_SC03_101_jr_8015AE2C", func_8015B950); +extern s32 func_8015AE2C(); + +// @class: plumbing +// @stuck: none — MATCH (271/271, pin-free, zero asm). The ONLY residual is DEF-SIDE plumbing, and it is now named exactly: the in-TU instantiation `DEFINE_func_8015BEE4()` (engine_core.h:1851-1855) expands to `extern s32 func_8015B950(void);` INSIDE ov_SC01_077_jr_8015AE2C.c, ~14 lines BELOW this definition, so the 1-param def collides with a `(void)` prototype -> `conflicting types for func_8015B950` (.run/bank_func_8015B950.log). §73 PARAMS axis / T0. Surgical fix = §65b de-macroize that ONE instantiation (blast radius: this TU); the fleet-wide `(void)`->`()` header edit is §63 and must be R22-validated. +/* func_8015B950 (ov_SC01_077_jr_8015AE2C, 271 ins, jtbl_801D8B74) — SESSION-21 re-verified + * + * ── ROUND-2 INDEPENDENT RE-VERIFICATION (2026-07-27, fresh agent, §88e discipline) ───────────── + * match_one : MATCH (271 ins) against the CURRENT tree — §87 staleness re-checked today. + * .text size: compiled .text = 0x43C = 1084 B = 271 ins, EXACTLY the target's declared 0x43C + * ("nonmatching func_8015B950, 0x43C"). So this is NOT a §83a length drift hiding + * behind a zero count — the count is over equal-length streams. + * jtbl : RE-DECODED MECHANICALLY, not inherited. Compiled .rodata = 0x1C = 28 B = 7 words, + * 7x R_MIPS_32 -> .text with implicit addends [58,58,58,E0,F0,100,58]; +0x8015B950 + * = [8015B9A8, 8015B9A8, 8015B9A8, 8015BA30, 8015BA40, 8015BA50, 8015B9A8]. + * Diffed word-for-word against asm/ov_SC01_077/data/tail14.data.s:15-23 — 7/7 identical. + * symcheck : SYMS-DIFF target=35 draft=34, sole MISSING = jtbl_801D8B74. This is the §81 jr + * FALSE POSITIVE, re-confirmed here by reading the relocs: gcc emits its OWN table and + * references it with R_MIPS_HI16/LO16 against the SECTION `.rodata` (t.o +0x40/+0x48), + * so the splat's dlabel NAME can never appear in the draft object's relocation set. + * Nothing is dropped and nothing is invented: the draft's other 34 symbols are exactly + * the target's other 34. + * FAMILY : the x138 remap is clean and §84-safe. Every sibling is 271 ins with an IDENTICAL + * callee set; only THREE names vary per overlay — the two data labels and the jtbl: + * ov_SC01_077 D_80185EF8 / D_80185F64 / jtbl_801D8B74 + * ov_SC03_099 D_80185A50 / D_80185ABC / jtbl_801BD898 + * ov_SC06_008 D_80187E44 / D_80187EB0 / jtbl_801A8734 + * The pair is always +0x6C apart, and NO literal in this draft encodes that distance + * (both labels are referenced by name), so there is no §84 derived-offset hazard. + * D_8011F9C4 is fleet-constant (main-EXE data) and must NOT be remapped. + * + * match_one: MATCH (271 ins) against the CURRENT tree (§87 staleness re-checked, 2026-07-27). + * PIN-FREE, zero asm, offset-pure (s32 arg0 + raw offsets) — x138 template-safe. + * Provenance: this is the Phase-26 crack (.run/phase26-cracks/func_8015B950.c) re-gated verbatim, + * with ONE deliberate change: the definition's return type void -> s32. + * - `void func_8015B950(s32 arg0)` : MATCH (271 ins) [the Phase-26 form] + * - `s32 func_8015B950(s32 arg0)` : MATCH (271 ins) [shipped — §3a-1 void->s32 is byte-neutral] + * The fleet/engine_core.h canonical decl is `extern s32 func_8015B950(void);` (engine_core.h:1852), + * and the last bank attempt (.run/bank_func_8015B950.log) died on `conflicting types for + * func_8015B950`. Shipping the s32 return kills the §73 RETURN axis for free and leaves only the + * cheap T0 PARAMS axis for the ladder (fix_header_decl.py / --fix-def-sig / cast_call_sites). + * Both forms are byte-identical, so the orchestrator may swap the return type back at zero cost. + * + * SYMBOLS (§58 rules 1/2 — all splat spellings, all verified present): + * D_80185F64 asm/ov_SC01_077/data/tail.data.s:4355 (the state-handler vtable) + * D_80185EF8 asm/ov_SC01_077/data/tail.data.s:4293 + * D_8011F9C4 main-EXE data; spelled `extern s32 D_8011F9C4;` in 5+ already-banked TUs + * jtbl_801D8B74 asm/ov_SC01_077/data/tail14.data.s:15 (compiler jump table — not named in C) + * + * JTBL VERIFIED (§8a gate): compiled .rodata = exactly 0x1C B / 7 words, 7x R_MIPS_32 .text with + * addends [0x58,0x58,0x58,0xE0,0xF0,0x100,0x58] -> +0x8015B950 = [B9A8,B9A8,B9A8,BA30,BA40,BA50, + * B9A8] == the original words at 0x801D8B74..0x801D8B8C. Bound `sltiu $v0,$v1,0x7` matches. + * The raw dlabel's 8th word 0x00000000 is NOT an entry — it is the intra-TU `.align 3` pad of the + * B34/B54/B74 jtbl chain; the object can never emit it (maspsx drops .align), so it must stay in + * the post-carve RAW data piece (the §53/§62/§81 carve chain applies at bank time). + * + * Same family as the TU's own already-matched func_8015AE2C: 7-case switch on ((s32 (*)(s32))func_801619A4)() + * (0/1/2/6 shared, 3/4/5 own, no default block — out-of-range and every `break` fall to the + * after-switch join), then a chain of "state handler" tests, each dispatching + * D_80185F64[*(u16*)arg0](arg0) and returning. + * + * THREE LEVERS (draft -> MATCH in 3 compiles): + * + * 1. PROLOGUE CONSTANT = an INITIALIZED LOCAL, not a literal in the compare. + * Target opens with `lui $s2, 0xFFF5` in the *prologue*, used once ~200 ins later in + * `slt $v0,$s2,$s1`. No gcc-2.7.2 pass hoists a (set reg const_int) across basic blocks + * (loop.c needs a loop; cse/combine/sched never move insns between BBs) — so the insn must + * have been EMITTED in the first BB, i.e. the constant is a local initialized at the top of + * the function. cse then cannot fold it back into the compare: the `slt` operand predicate is + * `arith_operand`, which rejects a CONST_INT wider than 16 bits, so validate_change fails and + * the pseudo survives. Its live range spans every call -> global.c gives it a callee-saved reg. + * Writing `z > -0xB0000` inline instead emits the `lui` into the branch delay slot next to the + * compare (caller-saved $v0) and the function is 1 insn short. => `s32 lim = -0xB0000;` at top. + * + * 2. `lh` vs `lhu`: a short->short copy is a pure HImode move and gcc emits `lhu`. The target's + * `lh $v0,0x26($s0)` means the value passed through an SImode (int) temp: expand makes + * (set (reg:SI) (sign_extend (mem:HI))) + (set (mem:HI) (subreg:HI ...)), and combine cannot + * merge them (the merged form is mem<-mem, which no movhi accepts) so the sign-extending load + * survives. => route both halfword copies through the `s32 t` temp. + * + * 3. THE `goto` LAYOUT — dodging jump.c's store-flag conversion (jump.c:1005-1065). + * An if/else chain writing 0/1 into `doit` makes gcc collapse the last pair into + * `sltiu $v0,$v0,1`. jump.c fires that conversion when the insn immediately after a + * conditional jump is a lone `SET pseudo, CONST_INT` whose following simplejump targets the + * SAME label as the branch (jump.c:1038 `reallabelprev == temp || ... JUMP_LABEL(temp4) == + * JUMP_LABEL(insn)`) — exactly the shape of `if (c) x=0; else x=1;`. + * The target instead cross-jumps ALL the `doit=0` exits into ONE shared block placed after the + * `doit=1` fall-through; reorg's fill_slots_from_thread then COPIES that single set into all + * three branch delay slots and redirects each branch past it (which is why `addu $v0,$zero, + * $zero` appears 3x in delay slots and the shared block vanishes). A `goto zero;` / `goto one;` + * chain expresses that layout directly, and each conditional jump is then followed by a + * compare/call rather than a lone const set, so the store-flag conversion never triggers. + * GENERAL RULE: multiple predicates that all assign the SAME constant to one flag => write + * them as `goto` to a shared assignment, never as an if/else ladder. + */ +extern s32 D_8011F9C4; +extern s32 D_80185EF8; + +extern s32 func_80161B18(void); +extern s32 func_801619A4(s32*); +extern s32 func_80149AA8(s32*); +extern void func_80149AD4(s32*); +extern s32 func_80149B54(s32*); +extern void func_80149BAC(s32*); +extern s32 func_801498E0(s32*); +extern s32 func_80149954(s32); +extern s32 func_80149A64(s32*); +extern void func_800CCCC0(s32 a0); +extern s32 func_80149CD4(s32 a0); +extern void func_8015E880(s32*); +extern s32 func_80149744(struct S_80149744*); +extern void func_80149788(void); +extern s32 func_801496D4(void*); +extern void func_80149704(void); +extern int func_80148AFC(void*); +extern void func_80146D90(s32 a0); +extern void func_80154150(s32 a0, s32 a1); +extern void func_801541D8(u8*, s32, s32); +extern s32 func_801488A8(u8*); +extern void func_80147078(s32*, s16); +extern void func_8015A264(void*); +extern s32 func_80013294(void*, void*); +extern void func_80159B70(void*); +extern s32 func_8016F1AC(void); +extern s32 func_80029178(s32 a0); +extern void func_80146DB8(s32*, s32*); +extern s32 func_80161CD0(s32, s32); +extern s32 func_80161208(s32 a0); +extern s32 func_801725A4(u8*); + +s32 func_8015B950(s32 arg0) +{ + + extern void (*D_80185F64[])(void *); + s16 sp10[4]; + s16 sp18[4]; + s32 t; + s32 z; + s32 doit; + s32 lim = -0xB0000; + + if (func_80161B18() != 0) { + return; + } + switch (((s32 (*)(s32))func_801619A4)(arg0)) { + case 0: + case 1: + case 2: + case 6: + if (((s32 (*)(s32))func_80149AA8)(arg0) != 0) { + D_80185F64[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149AD4)(arg0); + return; + } + if (((s32 (*)(s32))func_80149B54)(arg0) != 0) { + D_80185F64[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149BAC)(arg0); + return; + } + break; + case 3: + ((void (*)(s32))func_801498E0)(arg0); + break; + case 4: + ((void (*)(s32))func_80149954)(arg0); + break; + case 5: + if (((s32 (*)(s32))func_80149A64)(arg0) != 0) { + D_80185F64[*(u16 *)arg0]((void *)arg0); + func_800CCCC0(arg0); + return; + } + break; + } + if (func_80149CD4(arg0) != 0) { + D_80185F64[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_8015E880)(arg0); + return; + } + if (((s32 (*)(s32))func_80149744)(arg0) != 0) { + D_80185F64[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149788)(arg0); + return; + } + if (((s32 (*)(s32))func_801496D4)(arg0) != 0) { + D_80185F64[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149704)(arg0); + if (((u8)((s32 (*)(s32))func_80148AFC)(arg0)) == 0) { + func_80146D90(arg0); + } + if ((*(s32 *)(arg0 + 0x24) | *(s32 *)(arg0 + 0x2C)) != 0) { + func_80154150(arg0, 0xF); + } else { + ((void (*)(s32, s32, s32))func_801541D8)(arg0, 0xD, 6); + } + *(s32 *)(arg0 + 0x238) = 1; + return; + } + if (((s32 (*)(s32))func_801488A8)(arg0) != 0) { + sp10[0] = 0; + sp10[1] = 0; + sp10[2] = 0; + t = *(s16 *)(arg0 + 0x26); + sp18[0] = t; + sp18[1] = 0; + t = *(s16 *)(arg0 + 0x2E); + sp18[2] = t; + D_80185F64[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 1); + ((void (*)(s32))func_8015A264)(arg0); + t = -(((s32 (*)(s16 *, s16 *))func_80013294)(sp10, sp18) << 0x10); + if (t < *(s32 *)(arg0 + 0x2C)) { + *(s32 *)(arg0 + 0x2C) = t; + } + return; + } + if (*(u16 *)(arg0 + 0xB8) == 0x8000) { + D_80185F64[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 0); + ((void (*)(s32))func_80159B70)(arg0); + return; + } + z = *(s32 *)(arg0 + 0x2C); + if (func_8016F1AC() != 0) { + goto zero; + } + if (z <= lim) { + goto one; + } + if (D_8011F9C4 == 0) { + goto zero; + } + if (((u8)func_80029178(0x21)) != 0) { + goto zero; + } +one: + doit = 1; + goto join; +zero: + doit = 0; +join: + if (doit != 0) { + D_80185F64[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 0); + ((void (*)(s32))func_80159B70)(arg0); + func_80154150(arg0, 9); + ((void (*)(s32, s32 *))func_80146DB8)(arg0, &D_80185EF8); + ((void (*)(s32, s32))func_80161CD0)(arg0, *(u16 *)(arg0 + 0x16E)); + return; + } + if (func_80161208(arg0) == 0) { + ((void (*)(s32))func_801725A4)(arg0); + } +} DEFINE_func_8015BD8C() /* dedup: shared engine-core @0x8015BD8C (src/shared) */ diff --git a/src/ov_SC03_102/ov_SC03_102_jr_8015AE2C.c b/src/ov_SC03_102/ov_SC03_102_jr_8015AE2C.c index 6cbf67498..b056cf636 100644 --- a/src/ov_SC03_102/ov_SC03_102_jr_8015AE2C.c +++ b/src/ov_SC03_102/ov_SC03_102_jr_8015AE2C.c @@ -1513,7 +1513,259 @@ DEFINE_func_8015B858() /* dedup: shared engine-core @0x8015B858 (src/shared) */ DEFINE_func_8015B8F8() /* dedup: shared engine-core @0x8015B8F8 (src/shared) */ -INCLUDE_ASM("asm/ov_SC03_102/nonmatchings/ov_SC03_102_jr_8015AE2C", func_8015B950); +extern s32 func_8015AE2C(); + +// @class: plumbing +// @stuck: none — MATCH (271/271, pin-free, zero asm). The ONLY residual is DEF-SIDE plumbing, and it is now named exactly: the in-TU instantiation `DEFINE_func_8015BEE4()` (engine_core.h:1851-1855) expands to `extern s32 func_8015B950(void);` INSIDE ov_SC01_077_jr_8015AE2C.c, ~14 lines BELOW this definition, so the 1-param def collides with a `(void)` prototype -> `conflicting types for func_8015B950` (.run/bank_func_8015B950.log). §73 PARAMS axis / T0. Surgical fix = §65b de-macroize that ONE instantiation (blast radius: this TU); the fleet-wide `(void)`->`()` header edit is §63 and must be R22-validated. +/* func_8015B950 (ov_SC01_077_jr_8015AE2C, 271 ins, jtbl_801D8B74) — SESSION-21 re-verified + * + * ── ROUND-2 INDEPENDENT RE-VERIFICATION (2026-07-27, fresh agent, §88e discipline) ───────────── + * match_one : MATCH (271 ins) against the CURRENT tree — §87 staleness re-checked today. + * .text size: compiled .text = 0x43C = 1084 B = 271 ins, EXACTLY the target's declared 0x43C + * ("nonmatching func_8015B950, 0x43C"). So this is NOT a §83a length drift hiding + * behind a zero count — the count is over equal-length streams. + * jtbl : RE-DECODED MECHANICALLY, not inherited. Compiled .rodata = 0x1C = 28 B = 7 words, + * 7x R_MIPS_32 -> .text with implicit addends [58,58,58,E0,F0,100,58]; +0x8015B950 + * = [8015B9A8, 8015B9A8, 8015B9A8, 8015BA30, 8015BA40, 8015BA50, 8015B9A8]. + * Diffed word-for-word against asm/ov_SC01_077/data/tail14.data.s:15-23 — 7/7 identical. + * symcheck : SYMS-DIFF target=35 draft=34, sole MISSING = jtbl_801D8B74. This is the §81 jr + * FALSE POSITIVE, re-confirmed here by reading the relocs: gcc emits its OWN table and + * references it with R_MIPS_HI16/LO16 against the SECTION `.rodata` (t.o +0x40/+0x48), + * so the splat's dlabel NAME can never appear in the draft object's relocation set. + * Nothing is dropped and nothing is invented: the draft's other 34 symbols are exactly + * the target's other 34. + * FAMILY : the x138 remap is clean and §84-safe. Every sibling is 271 ins with an IDENTICAL + * callee set; only THREE names vary per overlay — the two data labels and the jtbl: + * ov_SC01_077 D_801887B0 / D_8018881C / jtbl_801D8B74 + * ov_SC03_099 D_80185A50 / D_80185ABC / jtbl_801BD898 + * ov_SC06_008 D_80187E44 / D_80187EB0 / jtbl_801A8734 + * The pair is always +0x6C apart, and NO literal in this draft encodes that distance + * (both labels are referenced by name), so there is no §84 derived-offset hazard. + * D_8011F9C4 is fleet-constant (main-EXE data) and must NOT be remapped. + * + * match_one: MATCH (271 ins) against the CURRENT tree (§87 staleness re-checked, 2026-07-27). + * PIN-FREE, zero asm, offset-pure (s32 arg0 + raw offsets) — x138 template-safe. + * Provenance: this is the Phase-26 crack (.run/phase26-cracks/func_8015B950.c) re-gated verbatim, + * with ONE deliberate change: the definition's return type void -> s32. + * - `void func_8015B950(s32 arg0)` : MATCH (271 ins) [the Phase-26 form] + * - `s32 func_8015B950(s32 arg0)` : MATCH (271 ins) [shipped — §3a-1 void->s32 is byte-neutral] + * The fleet/engine_core.h canonical decl is `extern s32 func_8015B950(void);` (engine_core.h:1852), + * and the last bank attempt (.run/bank_func_8015B950.log) died on `conflicting types for + * func_8015B950`. Shipping the s32 return kills the §73 RETURN axis for free and leaves only the + * cheap T0 PARAMS axis for the ladder (fix_header_decl.py / --fix-def-sig / cast_call_sites). + * Both forms are byte-identical, so the orchestrator may swap the return type back at zero cost. + * + * SYMBOLS (§58 rules 1/2 — all splat spellings, all verified present): + * D_8018881C asm/ov_SC01_077/data/tail.data.s:4355 (the state-handler vtable) + * D_801887B0 asm/ov_SC01_077/data/tail.data.s:4293 + * D_8011F9C4 main-EXE data; spelled `extern s32 D_8011F9C4;` in 5+ already-banked TUs + * jtbl_801D8B74 asm/ov_SC01_077/data/tail14.data.s:15 (compiler jump table — not named in C) + * + * JTBL VERIFIED (§8a gate): compiled .rodata = exactly 0x1C B / 7 words, 7x R_MIPS_32 .text with + * addends [0x58,0x58,0x58,0xE0,0xF0,0x100,0x58] -> +0x8015B950 = [B9A8,B9A8,B9A8,BA30,BA40,BA50, + * B9A8] == the original words at 0x801D8B74..0x801D8B8C. Bound `sltiu $v0,$v1,0x7` matches. + * The raw dlabel's 8th word 0x00000000 is NOT an entry — it is the intra-TU `.align 3` pad of the + * B34/B54/B74 jtbl chain; the object can never emit it (maspsx drops .align), so it must stay in + * the post-carve RAW data piece (the §53/§62/§81 carve chain applies at bank time). + * + * Same family as the TU's own already-matched func_8015AE2C: 7-case switch on ((s32 (*)(s32))func_801619A4)() + * (0/1/2/6 shared, 3/4/5 own, no default block — out-of-range and every `break` fall to the + * after-switch join), then a chain of "state handler" tests, each dispatching + * D_8018881C[*(u16*)arg0](arg0) and returning. + * + * THREE LEVERS (draft -> MATCH in 3 compiles): + * + * 1. PROLOGUE CONSTANT = an INITIALIZED LOCAL, not a literal in the compare. + * Target opens with `lui $s2, 0xFFF5` in the *prologue*, used once ~200 ins later in + * `slt $v0,$s2,$s1`. No gcc-2.7.2 pass hoists a (set reg const_int) across basic blocks + * (loop.c needs a loop; cse/combine/sched never move insns between BBs) — so the insn must + * have been EMITTED in the first BB, i.e. the constant is a local initialized at the top of + * the function. cse then cannot fold it back into the compare: the `slt` operand predicate is + * `arith_operand`, which rejects a CONST_INT wider than 16 bits, so validate_change fails and + * the pseudo survives. Its live range spans every call -> global.c gives it a callee-saved reg. + * Writing `z > -0xB0000` inline instead emits the `lui` into the branch delay slot next to the + * compare (caller-saved $v0) and the function is 1 insn short. => `s32 lim = -0xB0000;` at top. + * + * 2. `lh` vs `lhu`: a short->short copy is a pure HImode move and gcc emits `lhu`. The target's + * `lh $v0,0x26($s0)` means the value passed through an SImode (int) temp: expand makes + * (set (reg:SI) (sign_extend (mem:HI))) + (set (mem:HI) (subreg:HI ...)), and combine cannot + * merge them (the merged form is mem<-mem, which no movhi accepts) so the sign-extending load + * survives. => route both halfword copies through the `s32 t` temp. + * + * 3. THE `goto` LAYOUT — dodging jump.c's store-flag conversion (jump.c:1005-1065). + * An if/else chain writing 0/1 into `doit` makes gcc collapse the last pair into + * `sltiu $v0,$v0,1`. jump.c fires that conversion when the insn immediately after a + * conditional jump is a lone `SET pseudo, CONST_INT` whose following simplejump targets the + * SAME label as the branch (jump.c:1038 `reallabelprev == temp || ... JUMP_LABEL(temp4) == + * JUMP_LABEL(insn)`) — exactly the shape of `if (c) x=0; else x=1;`. + * The target instead cross-jumps ALL the `doit=0` exits into ONE shared block placed after the + * `doit=1` fall-through; reorg's fill_slots_from_thread then COPIES that single set into all + * three branch delay slots and redirects each branch past it (which is why `addu $v0,$zero, + * $zero` appears 3x in delay slots and the shared block vanishes). A `goto zero;` / `goto one;` + * chain expresses that layout directly, and each conditional jump is then followed by a + * compare/call rather than a lone const set, so the store-flag conversion never triggers. + * GENERAL RULE: multiple predicates that all assign the SAME constant to one flag => write + * them as `goto` to a shared assignment, never as an if/else ladder. + */ +extern s32 D_8011F9C4; +extern s32 D_801887B0; + +extern s32 func_80161B18(void); +extern s32 func_801619A4(s32*); +extern s32 func_80149AA8(s32*); +extern void func_80149AD4(s32*); +extern s32 func_80149B54(s32*); +extern void func_80149BAC(s32*); +extern s32 func_801498E0(s32*); +extern s32 func_80149954(s32); +extern s32 func_80149A64(s32*); +extern void func_800CCCC0(s32 a0); +extern s32 func_80149CD4(s32 a0); +extern void func_8015E880(s32*); +extern s32 func_80149744(struct S_80149744*); +extern void func_80149788(void); +extern s32 func_801496D4(void*); +extern void func_80149704(void); +extern int func_80148AFC(void*); +extern void func_80146D90(s32 a0); +extern void func_80154150(s32 a0, s32 a1); +extern void func_801541D8(u8*, s32, s32); +extern s32 func_801488A8(u8*); +extern void func_80147078(s32*, s16); +extern void func_8015A264(void*); +extern s32 func_80013294(void*, void*); +extern void func_80159B70(void*); +extern s32 func_8016F1AC(void); +extern s32 func_80029178(s32 a0); +extern void func_80146DB8(s32*, s32*); +extern s32 func_80161CD0(s32, s32); +extern s32 func_80161208(s32 a0); +extern s32 func_801725A4(u8*); + +s32 func_8015B950(s32 arg0) +{ + + extern void (*D_8018881C[])(void *); + s16 sp10[4]; + s16 sp18[4]; + s32 t; + s32 z; + s32 doit; + s32 lim = -0xB0000; + + if (func_80161B18() != 0) { + return; + } + switch (((s32 (*)(s32))func_801619A4)(arg0)) { + case 0: + case 1: + case 2: + case 6: + if (((s32 (*)(s32))func_80149AA8)(arg0) != 0) { + D_8018881C[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149AD4)(arg0); + return; + } + if (((s32 (*)(s32))func_80149B54)(arg0) != 0) { + D_8018881C[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149BAC)(arg0); + return; + } + break; + case 3: + ((void (*)(s32))func_801498E0)(arg0); + break; + case 4: + ((void (*)(s32))func_80149954)(arg0); + break; + case 5: + if (((s32 (*)(s32))func_80149A64)(arg0) != 0) { + D_8018881C[*(u16 *)arg0]((void *)arg0); + func_800CCCC0(arg0); + return; + } + break; + } + if (func_80149CD4(arg0) != 0) { + D_8018881C[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_8015E880)(arg0); + return; + } + if (((s32 (*)(s32))func_80149744)(arg0) != 0) { + D_8018881C[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149788)(arg0); + return; + } + if (((s32 (*)(s32))func_801496D4)(arg0) != 0) { + D_8018881C[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149704)(arg0); + if (((u8)((s32 (*)(s32))func_80148AFC)(arg0)) == 0) { + func_80146D90(arg0); + } + if ((*(s32 *)(arg0 + 0x24) | *(s32 *)(arg0 + 0x2C)) != 0) { + func_80154150(arg0, 0xF); + } else { + ((void (*)(s32, s32, s32))func_801541D8)(arg0, 0xD, 6); + } + *(s32 *)(arg0 + 0x238) = 1; + return; + } + if (((s32 (*)(s32))func_801488A8)(arg0) != 0) { + sp10[0] = 0; + sp10[1] = 0; + sp10[2] = 0; + t = *(s16 *)(arg0 + 0x26); + sp18[0] = t; + sp18[1] = 0; + t = *(s16 *)(arg0 + 0x2E); + sp18[2] = t; + D_8018881C[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 1); + ((void (*)(s32))func_8015A264)(arg0); + t = -(((s32 (*)(s16 *, s16 *))func_80013294)(sp10, sp18) << 0x10); + if (t < *(s32 *)(arg0 + 0x2C)) { + *(s32 *)(arg0 + 0x2C) = t; + } + return; + } + if (*(u16 *)(arg0 + 0xB8) == 0x8000) { + D_8018881C[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 0); + ((void (*)(s32))func_80159B70)(arg0); + return; + } + z = *(s32 *)(arg0 + 0x2C); + if (func_8016F1AC() != 0) { + goto zero; + } + if (z <= lim) { + goto one; + } + if (D_8011F9C4 == 0) { + goto zero; + } + if (((u8)func_80029178(0x21)) != 0) { + goto zero; + } +one: + doit = 1; + goto join; +zero: + doit = 0; +join: + if (doit != 0) { + D_8018881C[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 0); + ((void (*)(s32))func_80159B70)(arg0); + func_80154150(arg0, 9); + ((void (*)(s32, s32 *))func_80146DB8)(arg0, &D_801887B0); + ((void (*)(s32, s32))func_80161CD0)(arg0, *(u16 *)(arg0 + 0x16E)); + return; + } + if (func_80161208(arg0) == 0) { + ((void (*)(s32))func_801725A4)(arg0); + } +} DEFINE_func_8015BD8C() /* dedup: shared engine-core @0x8015BD8C (src/shared) */ diff --git a/src/ov_SC03_103/ov_SC03_103_jr_8015AE2C.c b/src/ov_SC03_103/ov_SC03_103_jr_8015AE2C.c index 19aebdbb5..c74a92b10 100644 --- a/src/ov_SC03_103/ov_SC03_103_jr_8015AE2C.c +++ b/src/ov_SC03_103/ov_SC03_103_jr_8015AE2C.c @@ -1513,7 +1513,259 @@ DEFINE_func_8015B858() /* dedup: shared engine-core @0x8015B858 (src/shared) */ DEFINE_func_8015B8F8() /* dedup: shared engine-core @0x8015B8F8 (src/shared) */ -INCLUDE_ASM("asm/ov_SC03_103/nonmatchings/ov_SC03_103_jr_8015AE2C", func_8015B950); +extern s32 func_8015AE2C(); + +// @class: plumbing +// @stuck: none — MATCH (271/271, pin-free, zero asm). The ONLY residual is DEF-SIDE plumbing, and it is now named exactly: the in-TU instantiation `DEFINE_func_8015BEE4()` (engine_core.h:1851-1855) expands to `extern s32 func_8015B950(void);` INSIDE ov_SC01_077_jr_8015AE2C.c, ~14 lines BELOW this definition, so the 1-param def collides with a `(void)` prototype -> `conflicting types for func_8015B950` (.run/bank_func_8015B950.log). §73 PARAMS axis / T0. Surgical fix = §65b de-macroize that ONE instantiation (blast radius: this TU); the fleet-wide `(void)`->`()` header edit is §63 and must be R22-validated. +/* func_8015B950 (ov_SC01_077_jr_8015AE2C, 271 ins, jtbl_801D8B74) — SESSION-21 re-verified + * + * ── ROUND-2 INDEPENDENT RE-VERIFICATION (2026-07-27, fresh agent, §88e discipline) ───────────── + * match_one : MATCH (271 ins) against the CURRENT tree — §87 staleness re-checked today. + * .text size: compiled .text = 0x43C = 1084 B = 271 ins, EXACTLY the target's declared 0x43C + * ("nonmatching func_8015B950, 0x43C"). So this is NOT a §83a length drift hiding + * behind a zero count — the count is over equal-length streams. + * jtbl : RE-DECODED MECHANICALLY, not inherited. Compiled .rodata = 0x1C = 28 B = 7 words, + * 7x R_MIPS_32 -> .text with implicit addends [58,58,58,E0,F0,100,58]; +0x8015B950 + * = [8015B9A8, 8015B9A8, 8015B9A8, 8015BA30, 8015BA40, 8015BA50, 8015B9A8]. + * Diffed word-for-word against asm/ov_SC01_077/data/tail14.data.s:15-23 — 7/7 identical. + * symcheck : SYMS-DIFF target=35 draft=34, sole MISSING = jtbl_801D8B74. This is the §81 jr + * FALSE POSITIVE, re-confirmed here by reading the relocs: gcc emits its OWN table and + * references it with R_MIPS_HI16/LO16 against the SECTION `.rodata` (t.o +0x40/+0x48), + * so the splat's dlabel NAME can never appear in the draft object's relocation set. + * Nothing is dropped and nothing is invented: the draft's other 34 symbols are exactly + * the target's other 34. + * FAMILY : the x138 remap is clean and §84-safe. Every sibling is 271 ins with an IDENTICAL + * callee set; only THREE names vary per overlay — the two data labels and the jtbl: + * ov_SC01_077 D_80186760 / D_801867CC / jtbl_801D8B74 + * ov_SC03_099 D_80185A50 / D_80185ABC / jtbl_801BD898 + * ov_SC06_008 D_80187E44 / D_80187EB0 / jtbl_801A8734 + * The pair is always +0x6C apart, and NO literal in this draft encodes that distance + * (both labels are referenced by name), so there is no §84 derived-offset hazard. + * D_8011F9C4 is fleet-constant (main-EXE data) and must NOT be remapped. + * + * match_one: MATCH (271 ins) against the CURRENT tree (§87 staleness re-checked, 2026-07-27). + * PIN-FREE, zero asm, offset-pure (s32 arg0 + raw offsets) — x138 template-safe. + * Provenance: this is the Phase-26 crack (.run/phase26-cracks/func_8015B950.c) re-gated verbatim, + * with ONE deliberate change: the definition's return type void -> s32. + * - `void func_8015B950(s32 arg0)` : MATCH (271 ins) [the Phase-26 form] + * - `s32 func_8015B950(s32 arg0)` : MATCH (271 ins) [shipped — §3a-1 void->s32 is byte-neutral] + * The fleet/engine_core.h canonical decl is `extern s32 func_8015B950(void);` (engine_core.h:1852), + * and the last bank attempt (.run/bank_func_8015B950.log) died on `conflicting types for + * func_8015B950`. Shipping the s32 return kills the §73 RETURN axis for free and leaves only the + * cheap T0 PARAMS axis for the ladder (fix_header_decl.py / --fix-def-sig / cast_call_sites). + * Both forms are byte-identical, so the orchestrator may swap the return type back at zero cost. + * + * SYMBOLS (§58 rules 1/2 — all splat spellings, all verified present): + * D_801867CC asm/ov_SC01_077/data/tail.data.s:4355 (the state-handler vtable) + * D_80186760 asm/ov_SC01_077/data/tail.data.s:4293 + * D_8011F9C4 main-EXE data; spelled `extern s32 D_8011F9C4;` in 5+ already-banked TUs + * jtbl_801D8B74 asm/ov_SC01_077/data/tail14.data.s:15 (compiler jump table — not named in C) + * + * JTBL VERIFIED (§8a gate): compiled .rodata = exactly 0x1C B / 7 words, 7x R_MIPS_32 .text with + * addends [0x58,0x58,0x58,0xE0,0xF0,0x100,0x58] -> +0x8015B950 = [B9A8,B9A8,B9A8,BA30,BA40,BA50, + * B9A8] == the original words at 0x801D8B74..0x801D8B8C. Bound `sltiu $v0,$v1,0x7` matches. + * The raw dlabel's 8th word 0x00000000 is NOT an entry — it is the intra-TU `.align 3` pad of the + * B34/B54/B74 jtbl chain; the object can never emit it (maspsx drops .align), so it must stay in + * the post-carve RAW data piece (the §53/§62/§81 carve chain applies at bank time). + * + * Same family as the TU's own already-matched func_8015AE2C: 7-case switch on ((s32 (*)(s32))func_801619A4)() + * (0/1/2/6 shared, 3/4/5 own, no default block — out-of-range and every `break` fall to the + * after-switch join), then a chain of "state handler" tests, each dispatching + * D_801867CC[*(u16*)arg0](arg0) and returning. + * + * THREE LEVERS (draft -> MATCH in 3 compiles): + * + * 1. PROLOGUE CONSTANT = an INITIALIZED LOCAL, not a literal in the compare. + * Target opens with `lui $s2, 0xFFF5` in the *prologue*, used once ~200 ins later in + * `slt $v0,$s2,$s1`. No gcc-2.7.2 pass hoists a (set reg const_int) across basic blocks + * (loop.c needs a loop; cse/combine/sched never move insns between BBs) — so the insn must + * have been EMITTED in the first BB, i.e. the constant is a local initialized at the top of + * the function. cse then cannot fold it back into the compare: the `slt` operand predicate is + * `arith_operand`, which rejects a CONST_INT wider than 16 bits, so validate_change fails and + * the pseudo survives. Its live range spans every call -> global.c gives it a callee-saved reg. + * Writing `z > -0xB0000` inline instead emits the `lui` into the branch delay slot next to the + * compare (caller-saved $v0) and the function is 1 insn short. => `s32 lim = -0xB0000;` at top. + * + * 2. `lh` vs `lhu`: a short->short copy is a pure HImode move and gcc emits `lhu`. The target's + * `lh $v0,0x26($s0)` means the value passed through an SImode (int) temp: expand makes + * (set (reg:SI) (sign_extend (mem:HI))) + (set (mem:HI) (subreg:HI ...)), and combine cannot + * merge them (the merged form is mem<-mem, which no movhi accepts) so the sign-extending load + * survives. => route both halfword copies through the `s32 t` temp. + * + * 3. THE `goto` LAYOUT — dodging jump.c's store-flag conversion (jump.c:1005-1065). + * An if/else chain writing 0/1 into `doit` makes gcc collapse the last pair into + * `sltiu $v0,$v0,1`. jump.c fires that conversion when the insn immediately after a + * conditional jump is a lone `SET pseudo, CONST_INT` whose following simplejump targets the + * SAME label as the branch (jump.c:1038 `reallabelprev == temp || ... JUMP_LABEL(temp4) == + * JUMP_LABEL(insn)`) — exactly the shape of `if (c) x=0; else x=1;`. + * The target instead cross-jumps ALL the `doit=0` exits into ONE shared block placed after the + * `doit=1` fall-through; reorg's fill_slots_from_thread then COPIES that single set into all + * three branch delay slots and redirects each branch past it (which is why `addu $v0,$zero, + * $zero` appears 3x in delay slots and the shared block vanishes). A `goto zero;` / `goto one;` + * chain expresses that layout directly, and each conditional jump is then followed by a + * compare/call rather than a lone const set, so the store-flag conversion never triggers. + * GENERAL RULE: multiple predicates that all assign the SAME constant to one flag => write + * them as `goto` to a shared assignment, never as an if/else ladder. + */ +extern s32 D_8011F9C4; +extern s32 D_80186760; + +extern s32 func_80161B18(void); +extern s32 func_801619A4(s32*); +extern s32 func_80149AA8(s32*); +extern void func_80149AD4(s32*); +extern s32 func_80149B54(s32*); +extern void func_80149BAC(s32*); +extern s32 func_801498E0(s32*); +extern s32 func_80149954(s32); +extern s32 func_80149A64(s32*); +extern void func_800CCCC0(s32 a0); +extern s32 func_80149CD4(s32 a0); +extern void func_8015E880(s32*); +extern s32 func_80149744(struct S_80149744*); +extern void func_80149788(void); +extern s32 func_801496D4(void*); +extern void func_80149704(void); +extern int func_80148AFC(void*); +extern void func_80146D90(s32 a0); +extern void func_80154150(s32 a0, s32 a1); +extern void func_801541D8(u8*, s32, s32); +extern s32 func_801488A8(u8*); +extern void func_80147078(s32*, s16); +extern void func_8015A264(void*); +extern s32 func_80013294(void*, void*); +extern void func_80159B70(void*); +extern s32 func_8016F1AC(void); +extern s32 func_80029178(s32 a0); +extern void func_80146DB8(s32*, s32*); +extern s32 func_80161CD0(s32, s32); +extern s32 func_80161208(s32 a0); +extern s32 func_801725A4(u8*); + +s32 func_8015B950(s32 arg0) +{ + + extern void (*D_801867CC[])(void *); + s16 sp10[4]; + s16 sp18[4]; + s32 t; + s32 z; + s32 doit; + s32 lim = -0xB0000; + + if (func_80161B18() != 0) { + return; + } + switch (((s32 (*)(s32))func_801619A4)(arg0)) { + case 0: + case 1: + case 2: + case 6: + if (((s32 (*)(s32))func_80149AA8)(arg0) != 0) { + D_801867CC[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149AD4)(arg0); + return; + } + if (((s32 (*)(s32))func_80149B54)(arg0) != 0) { + D_801867CC[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149BAC)(arg0); + return; + } + break; + case 3: + ((void (*)(s32))func_801498E0)(arg0); + break; + case 4: + ((void (*)(s32))func_80149954)(arg0); + break; + case 5: + if (((s32 (*)(s32))func_80149A64)(arg0) != 0) { + D_801867CC[*(u16 *)arg0]((void *)arg0); + func_800CCCC0(arg0); + return; + } + break; + } + if (func_80149CD4(arg0) != 0) { + D_801867CC[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_8015E880)(arg0); + return; + } + if (((s32 (*)(s32))func_80149744)(arg0) != 0) { + D_801867CC[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149788)(arg0); + return; + } + if (((s32 (*)(s32))func_801496D4)(arg0) != 0) { + D_801867CC[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149704)(arg0); + if (((u8)((s32 (*)(s32))func_80148AFC)(arg0)) == 0) { + func_80146D90(arg0); + } + if ((*(s32 *)(arg0 + 0x24) | *(s32 *)(arg0 + 0x2C)) != 0) { + func_80154150(arg0, 0xF); + } else { + ((void (*)(s32, s32, s32))func_801541D8)(arg0, 0xD, 6); + } + *(s32 *)(arg0 + 0x238) = 1; + return; + } + if (((s32 (*)(s32))func_801488A8)(arg0) != 0) { + sp10[0] = 0; + sp10[1] = 0; + sp10[2] = 0; + t = *(s16 *)(arg0 + 0x26); + sp18[0] = t; + sp18[1] = 0; + t = *(s16 *)(arg0 + 0x2E); + sp18[2] = t; + D_801867CC[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 1); + ((void (*)(s32))func_8015A264)(arg0); + t = -(((s32 (*)(s16 *, s16 *))func_80013294)(sp10, sp18) << 0x10); + if (t < *(s32 *)(arg0 + 0x2C)) { + *(s32 *)(arg0 + 0x2C) = t; + } + return; + } + if (*(u16 *)(arg0 + 0xB8) == 0x8000) { + D_801867CC[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 0); + ((void (*)(s32))func_80159B70)(arg0); + return; + } + z = *(s32 *)(arg0 + 0x2C); + if (func_8016F1AC() != 0) { + goto zero; + } + if (z <= lim) { + goto one; + } + if (D_8011F9C4 == 0) { + goto zero; + } + if (((u8)func_80029178(0x21)) != 0) { + goto zero; + } +one: + doit = 1; + goto join; +zero: + doit = 0; +join: + if (doit != 0) { + D_801867CC[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 0); + ((void (*)(s32))func_80159B70)(arg0); + func_80154150(arg0, 9); + ((void (*)(s32, s32 *))func_80146DB8)(arg0, &D_80186760); + ((void (*)(s32, s32))func_80161CD0)(arg0, *(u16 *)(arg0 + 0x16E)); + return; + } + if (func_80161208(arg0) == 0) { + ((void (*)(s32))func_801725A4)(arg0); + } +} DEFINE_func_8015BD8C() /* dedup: shared engine-core @0x8015BD8C (src/shared) */ diff --git a/src/ov_SC03_104/ov_SC03_104_jr_8015AE2C.c b/src/ov_SC03_104/ov_SC03_104_jr_8015AE2C.c index 322dcb12a..424db4573 100644 --- a/src/ov_SC03_104/ov_SC03_104_jr_8015AE2C.c +++ b/src/ov_SC03_104/ov_SC03_104_jr_8015AE2C.c @@ -1513,7 +1513,259 @@ DEFINE_func_8015B858() /* dedup: shared engine-core @0x8015B858 (src/shared) */ DEFINE_func_8015B8F8() /* dedup: shared engine-core @0x8015B8F8 (src/shared) */ -INCLUDE_ASM("asm/ov_SC03_104/nonmatchings/ov_SC03_104_jr_8015AE2C", func_8015B950); +extern s32 func_8015AE2C(); + +// @class: plumbing +// @stuck: none — MATCH (271/271, pin-free, zero asm). The ONLY residual is DEF-SIDE plumbing, and it is now named exactly: the in-TU instantiation `DEFINE_func_8015BEE4()` (engine_core.h:1851-1855) expands to `extern s32 func_8015B950(void);` INSIDE ov_SC01_077_jr_8015AE2C.c, ~14 lines BELOW this definition, so the 1-param def collides with a `(void)` prototype -> `conflicting types for func_8015B950` (.run/bank_func_8015B950.log). §73 PARAMS axis / T0. Surgical fix = §65b de-macroize that ONE instantiation (blast radius: this TU); the fleet-wide `(void)`->`()` header edit is §63 and must be R22-validated. +/* func_8015B950 (ov_SC01_077_jr_8015AE2C, 271 ins, jtbl_801D8B74) — SESSION-21 re-verified + * + * ── ROUND-2 INDEPENDENT RE-VERIFICATION (2026-07-27, fresh agent, §88e discipline) ───────────── + * match_one : MATCH (271 ins) against the CURRENT tree — §87 staleness re-checked today. + * .text size: compiled .text = 0x43C = 1084 B = 271 ins, EXACTLY the target's declared 0x43C + * ("nonmatching func_8015B950, 0x43C"). So this is NOT a §83a length drift hiding + * behind a zero count — the count is over equal-length streams. + * jtbl : RE-DECODED MECHANICALLY, not inherited. Compiled .rodata = 0x1C = 28 B = 7 words, + * 7x R_MIPS_32 -> .text with implicit addends [58,58,58,E0,F0,100,58]; +0x8015B950 + * = [8015B9A8, 8015B9A8, 8015B9A8, 8015BA30, 8015BA40, 8015BA50, 8015B9A8]. + * Diffed word-for-word against asm/ov_SC01_077/data/tail14.data.s:15-23 — 7/7 identical. + * symcheck : SYMS-DIFF target=35 draft=34, sole MISSING = jtbl_801D8B74. This is the §81 jr + * FALSE POSITIVE, re-confirmed here by reading the relocs: gcc emits its OWN table and + * references it with R_MIPS_HI16/LO16 against the SECTION `.rodata` (t.o +0x40/+0x48), + * so the splat's dlabel NAME can never appear in the draft object's relocation set. + * Nothing is dropped and nothing is invented: the draft's other 34 symbols are exactly + * the target's other 34. + * FAMILY : the x138 remap is clean and §84-safe. Every sibling is 271 ins with an IDENTICAL + * callee set; only THREE names vary per overlay — the two data labels and the jtbl: + * ov_SC01_077 D_8018D2F0 / D_8018D35C / jtbl_801D8B74 + * ov_SC03_099 D_80185A50 / D_80185ABC / jtbl_801BD898 + * ov_SC06_008 D_80187E44 / D_80187EB0 / jtbl_801A8734 + * The pair is always +0x6C apart, and NO literal in this draft encodes that distance + * (both labels are referenced by name), so there is no §84 derived-offset hazard. + * D_8011F9C4 is fleet-constant (main-EXE data) and must NOT be remapped. + * + * match_one: MATCH (271 ins) against the CURRENT tree (§87 staleness re-checked, 2026-07-27). + * PIN-FREE, zero asm, offset-pure (s32 arg0 + raw offsets) — x138 template-safe. + * Provenance: this is the Phase-26 crack (.run/phase26-cracks/func_8015B950.c) re-gated verbatim, + * with ONE deliberate change: the definition's return type void -> s32. + * - `void func_8015B950(s32 arg0)` : MATCH (271 ins) [the Phase-26 form] + * - `s32 func_8015B950(s32 arg0)` : MATCH (271 ins) [shipped — §3a-1 void->s32 is byte-neutral] + * The fleet/engine_core.h canonical decl is `extern s32 func_8015B950(void);` (engine_core.h:1852), + * and the last bank attempt (.run/bank_func_8015B950.log) died on `conflicting types for + * func_8015B950`. Shipping the s32 return kills the §73 RETURN axis for free and leaves only the + * cheap T0 PARAMS axis for the ladder (fix_header_decl.py / --fix-def-sig / cast_call_sites). + * Both forms are byte-identical, so the orchestrator may swap the return type back at zero cost. + * + * SYMBOLS (§58 rules 1/2 — all splat spellings, all verified present): + * D_8018D35C asm/ov_SC01_077/data/tail.data.s:4355 (the state-handler vtable) + * D_8018D2F0 asm/ov_SC01_077/data/tail.data.s:4293 + * D_8011F9C4 main-EXE data; spelled `extern s32 D_8011F9C4;` in 5+ already-banked TUs + * jtbl_801D8B74 asm/ov_SC01_077/data/tail14.data.s:15 (compiler jump table — not named in C) + * + * JTBL VERIFIED (§8a gate): compiled .rodata = exactly 0x1C B / 7 words, 7x R_MIPS_32 .text with + * addends [0x58,0x58,0x58,0xE0,0xF0,0x100,0x58] -> +0x8015B950 = [B9A8,B9A8,B9A8,BA30,BA40,BA50, + * B9A8] == the original words at 0x801D8B74..0x801D8B8C. Bound `sltiu $v0,$v1,0x7` matches. + * The raw dlabel's 8th word 0x00000000 is NOT an entry — it is the intra-TU `.align 3` pad of the + * B34/B54/B74 jtbl chain; the object can never emit it (maspsx drops .align), so it must stay in + * the post-carve RAW data piece (the §53/§62/§81 carve chain applies at bank time). + * + * Same family as the TU's own already-matched func_8015AE2C: 7-case switch on ((s32 (*)(s32))func_801619A4)() + * (0/1/2/6 shared, 3/4/5 own, no default block — out-of-range and every `break` fall to the + * after-switch join), then a chain of "state handler" tests, each dispatching + * D_8018D35C[*(u16*)arg0](arg0) and returning. + * + * THREE LEVERS (draft -> MATCH in 3 compiles): + * + * 1. PROLOGUE CONSTANT = an INITIALIZED LOCAL, not a literal in the compare. + * Target opens with `lui $s2, 0xFFF5` in the *prologue*, used once ~200 ins later in + * `slt $v0,$s2,$s1`. No gcc-2.7.2 pass hoists a (set reg const_int) across basic blocks + * (loop.c needs a loop; cse/combine/sched never move insns between BBs) — so the insn must + * have been EMITTED in the first BB, i.e. the constant is a local initialized at the top of + * the function. cse then cannot fold it back into the compare: the `slt` operand predicate is + * `arith_operand`, which rejects a CONST_INT wider than 16 bits, so validate_change fails and + * the pseudo survives. Its live range spans every call -> global.c gives it a callee-saved reg. + * Writing `z > -0xB0000` inline instead emits the `lui` into the branch delay slot next to the + * compare (caller-saved $v0) and the function is 1 insn short. => `s32 lim = -0xB0000;` at top. + * + * 2. `lh` vs `lhu`: a short->short copy is a pure HImode move and gcc emits `lhu`. The target's + * `lh $v0,0x26($s0)` means the value passed through an SImode (int) temp: expand makes + * (set (reg:SI) (sign_extend (mem:HI))) + (set (mem:HI) (subreg:HI ...)), and combine cannot + * merge them (the merged form is mem<-mem, which no movhi accepts) so the sign-extending load + * survives. => route both halfword copies through the `s32 t` temp. + * + * 3. THE `goto` LAYOUT — dodging jump.c's store-flag conversion (jump.c:1005-1065). + * An if/else chain writing 0/1 into `doit` makes gcc collapse the last pair into + * `sltiu $v0,$v0,1`. jump.c fires that conversion when the insn immediately after a + * conditional jump is a lone `SET pseudo, CONST_INT` whose following simplejump targets the + * SAME label as the branch (jump.c:1038 `reallabelprev == temp || ... JUMP_LABEL(temp4) == + * JUMP_LABEL(insn)`) — exactly the shape of `if (c) x=0; else x=1;`. + * The target instead cross-jumps ALL the `doit=0` exits into ONE shared block placed after the + * `doit=1` fall-through; reorg's fill_slots_from_thread then COPIES that single set into all + * three branch delay slots and redirects each branch past it (which is why `addu $v0,$zero, + * $zero` appears 3x in delay slots and the shared block vanishes). A `goto zero;` / `goto one;` + * chain expresses that layout directly, and each conditional jump is then followed by a + * compare/call rather than a lone const set, so the store-flag conversion never triggers. + * GENERAL RULE: multiple predicates that all assign the SAME constant to one flag => write + * them as `goto` to a shared assignment, never as an if/else ladder. + */ +extern s32 D_8011F9C4; +extern s32 D_8018D2F0; + +extern s32 func_80161B18(void); +extern s32 func_801619A4(s32*); +extern s32 func_80149AA8(s32*); +extern void func_80149AD4(s32*); +extern s32 func_80149B54(s32*); +extern void func_80149BAC(s32*); +extern s32 func_801498E0(s32*); +extern s32 func_80149954(s32); +extern s32 func_80149A64(s32*); +extern void func_800CCCC0(s32 a0); +extern s32 func_80149CD4(s32 a0); +extern void func_8015E880(s32*); +extern s32 func_80149744(struct S_80149744*); +extern void func_80149788(void); +extern s32 func_801496D4(void*); +extern void func_80149704(void); +extern int func_80148AFC(void*); +extern void func_80146D90(s32 a0); +extern void func_80154150(s32 a0, s32 a1); +extern void func_801541D8(u8*, s32, s32); +extern s32 func_801488A8(u8*); +extern void func_80147078(s32*, s16); +extern void func_8015A264(void*); +extern s32 func_80013294(void*, void*); +extern void func_80159B70(void*); +extern s32 func_8016F1AC(void); +extern s32 func_80029178(s32 a0); +extern void func_80146DB8(s32*, s32*); +extern s32 func_80161CD0(s32, s32); +extern s32 func_80161208(s32 a0); +extern s32 func_801725A4(u8*); + +s32 func_8015B950(s32 arg0) +{ + + extern void (*D_8018D35C[])(void *); + s16 sp10[4]; + s16 sp18[4]; + s32 t; + s32 z; + s32 doit; + s32 lim = -0xB0000; + + if (func_80161B18() != 0) { + return; + } + switch (((s32 (*)(s32))func_801619A4)(arg0)) { + case 0: + case 1: + case 2: + case 6: + if (((s32 (*)(s32))func_80149AA8)(arg0) != 0) { + D_8018D35C[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149AD4)(arg0); + return; + } + if (((s32 (*)(s32))func_80149B54)(arg0) != 0) { + D_8018D35C[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149BAC)(arg0); + return; + } + break; + case 3: + ((void (*)(s32))func_801498E0)(arg0); + break; + case 4: + ((void (*)(s32))func_80149954)(arg0); + break; + case 5: + if (((s32 (*)(s32))func_80149A64)(arg0) != 0) { + D_8018D35C[*(u16 *)arg0]((void *)arg0); + func_800CCCC0(arg0); + return; + } + break; + } + if (func_80149CD4(arg0) != 0) { + D_8018D35C[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_8015E880)(arg0); + return; + } + if (((s32 (*)(s32))func_80149744)(arg0) != 0) { + D_8018D35C[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149788)(arg0); + return; + } + if (((s32 (*)(s32))func_801496D4)(arg0) != 0) { + D_8018D35C[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149704)(arg0); + if (((u8)((s32 (*)(s32))func_80148AFC)(arg0)) == 0) { + func_80146D90(arg0); + } + if ((*(s32 *)(arg0 + 0x24) | *(s32 *)(arg0 + 0x2C)) != 0) { + func_80154150(arg0, 0xF); + } else { + ((void (*)(s32, s32, s32))func_801541D8)(arg0, 0xD, 6); + } + *(s32 *)(arg0 + 0x238) = 1; + return; + } + if (((s32 (*)(s32))func_801488A8)(arg0) != 0) { + sp10[0] = 0; + sp10[1] = 0; + sp10[2] = 0; + t = *(s16 *)(arg0 + 0x26); + sp18[0] = t; + sp18[1] = 0; + t = *(s16 *)(arg0 + 0x2E); + sp18[2] = t; + D_8018D35C[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 1); + ((void (*)(s32))func_8015A264)(arg0); + t = -(((s32 (*)(s16 *, s16 *))func_80013294)(sp10, sp18) << 0x10); + if (t < *(s32 *)(arg0 + 0x2C)) { + *(s32 *)(arg0 + 0x2C) = t; + } + return; + } + if (*(u16 *)(arg0 + 0xB8) == 0x8000) { + D_8018D35C[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 0); + ((void (*)(s32))func_80159B70)(arg0); + return; + } + z = *(s32 *)(arg0 + 0x2C); + if (func_8016F1AC() != 0) { + goto zero; + } + if (z <= lim) { + goto one; + } + if (D_8011F9C4 == 0) { + goto zero; + } + if (((u8)func_80029178(0x21)) != 0) { + goto zero; + } +one: + doit = 1; + goto join; +zero: + doit = 0; +join: + if (doit != 0) { + D_8018D35C[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 0); + ((void (*)(s32))func_80159B70)(arg0); + func_80154150(arg0, 9); + ((void (*)(s32, s32 *))func_80146DB8)(arg0, &D_8018D2F0); + ((void (*)(s32, s32))func_80161CD0)(arg0, *(u16 *)(arg0 + 0x16E)); + return; + } + if (func_80161208(arg0) == 0) { + ((void (*)(s32))func_801725A4)(arg0); + } +} DEFINE_func_8015BD8C() /* dedup: shared engine-core @0x8015BD8C (src/shared) */ diff --git a/src/ov_SC03_105/ov_SC03_105_jr_8015AE2C.c b/src/ov_SC03_105/ov_SC03_105_jr_8015AE2C.c index 90ab9fa3a..e56b835a2 100644 --- a/src/ov_SC03_105/ov_SC03_105_jr_8015AE2C.c +++ b/src/ov_SC03_105/ov_SC03_105_jr_8015AE2C.c @@ -1513,7 +1513,259 @@ DEFINE_func_8015B858() /* dedup: shared engine-core @0x8015B858 (src/shared) */ DEFINE_func_8015B8F8() /* dedup: shared engine-core @0x8015B8F8 (src/shared) */ -INCLUDE_ASM("asm/ov_SC03_105/nonmatchings/ov_SC03_105_jr_8015AE2C", func_8015B950); +extern s32 func_8015AE2C(); + +// @class: plumbing +// @stuck: none — MATCH (271/271, pin-free, zero asm). The ONLY residual is DEF-SIDE plumbing, and it is now named exactly: the in-TU instantiation `DEFINE_func_8015BEE4()` (engine_core.h:1851-1855) expands to `extern s32 func_8015B950(void);` INSIDE ov_SC01_077_jr_8015AE2C.c, ~14 lines BELOW this definition, so the 1-param def collides with a `(void)` prototype -> `conflicting types for func_8015B950` (.run/bank_func_8015B950.log). §73 PARAMS axis / T0. Surgical fix = §65b de-macroize that ONE instantiation (blast radius: this TU); the fleet-wide `(void)`->`()` header edit is §63 and must be R22-validated. +/* func_8015B950 (ov_SC01_077_jr_8015AE2C, 271 ins, jtbl_801D8B74) — SESSION-21 re-verified + * + * ── ROUND-2 INDEPENDENT RE-VERIFICATION (2026-07-27, fresh agent, §88e discipline) ───────────── + * match_one : MATCH (271 ins) against the CURRENT tree — §87 staleness re-checked today. + * .text size: compiled .text = 0x43C = 1084 B = 271 ins, EXACTLY the target's declared 0x43C + * ("nonmatching func_8015B950, 0x43C"). So this is NOT a §83a length drift hiding + * behind a zero count — the count is over equal-length streams. + * jtbl : RE-DECODED MECHANICALLY, not inherited. Compiled .rodata = 0x1C = 28 B = 7 words, + * 7x R_MIPS_32 -> .text with implicit addends [58,58,58,E0,F0,100,58]; +0x8015B950 + * = [8015B9A8, 8015B9A8, 8015B9A8, 8015BA30, 8015BA40, 8015BA50, 8015B9A8]. + * Diffed word-for-word against asm/ov_SC01_077/data/tail14.data.s:15-23 — 7/7 identical. + * symcheck : SYMS-DIFF target=35 draft=34, sole MISSING = jtbl_801D8B74. This is the §81 jr + * FALSE POSITIVE, re-confirmed here by reading the relocs: gcc emits its OWN table and + * references it with R_MIPS_HI16/LO16 against the SECTION `.rodata` (t.o +0x40/+0x48), + * so the splat's dlabel NAME can never appear in the draft object's relocation set. + * Nothing is dropped and nothing is invented: the draft's other 34 symbols are exactly + * the target's other 34. + * FAMILY : the x138 remap is clean and §84-safe. Every sibling is 271 ins with an IDENTICAL + * callee set; only THREE names vary per overlay — the two data labels and the jtbl: + * ov_SC01_077 D_8018C978 / D_8018C9E4 / jtbl_801D8B74 + * ov_SC03_099 D_80185A50 / D_80185ABC / jtbl_801BD898 + * ov_SC06_008 D_80187E44 / D_80187EB0 / jtbl_801A8734 + * The pair is always +0x6C apart, and NO literal in this draft encodes that distance + * (both labels are referenced by name), so there is no §84 derived-offset hazard. + * D_8011F9C4 is fleet-constant (main-EXE data) and must NOT be remapped. + * + * match_one: MATCH (271 ins) against the CURRENT tree (§87 staleness re-checked, 2026-07-27). + * PIN-FREE, zero asm, offset-pure (s32 arg0 + raw offsets) — x138 template-safe. + * Provenance: this is the Phase-26 crack (.run/phase26-cracks/func_8015B950.c) re-gated verbatim, + * with ONE deliberate change: the definition's return type void -> s32. + * - `void func_8015B950(s32 arg0)` : MATCH (271 ins) [the Phase-26 form] + * - `s32 func_8015B950(s32 arg0)` : MATCH (271 ins) [shipped — §3a-1 void->s32 is byte-neutral] + * The fleet/engine_core.h canonical decl is `extern s32 func_8015B950(void);` (engine_core.h:1852), + * and the last bank attempt (.run/bank_func_8015B950.log) died on `conflicting types for + * func_8015B950`. Shipping the s32 return kills the §73 RETURN axis for free and leaves only the + * cheap T0 PARAMS axis for the ladder (fix_header_decl.py / --fix-def-sig / cast_call_sites). + * Both forms are byte-identical, so the orchestrator may swap the return type back at zero cost. + * + * SYMBOLS (§58 rules 1/2 — all splat spellings, all verified present): + * D_8018C9E4 asm/ov_SC01_077/data/tail.data.s:4355 (the state-handler vtable) + * D_8018C978 asm/ov_SC01_077/data/tail.data.s:4293 + * D_8011F9C4 main-EXE data; spelled `extern s32 D_8011F9C4;` in 5+ already-banked TUs + * jtbl_801D8B74 asm/ov_SC01_077/data/tail14.data.s:15 (compiler jump table — not named in C) + * + * JTBL VERIFIED (§8a gate): compiled .rodata = exactly 0x1C B / 7 words, 7x R_MIPS_32 .text with + * addends [0x58,0x58,0x58,0xE0,0xF0,0x100,0x58] -> +0x8015B950 = [B9A8,B9A8,B9A8,BA30,BA40,BA50, + * B9A8] == the original words at 0x801D8B74..0x801D8B8C. Bound `sltiu $v0,$v1,0x7` matches. + * The raw dlabel's 8th word 0x00000000 is NOT an entry — it is the intra-TU `.align 3` pad of the + * B34/B54/B74 jtbl chain; the object can never emit it (maspsx drops .align), so it must stay in + * the post-carve RAW data piece (the §53/§62/§81 carve chain applies at bank time). + * + * Same family as the TU's own already-matched func_8015AE2C: 7-case switch on ((s32 (*)(s32))func_801619A4)() + * (0/1/2/6 shared, 3/4/5 own, no default block — out-of-range and every `break` fall to the + * after-switch join), then a chain of "state handler" tests, each dispatching + * D_8018C9E4[*(u16*)arg0](arg0) and returning. + * + * THREE LEVERS (draft -> MATCH in 3 compiles): + * + * 1. PROLOGUE CONSTANT = an INITIALIZED LOCAL, not a literal in the compare. + * Target opens with `lui $s2, 0xFFF5` in the *prologue*, used once ~200 ins later in + * `slt $v0,$s2,$s1`. No gcc-2.7.2 pass hoists a (set reg const_int) across basic blocks + * (loop.c needs a loop; cse/combine/sched never move insns between BBs) — so the insn must + * have been EMITTED in the first BB, i.e. the constant is a local initialized at the top of + * the function. cse then cannot fold it back into the compare: the `slt` operand predicate is + * `arith_operand`, which rejects a CONST_INT wider than 16 bits, so validate_change fails and + * the pseudo survives. Its live range spans every call -> global.c gives it a callee-saved reg. + * Writing `z > -0xB0000` inline instead emits the `lui` into the branch delay slot next to the + * compare (caller-saved $v0) and the function is 1 insn short. => `s32 lim = -0xB0000;` at top. + * + * 2. `lh` vs `lhu`: a short->short copy is a pure HImode move and gcc emits `lhu`. The target's + * `lh $v0,0x26($s0)` means the value passed through an SImode (int) temp: expand makes + * (set (reg:SI) (sign_extend (mem:HI))) + (set (mem:HI) (subreg:HI ...)), and combine cannot + * merge them (the merged form is mem<-mem, which no movhi accepts) so the sign-extending load + * survives. => route both halfword copies through the `s32 t` temp. + * + * 3. THE `goto` LAYOUT — dodging jump.c's store-flag conversion (jump.c:1005-1065). + * An if/else chain writing 0/1 into `doit` makes gcc collapse the last pair into + * `sltiu $v0,$v0,1`. jump.c fires that conversion when the insn immediately after a + * conditional jump is a lone `SET pseudo, CONST_INT` whose following simplejump targets the + * SAME label as the branch (jump.c:1038 `reallabelprev == temp || ... JUMP_LABEL(temp4) == + * JUMP_LABEL(insn)`) — exactly the shape of `if (c) x=0; else x=1;`. + * The target instead cross-jumps ALL the `doit=0` exits into ONE shared block placed after the + * `doit=1` fall-through; reorg's fill_slots_from_thread then COPIES that single set into all + * three branch delay slots and redirects each branch past it (which is why `addu $v0,$zero, + * $zero` appears 3x in delay slots and the shared block vanishes). A `goto zero;` / `goto one;` + * chain expresses that layout directly, and each conditional jump is then followed by a + * compare/call rather than a lone const set, so the store-flag conversion never triggers. + * GENERAL RULE: multiple predicates that all assign the SAME constant to one flag => write + * them as `goto` to a shared assignment, never as an if/else ladder. + */ +extern s32 D_8011F9C4; +extern s32 D_8018C978; + +extern s32 func_80161B18(void); +extern s32 func_801619A4(s32*); +extern s32 func_80149AA8(s32*); +extern void func_80149AD4(s32*); +extern s32 func_80149B54(s32*); +extern void func_80149BAC(s32*); +extern s32 func_801498E0(s32*); +extern s32 func_80149954(s32); +extern s32 func_80149A64(s32*); +extern void func_800CCCC0(s32 a0); +extern s32 func_80149CD4(s32 a0); +extern void func_8015E880(s32*); +extern s32 func_80149744(struct S_80149744*); +extern void func_80149788(void); +extern s32 func_801496D4(void*); +extern void func_80149704(void); +extern int func_80148AFC(void*); +extern void func_80146D90(s32 a0); +extern void func_80154150(s32 a0, s32 a1); +extern void func_801541D8(u8*, s32, s32); +extern s32 func_801488A8(u8*); +extern void func_80147078(s32*, s16); +extern void func_8015A264(void*); +extern s32 func_80013294(void*, void*); +extern void func_80159B70(void*); +extern s32 func_8016F1AC(void); +extern s32 func_80029178(s32 a0); +extern void func_80146DB8(s32*, s32*); +extern s32 func_80161CD0(s32, s32); +extern s32 func_80161208(s32 a0); +extern s32 func_801725A4(u8*); + +s32 func_8015B950(s32 arg0) +{ + + extern void (*D_8018C9E4[])(void *); + s16 sp10[4]; + s16 sp18[4]; + s32 t; + s32 z; + s32 doit; + s32 lim = -0xB0000; + + if (func_80161B18() != 0) { + return; + } + switch (((s32 (*)(s32))func_801619A4)(arg0)) { + case 0: + case 1: + case 2: + case 6: + if (((s32 (*)(s32))func_80149AA8)(arg0) != 0) { + D_8018C9E4[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149AD4)(arg0); + return; + } + if (((s32 (*)(s32))func_80149B54)(arg0) != 0) { + D_8018C9E4[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149BAC)(arg0); + return; + } + break; + case 3: + ((void (*)(s32))func_801498E0)(arg0); + break; + case 4: + ((void (*)(s32))func_80149954)(arg0); + break; + case 5: + if (((s32 (*)(s32))func_80149A64)(arg0) != 0) { + D_8018C9E4[*(u16 *)arg0]((void *)arg0); + func_800CCCC0(arg0); + return; + } + break; + } + if (func_80149CD4(arg0) != 0) { + D_8018C9E4[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_8015E880)(arg0); + return; + } + if (((s32 (*)(s32))func_80149744)(arg0) != 0) { + D_8018C9E4[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149788)(arg0); + return; + } + if (((s32 (*)(s32))func_801496D4)(arg0) != 0) { + D_8018C9E4[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149704)(arg0); + if (((u8)((s32 (*)(s32))func_80148AFC)(arg0)) == 0) { + func_80146D90(arg0); + } + if ((*(s32 *)(arg0 + 0x24) | *(s32 *)(arg0 + 0x2C)) != 0) { + func_80154150(arg0, 0xF); + } else { + ((void (*)(s32, s32, s32))func_801541D8)(arg0, 0xD, 6); + } + *(s32 *)(arg0 + 0x238) = 1; + return; + } + if (((s32 (*)(s32))func_801488A8)(arg0) != 0) { + sp10[0] = 0; + sp10[1] = 0; + sp10[2] = 0; + t = *(s16 *)(arg0 + 0x26); + sp18[0] = t; + sp18[1] = 0; + t = *(s16 *)(arg0 + 0x2E); + sp18[2] = t; + D_8018C9E4[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 1); + ((void (*)(s32))func_8015A264)(arg0); + t = -(((s32 (*)(s16 *, s16 *))func_80013294)(sp10, sp18) << 0x10); + if (t < *(s32 *)(arg0 + 0x2C)) { + *(s32 *)(arg0 + 0x2C) = t; + } + return; + } + if (*(u16 *)(arg0 + 0xB8) == 0x8000) { + D_8018C9E4[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 0); + ((void (*)(s32))func_80159B70)(arg0); + return; + } + z = *(s32 *)(arg0 + 0x2C); + if (func_8016F1AC() != 0) { + goto zero; + } + if (z <= lim) { + goto one; + } + if (D_8011F9C4 == 0) { + goto zero; + } + if (((u8)func_80029178(0x21)) != 0) { + goto zero; + } +one: + doit = 1; + goto join; +zero: + doit = 0; +join: + if (doit != 0) { + D_8018C9E4[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 0); + ((void (*)(s32))func_80159B70)(arg0); + func_80154150(arg0, 9); + ((void (*)(s32, s32 *))func_80146DB8)(arg0, &D_8018C978); + ((void (*)(s32, s32))func_80161CD0)(arg0, *(u16 *)(arg0 + 0x16E)); + return; + } + if (func_80161208(arg0) == 0) { + ((void (*)(s32))func_801725A4)(arg0); + } +} DEFINE_func_8015BD8C() /* dedup: shared engine-core @0x8015BD8C (src/shared) */ diff --git a/src/ov_SC03_108/ov_SC03_108_jr_8015AE2C.c b/src/ov_SC03_108/ov_SC03_108_jr_8015AE2C.c index 9d4973c47..fcac28363 100644 --- a/src/ov_SC03_108/ov_SC03_108_jr_8015AE2C.c +++ b/src/ov_SC03_108/ov_SC03_108_jr_8015AE2C.c @@ -1513,7 +1513,259 @@ DEFINE_func_8015B858() /* dedup: shared engine-core @0x8015B858 (src/shared) */ DEFINE_func_8015B8F8() /* dedup: shared engine-core @0x8015B8F8 (src/shared) */ -INCLUDE_ASM("asm/ov_SC03_108/nonmatchings/ov_SC03_108_jr_8015AE2C", func_8015B950); +extern s32 func_8015AE2C(); + +// @class: plumbing +// @stuck: none — MATCH (271/271, pin-free, zero asm). The ONLY residual is DEF-SIDE plumbing, and it is now named exactly: the in-TU instantiation `DEFINE_func_8015BEE4()` (engine_core.h:1851-1855) expands to `extern s32 func_8015B950(void);` INSIDE ov_SC01_077_jr_8015AE2C.c, ~14 lines BELOW this definition, so the 1-param def collides with a `(void)` prototype -> `conflicting types for func_8015B950` (.run/bank_func_8015B950.log). §73 PARAMS axis / T0. Surgical fix = §65b de-macroize that ONE instantiation (blast radius: this TU); the fleet-wide `(void)`->`()` header edit is §63 and must be R22-validated. +/* func_8015B950 (ov_SC01_077_jr_8015AE2C, 271 ins, jtbl_801D8B74) — SESSION-21 re-verified + * + * ── ROUND-2 INDEPENDENT RE-VERIFICATION (2026-07-27, fresh agent, §88e discipline) ───────────── + * match_one : MATCH (271 ins) against the CURRENT tree — §87 staleness re-checked today. + * .text size: compiled .text = 0x43C = 1084 B = 271 ins, EXACTLY the target's declared 0x43C + * ("nonmatching func_8015B950, 0x43C"). So this is NOT a §83a length drift hiding + * behind a zero count — the count is over equal-length streams. + * jtbl : RE-DECODED MECHANICALLY, not inherited. Compiled .rodata = 0x1C = 28 B = 7 words, + * 7x R_MIPS_32 -> .text with implicit addends [58,58,58,E0,F0,100,58]; +0x8015B950 + * = [8015B9A8, 8015B9A8, 8015B9A8, 8015BA30, 8015BA40, 8015BA50, 8015B9A8]. + * Diffed word-for-word against asm/ov_SC01_077/data/tail14.data.s:15-23 — 7/7 identical. + * symcheck : SYMS-DIFF target=35 draft=34, sole MISSING = jtbl_801D8B74. This is the §81 jr + * FALSE POSITIVE, re-confirmed here by reading the relocs: gcc emits its OWN table and + * references it with R_MIPS_HI16/LO16 against the SECTION `.rodata` (t.o +0x40/+0x48), + * so the splat's dlabel NAME can never appear in the draft object's relocation set. + * Nothing is dropped and nothing is invented: the draft's other 34 symbols are exactly + * the target's other 34. + * FAMILY : the x138 remap is clean and §84-safe. Every sibling is 271 ins with an IDENTICAL + * callee set; only THREE names vary per overlay — the two data labels and the jtbl: + * ov_SC01_077 D_801832D0 / D_8018333C / jtbl_801D8B74 + * ov_SC03_099 D_80185A50 / D_80185ABC / jtbl_801BD898 + * ov_SC06_008 D_80187E44 / D_80187EB0 / jtbl_801A8734 + * The pair is always +0x6C apart, and NO literal in this draft encodes that distance + * (both labels are referenced by name), so there is no §84 derived-offset hazard. + * D_8011F9C4 is fleet-constant (main-EXE data) and must NOT be remapped. + * + * match_one: MATCH (271 ins) against the CURRENT tree (§87 staleness re-checked, 2026-07-27). + * PIN-FREE, zero asm, offset-pure (s32 arg0 + raw offsets) — x138 template-safe. + * Provenance: this is the Phase-26 crack (.run/phase26-cracks/func_8015B950.c) re-gated verbatim, + * with ONE deliberate change: the definition's return type void -> s32. + * - `void func_8015B950(s32 arg0)` : MATCH (271 ins) [the Phase-26 form] + * - `s32 func_8015B950(s32 arg0)` : MATCH (271 ins) [shipped — §3a-1 void->s32 is byte-neutral] + * The fleet/engine_core.h canonical decl is `extern s32 func_8015B950(void);` (engine_core.h:1852), + * and the last bank attempt (.run/bank_func_8015B950.log) died on `conflicting types for + * func_8015B950`. Shipping the s32 return kills the §73 RETURN axis for free and leaves only the + * cheap T0 PARAMS axis for the ladder (fix_header_decl.py / --fix-def-sig / cast_call_sites). + * Both forms are byte-identical, so the orchestrator may swap the return type back at zero cost. + * + * SYMBOLS (§58 rules 1/2 — all splat spellings, all verified present): + * D_8018333C asm/ov_SC01_077/data/tail.data.s:4355 (the state-handler vtable) + * D_801832D0 asm/ov_SC01_077/data/tail.data.s:4293 + * D_8011F9C4 main-EXE data; spelled `extern s32 D_8011F9C4;` in 5+ already-banked TUs + * jtbl_801D8B74 asm/ov_SC01_077/data/tail14.data.s:15 (compiler jump table — not named in C) + * + * JTBL VERIFIED (§8a gate): compiled .rodata = exactly 0x1C B / 7 words, 7x R_MIPS_32 .text with + * addends [0x58,0x58,0x58,0xE0,0xF0,0x100,0x58] -> +0x8015B950 = [B9A8,B9A8,B9A8,BA30,BA40,BA50, + * B9A8] == the original words at 0x801D8B74..0x801D8B8C. Bound `sltiu $v0,$v1,0x7` matches. + * The raw dlabel's 8th word 0x00000000 is NOT an entry — it is the intra-TU `.align 3` pad of the + * B34/B54/B74 jtbl chain; the object can never emit it (maspsx drops .align), so it must stay in + * the post-carve RAW data piece (the §53/§62/§81 carve chain applies at bank time). + * + * Same family as the TU's own already-matched func_8015AE2C: 7-case switch on ((s32 (*)(s32))func_801619A4)() + * (0/1/2/6 shared, 3/4/5 own, no default block — out-of-range and every `break` fall to the + * after-switch join), then a chain of "state handler" tests, each dispatching + * D_8018333C[*(u16*)arg0](arg0) and returning. + * + * THREE LEVERS (draft -> MATCH in 3 compiles): + * + * 1. PROLOGUE CONSTANT = an INITIALIZED LOCAL, not a literal in the compare. + * Target opens with `lui $s2, 0xFFF5` in the *prologue*, used once ~200 ins later in + * `slt $v0,$s2,$s1`. No gcc-2.7.2 pass hoists a (set reg const_int) across basic blocks + * (loop.c needs a loop; cse/combine/sched never move insns between BBs) — so the insn must + * have been EMITTED in the first BB, i.e. the constant is a local initialized at the top of + * the function. cse then cannot fold it back into the compare: the `slt` operand predicate is + * `arith_operand`, which rejects a CONST_INT wider than 16 bits, so validate_change fails and + * the pseudo survives. Its live range spans every call -> global.c gives it a callee-saved reg. + * Writing `z > -0xB0000` inline instead emits the `lui` into the branch delay slot next to the + * compare (caller-saved $v0) and the function is 1 insn short. => `s32 lim = -0xB0000;` at top. + * + * 2. `lh` vs `lhu`: a short->short copy is a pure HImode move and gcc emits `lhu`. The target's + * `lh $v0,0x26($s0)` means the value passed through an SImode (int) temp: expand makes + * (set (reg:SI) (sign_extend (mem:HI))) + (set (mem:HI) (subreg:HI ...)), and combine cannot + * merge them (the merged form is mem<-mem, which no movhi accepts) so the sign-extending load + * survives. => route both halfword copies through the `s32 t` temp. + * + * 3. THE `goto` LAYOUT — dodging jump.c's store-flag conversion (jump.c:1005-1065). + * An if/else chain writing 0/1 into `doit` makes gcc collapse the last pair into + * `sltiu $v0,$v0,1`. jump.c fires that conversion when the insn immediately after a + * conditional jump is a lone `SET pseudo, CONST_INT` whose following simplejump targets the + * SAME label as the branch (jump.c:1038 `reallabelprev == temp || ... JUMP_LABEL(temp4) == + * JUMP_LABEL(insn)`) — exactly the shape of `if (c) x=0; else x=1;`. + * The target instead cross-jumps ALL the `doit=0` exits into ONE shared block placed after the + * `doit=1` fall-through; reorg's fill_slots_from_thread then COPIES that single set into all + * three branch delay slots and redirects each branch past it (which is why `addu $v0,$zero, + * $zero` appears 3x in delay slots and the shared block vanishes). A `goto zero;` / `goto one;` + * chain expresses that layout directly, and each conditional jump is then followed by a + * compare/call rather than a lone const set, so the store-flag conversion never triggers. + * GENERAL RULE: multiple predicates that all assign the SAME constant to one flag => write + * them as `goto` to a shared assignment, never as an if/else ladder. + */ +extern s32 D_8011F9C4; +extern s32 D_801832D0; + +extern s32 func_80161B18(void); +extern s32 func_801619A4(s32*); +extern s32 func_80149AA8(s32*); +extern void func_80149AD4(s32*); +extern s32 func_80149B54(s32*); +extern void func_80149BAC(s32*); +extern s32 func_801498E0(s32*); +extern s32 func_80149954(s32); +extern s32 func_80149A64(s32*); +extern void func_800CCCC0(s32 a0); +extern s32 func_80149CD4(s32 a0); +extern void func_8015E880(s32*); +extern s32 func_80149744(struct S_80149744*); +extern void func_80149788(void); +extern s32 func_801496D4(void*); +extern void func_80149704(void); +extern int func_80148AFC(void*); +extern void func_80146D90(s32 a0); +extern void func_80154150(s32 a0, s32 a1); +extern void func_801541D8(u8*, s32, s32); +extern s32 func_801488A8(u8*); +extern void func_80147078(s32*, s16); +extern void func_8015A264(void*); +extern s32 func_80013294(void*, void*); +extern void func_80159B70(void*); +extern s32 func_8016F1AC(void); +extern s32 func_80029178(s32 a0); +extern void func_80146DB8(s32*, s32*); +extern s32 func_80161CD0(s32, s32); +extern s32 func_80161208(s32 a0); +extern s32 func_801725A4(u8*); + +s32 func_8015B950(s32 arg0) +{ + + extern void (*D_8018333C[])(void *); + s16 sp10[4]; + s16 sp18[4]; + s32 t; + s32 z; + s32 doit; + s32 lim = -0xB0000; + + if (func_80161B18() != 0) { + return; + } + switch (((s32 (*)(s32))func_801619A4)(arg0)) { + case 0: + case 1: + case 2: + case 6: + if (((s32 (*)(s32))func_80149AA8)(arg0) != 0) { + D_8018333C[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149AD4)(arg0); + return; + } + if (((s32 (*)(s32))func_80149B54)(arg0) != 0) { + D_8018333C[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149BAC)(arg0); + return; + } + break; + case 3: + ((void (*)(s32))func_801498E0)(arg0); + break; + case 4: + ((void (*)(s32))func_80149954)(arg0); + break; + case 5: + if (((s32 (*)(s32))func_80149A64)(arg0) != 0) { + D_8018333C[*(u16 *)arg0]((void *)arg0); + func_800CCCC0(arg0); + return; + } + break; + } + if (func_80149CD4(arg0) != 0) { + D_8018333C[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_8015E880)(arg0); + return; + } + if (((s32 (*)(s32))func_80149744)(arg0) != 0) { + D_8018333C[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149788)(arg0); + return; + } + if (((s32 (*)(s32))func_801496D4)(arg0) != 0) { + D_8018333C[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149704)(arg0); + if (((u8)((s32 (*)(s32))func_80148AFC)(arg0)) == 0) { + func_80146D90(arg0); + } + if ((*(s32 *)(arg0 + 0x24) | *(s32 *)(arg0 + 0x2C)) != 0) { + func_80154150(arg0, 0xF); + } else { + ((void (*)(s32, s32, s32))func_801541D8)(arg0, 0xD, 6); + } + *(s32 *)(arg0 + 0x238) = 1; + return; + } + if (((s32 (*)(s32))func_801488A8)(arg0) != 0) { + sp10[0] = 0; + sp10[1] = 0; + sp10[2] = 0; + t = *(s16 *)(arg0 + 0x26); + sp18[0] = t; + sp18[1] = 0; + t = *(s16 *)(arg0 + 0x2E); + sp18[2] = t; + D_8018333C[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 1); + ((void (*)(s32))func_8015A264)(arg0); + t = -(((s32 (*)(s16 *, s16 *))func_80013294)(sp10, sp18) << 0x10); + if (t < *(s32 *)(arg0 + 0x2C)) { + *(s32 *)(arg0 + 0x2C) = t; + } + return; + } + if (*(u16 *)(arg0 + 0xB8) == 0x8000) { + D_8018333C[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 0); + ((void (*)(s32))func_80159B70)(arg0); + return; + } + z = *(s32 *)(arg0 + 0x2C); + if (func_8016F1AC() != 0) { + goto zero; + } + if (z <= lim) { + goto one; + } + if (D_8011F9C4 == 0) { + goto zero; + } + if (((u8)func_80029178(0x21)) != 0) { + goto zero; + } +one: + doit = 1; + goto join; +zero: + doit = 0; +join: + if (doit != 0) { + D_8018333C[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 0); + ((void (*)(s32))func_80159B70)(arg0); + func_80154150(arg0, 9); + ((void (*)(s32, s32 *))func_80146DB8)(arg0, &D_801832D0); + ((void (*)(s32, s32))func_80161CD0)(arg0, *(u16 *)(arg0 + 0x16E)); + return; + } + if (func_80161208(arg0) == 0) { + ((void (*)(s32))func_801725A4)(arg0); + } +} DEFINE_func_8015BD8C() /* dedup: shared engine-core @0x8015BD8C (src/shared) */ diff --git a/src/ov_SC03_109/ov_SC03_109_jr_8015AE2C.c b/src/ov_SC03_109/ov_SC03_109_jr_8015AE2C.c index c0ee80e24..b215a3478 100644 --- a/src/ov_SC03_109/ov_SC03_109_jr_8015AE2C.c +++ b/src/ov_SC03_109/ov_SC03_109_jr_8015AE2C.c @@ -1513,7 +1513,259 @@ DEFINE_func_8015B858() /* dedup: shared engine-core @0x8015B858 (src/shared) */ DEFINE_func_8015B8F8() /* dedup: shared engine-core @0x8015B8F8 (src/shared) */ -INCLUDE_ASM("asm/ov_SC03_109/nonmatchings/ov_SC03_109_jr_8015AE2C", func_8015B950); +extern s32 func_8015AE2C(); + +// @class: plumbing +// @stuck: none — MATCH (271/271, pin-free, zero asm). The ONLY residual is DEF-SIDE plumbing, and it is now named exactly: the in-TU instantiation `DEFINE_func_8015BEE4()` (engine_core.h:1851-1855) expands to `extern s32 func_8015B950(void);` INSIDE ov_SC01_077_jr_8015AE2C.c, ~14 lines BELOW this definition, so the 1-param def collides with a `(void)` prototype -> `conflicting types for func_8015B950` (.run/bank_func_8015B950.log). §73 PARAMS axis / T0. Surgical fix = §65b de-macroize that ONE instantiation (blast radius: this TU); the fleet-wide `(void)`->`()` header edit is §63 and must be R22-validated. +/* func_8015B950 (ov_SC01_077_jr_8015AE2C, 271 ins, jtbl_801D8B74) — SESSION-21 re-verified + * + * ── ROUND-2 INDEPENDENT RE-VERIFICATION (2026-07-27, fresh agent, §88e discipline) ───────────── + * match_one : MATCH (271 ins) against the CURRENT tree — §87 staleness re-checked today. + * .text size: compiled .text = 0x43C = 1084 B = 271 ins, EXACTLY the target's declared 0x43C + * ("nonmatching func_8015B950, 0x43C"). So this is NOT a §83a length drift hiding + * behind a zero count — the count is over equal-length streams. + * jtbl : RE-DECODED MECHANICALLY, not inherited. Compiled .rodata = 0x1C = 28 B = 7 words, + * 7x R_MIPS_32 -> .text with implicit addends [58,58,58,E0,F0,100,58]; +0x8015B950 + * = [8015B9A8, 8015B9A8, 8015B9A8, 8015BA30, 8015BA40, 8015BA50, 8015B9A8]. + * Diffed word-for-word against asm/ov_SC01_077/data/tail14.data.s:15-23 — 7/7 identical. + * symcheck : SYMS-DIFF target=35 draft=34, sole MISSING = jtbl_801D8B74. This is the §81 jr + * FALSE POSITIVE, re-confirmed here by reading the relocs: gcc emits its OWN table and + * references it with R_MIPS_HI16/LO16 against the SECTION `.rodata` (t.o +0x40/+0x48), + * so the splat's dlabel NAME can never appear in the draft object's relocation set. + * Nothing is dropped and nothing is invented: the draft's other 34 symbols are exactly + * the target's other 34. + * FAMILY : the x138 remap is clean and §84-safe. Every sibling is 271 ins with an IDENTICAL + * callee set; only THREE names vary per overlay — the two data labels and the jtbl: + * ov_SC01_077 D_8018097C / D_801809E8 / jtbl_801D8B74 + * ov_SC03_099 D_80185A50 / D_80185ABC / jtbl_801BD898 + * ov_SC06_008 D_80187E44 / D_80187EB0 / jtbl_801A8734 + * The pair is always +0x6C apart, and NO literal in this draft encodes that distance + * (both labels are referenced by name), so there is no §84 derived-offset hazard. + * D_8011F9C4 is fleet-constant (main-EXE data) and must NOT be remapped. + * + * match_one: MATCH (271 ins) against the CURRENT tree (§87 staleness re-checked, 2026-07-27). + * PIN-FREE, zero asm, offset-pure (s32 arg0 + raw offsets) — x138 template-safe. + * Provenance: this is the Phase-26 crack (.run/phase26-cracks/func_8015B950.c) re-gated verbatim, + * with ONE deliberate change: the definition's return type void -> s32. + * - `void func_8015B950(s32 arg0)` : MATCH (271 ins) [the Phase-26 form] + * - `s32 func_8015B950(s32 arg0)` : MATCH (271 ins) [shipped — §3a-1 void->s32 is byte-neutral] + * The fleet/engine_core.h canonical decl is `extern s32 func_8015B950(void);` (engine_core.h:1852), + * and the last bank attempt (.run/bank_func_8015B950.log) died on `conflicting types for + * func_8015B950`. Shipping the s32 return kills the §73 RETURN axis for free and leaves only the + * cheap T0 PARAMS axis for the ladder (fix_header_decl.py / --fix-def-sig / cast_call_sites). + * Both forms are byte-identical, so the orchestrator may swap the return type back at zero cost. + * + * SYMBOLS (§58 rules 1/2 — all splat spellings, all verified present): + * D_801809E8 asm/ov_SC01_077/data/tail.data.s:4355 (the state-handler vtable) + * D_8018097C asm/ov_SC01_077/data/tail.data.s:4293 + * D_8011F9C4 main-EXE data; spelled `extern s32 D_8011F9C4;` in 5+ already-banked TUs + * jtbl_801D8B74 asm/ov_SC01_077/data/tail14.data.s:15 (compiler jump table — not named in C) + * + * JTBL VERIFIED (§8a gate): compiled .rodata = exactly 0x1C B / 7 words, 7x R_MIPS_32 .text with + * addends [0x58,0x58,0x58,0xE0,0xF0,0x100,0x58] -> +0x8015B950 = [B9A8,B9A8,B9A8,BA30,BA40,BA50, + * B9A8] == the original words at 0x801D8B74..0x801D8B8C. Bound `sltiu $v0,$v1,0x7` matches. + * The raw dlabel's 8th word 0x00000000 is NOT an entry — it is the intra-TU `.align 3` pad of the + * B34/B54/B74 jtbl chain; the object can never emit it (maspsx drops .align), so it must stay in + * the post-carve RAW data piece (the §53/§62/§81 carve chain applies at bank time). + * + * Same family as the TU's own already-matched func_8015AE2C: 7-case switch on ((s32 (*)(s32))func_801619A4)() + * (0/1/2/6 shared, 3/4/5 own, no default block — out-of-range and every `break` fall to the + * after-switch join), then a chain of "state handler" tests, each dispatching + * D_801809E8[*(u16*)arg0](arg0) and returning. + * + * THREE LEVERS (draft -> MATCH in 3 compiles): + * + * 1. PROLOGUE CONSTANT = an INITIALIZED LOCAL, not a literal in the compare. + * Target opens with `lui $s2, 0xFFF5` in the *prologue*, used once ~200 ins later in + * `slt $v0,$s2,$s1`. No gcc-2.7.2 pass hoists a (set reg const_int) across basic blocks + * (loop.c needs a loop; cse/combine/sched never move insns between BBs) — so the insn must + * have been EMITTED in the first BB, i.e. the constant is a local initialized at the top of + * the function. cse then cannot fold it back into the compare: the `slt` operand predicate is + * `arith_operand`, which rejects a CONST_INT wider than 16 bits, so validate_change fails and + * the pseudo survives. Its live range spans every call -> global.c gives it a callee-saved reg. + * Writing `z > -0xB0000` inline instead emits the `lui` into the branch delay slot next to the + * compare (caller-saved $v0) and the function is 1 insn short. => `s32 lim = -0xB0000;` at top. + * + * 2. `lh` vs `lhu`: a short->short copy is a pure HImode move and gcc emits `lhu`. The target's + * `lh $v0,0x26($s0)` means the value passed through an SImode (int) temp: expand makes + * (set (reg:SI) (sign_extend (mem:HI))) + (set (mem:HI) (subreg:HI ...)), and combine cannot + * merge them (the merged form is mem<-mem, which no movhi accepts) so the sign-extending load + * survives. => route both halfword copies through the `s32 t` temp. + * + * 3. THE `goto` LAYOUT — dodging jump.c's store-flag conversion (jump.c:1005-1065). + * An if/else chain writing 0/1 into `doit` makes gcc collapse the last pair into + * `sltiu $v0,$v0,1`. jump.c fires that conversion when the insn immediately after a + * conditional jump is a lone `SET pseudo, CONST_INT` whose following simplejump targets the + * SAME label as the branch (jump.c:1038 `reallabelprev == temp || ... JUMP_LABEL(temp4) == + * JUMP_LABEL(insn)`) — exactly the shape of `if (c) x=0; else x=1;`. + * The target instead cross-jumps ALL the `doit=0` exits into ONE shared block placed after the + * `doit=1` fall-through; reorg's fill_slots_from_thread then COPIES that single set into all + * three branch delay slots and redirects each branch past it (which is why `addu $v0,$zero, + * $zero` appears 3x in delay slots and the shared block vanishes). A `goto zero;` / `goto one;` + * chain expresses that layout directly, and each conditional jump is then followed by a + * compare/call rather than a lone const set, so the store-flag conversion never triggers. + * GENERAL RULE: multiple predicates that all assign the SAME constant to one flag => write + * them as `goto` to a shared assignment, never as an if/else ladder. + */ +extern s32 D_8011F9C4; +extern s32 D_8018097C; + +extern s32 func_80161B18(void); +extern s32 func_801619A4(s32*); +extern s32 func_80149AA8(s32*); +extern void func_80149AD4(s32*); +extern s32 func_80149B54(s32*); +extern void func_80149BAC(s32*); +extern s32 func_801498E0(s32*); +extern s32 func_80149954(s32); +extern s32 func_80149A64(s32*); +extern void func_800CCCC0(s32 a0); +extern s32 func_80149CD4(s32 a0); +extern void func_8015E880(s32*); +extern s32 func_80149744(struct S_80149744*); +extern void func_80149788(void); +extern s32 func_801496D4(void*); +extern void func_80149704(void); +extern int func_80148AFC(void*); +extern void func_80146D90(s32 a0); +extern void func_80154150(s32 a0, s32 a1); +extern void func_801541D8(u8*, s32, s32); +extern s32 func_801488A8(u8*); +extern void func_80147078(s32*, s16); +extern void func_8015A264(void*); +extern s32 func_80013294(void*, void*); +extern void func_80159B70(void*); +extern s32 func_8016F1AC(void); +extern s32 func_80029178(s32 a0); +extern void func_80146DB8(s32*, s32*); +extern s32 func_80161CD0(s32, s32); +extern s32 func_80161208(s32 a0); +extern s32 func_801725A4(u8*); + +s32 func_8015B950(s32 arg0) +{ + + extern void (*D_801809E8[])(void *); + s16 sp10[4]; + s16 sp18[4]; + s32 t; + s32 z; + s32 doit; + s32 lim = -0xB0000; + + if (func_80161B18() != 0) { + return; + } + switch (((s32 (*)(s32))func_801619A4)(arg0)) { + case 0: + case 1: + case 2: + case 6: + if (((s32 (*)(s32))func_80149AA8)(arg0) != 0) { + D_801809E8[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149AD4)(arg0); + return; + } + if (((s32 (*)(s32))func_80149B54)(arg0) != 0) { + D_801809E8[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149BAC)(arg0); + return; + } + break; + case 3: + ((void (*)(s32))func_801498E0)(arg0); + break; + case 4: + ((void (*)(s32))func_80149954)(arg0); + break; + case 5: + if (((s32 (*)(s32))func_80149A64)(arg0) != 0) { + D_801809E8[*(u16 *)arg0]((void *)arg0); + func_800CCCC0(arg0); + return; + } + break; + } + if (func_80149CD4(arg0) != 0) { + D_801809E8[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_8015E880)(arg0); + return; + } + if (((s32 (*)(s32))func_80149744)(arg0) != 0) { + D_801809E8[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149788)(arg0); + return; + } + if (((s32 (*)(s32))func_801496D4)(arg0) != 0) { + D_801809E8[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149704)(arg0); + if (((u8)((s32 (*)(s32))func_80148AFC)(arg0)) == 0) { + func_80146D90(arg0); + } + if ((*(s32 *)(arg0 + 0x24) | *(s32 *)(arg0 + 0x2C)) != 0) { + func_80154150(arg0, 0xF); + } else { + ((void (*)(s32, s32, s32))func_801541D8)(arg0, 0xD, 6); + } + *(s32 *)(arg0 + 0x238) = 1; + return; + } + if (((s32 (*)(s32))func_801488A8)(arg0) != 0) { + sp10[0] = 0; + sp10[1] = 0; + sp10[2] = 0; + t = *(s16 *)(arg0 + 0x26); + sp18[0] = t; + sp18[1] = 0; + t = *(s16 *)(arg0 + 0x2E); + sp18[2] = t; + D_801809E8[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 1); + ((void (*)(s32))func_8015A264)(arg0); + t = -(((s32 (*)(s16 *, s16 *))func_80013294)(sp10, sp18) << 0x10); + if (t < *(s32 *)(arg0 + 0x2C)) { + *(s32 *)(arg0 + 0x2C) = t; + } + return; + } + if (*(u16 *)(arg0 + 0xB8) == 0x8000) { + D_801809E8[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 0); + ((void (*)(s32))func_80159B70)(arg0); + return; + } + z = *(s32 *)(arg0 + 0x2C); + if (func_8016F1AC() != 0) { + goto zero; + } + if (z <= lim) { + goto one; + } + if (D_8011F9C4 == 0) { + goto zero; + } + if (((u8)func_80029178(0x21)) != 0) { + goto zero; + } +one: + doit = 1; + goto join; +zero: + doit = 0; +join: + if (doit != 0) { + D_801809E8[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 0); + ((void (*)(s32))func_80159B70)(arg0); + func_80154150(arg0, 9); + ((void (*)(s32, s32 *))func_80146DB8)(arg0, &D_8018097C); + ((void (*)(s32, s32))func_80161CD0)(arg0, *(u16 *)(arg0 + 0x16E)); + return; + } + if (func_80161208(arg0) == 0) { + ((void (*)(s32))func_801725A4)(arg0); + } +} DEFINE_func_8015BD8C() /* dedup: shared engine-core @0x8015BD8C (src/shared) */ diff --git a/src/ov_SC03_110/ov_SC03_110_jr_8015AE2C.c b/src/ov_SC03_110/ov_SC03_110_jr_8015AE2C.c index 59f604c82..437fe448b 100644 --- a/src/ov_SC03_110/ov_SC03_110_jr_8015AE2C.c +++ b/src/ov_SC03_110/ov_SC03_110_jr_8015AE2C.c @@ -1513,7 +1513,259 @@ DEFINE_func_8015B858() /* dedup: shared engine-core @0x8015B858 (src/shared) */ DEFINE_func_8015B8F8() /* dedup: shared engine-core @0x8015B8F8 (src/shared) */ -INCLUDE_ASM("asm/ov_SC03_110/nonmatchings/ov_SC03_110_jr_8015AE2C", func_8015B950); +extern s32 func_8015AE2C(); + +// @class: plumbing +// @stuck: none — MATCH (271/271, pin-free, zero asm). The ONLY residual is DEF-SIDE plumbing, and it is now named exactly: the in-TU instantiation `DEFINE_func_8015BEE4()` (engine_core.h:1851-1855) expands to `extern s32 func_8015B950(void);` INSIDE ov_SC01_077_jr_8015AE2C.c, ~14 lines BELOW this definition, so the 1-param def collides with a `(void)` prototype -> `conflicting types for func_8015B950` (.run/bank_func_8015B950.log). §73 PARAMS axis / T0. Surgical fix = §65b de-macroize that ONE instantiation (blast radius: this TU); the fleet-wide `(void)`->`()` header edit is §63 and must be R22-validated. +/* func_8015B950 (ov_SC01_077_jr_8015AE2C, 271 ins, jtbl_801D8B74) — SESSION-21 re-verified + * + * ── ROUND-2 INDEPENDENT RE-VERIFICATION (2026-07-27, fresh agent, §88e discipline) ───────────── + * match_one : MATCH (271 ins) against the CURRENT tree — §87 staleness re-checked today. + * .text size: compiled .text = 0x43C = 1084 B = 271 ins, EXACTLY the target's declared 0x43C + * ("nonmatching func_8015B950, 0x43C"). So this is NOT a §83a length drift hiding + * behind a zero count — the count is over equal-length streams. + * jtbl : RE-DECODED MECHANICALLY, not inherited. Compiled .rodata = 0x1C = 28 B = 7 words, + * 7x R_MIPS_32 -> .text with implicit addends [58,58,58,E0,F0,100,58]; +0x8015B950 + * = [8015B9A8, 8015B9A8, 8015B9A8, 8015BA30, 8015BA40, 8015BA50, 8015B9A8]. + * Diffed word-for-word against asm/ov_SC01_077/data/tail14.data.s:15-23 — 7/7 identical. + * symcheck : SYMS-DIFF target=35 draft=34, sole MISSING = jtbl_801D8B74. This is the §81 jr + * FALSE POSITIVE, re-confirmed here by reading the relocs: gcc emits its OWN table and + * references it with R_MIPS_HI16/LO16 against the SECTION `.rodata` (t.o +0x40/+0x48), + * so the splat's dlabel NAME can never appear in the draft object's relocation set. + * Nothing is dropped and nothing is invented: the draft's other 34 symbols are exactly + * the target's other 34. + * FAMILY : the x138 remap is clean and §84-safe. Every sibling is 271 ins with an IDENTICAL + * callee set; only THREE names vary per overlay — the two data labels and the jtbl: + * ov_SC01_077 D_8018439C / D_80184408 / jtbl_801D8B74 + * ov_SC03_099 D_80185A50 / D_80185ABC / jtbl_801BD898 + * ov_SC06_008 D_80187E44 / D_80187EB0 / jtbl_801A8734 + * The pair is always +0x6C apart, and NO literal in this draft encodes that distance + * (both labels are referenced by name), so there is no §84 derived-offset hazard. + * D_8011F9C4 is fleet-constant (main-EXE data) and must NOT be remapped. + * + * match_one: MATCH (271 ins) against the CURRENT tree (§87 staleness re-checked, 2026-07-27). + * PIN-FREE, zero asm, offset-pure (s32 arg0 + raw offsets) — x138 template-safe. + * Provenance: this is the Phase-26 crack (.run/phase26-cracks/func_8015B950.c) re-gated verbatim, + * with ONE deliberate change: the definition's return type void -> s32. + * - `void func_8015B950(s32 arg0)` : MATCH (271 ins) [the Phase-26 form] + * - `s32 func_8015B950(s32 arg0)` : MATCH (271 ins) [shipped — §3a-1 void->s32 is byte-neutral] + * The fleet/engine_core.h canonical decl is `extern s32 func_8015B950(void);` (engine_core.h:1852), + * and the last bank attempt (.run/bank_func_8015B950.log) died on `conflicting types for + * func_8015B950`. Shipping the s32 return kills the §73 RETURN axis for free and leaves only the + * cheap T0 PARAMS axis for the ladder (fix_header_decl.py / --fix-def-sig / cast_call_sites). + * Both forms are byte-identical, so the orchestrator may swap the return type back at zero cost. + * + * SYMBOLS (§58 rules 1/2 — all splat spellings, all verified present): + * D_80184408 asm/ov_SC01_077/data/tail.data.s:4355 (the state-handler vtable) + * D_8018439C asm/ov_SC01_077/data/tail.data.s:4293 + * D_8011F9C4 main-EXE data; spelled `extern s32 D_8011F9C4;` in 5+ already-banked TUs + * jtbl_801D8B74 asm/ov_SC01_077/data/tail14.data.s:15 (compiler jump table — not named in C) + * + * JTBL VERIFIED (§8a gate): compiled .rodata = exactly 0x1C B / 7 words, 7x R_MIPS_32 .text with + * addends [0x58,0x58,0x58,0xE0,0xF0,0x100,0x58] -> +0x8015B950 = [B9A8,B9A8,B9A8,BA30,BA40,BA50, + * B9A8] == the original words at 0x801D8B74..0x801D8B8C. Bound `sltiu $v0,$v1,0x7` matches. + * The raw dlabel's 8th word 0x00000000 is NOT an entry — it is the intra-TU `.align 3` pad of the + * B34/B54/B74 jtbl chain; the object can never emit it (maspsx drops .align), so it must stay in + * the post-carve RAW data piece (the §53/§62/§81 carve chain applies at bank time). + * + * Same family as the TU's own already-matched func_8015AE2C: 7-case switch on ((s32 (*)(s32))func_801619A4)() + * (0/1/2/6 shared, 3/4/5 own, no default block — out-of-range and every `break` fall to the + * after-switch join), then a chain of "state handler" tests, each dispatching + * D_80184408[*(u16*)arg0](arg0) and returning. + * + * THREE LEVERS (draft -> MATCH in 3 compiles): + * + * 1. PROLOGUE CONSTANT = an INITIALIZED LOCAL, not a literal in the compare. + * Target opens with `lui $s2, 0xFFF5` in the *prologue*, used once ~200 ins later in + * `slt $v0,$s2,$s1`. No gcc-2.7.2 pass hoists a (set reg const_int) across basic blocks + * (loop.c needs a loop; cse/combine/sched never move insns between BBs) — so the insn must + * have been EMITTED in the first BB, i.e. the constant is a local initialized at the top of + * the function. cse then cannot fold it back into the compare: the `slt` operand predicate is + * `arith_operand`, which rejects a CONST_INT wider than 16 bits, so validate_change fails and + * the pseudo survives. Its live range spans every call -> global.c gives it a callee-saved reg. + * Writing `z > -0xB0000` inline instead emits the `lui` into the branch delay slot next to the + * compare (caller-saved $v0) and the function is 1 insn short. => `s32 lim = -0xB0000;` at top. + * + * 2. `lh` vs `lhu`: a short->short copy is a pure HImode move and gcc emits `lhu`. The target's + * `lh $v0,0x26($s0)` means the value passed through an SImode (int) temp: expand makes + * (set (reg:SI) (sign_extend (mem:HI))) + (set (mem:HI) (subreg:HI ...)), and combine cannot + * merge them (the merged form is mem<-mem, which no movhi accepts) so the sign-extending load + * survives. => route both halfword copies through the `s32 t` temp. + * + * 3. THE `goto` LAYOUT — dodging jump.c's store-flag conversion (jump.c:1005-1065). + * An if/else chain writing 0/1 into `doit` makes gcc collapse the last pair into + * `sltiu $v0,$v0,1`. jump.c fires that conversion when the insn immediately after a + * conditional jump is a lone `SET pseudo, CONST_INT` whose following simplejump targets the + * SAME label as the branch (jump.c:1038 `reallabelprev == temp || ... JUMP_LABEL(temp4) == + * JUMP_LABEL(insn)`) — exactly the shape of `if (c) x=0; else x=1;`. + * The target instead cross-jumps ALL the `doit=0` exits into ONE shared block placed after the + * `doit=1` fall-through; reorg's fill_slots_from_thread then COPIES that single set into all + * three branch delay slots and redirects each branch past it (which is why `addu $v0,$zero, + * $zero` appears 3x in delay slots and the shared block vanishes). A `goto zero;` / `goto one;` + * chain expresses that layout directly, and each conditional jump is then followed by a + * compare/call rather than a lone const set, so the store-flag conversion never triggers. + * GENERAL RULE: multiple predicates that all assign the SAME constant to one flag => write + * them as `goto` to a shared assignment, never as an if/else ladder. + */ +extern s32 D_8011F9C4; +extern s32 D_8018439C; + +extern s32 func_80161B18(void); +extern s32 func_801619A4(s32*); +extern s32 func_80149AA8(s32*); +extern void func_80149AD4(s32*); +extern s32 func_80149B54(s32*); +extern void func_80149BAC(s32*); +extern s32 func_801498E0(s32*); +extern s32 func_80149954(s32); +extern s32 func_80149A64(s32*); +extern void func_800CCCC0(s32 a0); +extern s32 func_80149CD4(s32 a0); +extern void func_8015E880(s32*); +extern s32 func_80149744(struct S_80149744*); +extern void func_80149788(void); +extern s32 func_801496D4(void*); +extern void func_80149704(void); +extern int func_80148AFC(void*); +extern void func_80146D90(s32 a0); +extern void func_80154150(s32 a0, s32 a1); +extern void func_801541D8(u8*, s32, s32); +extern s32 func_801488A8(u8*); +extern void func_80147078(s32*, s16); +extern void func_8015A264(void*); +extern s32 func_80013294(void*, void*); +extern void func_80159B70(void*); +extern s32 func_8016F1AC(void); +extern s32 func_80029178(s32 a0); +extern void func_80146DB8(s32*, s32*); +extern s32 func_80161CD0(s32, s32); +extern s32 func_80161208(s32 a0); +extern s32 func_801725A4(u8*); + +s32 func_8015B950(s32 arg0) +{ + + extern void (*D_80184408[])(void *); + s16 sp10[4]; + s16 sp18[4]; + s32 t; + s32 z; + s32 doit; + s32 lim = -0xB0000; + + if (func_80161B18() != 0) { + return; + } + switch (((s32 (*)(s32))func_801619A4)(arg0)) { + case 0: + case 1: + case 2: + case 6: + if (((s32 (*)(s32))func_80149AA8)(arg0) != 0) { + D_80184408[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149AD4)(arg0); + return; + } + if (((s32 (*)(s32))func_80149B54)(arg0) != 0) { + D_80184408[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149BAC)(arg0); + return; + } + break; + case 3: + ((void (*)(s32))func_801498E0)(arg0); + break; + case 4: + ((void (*)(s32))func_80149954)(arg0); + break; + case 5: + if (((s32 (*)(s32))func_80149A64)(arg0) != 0) { + D_80184408[*(u16 *)arg0]((void *)arg0); + func_800CCCC0(arg0); + return; + } + break; + } + if (func_80149CD4(arg0) != 0) { + D_80184408[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_8015E880)(arg0); + return; + } + if (((s32 (*)(s32))func_80149744)(arg0) != 0) { + D_80184408[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149788)(arg0); + return; + } + if (((s32 (*)(s32))func_801496D4)(arg0) != 0) { + D_80184408[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149704)(arg0); + if (((u8)((s32 (*)(s32))func_80148AFC)(arg0)) == 0) { + func_80146D90(arg0); + } + if ((*(s32 *)(arg0 + 0x24) | *(s32 *)(arg0 + 0x2C)) != 0) { + func_80154150(arg0, 0xF); + } else { + ((void (*)(s32, s32, s32))func_801541D8)(arg0, 0xD, 6); + } + *(s32 *)(arg0 + 0x238) = 1; + return; + } + if (((s32 (*)(s32))func_801488A8)(arg0) != 0) { + sp10[0] = 0; + sp10[1] = 0; + sp10[2] = 0; + t = *(s16 *)(arg0 + 0x26); + sp18[0] = t; + sp18[1] = 0; + t = *(s16 *)(arg0 + 0x2E); + sp18[2] = t; + D_80184408[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 1); + ((void (*)(s32))func_8015A264)(arg0); + t = -(((s32 (*)(s16 *, s16 *))func_80013294)(sp10, sp18) << 0x10); + if (t < *(s32 *)(arg0 + 0x2C)) { + *(s32 *)(arg0 + 0x2C) = t; + } + return; + } + if (*(u16 *)(arg0 + 0xB8) == 0x8000) { + D_80184408[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 0); + ((void (*)(s32))func_80159B70)(arg0); + return; + } + z = *(s32 *)(arg0 + 0x2C); + if (func_8016F1AC() != 0) { + goto zero; + } + if (z <= lim) { + goto one; + } + if (D_8011F9C4 == 0) { + goto zero; + } + if (((u8)func_80029178(0x21)) != 0) { + goto zero; + } +one: + doit = 1; + goto join; +zero: + doit = 0; +join: + if (doit != 0) { + D_80184408[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 0); + ((void (*)(s32))func_80159B70)(arg0); + func_80154150(arg0, 9); + ((void (*)(s32, s32 *))func_80146DB8)(arg0, &D_8018439C); + ((void (*)(s32, s32))func_80161CD0)(arg0, *(u16 *)(arg0 + 0x16E)); + return; + } + if (func_80161208(arg0) == 0) { + ((void (*)(s32))func_801725A4)(arg0); + } +} DEFINE_func_8015BD8C() /* dedup: shared engine-core @0x8015BD8C (src/shared) */ diff --git a/src/ov_SC03_111/ov_SC03_111_jr_8015AE2C.c b/src/ov_SC03_111/ov_SC03_111_jr_8015AE2C.c index 1c1b055cc..c35fe56b2 100644 --- a/src/ov_SC03_111/ov_SC03_111_jr_8015AE2C.c +++ b/src/ov_SC03_111/ov_SC03_111_jr_8015AE2C.c @@ -1513,7 +1513,259 @@ DEFINE_func_8015B858() /* dedup: shared engine-core @0x8015B858 (src/shared) */ DEFINE_func_8015B8F8() /* dedup: shared engine-core @0x8015B8F8 (src/shared) */ -INCLUDE_ASM("asm/ov_SC03_111/nonmatchings/ov_SC03_111_jr_8015AE2C", func_8015B950); +extern s32 func_8015AE2C(); + +// @class: plumbing +// @stuck: none — MATCH (271/271, pin-free, zero asm). The ONLY residual is DEF-SIDE plumbing, and it is now named exactly: the in-TU instantiation `DEFINE_func_8015BEE4()` (engine_core.h:1851-1855) expands to `extern s32 func_8015B950(void);` INSIDE ov_SC01_077_jr_8015AE2C.c, ~14 lines BELOW this definition, so the 1-param def collides with a `(void)` prototype -> `conflicting types for func_8015B950` (.run/bank_func_8015B950.log). §73 PARAMS axis / T0. Surgical fix = §65b de-macroize that ONE instantiation (blast radius: this TU); the fleet-wide `(void)`->`()` header edit is §63 and must be R22-validated. +/* func_8015B950 (ov_SC01_077_jr_8015AE2C, 271 ins, jtbl_801D8B74) — SESSION-21 re-verified + * + * ── ROUND-2 INDEPENDENT RE-VERIFICATION (2026-07-27, fresh agent, §88e discipline) ───────────── + * match_one : MATCH (271 ins) against the CURRENT tree — §87 staleness re-checked today. + * .text size: compiled .text = 0x43C = 1084 B = 271 ins, EXACTLY the target's declared 0x43C + * ("nonmatching func_8015B950, 0x43C"). So this is NOT a §83a length drift hiding + * behind a zero count — the count is over equal-length streams. + * jtbl : RE-DECODED MECHANICALLY, not inherited. Compiled .rodata = 0x1C = 28 B = 7 words, + * 7x R_MIPS_32 -> .text with implicit addends [58,58,58,E0,F0,100,58]; +0x8015B950 + * = [8015B9A8, 8015B9A8, 8015B9A8, 8015BA30, 8015BA40, 8015BA50, 8015B9A8]. + * Diffed word-for-word against asm/ov_SC01_077/data/tail14.data.s:15-23 — 7/7 identical. + * symcheck : SYMS-DIFF target=35 draft=34, sole MISSING = jtbl_801D8B74. This is the §81 jr + * FALSE POSITIVE, re-confirmed here by reading the relocs: gcc emits its OWN table and + * references it with R_MIPS_HI16/LO16 against the SECTION `.rodata` (t.o +0x40/+0x48), + * so the splat's dlabel NAME can never appear in the draft object's relocation set. + * Nothing is dropped and nothing is invented: the draft's other 34 symbols are exactly + * the target's other 34. + * FAMILY : the x138 remap is clean and §84-safe. Every sibling is 271 ins with an IDENTICAL + * callee set; only THREE names vary per overlay — the two data labels and the jtbl: + * ov_SC01_077 D_80186F50 / D_80186FBC / jtbl_801D8B74 + * ov_SC03_099 D_80185A50 / D_80185ABC / jtbl_801BD898 + * ov_SC06_008 D_80187E44 / D_80187EB0 / jtbl_801A8734 + * The pair is always +0x6C apart, and NO literal in this draft encodes that distance + * (both labels are referenced by name), so there is no §84 derived-offset hazard. + * D_8011F9C4 is fleet-constant (main-EXE data) and must NOT be remapped. + * + * match_one: MATCH (271 ins) against the CURRENT tree (§87 staleness re-checked, 2026-07-27). + * PIN-FREE, zero asm, offset-pure (s32 arg0 + raw offsets) — x138 template-safe. + * Provenance: this is the Phase-26 crack (.run/phase26-cracks/func_8015B950.c) re-gated verbatim, + * with ONE deliberate change: the definition's return type void -> s32. + * - `void func_8015B950(s32 arg0)` : MATCH (271 ins) [the Phase-26 form] + * - `s32 func_8015B950(s32 arg0)` : MATCH (271 ins) [shipped — §3a-1 void->s32 is byte-neutral] + * The fleet/engine_core.h canonical decl is `extern s32 func_8015B950(void);` (engine_core.h:1852), + * and the last bank attempt (.run/bank_func_8015B950.log) died on `conflicting types for + * func_8015B950`. Shipping the s32 return kills the §73 RETURN axis for free and leaves only the + * cheap T0 PARAMS axis for the ladder (fix_header_decl.py / --fix-def-sig / cast_call_sites). + * Both forms are byte-identical, so the orchestrator may swap the return type back at zero cost. + * + * SYMBOLS (§58 rules 1/2 — all splat spellings, all verified present): + * D_80186FBC asm/ov_SC01_077/data/tail.data.s:4355 (the state-handler vtable) + * D_80186F50 asm/ov_SC01_077/data/tail.data.s:4293 + * D_8011F9C4 main-EXE data; spelled `extern s32 D_8011F9C4;` in 5+ already-banked TUs + * jtbl_801D8B74 asm/ov_SC01_077/data/tail14.data.s:15 (compiler jump table — not named in C) + * + * JTBL VERIFIED (§8a gate): compiled .rodata = exactly 0x1C B / 7 words, 7x R_MIPS_32 .text with + * addends [0x58,0x58,0x58,0xE0,0xF0,0x100,0x58] -> +0x8015B950 = [B9A8,B9A8,B9A8,BA30,BA40,BA50, + * B9A8] == the original words at 0x801D8B74..0x801D8B8C. Bound `sltiu $v0,$v1,0x7` matches. + * The raw dlabel's 8th word 0x00000000 is NOT an entry — it is the intra-TU `.align 3` pad of the + * B34/B54/B74 jtbl chain; the object can never emit it (maspsx drops .align), so it must stay in + * the post-carve RAW data piece (the §53/§62/§81 carve chain applies at bank time). + * + * Same family as the TU's own already-matched func_8015AE2C: 7-case switch on ((s32 (*)(s32))func_801619A4)() + * (0/1/2/6 shared, 3/4/5 own, no default block — out-of-range and every `break` fall to the + * after-switch join), then a chain of "state handler" tests, each dispatching + * D_80186FBC[*(u16*)arg0](arg0) and returning. + * + * THREE LEVERS (draft -> MATCH in 3 compiles): + * + * 1. PROLOGUE CONSTANT = an INITIALIZED LOCAL, not a literal in the compare. + * Target opens with `lui $s2, 0xFFF5` in the *prologue*, used once ~200 ins later in + * `slt $v0,$s2,$s1`. No gcc-2.7.2 pass hoists a (set reg const_int) across basic blocks + * (loop.c needs a loop; cse/combine/sched never move insns between BBs) — so the insn must + * have been EMITTED in the first BB, i.e. the constant is a local initialized at the top of + * the function. cse then cannot fold it back into the compare: the `slt` operand predicate is + * `arith_operand`, which rejects a CONST_INT wider than 16 bits, so validate_change fails and + * the pseudo survives. Its live range spans every call -> global.c gives it a callee-saved reg. + * Writing `z > -0xB0000` inline instead emits the `lui` into the branch delay slot next to the + * compare (caller-saved $v0) and the function is 1 insn short. => `s32 lim = -0xB0000;` at top. + * + * 2. `lh` vs `lhu`: a short->short copy is a pure HImode move and gcc emits `lhu`. The target's + * `lh $v0,0x26($s0)` means the value passed through an SImode (int) temp: expand makes + * (set (reg:SI) (sign_extend (mem:HI))) + (set (mem:HI) (subreg:HI ...)), and combine cannot + * merge them (the merged form is mem<-mem, which no movhi accepts) so the sign-extending load + * survives. => route both halfword copies through the `s32 t` temp. + * + * 3. THE `goto` LAYOUT — dodging jump.c's store-flag conversion (jump.c:1005-1065). + * An if/else chain writing 0/1 into `doit` makes gcc collapse the last pair into + * `sltiu $v0,$v0,1`. jump.c fires that conversion when the insn immediately after a + * conditional jump is a lone `SET pseudo, CONST_INT` whose following simplejump targets the + * SAME label as the branch (jump.c:1038 `reallabelprev == temp || ... JUMP_LABEL(temp4) == + * JUMP_LABEL(insn)`) — exactly the shape of `if (c) x=0; else x=1;`. + * The target instead cross-jumps ALL the `doit=0` exits into ONE shared block placed after the + * `doit=1` fall-through; reorg's fill_slots_from_thread then COPIES that single set into all + * three branch delay slots and redirects each branch past it (which is why `addu $v0,$zero, + * $zero` appears 3x in delay slots and the shared block vanishes). A `goto zero;` / `goto one;` + * chain expresses that layout directly, and each conditional jump is then followed by a + * compare/call rather than a lone const set, so the store-flag conversion never triggers. + * GENERAL RULE: multiple predicates that all assign the SAME constant to one flag => write + * them as `goto` to a shared assignment, never as an if/else ladder. + */ +extern s32 D_8011F9C4; +extern s32 D_80186F50; + +extern s32 func_80161B18(void); +extern s32 func_801619A4(s32*); +extern s32 func_80149AA8(s32*); +extern void func_80149AD4(s32*); +extern s32 func_80149B54(s32*); +extern void func_80149BAC(s32*); +extern s32 func_801498E0(s32*); +extern s32 func_80149954(s32); +extern s32 func_80149A64(s32*); +extern void func_800CCCC0(s32 a0); +extern s32 func_80149CD4(s32 a0); +extern void func_8015E880(s32*); +extern s32 func_80149744(struct S_80149744*); +extern void func_80149788(void); +extern s32 func_801496D4(void*); +extern void func_80149704(void); +extern int func_80148AFC(void*); +extern void func_80146D90(s32 a0); +extern void func_80154150(s32 a0, s32 a1); +extern void func_801541D8(u8*, s32, s32); +extern s32 func_801488A8(u8*); +extern void func_80147078(s32*, s16); +extern void func_8015A264(void*); +extern s32 func_80013294(void*, void*); +extern void func_80159B70(void*); +extern s32 func_8016F1AC(void); +extern s32 func_80029178(s32 a0); +extern void func_80146DB8(s32*, s32*); +extern s32 func_80161CD0(s32, s32); +extern s32 func_80161208(s32 a0); +extern s32 func_801725A4(u8*); + +s32 func_8015B950(s32 arg0) +{ + + extern void (*D_80186FBC[])(void *); + s16 sp10[4]; + s16 sp18[4]; + s32 t; + s32 z; + s32 doit; + s32 lim = -0xB0000; + + if (func_80161B18() != 0) { + return; + } + switch (((s32 (*)(s32))func_801619A4)(arg0)) { + case 0: + case 1: + case 2: + case 6: + if (((s32 (*)(s32))func_80149AA8)(arg0) != 0) { + D_80186FBC[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149AD4)(arg0); + return; + } + if (((s32 (*)(s32))func_80149B54)(arg0) != 0) { + D_80186FBC[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149BAC)(arg0); + return; + } + break; + case 3: + ((void (*)(s32))func_801498E0)(arg0); + break; + case 4: + ((void (*)(s32))func_80149954)(arg0); + break; + case 5: + if (((s32 (*)(s32))func_80149A64)(arg0) != 0) { + D_80186FBC[*(u16 *)arg0]((void *)arg0); + func_800CCCC0(arg0); + return; + } + break; + } + if (func_80149CD4(arg0) != 0) { + D_80186FBC[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_8015E880)(arg0); + return; + } + if (((s32 (*)(s32))func_80149744)(arg0) != 0) { + D_80186FBC[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149788)(arg0); + return; + } + if (((s32 (*)(s32))func_801496D4)(arg0) != 0) { + D_80186FBC[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149704)(arg0); + if (((u8)((s32 (*)(s32))func_80148AFC)(arg0)) == 0) { + func_80146D90(arg0); + } + if ((*(s32 *)(arg0 + 0x24) | *(s32 *)(arg0 + 0x2C)) != 0) { + func_80154150(arg0, 0xF); + } else { + ((void (*)(s32, s32, s32))func_801541D8)(arg0, 0xD, 6); + } + *(s32 *)(arg0 + 0x238) = 1; + return; + } + if (((s32 (*)(s32))func_801488A8)(arg0) != 0) { + sp10[0] = 0; + sp10[1] = 0; + sp10[2] = 0; + t = *(s16 *)(arg0 + 0x26); + sp18[0] = t; + sp18[1] = 0; + t = *(s16 *)(arg0 + 0x2E); + sp18[2] = t; + D_80186FBC[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 1); + ((void (*)(s32))func_8015A264)(arg0); + t = -(((s32 (*)(s16 *, s16 *))func_80013294)(sp10, sp18) << 0x10); + if (t < *(s32 *)(arg0 + 0x2C)) { + *(s32 *)(arg0 + 0x2C) = t; + } + return; + } + if (*(u16 *)(arg0 + 0xB8) == 0x8000) { + D_80186FBC[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 0); + ((void (*)(s32))func_80159B70)(arg0); + return; + } + z = *(s32 *)(arg0 + 0x2C); + if (func_8016F1AC() != 0) { + goto zero; + } + if (z <= lim) { + goto one; + } + if (D_8011F9C4 == 0) { + goto zero; + } + if (((u8)func_80029178(0x21)) != 0) { + goto zero; + } +one: + doit = 1; + goto join; +zero: + doit = 0; +join: + if (doit != 0) { + D_80186FBC[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 0); + ((void (*)(s32))func_80159B70)(arg0); + func_80154150(arg0, 9); + ((void (*)(s32, s32 *))func_80146DB8)(arg0, &D_80186F50); + ((void (*)(s32, s32))func_80161CD0)(arg0, *(u16 *)(arg0 + 0x16E)); + return; + } + if (func_80161208(arg0) == 0) { + ((void (*)(s32))func_801725A4)(arg0); + } +} DEFINE_func_8015BD8C() /* dedup: shared engine-core @0x8015BD8C (src/shared) */ diff --git a/src/ov_SC03_112/ov_SC03_112_jr_8015AE2C.c b/src/ov_SC03_112/ov_SC03_112_jr_8015AE2C.c index 400d1d052..e4982e98b 100644 --- a/src/ov_SC03_112/ov_SC03_112_jr_8015AE2C.c +++ b/src/ov_SC03_112/ov_SC03_112_jr_8015AE2C.c @@ -1512,7 +1512,259 @@ DEFINE_func_8015B858() /* dedup: shared engine-core @0x8015B858 (src/shared) */ DEFINE_func_8015B8F8() /* dedup: shared engine-core @0x8015B8F8 (src/shared) */ -INCLUDE_ASM("asm/ov_SC03_112/nonmatchings/ov_SC03_112_jr_8015AE2C", func_8015B950); +extern s32 func_8015AE2C(); + +// @class: plumbing +// @stuck: none — MATCH (271/271, pin-free, zero asm). The ONLY residual is DEF-SIDE plumbing, and it is now named exactly: the in-TU instantiation `DEFINE_func_8015BEE4()` (engine_core.h:1851-1855) expands to `extern s32 func_8015B950(void);` INSIDE ov_SC01_077_jr_8015AE2C.c, ~14 lines BELOW this definition, so the 1-param def collides with a `(void)` prototype -> `conflicting types for func_8015B950` (.run/bank_func_8015B950.log). §73 PARAMS axis / T0. Surgical fix = §65b de-macroize that ONE instantiation (blast radius: this TU); the fleet-wide `(void)`->`()` header edit is §63 and must be R22-validated. +/* func_8015B950 (ov_SC01_077_jr_8015AE2C, 271 ins, jtbl_801D8B74) — SESSION-21 re-verified + * + * ── ROUND-2 INDEPENDENT RE-VERIFICATION (2026-07-27, fresh agent, §88e discipline) ───────────── + * match_one : MATCH (271 ins) against the CURRENT tree — §87 staleness re-checked today. + * .text size: compiled .text = 0x43C = 1084 B = 271 ins, EXACTLY the target's declared 0x43C + * ("nonmatching func_8015B950, 0x43C"). So this is NOT a §83a length drift hiding + * behind a zero count — the count is over equal-length streams. + * jtbl : RE-DECODED MECHANICALLY, not inherited. Compiled .rodata = 0x1C = 28 B = 7 words, + * 7x R_MIPS_32 -> .text with implicit addends [58,58,58,E0,F0,100,58]; +0x8015B950 + * = [8015B9A8, 8015B9A8, 8015B9A8, 8015BA30, 8015BA40, 8015BA50, 8015B9A8]. + * Diffed word-for-word against asm/ov_SC01_077/data/tail14.data.s:15-23 — 7/7 identical. + * symcheck : SYMS-DIFF target=35 draft=34, sole MISSING = jtbl_801D8B74. This is the §81 jr + * FALSE POSITIVE, re-confirmed here by reading the relocs: gcc emits its OWN table and + * references it with R_MIPS_HI16/LO16 against the SECTION `.rodata` (t.o +0x40/+0x48), + * so the splat's dlabel NAME can never appear in the draft object's relocation set. + * Nothing is dropped and nothing is invented: the draft's other 34 symbols are exactly + * the target's other 34. + * FAMILY : the x138 remap is clean and §84-safe. Every sibling is 271 ins with an IDENTICAL + * callee set; only THREE names vary per overlay — the two data labels and the jtbl: + * ov_SC01_077 D_80187D58 / D_80187DC4 / jtbl_801D8B74 + * ov_SC03_099 D_80185A50 / D_80185ABC / jtbl_801BD898 + * ov_SC06_008 D_80187E44 / D_80187EB0 / jtbl_801A8734 + * The pair is always +0x6C apart, and NO literal in this draft encodes that distance + * (both labels are referenced by name), so there is no §84 derived-offset hazard. + * D_8011F9C4 is fleet-constant (main-EXE data) and must NOT be remapped. + * + * match_one: MATCH (271 ins) against the CURRENT tree (§87 staleness re-checked, 2026-07-27). + * PIN-FREE, zero asm, offset-pure (s32 arg0 + raw offsets) — x138 template-safe. + * Provenance: this is the Phase-26 crack (.run/phase26-cracks/func_8015B950.c) re-gated verbatim, + * with ONE deliberate change: the definition's return type void -> s32. + * - `void func_8015B950(s32 arg0)` : MATCH (271 ins) [the Phase-26 form] + * - `s32 func_8015B950(s32 arg0)` : MATCH (271 ins) [shipped — §3a-1 void->s32 is byte-neutral] + * The fleet/engine_core.h canonical decl is `extern s32 func_8015B950(void);` (engine_core.h:1852), + * and the last bank attempt (.run/bank_func_8015B950.log) died on `conflicting types for + * func_8015B950`. Shipping the s32 return kills the §73 RETURN axis for free and leaves only the + * cheap T0 PARAMS axis for the ladder (fix_header_decl.py / --fix-def-sig / cast_call_sites). + * Both forms are byte-identical, so the orchestrator may swap the return type back at zero cost. + * + * SYMBOLS (§58 rules 1/2 — all splat spellings, all verified present): + * D_80187DC4 asm/ov_SC01_077/data/tail.data.s:4355 (the state-handler vtable) + * D_80187D58 asm/ov_SC01_077/data/tail.data.s:4293 + * D_8011F9C4 main-EXE data; spelled `extern s32 D_8011F9C4;` in 5+ already-banked TUs + * jtbl_801D8B74 asm/ov_SC01_077/data/tail14.data.s:15 (compiler jump table — not named in C) + * + * JTBL VERIFIED (§8a gate): compiled .rodata = exactly 0x1C B / 7 words, 7x R_MIPS_32 .text with + * addends [0x58,0x58,0x58,0xE0,0xF0,0x100,0x58] -> +0x8015B950 = [B9A8,B9A8,B9A8,BA30,BA40,BA50, + * B9A8] == the original words at 0x801D8B74..0x801D8B8C. Bound `sltiu $v0,$v1,0x7` matches. + * The raw dlabel's 8th word 0x00000000 is NOT an entry — it is the intra-TU `.align 3` pad of the + * B34/B54/B74 jtbl chain; the object can never emit it (maspsx drops .align), so it must stay in + * the post-carve RAW data piece (the §53/§62/§81 carve chain applies at bank time). + * + * Same family as the TU's own already-matched func_8015AE2C: 7-case switch on ((s32 (*)(s32))func_801619A4)() + * (0/1/2/6 shared, 3/4/5 own, no default block — out-of-range and every `break` fall to the + * after-switch join), then a chain of "state handler" tests, each dispatching + * D_80187DC4[*(u16*)arg0](arg0) and returning. + * + * THREE LEVERS (draft -> MATCH in 3 compiles): + * + * 1. PROLOGUE CONSTANT = an INITIALIZED LOCAL, not a literal in the compare. + * Target opens with `lui $s2, 0xFFF5` in the *prologue*, used once ~200 ins later in + * `slt $v0,$s2,$s1`. No gcc-2.7.2 pass hoists a (set reg const_int) across basic blocks + * (loop.c needs a loop; cse/combine/sched never move insns between BBs) — so the insn must + * have been EMITTED in the first BB, i.e. the constant is a local initialized at the top of + * the function. cse then cannot fold it back into the compare: the `slt` operand predicate is + * `arith_operand`, which rejects a CONST_INT wider than 16 bits, so validate_change fails and + * the pseudo survives. Its live range spans every call -> global.c gives it a callee-saved reg. + * Writing `z > -0xB0000` inline instead emits the `lui` into the branch delay slot next to the + * compare (caller-saved $v0) and the function is 1 insn short. => `s32 lim = -0xB0000;` at top. + * + * 2. `lh` vs `lhu`: a short->short copy is a pure HImode move and gcc emits `lhu`. The target's + * `lh $v0,0x26($s0)` means the value passed through an SImode (int) temp: expand makes + * (set (reg:SI) (sign_extend (mem:HI))) + (set (mem:HI) (subreg:HI ...)), and combine cannot + * merge them (the merged form is mem<-mem, which no movhi accepts) so the sign-extending load + * survives. => route both halfword copies through the `s32 t` temp. + * + * 3. THE `goto` LAYOUT — dodging jump.c's store-flag conversion (jump.c:1005-1065). + * An if/else chain writing 0/1 into `doit` makes gcc collapse the last pair into + * `sltiu $v0,$v0,1`. jump.c fires that conversion when the insn immediately after a + * conditional jump is a lone `SET pseudo, CONST_INT` whose following simplejump targets the + * SAME label as the branch (jump.c:1038 `reallabelprev == temp || ... JUMP_LABEL(temp4) == + * JUMP_LABEL(insn)`) — exactly the shape of `if (c) x=0; else x=1;`. + * The target instead cross-jumps ALL the `doit=0` exits into ONE shared block placed after the + * `doit=1` fall-through; reorg's fill_slots_from_thread then COPIES that single set into all + * three branch delay slots and redirects each branch past it (which is why `addu $v0,$zero, + * $zero` appears 3x in delay slots and the shared block vanishes). A `goto zero;` / `goto one;` + * chain expresses that layout directly, and each conditional jump is then followed by a + * compare/call rather than a lone const set, so the store-flag conversion never triggers. + * GENERAL RULE: multiple predicates that all assign the SAME constant to one flag => write + * them as `goto` to a shared assignment, never as an if/else ladder. + */ +extern s32 D_8011F9C4; +extern s32 D_80187D58; + +extern s32 func_80161B18(void); +extern s32 func_801619A4(s32*); +extern s32 func_80149AA8(s32*); +extern void func_80149AD4(s32*); +extern s32 func_80149B54(s32*); +extern void func_80149BAC(s32*); +extern s32 func_801498E0(s32*); +extern s32 func_80149954(s32); +extern s32 func_80149A64(s32*); +extern void func_800CCCC0(s32 a0); +extern s32 func_80149CD4(s32 a0); +extern void func_8015E880(s32*); +extern s32 func_80149744(struct S_80149744*); +extern void func_80149788(void); +extern s32 func_801496D4(void*); +extern void func_80149704(void); +extern int func_80148AFC(void*); +extern void func_80146D90(s32 a0); +extern void func_80154150(s32 a0, s32 a1); +extern void func_801541D8(u8*, s32, s32); +extern s32 func_801488A8(u8*); +extern void func_80147078(s32*, s16); +extern void func_8015A264(void*); +extern s32 func_80013294(void*, void*); +extern void func_80159B70(void*); +extern s32 func_8016F1AC(void); +extern s32 func_80029178(s32 a0); +extern void func_80146DB8(s32*, s32*); +extern s32 func_80161CD0(s32, s32); +extern s32 func_80161208(s32 a0); +extern s32 func_801725A4(u8*); + +s32 func_8015B950(s32 arg0) +{ + + extern void (*D_80187DC4[])(void *); + s16 sp10[4]; + s16 sp18[4]; + s32 t; + s32 z; + s32 doit; + s32 lim = -0xB0000; + + if (func_80161B18() != 0) { + return; + } + switch (((s32 (*)(s32))func_801619A4)(arg0)) { + case 0: + case 1: + case 2: + case 6: + if (((s32 (*)(s32))func_80149AA8)(arg0) != 0) { + D_80187DC4[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149AD4)(arg0); + return; + } + if (((s32 (*)(s32))func_80149B54)(arg0) != 0) { + D_80187DC4[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149BAC)(arg0); + return; + } + break; + case 3: + ((void (*)(s32))func_801498E0)(arg0); + break; + case 4: + ((void (*)(s32))func_80149954)(arg0); + break; + case 5: + if (((s32 (*)(s32))func_80149A64)(arg0) != 0) { + D_80187DC4[*(u16 *)arg0]((void *)arg0); + func_800CCCC0(arg0); + return; + } + break; + } + if (func_80149CD4(arg0) != 0) { + D_80187DC4[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_8015E880)(arg0); + return; + } + if (((s32 (*)(s32))func_80149744)(arg0) != 0) { + D_80187DC4[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149788)(arg0); + return; + } + if (((s32 (*)(s32))func_801496D4)(arg0) != 0) { + D_80187DC4[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149704)(arg0); + if (((u8)((s32 (*)(s32))func_80148AFC)(arg0)) == 0) { + func_80146D90(arg0); + } + if ((*(s32 *)(arg0 + 0x24) | *(s32 *)(arg0 + 0x2C)) != 0) { + func_80154150(arg0, 0xF); + } else { + ((void (*)(s32, s32, s32))func_801541D8)(arg0, 0xD, 6); + } + *(s32 *)(arg0 + 0x238) = 1; + return; + } + if (((s32 (*)(s32))func_801488A8)(arg0) != 0) { + sp10[0] = 0; + sp10[1] = 0; + sp10[2] = 0; + t = *(s16 *)(arg0 + 0x26); + sp18[0] = t; + sp18[1] = 0; + t = *(s16 *)(arg0 + 0x2E); + sp18[2] = t; + D_80187DC4[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 1); + ((void (*)(s32))func_8015A264)(arg0); + t = -(((s32 (*)(s16 *, s16 *))func_80013294)(sp10, sp18) << 0x10); + if (t < *(s32 *)(arg0 + 0x2C)) { + *(s32 *)(arg0 + 0x2C) = t; + } + return; + } + if (*(u16 *)(arg0 + 0xB8) == 0x8000) { + D_80187DC4[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 0); + ((void (*)(s32))func_80159B70)(arg0); + return; + } + z = *(s32 *)(arg0 + 0x2C); + if (func_8016F1AC() != 0) { + goto zero; + } + if (z <= lim) { + goto one; + } + if (D_8011F9C4 == 0) { + goto zero; + } + if (((u8)func_80029178(0x21)) != 0) { + goto zero; + } +one: + doit = 1; + goto join; +zero: + doit = 0; +join: + if (doit != 0) { + D_80187DC4[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 0); + ((void (*)(s32))func_80159B70)(arg0); + func_80154150(arg0, 9); + ((void (*)(s32, s32 *))func_80146DB8)(arg0, &D_80187D58); + ((void (*)(s32, s32))func_80161CD0)(arg0, *(u16 *)(arg0 + 0x16E)); + return; + } + if (func_80161208(arg0) == 0) { + ((void (*)(s32))func_801725A4)(arg0); + } +} DEFINE_func_8015BD8C() /* dedup: shared engine-core @0x8015BD8C (src/shared) */ diff --git a/src/ov_SC03_113/ov_SC03_113_jr_8015AE2C.c b/src/ov_SC03_113/ov_SC03_113_jr_8015AE2C.c index 804377cc4..683441e82 100644 --- a/src/ov_SC03_113/ov_SC03_113_jr_8015AE2C.c +++ b/src/ov_SC03_113/ov_SC03_113_jr_8015AE2C.c @@ -1512,7 +1512,259 @@ DEFINE_func_8015B858() /* dedup: shared engine-core @0x8015B858 (src/shared) */ DEFINE_func_8015B8F8() /* dedup: shared engine-core @0x8015B8F8 (src/shared) */ -INCLUDE_ASM("asm/ov_SC03_113/nonmatchings/ov_SC03_113_jr_8015AE2C", func_8015B950); +extern s32 func_8015AE2C(); + +// @class: plumbing +// @stuck: none — MATCH (271/271, pin-free, zero asm). The ONLY residual is DEF-SIDE plumbing, and it is now named exactly: the in-TU instantiation `DEFINE_func_8015BEE4()` (engine_core.h:1851-1855) expands to `extern s32 func_8015B950(void);` INSIDE ov_SC01_077_jr_8015AE2C.c, ~14 lines BELOW this definition, so the 1-param def collides with a `(void)` prototype -> `conflicting types for func_8015B950` (.run/bank_func_8015B950.log). §73 PARAMS axis / T0. Surgical fix = §65b de-macroize that ONE instantiation (blast radius: this TU); the fleet-wide `(void)`->`()` header edit is §63 and must be R22-validated. +/* func_8015B950 (ov_SC01_077_jr_8015AE2C, 271 ins, jtbl_801D8B74) — SESSION-21 re-verified + * + * ── ROUND-2 INDEPENDENT RE-VERIFICATION (2026-07-27, fresh agent, §88e discipline) ───────────── + * match_one : MATCH (271 ins) against the CURRENT tree — §87 staleness re-checked today. + * .text size: compiled .text = 0x43C = 1084 B = 271 ins, EXACTLY the target's declared 0x43C + * ("nonmatching func_8015B950, 0x43C"). So this is NOT a §83a length drift hiding + * behind a zero count — the count is over equal-length streams. + * jtbl : RE-DECODED MECHANICALLY, not inherited. Compiled .rodata = 0x1C = 28 B = 7 words, + * 7x R_MIPS_32 -> .text with implicit addends [58,58,58,E0,F0,100,58]; +0x8015B950 + * = [8015B9A8, 8015B9A8, 8015B9A8, 8015BA30, 8015BA40, 8015BA50, 8015B9A8]. + * Diffed word-for-word against asm/ov_SC01_077/data/tail14.data.s:15-23 — 7/7 identical. + * symcheck : SYMS-DIFF target=35 draft=34, sole MISSING = jtbl_801D8B74. This is the §81 jr + * FALSE POSITIVE, re-confirmed here by reading the relocs: gcc emits its OWN table and + * references it with R_MIPS_HI16/LO16 against the SECTION `.rodata` (t.o +0x40/+0x48), + * so the splat's dlabel NAME can never appear in the draft object's relocation set. + * Nothing is dropped and nothing is invented: the draft's other 34 symbols are exactly + * the target's other 34. + * FAMILY : the x138 remap is clean and §84-safe. Every sibling is 271 ins with an IDENTICAL + * callee set; only THREE names vary per overlay — the two data labels and the jtbl: + * ov_SC01_077 D_80185408 / D_80185474 / jtbl_801D8B74 + * ov_SC03_099 D_80185A50 / D_80185ABC / jtbl_801BD898 + * ov_SC06_008 D_80187E44 / D_80187EB0 / jtbl_801A8734 + * The pair is always +0x6C apart, and NO literal in this draft encodes that distance + * (both labels are referenced by name), so there is no §84 derived-offset hazard. + * D_8011F9C4 is fleet-constant (main-EXE data) and must NOT be remapped. + * + * match_one: MATCH (271 ins) against the CURRENT tree (§87 staleness re-checked, 2026-07-27). + * PIN-FREE, zero asm, offset-pure (s32 arg0 + raw offsets) — x138 template-safe. + * Provenance: this is the Phase-26 crack (.run/phase26-cracks/func_8015B950.c) re-gated verbatim, + * with ONE deliberate change: the definition's return type void -> s32. + * - `void func_8015B950(s32 arg0)` : MATCH (271 ins) [the Phase-26 form] + * - `s32 func_8015B950(s32 arg0)` : MATCH (271 ins) [shipped — §3a-1 void->s32 is byte-neutral] + * The fleet/engine_core.h canonical decl is `extern s32 func_8015B950(void);` (engine_core.h:1852), + * and the last bank attempt (.run/bank_func_8015B950.log) died on `conflicting types for + * func_8015B950`. Shipping the s32 return kills the §73 RETURN axis for free and leaves only the + * cheap T0 PARAMS axis for the ladder (fix_header_decl.py / --fix-def-sig / cast_call_sites). + * Both forms are byte-identical, so the orchestrator may swap the return type back at zero cost. + * + * SYMBOLS (§58 rules 1/2 — all splat spellings, all verified present): + * D_80185474 asm/ov_SC01_077/data/tail.data.s:4355 (the state-handler vtable) + * D_80185408 asm/ov_SC01_077/data/tail.data.s:4293 + * D_8011F9C4 main-EXE data; spelled `extern s32 D_8011F9C4;` in 5+ already-banked TUs + * jtbl_801D8B74 asm/ov_SC01_077/data/tail14.data.s:15 (compiler jump table — not named in C) + * + * JTBL VERIFIED (§8a gate): compiled .rodata = exactly 0x1C B / 7 words, 7x R_MIPS_32 .text with + * addends [0x58,0x58,0x58,0xE0,0xF0,0x100,0x58] -> +0x8015B950 = [B9A8,B9A8,B9A8,BA30,BA40,BA50, + * B9A8] == the original words at 0x801D8B74..0x801D8B8C. Bound `sltiu $v0,$v1,0x7` matches. + * The raw dlabel's 8th word 0x00000000 is NOT an entry — it is the intra-TU `.align 3` pad of the + * B34/B54/B74 jtbl chain; the object can never emit it (maspsx drops .align), so it must stay in + * the post-carve RAW data piece (the §53/§62/§81 carve chain applies at bank time). + * + * Same family as the TU's own already-matched func_8015AE2C: 7-case switch on ((s32 (*)(s32))func_801619A4)() + * (0/1/2/6 shared, 3/4/5 own, no default block — out-of-range and every `break` fall to the + * after-switch join), then a chain of "state handler" tests, each dispatching + * D_80185474[*(u16*)arg0](arg0) and returning. + * + * THREE LEVERS (draft -> MATCH in 3 compiles): + * + * 1. PROLOGUE CONSTANT = an INITIALIZED LOCAL, not a literal in the compare. + * Target opens with `lui $s2, 0xFFF5` in the *prologue*, used once ~200 ins later in + * `slt $v0,$s2,$s1`. No gcc-2.7.2 pass hoists a (set reg const_int) across basic blocks + * (loop.c needs a loop; cse/combine/sched never move insns between BBs) — so the insn must + * have been EMITTED in the first BB, i.e. the constant is a local initialized at the top of + * the function. cse then cannot fold it back into the compare: the `slt` operand predicate is + * `arith_operand`, which rejects a CONST_INT wider than 16 bits, so validate_change fails and + * the pseudo survives. Its live range spans every call -> global.c gives it a callee-saved reg. + * Writing `z > -0xB0000` inline instead emits the `lui` into the branch delay slot next to the + * compare (caller-saved $v0) and the function is 1 insn short. => `s32 lim = -0xB0000;` at top. + * + * 2. `lh` vs `lhu`: a short->short copy is a pure HImode move and gcc emits `lhu`. The target's + * `lh $v0,0x26($s0)` means the value passed through an SImode (int) temp: expand makes + * (set (reg:SI) (sign_extend (mem:HI))) + (set (mem:HI) (subreg:HI ...)), and combine cannot + * merge them (the merged form is mem<-mem, which no movhi accepts) so the sign-extending load + * survives. => route both halfword copies through the `s32 t` temp. + * + * 3. THE `goto` LAYOUT — dodging jump.c's store-flag conversion (jump.c:1005-1065). + * An if/else chain writing 0/1 into `doit` makes gcc collapse the last pair into + * `sltiu $v0,$v0,1`. jump.c fires that conversion when the insn immediately after a + * conditional jump is a lone `SET pseudo, CONST_INT` whose following simplejump targets the + * SAME label as the branch (jump.c:1038 `reallabelprev == temp || ... JUMP_LABEL(temp4) == + * JUMP_LABEL(insn)`) — exactly the shape of `if (c) x=0; else x=1;`. + * The target instead cross-jumps ALL the `doit=0` exits into ONE shared block placed after the + * `doit=1` fall-through; reorg's fill_slots_from_thread then COPIES that single set into all + * three branch delay slots and redirects each branch past it (which is why `addu $v0,$zero, + * $zero` appears 3x in delay slots and the shared block vanishes). A `goto zero;` / `goto one;` + * chain expresses that layout directly, and each conditional jump is then followed by a + * compare/call rather than a lone const set, so the store-flag conversion never triggers. + * GENERAL RULE: multiple predicates that all assign the SAME constant to one flag => write + * them as `goto` to a shared assignment, never as an if/else ladder. + */ +extern s32 D_8011F9C4; +extern s32 D_80185408; + +extern s32 func_80161B18(void); +extern s32 func_801619A4(s32*); +extern s32 func_80149AA8(s32*); +extern void func_80149AD4(s32*); +extern s32 func_80149B54(s32*); +extern void func_80149BAC(s32*); +extern s32 func_801498E0(s32*); +extern s32 func_80149954(s32); +extern s32 func_80149A64(s32*); +extern void func_800CCCC0(s32 a0); +extern s32 func_80149CD4(s32 a0); +extern void func_8015E880(s32*); +extern s32 func_80149744(struct S_80149744*); +extern void func_80149788(void); +extern s32 func_801496D4(void*); +extern void func_80149704(void); +extern int func_80148AFC(void*); +extern void func_80146D90(s32 a0); +extern void func_80154150(s32 a0, s32 a1); +extern void func_801541D8(u8*, s32, s32); +extern s32 func_801488A8(u8*); +extern void func_80147078(s32*, s16); +extern void func_8015A264(void*); +extern s32 func_80013294(void*, void*); +extern void func_80159B70(void*); +extern s32 func_8016F1AC(void); +extern s32 func_80029178(s32 a0); +extern void func_80146DB8(s32*, s32*); +extern s32 func_80161CD0(s32, s32); +extern s32 func_80161208(s32 a0); +extern s32 func_801725A4(u8*); + +s32 func_8015B950(s32 arg0) +{ + + extern void (*D_80185474[])(void *); + s16 sp10[4]; + s16 sp18[4]; + s32 t; + s32 z; + s32 doit; + s32 lim = -0xB0000; + + if (func_80161B18() != 0) { + return; + } + switch (((s32 (*)(s32))func_801619A4)(arg0)) { + case 0: + case 1: + case 2: + case 6: + if (((s32 (*)(s32))func_80149AA8)(arg0) != 0) { + D_80185474[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149AD4)(arg0); + return; + } + if (((s32 (*)(s32))func_80149B54)(arg0) != 0) { + D_80185474[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149BAC)(arg0); + return; + } + break; + case 3: + ((void (*)(s32))func_801498E0)(arg0); + break; + case 4: + ((void (*)(s32))func_80149954)(arg0); + break; + case 5: + if (((s32 (*)(s32))func_80149A64)(arg0) != 0) { + D_80185474[*(u16 *)arg0]((void *)arg0); + func_800CCCC0(arg0); + return; + } + break; + } + if (func_80149CD4(arg0) != 0) { + D_80185474[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_8015E880)(arg0); + return; + } + if (((s32 (*)(s32))func_80149744)(arg0) != 0) { + D_80185474[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149788)(arg0); + return; + } + if (((s32 (*)(s32))func_801496D4)(arg0) != 0) { + D_80185474[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149704)(arg0); + if (((u8)((s32 (*)(s32))func_80148AFC)(arg0)) == 0) { + func_80146D90(arg0); + } + if ((*(s32 *)(arg0 + 0x24) | *(s32 *)(arg0 + 0x2C)) != 0) { + func_80154150(arg0, 0xF); + } else { + ((void (*)(s32, s32, s32))func_801541D8)(arg0, 0xD, 6); + } + *(s32 *)(arg0 + 0x238) = 1; + return; + } + if (((s32 (*)(s32))func_801488A8)(arg0) != 0) { + sp10[0] = 0; + sp10[1] = 0; + sp10[2] = 0; + t = *(s16 *)(arg0 + 0x26); + sp18[0] = t; + sp18[1] = 0; + t = *(s16 *)(arg0 + 0x2E); + sp18[2] = t; + D_80185474[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 1); + ((void (*)(s32))func_8015A264)(arg0); + t = -(((s32 (*)(s16 *, s16 *))func_80013294)(sp10, sp18) << 0x10); + if (t < *(s32 *)(arg0 + 0x2C)) { + *(s32 *)(arg0 + 0x2C) = t; + } + return; + } + if (*(u16 *)(arg0 + 0xB8) == 0x8000) { + D_80185474[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 0); + ((void (*)(s32))func_80159B70)(arg0); + return; + } + z = *(s32 *)(arg0 + 0x2C); + if (func_8016F1AC() != 0) { + goto zero; + } + if (z <= lim) { + goto one; + } + if (D_8011F9C4 == 0) { + goto zero; + } + if (((u8)func_80029178(0x21)) != 0) { + goto zero; + } +one: + doit = 1; + goto join; +zero: + doit = 0; +join: + if (doit != 0) { + D_80185474[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 0); + ((void (*)(s32))func_80159B70)(arg0); + func_80154150(arg0, 9); + ((void (*)(s32, s32 *))func_80146DB8)(arg0, &D_80185408); + ((void (*)(s32, s32))func_80161CD0)(arg0, *(u16 *)(arg0 + 0x16E)); + return; + } + if (func_80161208(arg0) == 0) { + ((void (*)(s32))func_801725A4)(arg0); + } +} DEFINE_func_8015BD8C() /* dedup: shared engine-core @0x8015BD8C (src/shared) */ diff --git a/src/ov_SC03_114/ov_SC03_114_jr_8015AE2C.c b/src/ov_SC03_114/ov_SC03_114_jr_8015AE2C.c index 849bfe9e3..600a47c2d 100644 --- a/src/ov_SC03_114/ov_SC03_114_jr_8015AE2C.c +++ b/src/ov_SC03_114/ov_SC03_114_jr_8015AE2C.c @@ -1512,7 +1512,259 @@ DEFINE_func_8015B858() /* dedup: shared engine-core @0x8015B858 (src/shared) */ DEFINE_func_8015B8F8() /* dedup: shared engine-core @0x8015B8F8 (src/shared) */ -INCLUDE_ASM("asm/ov_SC03_114/nonmatchings/ov_SC03_114_jr_8015AE2C", func_8015B950); +extern s32 func_8015AE2C(); + +// @class: plumbing +// @stuck: none — MATCH (271/271, pin-free, zero asm). The ONLY residual is DEF-SIDE plumbing, and it is now named exactly: the in-TU instantiation `DEFINE_func_8015BEE4()` (engine_core.h:1851-1855) expands to `extern s32 func_8015B950(void);` INSIDE ov_SC01_077_jr_8015AE2C.c, ~14 lines BELOW this definition, so the 1-param def collides with a `(void)` prototype -> `conflicting types for func_8015B950` (.run/bank_func_8015B950.log). §73 PARAMS axis / T0. Surgical fix = §65b de-macroize that ONE instantiation (blast radius: this TU); the fleet-wide `(void)`->`()` header edit is §63 and must be R22-validated. +/* func_8015B950 (ov_SC01_077_jr_8015AE2C, 271 ins, jtbl_801D8B74) — SESSION-21 re-verified + * + * ── ROUND-2 INDEPENDENT RE-VERIFICATION (2026-07-27, fresh agent, §88e discipline) ───────────── + * match_one : MATCH (271 ins) against the CURRENT tree — §87 staleness re-checked today. + * .text size: compiled .text = 0x43C = 1084 B = 271 ins, EXACTLY the target's declared 0x43C + * ("nonmatching func_8015B950, 0x43C"). So this is NOT a §83a length drift hiding + * behind a zero count — the count is over equal-length streams. + * jtbl : RE-DECODED MECHANICALLY, not inherited. Compiled .rodata = 0x1C = 28 B = 7 words, + * 7x R_MIPS_32 -> .text with implicit addends [58,58,58,E0,F0,100,58]; +0x8015B950 + * = [8015B9A8, 8015B9A8, 8015B9A8, 8015BA30, 8015BA40, 8015BA50, 8015B9A8]. + * Diffed word-for-word against asm/ov_SC01_077/data/tail14.data.s:15-23 — 7/7 identical. + * symcheck : SYMS-DIFF target=35 draft=34, sole MISSING = jtbl_801D8B74. This is the §81 jr + * FALSE POSITIVE, re-confirmed here by reading the relocs: gcc emits its OWN table and + * references it with R_MIPS_HI16/LO16 against the SECTION `.rodata` (t.o +0x40/+0x48), + * so the splat's dlabel NAME can never appear in the draft object's relocation set. + * Nothing is dropped and nothing is invented: the draft's other 34 symbols are exactly + * the target's other 34. + * FAMILY : the x138 remap is clean and §84-safe. Every sibling is 271 ins with an IDENTICAL + * callee set; only THREE names vary per overlay — the two data labels and the jtbl: + * ov_SC01_077 D_80181070 / D_801810DC / jtbl_801D8B74 + * ov_SC03_099 D_80185A50 / D_80185ABC / jtbl_801BD898 + * ov_SC06_008 D_80187E44 / D_80187EB0 / jtbl_801A8734 + * The pair is always +0x6C apart, and NO literal in this draft encodes that distance + * (both labels are referenced by name), so there is no §84 derived-offset hazard. + * D_8011F9C4 is fleet-constant (main-EXE data) and must NOT be remapped. + * + * match_one: MATCH (271 ins) against the CURRENT tree (§87 staleness re-checked, 2026-07-27). + * PIN-FREE, zero asm, offset-pure (s32 arg0 + raw offsets) — x138 template-safe. + * Provenance: this is the Phase-26 crack (.run/phase26-cracks/func_8015B950.c) re-gated verbatim, + * with ONE deliberate change: the definition's return type void -> s32. + * - `void func_8015B950(s32 arg0)` : MATCH (271 ins) [the Phase-26 form] + * - `s32 func_8015B950(s32 arg0)` : MATCH (271 ins) [shipped — §3a-1 void->s32 is byte-neutral] + * The fleet/engine_core.h canonical decl is `extern s32 func_8015B950(void);` (engine_core.h:1852), + * and the last bank attempt (.run/bank_func_8015B950.log) died on `conflicting types for + * func_8015B950`. Shipping the s32 return kills the §73 RETURN axis for free and leaves only the + * cheap T0 PARAMS axis for the ladder (fix_header_decl.py / --fix-def-sig / cast_call_sites). + * Both forms are byte-identical, so the orchestrator may swap the return type back at zero cost. + * + * SYMBOLS (§58 rules 1/2 — all splat spellings, all verified present): + * D_801810DC asm/ov_SC01_077/data/tail.data.s:4355 (the state-handler vtable) + * D_80181070 asm/ov_SC01_077/data/tail.data.s:4293 + * D_8011F9C4 main-EXE data; spelled `extern s32 D_8011F9C4;` in 5+ already-banked TUs + * jtbl_801D8B74 asm/ov_SC01_077/data/tail14.data.s:15 (compiler jump table — not named in C) + * + * JTBL VERIFIED (§8a gate): compiled .rodata = exactly 0x1C B / 7 words, 7x R_MIPS_32 .text with + * addends [0x58,0x58,0x58,0xE0,0xF0,0x100,0x58] -> +0x8015B950 = [B9A8,B9A8,B9A8,BA30,BA40,BA50, + * B9A8] == the original words at 0x801D8B74..0x801D8B8C. Bound `sltiu $v0,$v1,0x7` matches. + * The raw dlabel's 8th word 0x00000000 is NOT an entry — it is the intra-TU `.align 3` pad of the + * B34/B54/B74 jtbl chain; the object can never emit it (maspsx drops .align), so it must stay in + * the post-carve RAW data piece (the §53/§62/§81 carve chain applies at bank time). + * + * Same family as the TU's own already-matched func_8015AE2C: 7-case switch on ((s32 (*)(s32))func_801619A4)() + * (0/1/2/6 shared, 3/4/5 own, no default block — out-of-range and every `break` fall to the + * after-switch join), then a chain of "state handler" tests, each dispatching + * D_801810DC[*(u16*)arg0](arg0) and returning. + * + * THREE LEVERS (draft -> MATCH in 3 compiles): + * + * 1. PROLOGUE CONSTANT = an INITIALIZED LOCAL, not a literal in the compare. + * Target opens with `lui $s2, 0xFFF5` in the *prologue*, used once ~200 ins later in + * `slt $v0,$s2,$s1`. No gcc-2.7.2 pass hoists a (set reg const_int) across basic blocks + * (loop.c needs a loop; cse/combine/sched never move insns between BBs) — so the insn must + * have been EMITTED in the first BB, i.e. the constant is a local initialized at the top of + * the function. cse then cannot fold it back into the compare: the `slt` operand predicate is + * `arith_operand`, which rejects a CONST_INT wider than 16 bits, so validate_change fails and + * the pseudo survives. Its live range spans every call -> global.c gives it a callee-saved reg. + * Writing `z > -0xB0000` inline instead emits the `lui` into the branch delay slot next to the + * compare (caller-saved $v0) and the function is 1 insn short. => `s32 lim = -0xB0000;` at top. + * + * 2. `lh` vs `lhu`: a short->short copy is a pure HImode move and gcc emits `lhu`. The target's + * `lh $v0,0x26($s0)` means the value passed through an SImode (int) temp: expand makes + * (set (reg:SI) (sign_extend (mem:HI))) + (set (mem:HI) (subreg:HI ...)), and combine cannot + * merge them (the merged form is mem<-mem, which no movhi accepts) so the sign-extending load + * survives. => route both halfword copies through the `s32 t` temp. + * + * 3. THE `goto` LAYOUT — dodging jump.c's store-flag conversion (jump.c:1005-1065). + * An if/else chain writing 0/1 into `doit` makes gcc collapse the last pair into + * `sltiu $v0,$v0,1`. jump.c fires that conversion when the insn immediately after a + * conditional jump is a lone `SET pseudo, CONST_INT` whose following simplejump targets the + * SAME label as the branch (jump.c:1038 `reallabelprev == temp || ... JUMP_LABEL(temp4) == + * JUMP_LABEL(insn)`) — exactly the shape of `if (c) x=0; else x=1;`. + * The target instead cross-jumps ALL the `doit=0` exits into ONE shared block placed after the + * `doit=1` fall-through; reorg's fill_slots_from_thread then COPIES that single set into all + * three branch delay slots and redirects each branch past it (which is why `addu $v0,$zero, + * $zero` appears 3x in delay slots and the shared block vanishes). A `goto zero;` / `goto one;` + * chain expresses that layout directly, and each conditional jump is then followed by a + * compare/call rather than a lone const set, so the store-flag conversion never triggers. + * GENERAL RULE: multiple predicates that all assign the SAME constant to one flag => write + * them as `goto` to a shared assignment, never as an if/else ladder. + */ +extern s32 D_8011F9C4; +extern s32 D_80181070; + +extern s32 func_80161B18(void); +extern s32 func_801619A4(s32*); +extern s32 func_80149AA8(s32*); +extern void func_80149AD4(s32*); +extern s32 func_80149B54(s32*); +extern void func_80149BAC(s32*); +extern s32 func_801498E0(s32*); +extern s32 func_80149954(s32); +extern s32 func_80149A64(s32*); +extern void func_800CCCC0(s32 a0); +extern s32 func_80149CD4(s32 a0); +extern void func_8015E880(s32*); +extern s32 func_80149744(struct S_80149744*); +extern void func_80149788(void); +extern s32 func_801496D4(void*); +extern void func_80149704(void); +extern int func_80148AFC(void*); +extern void func_80146D90(s32 a0); +extern void func_80154150(s32 a0, s32 a1); +extern void func_801541D8(u8*, s32, s32); +extern s32 func_801488A8(u8*); +extern void func_80147078(s32*, s16); +extern void func_8015A264(void*); +extern s32 func_80013294(void*, void*); +extern void func_80159B70(void*); +extern s32 func_8016F1AC(void); +extern s32 func_80029178(s32 a0); +extern void func_80146DB8(s32*, s32*); +extern s32 func_80161CD0(s32, s32); +extern s32 func_80161208(s32 a0); +extern s32 func_801725A4(u8*); + +s32 func_8015B950(s32 arg0) +{ + + extern void (*D_801810DC[])(void *); + s16 sp10[4]; + s16 sp18[4]; + s32 t; + s32 z; + s32 doit; + s32 lim = -0xB0000; + + if (func_80161B18() != 0) { + return; + } + switch (((s32 (*)(s32))func_801619A4)(arg0)) { + case 0: + case 1: + case 2: + case 6: + if (((s32 (*)(s32))func_80149AA8)(arg0) != 0) { + D_801810DC[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149AD4)(arg0); + return; + } + if (((s32 (*)(s32))func_80149B54)(arg0) != 0) { + D_801810DC[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149BAC)(arg0); + return; + } + break; + case 3: + ((void (*)(s32))func_801498E0)(arg0); + break; + case 4: + ((void (*)(s32))func_80149954)(arg0); + break; + case 5: + if (((s32 (*)(s32))func_80149A64)(arg0) != 0) { + D_801810DC[*(u16 *)arg0]((void *)arg0); + func_800CCCC0(arg0); + return; + } + break; + } + if (func_80149CD4(arg0) != 0) { + D_801810DC[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_8015E880)(arg0); + return; + } + if (((s32 (*)(s32))func_80149744)(arg0) != 0) { + D_801810DC[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149788)(arg0); + return; + } + if (((s32 (*)(s32))func_801496D4)(arg0) != 0) { + D_801810DC[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149704)(arg0); + if (((u8)((s32 (*)(s32))func_80148AFC)(arg0)) == 0) { + func_80146D90(arg0); + } + if ((*(s32 *)(arg0 + 0x24) | *(s32 *)(arg0 + 0x2C)) != 0) { + func_80154150(arg0, 0xF); + } else { + ((void (*)(s32, s32, s32))func_801541D8)(arg0, 0xD, 6); + } + *(s32 *)(arg0 + 0x238) = 1; + return; + } + if (((s32 (*)(s32))func_801488A8)(arg0) != 0) { + sp10[0] = 0; + sp10[1] = 0; + sp10[2] = 0; + t = *(s16 *)(arg0 + 0x26); + sp18[0] = t; + sp18[1] = 0; + t = *(s16 *)(arg0 + 0x2E); + sp18[2] = t; + D_801810DC[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 1); + ((void (*)(s32))func_8015A264)(arg0); + t = -(((s32 (*)(s16 *, s16 *))func_80013294)(sp10, sp18) << 0x10); + if (t < *(s32 *)(arg0 + 0x2C)) { + *(s32 *)(arg0 + 0x2C) = t; + } + return; + } + if (*(u16 *)(arg0 + 0xB8) == 0x8000) { + D_801810DC[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 0); + ((void (*)(s32))func_80159B70)(arg0); + return; + } + z = *(s32 *)(arg0 + 0x2C); + if (func_8016F1AC() != 0) { + goto zero; + } + if (z <= lim) { + goto one; + } + if (D_8011F9C4 == 0) { + goto zero; + } + if (((u8)func_80029178(0x21)) != 0) { + goto zero; + } +one: + doit = 1; + goto join; +zero: + doit = 0; +join: + if (doit != 0) { + D_801810DC[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 0); + ((void (*)(s32))func_80159B70)(arg0); + func_80154150(arg0, 9); + ((void (*)(s32, s32 *))func_80146DB8)(arg0, &D_80181070); + ((void (*)(s32, s32))func_80161CD0)(arg0, *(u16 *)(arg0 + 0x16E)); + return; + } + if (func_80161208(arg0) == 0) { + ((void (*)(s32))func_801725A4)(arg0); + } +} DEFINE_func_8015BD8C() /* dedup: shared engine-core @0x8015BD8C (src/shared) */ diff --git a/src/ov_SC03_115/ov_SC03_115_jr_8015AE2C.c b/src/ov_SC03_115/ov_SC03_115_jr_8015AE2C.c index ca0b22ada..060f497af 100644 --- a/src/ov_SC03_115/ov_SC03_115_jr_8015AE2C.c +++ b/src/ov_SC03_115/ov_SC03_115_jr_8015AE2C.c @@ -1512,7 +1512,259 @@ DEFINE_func_8015B858() /* dedup: shared engine-core @0x8015B858 (src/shared) */ DEFINE_func_8015B8F8() /* dedup: shared engine-core @0x8015B8F8 (src/shared) */ -INCLUDE_ASM("asm/ov_SC03_115/nonmatchings/ov_SC03_115_jr_8015AE2C", func_8015B950); +extern s32 func_8015AE2C(); + +// @class: plumbing +// @stuck: none — MATCH (271/271, pin-free, zero asm). The ONLY residual is DEF-SIDE plumbing, and it is now named exactly: the in-TU instantiation `DEFINE_func_8015BEE4()` (engine_core.h:1851-1855) expands to `extern s32 func_8015B950(void);` INSIDE ov_SC01_077_jr_8015AE2C.c, ~14 lines BELOW this definition, so the 1-param def collides with a `(void)` prototype -> `conflicting types for func_8015B950` (.run/bank_func_8015B950.log). §73 PARAMS axis / T0. Surgical fix = §65b de-macroize that ONE instantiation (blast radius: this TU); the fleet-wide `(void)`->`()` header edit is §63 and must be R22-validated. +/* func_8015B950 (ov_SC01_077_jr_8015AE2C, 271 ins, jtbl_801D8B74) — SESSION-21 re-verified + * + * ── ROUND-2 INDEPENDENT RE-VERIFICATION (2026-07-27, fresh agent, §88e discipline) ───────────── + * match_one : MATCH (271 ins) against the CURRENT tree — §87 staleness re-checked today. + * .text size: compiled .text = 0x43C = 1084 B = 271 ins, EXACTLY the target's declared 0x43C + * ("nonmatching func_8015B950, 0x43C"). So this is NOT a §83a length drift hiding + * behind a zero count — the count is over equal-length streams. + * jtbl : RE-DECODED MECHANICALLY, not inherited. Compiled .rodata = 0x1C = 28 B = 7 words, + * 7x R_MIPS_32 -> .text with implicit addends [58,58,58,E0,F0,100,58]; +0x8015B950 + * = [8015B9A8, 8015B9A8, 8015B9A8, 8015BA30, 8015BA40, 8015BA50, 8015B9A8]. + * Diffed word-for-word against asm/ov_SC01_077/data/tail14.data.s:15-23 — 7/7 identical. + * symcheck : SYMS-DIFF target=35 draft=34, sole MISSING = jtbl_801D8B74. This is the §81 jr + * FALSE POSITIVE, re-confirmed here by reading the relocs: gcc emits its OWN table and + * references it with R_MIPS_HI16/LO16 against the SECTION `.rodata` (t.o +0x40/+0x48), + * so the splat's dlabel NAME can never appear in the draft object's relocation set. + * Nothing is dropped and nothing is invented: the draft's other 34 symbols are exactly + * the target's other 34. + * FAMILY : the x138 remap is clean and §84-safe. Every sibling is 271 ins with an IDENTICAL + * callee set; only THREE names vary per overlay — the two data labels and the jtbl: + * ov_SC01_077 D_80182ADC / D_80182B48 / jtbl_801D8B74 + * ov_SC03_099 D_80185A50 / D_80185ABC / jtbl_801BD898 + * ov_SC06_008 D_80187E44 / D_80187EB0 / jtbl_801A8734 + * The pair is always +0x6C apart, and NO literal in this draft encodes that distance + * (both labels are referenced by name), so there is no §84 derived-offset hazard. + * D_8011F9C4 is fleet-constant (main-EXE data) and must NOT be remapped. + * + * match_one: MATCH (271 ins) against the CURRENT tree (§87 staleness re-checked, 2026-07-27). + * PIN-FREE, zero asm, offset-pure (s32 arg0 + raw offsets) — x138 template-safe. + * Provenance: this is the Phase-26 crack (.run/phase26-cracks/func_8015B950.c) re-gated verbatim, + * with ONE deliberate change: the definition's return type void -> s32. + * - `void func_8015B950(s32 arg0)` : MATCH (271 ins) [the Phase-26 form] + * - `s32 func_8015B950(s32 arg0)` : MATCH (271 ins) [shipped — §3a-1 void->s32 is byte-neutral] + * The fleet/engine_core.h canonical decl is `extern s32 func_8015B950(void);` (engine_core.h:1852), + * and the last bank attempt (.run/bank_func_8015B950.log) died on `conflicting types for + * func_8015B950`. Shipping the s32 return kills the §73 RETURN axis for free and leaves only the + * cheap T0 PARAMS axis for the ladder (fix_header_decl.py / --fix-def-sig / cast_call_sites). + * Both forms are byte-identical, so the orchestrator may swap the return type back at zero cost. + * + * SYMBOLS (§58 rules 1/2 — all splat spellings, all verified present): + * D_80182B48 asm/ov_SC01_077/data/tail.data.s:4355 (the state-handler vtable) + * D_80182ADC asm/ov_SC01_077/data/tail.data.s:4293 + * D_8011F9C4 main-EXE data; spelled `extern s32 D_8011F9C4;` in 5+ already-banked TUs + * jtbl_801D8B74 asm/ov_SC01_077/data/tail14.data.s:15 (compiler jump table — not named in C) + * + * JTBL VERIFIED (§8a gate): compiled .rodata = exactly 0x1C B / 7 words, 7x R_MIPS_32 .text with + * addends [0x58,0x58,0x58,0xE0,0xF0,0x100,0x58] -> +0x8015B950 = [B9A8,B9A8,B9A8,BA30,BA40,BA50, + * B9A8] == the original words at 0x801D8B74..0x801D8B8C. Bound `sltiu $v0,$v1,0x7` matches. + * The raw dlabel's 8th word 0x00000000 is NOT an entry — it is the intra-TU `.align 3` pad of the + * B34/B54/B74 jtbl chain; the object can never emit it (maspsx drops .align), so it must stay in + * the post-carve RAW data piece (the §53/§62/§81 carve chain applies at bank time). + * + * Same family as the TU's own already-matched func_8015AE2C: 7-case switch on ((s32 (*)(s32))func_801619A4)() + * (0/1/2/6 shared, 3/4/5 own, no default block — out-of-range and every `break` fall to the + * after-switch join), then a chain of "state handler" tests, each dispatching + * D_80182B48[*(u16*)arg0](arg0) and returning. + * + * THREE LEVERS (draft -> MATCH in 3 compiles): + * + * 1. PROLOGUE CONSTANT = an INITIALIZED LOCAL, not a literal in the compare. + * Target opens with `lui $s2, 0xFFF5` in the *prologue*, used once ~200 ins later in + * `slt $v0,$s2,$s1`. No gcc-2.7.2 pass hoists a (set reg const_int) across basic blocks + * (loop.c needs a loop; cse/combine/sched never move insns between BBs) — so the insn must + * have been EMITTED in the first BB, i.e. the constant is a local initialized at the top of + * the function. cse then cannot fold it back into the compare: the `slt` operand predicate is + * `arith_operand`, which rejects a CONST_INT wider than 16 bits, so validate_change fails and + * the pseudo survives. Its live range spans every call -> global.c gives it a callee-saved reg. + * Writing `z > -0xB0000` inline instead emits the `lui` into the branch delay slot next to the + * compare (caller-saved $v0) and the function is 1 insn short. => `s32 lim = -0xB0000;` at top. + * + * 2. `lh` vs `lhu`: a short->short copy is a pure HImode move and gcc emits `lhu`. The target's + * `lh $v0,0x26($s0)` means the value passed through an SImode (int) temp: expand makes + * (set (reg:SI) (sign_extend (mem:HI))) + (set (mem:HI) (subreg:HI ...)), and combine cannot + * merge them (the merged form is mem<-mem, which no movhi accepts) so the sign-extending load + * survives. => route both halfword copies through the `s32 t` temp. + * + * 3. THE `goto` LAYOUT — dodging jump.c's store-flag conversion (jump.c:1005-1065). + * An if/else chain writing 0/1 into `doit` makes gcc collapse the last pair into + * `sltiu $v0,$v0,1`. jump.c fires that conversion when the insn immediately after a + * conditional jump is a lone `SET pseudo, CONST_INT` whose following simplejump targets the + * SAME label as the branch (jump.c:1038 `reallabelprev == temp || ... JUMP_LABEL(temp4) == + * JUMP_LABEL(insn)`) — exactly the shape of `if (c) x=0; else x=1;`. + * The target instead cross-jumps ALL the `doit=0` exits into ONE shared block placed after the + * `doit=1` fall-through; reorg's fill_slots_from_thread then COPIES that single set into all + * three branch delay slots and redirects each branch past it (which is why `addu $v0,$zero, + * $zero` appears 3x in delay slots and the shared block vanishes). A `goto zero;` / `goto one;` + * chain expresses that layout directly, and each conditional jump is then followed by a + * compare/call rather than a lone const set, so the store-flag conversion never triggers. + * GENERAL RULE: multiple predicates that all assign the SAME constant to one flag => write + * them as `goto` to a shared assignment, never as an if/else ladder. + */ +extern s32 D_8011F9C4; +extern s32 D_80182ADC; + +extern s32 func_80161B18(void); +extern s32 func_801619A4(s32*); +extern s32 func_80149AA8(s32*); +extern void func_80149AD4(s32*); +extern s32 func_80149B54(s32*); +extern void func_80149BAC(s32*); +extern s32 func_801498E0(s32*); +extern s32 func_80149954(s32); +extern s32 func_80149A64(s32*); +extern void func_800CCCC0(s32 a0); +extern s32 func_80149CD4(s32 a0); +extern void func_8015E880(s32*); +extern s32 func_80149744(struct S_80149744*); +extern void func_80149788(void); +extern s32 func_801496D4(void*); +extern void func_80149704(void); +extern int func_80148AFC(void*); +extern void func_80146D90(s32 a0); +extern void func_80154150(s32 a0, s32 a1); +extern void func_801541D8(u8*, s32, s32); +extern s32 func_801488A8(u8*); +extern void func_80147078(s32*, s16); +extern void func_8015A264(void*); +extern s32 func_80013294(void*, void*); +extern void func_80159B70(void*); +extern s32 func_8016F1AC(void); +extern s32 func_80029178(s32 a0); +extern void func_80146DB8(s32*, s32*); +extern s32 func_80161CD0(s32, s32); +extern s32 func_80161208(s32 a0); +extern s32 func_801725A4(u8*); + +s32 func_8015B950(s32 arg0) +{ + + extern void (*D_80182B48[])(void *); + s16 sp10[4]; + s16 sp18[4]; + s32 t; + s32 z; + s32 doit; + s32 lim = -0xB0000; + + if (func_80161B18() != 0) { + return; + } + switch (((s32 (*)(s32))func_801619A4)(arg0)) { + case 0: + case 1: + case 2: + case 6: + if (((s32 (*)(s32))func_80149AA8)(arg0) != 0) { + D_80182B48[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149AD4)(arg0); + return; + } + if (((s32 (*)(s32))func_80149B54)(arg0) != 0) { + D_80182B48[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149BAC)(arg0); + return; + } + break; + case 3: + ((void (*)(s32))func_801498E0)(arg0); + break; + case 4: + ((void (*)(s32))func_80149954)(arg0); + break; + case 5: + if (((s32 (*)(s32))func_80149A64)(arg0) != 0) { + D_80182B48[*(u16 *)arg0]((void *)arg0); + func_800CCCC0(arg0); + return; + } + break; + } + if (func_80149CD4(arg0) != 0) { + D_80182B48[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_8015E880)(arg0); + return; + } + if (((s32 (*)(s32))func_80149744)(arg0) != 0) { + D_80182B48[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149788)(arg0); + return; + } + if (((s32 (*)(s32))func_801496D4)(arg0) != 0) { + D_80182B48[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149704)(arg0); + if (((u8)((s32 (*)(s32))func_80148AFC)(arg0)) == 0) { + func_80146D90(arg0); + } + if ((*(s32 *)(arg0 + 0x24) | *(s32 *)(arg0 + 0x2C)) != 0) { + func_80154150(arg0, 0xF); + } else { + ((void (*)(s32, s32, s32))func_801541D8)(arg0, 0xD, 6); + } + *(s32 *)(arg0 + 0x238) = 1; + return; + } + if (((s32 (*)(s32))func_801488A8)(arg0) != 0) { + sp10[0] = 0; + sp10[1] = 0; + sp10[2] = 0; + t = *(s16 *)(arg0 + 0x26); + sp18[0] = t; + sp18[1] = 0; + t = *(s16 *)(arg0 + 0x2E); + sp18[2] = t; + D_80182B48[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 1); + ((void (*)(s32))func_8015A264)(arg0); + t = -(((s32 (*)(s16 *, s16 *))func_80013294)(sp10, sp18) << 0x10); + if (t < *(s32 *)(arg0 + 0x2C)) { + *(s32 *)(arg0 + 0x2C) = t; + } + return; + } + if (*(u16 *)(arg0 + 0xB8) == 0x8000) { + D_80182B48[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 0); + ((void (*)(s32))func_80159B70)(arg0); + return; + } + z = *(s32 *)(arg0 + 0x2C); + if (func_8016F1AC() != 0) { + goto zero; + } + if (z <= lim) { + goto one; + } + if (D_8011F9C4 == 0) { + goto zero; + } + if (((u8)func_80029178(0x21)) != 0) { + goto zero; + } +one: + doit = 1; + goto join; +zero: + doit = 0; +join: + if (doit != 0) { + D_80182B48[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 0); + ((void (*)(s32))func_80159B70)(arg0); + func_80154150(arg0, 9); + ((void (*)(s32, s32 *))func_80146DB8)(arg0, &D_80182ADC); + ((void (*)(s32, s32))func_80161CD0)(arg0, *(u16 *)(arg0 + 0x16E)); + return; + } + if (func_80161208(arg0) == 0) { + ((void (*)(s32))func_801725A4)(arg0); + } +} DEFINE_func_8015BD8C() /* dedup: shared engine-core @0x8015BD8C (src/shared) */ diff --git a/src/ov_SC03_116/ov_SC03_116_jr_8015AE2C.c b/src/ov_SC03_116/ov_SC03_116_jr_8015AE2C.c index 422dd1114..2c285e67e 100644 --- a/src/ov_SC03_116/ov_SC03_116_jr_8015AE2C.c +++ b/src/ov_SC03_116/ov_SC03_116_jr_8015AE2C.c @@ -1512,7 +1512,259 @@ DEFINE_func_8015B858() /* dedup: shared engine-core @0x8015B858 (src/shared) */ DEFINE_func_8015B8F8() /* dedup: shared engine-core @0x8015B8F8 (src/shared) */ -INCLUDE_ASM("asm/ov_SC03_116/nonmatchings/ov_SC03_116_jr_8015AE2C", func_8015B950); +extern s32 func_8015AE2C(); + +// @class: plumbing +// @stuck: none — MATCH (271/271, pin-free, zero asm). The ONLY residual is DEF-SIDE plumbing, and it is now named exactly: the in-TU instantiation `DEFINE_func_8015BEE4()` (engine_core.h:1851-1855) expands to `extern s32 func_8015B950(void);` INSIDE ov_SC01_077_jr_8015AE2C.c, ~14 lines BELOW this definition, so the 1-param def collides with a `(void)` prototype -> `conflicting types for func_8015B950` (.run/bank_func_8015B950.log). §73 PARAMS axis / T0. Surgical fix = §65b de-macroize that ONE instantiation (blast radius: this TU); the fleet-wide `(void)`->`()` header edit is §63 and must be R22-validated. +/* func_8015B950 (ov_SC01_077_jr_8015AE2C, 271 ins, jtbl_801D8B74) — SESSION-21 re-verified + * + * ── ROUND-2 INDEPENDENT RE-VERIFICATION (2026-07-27, fresh agent, §88e discipline) ───────────── + * match_one : MATCH (271 ins) against the CURRENT tree — §87 staleness re-checked today. + * .text size: compiled .text = 0x43C = 1084 B = 271 ins, EXACTLY the target's declared 0x43C + * ("nonmatching func_8015B950, 0x43C"). So this is NOT a §83a length drift hiding + * behind a zero count — the count is over equal-length streams. + * jtbl : RE-DECODED MECHANICALLY, not inherited. Compiled .rodata = 0x1C = 28 B = 7 words, + * 7x R_MIPS_32 -> .text with implicit addends [58,58,58,E0,F0,100,58]; +0x8015B950 + * = [8015B9A8, 8015B9A8, 8015B9A8, 8015BA30, 8015BA40, 8015BA50, 8015B9A8]. + * Diffed word-for-word against asm/ov_SC01_077/data/tail14.data.s:15-23 — 7/7 identical. + * symcheck : SYMS-DIFF target=35 draft=34, sole MISSING = jtbl_801D8B74. This is the §81 jr + * FALSE POSITIVE, re-confirmed here by reading the relocs: gcc emits its OWN table and + * references it with R_MIPS_HI16/LO16 against the SECTION `.rodata` (t.o +0x40/+0x48), + * so the splat's dlabel NAME can never appear in the draft object's relocation set. + * Nothing is dropped and nothing is invented: the draft's other 34 symbols are exactly + * the target's other 34. + * FAMILY : the x138 remap is clean and §84-safe. Every sibling is 271 ins with an IDENTICAL + * callee set; only THREE names vary per overlay — the two data labels and the jtbl: + * ov_SC01_077 D_80184EE0 / D_80184F4C / jtbl_801D8B74 + * ov_SC03_099 D_80185A50 / D_80185ABC / jtbl_801BD898 + * ov_SC06_008 D_80187E44 / D_80187EB0 / jtbl_801A8734 + * The pair is always +0x6C apart, and NO literal in this draft encodes that distance + * (both labels are referenced by name), so there is no §84 derived-offset hazard. + * D_8011F9C4 is fleet-constant (main-EXE data) and must NOT be remapped. + * + * match_one: MATCH (271 ins) against the CURRENT tree (§87 staleness re-checked, 2026-07-27). + * PIN-FREE, zero asm, offset-pure (s32 arg0 + raw offsets) — x138 template-safe. + * Provenance: this is the Phase-26 crack (.run/phase26-cracks/func_8015B950.c) re-gated verbatim, + * with ONE deliberate change: the definition's return type void -> s32. + * - `void func_8015B950(s32 arg0)` : MATCH (271 ins) [the Phase-26 form] + * - `s32 func_8015B950(s32 arg0)` : MATCH (271 ins) [shipped — §3a-1 void->s32 is byte-neutral] + * The fleet/engine_core.h canonical decl is `extern s32 func_8015B950(void);` (engine_core.h:1852), + * and the last bank attempt (.run/bank_func_8015B950.log) died on `conflicting types for + * func_8015B950`. Shipping the s32 return kills the §73 RETURN axis for free and leaves only the + * cheap T0 PARAMS axis for the ladder (fix_header_decl.py / --fix-def-sig / cast_call_sites). + * Both forms are byte-identical, so the orchestrator may swap the return type back at zero cost. + * + * SYMBOLS (§58 rules 1/2 — all splat spellings, all verified present): + * D_80184F4C asm/ov_SC01_077/data/tail.data.s:4355 (the state-handler vtable) + * D_80184EE0 asm/ov_SC01_077/data/tail.data.s:4293 + * D_8011F9C4 main-EXE data; spelled `extern s32 D_8011F9C4;` in 5+ already-banked TUs + * jtbl_801D8B74 asm/ov_SC01_077/data/tail14.data.s:15 (compiler jump table — not named in C) + * + * JTBL VERIFIED (§8a gate): compiled .rodata = exactly 0x1C B / 7 words, 7x R_MIPS_32 .text with + * addends [0x58,0x58,0x58,0xE0,0xF0,0x100,0x58] -> +0x8015B950 = [B9A8,B9A8,B9A8,BA30,BA40,BA50, + * B9A8] == the original words at 0x801D8B74..0x801D8B8C. Bound `sltiu $v0,$v1,0x7` matches. + * The raw dlabel's 8th word 0x00000000 is NOT an entry — it is the intra-TU `.align 3` pad of the + * B34/B54/B74 jtbl chain; the object can never emit it (maspsx drops .align), so it must stay in + * the post-carve RAW data piece (the §53/§62/§81 carve chain applies at bank time). + * + * Same family as the TU's own already-matched func_8015AE2C: 7-case switch on ((s32 (*)(s32))func_801619A4)() + * (0/1/2/6 shared, 3/4/5 own, no default block — out-of-range and every `break` fall to the + * after-switch join), then a chain of "state handler" tests, each dispatching + * D_80184F4C[*(u16*)arg0](arg0) and returning. + * + * THREE LEVERS (draft -> MATCH in 3 compiles): + * + * 1. PROLOGUE CONSTANT = an INITIALIZED LOCAL, not a literal in the compare. + * Target opens with `lui $s2, 0xFFF5` in the *prologue*, used once ~200 ins later in + * `slt $v0,$s2,$s1`. No gcc-2.7.2 pass hoists a (set reg const_int) across basic blocks + * (loop.c needs a loop; cse/combine/sched never move insns between BBs) — so the insn must + * have been EMITTED in the first BB, i.e. the constant is a local initialized at the top of + * the function. cse then cannot fold it back into the compare: the `slt` operand predicate is + * `arith_operand`, which rejects a CONST_INT wider than 16 bits, so validate_change fails and + * the pseudo survives. Its live range spans every call -> global.c gives it a callee-saved reg. + * Writing `z > -0xB0000` inline instead emits the `lui` into the branch delay slot next to the + * compare (caller-saved $v0) and the function is 1 insn short. => `s32 lim = -0xB0000;` at top. + * + * 2. `lh` vs `lhu`: a short->short copy is a pure HImode move and gcc emits `lhu`. The target's + * `lh $v0,0x26($s0)` means the value passed through an SImode (int) temp: expand makes + * (set (reg:SI) (sign_extend (mem:HI))) + (set (mem:HI) (subreg:HI ...)), and combine cannot + * merge them (the merged form is mem<-mem, which no movhi accepts) so the sign-extending load + * survives. => route both halfword copies through the `s32 t` temp. + * + * 3. THE `goto` LAYOUT — dodging jump.c's store-flag conversion (jump.c:1005-1065). + * An if/else chain writing 0/1 into `doit` makes gcc collapse the last pair into + * `sltiu $v0,$v0,1`. jump.c fires that conversion when the insn immediately after a + * conditional jump is a lone `SET pseudo, CONST_INT` whose following simplejump targets the + * SAME label as the branch (jump.c:1038 `reallabelprev == temp || ... JUMP_LABEL(temp4) == + * JUMP_LABEL(insn)`) — exactly the shape of `if (c) x=0; else x=1;`. + * The target instead cross-jumps ALL the `doit=0` exits into ONE shared block placed after the + * `doit=1` fall-through; reorg's fill_slots_from_thread then COPIES that single set into all + * three branch delay slots and redirects each branch past it (which is why `addu $v0,$zero, + * $zero` appears 3x in delay slots and the shared block vanishes). A `goto zero;` / `goto one;` + * chain expresses that layout directly, and each conditional jump is then followed by a + * compare/call rather than a lone const set, so the store-flag conversion never triggers. + * GENERAL RULE: multiple predicates that all assign the SAME constant to one flag => write + * them as `goto` to a shared assignment, never as an if/else ladder. + */ +extern s32 D_8011F9C4; +extern s32 D_80184EE0; + +extern s32 func_80161B18(void); +extern s32 func_801619A4(s32*); +extern s32 func_80149AA8(s32*); +extern void func_80149AD4(s32*); +extern s32 func_80149B54(s32*); +extern void func_80149BAC(s32*); +extern s32 func_801498E0(s32*); +extern s32 func_80149954(s32); +extern s32 func_80149A64(s32*); +extern void func_800CCCC0(s32 a0); +extern s32 func_80149CD4(s32 a0); +extern void func_8015E880(s32*); +extern s32 func_80149744(struct S_80149744*); +extern void func_80149788(void); +extern s32 func_801496D4(void*); +extern void func_80149704(void); +extern int func_80148AFC(void*); +extern void func_80146D90(s32 a0); +extern void func_80154150(s32 a0, s32 a1); +extern void func_801541D8(u8*, s32, s32); +extern s32 func_801488A8(u8*); +extern void func_80147078(s32*, s16); +extern void func_8015A264(void*); +extern s32 func_80013294(void*, void*); +extern void func_80159B70(void*); +extern s32 func_8016F1AC(void); +extern s32 func_80029178(s32 a0); +extern void func_80146DB8(s32*, s32*); +extern s32 func_80161CD0(s32, s32); +extern s32 func_80161208(s32 a0); +extern s32 func_801725A4(u8*); + +s32 func_8015B950(s32 arg0) +{ + + extern void (*D_80184F4C[])(void *); + s16 sp10[4]; + s16 sp18[4]; + s32 t; + s32 z; + s32 doit; + s32 lim = -0xB0000; + + if (func_80161B18() != 0) { + return; + } + switch (((s32 (*)(s32))func_801619A4)(arg0)) { + case 0: + case 1: + case 2: + case 6: + if (((s32 (*)(s32))func_80149AA8)(arg0) != 0) { + D_80184F4C[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149AD4)(arg0); + return; + } + if (((s32 (*)(s32))func_80149B54)(arg0) != 0) { + D_80184F4C[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149BAC)(arg0); + return; + } + break; + case 3: + ((void (*)(s32))func_801498E0)(arg0); + break; + case 4: + ((void (*)(s32))func_80149954)(arg0); + break; + case 5: + if (((s32 (*)(s32))func_80149A64)(arg0) != 0) { + D_80184F4C[*(u16 *)arg0]((void *)arg0); + func_800CCCC0(arg0); + return; + } + break; + } + if (func_80149CD4(arg0) != 0) { + D_80184F4C[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_8015E880)(arg0); + return; + } + if (((s32 (*)(s32))func_80149744)(arg0) != 0) { + D_80184F4C[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149788)(arg0); + return; + } + if (((s32 (*)(s32))func_801496D4)(arg0) != 0) { + D_80184F4C[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149704)(arg0); + if (((u8)((s32 (*)(s32))func_80148AFC)(arg0)) == 0) { + func_80146D90(arg0); + } + if ((*(s32 *)(arg0 + 0x24) | *(s32 *)(arg0 + 0x2C)) != 0) { + func_80154150(arg0, 0xF); + } else { + ((void (*)(s32, s32, s32))func_801541D8)(arg0, 0xD, 6); + } + *(s32 *)(arg0 + 0x238) = 1; + return; + } + if (((s32 (*)(s32))func_801488A8)(arg0) != 0) { + sp10[0] = 0; + sp10[1] = 0; + sp10[2] = 0; + t = *(s16 *)(arg0 + 0x26); + sp18[0] = t; + sp18[1] = 0; + t = *(s16 *)(arg0 + 0x2E); + sp18[2] = t; + D_80184F4C[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 1); + ((void (*)(s32))func_8015A264)(arg0); + t = -(((s32 (*)(s16 *, s16 *))func_80013294)(sp10, sp18) << 0x10); + if (t < *(s32 *)(arg0 + 0x2C)) { + *(s32 *)(arg0 + 0x2C) = t; + } + return; + } + if (*(u16 *)(arg0 + 0xB8) == 0x8000) { + D_80184F4C[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 0); + ((void (*)(s32))func_80159B70)(arg0); + return; + } + z = *(s32 *)(arg0 + 0x2C); + if (func_8016F1AC() != 0) { + goto zero; + } + if (z <= lim) { + goto one; + } + if (D_8011F9C4 == 0) { + goto zero; + } + if (((u8)func_80029178(0x21)) != 0) { + goto zero; + } +one: + doit = 1; + goto join; +zero: + doit = 0; +join: + if (doit != 0) { + D_80184F4C[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 0); + ((void (*)(s32))func_80159B70)(arg0); + func_80154150(arg0, 9); + ((void (*)(s32, s32 *))func_80146DB8)(arg0, &D_80184EE0); + ((void (*)(s32, s32))func_80161CD0)(arg0, *(u16 *)(arg0 + 0x16E)); + return; + } + if (func_80161208(arg0) == 0) { + ((void (*)(s32))func_801725A4)(arg0); + } +} DEFINE_func_8015BD8C() /* dedup: shared engine-core @0x8015BD8C (src/shared) */ diff --git a/src/ov_SC03_117/ov_SC03_117_jr_8015AE2C.c b/src/ov_SC03_117/ov_SC03_117_jr_8015AE2C.c index 3221170b8..c0925dccc 100644 --- a/src/ov_SC03_117/ov_SC03_117_jr_8015AE2C.c +++ b/src/ov_SC03_117/ov_SC03_117_jr_8015AE2C.c @@ -1512,7 +1512,259 @@ DEFINE_func_8015B858() /* dedup: shared engine-core @0x8015B858 (src/shared) */ DEFINE_func_8015B8F8() /* dedup: shared engine-core @0x8015B8F8 (src/shared) */ -INCLUDE_ASM("asm/ov_SC03_117/nonmatchings/ov_SC03_117_jr_8015AE2C", func_8015B950); +extern s32 func_8015AE2C(); + +// @class: plumbing +// @stuck: none — MATCH (271/271, pin-free, zero asm). The ONLY residual is DEF-SIDE plumbing, and it is now named exactly: the in-TU instantiation `DEFINE_func_8015BEE4()` (engine_core.h:1851-1855) expands to `extern s32 func_8015B950(void);` INSIDE ov_SC01_077_jr_8015AE2C.c, ~14 lines BELOW this definition, so the 1-param def collides with a `(void)` prototype -> `conflicting types for func_8015B950` (.run/bank_func_8015B950.log). §73 PARAMS axis / T0. Surgical fix = §65b de-macroize that ONE instantiation (blast radius: this TU); the fleet-wide `(void)`->`()` header edit is §63 and must be R22-validated. +/* func_8015B950 (ov_SC01_077_jr_8015AE2C, 271 ins, jtbl_801D8B74) — SESSION-21 re-verified + * + * ── ROUND-2 INDEPENDENT RE-VERIFICATION (2026-07-27, fresh agent, §88e discipline) ───────────── + * match_one : MATCH (271 ins) against the CURRENT tree — §87 staleness re-checked today. + * .text size: compiled .text = 0x43C = 1084 B = 271 ins, EXACTLY the target's declared 0x43C + * ("nonmatching func_8015B950, 0x43C"). So this is NOT a §83a length drift hiding + * behind a zero count — the count is over equal-length streams. + * jtbl : RE-DECODED MECHANICALLY, not inherited. Compiled .rodata = 0x1C = 28 B = 7 words, + * 7x R_MIPS_32 -> .text with implicit addends [58,58,58,E0,F0,100,58]; +0x8015B950 + * = [8015B9A8, 8015B9A8, 8015B9A8, 8015BA30, 8015BA40, 8015BA50, 8015B9A8]. + * Diffed word-for-word against asm/ov_SC01_077/data/tail14.data.s:15-23 — 7/7 identical. + * symcheck : SYMS-DIFF target=35 draft=34, sole MISSING = jtbl_801D8B74. This is the §81 jr + * FALSE POSITIVE, re-confirmed here by reading the relocs: gcc emits its OWN table and + * references it with R_MIPS_HI16/LO16 against the SECTION `.rodata` (t.o +0x40/+0x48), + * so the splat's dlabel NAME can never appear in the draft object's relocation set. + * Nothing is dropped and nothing is invented: the draft's other 34 symbols are exactly + * the target's other 34. + * FAMILY : the x138 remap is clean and §84-safe. Every sibling is 271 ins with an IDENTICAL + * callee set; only THREE names vary per overlay — the two data labels and the jtbl: + * ov_SC01_077 D_80186EEC / D_80186F58 / jtbl_801D8B74 + * ov_SC03_099 D_80185A50 / D_80185ABC / jtbl_801BD898 + * ov_SC06_008 D_80187E44 / D_80187EB0 / jtbl_801A8734 + * The pair is always +0x6C apart, and NO literal in this draft encodes that distance + * (both labels are referenced by name), so there is no §84 derived-offset hazard. + * D_8011F9C4 is fleet-constant (main-EXE data) and must NOT be remapped. + * + * match_one: MATCH (271 ins) against the CURRENT tree (§87 staleness re-checked, 2026-07-27). + * PIN-FREE, zero asm, offset-pure (s32 arg0 + raw offsets) — x138 template-safe. + * Provenance: this is the Phase-26 crack (.run/phase26-cracks/func_8015B950.c) re-gated verbatim, + * with ONE deliberate change: the definition's return type void -> s32. + * - `void func_8015B950(s32 arg0)` : MATCH (271 ins) [the Phase-26 form] + * - `s32 func_8015B950(s32 arg0)` : MATCH (271 ins) [shipped — §3a-1 void->s32 is byte-neutral] + * The fleet/engine_core.h canonical decl is `extern s32 func_8015B950(void);` (engine_core.h:1852), + * and the last bank attempt (.run/bank_func_8015B950.log) died on `conflicting types for + * func_8015B950`. Shipping the s32 return kills the §73 RETURN axis for free and leaves only the + * cheap T0 PARAMS axis for the ladder (fix_header_decl.py / --fix-def-sig / cast_call_sites). + * Both forms are byte-identical, so the orchestrator may swap the return type back at zero cost. + * + * SYMBOLS (§58 rules 1/2 — all splat spellings, all verified present): + * D_80186F58 asm/ov_SC01_077/data/tail.data.s:4355 (the state-handler vtable) + * D_80186EEC asm/ov_SC01_077/data/tail.data.s:4293 + * D_8011F9C4 main-EXE data; spelled `extern s32 D_8011F9C4;` in 5+ already-banked TUs + * jtbl_801D8B74 asm/ov_SC01_077/data/tail14.data.s:15 (compiler jump table — not named in C) + * + * JTBL VERIFIED (§8a gate): compiled .rodata = exactly 0x1C B / 7 words, 7x R_MIPS_32 .text with + * addends [0x58,0x58,0x58,0xE0,0xF0,0x100,0x58] -> +0x8015B950 = [B9A8,B9A8,B9A8,BA30,BA40,BA50, + * B9A8] == the original words at 0x801D8B74..0x801D8B8C. Bound `sltiu $v0,$v1,0x7` matches. + * The raw dlabel's 8th word 0x00000000 is NOT an entry — it is the intra-TU `.align 3` pad of the + * B34/B54/B74 jtbl chain; the object can never emit it (maspsx drops .align), so it must stay in + * the post-carve RAW data piece (the §53/§62/§81 carve chain applies at bank time). + * + * Same family as the TU's own already-matched func_8015AE2C: 7-case switch on ((s32 (*)(s32))func_801619A4)() + * (0/1/2/6 shared, 3/4/5 own, no default block — out-of-range and every `break` fall to the + * after-switch join), then a chain of "state handler" tests, each dispatching + * D_80186F58[*(u16*)arg0](arg0) and returning. + * + * THREE LEVERS (draft -> MATCH in 3 compiles): + * + * 1. PROLOGUE CONSTANT = an INITIALIZED LOCAL, not a literal in the compare. + * Target opens with `lui $s2, 0xFFF5` in the *prologue*, used once ~200 ins later in + * `slt $v0,$s2,$s1`. No gcc-2.7.2 pass hoists a (set reg const_int) across basic blocks + * (loop.c needs a loop; cse/combine/sched never move insns between BBs) — so the insn must + * have been EMITTED in the first BB, i.e. the constant is a local initialized at the top of + * the function. cse then cannot fold it back into the compare: the `slt` operand predicate is + * `arith_operand`, which rejects a CONST_INT wider than 16 bits, so validate_change fails and + * the pseudo survives. Its live range spans every call -> global.c gives it a callee-saved reg. + * Writing `z > -0xB0000` inline instead emits the `lui` into the branch delay slot next to the + * compare (caller-saved $v0) and the function is 1 insn short. => `s32 lim = -0xB0000;` at top. + * + * 2. `lh` vs `lhu`: a short->short copy is a pure HImode move and gcc emits `lhu`. The target's + * `lh $v0,0x26($s0)` means the value passed through an SImode (int) temp: expand makes + * (set (reg:SI) (sign_extend (mem:HI))) + (set (mem:HI) (subreg:HI ...)), and combine cannot + * merge them (the merged form is mem<-mem, which no movhi accepts) so the sign-extending load + * survives. => route both halfword copies through the `s32 t` temp. + * + * 3. THE `goto` LAYOUT — dodging jump.c's store-flag conversion (jump.c:1005-1065). + * An if/else chain writing 0/1 into `doit` makes gcc collapse the last pair into + * `sltiu $v0,$v0,1`. jump.c fires that conversion when the insn immediately after a + * conditional jump is a lone `SET pseudo, CONST_INT` whose following simplejump targets the + * SAME label as the branch (jump.c:1038 `reallabelprev == temp || ... JUMP_LABEL(temp4) == + * JUMP_LABEL(insn)`) — exactly the shape of `if (c) x=0; else x=1;`. + * The target instead cross-jumps ALL the `doit=0` exits into ONE shared block placed after the + * `doit=1` fall-through; reorg's fill_slots_from_thread then COPIES that single set into all + * three branch delay slots and redirects each branch past it (which is why `addu $v0,$zero, + * $zero` appears 3x in delay slots and the shared block vanishes). A `goto zero;` / `goto one;` + * chain expresses that layout directly, and each conditional jump is then followed by a + * compare/call rather than a lone const set, so the store-flag conversion never triggers. + * GENERAL RULE: multiple predicates that all assign the SAME constant to one flag => write + * them as `goto` to a shared assignment, never as an if/else ladder. + */ +extern s32 D_8011F9C4; +extern s32 D_80186EEC; + +extern s32 func_80161B18(void); +extern s32 func_801619A4(s32*); +extern s32 func_80149AA8(s32*); +extern void func_80149AD4(s32*); +extern s32 func_80149B54(s32*); +extern void func_80149BAC(s32*); +extern s32 func_801498E0(s32*); +extern s32 func_80149954(s32); +extern s32 func_80149A64(s32*); +extern void func_800CCCC0(s32 a0); +extern s32 func_80149CD4(s32 a0); +extern void func_8015E880(s32*); +extern s32 func_80149744(struct S_80149744*); +extern void func_80149788(void); +extern s32 func_801496D4(void*); +extern void func_80149704(void); +extern int func_80148AFC(void*); +extern void func_80146D90(s32 a0); +extern void func_80154150(s32 a0, s32 a1); +extern void func_801541D8(u8*, s32, s32); +extern s32 func_801488A8(u8*); +extern void func_80147078(s32*, s16); +extern void func_8015A264(void*); +extern s32 func_80013294(void*, void*); +extern void func_80159B70(void*); +extern s32 func_8016F1AC(void); +extern s32 func_80029178(s32 a0); +extern void func_80146DB8(s32*, s32*); +extern s32 func_80161CD0(s32, s32); +extern s32 func_80161208(s32 a0); +extern s32 func_801725A4(u8*); + +s32 func_8015B950(s32 arg0) +{ + + extern void (*D_80186F58[])(void *); + s16 sp10[4]; + s16 sp18[4]; + s32 t; + s32 z; + s32 doit; + s32 lim = -0xB0000; + + if (func_80161B18() != 0) { + return; + } + switch (((s32 (*)(s32))func_801619A4)(arg0)) { + case 0: + case 1: + case 2: + case 6: + if (((s32 (*)(s32))func_80149AA8)(arg0) != 0) { + D_80186F58[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149AD4)(arg0); + return; + } + if (((s32 (*)(s32))func_80149B54)(arg0) != 0) { + D_80186F58[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149BAC)(arg0); + return; + } + break; + case 3: + ((void (*)(s32))func_801498E0)(arg0); + break; + case 4: + ((void (*)(s32))func_80149954)(arg0); + break; + case 5: + if (((s32 (*)(s32))func_80149A64)(arg0) != 0) { + D_80186F58[*(u16 *)arg0]((void *)arg0); + func_800CCCC0(arg0); + return; + } + break; + } + if (func_80149CD4(arg0) != 0) { + D_80186F58[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_8015E880)(arg0); + return; + } + if (((s32 (*)(s32))func_80149744)(arg0) != 0) { + D_80186F58[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149788)(arg0); + return; + } + if (((s32 (*)(s32))func_801496D4)(arg0) != 0) { + D_80186F58[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149704)(arg0); + if (((u8)((s32 (*)(s32))func_80148AFC)(arg0)) == 0) { + func_80146D90(arg0); + } + if ((*(s32 *)(arg0 + 0x24) | *(s32 *)(arg0 + 0x2C)) != 0) { + func_80154150(arg0, 0xF); + } else { + ((void (*)(s32, s32, s32))func_801541D8)(arg0, 0xD, 6); + } + *(s32 *)(arg0 + 0x238) = 1; + return; + } + if (((s32 (*)(s32))func_801488A8)(arg0) != 0) { + sp10[0] = 0; + sp10[1] = 0; + sp10[2] = 0; + t = *(s16 *)(arg0 + 0x26); + sp18[0] = t; + sp18[1] = 0; + t = *(s16 *)(arg0 + 0x2E); + sp18[2] = t; + D_80186F58[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 1); + ((void (*)(s32))func_8015A264)(arg0); + t = -(((s32 (*)(s16 *, s16 *))func_80013294)(sp10, sp18) << 0x10); + if (t < *(s32 *)(arg0 + 0x2C)) { + *(s32 *)(arg0 + 0x2C) = t; + } + return; + } + if (*(u16 *)(arg0 + 0xB8) == 0x8000) { + D_80186F58[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 0); + ((void (*)(s32))func_80159B70)(arg0); + return; + } + z = *(s32 *)(arg0 + 0x2C); + if (func_8016F1AC() != 0) { + goto zero; + } + if (z <= lim) { + goto one; + } + if (D_8011F9C4 == 0) { + goto zero; + } + if (((u8)func_80029178(0x21)) != 0) { + goto zero; + } +one: + doit = 1; + goto join; +zero: + doit = 0; +join: + if (doit != 0) { + D_80186F58[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 0); + ((void (*)(s32))func_80159B70)(arg0); + func_80154150(arg0, 9); + ((void (*)(s32, s32 *))func_80146DB8)(arg0, &D_80186EEC); + ((void (*)(s32, s32))func_80161CD0)(arg0, *(u16 *)(arg0 + 0x16E)); + return; + } + if (func_80161208(arg0) == 0) { + ((void (*)(s32))func_801725A4)(arg0); + } +} DEFINE_func_8015BD8C() /* dedup: shared engine-core @0x8015BD8C (src/shared) */ diff --git a/src/ov_SC03_118/ov_SC03_118_jr_8015AE2C.c b/src/ov_SC03_118/ov_SC03_118_jr_8015AE2C.c index 9162f2238..e88e76722 100644 --- a/src/ov_SC03_118/ov_SC03_118_jr_8015AE2C.c +++ b/src/ov_SC03_118/ov_SC03_118_jr_8015AE2C.c @@ -1512,7 +1512,259 @@ DEFINE_func_8015B858() /* dedup: shared engine-core @0x8015B858 (src/shared) */ DEFINE_func_8015B8F8() /* dedup: shared engine-core @0x8015B8F8 (src/shared) */ -INCLUDE_ASM("asm/ov_SC03_118/nonmatchings/ov_SC03_118_jr_8015AE2C", func_8015B950); +extern s32 func_8015AE2C(); + +// @class: plumbing +// @stuck: none — MATCH (271/271, pin-free, zero asm). The ONLY residual is DEF-SIDE plumbing, and it is now named exactly: the in-TU instantiation `DEFINE_func_8015BEE4()` (engine_core.h:1851-1855) expands to `extern s32 func_8015B950(void);` INSIDE ov_SC01_077_jr_8015AE2C.c, ~14 lines BELOW this definition, so the 1-param def collides with a `(void)` prototype -> `conflicting types for func_8015B950` (.run/bank_func_8015B950.log). §73 PARAMS axis / T0. Surgical fix = §65b de-macroize that ONE instantiation (blast radius: this TU); the fleet-wide `(void)`->`()` header edit is §63 and must be R22-validated. +/* func_8015B950 (ov_SC01_077_jr_8015AE2C, 271 ins, jtbl_801D8B74) — SESSION-21 re-verified + * + * ── ROUND-2 INDEPENDENT RE-VERIFICATION (2026-07-27, fresh agent, §88e discipline) ───────────── + * match_one : MATCH (271 ins) against the CURRENT tree — §87 staleness re-checked today. + * .text size: compiled .text = 0x43C = 1084 B = 271 ins, EXACTLY the target's declared 0x43C + * ("nonmatching func_8015B950, 0x43C"). So this is NOT a §83a length drift hiding + * behind a zero count — the count is over equal-length streams. + * jtbl : RE-DECODED MECHANICALLY, not inherited. Compiled .rodata = 0x1C = 28 B = 7 words, + * 7x R_MIPS_32 -> .text with implicit addends [58,58,58,E0,F0,100,58]; +0x8015B950 + * = [8015B9A8, 8015B9A8, 8015B9A8, 8015BA30, 8015BA40, 8015BA50, 8015B9A8]. + * Diffed word-for-word against asm/ov_SC01_077/data/tail14.data.s:15-23 — 7/7 identical. + * symcheck : SYMS-DIFF target=35 draft=34, sole MISSING = jtbl_801D8B74. This is the §81 jr + * FALSE POSITIVE, re-confirmed here by reading the relocs: gcc emits its OWN table and + * references it with R_MIPS_HI16/LO16 against the SECTION `.rodata` (t.o +0x40/+0x48), + * so the splat's dlabel NAME can never appear in the draft object's relocation set. + * Nothing is dropped and nothing is invented: the draft's other 34 symbols are exactly + * the target's other 34. + * FAMILY : the x138 remap is clean and §84-safe. Every sibling is 271 ins with an IDENTICAL + * callee set; only THREE names vary per overlay — the two data labels and the jtbl: + * ov_SC01_077 D_8018BF98 / D_8018C004 / jtbl_801D8B74 + * ov_SC03_099 D_80185A50 / D_80185ABC / jtbl_801BD898 + * ov_SC06_008 D_80187E44 / D_80187EB0 / jtbl_801A8734 + * The pair is always +0x6C apart, and NO literal in this draft encodes that distance + * (both labels are referenced by name), so there is no §84 derived-offset hazard. + * D_8011F9C4 is fleet-constant (main-EXE data) and must NOT be remapped. + * + * match_one: MATCH (271 ins) against the CURRENT tree (§87 staleness re-checked, 2026-07-27). + * PIN-FREE, zero asm, offset-pure (s32 arg0 + raw offsets) — x138 template-safe. + * Provenance: this is the Phase-26 crack (.run/phase26-cracks/func_8015B950.c) re-gated verbatim, + * with ONE deliberate change: the definition's return type void -> s32. + * - `void func_8015B950(s32 arg0)` : MATCH (271 ins) [the Phase-26 form] + * - `s32 func_8015B950(s32 arg0)` : MATCH (271 ins) [shipped — §3a-1 void->s32 is byte-neutral] + * The fleet/engine_core.h canonical decl is `extern s32 func_8015B950(void);` (engine_core.h:1852), + * and the last bank attempt (.run/bank_func_8015B950.log) died on `conflicting types for + * func_8015B950`. Shipping the s32 return kills the §73 RETURN axis for free and leaves only the + * cheap T0 PARAMS axis for the ladder (fix_header_decl.py / --fix-def-sig / cast_call_sites). + * Both forms are byte-identical, so the orchestrator may swap the return type back at zero cost. + * + * SYMBOLS (§58 rules 1/2 — all splat spellings, all verified present): + * D_8018C004 asm/ov_SC01_077/data/tail.data.s:4355 (the state-handler vtable) + * D_8018BF98 asm/ov_SC01_077/data/tail.data.s:4293 + * D_8011F9C4 main-EXE data; spelled `extern s32 D_8011F9C4;` in 5+ already-banked TUs + * jtbl_801D8B74 asm/ov_SC01_077/data/tail14.data.s:15 (compiler jump table — not named in C) + * + * JTBL VERIFIED (§8a gate): compiled .rodata = exactly 0x1C B / 7 words, 7x R_MIPS_32 .text with + * addends [0x58,0x58,0x58,0xE0,0xF0,0x100,0x58] -> +0x8015B950 = [B9A8,B9A8,B9A8,BA30,BA40,BA50, + * B9A8] == the original words at 0x801D8B74..0x801D8B8C. Bound `sltiu $v0,$v1,0x7` matches. + * The raw dlabel's 8th word 0x00000000 is NOT an entry — it is the intra-TU `.align 3` pad of the + * B34/B54/B74 jtbl chain; the object can never emit it (maspsx drops .align), so it must stay in + * the post-carve RAW data piece (the §53/§62/§81 carve chain applies at bank time). + * + * Same family as the TU's own already-matched func_8015AE2C: 7-case switch on ((s32 (*)(s32))func_801619A4)() + * (0/1/2/6 shared, 3/4/5 own, no default block — out-of-range and every `break` fall to the + * after-switch join), then a chain of "state handler" tests, each dispatching + * D_8018C004[*(u16*)arg0](arg0) and returning. + * + * THREE LEVERS (draft -> MATCH in 3 compiles): + * + * 1. PROLOGUE CONSTANT = an INITIALIZED LOCAL, not a literal in the compare. + * Target opens with `lui $s2, 0xFFF5` in the *prologue*, used once ~200 ins later in + * `slt $v0,$s2,$s1`. No gcc-2.7.2 pass hoists a (set reg const_int) across basic blocks + * (loop.c needs a loop; cse/combine/sched never move insns between BBs) — so the insn must + * have been EMITTED in the first BB, i.e. the constant is a local initialized at the top of + * the function. cse then cannot fold it back into the compare: the `slt` operand predicate is + * `arith_operand`, which rejects a CONST_INT wider than 16 bits, so validate_change fails and + * the pseudo survives. Its live range spans every call -> global.c gives it a callee-saved reg. + * Writing `z > -0xB0000` inline instead emits the `lui` into the branch delay slot next to the + * compare (caller-saved $v0) and the function is 1 insn short. => `s32 lim = -0xB0000;` at top. + * + * 2. `lh` vs `lhu`: a short->short copy is a pure HImode move and gcc emits `lhu`. The target's + * `lh $v0,0x26($s0)` means the value passed through an SImode (int) temp: expand makes + * (set (reg:SI) (sign_extend (mem:HI))) + (set (mem:HI) (subreg:HI ...)), and combine cannot + * merge them (the merged form is mem<-mem, which no movhi accepts) so the sign-extending load + * survives. => route both halfword copies through the `s32 t` temp. + * + * 3. THE `goto` LAYOUT — dodging jump.c's store-flag conversion (jump.c:1005-1065). + * An if/else chain writing 0/1 into `doit` makes gcc collapse the last pair into + * `sltiu $v0,$v0,1`. jump.c fires that conversion when the insn immediately after a + * conditional jump is a lone `SET pseudo, CONST_INT` whose following simplejump targets the + * SAME label as the branch (jump.c:1038 `reallabelprev == temp || ... JUMP_LABEL(temp4) == + * JUMP_LABEL(insn)`) — exactly the shape of `if (c) x=0; else x=1;`. + * The target instead cross-jumps ALL the `doit=0` exits into ONE shared block placed after the + * `doit=1` fall-through; reorg's fill_slots_from_thread then COPIES that single set into all + * three branch delay slots and redirects each branch past it (which is why `addu $v0,$zero, + * $zero` appears 3x in delay slots and the shared block vanishes). A `goto zero;` / `goto one;` + * chain expresses that layout directly, and each conditional jump is then followed by a + * compare/call rather than a lone const set, so the store-flag conversion never triggers. + * GENERAL RULE: multiple predicates that all assign the SAME constant to one flag => write + * them as `goto` to a shared assignment, never as an if/else ladder. + */ +extern s32 D_8011F9C4; +extern s32 D_8018BF98; + +extern s32 func_80161B18(void); +extern s32 func_801619A4(s32*); +extern s32 func_80149AA8(s32*); +extern void func_80149AD4(s32*); +extern s32 func_80149B54(s32*); +extern void func_80149BAC(s32*); +extern s32 func_801498E0(s32*); +extern s32 func_80149954(s32); +extern s32 func_80149A64(s32*); +extern void func_800CCCC0(s32 a0); +extern s32 func_80149CD4(s32 a0); +extern void func_8015E880(s32*); +extern s32 func_80149744(struct S_80149744*); +extern void func_80149788(void); +extern s32 func_801496D4(void*); +extern void func_80149704(void); +extern int func_80148AFC(void*); +extern void func_80146D90(s32 a0); +extern void func_80154150(s32 a0, s32 a1); +extern void func_801541D8(u8*, s32, s32); +extern s32 func_801488A8(u8*); +extern void func_80147078(s32*, s16); +extern void func_8015A264(void*); +extern s32 func_80013294(void*, void*); +extern void func_80159B70(void*); +extern s32 func_8016F1AC(void); +extern s32 func_80029178(s32 a0); +extern void func_80146DB8(s32*, s32*); +extern s32 func_80161CD0(s32, s32); +extern s32 func_80161208(s32 a0); +extern s32 func_801725A4(u8*); + +s32 func_8015B950(s32 arg0) +{ + + extern void (*D_8018C004[])(void *); + s16 sp10[4]; + s16 sp18[4]; + s32 t; + s32 z; + s32 doit; + s32 lim = -0xB0000; + + if (func_80161B18() != 0) { + return; + } + switch (((s32 (*)(s32))func_801619A4)(arg0)) { + case 0: + case 1: + case 2: + case 6: + if (((s32 (*)(s32))func_80149AA8)(arg0) != 0) { + D_8018C004[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149AD4)(arg0); + return; + } + if (((s32 (*)(s32))func_80149B54)(arg0) != 0) { + D_8018C004[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149BAC)(arg0); + return; + } + break; + case 3: + ((void (*)(s32))func_801498E0)(arg0); + break; + case 4: + ((void (*)(s32))func_80149954)(arg0); + break; + case 5: + if (((s32 (*)(s32))func_80149A64)(arg0) != 0) { + D_8018C004[*(u16 *)arg0]((void *)arg0); + func_800CCCC0(arg0); + return; + } + break; + } + if (func_80149CD4(arg0) != 0) { + D_8018C004[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_8015E880)(arg0); + return; + } + if (((s32 (*)(s32))func_80149744)(arg0) != 0) { + D_8018C004[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149788)(arg0); + return; + } + if (((s32 (*)(s32))func_801496D4)(arg0) != 0) { + D_8018C004[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149704)(arg0); + if (((u8)((s32 (*)(s32))func_80148AFC)(arg0)) == 0) { + func_80146D90(arg0); + } + if ((*(s32 *)(arg0 + 0x24) | *(s32 *)(arg0 + 0x2C)) != 0) { + func_80154150(arg0, 0xF); + } else { + ((void (*)(s32, s32, s32))func_801541D8)(arg0, 0xD, 6); + } + *(s32 *)(arg0 + 0x238) = 1; + return; + } + if (((s32 (*)(s32))func_801488A8)(arg0) != 0) { + sp10[0] = 0; + sp10[1] = 0; + sp10[2] = 0; + t = *(s16 *)(arg0 + 0x26); + sp18[0] = t; + sp18[1] = 0; + t = *(s16 *)(arg0 + 0x2E); + sp18[2] = t; + D_8018C004[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 1); + ((void (*)(s32))func_8015A264)(arg0); + t = -(((s32 (*)(s16 *, s16 *))func_80013294)(sp10, sp18) << 0x10); + if (t < *(s32 *)(arg0 + 0x2C)) { + *(s32 *)(arg0 + 0x2C) = t; + } + return; + } + if (*(u16 *)(arg0 + 0xB8) == 0x8000) { + D_8018C004[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 0); + ((void (*)(s32))func_80159B70)(arg0); + return; + } + z = *(s32 *)(arg0 + 0x2C); + if (func_8016F1AC() != 0) { + goto zero; + } + if (z <= lim) { + goto one; + } + if (D_8011F9C4 == 0) { + goto zero; + } + if (((u8)func_80029178(0x21)) != 0) { + goto zero; + } +one: + doit = 1; + goto join; +zero: + doit = 0; +join: + if (doit != 0) { + D_8018C004[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 0); + ((void (*)(s32))func_80159B70)(arg0); + func_80154150(arg0, 9); + ((void (*)(s32, s32 *))func_80146DB8)(arg0, &D_8018BF98); + ((void (*)(s32, s32))func_80161CD0)(arg0, *(u16 *)(arg0 + 0x16E)); + return; + } + if (func_80161208(arg0) == 0) { + ((void (*)(s32))func_801725A4)(arg0); + } +} DEFINE_func_8015BD8C() /* dedup: shared engine-core @0x8015BD8C (src/shared) */ diff --git a/src/ov_SC03_119/ov_SC03_119_jr_8015AE2C.c b/src/ov_SC03_119/ov_SC03_119_jr_8015AE2C.c index 002545d5a..1e236d462 100644 --- a/src/ov_SC03_119/ov_SC03_119_jr_8015AE2C.c +++ b/src/ov_SC03_119/ov_SC03_119_jr_8015AE2C.c @@ -1512,7 +1512,259 @@ DEFINE_func_8015B858() /* dedup: shared engine-core @0x8015B858 (src/shared) */ DEFINE_func_8015B8F8() /* dedup: shared engine-core @0x8015B8F8 (src/shared) */ -INCLUDE_ASM("asm/ov_SC03_119/nonmatchings/ov_SC03_119_jr_8015AE2C", func_8015B950); +extern s32 func_8015AE2C(); + +// @class: plumbing +// @stuck: none — MATCH (271/271, pin-free, zero asm). The ONLY residual is DEF-SIDE plumbing, and it is now named exactly: the in-TU instantiation `DEFINE_func_8015BEE4()` (engine_core.h:1851-1855) expands to `extern s32 func_8015B950(void);` INSIDE ov_SC01_077_jr_8015AE2C.c, ~14 lines BELOW this definition, so the 1-param def collides with a `(void)` prototype -> `conflicting types for func_8015B950` (.run/bank_func_8015B950.log). §73 PARAMS axis / T0. Surgical fix = §65b de-macroize that ONE instantiation (blast radius: this TU); the fleet-wide `(void)`->`()` header edit is §63 and must be R22-validated. +/* func_8015B950 (ov_SC01_077_jr_8015AE2C, 271 ins, jtbl_801D8B74) — SESSION-21 re-verified + * + * ── ROUND-2 INDEPENDENT RE-VERIFICATION (2026-07-27, fresh agent, §88e discipline) ───────────── + * match_one : MATCH (271 ins) against the CURRENT tree — §87 staleness re-checked today. + * .text size: compiled .text = 0x43C = 1084 B = 271 ins, EXACTLY the target's declared 0x43C + * ("nonmatching func_8015B950, 0x43C"). So this is NOT a §83a length drift hiding + * behind a zero count — the count is over equal-length streams. + * jtbl : RE-DECODED MECHANICALLY, not inherited. Compiled .rodata = 0x1C = 28 B = 7 words, + * 7x R_MIPS_32 -> .text with implicit addends [58,58,58,E0,F0,100,58]; +0x8015B950 + * = [8015B9A8, 8015B9A8, 8015B9A8, 8015BA30, 8015BA40, 8015BA50, 8015B9A8]. + * Diffed word-for-word against asm/ov_SC01_077/data/tail14.data.s:15-23 — 7/7 identical. + * symcheck : SYMS-DIFF target=35 draft=34, sole MISSING = jtbl_801D8B74. This is the §81 jr + * FALSE POSITIVE, re-confirmed here by reading the relocs: gcc emits its OWN table and + * references it with R_MIPS_HI16/LO16 against the SECTION `.rodata` (t.o +0x40/+0x48), + * so the splat's dlabel NAME can never appear in the draft object's relocation set. + * Nothing is dropped and nothing is invented: the draft's other 34 symbols are exactly + * the target's other 34. + * FAMILY : the x138 remap is clean and §84-safe. Every sibling is 271 ins with an IDENTICAL + * callee set; only THREE names vary per overlay — the two data labels and the jtbl: + * ov_SC01_077 D_8018BF98 / D_8018C004 / jtbl_801D8B74 + * ov_SC03_099 D_80185A50 / D_80185ABC / jtbl_801BD898 + * ov_SC06_008 D_80187E44 / D_80187EB0 / jtbl_801A8734 + * The pair is always +0x6C apart, and NO literal in this draft encodes that distance + * (both labels are referenced by name), so there is no §84 derived-offset hazard. + * D_8011F9C4 is fleet-constant (main-EXE data) and must NOT be remapped. + * + * match_one: MATCH (271 ins) against the CURRENT tree (§87 staleness re-checked, 2026-07-27). + * PIN-FREE, zero asm, offset-pure (s32 arg0 + raw offsets) — x138 template-safe. + * Provenance: this is the Phase-26 crack (.run/phase26-cracks/func_8015B950.c) re-gated verbatim, + * with ONE deliberate change: the definition's return type void -> s32. + * - `void func_8015B950(s32 arg0)` : MATCH (271 ins) [the Phase-26 form] + * - `s32 func_8015B950(s32 arg0)` : MATCH (271 ins) [shipped — §3a-1 void->s32 is byte-neutral] + * The fleet/engine_core.h canonical decl is `extern s32 func_8015B950(void);` (engine_core.h:1852), + * and the last bank attempt (.run/bank_func_8015B950.log) died on `conflicting types for + * func_8015B950`. Shipping the s32 return kills the §73 RETURN axis for free and leaves only the + * cheap T0 PARAMS axis for the ladder (fix_header_decl.py / --fix-def-sig / cast_call_sites). + * Both forms are byte-identical, so the orchestrator may swap the return type back at zero cost. + * + * SYMBOLS (§58 rules 1/2 — all splat spellings, all verified present): + * D_8018C004 asm/ov_SC01_077/data/tail.data.s:4355 (the state-handler vtable) + * D_8018BF98 asm/ov_SC01_077/data/tail.data.s:4293 + * D_8011F9C4 main-EXE data; spelled `extern s32 D_8011F9C4;` in 5+ already-banked TUs + * jtbl_801D8B74 asm/ov_SC01_077/data/tail14.data.s:15 (compiler jump table — not named in C) + * + * JTBL VERIFIED (§8a gate): compiled .rodata = exactly 0x1C B / 7 words, 7x R_MIPS_32 .text with + * addends [0x58,0x58,0x58,0xE0,0xF0,0x100,0x58] -> +0x8015B950 = [B9A8,B9A8,B9A8,BA30,BA40,BA50, + * B9A8] == the original words at 0x801D8B74..0x801D8B8C. Bound `sltiu $v0,$v1,0x7` matches. + * The raw dlabel's 8th word 0x00000000 is NOT an entry — it is the intra-TU `.align 3` pad of the + * B34/B54/B74 jtbl chain; the object can never emit it (maspsx drops .align), so it must stay in + * the post-carve RAW data piece (the §53/§62/§81 carve chain applies at bank time). + * + * Same family as the TU's own already-matched func_8015AE2C: 7-case switch on ((s32 (*)(s32))func_801619A4)() + * (0/1/2/6 shared, 3/4/5 own, no default block — out-of-range and every `break` fall to the + * after-switch join), then a chain of "state handler" tests, each dispatching + * D_8018C004[*(u16*)arg0](arg0) and returning. + * + * THREE LEVERS (draft -> MATCH in 3 compiles): + * + * 1. PROLOGUE CONSTANT = an INITIALIZED LOCAL, not a literal in the compare. + * Target opens with `lui $s2, 0xFFF5` in the *prologue*, used once ~200 ins later in + * `slt $v0,$s2,$s1`. No gcc-2.7.2 pass hoists a (set reg const_int) across basic blocks + * (loop.c needs a loop; cse/combine/sched never move insns between BBs) — so the insn must + * have been EMITTED in the first BB, i.e. the constant is a local initialized at the top of + * the function. cse then cannot fold it back into the compare: the `slt` operand predicate is + * `arith_operand`, which rejects a CONST_INT wider than 16 bits, so validate_change fails and + * the pseudo survives. Its live range spans every call -> global.c gives it a callee-saved reg. + * Writing `z > -0xB0000` inline instead emits the `lui` into the branch delay slot next to the + * compare (caller-saved $v0) and the function is 1 insn short. => `s32 lim = -0xB0000;` at top. + * + * 2. `lh` vs `lhu`: a short->short copy is a pure HImode move and gcc emits `lhu`. The target's + * `lh $v0,0x26($s0)` means the value passed through an SImode (int) temp: expand makes + * (set (reg:SI) (sign_extend (mem:HI))) + (set (mem:HI) (subreg:HI ...)), and combine cannot + * merge them (the merged form is mem<-mem, which no movhi accepts) so the sign-extending load + * survives. => route both halfword copies through the `s32 t` temp. + * + * 3. THE `goto` LAYOUT — dodging jump.c's store-flag conversion (jump.c:1005-1065). + * An if/else chain writing 0/1 into `doit` makes gcc collapse the last pair into + * `sltiu $v0,$v0,1`. jump.c fires that conversion when the insn immediately after a + * conditional jump is a lone `SET pseudo, CONST_INT` whose following simplejump targets the + * SAME label as the branch (jump.c:1038 `reallabelprev == temp || ... JUMP_LABEL(temp4) == + * JUMP_LABEL(insn)`) — exactly the shape of `if (c) x=0; else x=1;`. + * The target instead cross-jumps ALL the `doit=0` exits into ONE shared block placed after the + * `doit=1` fall-through; reorg's fill_slots_from_thread then COPIES that single set into all + * three branch delay slots and redirects each branch past it (which is why `addu $v0,$zero, + * $zero` appears 3x in delay slots and the shared block vanishes). A `goto zero;` / `goto one;` + * chain expresses that layout directly, and each conditional jump is then followed by a + * compare/call rather than a lone const set, so the store-flag conversion never triggers. + * GENERAL RULE: multiple predicates that all assign the SAME constant to one flag => write + * them as `goto` to a shared assignment, never as an if/else ladder. + */ +extern s32 D_8011F9C4; +extern s32 D_8018BF98; + +extern s32 func_80161B18(void); +extern s32 func_801619A4(s32*); +extern s32 func_80149AA8(s32*); +extern void func_80149AD4(s32*); +extern s32 func_80149B54(s32*); +extern void func_80149BAC(s32*); +extern s32 func_801498E0(s32*); +extern s32 func_80149954(s32); +extern s32 func_80149A64(s32*); +extern void func_800CCCC0(s32 a0); +extern s32 func_80149CD4(s32 a0); +extern void func_8015E880(s32*); +extern s32 func_80149744(struct S_80149744*); +extern void func_80149788(void); +extern s32 func_801496D4(void*); +extern void func_80149704(void); +extern int func_80148AFC(void*); +extern void func_80146D90(s32 a0); +extern void func_80154150(s32 a0, s32 a1); +extern void func_801541D8(u8*, s32, s32); +extern s32 func_801488A8(u8*); +extern void func_80147078(s32*, s16); +extern void func_8015A264(void*); +extern s32 func_80013294(void*, void*); +extern void func_80159B70(void*); +extern s32 func_8016F1AC(void); +extern s32 func_80029178(s32 a0); +extern void func_80146DB8(s32*, s32*); +extern s32 func_80161CD0(s32, s32); +extern s32 func_80161208(s32 a0); +extern s32 func_801725A4(u8*); + +s32 func_8015B950(s32 arg0) +{ + + extern void (*D_8018C004[])(void *); + s16 sp10[4]; + s16 sp18[4]; + s32 t; + s32 z; + s32 doit; + s32 lim = -0xB0000; + + if (func_80161B18() != 0) { + return; + } + switch (((s32 (*)(s32))func_801619A4)(arg0)) { + case 0: + case 1: + case 2: + case 6: + if (((s32 (*)(s32))func_80149AA8)(arg0) != 0) { + D_8018C004[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149AD4)(arg0); + return; + } + if (((s32 (*)(s32))func_80149B54)(arg0) != 0) { + D_8018C004[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149BAC)(arg0); + return; + } + break; + case 3: + ((void (*)(s32))func_801498E0)(arg0); + break; + case 4: + ((void (*)(s32))func_80149954)(arg0); + break; + case 5: + if (((s32 (*)(s32))func_80149A64)(arg0) != 0) { + D_8018C004[*(u16 *)arg0]((void *)arg0); + func_800CCCC0(arg0); + return; + } + break; + } + if (func_80149CD4(arg0) != 0) { + D_8018C004[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_8015E880)(arg0); + return; + } + if (((s32 (*)(s32))func_80149744)(arg0) != 0) { + D_8018C004[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149788)(arg0); + return; + } + if (((s32 (*)(s32))func_801496D4)(arg0) != 0) { + D_8018C004[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149704)(arg0); + if (((u8)((s32 (*)(s32))func_80148AFC)(arg0)) == 0) { + func_80146D90(arg0); + } + if ((*(s32 *)(arg0 + 0x24) | *(s32 *)(arg0 + 0x2C)) != 0) { + func_80154150(arg0, 0xF); + } else { + ((void (*)(s32, s32, s32))func_801541D8)(arg0, 0xD, 6); + } + *(s32 *)(arg0 + 0x238) = 1; + return; + } + if (((s32 (*)(s32))func_801488A8)(arg0) != 0) { + sp10[0] = 0; + sp10[1] = 0; + sp10[2] = 0; + t = *(s16 *)(arg0 + 0x26); + sp18[0] = t; + sp18[1] = 0; + t = *(s16 *)(arg0 + 0x2E); + sp18[2] = t; + D_8018C004[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 1); + ((void (*)(s32))func_8015A264)(arg0); + t = -(((s32 (*)(s16 *, s16 *))func_80013294)(sp10, sp18) << 0x10); + if (t < *(s32 *)(arg0 + 0x2C)) { + *(s32 *)(arg0 + 0x2C) = t; + } + return; + } + if (*(u16 *)(arg0 + 0xB8) == 0x8000) { + D_8018C004[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 0); + ((void (*)(s32))func_80159B70)(arg0); + return; + } + z = *(s32 *)(arg0 + 0x2C); + if (func_8016F1AC() != 0) { + goto zero; + } + if (z <= lim) { + goto one; + } + if (D_8011F9C4 == 0) { + goto zero; + } + if (((u8)func_80029178(0x21)) != 0) { + goto zero; + } +one: + doit = 1; + goto join; +zero: + doit = 0; +join: + if (doit != 0) { + D_8018C004[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 0); + ((void (*)(s32))func_80159B70)(arg0); + func_80154150(arg0, 9); + ((void (*)(s32, s32 *))func_80146DB8)(arg0, &D_8018BF98); + ((void (*)(s32, s32))func_80161CD0)(arg0, *(u16 *)(arg0 + 0x16E)); + return; + } + if (func_80161208(arg0) == 0) { + ((void (*)(s32))func_801725A4)(arg0); + } +} DEFINE_func_8015BD8C() /* dedup: shared engine-core @0x8015BD8C (src/shared) */ diff --git a/src/ov_SC03_121/ov_SC03_121_jr_8015AE2C.c b/src/ov_SC03_121/ov_SC03_121_jr_8015AE2C.c index 5f88b0be9..b7ef05368 100644 --- a/src/ov_SC03_121/ov_SC03_121_jr_8015AE2C.c +++ b/src/ov_SC03_121/ov_SC03_121_jr_8015AE2C.c @@ -1512,7 +1512,259 @@ DEFINE_func_8015B858() /* dedup: shared engine-core @0x8015B858 (src/shared) */ DEFINE_func_8015B8F8() /* dedup: shared engine-core @0x8015B8F8 (src/shared) */ -INCLUDE_ASM("asm/ov_SC03_121/nonmatchings/ov_SC03_121_jr_8015AE2C", func_8015B950); +extern s32 func_8015AE2C(); + +// @class: plumbing +// @stuck: none — MATCH (271/271, pin-free, zero asm). The ONLY residual is DEF-SIDE plumbing, and it is now named exactly: the in-TU instantiation `DEFINE_func_8015BEE4()` (engine_core.h:1851-1855) expands to `extern s32 func_8015B950(void);` INSIDE ov_SC01_077_jr_8015AE2C.c, ~14 lines BELOW this definition, so the 1-param def collides with a `(void)` prototype -> `conflicting types for func_8015B950` (.run/bank_func_8015B950.log). §73 PARAMS axis / T0. Surgical fix = §65b de-macroize that ONE instantiation (blast radius: this TU); the fleet-wide `(void)`->`()` header edit is §63 and must be R22-validated. +/* func_8015B950 (ov_SC01_077_jr_8015AE2C, 271 ins, jtbl_801D8B74) — SESSION-21 re-verified + * + * ── ROUND-2 INDEPENDENT RE-VERIFICATION (2026-07-27, fresh agent, §88e discipline) ───────────── + * match_one : MATCH (271 ins) against the CURRENT tree — §87 staleness re-checked today. + * .text size: compiled .text = 0x43C = 1084 B = 271 ins, EXACTLY the target's declared 0x43C + * ("nonmatching func_8015B950, 0x43C"). So this is NOT a §83a length drift hiding + * behind a zero count — the count is over equal-length streams. + * jtbl : RE-DECODED MECHANICALLY, not inherited. Compiled .rodata = 0x1C = 28 B = 7 words, + * 7x R_MIPS_32 -> .text with implicit addends [58,58,58,E0,F0,100,58]; +0x8015B950 + * = [8015B9A8, 8015B9A8, 8015B9A8, 8015BA30, 8015BA40, 8015BA50, 8015B9A8]. + * Diffed word-for-word against asm/ov_SC01_077/data/tail14.data.s:15-23 — 7/7 identical. + * symcheck : SYMS-DIFF target=35 draft=34, sole MISSING = jtbl_801D8B74. This is the §81 jr + * FALSE POSITIVE, re-confirmed here by reading the relocs: gcc emits its OWN table and + * references it with R_MIPS_HI16/LO16 against the SECTION `.rodata` (t.o +0x40/+0x48), + * so the splat's dlabel NAME can never appear in the draft object's relocation set. + * Nothing is dropped and nothing is invented: the draft's other 34 symbols are exactly + * the target's other 34. + * FAMILY : the x138 remap is clean and §84-safe. Every sibling is 271 ins with an IDENTICAL + * callee set; only THREE names vary per overlay — the two data labels and the jtbl: + * ov_SC01_077 D_801847B4 / D_80184820 / jtbl_801D8B74 + * ov_SC03_099 D_80185A50 / D_80185ABC / jtbl_801BD898 + * ov_SC06_008 D_80187E44 / D_80187EB0 / jtbl_801A8734 + * The pair is always +0x6C apart, and NO literal in this draft encodes that distance + * (both labels are referenced by name), so there is no §84 derived-offset hazard. + * D_8011F9C4 is fleet-constant (main-EXE data) and must NOT be remapped. + * + * match_one: MATCH (271 ins) against the CURRENT tree (§87 staleness re-checked, 2026-07-27). + * PIN-FREE, zero asm, offset-pure (s32 arg0 + raw offsets) — x138 template-safe. + * Provenance: this is the Phase-26 crack (.run/phase26-cracks/func_8015B950.c) re-gated verbatim, + * with ONE deliberate change: the definition's return type void -> s32. + * - `void func_8015B950(s32 arg0)` : MATCH (271 ins) [the Phase-26 form] + * - `s32 func_8015B950(s32 arg0)` : MATCH (271 ins) [shipped — §3a-1 void->s32 is byte-neutral] + * The fleet/engine_core.h canonical decl is `extern s32 func_8015B950(void);` (engine_core.h:1852), + * and the last bank attempt (.run/bank_func_8015B950.log) died on `conflicting types for + * func_8015B950`. Shipping the s32 return kills the §73 RETURN axis for free and leaves only the + * cheap T0 PARAMS axis for the ladder (fix_header_decl.py / --fix-def-sig / cast_call_sites). + * Both forms are byte-identical, so the orchestrator may swap the return type back at zero cost. + * + * SYMBOLS (§58 rules 1/2 — all splat spellings, all verified present): + * D_80184820 asm/ov_SC01_077/data/tail.data.s:4355 (the state-handler vtable) + * D_801847B4 asm/ov_SC01_077/data/tail.data.s:4293 + * D_8011F9C4 main-EXE data; spelled `extern s32 D_8011F9C4;` in 5+ already-banked TUs + * jtbl_801D8B74 asm/ov_SC01_077/data/tail14.data.s:15 (compiler jump table — not named in C) + * + * JTBL VERIFIED (§8a gate): compiled .rodata = exactly 0x1C B / 7 words, 7x R_MIPS_32 .text with + * addends [0x58,0x58,0x58,0xE0,0xF0,0x100,0x58] -> +0x8015B950 = [B9A8,B9A8,B9A8,BA30,BA40,BA50, + * B9A8] == the original words at 0x801D8B74..0x801D8B8C. Bound `sltiu $v0,$v1,0x7` matches. + * The raw dlabel's 8th word 0x00000000 is NOT an entry — it is the intra-TU `.align 3` pad of the + * B34/B54/B74 jtbl chain; the object can never emit it (maspsx drops .align), so it must stay in + * the post-carve RAW data piece (the §53/§62/§81 carve chain applies at bank time). + * + * Same family as the TU's own already-matched func_8015AE2C: 7-case switch on ((s32 (*)(s32))func_801619A4)() + * (0/1/2/6 shared, 3/4/5 own, no default block — out-of-range and every `break` fall to the + * after-switch join), then a chain of "state handler" tests, each dispatching + * D_80184820[*(u16*)arg0](arg0) and returning. + * + * THREE LEVERS (draft -> MATCH in 3 compiles): + * + * 1. PROLOGUE CONSTANT = an INITIALIZED LOCAL, not a literal in the compare. + * Target opens with `lui $s2, 0xFFF5` in the *prologue*, used once ~200 ins later in + * `slt $v0,$s2,$s1`. No gcc-2.7.2 pass hoists a (set reg const_int) across basic blocks + * (loop.c needs a loop; cse/combine/sched never move insns between BBs) — so the insn must + * have been EMITTED in the first BB, i.e. the constant is a local initialized at the top of + * the function. cse then cannot fold it back into the compare: the `slt` operand predicate is + * `arith_operand`, which rejects a CONST_INT wider than 16 bits, so validate_change fails and + * the pseudo survives. Its live range spans every call -> global.c gives it a callee-saved reg. + * Writing `z > -0xB0000` inline instead emits the `lui` into the branch delay slot next to the + * compare (caller-saved $v0) and the function is 1 insn short. => `s32 lim = -0xB0000;` at top. + * + * 2. `lh` vs `lhu`: a short->short copy is a pure HImode move and gcc emits `lhu`. The target's + * `lh $v0,0x26($s0)` means the value passed through an SImode (int) temp: expand makes + * (set (reg:SI) (sign_extend (mem:HI))) + (set (mem:HI) (subreg:HI ...)), and combine cannot + * merge them (the merged form is mem<-mem, which no movhi accepts) so the sign-extending load + * survives. => route both halfword copies through the `s32 t` temp. + * + * 3. THE `goto` LAYOUT — dodging jump.c's store-flag conversion (jump.c:1005-1065). + * An if/else chain writing 0/1 into `doit` makes gcc collapse the last pair into + * `sltiu $v0,$v0,1`. jump.c fires that conversion when the insn immediately after a + * conditional jump is a lone `SET pseudo, CONST_INT` whose following simplejump targets the + * SAME label as the branch (jump.c:1038 `reallabelprev == temp || ... JUMP_LABEL(temp4) == + * JUMP_LABEL(insn)`) — exactly the shape of `if (c) x=0; else x=1;`. + * The target instead cross-jumps ALL the `doit=0` exits into ONE shared block placed after the + * `doit=1` fall-through; reorg's fill_slots_from_thread then COPIES that single set into all + * three branch delay slots and redirects each branch past it (which is why `addu $v0,$zero, + * $zero` appears 3x in delay slots and the shared block vanishes). A `goto zero;` / `goto one;` + * chain expresses that layout directly, and each conditional jump is then followed by a + * compare/call rather than a lone const set, so the store-flag conversion never triggers. + * GENERAL RULE: multiple predicates that all assign the SAME constant to one flag => write + * them as `goto` to a shared assignment, never as an if/else ladder. + */ +extern s32 D_8011F9C4; +extern s32 D_801847B4; + +extern s32 func_80161B18(void); +extern s32 func_801619A4(s32*); +extern s32 func_80149AA8(s32*); +extern void func_80149AD4(s32*); +extern s32 func_80149B54(s32*); +extern void func_80149BAC(s32*); +extern s32 func_801498E0(s32*); +extern s32 func_80149954(s32); +extern s32 func_80149A64(s32*); +extern void func_800CCCC0(s32 a0); +extern s32 func_80149CD4(s32 a0); +extern void func_8015E880(s32*); +extern s32 func_80149744(struct S_80149744*); +extern void func_80149788(void); +extern s32 func_801496D4(void*); +extern void func_80149704(void); +extern int func_80148AFC(void*); +extern void func_80146D90(s32 a0); +extern void func_80154150(s32 a0, s32 a1); +extern void func_801541D8(u8*, s32, s32); +extern s32 func_801488A8(u8*); +extern void func_80147078(s32*, s16); +extern void func_8015A264(void*); +extern s32 func_80013294(void*, void*); +extern void func_80159B70(void*); +extern s32 func_8016F1AC(void); +extern s32 func_80029178(s32 a0); +extern void func_80146DB8(s32*, s32*); +extern s32 func_80161CD0(s32, s32); +extern s32 func_80161208(s32 a0); +extern s32 func_801725A4(u8*); + +s32 func_8015B950(s32 arg0) +{ + + extern void (*D_80184820[])(void *); + s16 sp10[4]; + s16 sp18[4]; + s32 t; + s32 z; + s32 doit; + s32 lim = -0xB0000; + + if (func_80161B18() != 0) { + return; + } + switch (((s32 (*)(s32))func_801619A4)(arg0)) { + case 0: + case 1: + case 2: + case 6: + if (((s32 (*)(s32))func_80149AA8)(arg0) != 0) { + D_80184820[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149AD4)(arg0); + return; + } + if (((s32 (*)(s32))func_80149B54)(arg0) != 0) { + D_80184820[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149BAC)(arg0); + return; + } + break; + case 3: + ((void (*)(s32))func_801498E0)(arg0); + break; + case 4: + ((void (*)(s32))func_80149954)(arg0); + break; + case 5: + if (((s32 (*)(s32))func_80149A64)(arg0) != 0) { + D_80184820[*(u16 *)arg0]((void *)arg0); + func_800CCCC0(arg0); + return; + } + break; + } + if (func_80149CD4(arg0) != 0) { + D_80184820[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_8015E880)(arg0); + return; + } + if (((s32 (*)(s32))func_80149744)(arg0) != 0) { + D_80184820[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149788)(arg0); + return; + } + if (((s32 (*)(s32))func_801496D4)(arg0) != 0) { + D_80184820[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149704)(arg0); + if (((u8)((s32 (*)(s32))func_80148AFC)(arg0)) == 0) { + func_80146D90(arg0); + } + if ((*(s32 *)(arg0 + 0x24) | *(s32 *)(arg0 + 0x2C)) != 0) { + func_80154150(arg0, 0xF); + } else { + ((void (*)(s32, s32, s32))func_801541D8)(arg0, 0xD, 6); + } + *(s32 *)(arg0 + 0x238) = 1; + return; + } + if (((s32 (*)(s32))func_801488A8)(arg0) != 0) { + sp10[0] = 0; + sp10[1] = 0; + sp10[2] = 0; + t = *(s16 *)(arg0 + 0x26); + sp18[0] = t; + sp18[1] = 0; + t = *(s16 *)(arg0 + 0x2E); + sp18[2] = t; + D_80184820[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 1); + ((void (*)(s32))func_8015A264)(arg0); + t = -(((s32 (*)(s16 *, s16 *))func_80013294)(sp10, sp18) << 0x10); + if (t < *(s32 *)(arg0 + 0x2C)) { + *(s32 *)(arg0 + 0x2C) = t; + } + return; + } + if (*(u16 *)(arg0 + 0xB8) == 0x8000) { + D_80184820[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 0); + ((void (*)(s32))func_80159B70)(arg0); + return; + } + z = *(s32 *)(arg0 + 0x2C); + if (func_8016F1AC() != 0) { + goto zero; + } + if (z <= lim) { + goto one; + } + if (D_8011F9C4 == 0) { + goto zero; + } + if (((u8)func_80029178(0x21)) != 0) { + goto zero; + } +one: + doit = 1; + goto join; +zero: + doit = 0; +join: + if (doit != 0) { + D_80184820[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 0); + ((void (*)(s32))func_80159B70)(arg0); + func_80154150(arg0, 9); + ((void (*)(s32, s32 *))func_80146DB8)(arg0, &D_801847B4); + ((void (*)(s32, s32))func_80161CD0)(arg0, *(u16 *)(arg0 + 0x16E)); + return; + } + if (func_80161208(arg0) == 0) { + ((void (*)(s32))func_801725A4)(arg0); + } +} DEFINE_func_8015BD8C() /* dedup: shared engine-core @0x8015BD8C (src/shared) */ diff --git a/src/ov_SC03_124/ov_SC03_124_jr_8015AE2C.c b/src/ov_SC03_124/ov_SC03_124_jr_8015AE2C.c index 7b3ea2894..740d65de4 100644 --- a/src/ov_SC03_124/ov_SC03_124_jr_8015AE2C.c +++ b/src/ov_SC03_124/ov_SC03_124_jr_8015AE2C.c @@ -1512,7 +1512,259 @@ DEFINE_func_8015B858() /* dedup: shared engine-core @0x8015B858 (src/shared) */ DEFINE_func_8015B8F8() /* dedup: shared engine-core @0x8015B8F8 (src/shared) */ -INCLUDE_ASM("asm/ov_SC03_124/nonmatchings/ov_SC03_124_jr_8015AE2C", func_8015B950); +extern s32 func_8015AE2C(); + +// @class: plumbing +// @stuck: none — MATCH (271/271, pin-free, zero asm). The ONLY residual is DEF-SIDE plumbing, and it is now named exactly: the in-TU instantiation `DEFINE_func_8015BEE4()` (engine_core.h:1851-1855) expands to `extern s32 func_8015B950(void);` INSIDE ov_SC01_077_jr_8015AE2C.c, ~14 lines BELOW this definition, so the 1-param def collides with a `(void)` prototype -> `conflicting types for func_8015B950` (.run/bank_func_8015B950.log). §73 PARAMS axis / T0. Surgical fix = §65b de-macroize that ONE instantiation (blast radius: this TU); the fleet-wide `(void)`->`()` header edit is §63 and must be R22-validated. +/* func_8015B950 (ov_SC01_077_jr_8015AE2C, 271 ins, jtbl_801D8B74) — SESSION-21 re-verified + * + * ── ROUND-2 INDEPENDENT RE-VERIFICATION (2026-07-27, fresh agent, §88e discipline) ───────────── + * match_one : MATCH (271 ins) against the CURRENT tree — §87 staleness re-checked today. + * .text size: compiled .text = 0x43C = 1084 B = 271 ins, EXACTLY the target's declared 0x43C + * ("nonmatching func_8015B950, 0x43C"). So this is NOT a §83a length drift hiding + * behind a zero count — the count is over equal-length streams. + * jtbl : RE-DECODED MECHANICALLY, not inherited. Compiled .rodata = 0x1C = 28 B = 7 words, + * 7x R_MIPS_32 -> .text with implicit addends [58,58,58,E0,F0,100,58]; +0x8015B950 + * = [8015B9A8, 8015B9A8, 8015B9A8, 8015BA30, 8015BA40, 8015BA50, 8015B9A8]. + * Diffed word-for-word against asm/ov_SC01_077/data/tail14.data.s:15-23 — 7/7 identical. + * symcheck : SYMS-DIFF target=35 draft=34, sole MISSING = jtbl_801D8B74. This is the §81 jr + * FALSE POSITIVE, re-confirmed here by reading the relocs: gcc emits its OWN table and + * references it with R_MIPS_HI16/LO16 against the SECTION `.rodata` (t.o +0x40/+0x48), + * so the splat's dlabel NAME can never appear in the draft object's relocation set. + * Nothing is dropped and nothing is invented: the draft's other 34 symbols are exactly + * the target's other 34. + * FAMILY : the x138 remap is clean and §84-safe. Every sibling is 271 ins with an IDENTICAL + * callee set; only THREE names vary per overlay — the two data labels and the jtbl: + * ov_SC01_077 D_8018D1E0 / D_8018D24C / jtbl_801D8B74 + * ov_SC03_099 D_80185A50 / D_80185ABC / jtbl_801BD898 + * ov_SC06_008 D_80187E44 / D_80187EB0 / jtbl_801A8734 + * The pair is always +0x6C apart, and NO literal in this draft encodes that distance + * (both labels are referenced by name), so there is no §84 derived-offset hazard. + * D_8011F9C4 is fleet-constant (main-EXE data) and must NOT be remapped. + * + * match_one: MATCH (271 ins) against the CURRENT tree (§87 staleness re-checked, 2026-07-27). + * PIN-FREE, zero asm, offset-pure (s32 arg0 + raw offsets) — x138 template-safe. + * Provenance: this is the Phase-26 crack (.run/phase26-cracks/func_8015B950.c) re-gated verbatim, + * with ONE deliberate change: the definition's return type void -> s32. + * - `void func_8015B950(s32 arg0)` : MATCH (271 ins) [the Phase-26 form] + * - `s32 func_8015B950(s32 arg0)` : MATCH (271 ins) [shipped — §3a-1 void->s32 is byte-neutral] + * The fleet/engine_core.h canonical decl is `extern s32 func_8015B950(void);` (engine_core.h:1852), + * and the last bank attempt (.run/bank_func_8015B950.log) died on `conflicting types for + * func_8015B950`. Shipping the s32 return kills the §73 RETURN axis for free and leaves only the + * cheap T0 PARAMS axis for the ladder (fix_header_decl.py / --fix-def-sig / cast_call_sites). + * Both forms are byte-identical, so the orchestrator may swap the return type back at zero cost. + * + * SYMBOLS (§58 rules 1/2 — all splat spellings, all verified present): + * D_8018D24C asm/ov_SC01_077/data/tail.data.s:4355 (the state-handler vtable) + * D_8018D1E0 asm/ov_SC01_077/data/tail.data.s:4293 + * D_8011F9C4 main-EXE data; spelled `extern s32 D_8011F9C4;` in 5+ already-banked TUs + * jtbl_801D8B74 asm/ov_SC01_077/data/tail14.data.s:15 (compiler jump table — not named in C) + * + * JTBL VERIFIED (§8a gate): compiled .rodata = exactly 0x1C B / 7 words, 7x R_MIPS_32 .text with + * addends [0x58,0x58,0x58,0xE0,0xF0,0x100,0x58] -> +0x8015B950 = [B9A8,B9A8,B9A8,BA30,BA40,BA50, + * B9A8] == the original words at 0x801D8B74..0x801D8B8C. Bound `sltiu $v0,$v1,0x7` matches. + * The raw dlabel's 8th word 0x00000000 is NOT an entry — it is the intra-TU `.align 3` pad of the + * B34/B54/B74 jtbl chain; the object can never emit it (maspsx drops .align), so it must stay in + * the post-carve RAW data piece (the §53/§62/§81 carve chain applies at bank time). + * + * Same family as the TU's own already-matched func_8015AE2C: 7-case switch on ((s32 (*)(s32))func_801619A4)() + * (0/1/2/6 shared, 3/4/5 own, no default block — out-of-range and every `break` fall to the + * after-switch join), then a chain of "state handler" tests, each dispatching + * D_8018D24C[*(u16*)arg0](arg0) and returning. + * + * THREE LEVERS (draft -> MATCH in 3 compiles): + * + * 1. PROLOGUE CONSTANT = an INITIALIZED LOCAL, not a literal in the compare. + * Target opens with `lui $s2, 0xFFF5` in the *prologue*, used once ~200 ins later in + * `slt $v0,$s2,$s1`. No gcc-2.7.2 pass hoists a (set reg const_int) across basic blocks + * (loop.c needs a loop; cse/combine/sched never move insns between BBs) — so the insn must + * have been EMITTED in the first BB, i.e. the constant is a local initialized at the top of + * the function. cse then cannot fold it back into the compare: the `slt` operand predicate is + * `arith_operand`, which rejects a CONST_INT wider than 16 bits, so validate_change fails and + * the pseudo survives. Its live range spans every call -> global.c gives it a callee-saved reg. + * Writing `z > -0xB0000` inline instead emits the `lui` into the branch delay slot next to the + * compare (caller-saved $v0) and the function is 1 insn short. => `s32 lim = -0xB0000;` at top. + * + * 2. `lh` vs `lhu`: a short->short copy is a pure HImode move and gcc emits `lhu`. The target's + * `lh $v0,0x26($s0)` means the value passed through an SImode (int) temp: expand makes + * (set (reg:SI) (sign_extend (mem:HI))) + (set (mem:HI) (subreg:HI ...)), and combine cannot + * merge them (the merged form is mem<-mem, which no movhi accepts) so the sign-extending load + * survives. => route both halfword copies through the `s32 t` temp. + * + * 3. THE `goto` LAYOUT — dodging jump.c's store-flag conversion (jump.c:1005-1065). + * An if/else chain writing 0/1 into `doit` makes gcc collapse the last pair into + * `sltiu $v0,$v0,1`. jump.c fires that conversion when the insn immediately after a + * conditional jump is a lone `SET pseudo, CONST_INT` whose following simplejump targets the + * SAME label as the branch (jump.c:1038 `reallabelprev == temp || ... JUMP_LABEL(temp4) == + * JUMP_LABEL(insn)`) — exactly the shape of `if (c) x=0; else x=1;`. + * The target instead cross-jumps ALL the `doit=0` exits into ONE shared block placed after the + * `doit=1` fall-through; reorg's fill_slots_from_thread then COPIES that single set into all + * three branch delay slots and redirects each branch past it (which is why `addu $v0,$zero, + * $zero` appears 3x in delay slots and the shared block vanishes). A `goto zero;` / `goto one;` + * chain expresses that layout directly, and each conditional jump is then followed by a + * compare/call rather than a lone const set, so the store-flag conversion never triggers. + * GENERAL RULE: multiple predicates that all assign the SAME constant to one flag => write + * them as `goto` to a shared assignment, never as an if/else ladder. + */ +extern s32 D_8011F9C4; +extern s32 D_8018D1E0; + +extern s32 func_80161B18(void); +extern s32 func_801619A4(s32*); +extern s32 func_80149AA8(s32*); +extern void func_80149AD4(s32*); +extern s32 func_80149B54(s32*); +extern void func_80149BAC(s32*); +extern s32 func_801498E0(s32*); +extern s32 func_80149954(s32); +extern s32 func_80149A64(s32*); +extern void func_800CCCC0(s32 a0); +extern s32 func_80149CD4(s32 a0); +extern void func_8015E880(s32*); +extern s32 func_80149744(struct S_80149744*); +extern void func_80149788(void); +extern s32 func_801496D4(void*); +extern void func_80149704(void); +extern int func_80148AFC(void*); +extern void func_80146D90(s32 a0); +extern void func_80154150(s32 a0, s32 a1); +extern void func_801541D8(u8*, s32, s32); +extern s32 func_801488A8(u8*); +extern void func_80147078(s32*, s16); +extern void func_8015A264(void*); +extern s32 func_80013294(void*, void*); +extern void func_80159B70(void*); +extern s32 func_8016F1AC(void); +extern s32 func_80029178(s32 a0); +extern void func_80146DB8(s32*, s32*); +extern s32 func_80161CD0(s32, s32); +extern s32 func_80161208(s32 a0); +extern s32 func_801725A4(u8*); + +s32 func_8015B950(s32 arg0) +{ + + extern void (*D_8018D24C[])(void *); + s16 sp10[4]; + s16 sp18[4]; + s32 t; + s32 z; + s32 doit; + s32 lim = -0xB0000; + + if (func_80161B18() != 0) { + return; + } + switch (((s32 (*)(s32))func_801619A4)(arg0)) { + case 0: + case 1: + case 2: + case 6: + if (((s32 (*)(s32))func_80149AA8)(arg0) != 0) { + D_8018D24C[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149AD4)(arg0); + return; + } + if (((s32 (*)(s32))func_80149B54)(arg0) != 0) { + D_8018D24C[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149BAC)(arg0); + return; + } + break; + case 3: + ((void (*)(s32))func_801498E0)(arg0); + break; + case 4: + ((void (*)(s32))func_80149954)(arg0); + break; + case 5: + if (((s32 (*)(s32))func_80149A64)(arg0) != 0) { + D_8018D24C[*(u16 *)arg0]((void *)arg0); + func_800CCCC0(arg0); + return; + } + break; + } + if (func_80149CD4(arg0) != 0) { + D_8018D24C[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_8015E880)(arg0); + return; + } + if (((s32 (*)(s32))func_80149744)(arg0) != 0) { + D_8018D24C[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149788)(arg0); + return; + } + if (((s32 (*)(s32))func_801496D4)(arg0) != 0) { + D_8018D24C[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149704)(arg0); + if (((u8)((s32 (*)(s32))func_80148AFC)(arg0)) == 0) { + func_80146D90(arg0); + } + if ((*(s32 *)(arg0 + 0x24) | *(s32 *)(arg0 + 0x2C)) != 0) { + func_80154150(arg0, 0xF); + } else { + ((void (*)(s32, s32, s32))func_801541D8)(arg0, 0xD, 6); + } + *(s32 *)(arg0 + 0x238) = 1; + return; + } + if (((s32 (*)(s32))func_801488A8)(arg0) != 0) { + sp10[0] = 0; + sp10[1] = 0; + sp10[2] = 0; + t = *(s16 *)(arg0 + 0x26); + sp18[0] = t; + sp18[1] = 0; + t = *(s16 *)(arg0 + 0x2E); + sp18[2] = t; + D_8018D24C[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 1); + ((void (*)(s32))func_8015A264)(arg0); + t = -(((s32 (*)(s16 *, s16 *))func_80013294)(sp10, sp18) << 0x10); + if (t < *(s32 *)(arg0 + 0x2C)) { + *(s32 *)(arg0 + 0x2C) = t; + } + return; + } + if (*(u16 *)(arg0 + 0xB8) == 0x8000) { + D_8018D24C[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 0); + ((void (*)(s32))func_80159B70)(arg0); + return; + } + z = *(s32 *)(arg0 + 0x2C); + if (func_8016F1AC() != 0) { + goto zero; + } + if (z <= lim) { + goto one; + } + if (D_8011F9C4 == 0) { + goto zero; + } + if (((u8)func_80029178(0x21)) != 0) { + goto zero; + } +one: + doit = 1; + goto join; +zero: + doit = 0; +join: + if (doit != 0) { + D_8018D24C[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 0); + ((void (*)(s32))func_80159B70)(arg0); + func_80154150(arg0, 9); + ((void (*)(s32, s32 *))func_80146DB8)(arg0, &D_8018D1E0); + ((void (*)(s32, s32))func_80161CD0)(arg0, *(u16 *)(arg0 + 0x16E)); + return; + } + if (func_80161208(arg0) == 0) { + ((void (*)(s32))func_801725A4)(arg0); + } +} DEFINE_func_8015BD8C() /* dedup: shared engine-core @0x8015BD8C (src/shared) */ diff --git a/src/ov_SC03_125/ov_SC03_125_jr_8015AE2C.c b/src/ov_SC03_125/ov_SC03_125_jr_8015AE2C.c index fa510fb2f..1aad0cba8 100644 --- a/src/ov_SC03_125/ov_SC03_125_jr_8015AE2C.c +++ b/src/ov_SC03_125/ov_SC03_125_jr_8015AE2C.c @@ -1512,7 +1512,259 @@ DEFINE_func_8015B858() /* dedup: shared engine-core @0x8015B858 (src/shared) */ DEFINE_func_8015B8F8() /* dedup: shared engine-core @0x8015B8F8 (src/shared) */ -INCLUDE_ASM("asm/ov_SC03_125/nonmatchings/ov_SC03_125_jr_8015AE2C", func_8015B950); +extern s32 func_8015AE2C(); + +// @class: plumbing +// @stuck: none — MATCH (271/271, pin-free, zero asm). The ONLY residual is DEF-SIDE plumbing, and it is now named exactly: the in-TU instantiation `DEFINE_func_8015BEE4()` (engine_core.h:1851-1855) expands to `extern s32 func_8015B950(void);` INSIDE ov_SC01_077_jr_8015AE2C.c, ~14 lines BELOW this definition, so the 1-param def collides with a `(void)` prototype -> `conflicting types for func_8015B950` (.run/bank_func_8015B950.log). §73 PARAMS axis / T0. Surgical fix = §65b de-macroize that ONE instantiation (blast radius: this TU); the fleet-wide `(void)`->`()` header edit is §63 and must be R22-validated. +/* func_8015B950 (ov_SC01_077_jr_8015AE2C, 271 ins, jtbl_801D8B74) — SESSION-21 re-verified + * + * ── ROUND-2 INDEPENDENT RE-VERIFICATION (2026-07-27, fresh agent, §88e discipline) ───────────── + * match_one : MATCH (271 ins) against the CURRENT tree — §87 staleness re-checked today. + * .text size: compiled .text = 0x43C = 1084 B = 271 ins, EXACTLY the target's declared 0x43C + * ("nonmatching func_8015B950, 0x43C"). So this is NOT a §83a length drift hiding + * behind a zero count — the count is over equal-length streams. + * jtbl : RE-DECODED MECHANICALLY, not inherited. Compiled .rodata = 0x1C = 28 B = 7 words, + * 7x R_MIPS_32 -> .text with implicit addends [58,58,58,E0,F0,100,58]; +0x8015B950 + * = [8015B9A8, 8015B9A8, 8015B9A8, 8015BA30, 8015BA40, 8015BA50, 8015B9A8]. + * Diffed word-for-word against asm/ov_SC01_077/data/tail14.data.s:15-23 — 7/7 identical. + * symcheck : SYMS-DIFF target=35 draft=34, sole MISSING = jtbl_801D8B74. This is the §81 jr + * FALSE POSITIVE, re-confirmed here by reading the relocs: gcc emits its OWN table and + * references it with R_MIPS_HI16/LO16 against the SECTION `.rodata` (t.o +0x40/+0x48), + * so the splat's dlabel NAME can never appear in the draft object's relocation set. + * Nothing is dropped and nothing is invented: the draft's other 34 symbols are exactly + * the target's other 34. + * FAMILY : the x138 remap is clean and §84-safe. Every sibling is 271 ins with an IDENTICAL + * callee set; only THREE names vary per overlay — the two data labels and the jtbl: + * ov_SC01_077 D_801863B0 / D_8018641C / jtbl_801D8B74 + * ov_SC03_099 D_80185A50 / D_80185ABC / jtbl_801BD898 + * ov_SC06_008 D_80187E44 / D_80187EB0 / jtbl_801A8734 + * The pair is always +0x6C apart, and NO literal in this draft encodes that distance + * (both labels are referenced by name), so there is no §84 derived-offset hazard. + * D_8011F9C4 is fleet-constant (main-EXE data) and must NOT be remapped. + * + * match_one: MATCH (271 ins) against the CURRENT tree (§87 staleness re-checked, 2026-07-27). + * PIN-FREE, zero asm, offset-pure (s32 arg0 + raw offsets) — x138 template-safe. + * Provenance: this is the Phase-26 crack (.run/phase26-cracks/func_8015B950.c) re-gated verbatim, + * with ONE deliberate change: the definition's return type void -> s32. + * - `void func_8015B950(s32 arg0)` : MATCH (271 ins) [the Phase-26 form] + * - `s32 func_8015B950(s32 arg0)` : MATCH (271 ins) [shipped — §3a-1 void->s32 is byte-neutral] + * The fleet/engine_core.h canonical decl is `extern s32 func_8015B950(void);` (engine_core.h:1852), + * and the last bank attempt (.run/bank_func_8015B950.log) died on `conflicting types for + * func_8015B950`. Shipping the s32 return kills the §73 RETURN axis for free and leaves only the + * cheap T0 PARAMS axis for the ladder (fix_header_decl.py / --fix-def-sig / cast_call_sites). + * Both forms are byte-identical, so the orchestrator may swap the return type back at zero cost. + * + * SYMBOLS (§58 rules 1/2 — all splat spellings, all verified present): + * D_8018641C asm/ov_SC01_077/data/tail.data.s:4355 (the state-handler vtable) + * D_801863B0 asm/ov_SC01_077/data/tail.data.s:4293 + * D_8011F9C4 main-EXE data; spelled `extern s32 D_8011F9C4;` in 5+ already-banked TUs + * jtbl_801D8B74 asm/ov_SC01_077/data/tail14.data.s:15 (compiler jump table — not named in C) + * + * JTBL VERIFIED (§8a gate): compiled .rodata = exactly 0x1C B / 7 words, 7x R_MIPS_32 .text with + * addends [0x58,0x58,0x58,0xE0,0xF0,0x100,0x58] -> +0x8015B950 = [B9A8,B9A8,B9A8,BA30,BA40,BA50, + * B9A8] == the original words at 0x801D8B74..0x801D8B8C. Bound `sltiu $v0,$v1,0x7` matches. + * The raw dlabel's 8th word 0x00000000 is NOT an entry — it is the intra-TU `.align 3` pad of the + * B34/B54/B74 jtbl chain; the object can never emit it (maspsx drops .align), so it must stay in + * the post-carve RAW data piece (the §53/§62/§81 carve chain applies at bank time). + * + * Same family as the TU's own already-matched func_8015AE2C: 7-case switch on ((s32 (*)(s32))func_801619A4)() + * (0/1/2/6 shared, 3/4/5 own, no default block — out-of-range and every `break` fall to the + * after-switch join), then a chain of "state handler" tests, each dispatching + * D_8018641C[*(u16*)arg0](arg0) and returning. + * + * THREE LEVERS (draft -> MATCH in 3 compiles): + * + * 1. PROLOGUE CONSTANT = an INITIALIZED LOCAL, not a literal in the compare. + * Target opens with `lui $s2, 0xFFF5` in the *prologue*, used once ~200 ins later in + * `slt $v0,$s2,$s1`. No gcc-2.7.2 pass hoists a (set reg const_int) across basic blocks + * (loop.c needs a loop; cse/combine/sched never move insns between BBs) — so the insn must + * have been EMITTED in the first BB, i.e. the constant is a local initialized at the top of + * the function. cse then cannot fold it back into the compare: the `slt` operand predicate is + * `arith_operand`, which rejects a CONST_INT wider than 16 bits, so validate_change fails and + * the pseudo survives. Its live range spans every call -> global.c gives it a callee-saved reg. + * Writing `z > -0xB0000` inline instead emits the `lui` into the branch delay slot next to the + * compare (caller-saved $v0) and the function is 1 insn short. => `s32 lim = -0xB0000;` at top. + * + * 2. `lh` vs `lhu`: a short->short copy is a pure HImode move and gcc emits `lhu`. The target's + * `lh $v0,0x26($s0)` means the value passed through an SImode (int) temp: expand makes + * (set (reg:SI) (sign_extend (mem:HI))) + (set (mem:HI) (subreg:HI ...)), and combine cannot + * merge them (the merged form is mem<-mem, which no movhi accepts) so the sign-extending load + * survives. => route both halfword copies through the `s32 t` temp. + * + * 3. THE `goto` LAYOUT — dodging jump.c's store-flag conversion (jump.c:1005-1065). + * An if/else chain writing 0/1 into `doit` makes gcc collapse the last pair into + * `sltiu $v0,$v0,1`. jump.c fires that conversion when the insn immediately after a + * conditional jump is a lone `SET pseudo, CONST_INT` whose following simplejump targets the + * SAME label as the branch (jump.c:1038 `reallabelprev == temp || ... JUMP_LABEL(temp4) == + * JUMP_LABEL(insn)`) — exactly the shape of `if (c) x=0; else x=1;`. + * The target instead cross-jumps ALL the `doit=0` exits into ONE shared block placed after the + * `doit=1` fall-through; reorg's fill_slots_from_thread then COPIES that single set into all + * three branch delay slots and redirects each branch past it (which is why `addu $v0,$zero, + * $zero` appears 3x in delay slots and the shared block vanishes). A `goto zero;` / `goto one;` + * chain expresses that layout directly, and each conditional jump is then followed by a + * compare/call rather than a lone const set, so the store-flag conversion never triggers. + * GENERAL RULE: multiple predicates that all assign the SAME constant to one flag => write + * them as `goto` to a shared assignment, never as an if/else ladder. + */ +extern s32 D_8011F9C4; +extern s32 D_801863B0; + +extern s32 func_80161B18(void); +extern s32 func_801619A4(s32*); +extern s32 func_80149AA8(s32*); +extern void func_80149AD4(s32*); +extern s32 func_80149B54(s32*); +extern void func_80149BAC(s32*); +extern s32 func_801498E0(s32*); +extern s32 func_80149954(s32); +extern s32 func_80149A64(s32*); +extern void func_800CCCC0(s32 a0); +extern s32 func_80149CD4(s32 a0); +extern void func_8015E880(s32*); +extern s32 func_80149744(struct S_80149744*); +extern void func_80149788(void); +extern s32 func_801496D4(void*); +extern void func_80149704(void); +extern int func_80148AFC(void*); +extern void func_80146D90(s32 a0); +extern void func_80154150(s32 a0, s32 a1); +extern void func_801541D8(u8*, s32, s32); +extern s32 func_801488A8(u8*); +extern void func_80147078(s32*, s16); +extern void func_8015A264(void*); +extern s32 func_80013294(void*, void*); +extern void func_80159B70(void*); +extern s32 func_8016F1AC(void); +extern s32 func_80029178(s32 a0); +extern void func_80146DB8(s32*, s32*); +extern s32 func_80161CD0(s32, s32); +extern s32 func_80161208(s32 a0); +extern s32 func_801725A4(u8*); + +s32 func_8015B950(s32 arg0) +{ + + extern void (*D_8018641C[])(void *); + s16 sp10[4]; + s16 sp18[4]; + s32 t; + s32 z; + s32 doit; + s32 lim = -0xB0000; + + if (func_80161B18() != 0) { + return; + } + switch (((s32 (*)(s32))func_801619A4)(arg0)) { + case 0: + case 1: + case 2: + case 6: + if (((s32 (*)(s32))func_80149AA8)(arg0) != 0) { + D_8018641C[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149AD4)(arg0); + return; + } + if (((s32 (*)(s32))func_80149B54)(arg0) != 0) { + D_8018641C[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149BAC)(arg0); + return; + } + break; + case 3: + ((void (*)(s32))func_801498E0)(arg0); + break; + case 4: + ((void (*)(s32))func_80149954)(arg0); + break; + case 5: + if (((s32 (*)(s32))func_80149A64)(arg0) != 0) { + D_8018641C[*(u16 *)arg0]((void *)arg0); + func_800CCCC0(arg0); + return; + } + break; + } + if (func_80149CD4(arg0) != 0) { + D_8018641C[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_8015E880)(arg0); + return; + } + if (((s32 (*)(s32))func_80149744)(arg0) != 0) { + D_8018641C[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149788)(arg0); + return; + } + if (((s32 (*)(s32))func_801496D4)(arg0) != 0) { + D_8018641C[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149704)(arg0); + if (((u8)((s32 (*)(s32))func_80148AFC)(arg0)) == 0) { + func_80146D90(arg0); + } + if ((*(s32 *)(arg0 + 0x24) | *(s32 *)(arg0 + 0x2C)) != 0) { + func_80154150(arg0, 0xF); + } else { + ((void (*)(s32, s32, s32))func_801541D8)(arg0, 0xD, 6); + } + *(s32 *)(arg0 + 0x238) = 1; + return; + } + if (((s32 (*)(s32))func_801488A8)(arg0) != 0) { + sp10[0] = 0; + sp10[1] = 0; + sp10[2] = 0; + t = *(s16 *)(arg0 + 0x26); + sp18[0] = t; + sp18[1] = 0; + t = *(s16 *)(arg0 + 0x2E); + sp18[2] = t; + D_8018641C[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 1); + ((void (*)(s32))func_8015A264)(arg0); + t = -(((s32 (*)(s16 *, s16 *))func_80013294)(sp10, sp18) << 0x10); + if (t < *(s32 *)(arg0 + 0x2C)) { + *(s32 *)(arg0 + 0x2C) = t; + } + return; + } + if (*(u16 *)(arg0 + 0xB8) == 0x8000) { + D_8018641C[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 0); + ((void (*)(s32))func_80159B70)(arg0); + return; + } + z = *(s32 *)(arg0 + 0x2C); + if (func_8016F1AC() != 0) { + goto zero; + } + if (z <= lim) { + goto one; + } + if (D_8011F9C4 == 0) { + goto zero; + } + if (((u8)func_80029178(0x21)) != 0) { + goto zero; + } +one: + doit = 1; + goto join; +zero: + doit = 0; +join: + if (doit != 0) { + D_8018641C[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 0); + ((void (*)(s32))func_80159B70)(arg0); + func_80154150(arg0, 9); + ((void (*)(s32, s32 *))func_80146DB8)(arg0, &D_801863B0); + ((void (*)(s32, s32))func_80161CD0)(arg0, *(u16 *)(arg0 + 0x16E)); + return; + } + if (func_80161208(arg0) == 0) { + ((void (*)(s32))func_801725A4)(arg0); + } +} DEFINE_func_8015BD8C() /* dedup: shared engine-core @0x8015BD8C (src/shared) */ diff --git a/src/ov_SC03_126/ov_SC03_126_jr_8015AE2C.c b/src/ov_SC03_126/ov_SC03_126_jr_8015AE2C.c index 59955dc9c..778cdb81f 100644 --- a/src/ov_SC03_126/ov_SC03_126_jr_8015AE2C.c +++ b/src/ov_SC03_126/ov_SC03_126_jr_8015AE2C.c @@ -1512,7 +1512,259 @@ DEFINE_func_8015B858() /* dedup: shared engine-core @0x8015B858 (src/shared) */ DEFINE_func_8015B8F8() /* dedup: shared engine-core @0x8015B8F8 (src/shared) */ -INCLUDE_ASM("asm/ov_SC03_126/nonmatchings/ov_SC03_126_jr_8015AE2C", func_8015B950); +extern s32 func_8015AE2C(); + +// @class: plumbing +// @stuck: none — MATCH (271/271, pin-free, zero asm). The ONLY residual is DEF-SIDE plumbing, and it is now named exactly: the in-TU instantiation `DEFINE_func_8015BEE4()` (engine_core.h:1851-1855) expands to `extern s32 func_8015B950(void);` INSIDE ov_SC01_077_jr_8015AE2C.c, ~14 lines BELOW this definition, so the 1-param def collides with a `(void)` prototype -> `conflicting types for func_8015B950` (.run/bank_func_8015B950.log). §73 PARAMS axis / T0. Surgical fix = §65b de-macroize that ONE instantiation (blast radius: this TU); the fleet-wide `(void)`->`()` header edit is §63 and must be R22-validated. +/* func_8015B950 (ov_SC01_077_jr_8015AE2C, 271 ins, jtbl_801D8B74) — SESSION-21 re-verified + * + * ── ROUND-2 INDEPENDENT RE-VERIFICATION (2026-07-27, fresh agent, §88e discipline) ───────────── + * match_one : MATCH (271 ins) against the CURRENT tree — §87 staleness re-checked today. + * .text size: compiled .text = 0x43C = 1084 B = 271 ins, EXACTLY the target's declared 0x43C + * ("nonmatching func_8015B950, 0x43C"). So this is NOT a §83a length drift hiding + * behind a zero count — the count is over equal-length streams. + * jtbl : RE-DECODED MECHANICALLY, not inherited. Compiled .rodata = 0x1C = 28 B = 7 words, + * 7x R_MIPS_32 -> .text with implicit addends [58,58,58,E0,F0,100,58]; +0x8015B950 + * = [8015B9A8, 8015B9A8, 8015B9A8, 8015BA30, 8015BA40, 8015BA50, 8015B9A8]. + * Diffed word-for-word against asm/ov_SC01_077/data/tail14.data.s:15-23 — 7/7 identical. + * symcheck : SYMS-DIFF target=35 draft=34, sole MISSING = jtbl_801D8B74. This is the §81 jr + * FALSE POSITIVE, re-confirmed here by reading the relocs: gcc emits its OWN table and + * references it with R_MIPS_HI16/LO16 against the SECTION `.rodata` (t.o +0x40/+0x48), + * so the splat's dlabel NAME can never appear in the draft object's relocation set. + * Nothing is dropped and nothing is invented: the draft's other 34 symbols are exactly + * the target's other 34. + * FAMILY : the x138 remap is clean and §84-safe. Every sibling is 271 ins with an IDENTICAL + * callee set; only THREE names vary per overlay — the two data labels and the jtbl: + * ov_SC01_077 D_801818A8 / D_80181914 / jtbl_801D8B74 + * ov_SC03_099 D_80185A50 / D_80185ABC / jtbl_801BD898 + * ov_SC06_008 D_80187E44 / D_80187EB0 / jtbl_801A8734 + * The pair is always +0x6C apart, and NO literal in this draft encodes that distance + * (both labels are referenced by name), so there is no §84 derived-offset hazard. + * D_8011F9C4 is fleet-constant (main-EXE data) and must NOT be remapped. + * + * match_one: MATCH (271 ins) against the CURRENT tree (§87 staleness re-checked, 2026-07-27). + * PIN-FREE, zero asm, offset-pure (s32 arg0 + raw offsets) — x138 template-safe. + * Provenance: this is the Phase-26 crack (.run/phase26-cracks/func_8015B950.c) re-gated verbatim, + * with ONE deliberate change: the definition's return type void -> s32. + * - `void func_8015B950(s32 arg0)` : MATCH (271 ins) [the Phase-26 form] + * - `s32 func_8015B950(s32 arg0)` : MATCH (271 ins) [shipped — §3a-1 void->s32 is byte-neutral] + * The fleet/engine_core.h canonical decl is `extern s32 func_8015B950(void);` (engine_core.h:1852), + * and the last bank attempt (.run/bank_func_8015B950.log) died on `conflicting types for + * func_8015B950`. Shipping the s32 return kills the §73 RETURN axis for free and leaves only the + * cheap T0 PARAMS axis for the ladder (fix_header_decl.py / --fix-def-sig / cast_call_sites). + * Both forms are byte-identical, so the orchestrator may swap the return type back at zero cost. + * + * SYMBOLS (§58 rules 1/2 — all splat spellings, all verified present): + * D_80181914 asm/ov_SC01_077/data/tail.data.s:4355 (the state-handler vtable) + * D_801818A8 asm/ov_SC01_077/data/tail.data.s:4293 + * D_8011F9C4 main-EXE data; spelled `extern s32 D_8011F9C4;` in 5+ already-banked TUs + * jtbl_801D8B74 asm/ov_SC01_077/data/tail14.data.s:15 (compiler jump table — not named in C) + * + * JTBL VERIFIED (§8a gate): compiled .rodata = exactly 0x1C B / 7 words, 7x R_MIPS_32 .text with + * addends [0x58,0x58,0x58,0xE0,0xF0,0x100,0x58] -> +0x8015B950 = [B9A8,B9A8,B9A8,BA30,BA40,BA50, + * B9A8] == the original words at 0x801D8B74..0x801D8B8C. Bound `sltiu $v0,$v1,0x7` matches. + * The raw dlabel's 8th word 0x00000000 is NOT an entry — it is the intra-TU `.align 3` pad of the + * B34/B54/B74 jtbl chain; the object can never emit it (maspsx drops .align), so it must stay in + * the post-carve RAW data piece (the §53/§62/§81 carve chain applies at bank time). + * + * Same family as the TU's own already-matched func_8015AE2C: 7-case switch on ((s32 (*)(s32))func_801619A4)() + * (0/1/2/6 shared, 3/4/5 own, no default block — out-of-range and every `break` fall to the + * after-switch join), then a chain of "state handler" tests, each dispatching + * D_80181914[*(u16*)arg0](arg0) and returning. + * + * THREE LEVERS (draft -> MATCH in 3 compiles): + * + * 1. PROLOGUE CONSTANT = an INITIALIZED LOCAL, not a literal in the compare. + * Target opens with `lui $s2, 0xFFF5` in the *prologue*, used once ~200 ins later in + * `slt $v0,$s2,$s1`. No gcc-2.7.2 pass hoists a (set reg const_int) across basic blocks + * (loop.c needs a loop; cse/combine/sched never move insns between BBs) — so the insn must + * have been EMITTED in the first BB, i.e. the constant is a local initialized at the top of + * the function. cse then cannot fold it back into the compare: the `slt` operand predicate is + * `arith_operand`, which rejects a CONST_INT wider than 16 bits, so validate_change fails and + * the pseudo survives. Its live range spans every call -> global.c gives it a callee-saved reg. + * Writing `z > -0xB0000` inline instead emits the `lui` into the branch delay slot next to the + * compare (caller-saved $v0) and the function is 1 insn short. => `s32 lim = -0xB0000;` at top. + * + * 2. `lh` vs `lhu`: a short->short copy is a pure HImode move and gcc emits `lhu`. The target's + * `lh $v0,0x26($s0)` means the value passed through an SImode (int) temp: expand makes + * (set (reg:SI) (sign_extend (mem:HI))) + (set (mem:HI) (subreg:HI ...)), and combine cannot + * merge them (the merged form is mem<-mem, which no movhi accepts) so the sign-extending load + * survives. => route both halfword copies through the `s32 t` temp. + * + * 3. THE `goto` LAYOUT — dodging jump.c's store-flag conversion (jump.c:1005-1065). + * An if/else chain writing 0/1 into `doit` makes gcc collapse the last pair into + * `sltiu $v0,$v0,1`. jump.c fires that conversion when the insn immediately after a + * conditional jump is a lone `SET pseudo, CONST_INT` whose following simplejump targets the + * SAME label as the branch (jump.c:1038 `reallabelprev == temp || ... JUMP_LABEL(temp4) == + * JUMP_LABEL(insn)`) — exactly the shape of `if (c) x=0; else x=1;`. + * The target instead cross-jumps ALL the `doit=0` exits into ONE shared block placed after the + * `doit=1` fall-through; reorg's fill_slots_from_thread then COPIES that single set into all + * three branch delay slots and redirects each branch past it (which is why `addu $v0,$zero, + * $zero` appears 3x in delay slots and the shared block vanishes). A `goto zero;` / `goto one;` + * chain expresses that layout directly, and each conditional jump is then followed by a + * compare/call rather than a lone const set, so the store-flag conversion never triggers. + * GENERAL RULE: multiple predicates that all assign the SAME constant to one flag => write + * them as `goto` to a shared assignment, never as an if/else ladder. + */ +extern s32 D_8011F9C4; +extern s32 D_801818A8; + +extern s32 func_80161B18(void); +extern s32 func_801619A4(s32*); +extern s32 func_80149AA8(s32*); +extern void func_80149AD4(s32*); +extern s32 func_80149B54(s32*); +extern void func_80149BAC(s32*); +extern s32 func_801498E0(s32*); +extern s32 func_80149954(s32); +extern s32 func_80149A64(s32*); +extern void func_800CCCC0(s32 a0); +extern s32 func_80149CD4(s32 a0); +extern void func_8015E880(s32*); +extern s32 func_80149744(struct S_80149744*); +extern void func_80149788(void); +extern s32 func_801496D4(void*); +extern void func_80149704(void); +extern int func_80148AFC(void*); +extern void func_80146D90(s32 a0); +extern void func_80154150(s32 a0, s32 a1); +extern void func_801541D8(u8*, s32, s32); +extern s32 func_801488A8(u8*); +extern void func_80147078(s32*, s16); +extern void func_8015A264(void*); +extern s32 func_80013294(void*, void*); +extern void func_80159B70(void*); +extern s32 func_8016F1AC(void); +extern s32 func_80029178(s32 a0); +extern void func_80146DB8(s32*, s32*); +extern s32 func_80161CD0(s32, s32); +extern s32 func_80161208(s32 a0); +extern s32 func_801725A4(u8*); + +s32 func_8015B950(s32 arg0) +{ + + extern void (*D_80181914[])(void *); + s16 sp10[4]; + s16 sp18[4]; + s32 t; + s32 z; + s32 doit; + s32 lim = -0xB0000; + + if (func_80161B18() != 0) { + return; + } + switch (((s32 (*)(s32))func_801619A4)(arg0)) { + case 0: + case 1: + case 2: + case 6: + if (((s32 (*)(s32))func_80149AA8)(arg0) != 0) { + D_80181914[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149AD4)(arg0); + return; + } + if (((s32 (*)(s32))func_80149B54)(arg0) != 0) { + D_80181914[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149BAC)(arg0); + return; + } + break; + case 3: + ((void (*)(s32))func_801498E0)(arg0); + break; + case 4: + ((void (*)(s32))func_80149954)(arg0); + break; + case 5: + if (((s32 (*)(s32))func_80149A64)(arg0) != 0) { + D_80181914[*(u16 *)arg0]((void *)arg0); + func_800CCCC0(arg0); + return; + } + break; + } + if (func_80149CD4(arg0) != 0) { + D_80181914[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_8015E880)(arg0); + return; + } + if (((s32 (*)(s32))func_80149744)(arg0) != 0) { + D_80181914[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149788)(arg0); + return; + } + if (((s32 (*)(s32))func_801496D4)(arg0) != 0) { + D_80181914[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149704)(arg0); + if (((u8)((s32 (*)(s32))func_80148AFC)(arg0)) == 0) { + func_80146D90(arg0); + } + if ((*(s32 *)(arg0 + 0x24) | *(s32 *)(arg0 + 0x2C)) != 0) { + func_80154150(arg0, 0xF); + } else { + ((void (*)(s32, s32, s32))func_801541D8)(arg0, 0xD, 6); + } + *(s32 *)(arg0 + 0x238) = 1; + return; + } + if (((s32 (*)(s32))func_801488A8)(arg0) != 0) { + sp10[0] = 0; + sp10[1] = 0; + sp10[2] = 0; + t = *(s16 *)(arg0 + 0x26); + sp18[0] = t; + sp18[1] = 0; + t = *(s16 *)(arg0 + 0x2E); + sp18[2] = t; + D_80181914[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 1); + ((void (*)(s32))func_8015A264)(arg0); + t = -(((s32 (*)(s16 *, s16 *))func_80013294)(sp10, sp18) << 0x10); + if (t < *(s32 *)(arg0 + 0x2C)) { + *(s32 *)(arg0 + 0x2C) = t; + } + return; + } + if (*(u16 *)(arg0 + 0xB8) == 0x8000) { + D_80181914[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 0); + ((void (*)(s32))func_80159B70)(arg0); + return; + } + z = *(s32 *)(arg0 + 0x2C); + if (func_8016F1AC() != 0) { + goto zero; + } + if (z <= lim) { + goto one; + } + if (D_8011F9C4 == 0) { + goto zero; + } + if (((u8)func_80029178(0x21)) != 0) { + goto zero; + } +one: + doit = 1; + goto join; +zero: + doit = 0; +join: + if (doit != 0) { + D_80181914[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 0); + ((void (*)(s32))func_80159B70)(arg0); + func_80154150(arg0, 9); + ((void (*)(s32, s32 *))func_80146DB8)(arg0, &D_801818A8); + ((void (*)(s32, s32))func_80161CD0)(arg0, *(u16 *)(arg0 + 0x16E)); + return; + } + if (func_80161208(arg0) == 0) { + ((void (*)(s32))func_801725A4)(arg0); + } +} DEFINE_func_8015BD8C() /* dedup: shared engine-core @0x8015BD8C (src/shared) */ diff --git a/src/ov_SC04_000/ov_SC04_000_jr_8015AE2C.c b/src/ov_SC04_000/ov_SC04_000_jr_8015AE2C.c index ef4673a47..2e6ff604e 100644 --- a/src/ov_SC04_000/ov_SC04_000_jr_8015AE2C.c +++ b/src/ov_SC04_000/ov_SC04_000_jr_8015AE2C.c @@ -1512,7 +1512,259 @@ DEFINE_func_8015B858() /* dedup: shared engine-core @0x8015B858 (src/shared) */ DEFINE_func_8015B8F8() /* dedup: shared engine-core @0x8015B8F8 (src/shared) */ -INCLUDE_ASM("asm/ov_SC04_000/nonmatchings/ov_SC04_000_jr_8015AE2C", func_8015B950); +extern s32 func_8015AE2C(); + +// @class: plumbing +// @stuck: none — MATCH (271/271, pin-free, zero asm). The ONLY residual is DEF-SIDE plumbing, and it is now named exactly: the in-TU instantiation `DEFINE_func_8015BEE4()` (engine_core.h:1851-1855) expands to `extern s32 func_8015B950(void);` INSIDE ov_SC01_077_jr_8015AE2C.c, ~14 lines BELOW this definition, so the 1-param def collides with a `(void)` prototype -> `conflicting types for func_8015B950` (.run/bank_func_8015B950.log). §73 PARAMS axis / T0. Surgical fix = §65b de-macroize that ONE instantiation (blast radius: this TU); the fleet-wide `(void)`->`()` header edit is §63 and must be R22-validated. +/* func_8015B950 (ov_SC01_077_jr_8015AE2C, 271 ins, jtbl_801D8B74) — SESSION-21 re-verified + * + * ── ROUND-2 INDEPENDENT RE-VERIFICATION (2026-07-27, fresh agent, §88e discipline) ───────────── + * match_one : MATCH (271 ins) against the CURRENT tree — §87 staleness re-checked today. + * .text size: compiled .text = 0x43C = 1084 B = 271 ins, EXACTLY the target's declared 0x43C + * ("nonmatching func_8015B950, 0x43C"). So this is NOT a §83a length drift hiding + * behind a zero count — the count is over equal-length streams. + * jtbl : RE-DECODED MECHANICALLY, not inherited. Compiled .rodata = 0x1C = 28 B = 7 words, + * 7x R_MIPS_32 -> .text with implicit addends [58,58,58,E0,F0,100,58]; +0x8015B950 + * = [8015B9A8, 8015B9A8, 8015B9A8, 8015BA30, 8015BA40, 8015BA50, 8015B9A8]. + * Diffed word-for-word against asm/ov_SC01_077/data/tail14.data.s:15-23 — 7/7 identical. + * symcheck : SYMS-DIFF target=35 draft=34, sole MISSING = jtbl_801D8B74. This is the §81 jr + * FALSE POSITIVE, re-confirmed here by reading the relocs: gcc emits its OWN table and + * references it with R_MIPS_HI16/LO16 against the SECTION `.rodata` (t.o +0x40/+0x48), + * so the splat's dlabel NAME can never appear in the draft object's relocation set. + * Nothing is dropped and nothing is invented: the draft's other 34 symbols are exactly + * the target's other 34. + * FAMILY : the x138 remap is clean and §84-safe. Every sibling is 271 ins with an IDENTICAL + * callee set; only THREE names vary per overlay — the two data labels and the jtbl: + * ov_SC01_077 D_801858B4 / D_80185920 / jtbl_801D8B74 + * ov_SC03_099 D_80185A50 / D_80185ABC / jtbl_801BD898 + * ov_SC06_008 D_80187E44 / D_80187EB0 / jtbl_801A8734 + * The pair is always +0x6C apart, and NO literal in this draft encodes that distance + * (both labels are referenced by name), so there is no §84 derived-offset hazard. + * D_8011F9C4 is fleet-constant (main-EXE data) and must NOT be remapped. + * + * match_one: MATCH (271 ins) against the CURRENT tree (§87 staleness re-checked, 2026-07-27). + * PIN-FREE, zero asm, offset-pure (s32 arg0 + raw offsets) — x138 template-safe. + * Provenance: this is the Phase-26 crack (.run/phase26-cracks/func_8015B950.c) re-gated verbatim, + * with ONE deliberate change: the definition's return type void -> s32. + * - `void func_8015B950(s32 arg0)` : MATCH (271 ins) [the Phase-26 form] + * - `s32 func_8015B950(s32 arg0)` : MATCH (271 ins) [shipped — §3a-1 void->s32 is byte-neutral] + * The fleet/engine_core.h canonical decl is `extern s32 func_8015B950(void);` (engine_core.h:1852), + * and the last bank attempt (.run/bank_func_8015B950.log) died on `conflicting types for + * func_8015B950`. Shipping the s32 return kills the §73 RETURN axis for free and leaves only the + * cheap T0 PARAMS axis for the ladder (fix_header_decl.py / --fix-def-sig / cast_call_sites). + * Both forms are byte-identical, so the orchestrator may swap the return type back at zero cost. + * + * SYMBOLS (§58 rules 1/2 — all splat spellings, all verified present): + * D_80185920 asm/ov_SC01_077/data/tail.data.s:4355 (the state-handler vtable) + * D_801858B4 asm/ov_SC01_077/data/tail.data.s:4293 + * D_8011F9C4 main-EXE data; spelled `extern s32 D_8011F9C4;` in 5+ already-banked TUs + * jtbl_801D8B74 asm/ov_SC01_077/data/tail14.data.s:15 (compiler jump table — not named in C) + * + * JTBL VERIFIED (§8a gate): compiled .rodata = exactly 0x1C B / 7 words, 7x R_MIPS_32 .text with + * addends [0x58,0x58,0x58,0xE0,0xF0,0x100,0x58] -> +0x8015B950 = [B9A8,B9A8,B9A8,BA30,BA40,BA50, + * B9A8] == the original words at 0x801D8B74..0x801D8B8C. Bound `sltiu $v0,$v1,0x7` matches. + * The raw dlabel's 8th word 0x00000000 is NOT an entry — it is the intra-TU `.align 3` pad of the + * B34/B54/B74 jtbl chain; the object can never emit it (maspsx drops .align), so it must stay in + * the post-carve RAW data piece (the §53/§62/§81 carve chain applies at bank time). + * + * Same family as the TU's own already-matched func_8015AE2C: 7-case switch on ((s32 (*)(s32))func_801619A4)() + * (0/1/2/6 shared, 3/4/5 own, no default block — out-of-range and every `break` fall to the + * after-switch join), then a chain of "state handler" tests, each dispatching + * D_80185920[*(u16*)arg0](arg0) and returning. + * + * THREE LEVERS (draft -> MATCH in 3 compiles): + * + * 1. PROLOGUE CONSTANT = an INITIALIZED LOCAL, not a literal in the compare. + * Target opens with `lui $s2, 0xFFF5` in the *prologue*, used once ~200 ins later in + * `slt $v0,$s2,$s1`. No gcc-2.7.2 pass hoists a (set reg const_int) across basic blocks + * (loop.c needs a loop; cse/combine/sched never move insns between BBs) — so the insn must + * have been EMITTED in the first BB, i.e. the constant is a local initialized at the top of + * the function. cse then cannot fold it back into the compare: the `slt` operand predicate is + * `arith_operand`, which rejects a CONST_INT wider than 16 bits, so validate_change fails and + * the pseudo survives. Its live range spans every call -> global.c gives it a callee-saved reg. + * Writing `z > -0xB0000` inline instead emits the `lui` into the branch delay slot next to the + * compare (caller-saved $v0) and the function is 1 insn short. => `s32 lim = -0xB0000;` at top. + * + * 2. `lh` vs `lhu`: a short->short copy is a pure HImode move and gcc emits `lhu`. The target's + * `lh $v0,0x26($s0)` means the value passed through an SImode (int) temp: expand makes + * (set (reg:SI) (sign_extend (mem:HI))) + (set (mem:HI) (subreg:HI ...)), and combine cannot + * merge them (the merged form is mem<-mem, which no movhi accepts) so the sign-extending load + * survives. => route both halfword copies through the `s32 t` temp. + * + * 3. THE `goto` LAYOUT — dodging jump.c's store-flag conversion (jump.c:1005-1065). + * An if/else chain writing 0/1 into `doit` makes gcc collapse the last pair into + * `sltiu $v0,$v0,1`. jump.c fires that conversion when the insn immediately after a + * conditional jump is a lone `SET pseudo, CONST_INT` whose following simplejump targets the + * SAME label as the branch (jump.c:1038 `reallabelprev == temp || ... JUMP_LABEL(temp4) == + * JUMP_LABEL(insn)`) — exactly the shape of `if (c) x=0; else x=1;`. + * The target instead cross-jumps ALL the `doit=0` exits into ONE shared block placed after the + * `doit=1` fall-through; reorg's fill_slots_from_thread then COPIES that single set into all + * three branch delay slots and redirects each branch past it (which is why `addu $v0,$zero, + * $zero` appears 3x in delay slots and the shared block vanishes). A `goto zero;` / `goto one;` + * chain expresses that layout directly, and each conditional jump is then followed by a + * compare/call rather than a lone const set, so the store-flag conversion never triggers. + * GENERAL RULE: multiple predicates that all assign the SAME constant to one flag => write + * them as `goto` to a shared assignment, never as an if/else ladder. + */ +extern s32 D_8011F9C4; +extern s32 D_801858B4; + +extern s32 func_80161B18(void); +extern s32 func_801619A4(s32*); +extern s32 func_80149AA8(s32*); +extern void func_80149AD4(s32*); +extern s32 func_80149B54(s32*); +extern void func_80149BAC(s32*); +extern s32 func_801498E0(s32*); +extern s32 func_80149954(s32); +extern s32 func_80149A64(s32*); +extern void func_800CCCC0(s32 a0); +extern s32 func_80149CD4(s32 a0); +extern void func_8015E880(s32*); +extern s32 func_80149744(struct S_80149744*); +extern void func_80149788(void); +extern s32 func_801496D4(void*); +extern void func_80149704(void); +extern int func_80148AFC(void*); +extern void func_80146D90(s32 a0); +extern void func_80154150(s32 a0, s32 a1); +extern void func_801541D8(u8*, s32, s32); +extern s32 func_801488A8(u8*); +extern void func_80147078(s32*, s16); +extern void func_8015A264(void*); +extern s32 func_80013294(void*, void*); +extern void func_80159B70(void*); +extern s32 func_8016F1AC(void); +extern s32 func_80029178(s32 a0); +extern void func_80146DB8(s32*, s32*); +extern s32 func_80161CD0(s32, s32); +extern s32 func_80161208(s32 a0); +extern s32 func_801725A4(u8*); + +s32 func_8015B950(s32 arg0) +{ + + extern void (*D_80185920[])(void *); + s16 sp10[4]; + s16 sp18[4]; + s32 t; + s32 z; + s32 doit; + s32 lim = -0xB0000; + + if (func_80161B18() != 0) { + return; + } + switch (((s32 (*)(s32))func_801619A4)(arg0)) { + case 0: + case 1: + case 2: + case 6: + if (((s32 (*)(s32))func_80149AA8)(arg0) != 0) { + D_80185920[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149AD4)(arg0); + return; + } + if (((s32 (*)(s32))func_80149B54)(arg0) != 0) { + D_80185920[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149BAC)(arg0); + return; + } + break; + case 3: + ((void (*)(s32))func_801498E0)(arg0); + break; + case 4: + ((void (*)(s32))func_80149954)(arg0); + break; + case 5: + if (((s32 (*)(s32))func_80149A64)(arg0) != 0) { + D_80185920[*(u16 *)arg0]((void *)arg0); + func_800CCCC0(arg0); + return; + } + break; + } + if (func_80149CD4(arg0) != 0) { + D_80185920[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_8015E880)(arg0); + return; + } + if (((s32 (*)(s32))func_80149744)(arg0) != 0) { + D_80185920[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149788)(arg0); + return; + } + if (((s32 (*)(s32))func_801496D4)(arg0) != 0) { + D_80185920[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149704)(arg0); + if (((u8)((s32 (*)(s32))func_80148AFC)(arg0)) == 0) { + func_80146D90(arg0); + } + if ((*(s32 *)(arg0 + 0x24) | *(s32 *)(arg0 + 0x2C)) != 0) { + func_80154150(arg0, 0xF); + } else { + ((void (*)(s32, s32, s32))func_801541D8)(arg0, 0xD, 6); + } + *(s32 *)(arg0 + 0x238) = 1; + return; + } + if (((s32 (*)(s32))func_801488A8)(arg0) != 0) { + sp10[0] = 0; + sp10[1] = 0; + sp10[2] = 0; + t = *(s16 *)(arg0 + 0x26); + sp18[0] = t; + sp18[1] = 0; + t = *(s16 *)(arg0 + 0x2E); + sp18[2] = t; + D_80185920[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 1); + ((void (*)(s32))func_8015A264)(arg0); + t = -(((s32 (*)(s16 *, s16 *))func_80013294)(sp10, sp18) << 0x10); + if (t < *(s32 *)(arg0 + 0x2C)) { + *(s32 *)(arg0 + 0x2C) = t; + } + return; + } + if (*(u16 *)(arg0 + 0xB8) == 0x8000) { + D_80185920[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 0); + ((void (*)(s32))func_80159B70)(arg0); + return; + } + z = *(s32 *)(arg0 + 0x2C); + if (func_8016F1AC() != 0) { + goto zero; + } + if (z <= lim) { + goto one; + } + if (D_8011F9C4 == 0) { + goto zero; + } + if (((u8)func_80029178(0x21)) != 0) { + goto zero; + } +one: + doit = 1; + goto join; +zero: + doit = 0; +join: + if (doit != 0) { + D_80185920[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 0); + ((void (*)(s32))func_80159B70)(arg0); + func_80154150(arg0, 9); + ((void (*)(s32, s32 *))func_80146DB8)(arg0, &D_801858B4); + ((void (*)(s32, s32))func_80161CD0)(arg0, *(u16 *)(arg0 + 0x16E)); + return; + } + if (func_80161208(arg0) == 0) { + ((void (*)(s32))func_801725A4)(arg0); + } +} DEFINE_func_8015BD8C() /* dedup: shared engine-core @0x8015BD8C (src/shared) */ diff --git a/src/ov_SC04_002/ov_SC04_002_jr_8015AE2C.c b/src/ov_SC04_002/ov_SC04_002_jr_8015AE2C.c index dc88e0298..6a35c78b7 100644 --- a/src/ov_SC04_002/ov_SC04_002_jr_8015AE2C.c +++ b/src/ov_SC04_002/ov_SC04_002_jr_8015AE2C.c @@ -1512,7 +1512,259 @@ DEFINE_func_8015B858() /* dedup: shared engine-core @0x8015B858 (src/shared) */ DEFINE_func_8015B8F8() /* dedup: shared engine-core @0x8015B8F8 (src/shared) */ -INCLUDE_ASM("asm/ov_SC04_002/nonmatchings/ov_SC04_002_jr_8015AE2C", func_8015B950); +extern s32 func_8015AE2C(); + +// @class: plumbing +// @stuck: none — MATCH (271/271, pin-free, zero asm). The ONLY residual is DEF-SIDE plumbing, and it is now named exactly: the in-TU instantiation `DEFINE_func_8015BEE4()` (engine_core.h:1851-1855) expands to `extern s32 func_8015B950(void);` INSIDE ov_SC01_077_jr_8015AE2C.c, ~14 lines BELOW this definition, so the 1-param def collides with a `(void)` prototype -> `conflicting types for func_8015B950` (.run/bank_func_8015B950.log). §73 PARAMS axis / T0. Surgical fix = §65b de-macroize that ONE instantiation (blast radius: this TU); the fleet-wide `(void)`->`()` header edit is §63 and must be R22-validated. +/* func_8015B950 (ov_SC01_077_jr_8015AE2C, 271 ins, jtbl_801D8B74) — SESSION-21 re-verified + * + * ── ROUND-2 INDEPENDENT RE-VERIFICATION (2026-07-27, fresh agent, §88e discipline) ───────────── + * match_one : MATCH (271 ins) against the CURRENT tree — §87 staleness re-checked today. + * .text size: compiled .text = 0x43C = 1084 B = 271 ins, EXACTLY the target's declared 0x43C + * ("nonmatching func_8015B950, 0x43C"). So this is NOT a §83a length drift hiding + * behind a zero count — the count is over equal-length streams. + * jtbl : RE-DECODED MECHANICALLY, not inherited. Compiled .rodata = 0x1C = 28 B = 7 words, + * 7x R_MIPS_32 -> .text with implicit addends [58,58,58,E0,F0,100,58]; +0x8015B950 + * = [8015B9A8, 8015B9A8, 8015B9A8, 8015BA30, 8015BA40, 8015BA50, 8015B9A8]. + * Diffed word-for-word against asm/ov_SC01_077/data/tail14.data.s:15-23 — 7/7 identical. + * symcheck : SYMS-DIFF target=35 draft=34, sole MISSING = jtbl_801D8B74. This is the §81 jr + * FALSE POSITIVE, re-confirmed here by reading the relocs: gcc emits its OWN table and + * references it with R_MIPS_HI16/LO16 against the SECTION `.rodata` (t.o +0x40/+0x48), + * so the splat's dlabel NAME can never appear in the draft object's relocation set. + * Nothing is dropped and nothing is invented: the draft's other 34 symbols are exactly + * the target's other 34. + * FAMILY : the x138 remap is clean and §84-safe. Every sibling is 271 ins with an IDENTICAL + * callee set; only THREE names vary per overlay — the two data labels and the jtbl: + * ov_SC01_077 D_8018AA20 / D_8018AA8C / jtbl_801D8B74 + * ov_SC03_099 D_80185A50 / D_80185ABC / jtbl_801BD898 + * ov_SC06_008 D_80187E44 / D_80187EB0 / jtbl_801A8734 + * The pair is always +0x6C apart, and NO literal in this draft encodes that distance + * (both labels are referenced by name), so there is no §84 derived-offset hazard. + * D_8011F9C4 is fleet-constant (main-EXE data) and must NOT be remapped. + * + * match_one: MATCH (271 ins) against the CURRENT tree (§87 staleness re-checked, 2026-07-27). + * PIN-FREE, zero asm, offset-pure (s32 arg0 + raw offsets) — x138 template-safe. + * Provenance: this is the Phase-26 crack (.run/phase26-cracks/func_8015B950.c) re-gated verbatim, + * with ONE deliberate change: the definition's return type void -> s32. + * - `void func_8015B950(s32 arg0)` : MATCH (271 ins) [the Phase-26 form] + * - `s32 func_8015B950(s32 arg0)` : MATCH (271 ins) [shipped — §3a-1 void->s32 is byte-neutral] + * The fleet/engine_core.h canonical decl is `extern s32 func_8015B950(void);` (engine_core.h:1852), + * and the last bank attempt (.run/bank_func_8015B950.log) died on `conflicting types for + * func_8015B950`. Shipping the s32 return kills the §73 RETURN axis for free and leaves only the + * cheap T0 PARAMS axis for the ladder (fix_header_decl.py / --fix-def-sig / cast_call_sites). + * Both forms are byte-identical, so the orchestrator may swap the return type back at zero cost. + * + * SYMBOLS (§58 rules 1/2 — all splat spellings, all verified present): + * D_8018AA8C asm/ov_SC01_077/data/tail.data.s:4355 (the state-handler vtable) + * D_8018AA20 asm/ov_SC01_077/data/tail.data.s:4293 + * D_8011F9C4 main-EXE data; spelled `extern s32 D_8011F9C4;` in 5+ already-banked TUs + * jtbl_801D8B74 asm/ov_SC01_077/data/tail14.data.s:15 (compiler jump table — not named in C) + * + * JTBL VERIFIED (§8a gate): compiled .rodata = exactly 0x1C B / 7 words, 7x R_MIPS_32 .text with + * addends [0x58,0x58,0x58,0xE0,0xF0,0x100,0x58] -> +0x8015B950 = [B9A8,B9A8,B9A8,BA30,BA40,BA50, + * B9A8] == the original words at 0x801D8B74..0x801D8B8C. Bound `sltiu $v0,$v1,0x7` matches. + * The raw dlabel's 8th word 0x00000000 is NOT an entry — it is the intra-TU `.align 3` pad of the + * B34/B54/B74 jtbl chain; the object can never emit it (maspsx drops .align), so it must stay in + * the post-carve RAW data piece (the §53/§62/§81 carve chain applies at bank time). + * + * Same family as the TU's own already-matched func_8015AE2C: 7-case switch on ((s32 (*)(s32))func_801619A4)() + * (0/1/2/6 shared, 3/4/5 own, no default block — out-of-range and every `break` fall to the + * after-switch join), then a chain of "state handler" tests, each dispatching + * D_8018AA8C[*(u16*)arg0](arg0) and returning. + * + * THREE LEVERS (draft -> MATCH in 3 compiles): + * + * 1. PROLOGUE CONSTANT = an INITIALIZED LOCAL, not a literal in the compare. + * Target opens with `lui $s2, 0xFFF5` in the *prologue*, used once ~200 ins later in + * `slt $v0,$s2,$s1`. No gcc-2.7.2 pass hoists a (set reg const_int) across basic blocks + * (loop.c needs a loop; cse/combine/sched never move insns between BBs) — so the insn must + * have been EMITTED in the first BB, i.e. the constant is a local initialized at the top of + * the function. cse then cannot fold it back into the compare: the `slt` operand predicate is + * `arith_operand`, which rejects a CONST_INT wider than 16 bits, so validate_change fails and + * the pseudo survives. Its live range spans every call -> global.c gives it a callee-saved reg. + * Writing `z > -0xB0000` inline instead emits the `lui` into the branch delay slot next to the + * compare (caller-saved $v0) and the function is 1 insn short. => `s32 lim = -0xB0000;` at top. + * + * 2. `lh` vs `lhu`: a short->short copy is a pure HImode move and gcc emits `lhu`. The target's + * `lh $v0,0x26($s0)` means the value passed through an SImode (int) temp: expand makes + * (set (reg:SI) (sign_extend (mem:HI))) + (set (mem:HI) (subreg:HI ...)), and combine cannot + * merge them (the merged form is mem<-mem, which no movhi accepts) so the sign-extending load + * survives. => route both halfword copies through the `s32 t` temp. + * + * 3. THE `goto` LAYOUT — dodging jump.c's store-flag conversion (jump.c:1005-1065). + * An if/else chain writing 0/1 into `doit` makes gcc collapse the last pair into + * `sltiu $v0,$v0,1`. jump.c fires that conversion when the insn immediately after a + * conditional jump is a lone `SET pseudo, CONST_INT` whose following simplejump targets the + * SAME label as the branch (jump.c:1038 `reallabelprev == temp || ... JUMP_LABEL(temp4) == + * JUMP_LABEL(insn)`) — exactly the shape of `if (c) x=0; else x=1;`. + * The target instead cross-jumps ALL the `doit=0` exits into ONE shared block placed after the + * `doit=1` fall-through; reorg's fill_slots_from_thread then COPIES that single set into all + * three branch delay slots and redirects each branch past it (which is why `addu $v0,$zero, + * $zero` appears 3x in delay slots and the shared block vanishes). A `goto zero;` / `goto one;` + * chain expresses that layout directly, and each conditional jump is then followed by a + * compare/call rather than a lone const set, so the store-flag conversion never triggers. + * GENERAL RULE: multiple predicates that all assign the SAME constant to one flag => write + * them as `goto` to a shared assignment, never as an if/else ladder. + */ +extern s32 D_8011F9C4; +extern s32 D_8018AA20; + +extern s32 func_80161B18(void); +extern s32 func_801619A4(s32*); +extern s32 func_80149AA8(s32*); +extern void func_80149AD4(s32*); +extern s32 func_80149B54(s32*); +extern void func_80149BAC(s32*); +extern s32 func_801498E0(s32*); +extern s32 func_80149954(s32); +extern s32 func_80149A64(s32*); +extern void func_800CCCC0(s32 a0); +extern s32 func_80149CD4(s32 a0); +extern void func_8015E880(s32*); +extern s32 func_80149744(struct S_80149744*); +extern void func_80149788(void); +extern s32 func_801496D4(void*); +extern void func_80149704(void); +extern int func_80148AFC(void*); +extern void func_80146D90(s32 a0); +extern void func_80154150(s32 a0, s32 a1); +extern void func_801541D8(u8*, s32, s32); +extern s32 func_801488A8(u8*); +extern void func_80147078(s32*, s16); +extern void func_8015A264(void*); +extern s32 func_80013294(void*, void*); +extern void func_80159B70(void*); +extern s32 func_8016F1AC(void); +extern s32 func_80029178(s32 a0); +extern void func_80146DB8(s32*, s32*); +extern s32 func_80161CD0(s32, s32); +extern s32 func_80161208(s32 a0); +extern s32 func_801725A4(u8*); + +s32 func_8015B950(s32 arg0) +{ + + extern void (*D_8018AA8C[])(void *); + s16 sp10[4]; + s16 sp18[4]; + s32 t; + s32 z; + s32 doit; + s32 lim = -0xB0000; + + if (func_80161B18() != 0) { + return; + } + switch (((s32 (*)(s32))func_801619A4)(arg0)) { + case 0: + case 1: + case 2: + case 6: + if (((s32 (*)(s32))func_80149AA8)(arg0) != 0) { + D_8018AA8C[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149AD4)(arg0); + return; + } + if (((s32 (*)(s32))func_80149B54)(arg0) != 0) { + D_8018AA8C[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149BAC)(arg0); + return; + } + break; + case 3: + ((void (*)(s32))func_801498E0)(arg0); + break; + case 4: + ((void (*)(s32))func_80149954)(arg0); + break; + case 5: + if (((s32 (*)(s32))func_80149A64)(arg0) != 0) { + D_8018AA8C[*(u16 *)arg0]((void *)arg0); + func_800CCCC0(arg0); + return; + } + break; + } + if (func_80149CD4(arg0) != 0) { + D_8018AA8C[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_8015E880)(arg0); + return; + } + if (((s32 (*)(s32))func_80149744)(arg0) != 0) { + D_8018AA8C[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149788)(arg0); + return; + } + if (((s32 (*)(s32))func_801496D4)(arg0) != 0) { + D_8018AA8C[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149704)(arg0); + if (((u8)((s32 (*)(s32))func_80148AFC)(arg0)) == 0) { + func_80146D90(arg0); + } + if ((*(s32 *)(arg0 + 0x24) | *(s32 *)(arg0 + 0x2C)) != 0) { + func_80154150(arg0, 0xF); + } else { + ((void (*)(s32, s32, s32))func_801541D8)(arg0, 0xD, 6); + } + *(s32 *)(arg0 + 0x238) = 1; + return; + } + if (((s32 (*)(s32))func_801488A8)(arg0) != 0) { + sp10[0] = 0; + sp10[1] = 0; + sp10[2] = 0; + t = *(s16 *)(arg0 + 0x26); + sp18[0] = t; + sp18[1] = 0; + t = *(s16 *)(arg0 + 0x2E); + sp18[2] = t; + D_8018AA8C[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 1); + ((void (*)(s32))func_8015A264)(arg0); + t = -(((s32 (*)(s16 *, s16 *))func_80013294)(sp10, sp18) << 0x10); + if (t < *(s32 *)(arg0 + 0x2C)) { + *(s32 *)(arg0 + 0x2C) = t; + } + return; + } + if (*(u16 *)(arg0 + 0xB8) == 0x8000) { + D_8018AA8C[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 0); + ((void (*)(s32))func_80159B70)(arg0); + return; + } + z = *(s32 *)(arg0 + 0x2C); + if (func_8016F1AC() != 0) { + goto zero; + } + if (z <= lim) { + goto one; + } + if (D_8011F9C4 == 0) { + goto zero; + } + if (((u8)func_80029178(0x21)) != 0) { + goto zero; + } +one: + doit = 1; + goto join; +zero: + doit = 0; +join: + if (doit != 0) { + D_8018AA8C[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 0); + ((void (*)(s32))func_80159B70)(arg0); + func_80154150(arg0, 9); + ((void (*)(s32, s32 *))func_80146DB8)(arg0, &D_8018AA20); + ((void (*)(s32, s32))func_80161CD0)(arg0, *(u16 *)(arg0 + 0x16E)); + return; + } + if (func_80161208(arg0) == 0) { + ((void (*)(s32))func_801725A4)(arg0); + } +} DEFINE_func_8015BD8C() /* dedup: shared engine-core @0x8015BD8C (src/shared) */ diff --git a/src/ov_SC04_003/ov_SC04_003_jr_8015AE2C.c b/src/ov_SC04_003/ov_SC04_003_jr_8015AE2C.c index 7342a0def..0b2df33ff 100644 --- a/src/ov_SC04_003/ov_SC04_003_jr_8015AE2C.c +++ b/src/ov_SC04_003/ov_SC04_003_jr_8015AE2C.c @@ -1512,7 +1512,259 @@ DEFINE_func_8015B858() /* dedup: shared engine-core @0x8015B858 (src/shared) */ DEFINE_func_8015B8F8() /* dedup: shared engine-core @0x8015B8F8 (src/shared) */ -INCLUDE_ASM("asm/ov_SC04_003/nonmatchings/ov_SC04_003_jr_8015AE2C", func_8015B950); +extern s32 func_8015AE2C(); + +// @class: plumbing +// @stuck: none — MATCH (271/271, pin-free, zero asm). The ONLY residual is DEF-SIDE plumbing, and it is now named exactly: the in-TU instantiation `DEFINE_func_8015BEE4()` (engine_core.h:1851-1855) expands to `extern s32 func_8015B950(void);` INSIDE ov_SC01_077_jr_8015AE2C.c, ~14 lines BELOW this definition, so the 1-param def collides with a `(void)` prototype -> `conflicting types for func_8015B950` (.run/bank_func_8015B950.log). §73 PARAMS axis / T0. Surgical fix = §65b de-macroize that ONE instantiation (blast radius: this TU); the fleet-wide `(void)`->`()` header edit is §63 and must be R22-validated. +/* func_8015B950 (ov_SC01_077_jr_8015AE2C, 271 ins, jtbl_801D8B74) — SESSION-21 re-verified + * + * ── ROUND-2 INDEPENDENT RE-VERIFICATION (2026-07-27, fresh agent, §88e discipline) ───────────── + * match_one : MATCH (271 ins) against the CURRENT tree — §87 staleness re-checked today. + * .text size: compiled .text = 0x43C = 1084 B = 271 ins, EXACTLY the target's declared 0x43C + * ("nonmatching func_8015B950, 0x43C"). So this is NOT a §83a length drift hiding + * behind a zero count — the count is over equal-length streams. + * jtbl : RE-DECODED MECHANICALLY, not inherited. Compiled .rodata = 0x1C = 28 B = 7 words, + * 7x R_MIPS_32 -> .text with implicit addends [58,58,58,E0,F0,100,58]; +0x8015B950 + * = [8015B9A8, 8015B9A8, 8015B9A8, 8015BA30, 8015BA40, 8015BA50, 8015B9A8]. + * Diffed word-for-word against asm/ov_SC01_077/data/tail14.data.s:15-23 — 7/7 identical. + * symcheck : SYMS-DIFF target=35 draft=34, sole MISSING = jtbl_801D8B74. This is the §81 jr + * FALSE POSITIVE, re-confirmed here by reading the relocs: gcc emits its OWN table and + * references it with R_MIPS_HI16/LO16 against the SECTION `.rodata` (t.o +0x40/+0x48), + * so the splat's dlabel NAME can never appear in the draft object's relocation set. + * Nothing is dropped and nothing is invented: the draft's other 34 symbols are exactly + * the target's other 34. + * FAMILY : the x138 remap is clean and §84-safe. Every sibling is 271 ins with an IDENTICAL + * callee set; only THREE names vary per overlay — the two data labels and the jtbl: + * ov_SC01_077 D_801847BC / D_80184828 / jtbl_801D8B74 + * ov_SC03_099 D_80185A50 / D_80185ABC / jtbl_801BD898 + * ov_SC06_008 D_80187E44 / D_80187EB0 / jtbl_801A8734 + * The pair is always +0x6C apart, and NO literal in this draft encodes that distance + * (both labels are referenced by name), so there is no §84 derived-offset hazard. + * D_8011F9C4 is fleet-constant (main-EXE data) and must NOT be remapped. + * + * match_one: MATCH (271 ins) against the CURRENT tree (§87 staleness re-checked, 2026-07-27). + * PIN-FREE, zero asm, offset-pure (s32 arg0 + raw offsets) — x138 template-safe. + * Provenance: this is the Phase-26 crack (.run/phase26-cracks/func_8015B950.c) re-gated verbatim, + * with ONE deliberate change: the definition's return type void -> s32. + * - `void func_8015B950(s32 arg0)` : MATCH (271 ins) [the Phase-26 form] + * - `s32 func_8015B950(s32 arg0)` : MATCH (271 ins) [shipped — §3a-1 void->s32 is byte-neutral] + * The fleet/engine_core.h canonical decl is `extern s32 func_8015B950(void);` (engine_core.h:1852), + * and the last bank attempt (.run/bank_func_8015B950.log) died on `conflicting types for + * func_8015B950`. Shipping the s32 return kills the §73 RETURN axis for free and leaves only the + * cheap T0 PARAMS axis for the ladder (fix_header_decl.py / --fix-def-sig / cast_call_sites). + * Both forms are byte-identical, so the orchestrator may swap the return type back at zero cost. + * + * SYMBOLS (§58 rules 1/2 — all splat spellings, all verified present): + * D_80184828 asm/ov_SC01_077/data/tail.data.s:4355 (the state-handler vtable) + * D_801847BC asm/ov_SC01_077/data/tail.data.s:4293 + * D_8011F9C4 main-EXE data; spelled `extern s32 D_8011F9C4;` in 5+ already-banked TUs + * jtbl_801D8B74 asm/ov_SC01_077/data/tail14.data.s:15 (compiler jump table — not named in C) + * + * JTBL VERIFIED (§8a gate): compiled .rodata = exactly 0x1C B / 7 words, 7x R_MIPS_32 .text with + * addends [0x58,0x58,0x58,0xE0,0xF0,0x100,0x58] -> +0x8015B950 = [B9A8,B9A8,B9A8,BA30,BA40,BA50, + * B9A8] == the original words at 0x801D8B74..0x801D8B8C. Bound `sltiu $v0,$v1,0x7` matches. + * The raw dlabel's 8th word 0x00000000 is NOT an entry — it is the intra-TU `.align 3` pad of the + * B34/B54/B74 jtbl chain; the object can never emit it (maspsx drops .align), so it must stay in + * the post-carve RAW data piece (the §53/§62/§81 carve chain applies at bank time). + * + * Same family as the TU's own already-matched func_8015AE2C: 7-case switch on ((s32 (*)(s32))func_801619A4)() + * (0/1/2/6 shared, 3/4/5 own, no default block — out-of-range and every `break` fall to the + * after-switch join), then a chain of "state handler" tests, each dispatching + * D_80184828[*(u16*)arg0](arg0) and returning. + * + * THREE LEVERS (draft -> MATCH in 3 compiles): + * + * 1. PROLOGUE CONSTANT = an INITIALIZED LOCAL, not a literal in the compare. + * Target opens with `lui $s2, 0xFFF5` in the *prologue*, used once ~200 ins later in + * `slt $v0,$s2,$s1`. No gcc-2.7.2 pass hoists a (set reg const_int) across basic blocks + * (loop.c needs a loop; cse/combine/sched never move insns between BBs) — so the insn must + * have been EMITTED in the first BB, i.e. the constant is a local initialized at the top of + * the function. cse then cannot fold it back into the compare: the `slt` operand predicate is + * `arith_operand`, which rejects a CONST_INT wider than 16 bits, so validate_change fails and + * the pseudo survives. Its live range spans every call -> global.c gives it a callee-saved reg. + * Writing `z > -0xB0000` inline instead emits the `lui` into the branch delay slot next to the + * compare (caller-saved $v0) and the function is 1 insn short. => `s32 lim = -0xB0000;` at top. + * + * 2. `lh` vs `lhu`: a short->short copy is a pure HImode move and gcc emits `lhu`. The target's + * `lh $v0,0x26($s0)` means the value passed through an SImode (int) temp: expand makes + * (set (reg:SI) (sign_extend (mem:HI))) + (set (mem:HI) (subreg:HI ...)), and combine cannot + * merge them (the merged form is mem<-mem, which no movhi accepts) so the sign-extending load + * survives. => route both halfword copies through the `s32 t` temp. + * + * 3. THE `goto` LAYOUT — dodging jump.c's store-flag conversion (jump.c:1005-1065). + * An if/else chain writing 0/1 into `doit` makes gcc collapse the last pair into + * `sltiu $v0,$v0,1`. jump.c fires that conversion when the insn immediately after a + * conditional jump is a lone `SET pseudo, CONST_INT` whose following simplejump targets the + * SAME label as the branch (jump.c:1038 `reallabelprev == temp || ... JUMP_LABEL(temp4) == + * JUMP_LABEL(insn)`) — exactly the shape of `if (c) x=0; else x=1;`. + * The target instead cross-jumps ALL the `doit=0` exits into ONE shared block placed after the + * `doit=1` fall-through; reorg's fill_slots_from_thread then COPIES that single set into all + * three branch delay slots and redirects each branch past it (which is why `addu $v0,$zero, + * $zero` appears 3x in delay slots and the shared block vanishes). A `goto zero;` / `goto one;` + * chain expresses that layout directly, and each conditional jump is then followed by a + * compare/call rather than a lone const set, so the store-flag conversion never triggers. + * GENERAL RULE: multiple predicates that all assign the SAME constant to one flag => write + * them as `goto` to a shared assignment, never as an if/else ladder. + */ +extern s32 D_8011F9C4; +extern s32 D_801847BC; + +extern s32 func_80161B18(void); +extern s32 func_801619A4(s32*); +extern s32 func_80149AA8(s32*); +extern void func_80149AD4(s32*); +extern s32 func_80149B54(s32*); +extern void func_80149BAC(s32*); +extern s32 func_801498E0(s32*); +extern s32 func_80149954(s32); +extern s32 func_80149A64(s32*); +extern void func_800CCCC0(s32 a0); +extern s32 func_80149CD4(s32 a0); +extern void func_8015E880(s32*); +extern s32 func_80149744(struct S_80149744*); +extern void func_80149788(void); +extern s32 func_801496D4(void*); +extern void func_80149704(void); +extern int func_80148AFC(void*); +extern void func_80146D90(s32 a0); +extern void func_80154150(s32 a0, s32 a1); +extern void func_801541D8(u8*, s32, s32); +extern s32 func_801488A8(u8*); +extern void func_80147078(s32*, s16); +extern void func_8015A264(void*); +extern s32 func_80013294(void*, void*); +extern void func_80159B70(void*); +extern s32 func_8016F1AC(void); +extern s32 func_80029178(s32 a0); +extern void func_80146DB8(s32*, s32*); +extern s32 func_80161CD0(s32, s32); +extern s32 func_80161208(s32 a0); +extern s32 func_801725A4(u8*); + +s32 func_8015B950(s32 arg0) +{ + + extern void (*D_80184828[])(void *); + s16 sp10[4]; + s16 sp18[4]; + s32 t; + s32 z; + s32 doit; + s32 lim = -0xB0000; + + if (func_80161B18() != 0) { + return; + } + switch (((s32 (*)(s32))func_801619A4)(arg0)) { + case 0: + case 1: + case 2: + case 6: + if (((s32 (*)(s32))func_80149AA8)(arg0) != 0) { + D_80184828[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149AD4)(arg0); + return; + } + if (((s32 (*)(s32))func_80149B54)(arg0) != 0) { + D_80184828[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149BAC)(arg0); + return; + } + break; + case 3: + ((void (*)(s32))func_801498E0)(arg0); + break; + case 4: + ((void (*)(s32))func_80149954)(arg0); + break; + case 5: + if (((s32 (*)(s32))func_80149A64)(arg0) != 0) { + D_80184828[*(u16 *)arg0]((void *)arg0); + func_800CCCC0(arg0); + return; + } + break; + } + if (func_80149CD4(arg0) != 0) { + D_80184828[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_8015E880)(arg0); + return; + } + if (((s32 (*)(s32))func_80149744)(arg0) != 0) { + D_80184828[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149788)(arg0); + return; + } + if (((s32 (*)(s32))func_801496D4)(arg0) != 0) { + D_80184828[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149704)(arg0); + if (((u8)((s32 (*)(s32))func_80148AFC)(arg0)) == 0) { + func_80146D90(arg0); + } + if ((*(s32 *)(arg0 + 0x24) | *(s32 *)(arg0 + 0x2C)) != 0) { + func_80154150(arg0, 0xF); + } else { + ((void (*)(s32, s32, s32))func_801541D8)(arg0, 0xD, 6); + } + *(s32 *)(arg0 + 0x238) = 1; + return; + } + if (((s32 (*)(s32))func_801488A8)(arg0) != 0) { + sp10[0] = 0; + sp10[1] = 0; + sp10[2] = 0; + t = *(s16 *)(arg0 + 0x26); + sp18[0] = t; + sp18[1] = 0; + t = *(s16 *)(arg0 + 0x2E); + sp18[2] = t; + D_80184828[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 1); + ((void (*)(s32))func_8015A264)(arg0); + t = -(((s32 (*)(s16 *, s16 *))func_80013294)(sp10, sp18) << 0x10); + if (t < *(s32 *)(arg0 + 0x2C)) { + *(s32 *)(arg0 + 0x2C) = t; + } + return; + } + if (*(u16 *)(arg0 + 0xB8) == 0x8000) { + D_80184828[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 0); + ((void (*)(s32))func_80159B70)(arg0); + return; + } + z = *(s32 *)(arg0 + 0x2C); + if (func_8016F1AC() != 0) { + goto zero; + } + if (z <= lim) { + goto one; + } + if (D_8011F9C4 == 0) { + goto zero; + } + if (((u8)func_80029178(0x21)) != 0) { + goto zero; + } +one: + doit = 1; + goto join; +zero: + doit = 0; +join: + if (doit != 0) { + D_80184828[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 0); + ((void (*)(s32))func_80159B70)(arg0); + func_80154150(arg0, 9); + ((void (*)(s32, s32 *))func_80146DB8)(arg0, &D_801847BC); + ((void (*)(s32, s32))func_80161CD0)(arg0, *(u16 *)(arg0 + 0x16E)); + return; + } + if (func_80161208(arg0) == 0) { + ((void (*)(s32))func_801725A4)(arg0); + } +} DEFINE_func_8015BD8C() /* dedup: shared engine-core @0x8015BD8C (src/shared) */ diff --git a/src/ov_SC04_004/ov_SC04_004_jr_8015AE2C.c b/src/ov_SC04_004/ov_SC04_004_jr_8015AE2C.c index 1be2ed136..bb9d576eb 100644 --- a/src/ov_SC04_004/ov_SC04_004_jr_8015AE2C.c +++ b/src/ov_SC04_004/ov_SC04_004_jr_8015AE2C.c @@ -1512,7 +1512,259 @@ DEFINE_func_8015B858() /* dedup: shared engine-core @0x8015B858 (src/shared) */ DEFINE_func_8015B8F8() /* dedup: shared engine-core @0x8015B8F8 (src/shared) */ -INCLUDE_ASM("asm/ov_SC04_004/nonmatchings/ov_SC04_004_jr_8015AE2C", func_8015B950); +extern s32 func_8015AE2C(); + +// @class: plumbing +// @stuck: none — MATCH (271/271, pin-free, zero asm). The ONLY residual is DEF-SIDE plumbing, and it is now named exactly: the in-TU instantiation `DEFINE_func_8015BEE4()` (engine_core.h:1851-1855) expands to `extern s32 func_8015B950(void);` INSIDE ov_SC01_077_jr_8015AE2C.c, ~14 lines BELOW this definition, so the 1-param def collides with a `(void)` prototype -> `conflicting types for func_8015B950` (.run/bank_func_8015B950.log). §73 PARAMS axis / T0. Surgical fix = §65b de-macroize that ONE instantiation (blast radius: this TU); the fleet-wide `(void)`->`()` header edit is §63 and must be R22-validated. +/* func_8015B950 (ov_SC01_077_jr_8015AE2C, 271 ins, jtbl_801D8B74) — SESSION-21 re-verified + * + * ── ROUND-2 INDEPENDENT RE-VERIFICATION (2026-07-27, fresh agent, §88e discipline) ───────────── + * match_one : MATCH (271 ins) against the CURRENT tree — §87 staleness re-checked today. + * .text size: compiled .text = 0x43C = 1084 B = 271 ins, EXACTLY the target's declared 0x43C + * ("nonmatching func_8015B950, 0x43C"). So this is NOT a §83a length drift hiding + * behind a zero count — the count is over equal-length streams. + * jtbl : RE-DECODED MECHANICALLY, not inherited. Compiled .rodata = 0x1C = 28 B = 7 words, + * 7x R_MIPS_32 -> .text with implicit addends [58,58,58,E0,F0,100,58]; +0x8015B950 + * = [8015B9A8, 8015B9A8, 8015B9A8, 8015BA30, 8015BA40, 8015BA50, 8015B9A8]. + * Diffed word-for-word against asm/ov_SC01_077/data/tail14.data.s:15-23 — 7/7 identical. + * symcheck : SYMS-DIFF target=35 draft=34, sole MISSING = jtbl_801D8B74. This is the §81 jr + * FALSE POSITIVE, re-confirmed here by reading the relocs: gcc emits its OWN table and + * references it with R_MIPS_HI16/LO16 against the SECTION `.rodata` (t.o +0x40/+0x48), + * so the splat's dlabel NAME can never appear in the draft object's relocation set. + * Nothing is dropped and nothing is invented: the draft's other 34 symbols are exactly + * the target's other 34. + * FAMILY : the x138 remap is clean and §84-safe. Every sibling is 271 ins with an IDENTICAL + * callee set; only THREE names vary per overlay — the two data labels and the jtbl: + * ov_SC01_077 D_80186CF0 / D_80186D5C / jtbl_801D8B74 + * ov_SC03_099 D_80185A50 / D_80185ABC / jtbl_801BD898 + * ov_SC06_008 D_80187E44 / D_80187EB0 / jtbl_801A8734 + * The pair is always +0x6C apart, and NO literal in this draft encodes that distance + * (both labels are referenced by name), so there is no §84 derived-offset hazard. + * D_8011F9C4 is fleet-constant (main-EXE data) and must NOT be remapped. + * + * match_one: MATCH (271 ins) against the CURRENT tree (§87 staleness re-checked, 2026-07-27). + * PIN-FREE, zero asm, offset-pure (s32 arg0 + raw offsets) — x138 template-safe. + * Provenance: this is the Phase-26 crack (.run/phase26-cracks/func_8015B950.c) re-gated verbatim, + * with ONE deliberate change: the definition's return type void -> s32. + * - `void func_8015B950(s32 arg0)` : MATCH (271 ins) [the Phase-26 form] + * - `s32 func_8015B950(s32 arg0)` : MATCH (271 ins) [shipped — §3a-1 void->s32 is byte-neutral] + * The fleet/engine_core.h canonical decl is `extern s32 func_8015B950(void);` (engine_core.h:1852), + * and the last bank attempt (.run/bank_func_8015B950.log) died on `conflicting types for + * func_8015B950`. Shipping the s32 return kills the §73 RETURN axis for free and leaves only the + * cheap T0 PARAMS axis for the ladder (fix_header_decl.py / --fix-def-sig / cast_call_sites). + * Both forms are byte-identical, so the orchestrator may swap the return type back at zero cost. + * + * SYMBOLS (§58 rules 1/2 — all splat spellings, all verified present): + * D_80186D5C asm/ov_SC01_077/data/tail.data.s:4355 (the state-handler vtable) + * D_80186CF0 asm/ov_SC01_077/data/tail.data.s:4293 + * D_8011F9C4 main-EXE data; spelled `extern s32 D_8011F9C4;` in 5+ already-banked TUs + * jtbl_801D8B74 asm/ov_SC01_077/data/tail14.data.s:15 (compiler jump table — not named in C) + * + * JTBL VERIFIED (§8a gate): compiled .rodata = exactly 0x1C B / 7 words, 7x R_MIPS_32 .text with + * addends [0x58,0x58,0x58,0xE0,0xF0,0x100,0x58] -> +0x8015B950 = [B9A8,B9A8,B9A8,BA30,BA40,BA50, + * B9A8] == the original words at 0x801D8B74..0x801D8B8C. Bound `sltiu $v0,$v1,0x7` matches. + * The raw dlabel's 8th word 0x00000000 is NOT an entry — it is the intra-TU `.align 3` pad of the + * B34/B54/B74 jtbl chain; the object can never emit it (maspsx drops .align), so it must stay in + * the post-carve RAW data piece (the §53/§62/§81 carve chain applies at bank time). + * + * Same family as the TU's own already-matched func_8015AE2C: 7-case switch on ((s32 (*)(s32))func_801619A4)() + * (0/1/2/6 shared, 3/4/5 own, no default block — out-of-range and every `break` fall to the + * after-switch join), then a chain of "state handler" tests, each dispatching + * D_80186D5C[*(u16*)arg0](arg0) and returning. + * + * THREE LEVERS (draft -> MATCH in 3 compiles): + * + * 1. PROLOGUE CONSTANT = an INITIALIZED LOCAL, not a literal in the compare. + * Target opens with `lui $s2, 0xFFF5` in the *prologue*, used once ~200 ins later in + * `slt $v0,$s2,$s1`. No gcc-2.7.2 pass hoists a (set reg const_int) across basic blocks + * (loop.c needs a loop; cse/combine/sched never move insns between BBs) — so the insn must + * have been EMITTED in the first BB, i.e. the constant is a local initialized at the top of + * the function. cse then cannot fold it back into the compare: the `slt` operand predicate is + * `arith_operand`, which rejects a CONST_INT wider than 16 bits, so validate_change fails and + * the pseudo survives. Its live range spans every call -> global.c gives it a callee-saved reg. + * Writing `z > -0xB0000` inline instead emits the `lui` into the branch delay slot next to the + * compare (caller-saved $v0) and the function is 1 insn short. => `s32 lim = -0xB0000;` at top. + * + * 2. `lh` vs `lhu`: a short->short copy is a pure HImode move and gcc emits `lhu`. The target's + * `lh $v0,0x26($s0)` means the value passed through an SImode (int) temp: expand makes + * (set (reg:SI) (sign_extend (mem:HI))) + (set (mem:HI) (subreg:HI ...)), and combine cannot + * merge them (the merged form is mem<-mem, which no movhi accepts) so the sign-extending load + * survives. => route both halfword copies through the `s32 t` temp. + * + * 3. THE `goto` LAYOUT — dodging jump.c's store-flag conversion (jump.c:1005-1065). + * An if/else chain writing 0/1 into `doit` makes gcc collapse the last pair into + * `sltiu $v0,$v0,1`. jump.c fires that conversion when the insn immediately after a + * conditional jump is a lone `SET pseudo, CONST_INT` whose following simplejump targets the + * SAME label as the branch (jump.c:1038 `reallabelprev == temp || ... JUMP_LABEL(temp4) == + * JUMP_LABEL(insn)`) — exactly the shape of `if (c) x=0; else x=1;`. + * The target instead cross-jumps ALL the `doit=0` exits into ONE shared block placed after the + * `doit=1` fall-through; reorg's fill_slots_from_thread then COPIES that single set into all + * three branch delay slots and redirects each branch past it (which is why `addu $v0,$zero, + * $zero` appears 3x in delay slots and the shared block vanishes). A `goto zero;` / `goto one;` + * chain expresses that layout directly, and each conditional jump is then followed by a + * compare/call rather than a lone const set, so the store-flag conversion never triggers. + * GENERAL RULE: multiple predicates that all assign the SAME constant to one flag => write + * them as `goto` to a shared assignment, never as an if/else ladder. + */ +extern s32 D_8011F9C4; +extern s32 D_80186CF0; + +extern s32 func_80161B18(void); +extern s32 func_801619A4(s32*); +extern s32 func_80149AA8(s32*); +extern void func_80149AD4(s32*); +extern s32 func_80149B54(s32*); +extern void func_80149BAC(s32*); +extern s32 func_801498E0(s32*); +extern s32 func_80149954(s32); +extern s32 func_80149A64(s32*); +extern void func_800CCCC0(s32 a0); +extern s32 func_80149CD4(s32 a0); +extern void func_8015E880(s32*); +extern s32 func_80149744(struct S_80149744*); +extern void func_80149788(void); +extern s32 func_801496D4(void*); +extern void func_80149704(void); +extern int func_80148AFC(void*); +extern void func_80146D90(s32 a0); +extern void func_80154150(s32 a0, s32 a1); +extern void func_801541D8(u8*, s32, s32); +extern s32 func_801488A8(u8*); +extern void func_80147078(s32*, s16); +extern void func_8015A264(void*); +extern s32 func_80013294(void*, void*); +extern void func_80159B70(void*); +extern s32 func_8016F1AC(void); +extern s32 func_80029178(s32 a0); +extern void func_80146DB8(s32*, s32*); +extern s32 func_80161CD0(s32, s32); +extern s32 func_80161208(s32 a0); +extern s32 func_801725A4(u8*); + +s32 func_8015B950(s32 arg0) +{ + + extern void (*D_80186D5C[])(void *); + s16 sp10[4]; + s16 sp18[4]; + s32 t; + s32 z; + s32 doit; + s32 lim = -0xB0000; + + if (func_80161B18() != 0) { + return; + } + switch (((s32 (*)(s32))func_801619A4)(arg0)) { + case 0: + case 1: + case 2: + case 6: + if (((s32 (*)(s32))func_80149AA8)(arg0) != 0) { + D_80186D5C[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149AD4)(arg0); + return; + } + if (((s32 (*)(s32))func_80149B54)(arg0) != 0) { + D_80186D5C[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149BAC)(arg0); + return; + } + break; + case 3: + ((void (*)(s32))func_801498E0)(arg0); + break; + case 4: + ((void (*)(s32))func_80149954)(arg0); + break; + case 5: + if (((s32 (*)(s32))func_80149A64)(arg0) != 0) { + D_80186D5C[*(u16 *)arg0]((void *)arg0); + func_800CCCC0(arg0); + return; + } + break; + } + if (func_80149CD4(arg0) != 0) { + D_80186D5C[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_8015E880)(arg0); + return; + } + if (((s32 (*)(s32))func_80149744)(arg0) != 0) { + D_80186D5C[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149788)(arg0); + return; + } + if (((s32 (*)(s32))func_801496D4)(arg0) != 0) { + D_80186D5C[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149704)(arg0); + if (((u8)((s32 (*)(s32))func_80148AFC)(arg0)) == 0) { + func_80146D90(arg0); + } + if ((*(s32 *)(arg0 + 0x24) | *(s32 *)(arg0 + 0x2C)) != 0) { + func_80154150(arg0, 0xF); + } else { + ((void (*)(s32, s32, s32))func_801541D8)(arg0, 0xD, 6); + } + *(s32 *)(arg0 + 0x238) = 1; + return; + } + if (((s32 (*)(s32))func_801488A8)(arg0) != 0) { + sp10[0] = 0; + sp10[1] = 0; + sp10[2] = 0; + t = *(s16 *)(arg0 + 0x26); + sp18[0] = t; + sp18[1] = 0; + t = *(s16 *)(arg0 + 0x2E); + sp18[2] = t; + D_80186D5C[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 1); + ((void (*)(s32))func_8015A264)(arg0); + t = -(((s32 (*)(s16 *, s16 *))func_80013294)(sp10, sp18) << 0x10); + if (t < *(s32 *)(arg0 + 0x2C)) { + *(s32 *)(arg0 + 0x2C) = t; + } + return; + } + if (*(u16 *)(arg0 + 0xB8) == 0x8000) { + D_80186D5C[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 0); + ((void (*)(s32))func_80159B70)(arg0); + return; + } + z = *(s32 *)(arg0 + 0x2C); + if (func_8016F1AC() != 0) { + goto zero; + } + if (z <= lim) { + goto one; + } + if (D_8011F9C4 == 0) { + goto zero; + } + if (((u8)func_80029178(0x21)) != 0) { + goto zero; + } +one: + doit = 1; + goto join; +zero: + doit = 0; +join: + if (doit != 0) { + D_80186D5C[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 0); + ((void (*)(s32))func_80159B70)(arg0); + func_80154150(arg0, 9); + ((void (*)(s32, s32 *))func_80146DB8)(arg0, &D_80186CF0); + ((void (*)(s32, s32))func_80161CD0)(arg0, *(u16 *)(arg0 + 0x16E)); + return; + } + if (func_80161208(arg0) == 0) { + ((void (*)(s32))func_801725A4)(arg0); + } +} DEFINE_func_8015BD8C() /* dedup: shared engine-core @0x8015BD8C (src/shared) */ diff --git a/src/ov_SC04_005/ov_SC04_005_jr_8015AE2C.c b/src/ov_SC04_005/ov_SC04_005_jr_8015AE2C.c index 0f9c88afe..1c2097369 100644 --- a/src/ov_SC04_005/ov_SC04_005_jr_8015AE2C.c +++ b/src/ov_SC04_005/ov_SC04_005_jr_8015AE2C.c @@ -1512,7 +1512,259 @@ DEFINE_func_8015B858() /* dedup: shared engine-core @0x8015B858 (src/shared) */ DEFINE_func_8015B8F8() /* dedup: shared engine-core @0x8015B8F8 (src/shared) */ -INCLUDE_ASM("asm/ov_SC04_005/nonmatchings/ov_SC04_005_jr_8015AE2C", func_8015B950); +extern s32 func_8015AE2C(); + +// @class: plumbing +// @stuck: none — MATCH (271/271, pin-free, zero asm). The ONLY residual is DEF-SIDE plumbing, and it is now named exactly: the in-TU instantiation `DEFINE_func_8015BEE4()` (engine_core.h:1851-1855) expands to `extern s32 func_8015B950(void);` INSIDE ov_SC01_077_jr_8015AE2C.c, ~14 lines BELOW this definition, so the 1-param def collides with a `(void)` prototype -> `conflicting types for func_8015B950` (.run/bank_func_8015B950.log). §73 PARAMS axis / T0. Surgical fix = §65b de-macroize that ONE instantiation (blast radius: this TU); the fleet-wide `(void)`->`()` header edit is §63 and must be R22-validated. +/* func_8015B950 (ov_SC01_077_jr_8015AE2C, 271 ins, jtbl_801D8B74) — SESSION-21 re-verified + * + * ── ROUND-2 INDEPENDENT RE-VERIFICATION (2026-07-27, fresh agent, §88e discipline) ───────────── + * match_one : MATCH (271 ins) against the CURRENT tree — §87 staleness re-checked today. + * .text size: compiled .text = 0x43C = 1084 B = 271 ins, EXACTLY the target's declared 0x43C + * ("nonmatching func_8015B950, 0x43C"). So this is NOT a §83a length drift hiding + * behind a zero count — the count is over equal-length streams. + * jtbl : RE-DECODED MECHANICALLY, not inherited. Compiled .rodata = 0x1C = 28 B = 7 words, + * 7x R_MIPS_32 -> .text with implicit addends [58,58,58,E0,F0,100,58]; +0x8015B950 + * = [8015B9A8, 8015B9A8, 8015B9A8, 8015BA30, 8015BA40, 8015BA50, 8015B9A8]. + * Diffed word-for-word against asm/ov_SC01_077/data/tail14.data.s:15-23 — 7/7 identical. + * symcheck : SYMS-DIFF target=35 draft=34, sole MISSING = jtbl_801D8B74. This is the §81 jr + * FALSE POSITIVE, re-confirmed here by reading the relocs: gcc emits its OWN table and + * references it with R_MIPS_HI16/LO16 against the SECTION `.rodata` (t.o +0x40/+0x48), + * so the splat's dlabel NAME can never appear in the draft object's relocation set. + * Nothing is dropped and nothing is invented: the draft's other 34 symbols are exactly + * the target's other 34. + * FAMILY : the x138 remap is clean and §84-safe. Every sibling is 271 ins with an IDENTICAL + * callee set; only THREE names vary per overlay — the two data labels and the jtbl: + * ov_SC01_077 D_8018A124 / D_8018A190 / jtbl_801D8B74 + * ov_SC03_099 D_80185A50 / D_80185ABC / jtbl_801BD898 + * ov_SC06_008 D_80187E44 / D_80187EB0 / jtbl_801A8734 + * The pair is always +0x6C apart, and NO literal in this draft encodes that distance + * (both labels are referenced by name), so there is no §84 derived-offset hazard. + * D_8011F9C4 is fleet-constant (main-EXE data) and must NOT be remapped. + * + * match_one: MATCH (271 ins) against the CURRENT tree (§87 staleness re-checked, 2026-07-27). + * PIN-FREE, zero asm, offset-pure (s32 arg0 + raw offsets) — x138 template-safe. + * Provenance: this is the Phase-26 crack (.run/phase26-cracks/func_8015B950.c) re-gated verbatim, + * with ONE deliberate change: the definition's return type void -> s32. + * - `void func_8015B950(s32 arg0)` : MATCH (271 ins) [the Phase-26 form] + * - `s32 func_8015B950(s32 arg0)` : MATCH (271 ins) [shipped — §3a-1 void->s32 is byte-neutral] + * The fleet/engine_core.h canonical decl is `extern s32 func_8015B950(void);` (engine_core.h:1852), + * and the last bank attempt (.run/bank_func_8015B950.log) died on `conflicting types for + * func_8015B950`. Shipping the s32 return kills the §73 RETURN axis for free and leaves only the + * cheap T0 PARAMS axis for the ladder (fix_header_decl.py / --fix-def-sig / cast_call_sites). + * Both forms are byte-identical, so the orchestrator may swap the return type back at zero cost. + * + * SYMBOLS (§58 rules 1/2 — all splat spellings, all verified present): + * D_8018A190 asm/ov_SC01_077/data/tail.data.s:4355 (the state-handler vtable) + * D_8018A124 asm/ov_SC01_077/data/tail.data.s:4293 + * D_8011F9C4 main-EXE data; spelled `extern s32 D_8011F9C4;` in 5+ already-banked TUs + * jtbl_801D8B74 asm/ov_SC01_077/data/tail14.data.s:15 (compiler jump table — not named in C) + * + * JTBL VERIFIED (§8a gate): compiled .rodata = exactly 0x1C B / 7 words, 7x R_MIPS_32 .text with + * addends [0x58,0x58,0x58,0xE0,0xF0,0x100,0x58] -> +0x8015B950 = [B9A8,B9A8,B9A8,BA30,BA40,BA50, + * B9A8] == the original words at 0x801D8B74..0x801D8B8C. Bound `sltiu $v0,$v1,0x7` matches. + * The raw dlabel's 8th word 0x00000000 is NOT an entry — it is the intra-TU `.align 3` pad of the + * B34/B54/B74 jtbl chain; the object can never emit it (maspsx drops .align), so it must stay in + * the post-carve RAW data piece (the §53/§62/§81 carve chain applies at bank time). + * + * Same family as the TU's own already-matched func_8015AE2C: 7-case switch on ((s32 (*)(s32))func_801619A4)() + * (0/1/2/6 shared, 3/4/5 own, no default block — out-of-range and every `break` fall to the + * after-switch join), then a chain of "state handler" tests, each dispatching + * D_8018A190[*(u16*)arg0](arg0) and returning. + * + * THREE LEVERS (draft -> MATCH in 3 compiles): + * + * 1. PROLOGUE CONSTANT = an INITIALIZED LOCAL, not a literal in the compare. + * Target opens with `lui $s2, 0xFFF5` in the *prologue*, used once ~200 ins later in + * `slt $v0,$s2,$s1`. No gcc-2.7.2 pass hoists a (set reg const_int) across basic blocks + * (loop.c needs a loop; cse/combine/sched never move insns between BBs) — so the insn must + * have been EMITTED in the first BB, i.e. the constant is a local initialized at the top of + * the function. cse then cannot fold it back into the compare: the `slt` operand predicate is + * `arith_operand`, which rejects a CONST_INT wider than 16 bits, so validate_change fails and + * the pseudo survives. Its live range spans every call -> global.c gives it a callee-saved reg. + * Writing `z > -0xB0000` inline instead emits the `lui` into the branch delay slot next to the + * compare (caller-saved $v0) and the function is 1 insn short. => `s32 lim = -0xB0000;` at top. + * + * 2. `lh` vs `lhu`: a short->short copy is a pure HImode move and gcc emits `lhu`. The target's + * `lh $v0,0x26($s0)` means the value passed through an SImode (int) temp: expand makes + * (set (reg:SI) (sign_extend (mem:HI))) + (set (mem:HI) (subreg:HI ...)), and combine cannot + * merge them (the merged form is mem<-mem, which no movhi accepts) so the sign-extending load + * survives. => route both halfword copies through the `s32 t` temp. + * + * 3. THE `goto` LAYOUT — dodging jump.c's store-flag conversion (jump.c:1005-1065). + * An if/else chain writing 0/1 into `doit` makes gcc collapse the last pair into + * `sltiu $v0,$v0,1`. jump.c fires that conversion when the insn immediately after a + * conditional jump is a lone `SET pseudo, CONST_INT` whose following simplejump targets the + * SAME label as the branch (jump.c:1038 `reallabelprev == temp || ... JUMP_LABEL(temp4) == + * JUMP_LABEL(insn)`) — exactly the shape of `if (c) x=0; else x=1;`. + * The target instead cross-jumps ALL the `doit=0` exits into ONE shared block placed after the + * `doit=1` fall-through; reorg's fill_slots_from_thread then COPIES that single set into all + * three branch delay slots and redirects each branch past it (which is why `addu $v0,$zero, + * $zero` appears 3x in delay slots and the shared block vanishes). A `goto zero;` / `goto one;` + * chain expresses that layout directly, and each conditional jump is then followed by a + * compare/call rather than a lone const set, so the store-flag conversion never triggers. + * GENERAL RULE: multiple predicates that all assign the SAME constant to one flag => write + * them as `goto` to a shared assignment, never as an if/else ladder. + */ +extern s32 D_8011F9C4; +extern s32 D_8018A124; + +extern s32 func_80161B18(void); +extern s32 func_801619A4(s32*); +extern s32 func_80149AA8(s32*); +extern void func_80149AD4(s32*); +extern s32 func_80149B54(s32*); +extern void func_80149BAC(s32*); +extern s32 func_801498E0(s32*); +extern s32 func_80149954(s32); +extern s32 func_80149A64(s32*); +extern void func_800CCCC0(s32 a0); +extern s32 func_80149CD4(s32 a0); +extern void func_8015E880(s32*); +extern s32 func_80149744(struct S_80149744*); +extern void func_80149788(void); +extern s32 func_801496D4(void*); +extern void func_80149704(void); +extern int func_80148AFC(void*); +extern void func_80146D90(s32 a0); +extern void func_80154150(s32 a0, s32 a1); +extern void func_801541D8(u8*, s32, s32); +extern s32 func_801488A8(u8*); +extern void func_80147078(s32*, s16); +extern void func_8015A264(void*); +extern s32 func_80013294(void*, void*); +extern void func_80159B70(void*); +extern s32 func_8016F1AC(void); +extern s32 func_80029178(s32 a0); +extern void func_80146DB8(s32*, s32*); +extern s32 func_80161CD0(s32, s32); +extern s32 func_80161208(s32 a0); +extern s32 func_801725A4(u8*); + +s32 func_8015B950(s32 arg0) +{ + + extern void (*D_8018A190[])(void *); + s16 sp10[4]; + s16 sp18[4]; + s32 t; + s32 z; + s32 doit; + s32 lim = -0xB0000; + + if (func_80161B18() != 0) { + return; + } + switch (((s32 (*)(s32))func_801619A4)(arg0)) { + case 0: + case 1: + case 2: + case 6: + if (((s32 (*)(s32))func_80149AA8)(arg0) != 0) { + D_8018A190[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149AD4)(arg0); + return; + } + if (((s32 (*)(s32))func_80149B54)(arg0) != 0) { + D_8018A190[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149BAC)(arg0); + return; + } + break; + case 3: + ((void (*)(s32))func_801498E0)(arg0); + break; + case 4: + ((void (*)(s32))func_80149954)(arg0); + break; + case 5: + if (((s32 (*)(s32))func_80149A64)(arg0) != 0) { + D_8018A190[*(u16 *)arg0]((void *)arg0); + func_800CCCC0(arg0); + return; + } + break; + } + if (func_80149CD4(arg0) != 0) { + D_8018A190[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_8015E880)(arg0); + return; + } + if (((s32 (*)(s32))func_80149744)(arg0) != 0) { + D_8018A190[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149788)(arg0); + return; + } + if (((s32 (*)(s32))func_801496D4)(arg0) != 0) { + D_8018A190[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149704)(arg0); + if (((u8)((s32 (*)(s32))func_80148AFC)(arg0)) == 0) { + func_80146D90(arg0); + } + if ((*(s32 *)(arg0 + 0x24) | *(s32 *)(arg0 + 0x2C)) != 0) { + func_80154150(arg0, 0xF); + } else { + ((void (*)(s32, s32, s32))func_801541D8)(arg0, 0xD, 6); + } + *(s32 *)(arg0 + 0x238) = 1; + return; + } + if (((s32 (*)(s32))func_801488A8)(arg0) != 0) { + sp10[0] = 0; + sp10[1] = 0; + sp10[2] = 0; + t = *(s16 *)(arg0 + 0x26); + sp18[0] = t; + sp18[1] = 0; + t = *(s16 *)(arg0 + 0x2E); + sp18[2] = t; + D_8018A190[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 1); + ((void (*)(s32))func_8015A264)(arg0); + t = -(((s32 (*)(s16 *, s16 *))func_80013294)(sp10, sp18) << 0x10); + if (t < *(s32 *)(arg0 + 0x2C)) { + *(s32 *)(arg0 + 0x2C) = t; + } + return; + } + if (*(u16 *)(arg0 + 0xB8) == 0x8000) { + D_8018A190[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 0); + ((void (*)(s32))func_80159B70)(arg0); + return; + } + z = *(s32 *)(arg0 + 0x2C); + if (func_8016F1AC() != 0) { + goto zero; + } + if (z <= lim) { + goto one; + } + if (D_8011F9C4 == 0) { + goto zero; + } + if (((u8)func_80029178(0x21)) != 0) { + goto zero; + } +one: + doit = 1; + goto join; +zero: + doit = 0; +join: + if (doit != 0) { + D_8018A190[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 0); + ((void (*)(s32))func_80159B70)(arg0); + func_80154150(arg0, 9); + ((void (*)(s32, s32 *))func_80146DB8)(arg0, &D_8018A124); + ((void (*)(s32, s32))func_80161CD0)(arg0, *(u16 *)(arg0 + 0x16E)); + return; + } + if (func_80161208(arg0) == 0) { + ((void (*)(s32))func_801725A4)(arg0); + } +} DEFINE_func_8015BD8C() /* dedup: shared engine-core @0x8015BD8C (src/shared) */ diff --git a/src/ov_SC04_006/ov_SC04_006_jr_8015AE2C.c b/src/ov_SC04_006/ov_SC04_006_jr_8015AE2C.c index 678bb120e..41c802df3 100644 --- a/src/ov_SC04_006/ov_SC04_006_jr_8015AE2C.c +++ b/src/ov_SC04_006/ov_SC04_006_jr_8015AE2C.c @@ -1512,7 +1512,259 @@ DEFINE_func_8015B858() /* dedup: shared engine-core @0x8015B858 (src/shared) */ DEFINE_func_8015B8F8() /* dedup: shared engine-core @0x8015B8F8 (src/shared) */ -INCLUDE_ASM("asm/ov_SC04_006/nonmatchings/ov_SC04_006_jr_8015AE2C", func_8015B950); +extern s32 func_8015AE2C(); + +// @class: plumbing +// @stuck: none — MATCH (271/271, pin-free, zero asm). The ONLY residual is DEF-SIDE plumbing, and it is now named exactly: the in-TU instantiation `DEFINE_func_8015BEE4()` (engine_core.h:1851-1855) expands to `extern s32 func_8015B950(void);` INSIDE ov_SC01_077_jr_8015AE2C.c, ~14 lines BELOW this definition, so the 1-param def collides with a `(void)` prototype -> `conflicting types for func_8015B950` (.run/bank_func_8015B950.log). §73 PARAMS axis / T0. Surgical fix = §65b de-macroize that ONE instantiation (blast radius: this TU); the fleet-wide `(void)`->`()` header edit is §63 and must be R22-validated. +/* func_8015B950 (ov_SC01_077_jr_8015AE2C, 271 ins, jtbl_801D8B74) — SESSION-21 re-verified + * + * ── ROUND-2 INDEPENDENT RE-VERIFICATION (2026-07-27, fresh agent, §88e discipline) ───────────── + * match_one : MATCH (271 ins) against the CURRENT tree — §87 staleness re-checked today. + * .text size: compiled .text = 0x43C = 1084 B = 271 ins, EXACTLY the target's declared 0x43C + * ("nonmatching func_8015B950, 0x43C"). So this is NOT a §83a length drift hiding + * behind a zero count — the count is over equal-length streams. + * jtbl : RE-DECODED MECHANICALLY, not inherited. Compiled .rodata = 0x1C = 28 B = 7 words, + * 7x R_MIPS_32 -> .text with implicit addends [58,58,58,E0,F0,100,58]; +0x8015B950 + * = [8015B9A8, 8015B9A8, 8015B9A8, 8015BA30, 8015BA40, 8015BA50, 8015B9A8]. + * Diffed word-for-word against asm/ov_SC01_077/data/tail14.data.s:15-23 — 7/7 identical. + * symcheck : SYMS-DIFF target=35 draft=34, sole MISSING = jtbl_801D8B74. This is the §81 jr + * FALSE POSITIVE, re-confirmed here by reading the relocs: gcc emits its OWN table and + * references it with R_MIPS_HI16/LO16 against the SECTION `.rodata` (t.o +0x40/+0x48), + * so the splat's dlabel NAME can never appear in the draft object's relocation set. + * Nothing is dropped and nothing is invented: the draft's other 34 symbols are exactly + * the target's other 34. + * FAMILY : the x138 remap is clean and §84-safe. Every sibling is 271 ins with an IDENTICAL + * callee set; only THREE names vary per overlay — the two data labels and the jtbl: + * ov_SC01_077 D_80182204 / D_80182270 / jtbl_801D8B74 + * ov_SC03_099 D_80185A50 / D_80185ABC / jtbl_801BD898 + * ov_SC06_008 D_80187E44 / D_80187EB0 / jtbl_801A8734 + * The pair is always +0x6C apart, and NO literal in this draft encodes that distance + * (both labels are referenced by name), so there is no §84 derived-offset hazard. + * D_8011F9C4 is fleet-constant (main-EXE data) and must NOT be remapped. + * + * match_one: MATCH (271 ins) against the CURRENT tree (§87 staleness re-checked, 2026-07-27). + * PIN-FREE, zero asm, offset-pure (s32 arg0 + raw offsets) — x138 template-safe. + * Provenance: this is the Phase-26 crack (.run/phase26-cracks/func_8015B950.c) re-gated verbatim, + * with ONE deliberate change: the definition's return type void -> s32. + * - `void func_8015B950(s32 arg0)` : MATCH (271 ins) [the Phase-26 form] + * - `s32 func_8015B950(s32 arg0)` : MATCH (271 ins) [shipped — §3a-1 void->s32 is byte-neutral] + * The fleet/engine_core.h canonical decl is `extern s32 func_8015B950(void);` (engine_core.h:1852), + * and the last bank attempt (.run/bank_func_8015B950.log) died on `conflicting types for + * func_8015B950`. Shipping the s32 return kills the §73 RETURN axis for free and leaves only the + * cheap T0 PARAMS axis for the ladder (fix_header_decl.py / --fix-def-sig / cast_call_sites). + * Both forms are byte-identical, so the orchestrator may swap the return type back at zero cost. + * + * SYMBOLS (§58 rules 1/2 — all splat spellings, all verified present): + * D_80182270 asm/ov_SC01_077/data/tail.data.s:4355 (the state-handler vtable) + * D_80182204 asm/ov_SC01_077/data/tail.data.s:4293 + * D_8011F9C4 main-EXE data; spelled `extern s32 D_8011F9C4;` in 5+ already-banked TUs + * jtbl_801D8B74 asm/ov_SC01_077/data/tail14.data.s:15 (compiler jump table — not named in C) + * + * JTBL VERIFIED (§8a gate): compiled .rodata = exactly 0x1C B / 7 words, 7x R_MIPS_32 .text with + * addends [0x58,0x58,0x58,0xE0,0xF0,0x100,0x58] -> +0x8015B950 = [B9A8,B9A8,B9A8,BA30,BA40,BA50, + * B9A8] == the original words at 0x801D8B74..0x801D8B8C. Bound `sltiu $v0,$v1,0x7` matches. + * The raw dlabel's 8th word 0x00000000 is NOT an entry — it is the intra-TU `.align 3` pad of the + * B34/B54/B74 jtbl chain; the object can never emit it (maspsx drops .align), so it must stay in + * the post-carve RAW data piece (the §53/§62/§81 carve chain applies at bank time). + * + * Same family as the TU's own already-matched func_8015AE2C: 7-case switch on ((s32 (*)(s32))func_801619A4)() + * (0/1/2/6 shared, 3/4/5 own, no default block — out-of-range and every `break` fall to the + * after-switch join), then a chain of "state handler" tests, each dispatching + * D_80182270[*(u16*)arg0](arg0) and returning. + * + * THREE LEVERS (draft -> MATCH in 3 compiles): + * + * 1. PROLOGUE CONSTANT = an INITIALIZED LOCAL, not a literal in the compare. + * Target opens with `lui $s2, 0xFFF5` in the *prologue*, used once ~200 ins later in + * `slt $v0,$s2,$s1`. No gcc-2.7.2 pass hoists a (set reg const_int) across basic blocks + * (loop.c needs a loop; cse/combine/sched never move insns between BBs) — so the insn must + * have been EMITTED in the first BB, i.e. the constant is a local initialized at the top of + * the function. cse then cannot fold it back into the compare: the `slt` operand predicate is + * `arith_operand`, which rejects a CONST_INT wider than 16 bits, so validate_change fails and + * the pseudo survives. Its live range spans every call -> global.c gives it a callee-saved reg. + * Writing `z > -0xB0000` inline instead emits the `lui` into the branch delay slot next to the + * compare (caller-saved $v0) and the function is 1 insn short. => `s32 lim = -0xB0000;` at top. + * + * 2. `lh` vs `lhu`: a short->short copy is a pure HImode move and gcc emits `lhu`. The target's + * `lh $v0,0x26($s0)` means the value passed through an SImode (int) temp: expand makes + * (set (reg:SI) (sign_extend (mem:HI))) + (set (mem:HI) (subreg:HI ...)), and combine cannot + * merge them (the merged form is mem<-mem, which no movhi accepts) so the sign-extending load + * survives. => route both halfword copies through the `s32 t` temp. + * + * 3. THE `goto` LAYOUT — dodging jump.c's store-flag conversion (jump.c:1005-1065). + * An if/else chain writing 0/1 into `doit` makes gcc collapse the last pair into + * `sltiu $v0,$v0,1`. jump.c fires that conversion when the insn immediately after a + * conditional jump is a lone `SET pseudo, CONST_INT` whose following simplejump targets the + * SAME label as the branch (jump.c:1038 `reallabelprev == temp || ... JUMP_LABEL(temp4) == + * JUMP_LABEL(insn)`) — exactly the shape of `if (c) x=0; else x=1;`. + * The target instead cross-jumps ALL the `doit=0` exits into ONE shared block placed after the + * `doit=1` fall-through; reorg's fill_slots_from_thread then COPIES that single set into all + * three branch delay slots and redirects each branch past it (which is why `addu $v0,$zero, + * $zero` appears 3x in delay slots and the shared block vanishes). A `goto zero;` / `goto one;` + * chain expresses that layout directly, and each conditional jump is then followed by a + * compare/call rather than a lone const set, so the store-flag conversion never triggers. + * GENERAL RULE: multiple predicates that all assign the SAME constant to one flag => write + * them as `goto` to a shared assignment, never as an if/else ladder. + */ +extern s32 D_8011F9C4; +extern s32 D_80182204; + +extern s32 func_80161B18(void); +extern s32 func_801619A4(s32*); +extern s32 func_80149AA8(s32*); +extern void func_80149AD4(s32*); +extern s32 func_80149B54(s32*); +extern void func_80149BAC(s32*); +extern s32 func_801498E0(s32*); +extern s32 func_80149954(s32); +extern s32 func_80149A64(s32*); +extern void func_800CCCC0(s32 a0); +extern s32 func_80149CD4(s32 a0); +extern void func_8015E880(s32*); +extern s32 func_80149744(struct S_80149744*); +extern void func_80149788(void); +extern s32 func_801496D4(void*); +extern void func_80149704(void); +extern int func_80148AFC(void*); +extern void func_80146D90(s32 a0); +extern void func_80154150(s32 a0, s32 a1); +extern void func_801541D8(u8*, s32, s32); +extern s32 func_801488A8(u8*); +extern void func_80147078(s32*, s16); +extern void func_8015A264(void*); +extern s32 func_80013294(void*, void*); +extern void func_80159B70(void*); +extern s32 func_8016F1AC(void); +extern s32 func_80029178(s32 a0); +extern void func_80146DB8(s32*, s32*); +extern s32 func_80161CD0(s32, s32); +extern s32 func_80161208(s32 a0); +extern s32 func_801725A4(u8*); + +s32 func_8015B950(s32 arg0) +{ + + extern void (*D_80182270[])(void *); + s16 sp10[4]; + s16 sp18[4]; + s32 t; + s32 z; + s32 doit; + s32 lim = -0xB0000; + + if (func_80161B18() != 0) { + return; + } + switch (((s32 (*)(s32))func_801619A4)(arg0)) { + case 0: + case 1: + case 2: + case 6: + if (((s32 (*)(s32))func_80149AA8)(arg0) != 0) { + D_80182270[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149AD4)(arg0); + return; + } + if (((s32 (*)(s32))func_80149B54)(arg0) != 0) { + D_80182270[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149BAC)(arg0); + return; + } + break; + case 3: + ((void (*)(s32))func_801498E0)(arg0); + break; + case 4: + ((void (*)(s32))func_80149954)(arg0); + break; + case 5: + if (((s32 (*)(s32))func_80149A64)(arg0) != 0) { + D_80182270[*(u16 *)arg0]((void *)arg0); + func_800CCCC0(arg0); + return; + } + break; + } + if (func_80149CD4(arg0) != 0) { + D_80182270[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_8015E880)(arg0); + return; + } + if (((s32 (*)(s32))func_80149744)(arg0) != 0) { + D_80182270[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149788)(arg0); + return; + } + if (((s32 (*)(s32))func_801496D4)(arg0) != 0) { + D_80182270[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149704)(arg0); + if (((u8)((s32 (*)(s32))func_80148AFC)(arg0)) == 0) { + func_80146D90(arg0); + } + if ((*(s32 *)(arg0 + 0x24) | *(s32 *)(arg0 + 0x2C)) != 0) { + func_80154150(arg0, 0xF); + } else { + ((void (*)(s32, s32, s32))func_801541D8)(arg0, 0xD, 6); + } + *(s32 *)(arg0 + 0x238) = 1; + return; + } + if (((s32 (*)(s32))func_801488A8)(arg0) != 0) { + sp10[0] = 0; + sp10[1] = 0; + sp10[2] = 0; + t = *(s16 *)(arg0 + 0x26); + sp18[0] = t; + sp18[1] = 0; + t = *(s16 *)(arg0 + 0x2E); + sp18[2] = t; + D_80182270[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 1); + ((void (*)(s32))func_8015A264)(arg0); + t = -(((s32 (*)(s16 *, s16 *))func_80013294)(sp10, sp18) << 0x10); + if (t < *(s32 *)(arg0 + 0x2C)) { + *(s32 *)(arg0 + 0x2C) = t; + } + return; + } + if (*(u16 *)(arg0 + 0xB8) == 0x8000) { + D_80182270[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 0); + ((void (*)(s32))func_80159B70)(arg0); + return; + } + z = *(s32 *)(arg0 + 0x2C); + if (func_8016F1AC() != 0) { + goto zero; + } + if (z <= lim) { + goto one; + } + if (D_8011F9C4 == 0) { + goto zero; + } + if (((u8)func_80029178(0x21)) != 0) { + goto zero; + } +one: + doit = 1; + goto join; +zero: + doit = 0; +join: + if (doit != 0) { + D_80182270[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 0); + ((void (*)(s32))func_80159B70)(arg0); + func_80154150(arg0, 9); + ((void (*)(s32, s32 *))func_80146DB8)(arg0, &D_80182204); + ((void (*)(s32, s32))func_80161CD0)(arg0, *(u16 *)(arg0 + 0x16E)); + return; + } + if (func_80161208(arg0) == 0) { + ((void (*)(s32))func_801725A4)(arg0); + } +} DEFINE_func_8015BD8C() /* dedup: shared engine-core @0x8015BD8C (src/shared) */ diff --git a/src/ov_SC04_007/ov_SC04_007_jr_8015AE2C.c b/src/ov_SC04_007/ov_SC04_007_jr_8015AE2C.c index 4f0830648..74367c2e0 100644 --- a/src/ov_SC04_007/ov_SC04_007_jr_8015AE2C.c +++ b/src/ov_SC04_007/ov_SC04_007_jr_8015AE2C.c @@ -1512,7 +1512,259 @@ DEFINE_func_8015B858() /* dedup: shared engine-core @0x8015B858 (src/shared) */ DEFINE_func_8015B8F8() /* dedup: shared engine-core @0x8015B8F8 (src/shared) */ -INCLUDE_ASM("asm/ov_SC04_007/nonmatchings/ov_SC04_007_jr_8015AE2C", func_8015B950); +extern s32 func_8015AE2C(); + +// @class: plumbing +// @stuck: none — MATCH (271/271, pin-free, zero asm). The ONLY residual is DEF-SIDE plumbing, and it is now named exactly: the in-TU instantiation `DEFINE_func_8015BEE4()` (engine_core.h:1851-1855) expands to `extern s32 func_8015B950(void);` INSIDE ov_SC01_077_jr_8015AE2C.c, ~14 lines BELOW this definition, so the 1-param def collides with a `(void)` prototype -> `conflicting types for func_8015B950` (.run/bank_func_8015B950.log). §73 PARAMS axis / T0. Surgical fix = §65b de-macroize that ONE instantiation (blast radius: this TU); the fleet-wide `(void)`->`()` header edit is §63 and must be R22-validated. +/* func_8015B950 (ov_SC01_077_jr_8015AE2C, 271 ins, jtbl_801D8B74) — SESSION-21 re-verified + * + * ── ROUND-2 INDEPENDENT RE-VERIFICATION (2026-07-27, fresh agent, §88e discipline) ───────────── + * match_one : MATCH (271 ins) against the CURRENT tree — §87 staleness re-checked today. + * .text size: compiled .text = 0x43C = 1084 B = 271 ins, EXACTLY the target's declared 0x43C + * ("nonmatching func_8015B950, 0x43C"). So this is NOT a §83a length drift hiding + * behind a zero count — the count is over equal-length streams. + * jtbl : RE-DECODED MECHANICALLY, not inherited. Compiled .rodata = 0x1C = 28 B = 7 words, + * 7x R_MIPS_32 -> .text with implicit addends [58,58,58,E0,F0,100,58]; +0x8015B950 + * = [8015B9A8, 8015B9A8, 8015B9A8, 8015BA30, 8015BA40, 8015BA50, 8015B9A8]. + * Diffed word-for-word against asm/ov_SC01_077/data/tail14.data.s:15-23 — 7/7 identical. + * symcheck : SYMS-DIFF target=35 draft=34, sole MISSING = jtbl_801D8B74. This is the §81 jr + * FALSE POSITIVE, re-confirmed here by reading the relocs: gcc emits its OWN table and + * references it with R_MIPS_HI16/LO16 against the SECTION `.rodata` (t.o +0x40/+0x48), + * so the splat's dlabel NAME can never appear in the draft object's relocation set. + * Nothing is dropped and nothing is invented: the draft's other 34 symbols are exactly + * the target's other 34. + * FAMILY : the x138 remap is clean and §84-safe. Every sibling is 271 ins with an IDENTICAL + * callee set; only THREE names vary per overlay — the two data labels and the jtbl: + * ov_SC01_077 D_801881BC / D_80188228 / jtbl_801D8B74 + * ov_SC03_099 D_80185A50 / D_80185ABC / jtbl_801BD898 + * ov_SC06_008 D_80187E44 / D_80187EB0 / jtbl_801A8734 + * The pair is always +0x6C apart, and NO literal in this draft encodes that distance + * (both labels are referenced by name), so there is no §84 derived-offset hazard. + * D_8011F9C4 is fleet-constant (main-EXE data) and must NOT be remapped. + * + * match_one: MATCH (271 ins) against the CURRENT tree (§87 staleness re-checked, 2026-07-27). + * PIN-FREE, zero asm, offset-pure (s32 arg0 + raw offsets) — x138 template-safe. + * Provenance: this is the Phase-26 crack (.run/phase26-cracks/func_8015B950.c) re-gated verbatim, + * with ONE deliberate change: the definition's return type void -> s32. + * - `void func_8015B950(s32 arg0)` : MATCH (271 ins) [the Phase-26 form] + * - `s32 func_8015B950(s32 arg0)` : MATCH (271 ins) [shipped — §3a-1 void->s32 is byte-neutral] + * The fleet/engine_core.h canonical decl is `extern s32 func_8015B950(void);` (engine_core.h:1852), + * and the last bank attempt (.run/bank_func_8015B950.log) died on `conflicting types for + * func_8015B950`. Shipping the s32 return kills the §73 RETURN axis for free and leaves only the + * cheap T0 PARAMS axis for the ladder (fix_header_decl.py / --fix-def-sig / cast_call_sites). + * Both forms are byte-identical, so the orchestrator may swap the return type back at zero cost. + * + * SYMBOLS (§58 rules 1/2 — all splat spellings, all verified present): + * D_80188228 asm/ov_SC01_077/data/tail.data.s:4355 (the state-handler vtable) + * D_801881BC asm/ov_SC01_077/data/tail.data.s:4293 + * D_8011F9C4 main-EXE data; spelled `extern s32 D_8011F9C4;` in 5+ already-banked TUs + * jtbl_801D8B74 asm/ov_SC01_077/data/tail14.data.s:15 (compiler jump table — not named in C) + * + * JTBL VERIFIED (§8a gate): compiled .rodata = exactly 0x1C B / 7 words, 7x R_MIPS_32 .text with + * addends [0x58,0x58,0x58,0xE0,0xF0,0x100,0x58] -> +0x8015B950 = [B9A8,B9A8,B9A8,BA30,BA40,BA50, + * B9A8] == the original words at 0x801D8B74..0x801D8B8C. Bound `sltiu $v0,$v1,0x7` matches. + * The raw dlabel's 8th word 0x00000000 is NOT an entry — it is the intra-TU `.align 3` pad of the + * B34/B54/B74 jtbl chain; the object can never emit it (maspsx drops .align), so it must stay in + * the post-carve RAW data piece (the §53/§62/§81 carve chain applies at bank time). + * + * Same family as the TU's own already-matched func_8015AE2C: 7-case switch on ((s32 (*)(s32))func_801619A4)() + * (0/1/2/6 shared, 3/4/5 own, no default block — out-of-range and every `break` fall to the + * after-switch join), then a chain of "state handler" tests, each dispatching + * D_80188228[*(u16*)arg0](arg0) and returning. + * + * THREE LEVERS (draft -> MATCH in 3 compiles): + * + * 1. PROLOGUE CONSTANT = an INITIALIZED LOCAL, not a literal in the compare. + * Target opens with `lui $s2, 0xFFF5` in the *prologue*, used once ~200 ins later in + * `slt $v0,$s2,$s1`. No gcc-2.7.2 pass hoists a (set reg const_int) across basic blocks + * (loop.c needs a loop; cse/combine/sched never move insns between BBs) — so the insn must + * have been EMITTED in the first BB, i.e. the constant is a local initialized at the top of + * the function. cse then cannot fold it back into the compare: the `slt` operand predicate is + * `arith_operand`, which rejects a CONST_INT wider than 16 bits, so validate_change fails and + * the pseudo survives. Its live range spans every call -> global.c gives it a callee-saved reg. + * Writing `z > -0xB0000` inline instead emits the `lui` into the branch delay slot next to the + * compare (caller-saved $v0) and the function is 1 insn short. => `s32 lim = -0xB0000;` at top. + * + * 2. `lh` vs `lhu`: a short->short copy is a pure HImode move and gcc emits `lhu`. The target's + * `lh $v0,0x26($s0)` means the value passed through an SImode (int) temp: expand makes + * (set (reg:SI) (sign_extend (mem:HI))) + (set (mem:HI) (subreg:HI ...)), and combine cannot + * merge them (the merged form is mem<-mem, which no movhi accepts) so the sign-extending load + * survives. => route both halfword copies through the `s32 t` temp. + * + * 3. THE `goto` LAYOUT — dodging jump.c's store-flag conversion (jump.c:1005-1065). + * An if/else chain writing 0/1 into `doit` makes gcc collapse the last pair into + * `sltiu $v0,$v0,1`. jump.c fires that conversion when the insn immediately after a + * conditional jump is a lone `SET pseudo, CONST_INT` whose following simplejump targets the + * SAME label as the branch (jump.c:1038 `reallabelprev == temp || ... JUMP_LABEL(temp4) == + * JUMP_LABEL(insn)`) — exactly the shape of `if (c) x=0; else x=1;`. + * The target instead cross-jumps ALL the `doit=0` exits into ONE shared block placed after the + * `doit=1` fall-through; reorg's fill_slots_from_thread then COPIES that single set into all + * three branch delay slots and redirects each branch past it (which is why `addu $v0,$zero, + * $zero` appears 3x in delay slots and the shared block vanishes). A `goto zero;` / `goto one;` + * chain expresses that layout directly, and each conditional jump is then followed by a + * compare/call rather than a lone const set, so the store-flag conversion never triggers. + * GENERAL RULE: multiple predicates that all assign the SAME constant to one flag => write + * them as `goto` to a shared assignment, never as an if/else ladder. + */ +extern s32 D_8011F9C4; +extern s32 D_801881BC; + +extern s32 func_80161B18(void); +extern s32 func_801619A4(s32*); +extern s32 func_80149AA8(s32*); +extern void func_80149AD4(s32*); +extern s32 func_80149B54(s32*); +extern void func_80149BAC(s32*); +extern s32 func_801498E0(s32*); +extern s32 func_80149954(s32); +extern s32 func_80149A64(s32*); +extern void func_800CCCC0(s32 a0); +extern s32 func_80149CD4(s32 a0); +extern void func_8015E880(s32*); +extern s32 func_80149744(struct S_80149744*); +extern void func_80149788(void); +extern s32 func_801496D4(void*); +extern void func_80149704(void); +extern int func_80148AFC(void*); +extern void func_80146D90(s32 a0); +extern void func_80154150(s32 a0, s32 a1); +extern void func_801541D8(u8*, s32, s32); +extern s32 func_801488A8(u8*); +extern void func_80147078(s32*, s16); +extern void func_8015A264(void*); +extern s32 func_80013294(void*, void*); +extern void func_80159B70(void*); +extern s32 func_8016F1AC(void); +extern s32 func_80029178(s32 a0); +extern void func_80146DB8(s32*, s32*); +extern s32 func_80161CD0(s32, s32); +extern s32 func_80161208(s32 a0); +extern s32 func_801725A4(u8*); + +s32 func_8015B950(s32 arg0) +{ + + extern void (*D_80188228[])(void *); + s16 sp10[4]; + s16 sp18[4]; + s32 t; + s32 z; + s32 doit; + s32 lim = -0xB0000; + + if (func_80161B18() != 0) { + return; + } + switch (((s32 (*)(s32))func_801619A4)(arg0)) { + case 0: + case 1: + case 2: + case 6: + if (((s32 (*)(s32))func_80149AA8)(arg0) != 0) { + D_80188228[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149AD4)(arg0); + return; + } + if (((s32 (*)(s32))func_80149B54)(arg0) != 0) { + D_80188228[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149BAC)(arg0); + return; + } + break; + case 3: + ((void (*)(s32))func_801498E0)(arg0); + break; + case 4: + ((void (*)(s32))func_80149954)(arg0); + break; + case 5: + if (((s32 (*)(s32))func_80149A64)(arg0) != 0) { + D_80188228[*(u16 *)arg0]((void *)arg0); + func_800CCCC0(arg0); + return; + } + break; + } + if (func_80149CD4(arg0) != 0) { + D_80188228[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_8015E880)(arg0); + return; + } + if (((s32 (*)(s32))func_80149744)(arg0) != 0) { + D_80188228[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149788)(arg0); + return; + } + if (((s32 (*)(s32))func_801496D4)(arg0) != 0) { + D_80188228[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149704)(arg0); + if (((u8)((s32 (*)(s32))func_80148AFC)(arg0)) == 0) { + func_80146D90(arg0); + } + if ((*(s32 *)(arg0 + 0x24) | *(s32 *)(arg0 + 0x2C)) != 0) { + func_80154150(arg0, 0xF); + } else { + ((void (*)(s32, s32, s32))func_801541D8)(arg0, 0xD, 6); + } + *(s32 *)(arg0 + 0x238) = 1; + return; + } + if (((s32 (*)(s32))func_801488A8)(arg0) != 0) { + sp10[0] = 0; + sp10[1] = 0; + sp10[2] = 0; + t = *(s16 *)(arg0 + 0x26); + sp18[0] = t; + sp18[1] = 0; + t = *(s16 *)(arg0 + 0x2E); + sp18[2] = t; + D_80188228[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 1); + ((void (*)(s32))func_8015A264)(arg0); + t = -(((s32 (*)(s16 *, s16 *))func_80013294)(sp10, sp18) << 0x10); + if (t < *(s32 *)(arg0 + 0x2C)) { + *(s32 *)(arg0 + 0x2C) = t; + } + return; + } + if (*(u16 *)(arg0 + 0xB8) == 0x8000) { + D_80188228[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 0); + ((void (*)(s32))func_80159B70)(arg0); + return; + } + z = *(s32 *)(arg0 + 0x2C); + if (func_8016F1AC() != 0) { + goto zero; + } + if (z <= lim) { + goto one; + } + if (D_8011F9C4 == 0) { + goto zero; + } + if (((u8)func_80029178(0x21)) != 0) { + goto zero; + } +one: + doit = 1; + goto join; +zero: + doit = 0; +join: + if (doit != 0) { + D_80188228[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 0); + ((void (*)(s32))func_80159B70)(arg0); + func_80154150(arg0, 9); + ((void (*)(s32, s32 *))func_80146DB8)(arg0, &D_801881BC); + ((void (*)(s32, s32))func_80161CD0)(arg0, *(u16 *)(arg0 + 0x16E)); + return; + } + if (func_80161208(arg0) == 0) { + ((void (*)(s32))func_801725A4)(arg0); + } +} DEFINE_func_8015BD8C() /* dedup: shared engine-core @0x8015BD8C (src/shared) */ diff --git a/src/ov_SC04_008/ov_SC04_008_jr_8015AE2C.c b/src/ov_SC04_008/ov_SC04_008_jr_8015AE2C.c index ecf5e7ed9..2d27158c1 100644 --- a/src/ov_SC04_008/ov_SC04_008_jr_8015AE2C.c +++ b/src/ov_SC04_008/ov_SC04_008_jr_8015AE2C.c @@ -1512,7 +1512,259 @@ DEFINE_func_8015B858() /* dedup: shared engine-core @0x8015B858 (src/shared) */ DEFINE_func_8015B8F8() /* dedup: shared engine-core @0x8015B8F8 (src/shared) */ -INCLUDE_ASM("asm/ov_SC04_008/nonmatchings/ov_SC04_008_jr_8015AE2C", func_8015B950); +extern s32 func_8015AE2C(); + +// @class: plumbing +// @stuck: none — MATCH (271/271, pin-free, zero asm). The ONLY residual is DEF-SIDE plumbing, and it is now named exactly: the in-TU instantiation `DEFINE_func_8015BEE4()` (engine_core.h:1851-1855) expands to `extern s32 func_8015B950(void);` INSIDE ov_SC01_077_jr_8015AE2C.c, ~14 lines BELOW this definition, so the 1-param def collides with a `(void)` prototype -> `conflicting types for func_8015B950` (.run/bank_func_8015B950.log). §73 PARAMS axis / T0. Surgical fix = §65b de-macroize that ONE instantiation (blast radius: this TU); the fleet-wide `(void)`->`()` header edit is §63 and must be R22-validated. +/* func_8015B950 (ov_SC01_077_jr_8015AE2C, 271 ins, jtbl_801D8B74) — SESSION-21 re-verified + * + * ── ROUND-2 INDEPENDENT RE-VERIFICATION (2026-07-27, fresh agent, §88e discipline) ───────────── + * match_one : MATCH (271 ins) against the CURRENT tree — §87 staleness re-checked today. + * .text size: compiled .text = 0x43C = 1084 B = 271 ins, EXACTLY the target's declared 0x43C + * ("nonmatching func_8015B950, 0x43C"). So this is NOT a §83a length drift hiding + * behind a zero count — the count is over equal-length streams. + * jtbl : RE-DECODED MECHANICALLY, not inherited. Compiled .rodata = 0x1C = 28 B = 7 words, + * 7x R_MIPS_32 -> .text with implicit addends [58,58,58,E0,F0,100,58]; +0x8015B950 + * = [8015B9A8, 8015B9A8, 8015B9A8, 8015BA30, 8015BA40, 8015BA50, 8015B9A8]. + * Diffed word-for-word against asm/ov_SC01_077/data/tail14.data.s:15-23 — 7/7 identical. + * symcheck : SYMS-DIFF target=35 draft=34, sole MISSING = jtbl_801D8B74. This is the §81 jr + * FALSE POSITIVE, re-confirmed here by reading the relocs: gcc emits its OWN table and + * references it with R_MIPS_HI16/LO16 against the SECTION `.rodata` (t.o +0x40/+0x48), + * so the splat's dlabel NAME can never appear in the draft object's relocation set. + * Nothing is dropped and nothing is invented: the draft's other 34 symbols are exactly + * the target's other 34. + * FAMILY : the x138 remap is clean and §84-safe. Every sibling is 271 ins with an IDENTICAL + * callee set; only THREE names vary per overlay — the two data labels and the jtbl: + * ov_SC01_077 D_801810F4 / D_80181160 / jtbl_801D8B74 + * ov_SC03_099 D_80185A50 / D_80185ABC / jtbl_801BD898 + * ov_SC06_008 D_80187E44 / D_80187EB0 / jtbl_801A8734 + * The pair is always +0x6C apart, and NO literal in this draft encodes that distance + * (both labels are referenced by name), so there is no §84 derived-offset hazard. + * D_8011F9C4 is fleet-constant (main-EXE data) and must NOT be remapped. + * + * match_one: MATCH (271 ins) against the CURRENT tree (§87 staleness re-checked, 2026-07-27). + * PIN-FREE, zero asm, offset-pure (s32 arg0 + raw offsets) — x138 template-safe. + * Provenance: this is the Phase-26 crack (.run/phase26-cracks/func_8015B950.c) re-gated verbatim, + * with ONE deliberate change: the definition's return type void -> s32. + * - `void func_8015B950(s32 arg0)` : MATCH (271 ins) [the Phase-26 form] + * - `s32 func_8015B950(s32 arg0)` : MATCH (271 ins) [shipped — §3a-1 void->s32 is byte-neutral] + * The fleet/engine_core.h canonical decl is `extern s32 func_8015B950(void);` (engine_core.h:1852), + * and the last bank attempt (.run/bank_func_8015B950.log) died on `conflicting types for + * func_8015B950`. Shipping the s32 return kills the §73 RETURN axis for free and leaves only the + * cheap T0 PARAMS axis for the ladder (fix_header_decl.py / --fix-def-sig / cast_call_sites). + * Both forms are byte-identical, so the orchestrator may swap the return type back at zero cost. + * + * SYMBOLS (§58 rules 1/2 — all splat spellings, all verified present): + * D_80181160 asm/ov_SC01_077/data/tail.data.s:4355 (the state-handler vtable) + * D_801810F4 asm/ov_SC01_077/data/tail.data.s:4293 + * D_8011F9C4 main-EXE data; spelled `extern s32 D_8011F9C4;` in 5+ already-banked TUs + * jtbl_801D8B74 asm/ov_SC01_077/data/tail14.data.s:15 (compiler jump table — not named in C) + * + * JTBL VERIFIED (§8a gate): compiled .rodata = exactly 0x1C B / 7 words, 7x R_MIPS_32 .text with + * addends [0x58,0x58,0x58,0xE0,0xF0,0x100,0x58] -> +0x8015B950 = [B9A8,B9A8,B9A8,BA30,BA40,BA50, + * B9A8] == the original words at 0x801D8B74..0x801D8B8C. Bound `sltiu $v0,$v1,0x7` matches. + * The raw dlabel's 8th word 0x00000000 is NOT an entry — it is the intra-TU `.align 3` pad of the + * B34/B54/B74 jtbl chain; the object can never emit it (maspsx drops .align), so it must stay in + * the post-carve RAW data piece (the §53/§62/§81 carve chain applies at bank time). + * + * Same family as the TU's own already-matched func_8015AE2C: 7-case switch on ((s32 (*)(s32))func_801619A4)() + * (0/1/2/6 shared, 3/4/5 own, no default block — out-of-range and every `break` fall to the + * after-switch join), then a chain of "state handler" tests, each dispatching + * D_80181160[*(u16*)arg0](arg0) and returning. + * + * THREE LEVERS (draft -> MATCH in 3 compiles): + * + * 1. PROLOGUE CONSTANT = an INITIALIZED LOCAL, not a literal in the compare. + * Target opens with `lui $s2, 0xFFF5` in the *prologue*, used once ~200 ins later in + * `slt $v0,$s2,$s1`. No gcc-2.7.2 pass hoists a (set reg const_int) across basic blocks + * (loop.c needs a loop; cse/combine/sched never move insns between BBs) — so the insn must + * have been EMITTED in the first BB, i.e. the constant is a local initialized at the top of + * the function. cse then cannot fold it back into the compare: the `slt` operand predicate is + * `arith_operand`, which rejects a CONST_INT wider than 16 bits, so validate_change fails and + * the pseudo survives. Its live range spans every call -> global.c gives it a callee-saved reg. + * Writing `z > -0xB0000` inline instead emits the `lui` into the branch delay slot next to the + * compare (caller-saved $v0) and the function is 1 insn short. => `s32 lim = -0xB0000;` at top. + * + * 2. `lh` vs `lhu`: a short->short copy is a pure HImode move and gcc emits `lhu`. The target's + * `lh $v0,0x26($s0)` means the value passed through an SImode (int) temp: expand makes + * (set (reg:SI) (sign_extend (mem:HI))) + (set (mem:HI) (subreg:HI ...)), and combine cannot + * merge them (the merged form is mem<-mem, which no movhi accepts) so the sign-extending load + * survives. => route both halfword copies through the `s32 t` temp. + * + * 3. THE `goto` LAYOUT — dodging jump.c's store-flag conversion (jump.c:1005-1065). + * An if/else chain writing 0/1 into `doit` makes gcc collapse the last pair into + * `sltiu $v0,$v0,1`. jump.c fires that conversion when the insn immediately after a + * conditional jump is a lone `SET pseudo, CONST_INT` whose following simplejump targets the + * SAME label as the branch (jump.c:1038 `reallabelprev == temp || ... JUMP_LABEL(temp4) == + * JUMP_LABEL(insn)`) — exactly the shape of `if (c) x=0; else x=1;`. + * The target instead cross-jumps ALL the `doit=0` exits into ONE shared block placed after the + * `doit=1` fall-through; reorg's fill_slots_from_thread then COPIES that single set into all + * three branch delay slots and redirects each branch past it (which is why `addu $v0,$zero, + * $zero` appears 3x in delay slots and the shared block vanishes). A `goto zero;` / `goto one;` + * chain expresses that layout directly, and each conditional jump is then followed by a + * compare/call rather than a lone const set, so the store-flag conversion never triggers. + * GENERAL RULE: multiple predicates that all assign the SAME constant to one flag => write + * them as `goto` to a shared assignment, never as an if/else ladder. + */ +extern s32 D_8011F9C4; +extern s32 D_801810F4; + +extern s32 func_80161B18(void); +extern s32 func_801619A4(s32*); +extern s32 func_80149AA8(s32*); +extern void func_80149AD4(s32*); +extern s32 func_80149B54(s32*); +extern void func_80149BAC(s32*); +extern s32 func_801498E0(s32*); +extern s32 func_80149954(s32); +extern s32 func_80149A64(s32*); +extern void func_800CCCC0(s32 a0); +extern s32 func_80149CD4(s32 a0); +extern void func_8015E880(s32*); +extern s32 func_80149744(struct S_80149744*); +extern void func_80149788(void); +extern s32 func_801496D4(void*); +extern void func_80149704(void); +extern int func_80148AFC(void*); +extern void func_80146D90(s32 a0); +extern void func_80154150(s32 a0, s32 a1); +extern void func_801541D8(u8*, s32, s32); +extern s32 func_801488A8(u8*); +extern void func_80147078(s32*, s16); +extern void func_8015A264(void*); +extern s32 func_80013294(void*, void*); +extern void func_80159B70(void*); +extern s32 func_8016F1AC(void); +extern s32 func_80029178(s32 a0); +extern void func_80146DB8(s32*, s32*); +extern s32 func_80161CD0(s32, s32); +extern s32 func_80161208(s32 a0); +extern s32 func_801725A4(u8*); + +s32 func_8015B950(s32 arg0) +{ + + extern void (*D_80181160[])(void *); + s16 sp10[4]; + s16 sp18[4]; + s32 t; + s32 z; + s32 doit; + s32 lim = -0xB0000; + + if (func_80161B18() != 0) { + return; + } + switch (((s32 (*)(s32))func_801619A4)(arg0)) { + case 0: + case 1: + case 2: + case 6: + if (((s32 (*)(s32))func_80149AA8)(arg0) != 0) { + D_80181160[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149AD4)(arg0); + return; + } + if (((s32 (*)(s32))func_80149B54)(arg0) != 0) { + D_80181160[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149BAC)(arg0); + return; + } + break; + case 3: + ((void (*)(s32))func_801498E0)(arg0); + break; + case 4: + ((void (*)(s32))func_80149954)(arg0); + break; + case 5: + if (((s32 (*)(s32))func_80149A64)(arg0) != 0) { + D_80181160[*(u16 *)arg0]((void *)arg0); + func_800CCCC0(arg0); + return; + } + break; + } + if (func_80149CD4(arg0) != 0) { + D_80181160[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_8015E880)(arg0); + return; + } + if (((s32 (*)(s32))func_80149744)(arg0) != 0) { + D_80181160[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149788)(arg0); + return; + } + if (((s32 (*)(s32))func_801496D4)(arg0) != 0) { + D_80181160[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149704)(arg0); + if (((u8)((s32 (*)(s32))func_80148AFC)(arg0)) == 0) { + func_80146D90(arg0); + } + if ((*(s32 *)(arg0 + 0x24) | *(s32 *)(arg0 + 0x2C)) != 0) { + func_80154150(arg0, 0xF); + } else { + ((void (*)(s32, s32, s32))func_801541D8)(arg0, 0xD, 6); + } + *(s32 *)(arg0 + 0x238) = 1; + return; + } + if (((s32 (*)(s32))func_801488A8)(arg0) != 0) { + sp10[0] = 0; + sp10[1] = 0; + sp10[2] = 0; + t = *(s16 *)(arg0 + 0x26); + sp18[0] = t; + sp18[1] = 0; + t = *(s16 *)(arg0 + 0x2E); + sp18[2] = t; + D_80181160[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 1); + ((void (*)(s32))func_8015A264)(arg0); + t = -(((s32 (*)(s16 *, s16 *))func_80013294)(sp10, sp18) << 0x10); + if (t < *(s32 *)(arg0 + 0x2C)) { + *(s32 *)(arg0 + 0x2C) = t; + } + return; + } + if (*(u16 *)(arg0 + 0xB8) == 0x8000) { + D_80181160[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 0); + ((void (*)(s32))func_80159B70)(arg0); + return; + } + z = *(s32 *)(arg0 + 0x2C); + if (func_8016F1AC() != 0) { + goto zero; + } + if (z <= lim) { + goto one; + } + if (D_8011F9C4 == 0) { + goto zero; + } + if (((u8)func_80029178(0x21)) != 0) { + goto zero; + } +one: + doit = 1; + goto join; +zero: + doit = 0; +join: + if (doit != 0) { + D_80181160[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 0); + ((void (*)(s32))func_80159B70)(arg0); + func_80154150(arg0, 9); + ((void (*)(s32, s32 *))func_80146DB8)(arg0, &D_801810F4); + ((void (*)(s32, s32))func_80161CD0)(arg0, *(u16 *)(arg0 + 0x16E)); + return; + } + if (func_80161208(arg0) == 0) { + ((void (*)(s32))func_801725A4)(arg0); + } +} DEFINE_func_8015BD8C() /* dedup: shared engine-core @0x8015BD8C (src/shared) */ diff --git a/src/ov_SC04_009/ov_SC04_009_jr_8015AE2C.c b/src/ov_SC04_009/ov_SC04_009_jr_8015AE2C.c index 3343e9f38..328c13af9 100644 --- a/src/ov_SC04_009/ov_SC04_009_jr_8015AE2C.c +++ b/src/ov_SC04_009/ov_SC04_009_jr_8015AE2C.c @@ -1512,7 +1512,259 @@ DEFINE_func_8015B858() /* dedup: shared engine-core @0x8015B858 (src/shared) */ DEFINE_func_8015B8F8() /* dedup: shared engine-core @0x8015B8F8 (src/shared) */ -INCLUDE_ASM("asm/ov_SC04_009/nonmatchings/ov_SC04_009_jr_8015AE2C", func_8015B950); +extern s32 func_8015AE2C(); + +// @class: plumbing +// @stuck: none — MATCH (271/271, pin-free, zero asm). The ONLY residual is DEF-SIDE plumbing, and it is now named exactly: the in-TU instantiation `DEFINE_func_8015BEE4()` (engine_core.h:1851-1855) expands to `extern s32 func_8015B950(void);` INSIDE ov_SC01_077_jr_8015AE2C.c, ~14 lines BELOW this definition, so the 1-param def collides with a `(void)` prototype -> `conflicting types for func_8015B950` (.run/bank_func_8015B950.log). §73 PARAMS axis / T0. Surgical fix = §65b de-macroize that ONE instantiation (blast radius: this TU); the fleet-wide `(void)`->`()` header edit is §63 and must be R22-validated. +/* func_8015B950 (ov_SC01_077_jr_8015AE2C, 271 ins, jtbl_801D8B74) — SESSION-21 re-verified + * + * ── ROUND-2 INDEPENDENT RE-VERIFICATION (2026-07-27, fresh agent, §88e discipline) ───────────── + * match_one : MATCH (271 ins) against the CURRENT tree — §87 staleness re-checked today. + * .text size: compiled .text = 0x43C = 1084 B = 271 ins, EXACTLY the target's declared 0x43C + * ("nonmatching func_8015B950, 0x43C"). So this is NOT a §83a length drift hiding + * behind a zero count — the count is over equal-length streams. + * jtbl : RE-DECODED MECHANICALLY, not inherited. Compiled .rodata = 0x1C = 28 B = 7 words, + * 7x R_MIPS_32 -> .text with implicit addends [58,58,58,E0,F0,100,58]; +0x8015B950 + * = [8015B9A8, 8015B9A8, 8015B9A8, 8015BA30, 8015BA40, 8015BA50, 8015B9A8]. + * Diffed word-for-word against asm/ov_SC01_077/data/tail14.data.s:15-23 — 7/7 identical. + * symcheck : SYMS-DIFF target=35 draft=34, sole MISSING = jtbl_801D8B74. This is the §81 jr + * FALSE POSITIVE, re-confirmed here by reading the relocs: gcc emits its OWN table and + * references it with R_MIPS_HI16/LO16 against the SECTION `.rodata` (t.o +0x40/+0x48), + * so the splat's dlabel NAME can never appear in the draft object's relocation set. + * Nothing is dropped and nothing is invented: the draft's other 34 symbols are exactly + * the target's other 34. + * FAMILY : the x138 remap is clean and §84-safe. Every sibling is 271 ins with an IDENTICAL + * callee set; only THREE names vary per overlay — the two data labels and the jtbl: + * ov_SC01_077 D_80181120 / D_8018118C / jtbl_801D8B74 + * ov_SC03_099 D_80185A50 / D_80185ABC / jtbl_801BD898 + * ov_SC06_008 D_80187E44 / D_80187EB0 / jtbl_801A8734 + * The pair is always +0x6C apart, and NO literal in this draft encodes that distance + * (both labels are referenced by name), so there is no §84 derived-offset hazard. + * D_8011F9C4 is fleet-constant (main-EXE data) and must NOT be remapped. + * + * match_one: MATCH (271 ins) against the CURRENT tree (§87 staleness re-checked, 2026-07-27). + * PIN-FREE, zero asm, offset-pure (s32 arg0 + raw offsets) — x138 template-safe. + * Provenance: this is the Phase-26 crack (.run/phase26-cracks/func_8015B950.c) re-gated verbatim, + * with ONE deliberate change: the definition's return type void -> s32. + * - `void func_8015B950(s32 arg0)` : MATCH (271 ins) [the Phase-26 form] + * - `s32 func_8015B950(s32 arg0)` : MATCH (271 ins) [shipped — §3a-1 void->s32 is byte-neutral] + * The fleet/engine_core.h canonical decl is `extern s32 func_8015B950(void);` (engine_core.h:1852), + * and the last bank attempt (.run/bank_func_8015B950.log) died on `conflicting types for + * func_8015B950`. Shipping the s32 return kills the §73 RETURN axis for free and leaves only the + * cheap T0 PARAMS axis for the ladder (fix_header_decl.py / --fix-def-sig / cast_call_sites). + * Both forms are byte-identical, so the orchestrator may swap the return type back at zero cost. + * + * SYMBOLS (§58 rules 1/2 — all splat spellings, all verified present): + * D_8018118C asm/ov_SC01_077/data/tail.data.s:4355 (the state-handler vtable) + * D_80181120 asm/ov_SC01_077/data/tail.data.s:4293 + * D_8011F9C4 main-EXE data; spelled `extern s32 D_8011F9C4;` in 5+ already-banked TUs + * jtbl_801D8B74 asm/ov_SC01_077/data/tail14.data.s:15 (compiler jump table — not named in C) + * + * JTBL VERIFIED (§8a gate): compiled .rodata = exactly 0x1C B / 7 words, 7x R_MIPS_32 .text with + * addends [0x58,0x58,0x58,0xE0,0xF0,0x100,0x58] -> +0x8015B950 = [B9A8,B9A8,B9A8,BA30,BA40,BA50, + * B9A8] == the original words at 0x801D8B74..0x801D8B8C. Bound `sltiu $v0,$v1,0x7` matches. + * The raw dlabel's 8th word 0x00000000 is NOT an entry — it is the intra-TU `.align 3` pad of the + * B34/B54/B74 jtbl chain; the object can never emit it (maspsx drops .align), so it must stay in + * the post-carve RAW data piece (the §53/§62/§81 carve chain applies at bank time). + * + * Same family as the TU's own already-matched func_8015AE2C: 7-case switch on ((s32 (*)(s32))func_801619A4)() + * (0/1/2/6 shared, 3/4/5 own, no default block — out-of-range and every `break` fall to the + * after-switch join), then a chain of "state handler" tests, each dispatching + * D_8018118C[*(u16*)arg0](arg0) and returning. + * + * THREE LEVERS (draft -> MATCH in 3 compiles): + * + * 1. PROLOGUE CONSTANT = an INITIALIZED LOCAL, not a literal in the compare. + * Target opens with `lui $s2, 0xFFF5` in the *prologue*, used once ~200 ins later in + * `slt $v0,$s2,$s1`. No gcc-2.7.2 pass hoists a (set reg const_int) across basic blocks + * (loop.c needs a loop; cse/combine/sched never move insns between BBs) — so the insn must + * have been EMITTED in the first BB, i.e. the constant is a local initialized at the top of + * the function. cse then cannot fold it back into the compare: the `slt` operand predicate is + * `arith_operand`, which rejects a CONST_INT wider than 16 bits, so validate_change fails and + * the pseudo survives. Its live range spans every call -> global.c gives it a callee-saved reg. + * Writing `z > -0xB0000` inline instead emits the `lui` into the branch delay slot next to the + * compare (caller-saved $v0) and the function is 1 insn short. => `s32 lim = -0xB0000;` at top. + * + * 2. `lh` vs `lhu`: a short->short copy is a pure HImode move and gcc emits `lhu`. The target's + * `lh $v0,0x26($s0)` means the value passed through an SImode (int) temp: expand makes + * (set (reg:SI) (sign_extend (mem:HI))) + (set (mem:HI) (subreg:HI ...)), and combine cannot + * merge them (the merged form is mem<-mem, which no movhi accepts) so the sign-extending load + * survives. => route both halfword copies through the `s32 t` temp. + * + * 3. THE `goto` LAYOUT — dodging jump.c's store-flag conversion (jump.c:1005-1065). + * An if/else chain writing 0/1 into `doit` makes gcc collapse the last pair into + * `sltiu $v0,$v0,1`. jump.c fires that conversion when the insn immediately after a + * conditional jump is a lone `SET pseudo, CONST_INT` whose following simplejump targets the + * SAME label as the branch (jump.c:1038 `reallabelprev == temp || ... JUMP_LABEL(temp4) == + * JUMP_LABEL(insn)`) — exactly the shape of `if (c) x=0; else x=1;`. + * The target instead cross-jumps ALL the `doit=0` exits into ONE shared block placed after the + * `doit=1` fall-through; reorg's fill_slots_from_thread then COPIES that single set into all + * three branch delay slots and redirects each branch past it (which is why `addu $v0,$zero, + * $zero` appears 3x in delay slots and the shared block vanishes). A `goto zero;` / `goto one;` + * chain expresses that layout directly, and each conditional jump is then followed by a + * compare/call rather than a lone const set, so the store-flag conversion never triggers. + * GENERAL RULE: multiple predicates that all assign the SAME constant to one flag => write + * them as `goto` to a shared assignment, never as an if/else ladder. + */ +extern s32 D_8011F9C4; +extern s32 D_80181120; + +extern s32 func_80161B18(void); +extern s32 func_801619A4(s32*); +extern s32 func_80149AA8(s32*); +extern void func_80149AD4(s32*); +extern s32 func_80149B54(s32*); +extern void func_80149BAC(s32*); +extern s32 func_801498E0(s32*); +extern s32 func_80149954(s32); +extern s32 func_80149A64(s32*); +extern void func_800CCCC0(s32 a0); +extern s32 func_80149CD4(s32 a0); +extern void func_8015E880(s32*); +extern s32 func_80149744(struct S_80149744*); +extern void func_80149788(void); +extern s32 func_801496D4(void*); +extern void func_80149704(void); +extern int func_80148AFC(void*); +extern void func_80146D90(s32 a0); +extern void func_80154150(s32 a0, s32 a1); +extern void func_801541D8(u8*, s32, s32); +extern s32 func_801488A8(u8*); +extern void func_80147078(s32*, s16); +extern void func_8015A264(void*); +extern s32 func_80013294(void*, void*); +extern void func_80159B70(void*); +extern s32 func_8016F1AC(void); +extern s32 func_80029178(s32 a0); +extern void func_80146DB8(s32*, s32*); +extern s32 func_80161CD0(s32, s32); +extern s32 func_80161208(s32 a0); +extern s32 func_801725A4(u8*); + +s32 func_8015B950(s32 arg0) +{ + + extern void (*D_8018118C[])(void *); + s16 sp10[4]; + s16 sp18[4]; + s32 t; + s32 z; + s32 doit; + s32 lim = -0xB0000; + + if (func_80161B18() != 0) { + return; + } + switch (((s32 (*)(s32))func_801619A4)(arg0)) { + case 0: + case 1: + case 2: + case 6: + if (((s32 (*)(s32))func_80149AA8)(arg0) != 0) { + D_8018118C[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149AD4)(arg0); + return; + } + if (((s32 (*)(s32))func_80149B54)(arg0) != 0) { + D_8018118C[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149BAC)(arg0); + return; + } + break; + case 3: + ((void (*)(s32))func_801498E0)(arg0); + break; + case 4: + ((void (*)(s32))func_80149954)(arg0); + break; + case 5: + if (((s32 (*)(s32))func_80149A64)(arg0) != 0) { + D_8018118C[*(u16 *)arg0]((void *)arg0); + func_800CCCC0(arg0); + return; + } + break; + } + if (func_80149CD4(arg0) != 0) { + D_8018118C[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_8015E880)(arg0); + return; + } + if (((s32 (*)(s32))func_80149744)(arg0) != 0) { + D_8018118C[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149788)(arg0); + return; + } + if (((s32 (*)(s32))func_801496D4)(arg0) != 0) { + D_8018118C[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149704)(arg0); + if (((u8)((s32 (*)(s32))func_80148AFC)(arg0)) == 0) { + func_80146D90(arg0); + } + if ((*(s32 *)(arg0 + 0x24) | *(s32 *)(arg0 + 0x2C)) != 0) { + func_80154150(arg0, 0xF); + } else { + ((void (*)(s32, s32, s32))func_801541D8)(arg0, 0xD, 6); + } + *(s32 *)(arg0 + 0x238) = 1; + return; + } + if (((s32 (*)(s32))func_801488A8)(arg0) != 0) { + sp10[0] = 0; + sp10[1] = 0; + sp10[2] = 0; + t = *(s16 *)(arg0 + 0x26); + sp18[0] = t; + sp18[1] = 0; + t = *(s16 *)(arg0 + 0x2E); + sp18[2] = t; + D_8018118C[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 1); + ((void (*)(s32))func_8015A264)(arg0); + t = -(((s32 (*)(s16 *, s16 *))func_80013294)(sp10, sp18) << 0x10); + if (t < *(s32 *)(arg0 + 0x2C)) { + *(s32 *)(arg0 + 0x2C) = t; + } + return; + } + if (*(u16 *)(arg0 + 0xB8) == 0x8000) { + D_8018118C[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 0); + ((void (*)(s32))func_80159B70)(arg0); + return; + } + z = *(s32 *)(arg0 + 0x2C); + if (func_8016F1AC() != 0) { + goto zero; + } + if (z <= lim) { + goto one; + } + if (D_8011F9C4 == 0) { + goto zero; + } + if (((u8)func_80029178(0x21)) != 0) { + goto zero; + } +one: + doit = 1; + goto join; +zero: + doit = 0; +join: + if (doit != 0) { + D_8018118C[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 0); + ((void (*)(s32))func_80159B70)(arg0); + func_80154150(arg0, 9); + ((void (*)(s32, s32 *))func_80146DB8)(arg0, &D_80181120); + ((void (*)(s32, s32))func_80161CD0)(arg0, *(u16 *)(arg0 + 0x16E)); + return; + } + if (func_80161208(arg0) == 0) { + ((void (*)(s32))func_801725A4)(arg0); + } +} DEFINE_func_8015BD8C() /* dedup: shared engine-core @0x8015BD8C (src/shared) */ diff --git a/src/ov_SC04_010/ov_SC04_010_jr_8015AE2C.c b/src/ov_SC04_010/ov_SC04_010_jr_8015AE2C.c index c11045744..0ea594e8b 100644 --- a/src/ov_SC04_010/ov_SC04_010_jr_8015AE2C.c +++ b/src/ov_SC04_010/ov_SC04_010_jr_8015AE2C.c @@ -1512,7 +1512,259 @@ DEFINE_func_8015B858() /* dedup: shared engine-core @0x8015B858 (src/shared) */ DEFINE_func_8015B8F8() /* dedup: shared engine-core @0x8015B8F8 (src/shared) */ -INCLUDE_ASM("asm/ov_SC04_010/nonmatchings/ov_SC04_010_jr_8015AE2C", func_8015B950); +extern s32 func_8015AE2C(); + +// @class: plumbing +// @stuck: none — MATCH (271/271, pin-free, zero asm). The ONLY residual is DEF-SIDE plumbing, and it is now named exactly: the in-TU instantiation `DEFINE_func_8015BEE4()` (engine_core.h:1851-1855) expands to `extern s32 func_8015B950(void);` INSIDE ov_SC01_077_jr_8015AE2C.c, ~14 lines BELOW this definition, so the 1-param def collides with a `(void)` prototype -> `conflicting types for func_8015B950` (.run/bank_func_8015B950.log). §73 PARAMS axis / T0. Surgical fix = §65b de-macroize that ONE instantiation (blast radius: this TU); the fleet-wide `(void)`->`()` header edit is §63 and must be R22-validated. +/* func_8015B950 (ov_SC01_077_jr_8015AE2C, 271 ins, jtbl_801D8B74) — SESSION-21 re-verified + * + * ── ROUND-2 INDEPENDENT RE-VERIFICATION (2026-07-27, fresh agent, §88e discipline) ───────────── + * match_one : MATCH (271 ins) against the CURRENT tree — §87 staleness re-checked today. + * .text size: compiled .text = 0x43C = 1084 B = 271 ins, EXACTLY the target's declared 0x43C + * ("nonmatching func_8015B950, 0x43C"). So this is NOT a §83a length drift hiding + * behind a zero count — the count is over equal-length streams. + * jtbl : RE-DECODED MECHANICALLY, not inherited. Compiled .rodata = 0x1C = 28 B = 7 words, + * 7x R_MIPS_32 -> .text with implicit addends [58,58,58,E0,F0,100,58]; +0x8015B950 + * = [8015B9A8, 8015B9A8, 8015B9A8, 8015BA30, 8015BA40, 8015BA50, 8015B9A8]. + * Diffed word-for-word against asm/ov_SC01_077/data/tail14.data.s:15-23 — 7/7 identical. + * symcheck : SYMS-DIFF target=35 draft=34, sole MISSING = jtbl_801D8B74. This is the §81 jr + * FALSE POSITIVE, re-confirmed here by reading the relocs: gcc emits its OWN table and + * references it with R_MIPS_HI16/LO16 against the SECTION `.rodata` (t.o +0x40/+0x48), + * so the splat's dlabel NAME can never appear in the draft object's relocation set. + * Nothing is dropped and nothing is invented: the draft's other 34 symbols are exactly + * the target's other 34. + * FAMILY : the x138 remap is clean and §84-safe. Every sibling is 271 ins with an IDENTICAL + * callee set; only THREE names vary per overlay — the two data labels and the jtbl: + * ov_SC01_077 D_801807CC / D_80180838 / jtbl_801D8B74 + * ov_SC03_099 D_80185A50 / D_80185ABC / jtbl_801BD898 + * ov_SC06_008 D_80187E44 / D_80187EB0 / jtbl_801A8734 + * The pair is always +0x6C apart, and NO literal in this draft encodes that distance + * (both labels are referenced by name), so there is no §84 derived-offset hazard. + * D_8011F9C4 is fleet-constant (main-EXE data) and must NOT be remapped. + * + * match_one: MATCH (271 ins) against the CURRENT tree (§87 staleness re-checked, 2026-07-27). + * PIN-FREE, zero asm, offset-pure (s32 arg0 + raw offsets) — x138 template-safe. + * Provenance: this is the Phase-26 crack (.run/phase26-cracks/func_8015B950.c) re-gated verbatim, + * with ONE deliberate change: the definition's return type void -> s32. + * - `void func_8015B950(s32 arg0)` : MATCH (271 ins) [the Phase-26 form] + * - `s32 func_8015B950(s32 arg0)` : MATCH (271 ins) [shipped — §3a-1 void->s32 is byte-neutral] + * The fleet/engine_core.h canonical decl is `extern s32 func_8015B950(void);` (engine_core.h:1852), + * and the last bank attempt (.run/bank_func_8015B950.log) died on `conflicting types for + * func_8015B950`. Shipping the s32 return kills the §73 RETURN axis for free and leaves only the + * cheap T0 PARAMS axis for the ladder (fix_header_decl.py / --fix-def-sig / cast_call_sites). + * Both forms are byte-identical, so the orchestrator may swap the return type back at zero cost. + * + * SYMBOLS (§58 rules 1/2 — all splat spellings, all verified present): + * D_80180838 asm/ov_SC01_077/data/tail.data.s:4355 (the state-handler vtable) + * D_801807CC asm/ov_SC01_077/data/tail.data.s:4293 + * D_8011F9C4 main-EXE data; spelled `extern s32 D_8011F9C4;` in 5+ already-banked TUs + * jtbl_801D8B74 asm/ov_SC01_077/data/tail14.data.s:15 (compiler jump table — not named in C) + * + * JTBL VERIFIED (§8a gate): compiled .rodata = exactly 0x1C B / 7 words, 7x R_MIPS_32 .text with + * addends [0x58,0x58,0x58,0xE0,0xF0,0x100,0x58] -> +0x8015B950 = [B9A8,B9A8,B9A8,BA30,BA40,BA50, + * B9A8] == the original words at 0x801D8B74..0x801D8B8C. Bound `sltiu $v0,$v1,0x7` matches. + * The raw dlabel's 8th word 0x00000000 is NOT an entry — it is the intra-TU `.align 3` pad of the + * B34/B54/B74 jtbl chain; the object can never emit it (maspsx drops .align), so it must stay in + * the post-carve RAW data piece (the §53/§62/§81 carve chain applies at bank time). + * + * Same family as the TU's own already-matched func_8015AE2C: 7-case switch on ((s32 (*)(s32))func_801619A4)() + * (0/1/2/6 shared, 3/4/5 own, no default block — out-of-range and every `break` fall to the + * after-switch join), then a chain of "state handler" tests, each dispatching + * D_80180838[*(u16*)arg0](arg0) and returning. + * + * THREE LEVERS (draft -> MATCH in 3 compiles): + * + * 1. PROLOGUE CONSTANT = an INITIALIZED LOCAL, not a literal in the compare. + * Target opens with `lui $s2, 0xFFF5` in the *prologue*, used once ~200 ins later in + * `slt $v0,$s2,$s1`. No gcc-2.7.2 pass hoists a (set reg const_int) across basic blocks + * (loop.c needs a loop; cse/combine/sched never move insns between BBs) — so the insn must + * have been EMITTED in the first BB, i.e. the constant is a local initialized at the top of + * the function. cse then cannot fold it back into the compare: the `slt` operand predicate is + * `arith_operand`, which rejects a CONST_INT wider than 16 bits, so validate_change fails and + * the pseudo survives. Its live range spans every call -> global.c gives it a callee-saved reg. + * Writing `z > -0xB0000` inline instead emits the `lui` into the branch delay slot next to the + * compare (caller-saved $v0) and the function is 1 insn short. => `s32 lim = -0xB0000;` at top. + * + * 2. `lh` vs `lhu`: a short->short copy is a pure HImode move and gcc emits `lhu`. The target's + * `lh $v0,0x26($s0)` means the value passed through an SImode (int) temp: expand makes + * (set (reg:SI) (sign_extend (mem:HI))) + (set (mem:HI) (subreg:HI ...)), and combine cannot + * merge them (the merged form is mem<-mem, which no movhi accepts) so the sign-extending load + * survives. => route both halfword copies through the `s32 t` temp. + * + * 3. THE `goto` LAYOUT — dodging jump.c's store-flag conversion (jump.c:1005-1065). + * An if/else chain writing 0/1 into `doit` makes gcc collapse the last pair into + * `sltiu $v0,$v0,1`. jump.c fires that conversion when the insn immediately after a + * conditional jump is a lone `SET pseudo, CONST_INT` whose following simplejump targets the + * SAME label as the branch (jump.c:1038 `reallabelprev == temp || ... JUMP_LABEL(temp4) == + * JUMP_LABEL(insn)`) — exactly the shape of `if (c) x=0; else x=1;`. + * The target instead cross-jumps ALL the `doit=0` exits into ONE shared block placed after the + * `doit=1` fall-through; reorg's fill_slots_from_thread then COPIES that single set into all + * three branch delay slots and redirects each branch past it (which is why `addu $v0,$zero, + * $zero` appears 3x in delay slots and the shared block vanishes). A `goto zero;` / `goto one;` + * chain expresses that layout directly, and each conditional jump is then followed by a + * compare/call rather than a lone const set, so the store-flag conversion never triggers. + * GENERAL RULE: multiple predicates that all assign the SAME constant to one flag => write + * them as `goto` to a shared assignment, never as an if/else ladder. + */ +extern s32 D_8011F9C4; +extern s32 D_801807CC; + +extern s32 func_80161B18(void); +extern s32 func_801619A4(s32*); +extern s32 func_80149AA8(s32*); +extern void func_80149AD4(s32*); +extern s32 func_80149B54(s32*); +extern void func_80149BAC(s32*); +extern s32 func_801498E0(s32*); +extern s32 func_80149954(s32); +extern s32 func_80149A64(s32*); +extern void func_800CCCC0(s32 a0); +extern s32 func_80149CD4(s32 a0); +extern void func_8015E880(s32*); +extern s32 func_80149744(struct S_80149744*); +extern void func_80149788(void); +extern s32 func_801496D4(void*); +extern void func_80149704(void); +extern int func_80148AFC(void*); +extern void func_80146D90(s32 a0); +extern void func_80154150(s32 a0, s32 a1); +extern void func_801541D8(u8*, s32, s32); +extern s32 func_801488A8(u8*); +extern void func_80147078(s32*, s16); +extern void func_8015A264(void*); +extern s32 func_80013294(void*, void*); +extern void func_80159B70(void*); +extern s32 func_8016F1AC(void); +extern s32 func_80029178(s32 a0); +extern void func_80146DB8(s32*, s32*); +extern s32 func_80161CD0(s32, s32); +extern s32 func_80161208(s32 a0); +extern s32 func_801725A4(u8*); + +s32 func_8015B950(s32 arg0) +{ + + extern void (*D_80180838[])(void *); + s16 sp10[4]; + s16 sp18[4]; + s32 t; + s32 z; + s32 doit; + s32 lim = -0xB0000; + + if (func_80161B18() != 0) { + return; + } + switch (((s32 (*)(s32))func_801619A4)(arg0)) { + case 0: + case 1: + case 2: + case 6: + if (((s32 (*)(s32))func_80149AA8)(arg0) != 0) { + D_80180838[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149AD4)(arg0); + return; + } + if (((s32 (*)(s32))func_80149B54)(arg0) != 0) { + D_80180838[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149BAC)(arg0); + return; + } + break; + case 3: + ((void (*)(s32))func_801498E0)(arg0); + break; + case 4: + ((void (*)(s32))func_80149954)(arg0); + break; + case 5: + if (((s32 (*)(s32))func_80149A64)(arg0) != 0) { + D_80180838[*(u16 *)arg0]((void *)arg0); + func_800CCCC0(arg0); + return; + } + break; + } + if (func_80149CD4(arg0) != 0) { + D_80180838[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_8015E880)(arg0); + return; + } + if (((s32 (*)(s32))func_80149744)(arg0) != 0) { + D_80180838[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149788)(arg0); + return; + } + if (((s32 (*)(s32))func_801496D4)(arg0) != 0) { + D_80180838[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149704)(arg0); + if (((u8)((s32 (*)(s32))func_80148AFC)(arg0)) == 0) { + func_80146D90(arg0); + } + if ((*(s32 *)(arg0 + 0x24) | *(s32 *)(arg0 + 0x2C)) != 0) { + func_80154150(arg0, 0xF); + } else { + ((void (*)(s32, s32, s32))func_801541D8)(arg0, 0xD, 6); + } + *(s32 *)(arg0 + 0x238) = 1; + return; + } + if (((s32 (*)(s32))func_801488A8)(arg0) != 0) { + sp10[0] = 0; + sp10[1] = 0; + sp10[2] = 0; + t = *(s16 *)(arg0 + 0x26); + sp18[0] = t; + sp18[1] = 0; + t = *(s16 *)(arg0 + 0x2E); + sp18[2] = t; + D_80180838[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 1); + ((void (*)(s32))func_8015A264)(arg0); + t = -(((s32 (*)(s16 *, s16 *))func_80013294)(sp10, sp18) << 0x10); + if (t < *(s32 *)(arg0 + 0x2C)) { + *(s32 *)(arg0 + 0x2C) = t; + } + return; + } + if (*(u16 *)(arg0 + 0xB8) == 0x8000) { + D_80180838[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 0); + ((void (*)(s32))func_80159B70)(arg0); + return; + } + z = *(s32 *)(arg0 + 0x2C); + if (func_8016F1AC() != 0) { + goto zero; + } + if (z <= lim) { + goto one; + } + if (D_8011F9C4 == 0) { + goto zero; + } + if (((u8)func_80029178(0x21)) != 0) { + goto zero; + } +one: + doit = 1; + goto join; +zero: + doit = 0; +join: + if (doit != 0) { + D_80180838[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 0); + ((void (*)(s32))func_80159B70)(arg0); + func_80154150(arg0, 9); + ((void (*)(s32, s32 *))func_80146DB8)(arg0, &D_801807CC); + ((void (*)(s32, s32))func_80161CD0)(arg0, *(u16 *)(arg0 + 0x16E)); + return; + } + if (func_80161208(arg0) == 0) { + ((void (*)(s32))func_801725A4)(arg0); + } +} DEFINE_func_8015BD8C() /* dedup: shared engine-core @0x8015BD8C (src/shared) */ diff --git a/src/ov_SC04_011/ov_SC04_011_jr_8015AE2C.c b/src/ov_SC04_011/ov_SC04_011_jr_8015AE2C.c index ec8d82050..bba242198 100644 --- a/src/ov_SC04_011/ov_SC04_011_jr_8015AE2C.c +++ b/src/ov_SC04_011/ov_SC04_011_jr_8015AE2C.c @@ -1512,7 +1512,259 @@ DEFINE_func_8015B858() /* dedup: shared engine-core @0x8015B858 (src/shared) */ DEFINE_func_8015B8F8() /* dedup: shared engine-core @0x8015B8F8 (src/shared) */ -INCLUDE_ASM("asm/ov_SC04_011/nonmatchings/ov_SC04_011_jr_8015AE2C", func_8015B950); +extern s32 func_8015AE2C(); + +// @class: plumbing +// @stuck: none — MATCH (271/271, pin-free, zero asm). The ONLY residual is DEF-SIDE plumbing, and it is now named exactly: the in-TU instantiation `DEFINE_func_8015BEE4()` (engine_core.h:1851-1855) expands to `extern s32 func_8015B950(void);` INSIDE ov_SC01_077_jr_8015AE2C.c, ~14 lines BELOW this definition, so the 1-param def collides with a `(void)` prototype -> `conflicting types for func_8015B950` (.run/bank_func_8015B950.log). §73 PARAMS axis / T0. Surgical fix = §65b de-macroize that ONE instantiation (blast radius: this TU); the fleet-wide `(void)`->`()` header edit is §63 and must be R22-validated. +/* func_8015B950 (ov_SC01_077_jr_8015AE2C, 271 ins, jtbl_801D8B74) — SESSION-21 re-verified + * + * ── ROUND-2 INDEPENDENT RE-VERIFICATION (2026-07-27, fresh agent, §88e discipline) ───────────── + * match_one : MATCH (271 ins) against the CURRENT tree — §87 staleness re-checked today. + * .text size: compiled .text = 0x43C = 1084 B = 271 ins, EXACTLY the target's declared 0x43C + * ("nonmatching func_8015B950, 0x43C"). So this is NOT a §83a length drift hiding + * behind a zero count — the count is over equal-length streams. + * jtbl : RE-DECODED MECHANICALLY, not inherited. Compiled .rodata = 0x1C = 28 B = 7 words, + * 7x R_MIPS_32 -> .text with implicit addends [58,58,58,E0,F0,100,58]; +0x8015B950 + * = [8015B9A8, 8015B9A8, 8015B9A8, 8015BA30, 8015BA40, 8015BA50, 8015B9A8]. + * Diffed word-for-word against asm/ov_SC01_077/data/tail14.data.s:15-23 — 7/7 identical. + * symcheck : SYMS-DIFF target=35 draft=34, sole MISSING = jtbl_801D8B74. This is the §81 jr + * FALSE POSITIVE, re-confirmed here by reading the relocs: gcc emits its OWN table and + * references it with R_MIPS_HI16/LO16 against the SECTION `.rodata` (t.o +0x40/+0x48), + * so the splat's dlabel NAME can never appear in the draft object's relocation set. + * Nothing is dropped and nothing is invented: the draft's other 34 symbols are exactly + * the target's other 34. + * FAMILY : the x138 remap is clean and §84-safe. Every sibling is 271 ins with an IDENTICAL + * callee set; only THREE names vary per overlay — the two data labels and the jtbl: + * ov_SC01_077 D_80192A5C / D_80192AC8 / jtbl_801D8B74 + * ov_SC03_099 D_80185A50 / D_80185ABC / jtbl_801BD898 + * ov_SC06_008 D_80187E44 / D_80187EB0 / jtbl_801A8734 + * The pair is always +0x6C apart, and NO literal in this draft encodes that distance + * (both labels are referenced by name), so there is no §84 derived-offset hazard. + * D_8011F9C4 is fleet-constant (main-EXE data) and must NOT be remapped. + * + * match_one: MATCH (271 ins) against the CURRENT tree (§87 staleness re-checked, 2026-07-27). + * PIN-FREE, zero asm, offset-pure (s32 arg0 + raw offsets) — x138 template-safe. + * Provenance: this is the Phase-26 crack (.run/phase26-cracks/func_8015B950.c) re-gated verbatim, + * with ONE deliberate change: the definition's return type void -> s32. + * - `void func_8015B950(s32 arg0)` : MATCH (271 ins) [the Phase-26 form] + * - `s32 func_8015B950(s32 arg0)` : MATCH (271 ins) [shipped — §3a-1 void->s32 is byte-neutral] + * The fleet/engine_core.h canonical decl is `extern s32 func_8015B950(void);` (engine_core.h:1852), + * and the last bank attempt (.run/bank_func_8015B950.log) died on `conflicting types for + * func_8015B950`. Shipping the s32 return kills the §73 RETURN axis for free and leaves only the + * cheap T0 PARAMS axis for the ladder (fix_header_decl.py / --fix-def-sig / cast_call_sites). + * Both forms are byte-identical, so the orchestrator may swap the return type back at zero cost. + * + * SYMBOLS (§58 rules 1/2 — all splat spellings, all verified present): + * D_80192AC8 asm/ov_SC01_077/data/tail.data.s:4355 (the state-handler vtable) + * D_80192A5C asm/ov_SC01_077/data/tail.data.s:4293 + * D_8011F9C4 main-EXE data; spelled `extern s32 D_8011F9C4;` in 5+ already-banked TUs + * jtbl_801D8B74 asm/ov_SC01_077/data/tail14.data.s:15 (compiler jump table — not named in C) + * + * JTBL VERIFIED (§8a gate): compiled .rodata = exactly 0x1C B / 7 words, 7x R_MIPS_32 .text with + * addends [0x58,0x58,0x58,0xE0,0xF0,0x100,0x58] -> +0x8015B950 = [B9A8,B9A8,B9A8,BA30,BA40,BA50, + * B9A8] == the original words at 0x801D8B74..0x801D8B8C. Bound `sltiu $v0,$v1,0x7` matches. + * The raw dlabel's 8th word 0x00000000 is NOT an entry — it is the intra-TU `.align 3` pad of the + * B34/B54/B74 jtbl chain; the object can never emit it (maspsx drops .align), so it must stay in + * the post-carve RAW data piece (the §53/§62/§81 carve chain applies at bank time). + * + * Same family as the TU's own already-matched func_8015AE2C: 7-case switch on ((s32 (*)(s32))func_801619A4)() + * (0/1/2/6 shared, 3/4/5 own, no default block — out-of-range and every `break` fall to the + * after-switch join), then a chain of "state handler" tests, each dispatching + * D_80192AC8[*(u16*)arg0](arg0) and returning. + * + * THREE LEVERS (draft -> MATCH in 3 compiles): + * + * 1. PROLOGUE CONSTANT = an INITIALIZED LOCAL, not a literal in the compare. + * Target opens with `lui $s2, 0xFFF5` in the *prologue*, used once ~200 ins later in + * `slt $v0,$s2,$s1`. No gcc-2.7.2 pass hoists a (set reg const_int) across basic blocks + * (loop.c needs a loop; cse/combine/sched never move insns between BBs) — so the insn must + * have been EMITTED in the first BB, i.e. the constant is a local initialized at the top of + * the function. cse then cannot fold it back into the compare: the `slt` operand predicate is + * `arith_operand`, which rejects a CONST_INT wider than 16 bits, so validate_change fails and + * the pseudo survives. Its live range spans every call -> global.c gives it a callee-saved reg. + * Writing `z > -0xB0000` inline instead emits the `lui` into the branch delay slot next to the + * compare (caller-saved $v0) and the function is 1 insn short. => `s32 lim = -0xB0000;` at top. + * + * 2. `lh` vs `lhu`: a short->short copy is a pure HImode move and gcc emits `lhu`. The target's + * `lh $v0,0x26($s0)` means the value passed through an SImode (int) temp: expand makes + * (set (reg:SI) (sign_extend (mem:HI))) + (set (mem:HI) (subreg:HI ...)), and combine cannot + * merge them (the merged form is mem<-mem, which no movhi accepts) so the sign-extending load + * survives. => route both halfword copies through the `s32 t` temp. + * + * 3. THE `goto` LAYOUT — dodging jump.c's store-flag conversion (jump.c:1005-1065). + * An if/else chain writing 0/1 into `doit` makes gcc collapse the last pair into + * `sltiu $v0,$v0,1`. jump.c fires that conversion when the insn immediately after a + * conditional jump is a lone `SET pseudo, CONST_INT` whose following simplejump targets the + * SAME label as the branch (jump.c:1038 `reallabelprev == temp || ... JUMP_LABEL(temp4) == + * JUMP_LABEL(insn)`) — exactly the shape of `if (c) x=0; else x=1;`. + * The target instead cross-jumps ALL the `doit=0` exits into ONE shared block placed after the + * `doit=1` fall-through; reorg's fill_slots_from_thread then COPIES that single set into all + * three branch delay slots and redirects each branch past it (which is why `addu $v0,$zero, + * $zero` appears 3x in delay slots and the shared block vanishes). A `goto zero;` / `goto one;` + * chain expresses that layout directly, and each conditional jump is then followed by a + * compare/call rather than a lone const set, so the store-flag conversion never triggers. + * GENERAL RULE: multiple predicates that all assign the SAME constant to one flag => write + * them as `goto` to a shared assignment, never as an if/else ladder. + */ +extern s32 D_8011F9C4; +extern s32 D_80192A5C; + +extern s32 func_80161B18(void); +extern s32 func_801619A4(s32*); +extern s32 func_80149AA8(s32*); +extern void func_80149AD4(s32*); +extern s32 func_80149B54(s32*); +extern void func_80149BAC(s32*); +extern s32 func_801498E0(s32*); +extern s32 func_80149954(s32); +extern s32 func_80149A64(s32*); +extern void func_800CCCC0(s32 a0); +extern s32 func_80149CD4(s32 a0); +extern void func_8015E880(s32*); +extern s32 func_80149744(struct S_80149744*); +extern void func_80149788(void); +extern s32 func_801496D4(void*); +extern void func_80149704(void); +extern int func_80148AFC(void*); +extern void func_80146D90(s32 a0); +extern void func_80154150(s32 a0, s32 a1); +extern void func_801541D8(u8*, s32, s32); +extern s32 func_801488A8(u8*); +extern void func_80147078(s32*, s16); +extern void func_8015A264(void*); +extern s32 func_80013294(void*, void*); +extern void func_80159B70(void*); +extern s32 func_8016F1AC(void); +extern s32 func_80029178(s32 a0); +extern void func_80146DB8(s32*, s32*); +extern s32 func_80161CD0(s32, s32); +extern s32 func_80161208(s32 a0); +extern s32 func_801725A4(u8*); + +s32 func_8015B950(s32 arg0) +{ + + extern void (*D_80192AC8[])(void *); + s16 sp10[4]; + s16 sp18[4]; + s32 t; + s32 z; + s32 doit; + s32 lim = -0xB0000; + + if (func_80161B18() != 0) { + return; + } + switch (((s32 (*)(s32))func_801619A4)(arg0)) { + case 0: + case 1: + case 2: + case 6: + if (((s32 (*)(s32))func_80149AA8)(arg0) != 0) { + D_80192AC8[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149AD4)(arg0); + return; + } + if (((s32 (*)(s32))func_80149B54)(arg0) != 0) { + D_80192AC8[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149BAC)(arg0); + return; + } + break; + case 3: + ((void (*)(s32))func_801498E0)(arg0); + break; + case 4: + ((void (*)(s32))func_80149954)(arg0); + break; + case 5: + if (((s32 (*)(s32))func_80149A64)(arg0) != 0) { + D_80192AC8[*(u16 *)arg0]((void *)arg0); + func_800CCCC0(arg0); + return; + } + break; + } + if (func_80149CD4(arg0) != 0) { + D_80192AC8[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_8015E880)(arg0); + return; + } + if (((s32 (*)(s32))func_80149744)(arg0) != 0) { + D_80192AC8[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149788)(arg0); + return; + } + if (((s32 (*)(s32))func_801496D4)(arg0) != 0) { + D_80192AC8[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149704)(arg0); + if (((u8)((s32 (*)(s32))func_80148AFC)(arg0)) == 0) { + func_80146D90(arg0); + } + if ((*(s32 *)(arg0 + 0x24) | *(s32 *)(arg0 + 0x2C)) != 0) { + func_80154150(arg0, 0xF); + } else { + ((void (*)(s32, s32, s32))func_801541D8)(arg0, 0xD, 6); + } + *(s32 *)(arg0 + 0x238) = 1; + return; + } + if (((s32 (*)(s32))func_801488A8)(arg0) != 0) { + sp10[0] = 0; + sp10[1] = 0; + sp10[2] = 0; + t = *(s16 *)(arg0 + 0x26); + sp18[0] = t; + sp18[1] = 0; + t = *(s16 *)(arg0 + 0x2E); + sp18[2] = t; + D_80192AC8[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 1); + ((void (*)(s32))func_8015A264)(arg0); + t = -(((s32 (*)(s16 *, s16 *))func_80013294)(sp10, sp18) << 0x10); + if (t < *(s32 *)(arg0 + 0x2C)) { + *(s32 *)(arg0 + 0x2C) = t; + } + return; + } + if (*(u16 *)(arg0 + 0xB8) == 0x8000) { + D_80192AC8[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 0); + ((void (*)(s32))func_80159B70)(arg0); + return; + } + z = *(s32 *)(arg0 + 0x2C); + if (func_8016F1AC() != 0) { + goto zero; + } + if (z <= lim) { + goto one; + } + if (D_8011F9C4 == 0) { + goto zero; + } + if (((u8)func_80029178(0x21)) != 0) { + goto zero; + } +one: + doit = 1; + goto join; +zero: + doit = 0; +join: + if (doit != 0) { + D_80192AC8[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 0); + ((void (*)(s32))func_80159B70)(arg0); + func_80154150(arg0, 9); + ((void (*)(s32, s32 *))func_80146DB8)(arg0, &D_80192A5C); + ((void (*)(s32, s32))func_80161CD0)(arg0, *(u16 *)(arg0 + 0x16E)); + return; + } + if (func_80161208(arg0) == 0) { + ((void (*)(s32))func_801725A4)(arg0); + } +} DEFINE_func_8015BD8C() /* dedup: shared engine-core @0x8015BD8C (src/shared) */ diff --git a/src/ov_SC04_012/ov_SC04_012_jr_8015AE2C.c b/src/ov_SC04_012/ov_SC04_012_jr_8015AE2C.c index c6af2fec5..b2a575517 100644 --- a/src/ov_SC04_012/ov_SC04_012_jr_8015AE2C.c +++ b/src/ov_SC04_012/ov_SC04_012_jr_8015AE2C.c @@ -1512,7 +1512,259 @@ DEFINE_func_8015B858() /* dedup: shared engine-core @0x8015B858 (src/shared) */ DEFINE_func_8015B8F8() /* dedup: shared engine-core @0x8015B8F8 (src/shared) */ -INCLUDE_ASM("asm/ov_SC04_012/nonmatchings/ov_SC04_012_jr_8015AE2C", func_8015B950); +extern s32 func_8015AE2C(); + +// @class: plumbing +// @stuck: none — MATCH (271/271, pin-free, zero asm). The ONLY residual is DEF-SIDE plumbing, and it is now named exactly: the in-TU instantiation `DEFINE_func_8015BEE4()` (engine_core.h:1851-1855) expands to `extern s32 func_8015B950(void);` INSIDE ov_SC01_077_jr_8015AE2C.c, ~14 lines BELOW this definition, so the 1-param def collides with a `(void)` prototype -> `conflicting types for func_8015B950` (.run/bank_func_8015B950.log). §73 PARAMS axis / T0. Surgical fix = §65b de-macroize that ONE instantiation (blast radius: this TU); the fleet-wide `(void)`->`()` header edit is §63 and must be R22-validated. +/* func_8015B950 (ov_SC01_077_jr_8015AE2C, 271 ins, jtbl_801D8B74) — SESSION-21 re-verified + * + * ── ROUND-2 INDEPENDENT RE-VERIFICATION (2026-07-27, fresh agent, §88e discipline) ───────────── + * match_one : MATCH (271 ins) against the CURRENT tree — §87 staleness re-checked today. + * .text size: compiled .text = 0x43C = 1084 B = 271 ins, EXACTLY the target's declared 0x43C + * ("nonmatching func_8015B950, 0x43C"). So this is NOT a §83a length drift hiding + * behind a zero count — the count is over equal-length streams. + * jtbl : RE-DECODED MECHANICALLY, not inherited. Compiled .rodata = 0x1C = 28 B = 7 words, + * 7x R_MIPS_32 -> .text with implicit addends [58,58,58,E0,F0,100,58]; +0x8015B950 + * = [8015B9A8, 8015B9A8, 8015B9A8, 8015BA30, 8015BA40, 8015BA50, 8015B9A8]. + * Diffed word-for-word against asm/ov_SC01_077/data/tail14.data.s:15-23 — 7/7 identical. + * symcheck : SYMS-DIFF target=35 draft=34, sole MISSING = jtbl_801D8B74. This is the §81 jr + * FALSE POSITIVE, re-confirmed here by reading the relocs: gcc emits its OWN table and + * references it with R_MIPS_HI16/LO16 against the SECTION `.rodata` (t.o +0x40/+0x48), + * so the splat's dlabel NAME can never appear in the draft object's relocation set. + * Nothing is dropped and nothing is invented: the draft's other 34 symbols are exactly + * the target's other 34. + * FAMILY : the x138 remap is clean and §84-safe. Every sibling is 271 ins with an IDENTICAL + * callee set; only THREE names vary per overlay — the two data labels and the jtbl: + * ov_SC01_077 D_80180C30 / D_80180C9C / jtbl_801D8B74 + * ov_SC03_099 D_80185A50 / D_80185ABC / jtbl_801BD898 + * ov_SC06_008 D_80187E44 / D_80187EB0 / jtbl_801A8734 + * The pair is always +0x6C apart, and NO literal in this draft encodes that distance + * (both labels are referenced by name), so there is no §84 derived-offset hazard. + * D_8011F9C4 is fleet-constant (main-EXE data) and must NOT be remapped. + * + * match_one: MATCH (271 ins) against the CURRENT tree (§87 staleness re-checked, 2026-07-27). + * PIN-FREE, zero asm, offset-pure (s32 arg0 + raw offsets) — x138 template-safe. + * Provenance: this is the Phase-26 crack (.run/phase26-cracks/func_8015B950.c) re-gated verbatim, + * with ONE deliberate change: the definition's return type void -> s32. + * - `void func_8015B950(s32 arg0)` : MATCH (271 ins) [the Phase-26 form] + * - `s32 func_8015B950(s32 arg0)` : MATCH (271 ins) [shipped — §3a-1 void->s32 is byte-neutral] + * The fleet/engine_core.h canonical decl is `extern s32 func_8015B950(void);` (engine_core.h:1852), + * and the last bank attempt (.run/bank_func_8015B950.log) died on `conflicting types for + * func_8015B950`. Shipping the s32 return kills the §73 RETURN axis for free and leaves only the + * cheap T0 PARAMS axis for the ladder (fix_header_decl.py / --fix-def-sig / cast_call_sites). + * Both forms are byte-identical, so the orchestrator may swap the return type back at zero cost. + * + * SYMBOLS (§58 rules 1/2 — all splat spellings, all verified present): + * D_80180C9C asm/ov_SC01_077/data/tail.data.s:4355 (the state-handler vtable) + * D_80180C30 asm/ov_SC01_077/data/tail.data.s:4293 + * D_8011F9C4 main-EXE data; spelled `extern s32 D_8011F9C4;` in 5+ already-banked TUs + * jtbl_801D8B74 asm/ov_SC01_077/data/tail14.data.s:15 (compiler jump table — not named in C) + * + * JTBL VERIFIED (§8a gate): compiled .rodata = exactly 0x1C B / 7 words, 7x R_MIPS_32 .text with + * addends [0x58,0x58,0x58,0xE0,0xF0,0x100,0x58] -> +0x8015B950 = [B9A8,B9A8,B9A8,BA30,BA40,BA50, + * B9A8] == the original words at 0x801D8B74..0x801D8B8C. Bound `sltiu $v0,$v1,0x7` matches. + * The raw dlabel's 8th word 0x00000000 is NOT an entry — it is the intra-TU `.align 3` pad of the + * B34/B54/B74 jtbl chain; the object can never emit it (maspsx drops .align), so it must stay in + * the post-carve RAW data piece (the §53/§62/§81 carve chain applies at bank time). + * + * Same family as the TU's own already-matched func_8015AE2C: 7-case switch on ((s32 (*)(s32))func_801619A4)() + * (0/1/2/6 shared, 3/4/5 own, no default block — out-of-range and every `break` fall to the + * after-switch join), then a chain of "state handler" tests, each dispatching + * D_80180C9C[*(u16*)arg0](arg0) and returning. + * + * THREE LEVERS (draft -> MATCH in 3 compiles): + * + * 1. PROLOGUE CONSTANT = an INITIALIZED LOCAL, not a literal in the compare. + * Target opens with `lui $s2, 0xFFF5` in the *prologue*, used once ~200 ins later in + * `slt $v0,$s2,$s1`. No gcc-2.7.2 pass hoists a (set reg const_int) across basic blocks + * (loop.c needs a loop; cse/combine/sched never move insns between BBs) — so the insn must + * have been EMITTED in the first BB, i.e. the constant is a local initialized at the top of + * the function. cse then cannot fold it back into the compare: the `slt` operand predicate is + * `arith_operand`, which rejects a CONST_INT wider than 16 bits, so validate_change fails and + * the pseudo survives. Its live range spans every call -> global.c gives it a callee-saved reg. + * Writing `z > -0xB0000` inline instead emits the `lui` into the branch delay slot next to the + * compare (caller-saved $v0) and the function is 1 insn short. => `s32 lim = -0xB0000;` at top. + * + * 2. `lh` vs `lhu`: a short->short copy is a pure HImode move and gcc emits `lhu`. The target's + * `lh $v0,0x26($s0)` means the value passed through an SImode (int) temp: expand makes + * (set (reg:SI) (sign_extend (mem:HI))) + (set (mem:HI) (subreg:HI ...)), and combine cannot + * merge them (the merged form is mem<-mem, which no movhi accepts) so the sign-extending load + * survives. => route both halfword copies through the `s32 t` temp. + * + * 3. THE `goto` LAYOUT — dodging jump.c's store-flag conversion (jump.c:1005-1065). + * An if/else chain writing 0/1 into `doit` makes gcc collapse the last pair into + * `sltiu $v0,$v0,1`. jump.c fires that conversion when the insn immediately after a + * conditional jump is a lone `SET pseudo, CONST_INT` whose following simplejump targets the + * SAME label as the branch (jump.c:1038 `reallabelprev == temp || ... JUMP_LABEL(temp4) == + * JUMP_LABEL(insn)`) — exactly the shape of `if (c) x=0; else x=1;`. + * The target instead cross-jumps ALL the `doit=0` exits into ONE shared block placed after the + * `doit=1` fall-through; reorg's fill_slots_from_thread then COPIES that single set into all + * three branch delay slots and redirects each branch past it (which is why `addu $v0,$zero, + * $zero` appears 3x in delay slots and the shared block vanishes). A `goto zero;` / `goto one;` + * chain expresses that layout directly, and each conditional jump is then followed by a + * compare/call rather than a lone const set, so the store-flag conversion never triggers. + * GENERAL RULE: multiple predicates that all assign the SAME constant to one flag => write + * them as `goto` to a shared assignment, never as an if/else ladder. + */ +extern s32 D_8011F9C4; +extern s32 D_80180C30; + +extern s32 func_80161B18(void); +extern s32 func_801619A4(s32*); +extern s32 func_80149AA8(s32*); +extern void func_80149AD4(s32*); +extern s32 func_80149B54(s32*); +extern void func_80149BAC(s32*); +extern s32 func_801498E0(s32*); +extern s32 func_80149954(s32); +extern s32 func_80149A64(s32*); +extern void func_800CCCC0(s32 a0); +extern s32 func_80149CD4(s32 a0); +extern void func_8015E880(s32*); +extern s32 func_80149744(struct S_80149744*); +extern void func_80149788(void); +extern s32 func_801496D4(void*); +extern void func_80149704(void); +extern int func_80148AFC(void*); +extern void func_80146D90(s32 a0); +extern void func_80154150(s32 a0, s32 a1); +extern void func_801541D8(u8*, s32, s32); +extern s32 func_801488A8(u8*); +extern void func_80147078(s32*, s16); +extern void func_8015A264(void*); +extern s32 func_80013294(void*, void*); +extern void func_80159B70(void*); +extern s32 func_8016F1AC(void); +extern s32 func_80029178(s32 a0); +extern void func_80146DB8(s32*, s32*); +extern s32 func_80161CD0(s32, s32); +extern s32 func_80161208(s32 a0); +extern s32 func_801725A4(u8*); + +s32 func_8015B950(s32 arg0) +{ + + extern void (*D_80180C9C[])(void *); + s16 sp10[4]; + s16 sp18[4]; + s32 t; + s32 z; + s32 doit; + s32 lim = -0xB0000; + + if (func_80161B18() != 0) { + return; + } + switch (((s32 (*)(s32))func_801619A4)(arg0)) { + case 0: + case 1: + case 2: + case 6: + if (((s32 (*)(s32))func_80149AA8)(arg0) != 0) { + D_80180C9C[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149AD4)(arg0); + return; + } + if (((s32 (*)(s32))func_80149B54)(arg0) != 0) { + D_80180C9C[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149BAC)(arg0); + return; + } + break; + case 3: + ((void (*)(s32))func_801498E0)(arg0); + break; + case 4: + ((void (*)(s32))func_80149954)(arg0); + break; + case 5: + if (((s32 (*)(s32))func_80149A64)(arg0) != 0) { + D_80180C9C[*(u16 *)arg0]((void *)arg0); + func_800CCCC0(arg0); + return; + } + break; + } + if (func_80149CD4(arg0) != 0) { + D_80180C9C[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_8015E880)(arg0); + return; + } + if (((s32 (*)(s32))func_80149744)(arg0) != 0) { + D_80180C9C[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149788)(arg0); + return; + } + if (((s32 (*)(s32))func_801496D4)(arg0) != 0) { + D_80180C9C[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149704)(arg0); + if (((u8)((s32 (*)(s32))func_80148AFC)(arg0)) == 0) { + func_80146D90(arg0); + } + if ((*(s32 *)(arg0 + 0x24) | *(s32 *)(arg0 + 0x2C)) != 0) { + func_80154150(arg0, 0xF); + } else { + ((void (*)(s32, s32, s32))func_801541D8)(arg0, 0xD, 6); + } + *(s32 *)(arg0 + 0x238) = 1; + return; + } + if (((s32 (*)(s32))func_801488A8)(arg0) != 0) { + sp10[0] = 0; + sp10[1] = 0; + sp10[2] = 0; + t = *(s16 *)(arg0 + 0x26); + sp18[0] = t; + sp18[1] = 0; + t = *(s16 *)(arg0 + 0x2E); + sp18[2] = t; + D_80180C9C[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 1); + ((void (*)(s32))func_8015A264)(arg0); + t = -(((s32 (*)(s16 *, s16 *))func_80013294)(sp10, sp18) << 0x10); + if (t < *(s32 *)(arg0 + 0x2C)) { + *(s32 *)(arg0 + 0x2C) = t; + } + return; + } + if (*(u16 *)(arg0 + 0xB8) == 0x8000) { + D_80180C9C[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 0); + ((void (*)(s32))func_80159B70)(arg0); + return; + } + z = *(s32 *)(arg0 + 0x2C); + if (func_8016F1AC() != 0) { + goto zero; + } + if (z <= lim) { + goto one; + } + if (D_8011F9C4 == 0) { + goto zero; + } + if (((u8)func_80029178(0x21)) != 0) { + goto zero; + } +one: + doit = 1; + goto join; +zero: + doit = 0; +join: + if (doit != 0) { + D_80180C9C[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 0); + ((void (*)(s32))func_80159B70)(arg0); + func_80154150(arg0, 9); + ((void (*)(s32, s32 *))func_80146DB8)(arg0, &D_80180C30); + ((void (*)(s32, s32))func_80161CD0)(arg0, *(u16 *)(arg0 + 0x16E)); + return; + } + if (func_80161208(arg0) == 0) { + ((void (*)(s32))func_801725A4)(arg0); + } +} DEFINE_func_8015BD8C() /* dedup: shared engine-core @0x8015BD8C (src/shared) */ diff --git a/src/ov_SC04_015/ov_SC04_015_jr_8015AE2C.c b/src/ov_SC04_015/ov_SC04_015_jr_8015AE2C.c index 400ff0b1d..d8ddc641e 100644 --- a/src/ov_SC04_015/ov_SC04_015_jr_8015AE2C.c +++ b/src/ov_SC04_015/ov_SC04_015_jr_8015AE2C.c @@ -1512,7 +1512,259 @@ DEFINE_func_8015B858() /* dedup: shared engine-core @0x8015B858 (src/shared) */ DEFINE_func_8015B8F8() /* dedup: shared engine-core @0x8015B8F8 (src/shared) */ -INCLUDE_ASM("asm/ov_SC04_015/nonmatchings/ov_SC04_015_jr_8015AE2C", func_8015B950); +extern s32 func_8015AE2C(); + +// @class: plumbing +// @stuck: none — MATCH (271/271, pin-free, zero asm). The ONLY residual is DEF-SIDE plumbing, and it is now named exactly: the in-TU instantiation `DEFINE_func_8015BEE4()` (engine_core.h:1851-1855) expands to `extern s32 func_8015B950(void);` INSIDE ov_SC01_077_jr_8015AE2C.c, ~14 lines BELOW this definition, so the 1-param def collides with a `(void)` prototype -> `conflicting types for func_8015B950` (.run/bank_func_8015B950.log). §73 PARAMS axis / T0. Surgical fix = §65b de-macroize that ONE instantiation (blast radius: this TU); the fleet-wide `(void)`->`()` header edit is §63 and must be R22-validated. +/* func_8015B950 (ov_SC01_077_jr_8015AE2C, 271 ins, jtbl_801D8B74) — SESSION-21 re-verified + * + * ── ROUND-2 INDEPENDENT RE-VERIFICATION (2026-07-27, fresh agent, §88e discipline) ───────────── + * match_one : MATCH (271 ins) against the CURRENT tree — §87 staleness re-checked today. + * .text size: compiled .text = 0x43C = 1084 B = 271 ins, EXACTLY the target's declared 0x43C + * ("nonmatching func_8015B950, 0x43C"). So this is NOT a §83a length drift hiding + * behind a zero count — the count is over equal-length streams. + * jtbl : RE-DECODED MECHANICALLY, not inherited. Compiled .rodata = 0x1C = 28 B = 7 words, + * 7x R_MIPS_32 -> .text with implicit addends [58,58,58,E0,F0,100,58]; +0x8015B950 + * = [8015B9A8, 8015B9A8, 8015B9A8, 8015BA30, 8015BA40, 8015BA50, 8015B9A8]. + * Diffed word-for-word against asm/ov_SC01_077/data/tail14.data.s:15-23 — 7/7 identical. + * symcheck : SYMS-DIFF target=35 draft=34, sole MISSING = jtbl_801D8B74. This is the §81 jr + * FALSE POSITIVE, re-confirmed here by reading the relocs: gcc emits its OWN table and + * references it with R_MIPS_HI16/LO16 against the SECTION `.rodata` (t.o +0x40/+0x48), + * so the splat's dlabel NAME can never appear in the draft object's relocation set. + * Nothing is dropped and nothing is invented: the draft's other 34 symbols are exactly + * the target's other 34. + * FAMILY : the x138 remap is clean and §84-safe. Every sibling is 271 ins with an IDENTICAL + * callee set; only THREE names vary per overlay — the two data labels and the jtbl: + * ov_SC01_077 D_80186B68 / D_80186BD4 / jtbl_801D8B74 + * ov_SC03_099 D_80185A50 / D_80185ABC / jtbl_801BD898 + * ov_SC06_008 D_80187E44 / D_80187EB0 / jtbl_801A8734 + * The pair is always +0x6C apart, and NO literal in this draft encodes that distance + * (both labels are referenced by name), so there is no §84 derived-offset hazard. + * D_8011F9C4 is fleet-constant (main-EXE data) and must NOT be remapped. + * + * match_one: MATCH (271 ins) against the CURRENT tree (§87 staleness re-checked, 2026-07-27). + * PIN-FREE, zero asm, offset-pure (s32 arg0 + raw offsets) — x138 template-safe. + * Provenance: this is the Phase-26 crack (.run/phase26-cracks/func_8015B950.c) re-gated verbatim, + * with ONE deliberate change: the definition's return type void -> s32. + * - `void func_8015B950(s32 arg0)` : MATCH (271 ins) [the Phase-26 form] + * - `s32 func_8015B950(s32 arg0)` : MATCH (271 ins) [shipped — §3a-1 void->s32 is byte-neutral] + * The fleet/engine_core.h canonical decl is `extern s32 func_8015B950(void);` (engine_core.h:1852), + * and the last bank attempt (.run/bank_func_8015B950.log) died on `conflicting types for + * func_8015B950`. Shipping the s32 return kills the §73 RETURN axis for free and leaves only the + * cheap T0 PARAMS axis for the ladder (fix_header_decl.py / --fix-def-sig / cast_call_sites). + * Both forms are byte-identical, so the orchestrator may swap the return type back at zero cost. + * + * SYMBOLS (§58 rules 1/2 — all splat spellings, all verified present): + * D_80186BD4 asm/ov_SC01_077/data/tail.data.s:4355 (the state-handler vtable) + * D_80186B68 asm/ov_SC01_077/data/tail.data.s:4293 + * D_8011F9C4 main-EXE data; spelled `extern s32 D_8011F9C4;` in 5+ already-banked TUs + * jtbl_801D8B74 asm/ov_SC01_077/data/tail14.data.s:15 (compiler jump table — not named in C) + * + * JTBL VERIFIED (§8a gate): compiled .rodata = exactly 0x1C B / 7 words, 7x R_MIPS_32 .text with + * addends [0x58,0x58,0x58,0xE0,0xF0,0x100,0x58] -> +0x8015B950 = [B9A8,B9A8,B9A8,BA30,BA40,BA50, + * B9A8] == the original words at 0x801D8B74..0x801D8B8C. Bound `sltiu $v0,$v1,0x7` matches. + * The raw dlabel's 8th word 0x00000000 is NOT an entry — it is the intra-TU `.align 3` pad of the + * B34/B54/B74 jtbl chain; the object can never emit it (maspsx drops .align), so it must stay in + * the post-carve RAW data piece (the §53/§62/§81 carve chain applies at bank time). + * + * Same family as the TU's own already-matched func_8015AE2C: 7-case switch on ((s32 (*)(s32))func_801619A4)() + * (0/1/2/6 shared, 3/4/5 own, no default block — out-of-range and every `break` fall to the + * after-switch join), then a chain of "state handler" tests, each dispatching + * D_80186BD4[*(u16*)arg0](arg0) and returning. + * + * THREE LEVERS (draft -> MATCH in 3 compiles): + * + * 1. PROLOGUE CONSTANT = an INITIALIZED LOCAL, not a literal in the compare. + * Target opens with `lui $s2, 0xFFF5` in the *prologue*, used once ~200 ins later in + * `slt $v0,$s2,$s1`. No gcc-2.7.2 pass hoists a (set reg const_int) across basic blocks + * (loop.c needs a loop; cse/combine/sched never move insns between BBs) — so the insn must + * have been EMITTED in the first BB, i.e. the constant is a local initialized at the top of + * the function. cse then cannot fold it back into the compare: the `slt` operand predicate is + * `arith_operand`, which rejects a CONST_INT wider than 16 bits, so validate_change fails and + * the pseudo survives. Its live range spans every call -> global.c gives it a callee-saved reg. + * Writing `z > -0xB0000` inline instead emits the `lui` into the branch delay slot next to the + * compare (caller-saved $v0) and the function is 1 insn short. => `s32 lim = -0xB0000;` at top. + * + * 2. `lh` vs `lhu`: a short->short copy is a pure HImode move and gcc emits `lhu`. The target's + * `lh $v0,0x26($s0)` means the value passed through an SImode (int) temp: expand makes + * (set (reg:SI) (sign_extend (mem:HI))) + (set (mem:HI) (subreg:HI ...)), and combine cannot + * merge them (the merged form is mem<-mem, which no movhi accepts) so the sign-extending load + * survives. => route both halfword copies through the `s32 t` temp. + * + * 3. THE `goto` LAYOUT — dodging jump.c's store-flag conversion (jump.c:1005-1065). + * An if/else chain writing 0/1 into `doit` makes gcc collapse the last pair into + * `sltiu $v0,$v0,1`. jump.c fires that conversion when the insn immediately after a + * conditional jump is a lone `SET pseudo, CONST_INT` whose following simplejump targets the + * SAME label as the branch (jump.c:1038 `reallabelprev == temp || ... JUMP_LABEL(temp4) == + * JUMP_LABEL(insn)`) — exactly the shape of `if (c) x=0; else x=1;`. + * The target instead cross-jumps ALL the `doit=0` exits into ONE shared block placed after the + * `doit=1` fall-through; reorg's fill_slots_from_thread then COPIES that single set into all + * three branch delay slots and redirects each branch past it (which is why `addu $v0,$zero, + * $zero` appears 3x in delay slots and the shared block vanishes). A `goto zero;` / `goto one;` + * chain expresses that layout directly, and each conditional jump is then followed by a + * compare/call rather than a lone const set, so the store-flag conversion never triggers. + * GENERAL RULE: multiple predicates that all assign the SAME constant to one flag => write + * them as `goto` to a shared assignment, never as an if/else ladder. + */ +extern s32 D_8011F9C4; +extern s32 D_80186B68; + +extern s32 func_80161B18(void); +extern s32 func_801619A4(s32*); +extern s32 func_80149AA8(s32*); +extern void func_80149AD4(s32*); +extern s32 func_80149B54(s32*); +extern void func_80149BAC(s32*); +extern s32 func_801498E0(s32*); +extern s32 func_80149954(s32); +extern s32 func_80149A64(s32*); +extern void func_800CCCC0(s32 a0); +extern s32 func_80149CD4(s32 a0); +extern void func_8015E880(s32*); +extern s32 func_80149744(struct S_80149744*); +extern void func_80149788(void); +extern s32 func_801496D4(void*); +extern void func_80149704(void); +extern int func_80148AFC(void*); +extern void func_80146D90(s32 a0); +extern void func_80154150(s32 a0, s32 a1); +extern void func_801541D8(u8*, s32, s32); +extern s32 func_801488A8(u8*); +extern void func_80147078(s32*, s16); +extern void func_8015A264(void*); +extern s32 func_80013294(void*, void*); +extern void func_80159B70(void*); +extern s32 func_8016F1AC(void); +extern s32 func_80029178(s32 a0); +extern void func_80146DB8(s32*, s32*); +extern s32 func_80161CD0(s32, s32); +extern s32 func_80161208(s32 a0); +extern s32 func_801725A4(u8*); + +s32 func_8015B950(s32 arg0) +{ + + extern void (*D_80186BD4[])(void *); + s16 sp10[4]; + s16 sp18[4]; + s32 t; + s32 z; + s32 doit; + s32 lim = -0xB0000; + + if (func_80161B18() != 0) { + return; + } + switch (((s32 (*)(s32))func_801619A4)(arg0)) { + case 0: + case 1: + case 2: + case 6: + if (((s32 (*)(s32))func_80149AA8)(arg0) != 0) { + D_80186BD4[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149AD4)(arg0); + return; + } + if (((s32 (*)(s32))func_80149B54)(arg0) != 0) { + D_80186BD4[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149BAC)(arg0); + return; + } + break; + case 3: + ((void (*)(s32))func_801498E0)(arg0); + break; + case 4: + ((void (*)(s32))func_80149954)(arg0); + break; + case 5: + if (((s32 (*)(s32))func_80149A64)(arg0) != 0) { + D_80186BD4[*(u16 *)arg0]((void *)arg0); + func_800CCCC0(arg0); + return; + } + break; + } + if (func_80149CD4(arg0) != 0) { + D_80186BD4[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_8015E880)(arg0); + return; + } + if (((s32 (*)(s32))func_80149744)(arg0) != 0) { + D_80186BD4[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149788)(arg0); + return; + } + if (((s32 (*)(s32))func_801496D4)(arg0) != 0) { + D_80186BD4[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149704)(arg0); + if (((u8)((s32 (*)(s32))func_80148AFC)(arg0)) == 0) { + func_80146D90(arg0); + } + if ((*(s32 *)(arg0 + 0x24) | *(s32 *)(arg0 + 0x2C)) != 0) { + func_80154150(arg0, 0xF); + } else { + ((void (*)(s32, s32, s32))func_801541D8)(arg0, 0xD, 6); + } + *(s32 *)(arg0 + 0x238) = 1; + return; + } + if (((s32 (*)(s32))func_801488A8)(arg0) != 0) { + sp10[0] = 0; + sp10[1] = 0; + sp10[2] = 0; + t = *(s16 *)(arg0 + 0x26); + sp18[0] = t; + sp18[1] = 0; + t = *(s16 *)(arg0 + 0x2E); + sp18[2] = t; + D_80186BD4[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 1); + ((void (*)(s32))func_8015A264)(arg0); + t = -(((s32 (*)(s16 *, s16 *))func_80013294)(sp10, sp18) << 0x10); + if (t < *(s32 *)(arg0 + 0x2C)) { + *(s32 *)(arg0 + 0x2C) = t; + } + return; + } + if (*(u16 *)(arg0 + 0xB8) == 0x8000) { + D_80186BD4[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 0); + ((void (*)(s32))func_80159B70)(arg0); + return; + } + z = *(s32 *)(arg0 + 0x2C); + if (func_8016F1AC() != 0) { + goto zero; + } + if (z <= lim) { + goto one; + } + if (D_8011F9C4 == 0) { + goto zero; + } + if (((u8)func_80029178(0x21)) != 0) { + goto zero; + } +one: + doit = 1; + goto join; +zero: + doit = 0; +join: + if (doit != 0) { + D_80186BD4[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 0); + ((void (*)(s32))func_80159B70)(arg0); + func_80154150(arg0, 9); + ((void (*)(s32, s32 *))func_80146DB8)(arg0, &D_80186B68); + ((void (*)(s32, s32))func_80161CD0)(arg0, *(u16 *)(arg0 + 0x16E)); + return; + } + if (func_80161208(arg0) == 0) { + ((void (*)(s32))func_801725A4)(arg0); + } +} DEFINE_func_8015BD8C() /* dedup: shared engine-core @0x8015BD8C (src/shared) */ diff --git a/src/ov_SC04_016/ov_SC04_016_jr_8015AE2C.c b/src/ov_SC04_016/ov_SC04_016_jr_8015AE2C.c index 3c3395df2..d0483c578 100644 --- a/src/ov_SC04_016/ov_SC04_016_jr_8015AE2C.c +++ b/src/ov_SC04_016/ov_SC04_016_jr_8015AE2C.c @@ -1512,7 +1512,259 @@ DEFINE_func_8015B858() /* dedup: shared engine-core @0x8015B858 (src/shared) */ DEFINE_func_8015B8F8() /* dedup: shared engine-core @0x8015B8F8 (src/shared) */ -INCLUDE_ASM("asm/ov_SC04_016/nonmatchings/ov_SC04_016_jr_8015AE2C", func_8015B950); +extern s32 func_8015AE2C(); + +// @class: plumbing +// @stuck: none — MATCH (271/271, pin-free, zero asm). The ONLY residual is DEF-SIDE plumbing, and it is now named exactly: the in-TU instantiation `DEFINE_func_8015BEE4()` (engine_core.h:1851-1855) expands to `extern s32 func_8015B950(void);` INSIDE ov_SC01_077_jr_8015AE2C.c, ~14 lines BELOW this definition, so the 1-param def collides with a `(void)` prototype -> `conflicting types for func_8015B950` (.run/bank_func_8015B950.log). §73 PARAMS axis / T0. Surgical fix = §65b de-macroize that ONE instantiation (blast radius: this TU); the fleet-wide `(void)`->`()` header edit is §63 and must be R22-validated. +/* func_8015B950 (ov_SC01_077_jr_8015AE2C, 271 ins, jtbl_801D8B74) — SESSION-21 re-verified + * + * ── ROUND-2 INDEPENDENT RE-VERIFICATION (2026-07-27, fresh agent, §88e discipline) ───────────── + * match_one : MATCH (271 ins) against the CURRENT tree — §87 staleness re-checked today. + * .text size: compiled .text = 0x43C = 1084 B = 271 ins, EXACTLY the target's declared 0x43C + * ("nonmatching func_8015B950, 0x43C"). So this is NOT a §83a length drift hiding + * behind a zero count — the count is over equal-length streams. + * jtbl : RE-DECODED MECHANICALLY, not inherited. Compiled .rodata = 0x1C = 28 B = 7 words, + * 7x R_MIPS_32 -> .text with implicit addends [58,58,58,E0,F0,100,58]; +0x8015B950 + * = [8015B9A8, 8015B9A8, 8015B9A8, 8015BA30, 8015BA40, 8015BA50, 8015B9A8]. + * Diffed word-for-word against asm/ov_SC01_077/data/tail14.data.s:15-23 — 7/7 identical. + * symcheck : SYMS-DIFF target=35 draft=34, sole MISSING = jtbl_801D8B74. This is the §81 jr + * FALSE POSITIVE, re-confirmed here by reading the relocs: gcc emits its OWN table and + * references it with R_MIPS_HI16/LO16 against the SECTION `.rodata` (t.o +0x40/+0x48), + * so the splat's dlabel NAME can never appear in the draft object's relocation set. + * Nothing is dropped and nothing is invented: the draft's other 34 symbols are exactly + * the target's other 34. + * FAMILY : the x138 remap is clean and §84-safe. Every sibling is 271 ins with an IDENTICAL + * callee set; only THREE names vary per overlay — the two data labels and the jtbl: + * ov_SC01_077 D_8018262C / D_80182698 / jtbl_801D8B74 + * ov_SC03_099 D_80185A50 / D_80185ABC / jtbl_801BD898 + * ov_SC06_008 D_80187E44 / D_80187EB0 / jtbl_801A8734 + * The pair is always +0x6C apart, and NO literal in this draft encodes that distance + * (both labels are referenced by name), so there is no §84 derived-offset hazard. + * D_8011F9C4 is fleet-constant (main-EXE data) and must NOT be remapped. + * + * match_one: MATCH (271 ins) against the CURRENT tree (§87 staleness re-checked, 2026-07-27). + * PIN-FREE, zero asm, offset-pure (s32 arg0 + raw offsets) — x138 template-safe. + * Provenance: this is the Phase-26 crack (.run/phase26-cracks/func_8015B950.c) re-gated verbatim, + * with ONE deliberate change: the definition's return type void -> s32. + * - `void func_8015B950(s32 arg0)` : MATCH (271 ins) [the Phase-26 form] + * - `s32 func_8015B950(s32 arg0)` : MATCH (271 ins) [shipped — §3a-1 void->s32 is byte-neutral] + * The fleet/engine_core.h canonical decl is `extern s32 func_8015B950(void);` (engine_core.h:1852), + * and the last bank attempt (.run/bank_func_8015B950.log) died on `conflicting types for + * func_8015B950`. Shipping the s32 return kills the §73 RETURN axis for free and leaves only the + * cheap T0 PARAMS axis for the ladder (fix_header_decl.py / --fix-def-sig / cast_call_sites). + * Both forms are byte-identical, so the orchestrator may swap the return type back at zero cost. + * + * SYMBOLS (§58 rules 1/2 — all splat spellings, all verified present): + * D_80182698 asm/ov_SC01_077/data/tail.data.s:4355 (the state-handler vtable) + * D_8018262C asm/ov_SC01_077/data/tail.data.s:4293 + * D_8011F9C4 main-EXE data; spelled `extern s32 D_8011F9C4;` in 5+ already-banked TUs + * jtbl_801D8B74 asm/ov_SC01_077/data/tail14.data.s:15 (compiler jump table — not named in C) + * + * JTBL VERIFIED (§8a gate): compiled .rodata = exactly 0x1C B / 7 words, 7x R_MIPS_32 .text with + * addends [0x58,0x58,0x58,0xE0,0xF0,0x100,0x58] -> +0x8015B950 = [B9A8,B9A8,B9A8,BA30,BA40,BA50, + * B9A8] == the original words at 0x801D8B74..0x801D8B8C. Bound `sltiu $v0,$v1,0x7` matches. + * The raw dlabel's 8th word 0x00000000 is NOT an entry — it is the intra-TU `.align 3` pad of the + * B34/B54/B74 jtbl chain; the object can never emit it (maspsx drops .align), so it must stay in + * the post-carve RAW data piece (the §53/§62/§81 carve chain applies at bank time). + * + * Same family as the TU's own already-matched func_8015AE2C: 7-case switch on ((s32 (*)(s32))func_801619A4)() + * (0/1/2/6 shared, 3/4/5 own, no default block — out-of-range and every `break` fall to the + * after-switch join), then a chain of "state handler" tests, each dispatching + * D_80182698[*(u16*)arg0](arg0) and returning. + * + * THREE LEVERS (draft -> MATCH in 3 compiles): + * + * 1. PROLOGUE CONSTANT = an INITIALIZED LOCAL, not a literal in the compare. + * Target opens with `lui $s2, 0xFFF5` in the *prologue*, used once ~200 ins later in + * `slt $v0,$s2,$s1`. No gcc-2.7.2 pass hoists a (set reg const_int) across basic blocks + * (loop.c needs a loop; cse/combine/sched never move insns between BBs) — so the insn must + * have been EMITTED in the first BB, i.e. the constant is a local initialized at the top of + * the function. cse then cannot fold it back into the compare: the `slt` operand predicate is + * `arith_operand`, which rejects a CONST_INT wider than 16 bits, so validate_change fails and + * the pseudo survives. Its live range spans every call -> global.c gives it a callee-saved reg. + * Writing `z > -0xB0000` inline instead emits the `lui` into the branch delay slot next to the + * compare (caller-saved $v0) and the function is 1 insn short. => `s32 lim = -0xB0000;` at top. + * + * 2. `lh` vs `lhu`: a short->short copy is a pure HImode move and gcc emits `lhu`. The target's + * `lh $v0,0x26($s0)` means the value passed through an SImode (int) temp: expand makes + * (set (reg:SI) (sign_extend (mem:HI))) + (set (mem:HI) (subreg:HI ...)), and combine cannot + * merge them (the merged form is mem<-mem, which no movhi accepts) so the sign-extending load + * survives. => route both halfword copies through the `s32 t` temp. + * + * 3. THE `goto` LAYOUT — dodging jump.c's store-flag conversion (jump.c:1005-1065). + * An if/else chain writing 0/1 into `doit` makes gcc collapse the last pair into + * `sltiu $v0,$v0,1`. jump.c fires that conversion when the insn immediately after a + * conditional jump is a lone `SET pseudo, CONST_INT` whose following simplejump targets the + * SAME label as the branch (jump.c:1038 `reallabelprev == temp || ... JUMP_LABEL(temp4) == + * JUMP_LABEL(insn)`) — exactly the shape of `if (c) x=0; else x=1;`. + * The target instead cross-jumps ALL the `doit=0` exits into ONE shared block placed after the + * `doit=1` fall-through; reorg's fill_slots_from_thread then COPIES that single set into all + * three branch delay slots and redirects each branch past it (which is why `addu $v0,$zero, + * $zero` appears 3x in delay slots and the shared block vanishes). A `goto zero;` / `goto one;` + * chain expresses that layout directly, and each conditional jump is then followed by a + * compare/call rather than a lone const set, so the store-flag conversion never triggers. + * GENERAL RULE: multiple predicates that all assign the SAME constant to one flag => write + * them as `goto` to a shared assignment, never as an if/else ladder. + */ +extern s32 D_8011F9C4; +extern s32 D_8018262C; + +extern s32 func_80161B18(void); +extern s32 func_801619A4(s32*); +extern s32 func_80149AA8(s32*); +extern void func_80149AD4(s32*); +extern s32 func_80149B54(s32*); +extern void func_80149BAC(s32*); +extern s32 func_801498E0(s32*); +extern s32 func_80149954(s32); +extern s32 func_80149A64(s32*); +extern void func_800CCCC0(s32 a0); +extern s32 func_80149CD4(s32 a0); +extern void func_8015E880(s32*); +extern s32 func_80149744(struct S_80149744*); +extern void func_80149788(void); +extern s32 func_801496D4(void*); +extern void func_80149704(void); +extern int func_80148AFC(void*); +extern void func_80146D90(s32 a0); +extern void func_80154150(s32 a0, s32 a1); +extern void func_801541D8(u8*, s32, s32); +extern s32 func_801488A8(u8*); +extern void func_80147078(s32*, s16); +extern void func_8015A264(void*); +extern s32 func_80013294(void*, void*); +extern void func_80159B70(void*); +extern s32 func_8016F1AC(void); +extern s32 func_80029178(s32 a0); +extern void func_80146DB8(s32*, s32*); +extern s32 func_80161CD0(s32, s32); +extern s32 func_80161208(s32 a0); +extern s32 func_801725A4(u8*); + +s32 func_8015B950(s32 arg0) +{ + + extern void (*D_80182698[])(void *); + s16 sp10[4]; + s16 sp18[4]; + s32 t; + s32 z; + s32 doit; + s32 lim = -0xB0000; + + if (func_80161B18() != 0) { + return; + } + switch (((s32 (*)(s32))func_801619A4)(arg0)) { + case 0: + case 1: + case 2: + case 6: + if (((s32 (*)(s32))func_80149AA8)(arg0) != 0) { + D_80182698[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149AD4)(arg0); + return; + } + if (((s32 (*)(s32))func_80149B54)(arg0) != 0) { + D_80182698[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149BAC)(arg0); + return; + } + break; + case 3: + ((void (*)(s32))func_801498E0)(arg0); + break; + case 4: + ((void (*)(s32))func_80149954)(arg0); + break; + case 5: + if (((s32 (*)(s32))func_80149A64)(arg0) != 0) { + D_80182698[*(u16 *)arg0]((void *)arg0); + func_800CCCC0(arg0); + return; + } + break; + } + if (func_80149CD4(arg0) != 0) { + D_80182698[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_8015E880)(arg0); + return; + } + if (((s32 (*)(s32))func_80149744)(arg0) != 0) { + D_80182698[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149788)(arg0); + return; + } + if (((s32 (*)(s32))func_801496D4)(arg0) != 0) { + D_80182698[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149704)(arg0); + if (((u8)((s32 (*)(s32))func_80148AFC)(arg0)) == 0) { + func_80146D90(arg0); + } + if ((*(s32 *)(arg0 + 0x24) | *(s32 *)(arg0 + 0x2C)) != 0) { + func_80154150(arg0, 0xF); + } else { + ((void (*)(s32, s32, s32))func_801541D8)(arg0, 0xD, 6); + } + *(s32 *)(arg0 + 0x238) = 1; + return; + } + if (((s32 (*)(s32))func_801488A8)(arg0) != 0) { + sp10[0] = 0; + sp10[1] = 0; + sp10[2] = 0; + t = *(s16 *)(arg0 + 0x26); + sp18[0] = t; + sp18[1] = 0; + t = *(s16 *)(arg0 + 0x2E); + sp18[2] = t; + D_80182698[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 1); + ((void (*)(s32))func_8015A264)(arg0); + t = -(((s32 (*)(s16 *, s16 *))func_80013294)(sp10, sp18) << 0x10); + if (t < *(s32 *)(arg0 + 0x2C)) { + *(s32 *)(arg0 + 0x2C) = t; + } + return; + } + if (*(u16 *)(arg0 + 0xB8) == 0x8000) { + D_80182698[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 0); + ((void (*)(s32))func_80159B70)(arg0); + return; + } + z = *(s32 *)(arg0 + 0x2C); + if (func_8016F1AC() != 0) { + goto zero; + } + if (z <= lim) { + goto one; + } + if (D_8011F9C4 == 0) { + goto zero; + } + if (((u8)func_80029178(0x21)) != 0) { + goto zero; + } +one: + doit = 1; + goto join; +zero: + doit = 0; +join: + if (doit != 0) { + D_80182698[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 0); + ((void (*)(s32))func_80159B70)(arg0); + func_80154150(arg0, 9); + ((void (*)(s32, s32 *))func_80146DB8)(arg0, &D_8018262C); + ((void (*)(s32, s32))func_80161CD0)(arg0, *(u16 *)(arg0 + 0x16E)); + return; + } + if (func_80161208(arg0) == 0) { + ((void (*)(s32))func_801725A4)(arg0); + } +} DEFINE_func_8015BD8C() /* dedup: shared engine-core @0x8015BD8C (src/shared) */ diff --git a/src/ov_SC04_018/ov_SC04_018_jr_8015AE2C.c b/src/ov_SC04_018/ov_SC04_018_jr_8015AE2C.c index f6d203af6..5c97f40c8 100644 --- a/src/ov_SC04_018/ov_SC04_018_jr_8015AE2C.c +++ b/src/ov_SC04_018/ov_SC04_018_jr_8015AE2C.c @@ -1512,7 +1512,259 @@ DEFINE_func_8015B858() /* dedup: shared engine-core @0x8015B858 (src/shared) */ DEFINE_func_8015B8F8() /* dedup: shared engine-core @0x8015B8F8 (src/shared) */ -INCLUDE_ASM("asm/ov_SC04_018/nonmatchings/ov_SC04_018_jr_8015AE2C", func_8015B950); +extern s32 func_8015AE2C(); + +// @class: plumbing +// @stuck: none — MATCH (271/271, pin-free, zero asm). The ONLY residual is DEF-SIDE plumbing, and it is now named exactly: the in-TU instantiation `DEFINE_func_8015BEE4()` (engine_core.h:1851-1855) expands to `extern s32 func_8015B950(void);` INSIDE ov_SC01_077_jr_8015AE2C.c, ~14 lines BELOW this definition, so the 1-param def collides with a `(void)` prototype -> `conflicting types for func_8015B950` (.run/bank_func_8015B950.log). §73 PARAMS axis / T0. Surgical fix = §65b de-macroize that ONE instantiation (blast radius: this TU); the fleet-wide `(void)`->`()` header edit is §63 and must be R22-validated. +/* func_8015B950 (ov_SC01_077_jr_8015AE2C, 271 ins, jtbl_801D8B74) — SESSION-21 re-verified + * + * ── ROUND-2 INDEPENDENT RE-VERIFICATION (2026-07-27, fresh agent, §88e discipline) ───────────── + * match_one : MATCH (271 ins) against the CURRENT tree — §87 staleness re-checked today. + * .text size: compiled .text = 0x43C = 1084 B = 271 ins, EXACTLY the target's declared 0x43C + * ("nonmatching func_8015B950, 0x43C"). So this is NOT a §83a length drift hiding + * behind a zero count — the count is over equal-length streams. + * jtbl : RE-DECODED MECHANICALLY, not inherited. Compiled .rodata = 0x1C = 28 B = 7 words, + * 7x R_MIPS_32 -> .text with implicit addends [58,58,58,E0,F0,100,58]; +0x8015B950 + * = [8015B9A8, 8015B9A8, 8015B9A8, 8015BA30, 8015BA40, 8015BA50, 8015B9A8]. + * Diffed word-for-word against asm/ov_SC01_077/data/tail14.data.s:15-23 — 7/7 identical. + * symcheck : SYMS-DIFF target=35 draft=34, sole MISSING = jtbl_801D8B74. This is the §81 jr + * FALSE POSITIVE, re-confirmed here by reading the relocs: gcc emits its OWN table and + * references it with R_MIPS_HI16/LO16 against the SECTION `.rodata` (t.o +0x40/+0x48), + * so the splat's dlabel NAME can never appear in the draft object's relocation set. + * Nothing is dropped and nothing is invented: the draft's other 34 symbols are exactly + * the target's other 34. + * FAMILY : the x138 remap is clean and §84-safe. Every sibling is 271 ins with an IDENTICAL + * callee set; only THREE names vary per overlay — the two data labels and the jtbl: + * ov_SC01_077 D_8018F844 / D_8018F8B0 / jtbl_801D8B74 + * ov_SC03_099 D_80185A50 / D_80185ABC / jtbl_801BD898 + * ov_SC06_008 D_80187E44 / D_80187EB0 / jtbl_801A8734 + * The pair is always +0x6C apart, and NO literal in this draft encodes that distance + * (both labels are referenced by name), so there is no §84 derived-offset hazard. + * D_8011F9C4 is fleet-constant (main-EXE data) and must NOT be remapped. + * + * match_one: MATCH (271 ins) against the CURRENT tree (§87 staleness re-checked, 2026-07-27). + * PIN-FREE, zero asm, offset-pure (s32 arg0 + raw offsets) — x138 template-safe. + * Provenance: this is the Phase-26 crack (.run/phase26-cracks/func_8015B950.c) re-gated verbatim, + * with ONE deliberate change: the definition's return type void -> s32. + * - `void func_8015B950(s32 arg0)` : MATCH (271 ins) [the Phase-26 form] + * - `s32 func_8015B950(s32 arg0)` : MATCH (271 ins) [shipped — §3a-1 void->s32 is byte-neutral] + * The fleet/engine_core.h canonical decl is `extern s32 func_8015B950(void);` (engine_core.h:1852), + * and the last bank attempt (.run/bank_func_8015B950.log) died on `conflicting types for + * func_8015B950`. Shipping the s32 return kills the §73 RETURN axis for free and leaves only the + * cheap T0 PARAMS axis for the ladder (fix_header_decl.py / --fix-def-sig / cast_call_sites). + * Both forms are byte-identical, so the orchestrator may swap the return type back at zero cost. + * + * SYMBOLS (§58 rules 1/2 — all splat spellings, all verified present): + * D_8018F8B0 asm/ov_SC01_077/data/tail.data.s:4355 (the state-handler vtable) + * D_8018F844 asm/ov_SC01_077/data/tail.data.s:4293 + * D_8011F9C4 main-EXE data; spelled `extern s32 D_8011F9C4;` in 5+ already-banked TUs + * jtbl_801D8B74 asm/ov_SC01_077/data/tail14.data.s:15 (compiler jump table — not named in C) + * + * JTBL VERIFIED (§8a gate): compiled .rodata = exactly 0x1C B / 7 words, 7x R_MIPS_32 .text with + * addends [0x58,0x58,0x58,0xE0,0xF0,0x100,0x58] -> +0x8015B950 = [B9A8,B9A8,B9A8,BA30,BA40,BA50, + * B9A8] == the original words at 0x801D8B74..0x801D8B8C. Bound `sltiu $v0,$v1,0x7` matches. + * The raw dlabel's 8th word 0x00000000 is NOT an entry — it is the intra-TU `.align 3` pad of the + * B34/B54/B74 jtbl chain; the object can never emit it (maspsx drops .align), so it must stay in + * the post-carve RAW data piece (the §53/§62/§81 carve chain applies at bank time). + * + * Same family as the TU's own already-matched func_8015AE2C: 7-case switch on ((s32 (*)(s32))func_801619A4)() + * (0/1/2/6 shared, 3/4/5 own, no default block — out-of-range and every `break` fall to the + * after-switch join), then a chain of "state handler" tests, each dispatching + * D_8018F8B0[*(u16*)arg0](arg0) and returning. + * + * THREE LEVERS (draft -> MATCH in 3 compiles): + * + * 1. PROLOGUE CONSTANT = an INITIALIZED LOCAL, not a literal in the compare. + * Target opens with `lui $s2, 0xFFF5` in the *prologue*, used once ~200 ins later in + * `slt $v0,$s2,$s1`. No gcc-2.7.2 pass hoists a (set reg const_int) across basic blocks + * (loop.c needs a loop; cse/combine/sched never move insns between BBs) — so the insn must + * have been EMITTED in the first BB, i.e. the constant is a local initialized at the top of + * the function. cse then cannot fold it back into the compare: the `slt` operand predicate is + * `arith_operand`, which rejects a CONST_INT wider than 16 bits, so validate_change fails and + * the pseudo survives. Its live range spans every call -> global.c gives it a callee-saved reg. + * Writing `z > -0xB0000` inline instead emits the `lui` into the branch delay slot next to the + * compare (caller-saved $v0) and the function is 1 insn short. => `s32 lim = -0xB0000;` at top. + * + * 2. `lh` vs `lhu`: a short->short copy is a pure HImode move and gcc emits `lhu`. The target's + * `lh $v0,0x26($s0)` means the value passed through an SImode (int) temp: expand makes + * (set (reg:SI) (sign_extend (mem:HI))) + (set (mem:HI) (subreg:HI ...)), and combine cannot + * merge them (the merged form is mem<-mem, which no movhi accepts) so the sign-extending load + * survives. => route both halfword copies through the `s32 t` temp. + * + * 3. THE `goto` LAYOUT — dodging jump.c's store-flag conversion (jump.c:1005-1065). + * An if/else chain writing 0/1 into `doit` makes gcc collapse the last pair into + * `sltiu $v0,$v0,1`. jump.c fires that conversion when the insn immediately after a + * conditional jump is a lone `SET pseudo, CONST_INT` whose following simplejump targets the + * SAME label as the branch (jump.c:1038 `reallabelprev == temp || ... JUMP_LABEL(temp4) == + * JUMP_LABEL(insn)`) — exactly the shape of `if (c) x=0; else x=1;`. + * The target instead cross-jumps ALL the `doit=0` exits into ONE shared block placed after the + * `doit=1` fall-through; reorg's fill_slots_from_thread then COPIES that single set into all + * three branch delay slots and redirects each branch past it (which is why `addu $v0,$zero, + * $zero` appears 3x in delay slots and the shared block vanishes). A `goto zero;` / `goto one;` + * chain expresses that layout directly, and each conditional jump is then followed by a + * compare/call rather than a lone const set, so the store-flag conversion never triggers. + * GENERAL RULE: multiple predicates that all assign the SAME constant to one flag => write + * them as `goto` to a shared assignment, never as an if/else ladder. + */ +extern s32 D_8011F9C4; +extern s32 D_8018F844; + +extern s32 func_80161B18(void); +extern s32 func_801619A4(s32*); +extern s32 func_80149AA8(s32*); +extern void func_80149AD4(s32*); +extern s32 func_80149B54(s32*); +extern void func_80149BAC(s32*); +extern s32 func_801498E0(s32*); +extern s32 func_80149954(s32); +extern s32 func_80149A64(s32*); +extern void func_800CCCC0(s32 a0); +extern s32 func_80149CD4(s32 a0); +extern void func_8015E880(s32*); +extern s32 func_80149744(struct S_80149744*); +extern void func_80149788(void); +extern s32 func_801496D4(void*); +extern void func_80149704(void); +extern int func_80148AFC(void*); +extern void func_80146D90(s32 a0); +extern void func_80154150(s32 a0, s32 a1); +extern void func_801541D8(u8*, s32, s32); +extern s32 func_801488A8(u8*); +extern void func_80147078(s32*, s16); +extern void func_8015A264(void*); +extern s32 func_80013294(void*, void*); +extern void func_80159B70(void*); +extern s32 func_8016F1AC(void); +extern s32 func_80029178(s32 a0); +extern void func_80146DB8(s32*, s32*); +extern s32 func_80161CD0(s32, s32); +extern s32 func_80161208(s32 a0); +extern s32 func_801725A4(u8*); + +s32 func_8015B950(s32 arg0) +{ + + extern void (*D_8018F8B0[])(void *); + s16 sp10[4]; + s16 sp18[4]; + s32 t; + s32 z; + s32 doit; + s32 lim = -0xB0000; + + if (func_80161B18() != 0) { + return; + } + switch (((s32 (*)(s32))func_801619A4)(arg0)) { + case 0: + case 1: + case 2: + case 6: + if (((s32 (*)(s32))func_80149AA8)(arg0) != 0) { + D_8018F8B0[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149AD4)(arg0); + return; + } + if (((s32 (*)(s32))func_80149B54)(arg0) != 0) { + D_8018F8B0[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149BAC)(arg0); + return; + } + break; + case 3: + ((void (*)(s32))func_801498E0)(arg0); + break; + case 4: + ((void (*)(s32))func_80149954)(arg0); + break; + case 5: + if (((s32 (*)(s32))func_80149A64)(arg0) != 0) { + D_8018F8B0[*(u16 *)arg0]((void *)arg0); + func_800CCCC0(arg0); + return; + } + break; + } + if (func_80149CD4(arg0) != 0) { + D_8018F8B0[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_8015E880)(arg0); + return; + } + if (((s32 (*)(s32))func_80149744)(arg0) != 0) { + D_8018F8B0[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149788)(arg0); + return; + } + if (((s32 (*)(s32))func_801496D4)(arg0) != 0) { + D_8018F8B0[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149704)(arg0); + if (((u8)((s32 (*)(s32))func_80148AFC)(arg0)) == 0) { + func_80146D90(arg0); + } + if ((*(s32 *)(arg0 + 0x24) | *(s32 *)(arg0 + 0x2C)) != 0) { + func_80154150(arg0, 0xF); + } else { + ((void (*)(s32, s32, s32))func_801541D8)(arg0, 0xD, 6); + } + *(s32 *)(arg0 + 0x238) = 1; + return; + } + if (((s32 (*)(s32))func_801488A8)(arg0) != 0) { + sp10[0] = 0; + sp10[1] = 0; + sp10[2] = 0; + t = *(s16 *)(arg0 + 0x26); + sp18[0] = t; + sp18[1] = 0; + t = *(s16 *)(arg0 + 0x2E); + sp18[2] = t; + D_8018F8B0[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 1); + ((void (*)(s32))func_8015A264)(arg0); + t = -(((s32 (*)(s16 *, s16 *))func_80013294)(sp10, sp18) << 0x10); + if (t < *(s32 *)(arg0 + 0x2C)) { + *(s32 *)(arg0 + 0x2C) = t; + } + return; + } + if (*(u16 *)(arg0 + 0xB8) == 0x8000) { + D_8018F8B0[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 0); + ((void (*)(s32))func_80159B70)(arg0); + return; + } + z = *(s32 *)(arg0 + 0x2C); + if (func_8016F1AC() != 0) { + goto zero; + } + if (z <= lim) { + goto one; + } + if (D_8011F9C4 == 0) { + goto zero; + } + if (((u8)func_80029178(0x21)) != 0) { + goto zero; + } +one: + doit = 1; + goto join; +zero: + doit = 0; +join: + if (doit != 0) { + D_8018F8B0[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 0); + ((void (*)(s32))func_80159B70)(arg0); + func_80154150(arg0, 9); + ((void (*)(s32, s32 *))func_80146DB8)(arg0, &D_8018F844); + ((void (*)(s32, s32))func_80161CD0)(arg0, *(u16 *)(arg0 + 0x16E)); + return; + } + if (func_80161208(arg0) == 0) { + ((void (*)(s32))func_801725A4)(arg0); + } +} DEFINE_func_8015BD8C() /* dedup: shared engine-core @0x8015BD8C (src/shared) */ diff --git a/src/ov_SC04_019/ov_SC04_019_jr_8015AE2C.c b/src/ov_SC04_019/ov_SC04_019_jr_8015AE2C.c index 0122d1dc8..ae68d611a 100644 --- a/src/ov_SC04_019/ov_SC04_019_jr_8015AE2C.c +++ b/src/ov_SC04_019/ov_SC04_019_jr_8015AE2C.c @@ -1512,7 +1512,259 @@ DEFINE_func_8015B858() /* dedup: shared engine-core @0x8015B858 (src/shared) */ DEFINE_func_8015B8F8() /* dedup: shared engine-core @0x8015B8F8 (src/shared) */ -INCLUDE_ASM("asm/ov_SC04_019/nonmatchings/ov_SC04_019_jr_8015AE2C", func_8015B950); +extern s32 func_8015AE2C(); + +// @class: plumbing +// @stuck: none — MATCH (271/271, pin-free, zero asm). The ONLY residual is DEF-SIDE plumbing, and it is now named exactly: the in-TU instantiation `DEFINE_func_8015BEE4()` (engine_core.h:1851-1855) expands to `extern s32 func_8015B950(void);` INSIDE ov_SC01_077_jr_8015AE2C.c, ~14 lines BELOW this definition, so the 1-param def collides with a `(void)` prototype -> `conflicting types for func_8015B950` (.run/bank_func_8015B950.log). §73 PARAMS axis / T0. Surgical fix = §65b de-macroize that ONE instantiation (blast radius: this TU); the fleet-wide `(void)`->`()` header edit is §63 and must be R22-validated. +/* func_8015B950 (ov_SC01_077_jr_8015AE2C, 271 ins, jtbl_801D8B74) — SESSION-21 re-verified + * + * ── ROUND-2 INDEPENDENT RE-VERIFICATION (2026-07-27, fresh agent, §88e discipline) ───────────── + * match_one : MATCH (271 ins) against the CURRENT tree — §87 staleness re-checked today. + * .text size: compiled .text = 0x43C = 1084 B = 271 ins, EXACTLY the target's declared 0x43C + * ("nonmatching func_8015B950, 0x43C"). So this is NOT a §83a length drift hiding + * behind a zero count — the count is over equal-length streams. + * jtbl : RE-DECODED MECHANICALLY, not inherited. Compiled .rodata = 0x1C = 28 B = 7 words, + * 7x R_MIPS_32 -> .text with implicit addends [58,58,58,E0,F0,100,58]; +0x8015B950 + * = [8015B9A8, 8015B9A8, 8015B9A8, 8015BA30, 8015BA40, 8015BA50, 8015B9A8]. + * Diffed word-for-word against asm/ov_SC01_077/data/tail14.data.s:15-23 — 7/7 identical. + * symcheck : SYMS-DIFF target=35 draft=34, sole MISSING = jtbl_801D8B74. This is the §81 jr + * FALSE POSITIVE, re-confirmed here by reading the relocs: gcc emits its OWN table and + * references it with R_MIPS_HI16/LO16 against the SECTION `.rodata` (t.o +0x40/+0x48), + * so the splat's dlabel NAME can never appear in the draft object's relocation set. + * Nothing is dropped and nothing is invented: the draft's other 34 symbols are exactly + * the target's other 34. + * FAMILY : the x138 remap is clean and §84-safe. Every sibling is 271 ins with an IDENTICAL + * callee set; only THREE names vary per overlay — the two data labels and the jtbl: + * ov_SC01_077 D_8018F844 / D_8018F8B0 / jtbl_801D8B74 + * ov_SC03_099 D_80185A50 / D_80185ABC / jtbl_801BD898 + * ov_SC06_008 D_80187E44 / D_80187EB0 / jtbl_801A8734 + * The pair is always +0x6C apart, and NO literal in this draft encodes that distance + * (both labels are referenced by name), so there is no §84 derived-offset hazard. + * D_8011F9C4 is fleet-constant (main-EXE data) and must NOT be remapped. + * + * match_one: MATCH (271 ins) against the CURRENT tree (§87 staleness re-checked, 2026-07-27). + * PIN-FREE, zero asm, offset-pure (s32 arg0 + raw offsets) — x138 template-safe. + * Provenance: this is the Phase-26 crack (.run/phase26-cracks/func_8015B950.c) re-gated verbatim, + * with ONE deliberate change: the definition's return type void -> s32. + * - `void func_8015B950(s32 arg0)` : MATCH (271 ins) [the Phase-26 form] + * - `s32 func_8015B950(s32 arg0)` : MATCH (271 ins) [shipped — §3a-1 void->s32 is byte-neutral] + * The fleet/engine_core.h canonical decl is `extern s32 func_8015B950(void);` (engine_core.h:1852), + * and the last bank attempt (.run/bank_func_8015B950.log) died on `conflicting types for + * func_8015B950`. Shipping the s32 return kills the §73 RETURN axis for free and leaves only the + * cheap T0 PARAMS axis for the ladder (fix_header_decl.py / --fix-def-sig / cast_call_sites). + * Both forms are byte-identical, so the orchestrator may swap the return type back at zero cost. + * + * SYMBOLS (§58 rules 1/2 — all splat spellings, all verified present): + * D_8018F8B0 asm/ov_SC01_077/data/tail.data.s:4355 (the state-handler vtable) + * D_8018F844 asm/ov_SC01_077/data/tail.data.s:4293 + * D_8011F9C4 main-EXE data; spelled `extern s32 D_8011F9C4;` in 5+ already-banked TUs + * jtbl_801D8B74 asm/ov_SC01_077/data/tail14.data.s:15 (compiler jump table — not named in C) + * + * JTBL VERIFIED (§8a gate): compiled .rodata = exactly 0x1C B / 7 words, 7x R_MIPS_32 .text with + * addends [0x58,0x58,0x58,0xE0,0xF0,0x100,0x58] -> +0x8015B950 = [B9A8,B9A8,B9A8,BA30,BA40,BA50, + * B9A8] == the original words at 0x801D8B74..0x801D8B8C. Bound `sltiu $v0,$v1,0x7` matches. + * The raw dlabel's 8th word 0x00000000 is NOT an entry — it is the intra-TU `.align 3` pad of the + * B34/B54/B74 jtbl chain; the object can never emit it (maspsx drops .align), so it must stay in + * the post-carve RAW data piece (the §53/§62/§81 carve chain applies at bank time). + * + * Same family as the TU's own already-matched func_8015AE2C: 7-case switch on ((s32 (*)(s32))func_801619A4)() + * (0/1/2/6 shared, 3/4/5 own, no default block — out-of-range and every `break` fall to the + * after-switch join), then a chain of "state handler" tests, each dispatching + * D_8018F8B0[*(u16*)arg0](arg0) and returning. + * + * THREE LEVERS (draft -> MATCH in 3 compiles): + * + * 1. PROLOGUE CONSTANT = an INITIALIZED LOCAL, not a literal in the compare. + * Target opens with `lui $s2, 0xFFF5` in the *prologue*, used once ~200 ins later in + * `slt $v0,$s2,$s1`. No gcc-2.7.2 pass hoists a (set reg const_int) across basic blocks + * (loop.c needs a loop; cse/combine/sched never move insns between BBs) — so the insn must + * have been EMITTED in the first BB, i.e. the constant is a local initialized at the top of + * the function. cse then cannot fold it back into the compare: the `slt` operand predicate is + * `arith_operand`, which rejects a CONST_INT wider than 16 bits, so validate_change fails and + * the pseudo survives. Its live range spans every call -> global.c gives it a callee-saved reg. + * Writing `z > -0xB0000` inline instead emits the `lui` into the branch delay slot next to the + * compare (caller-saved $v0) and the function is 1 insn short. => `s32 lim = -0xB0000;` at top. + * + * 2. `lh` vs `lhu`: a short->short copy is a pure HImode move and gcc emits `lhu`. The target's + * `lh $v0,0x26($s0)` means the value passed through an SImode (int) temp: expand makes + * (set (reg:SI) (sign_extend (mem:HI))) + (set (mem:HI) (subreg:HI ...)), and combine cannot + * merge them (the merged form is mem<-mem, which no movhi accepts) so the sign-extending load + * survives. => route both halfword copies through the `s32 t` temp. + * + * 3. THE `goto` LAYOUT — dodging jump.c's store-flag conversion (jump.c:1005-1065). + * An if/else chain writing 0/1 into `doit` makes gcc collapse the last pair into + * `sltiu $v0,$v0,1`. jump.c fires that conversion when the insn immediately after a + * conditional jump is a lone `SET pseudo, CONST_INT` whose following simplejump targets the + * SAME label as the branch (jump.c:1038 `reallabelprev == temp || ... JUMP_LABEL(temp4) == + * JUMP_LABEL(insn)`) — exactly the shape of `if (c) x=0; else x=1;`. + * The target instead cross-jumps ALL the `doit=0` exits into ONE shared block placed after the + * `doit=1` fall-through; reorg's fill_slots_from_thread then COPIES that single set into all + * three branch delay slots and redirects each branch past it (which is why `addu $v0,$zero, + * $zero` appears 3x in delay slots and the shared block vanishes). A `goto zero;` / `goto one;` + * chain expresses that layout directly, and each conditional jump is then followed by a + * compare/call rather than a lone const set, so the store-flag conversion never triggers. + * GENERAL RULE: multiple predicates that all assign the SAME constant to one flag => write + * them as `goto` to a shared assignment, never as an if/else ladder. + */ +extern s32 D_8011F9C4; +extern s32 D_8018F844; + +extern s32 func_80161B18(void); +extern s32 func_801619A4(s32*); +extern s32 func_80149AA8(s32*); +extern void func_80149AD4(s32*); +extern s32 func_80149B54(s32*); +extern void func_80149BAC(s32*); +extern s32 func_801498E0(s32*); +extern s32 func_80149954(s32); +extern s32 func_80149A64(s32*); +extern void func_800CCCC0(s32 a0); +extern s32 func_80149CD4(s32 a0); +extern void func_8015E880(s32*); +extern s32 func_80149744(struct S_80149744*); +extern void func_80149788(void); +extern s32 func_801496D4(void*); +extern void func_80149704(void); +extern int func_80148AFC(void*); +extern void func_80146D90(s32 a0); +extern void func_80154150(s32 a0, s32 a1); +extern void func_801541D8(u8*, s32, s32); +extern s32 func_801488A8(u8*); +extern void func_80147078(s32*, s16); +extern void func_8015A264(void*); +extern s32 func_80013294(void*, void*); +extern void func_80159B70(void*); +extern s32 func_8016F1AC(void); +extern s32 func_80029178(s32 a0); +extern void func_80146DB8(s32*, s32*); +extern s32 func_80161CD0(s32, s32); +extern s32 func_80161208(s32 a0); +extern s32 func_801725A4(u8*); + +s32 func_8015B950(s32 arg0) +{ + + extern void (*D_8018F8B0[])(void *); + s16 sp10[4]; + s16 sp18[4]; + s32 t; + s32 z; + s32 doit; + s32 lim = -0xB0000; + + if (func_80161B18() != 0) { + return; + } + switch (((s32 (*)(s32))func_801619A4)(arg0)) { + case 0: + case 1: + case 2: + case 6: + if (((s32 (*)(s32))func_80149AA8)(arg0) != 0) { + D_8018F8B0[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149AD4)(arg0); + return; + } + if (((s32 (*)(s32))func_80149B54)(arg0) != 0) { + D_8018F8B0[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149BAC)(arg0); + return; + } + break; + case 3: + ((void (*)(s32))func_801498E0)(arg0); + break; + case 4: + ((void (*)(s32))func_80149954)(arg0); + break; + case 5: + if (((s32 (*)(s32))func_80149A64)(arg0) != 0) { + D_8018F8B0[*(u16 *)arg0]((void *)arg0); + func_800CCCC0(arg0); + return; + } + break; + } + if (func_80149CD4(arg0) != 0) { + D_8018F8B0[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_8015E880)(arg0); + return; + } + if (((s32 (*)(s32))func_80149744)(arg0) != 0) { + D_8018F8B0[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149788)(arg0); + return; + } + if (((s32 (*)(s32))func_801496D4)(arg0) != 0) { + D_8018F8B0[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149704)(arg0); + if (((u8)((s32 (*)(s32))func_80148AFC)(arg0)) == 0) { + func_80146D90(arg0); + } + if ((*(s32 *)(arg0 + 0x24) | *(s32 *)(arg0 + 0x2C)) != 0) { + func_80154150(arg0, 0xF); + } else { + ((void (*)(s32, s32, s32))func_801541D8)(arg0, 0xD, 6); + } + *(s32 *)(arg0 + 0x238) = 1; + return; + } + if (((s32 (*)(s32))func_801488A8)(arg0) != 0) { + sp10[0] = 0; + sp10[1] = 0; + sp10[2] = 0; + t = *(s16 *)(arg0 + 0x26); + sp18[0] = t; + sp18[1] = 0; + t = *(s16 *)(arg0 + 0x2E); + sp18[2] = t; + D_8018F8B0[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 1); + ((void (*)(s32))func_8015A264)(arg0); + t = -(((s32 (*)(s16 *, s16 *))func_80013294)(sp10, sp18) << 0x10); + if (t < *(s32 *)(arg0 + 0x2C)) { + *(s32 *)(arg0 + 0x2C) = t; + } + return; + } + if (*(u16 *)(arg0 + 0xB8) == 0x8000) { + D_8018F8B0[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 0); + ((void (*)(s32))func_80159B70)(arg0); + return; + } + z = *(s32 *)(arg0 + 0x2C); + if (func_8016F1AC() != 0) { + goto zero; + } + if (z <= lim) { + goto one; + } + if (D_8011F9C4 == 0) { + goto zero; + } + if (((u8)func_80029178(0x21)) != 0) { + goto zero; + } +one: + doit = 1; + goto join; +zero: + doit = 0; +join: + if (doit != 0) { + D_8018F8B0[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 0); + ((void (*)(s32))func_80159B70)(arg0); + func_80154150(arg0, 9); + ((void (*)(s32, s32 *))func_80146DB8)(arg0, &D_8018F844); + ((void (*)(s32, s32))func_80161CD0)(arg0, *(u16 *)(arg0 + 0x16E)); + return; + } + if (func_80161208(arg0) == 0) { + ((void (*)(s32))func_801725A4)(arg0); + } +} DEFINE_func_8015BD8C() /* dedup: shared engine-core @0x8015BD8C (src/shared) */ diff --git a/src/ov_SC04_020/ov_SC04_020_jr_8015AE2C.c b/src/ov_SC04_020/ov_SC04_020_jr_8015AE2C.c index 1b791734f..093e4adfd 100644 --- a/src/ov_SC04_020/ov_SC04_020_jr_8015AE2C.c +++ b/src/ov_SC04_020/ov_SC04_020_jr_8015AE2C.c @@ -1512,7 +1512,259 @@ DEFINE_func_8015B858() /* dedup: shared engine-core @0x8015B858 (src/shared) */ DEFINE_func_8015B8F8() /* dedup: shared engine-core @0x8015B8F8 (src/shared) */ -INCLUDE_ASM("asm/ov_SC04_020/nonmatchings/ov_SC04_020_jr_8015AE2C", func_8015B950); +extern s32 func_8015AE2C(); + +// @class: plumbing +// @stuck: none — MATCH (271/271, pin-free, zero asm). The ONLY residual is DEF-SIDE plumbing, and it is now named exactly: the in-TU instantiation `DEFINE_func_8015BEE4()` (engine_core.h:1851-1855) expands to `extern s32 func_8015B950(void);` INSIDE ov_SC01_077_jr_8015AE2C.c, ~14 lines BELOW this definition, so the 1-param def collides with a `(void)` prototype -> `conflicting types for func_8015B950` (.run/bank_func_8015B950.log). §73 PARAMS axis / T0. Surgical fix = §65b de-macroize that ONE instantiation (blast radius: this TU); the fleet-wide `(void)`->`()` header edit is §63 and must be R22-validated. +/* func_8015B950 (ov_SC01_077_jr_8015AE2C, 271 ins, jtbl_801D8B74) — SESSION-21 re-verified + * + * ── ROUND-2 INDEPENDENT RE-VERIFICATION (2026-07-27, fresh agent, §88e discipline) ───────────── + * match_one : MATCH (271 ins) against the CURRENT tree — §87 staleness re-checked today. + * .text size: compiled .text = 0x43C = 1084 B = 271 ins, EXACTLY the target's declared 0x43C + * ("nonmatching func_8015B950, 0x43C"). So this is NOT a §83a length drift hiding + * behind a zero count — the count is over equal-length streams. + * jtbl : RE-DECODED MECHANICALLY, not inherited. Compiled .rodata = 0x1C = 28 B = 7 words, + * 7x R_MIPS_32 -> .text with implicit addends [58,58,58,E0,F0,100,58]; +0x8015B950 + * = [8015B9A8, 8015B9A8, 8015B9A8, 8015BA30, 8015BA40, 8015BA50, 8015B9A8]. + * Diffed word-for-word against asm/ov_SC01_077/data/tail14.data.s:15-23 — 7/7 identical. + * symcheck : SYMS-DIFF target=35 draft=34, sole MISSING = jtbl_801D8B74. This is the §81 jr + * FALSE POSITIVE, re-confirmed here by reading the relocs: gcc emits its OWN table and + * references it with R_MIPS_HI16/LO16 against the SECTION `.rodata` (t.o +0x40/+0x48), + * so the splat's dlabel NAME can never appear in the draft object's relocation set. + * Nothing is dropped and nothing is invented: the draft's other 34 symbols are exactly + * the target's other 34. + * FAMILY : the x138 remap is clean and §84-safe. Every sibling is 271 ins with an IDENTICAL + * callee set; only THREE names vary per overlay — the two data labels and the jtbl: + * ov_SC01_077 D_8018597C / D_801859E8 / jtbl_801D8B74 + * ov_SC03_099 D_80185A50 / D_80185ABC / jtbl_801BD898 + * ov_SC06_008 D_80187E44 / D_80187EB0 / jtbl_801A8734 + * The pair is always +0x6C apart, and NO literal in this draft encodes that distance + * (both labels are referenced by name), so there is no §84 derived-offset hazard. + * D_8011F9C4 is fleet-constant (main-EXE data) and must NOT be remapped. + * + * match_one: MATCH (271 ins) against the CURRENT tree (§87 staleness re-checked, 2026-07-27). + * PIN-FREE, zero asm, offset-pure (s32 arg0 + raw offsets) — x138 template-safe. + * Provenance: this is the Phase-26 crack (.run/phase26-cracks/func_8015B950.c) re-gated verbatim, + * with ONE deliberate change: the definition's return type void -> s32. + * - `void func_8015B950(s32 arg0)` : MATCH (271 ins) [the Phase-26 form] + * - `s32 func_8015B950(s32 arg0)` : MATCH (271 ins) [shipped — §3a-1 void->s32 is byte-neutral] + * The fleet/engine_core.h canonical decl is `extern s32 func_8015B950(void);` (engine_core.h:1852), + * and the last bank attempt (.run/bank_func_8015B950.log) died on `conflicting types for + * func_8015B950`. Shipping the s32 return kills the §73 RETURN axis for free and leaves only the + * cheap T0 PARAMS axis for the ladder (fix_header_decl.py / --fix-def-sig / cast_call_sites). + * Both forms are byte-identical, so the orchestrator may swap the return type back at zero cost. + * + * SYMBOLS (§58 rules 1/2 — all splat spellings, all verified present): + * D_801859E8 asm/ov_SC01_077/data/tail.data.s:4355 (the state-handler vtable) + * D_8018597C asm/ov_SC01_077/data/tail.data.s:4293 + * D_8011F9C4 main-EXE data; spelled `extern s32 D_8011F9C4;` in 5+ already-banked TUs + * jtbl_801D8B74 asm/ov_SC01_077/data/tail14.data.s:15 (compiler jump table — not named in C) + * + * JTBL VERIFIED (§8a gate): compiled .rodata = exactly 0x1C B / 7 words, 7x R_MIPS_32 .text with + * addends [0x58,0x58,0x58,0xE0,0xF0,0x100,0x58] -> +0x8015B950 = [B9A8,B9A8,B9A8,BA30,BA40,BA50, + * B9A8] == the original words at 0x801D8B74..0x801D8B8C. Bound `sltiu $v0,$v1,0x7` matches. + * The raw dlabel's 8th word 0x00000000 is NOT an entry — it is the intra-TU `.align 3` pad of the + * B34/B54/B74 jtbl chain; the object can never emit it (maspsx drops .align), so it must stay in + * the post-carve RAW data piece (the §53/§62/§81 carve chain applies at bank time). + * + * Same family as the TU's own already-matched func_8015AE2C: 7-case switch on ((s32 (*)(s32))func_801619A4)() + * (0/1/2/6 shared, 3/4/5 own, no default block — out-of-range and every `break` fall to the + * after-switch join), then a chain of "state handler" tests, each dispatching + * D_801859E8[*(u16*)arg0](arg0) and returning. + * + * THREE LEVERS (draft -> MATCH in 3 compiles): + * + * 1. PROLOGUE CONSTANT = an INITIALIZED LOCAL, not a literal in the compare. + * Target opens with `lui $s2, 0xFFF5` in the *prologue*, used once ~200 ins later in + * `slt $v0,$s2,$s1`. No gcc-2.7.2 pass hoists a (set reg const_int) across basic blocks + * (loop.c needs a loop; cse/combine/sched never move insns between BBs) — so the insn must + * have been EMITTED in the first BB, i.e. the constant is a local initialized at the top of + * the function. cse then cannot fold it back into the compare: the `slt` operand predicate is + * `arith_operand`, which rejects a CONST_INT wider than 16 bits, so validate_change fails and + * the pseudo survives. Its live range spans every call -> global.c gives it a callee-saved reg. + * Writing `z > -0xB0000` inline instead emits the `lui` into the branch delay slot next to the + * compare (caller-saved $v0) and the function is 1 insn short. => `s32 lim = -0xB0000;` at top. + * + * 2. `lh` vs `lhu`: a short->short copy is a pure HImode move and gcc emits `lhu`. The target's + * `lh $v0,0x26($s0)` means the value passed through an SImode (int) temp: expand makes + * (set (reg:SI) (sign_extend (mem:HI))) + (set (mem:HI) (subreg:HI ...)), and combine cannot + * merge them (the merged form is mem<-mem, which no movhi accepts) so the sign-extending load + * survives. => route both halfword copies through the `s32 t` temp. + * + * 3. THE `goto` LAYOUT — dodging jump.c's store-flag conversion (jump.c:1005-1065). + * An if/else chain writing 0/1 into `doit` makes gcc collapse the last pair into + * `sltiu $v0,$v0,1`. jump.c fires that conversion when the insn immediately after a + * conditional jump is a lone `SET pseudo, CONST_INT` whose following simplejump targets the + * SAME label as the branch (jump.c:1038 `reallabelprev == temp || ... JUMP_LABEL(temp4) == + * JUMP_LABEL(insn)`) — exactly the shape of `if (c) x=0; else x=1;`. + * The target instead cross-jumps ALL the `doit=0` exits into ONE shared block placed after the + * `doit=1` fall-through; reorg's fill_slots_from_thread then COPIES that single set into all + * three branch delay slots and redirects each branch past it (which is why `addu $v0,$zero, + * $zero` appears 3x in delay slots and the shared block vanishes). A `goto zero;` / `goto one;` + * chain expresses that layout directly, and each conditional jump is then followed by a + * compare/call rather than a lone const set, so the store-flag conversion never triggers. + * GENERAL RULE: multiple predicates that all assign the SAME constant to one flag => write + * them as `goto` to a shared assignment, never as an if/else ladder. + */ +extern s32 D_8011F9C4; +extern s32 D_8018597C; + +extern s32 func_80161B18(void); +extern s32 func_801619A4(s32*); +extern s32 func_80149AA8(s32*); +extern void func_80149AD4(s32*); +extern s32 func_80149B54(s32*); +extern void func_80149BAC(s32*); +extern s32 func_801498E0(s32*); +extern s32 func_80149954(s32); +extern s32 func_80149A64(s32*); +extern void func_800CCCC0(s32 a0); +extern s32 func_80149CD4(s32 a0); +extern void func_8015E880(s32*); +extern s32 func_80149744(struct S_80149744*); +extern void func_80149788(void); +extern s32 func_801496D4(void*); +extern void func_80149704(void); +extern int func_80148AFC(void*); +extern void func_80146D90(s32 a0); +extern void func_80154150(s32 a0, s32 a1); +extern void func_801541D8(u8*, s32, s32); +extern s32 func_801488A8(u8*); +extern void func_80147078(s32*, s16); +extern void func_8015A264(void*); +extern s32 func_80013294(void*, void*); +extern void func_80159B70(void*); +extern s32 func_8016F1AC(void); +extern s32 func_80029178(s32 a0); +extern void func_80146DB8(s32*, s32*); +extern s32 func_80161CD0(s32, s32); +extern s32 func_80161208(s32 a0); +extern s32 func_801725A4(u8*); + +s32 func_8015B950(s32 arg0) +{ + + extern void (*D_801859E8[])(void *); + s16 sp10[4]; + s16 sp18[4]; + s32 t; + s32 z; + s32 doit; + s32 lim = -0xB0000; + + if (func_80161B18() != 0) { + return; + } + switch (((s32 (*)(s32))func_801619A4)(arg0)) { + case 0: + case 1: + case 2: + case 6: + if (((s32 (*)(s32))func_80149AA8)(arg0) != 0) { + D_801859E8[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149AD4)(arg0); + return; + } + if (((s32 (*)(s32))func_80149B54)(arg0) != 0) { + D_801859E8[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149BAC)(arg0); + return; + } + break; + case 3: + ((void (*)(s32))func_801498E0)(arg0); + break; + case 4: + ((void (*)(s32))func_80149954)(arg0); + break; + case 5: + if (((s32 (*)(s32))func_80149A64)(arg0) != 0) { + D_801859E8[*(u16 *)arg0]((void *)arg0); + func_800CCCC0(arg0); + return; + } + break; + } + if (func_80149CD4(arg0) != 0) { + D_801859E8[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_8015E880)(arg0); + return; + } + if (((s32 (*)(s32))func_80149744)(arg0) != 0) { + D_801859E8[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149788)(arg0); + return; + } + if (((s32 (*)(s32))func_801496D4)(arg0) != 0) { + D_801859E8[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149704)(arg0); + if (((u8)((s32 (*)(s32))func_80148AFC)(arg0)) == 0) { + func_80146D90(arg0); + } + if ((*(s32 *)(arg0 + 0x24) | *(s32 *)(arg0 + 0x2C)) != 0) { + func_80154150(arg0, 0xF); + } else { + ((void (*)(s32, s32, s32))func_801541D8)(arg0, 0xD, 6); + } + *(s32 *)(arg0 + 0x238) = 1; + return; + } + if (((s32 (*)(s32))func_801488A8)(arg0) != 0) { + sp10[0] = 0; + sp10[1] = 0; + sp10[2] = 0; + t = *(s16 *)(arg0 + 0x26); + sp18[0] = t; + sp18[1] = 0; + t = *(s16 *)(arg0 + 0x2E); + sp18[2] = t; + D_801859E8[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 1); + ((void (*)(s32))func_8015A264)(arg0); + t = -(((s32 (*)(s16 *, s16 *))func_80013294)(sp10, sp18) << 0x10); + if (t < *(s32 *)(arg0 + 0x2C)) { + *(s32 *)(arg0 + 0x2C) = t; + } + return; + } + if (*(u16 *)(arg0 + 0xB8) == 0x8000) { + D_801859E8[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 0); + ((void (*)(s32))func_80159B70)(arg0); + return; + } + z = *(s32 *)(arg0 + 0x2C); + if (func_8016F1AC() != 0) { + goto zero; + } + if (z <= lim) { + goto one; + } + if (D_8011F9C4 == 0) { + goto zero; + } + if (((u8)func_80029178(0x21)) != 0) { + goto zero; + } +one: + doit = 1; + goto join; +zero: + doit = 0; +join: + if (doit != 0) { + D_801859E8[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 0); + ((void (*)(s32))func_80159B70)(arg0); + func_80154150(arg0, 9); + ((void (*)(s32, s32 *))func_80146DB8)(arg0, &D_8018597C); + ((void (*)(s32, s32))func_80161CD0)(arg0, *(u16 *)(arg0 + 0x16E)); + return; + } + if (func_80161208(arg0) == 0) { + ((void (*)(s32))func_801725A4)(arg0); + } +} DEFINE_func_8015BD8C() /* dedup: shared engine-core @0x8015BD8C (src/shared) */ diff --git a/src/ov_SC04_021/ov_SC04_021_jr_8015AE2C.c b/src/ov_SC04_021/ov_SC04_021_jr_8015AE2C.c index cdc2c4e0d..cde3c55a9 100644 --- a/src/ov_SC04_021/ov_SC04_021_jr_8015AE2C.c +++ b/src/ov_SC04_021/ov_SC04_021_jr_8015AE2C.c @@ -1512,7 +1512,259 @@ DEFINE_func_8015B858() /* dedup: shared engine-core @0x8015B858 (src/shared) */ DEFINE_func_8015B8F8() /* dedup: shared engine-core @0x8015B8F8 (src/shared) */ -INCLUDE_ASM("asm/ov_SC04_021/nonmatchings/ov_SC04_021_jr_8015AE2C", func_8015B950); +extern s32 func_8015AE2C(); + +// @class: plumbing +// @stuck: none — MATCH (271/271, pin-free, zero asm). The ONLY residual is DEF-SIDE plumbing, and it is now named exactly: the in-TU instantiation `DEFINE_func_8015BEE4()` (engine_core.h:1851-1855) expands to `extern s32 func_8015B950(void);` INSIDE ov_SC01_077_jr_8015AE2C.c, ~14 lines BELOW this definition, so the 1-param def collides with a `(void)` prototype -> `conflicting types for func_8015B950` (.run/bank_func_8015B950.log). §73 PARAMS axis / T0. Surgical fix = §65b de-macroize that ONE instantiation (blast radius: this TU); the fleet-wide `(void)`->`()` header edit is §63 and must be R22-validated. +/* func_8015B950 (ov_SC01_077_jr_8015AE2C, 271 ins, jtbl_801D8B74) — SESSION-21 re-verified + * + * ── ROUND-2 INDEPENDENT RE-VERIFICATION (2026-07-27, fresh agent, §88e discipline) ───────────── + * match_one : MATCH (271 ins) against the CURRENT tree — §87 staleness re-checked today. + * .text size: compiled .text = 0x43C = 1084 B = 271 ins, EXACTLY the target's declared 0x43C + * ("nonmatching func_8015B950, 0x43C"). So this is NOT a §83a length drift hiding + * behind a zero count — the count is over equal-length streams. + * jtbl : RE-DECODED MECHANICALLY, not inherited. Compiled .rodata = 0x1C = 28 B = 7 words, + * 7x R_MIPS_32 -> .text with implicit addends [58,58,58,E0,F0,100,58]; +0x8015B950 + * = [8015B9A8, 8015B9A8, 8015B9A8, 8015BA30, 8015BA40, 8015BA50, 8015B9A8]. + * Diffed word-for-word against asm/ov_SC01_077/data/tail14.data.s:15-23 — 7/7 identical. + * symcheck : SYMS-DIFF target=35 draft=34, sole MISSING = jtbl_801D8B74. This is the §81 jr + * FALSE POSITIVE, re-confirmed here by reading the relocs: gcc emits its OWN table and + * references it with R_MIPS_HI16/LO16 against the SECTION `.rodata` (t.o +0x40/+0x48), + * so the splat's dlabel NAME can never appear in the draft object's relocation set. + * Nothing is dropped and nothing is invented: the draft's other 34 symbols are exactly + * the target's other 34. + * FAMILY : the x138 remap is clean and §84-safe. Every sibling is 271 ins with an IDENTICAL + * callee set; only THREE names vary per overlay — the two data labels and the jtbl: + * ov_SC01_077 D_801818A8 / D_80181914 / jtbl_801D8B74 + * ov_SC03_099 D_80185A50 / D_80185ABC / jtbl_801BD898 + * ov_SC06_008 D_80187E44 / D_80187EB0 / jtbl_801A8734 + * The pair is always +0x6C apart, and NO literal in this draft encodes that distance + * (both labels are referenced by name), so there is no §84 derived-offset hazard. + * D_8011F9C4 is fleet-constant (main-EXE data) and must NOT be remapped. + * + * match_one: MATCH (271 ins) against the CURRENT tree (§87 staleness re-checked, 2026-07-27). + * PIN-FREE, zero asm, offset-pure (s32 arg0 + raw offsets) — x138 template-safe. + * Provenance: this is the Phase-26 crack (.run/phase26-cracks/func_8015B950.c) re-gated verbatim, + * with ONE deliberate change: the definition's return type void -> s32. + * - `void func_8015B950(s32 arg0)` : MATCH (271 ins) [the Phase-26 form] + * - `s32 func_8015B950(s32 arg0)` : MATCH (271 ins) [shipped — §3a-1 void->s32 is byte-neutral] + * The fleet/engine_core.h canonical decl is `extern s32 func_8015B950(void);` (engine_core.h:1852), + * and the last bank attempt (.run/bank_func_8015B950.log) died on `conflicting types for + * func_8015B950`. Shipping the s32 return kills the §73 RETURN axis for free and leaves only the + * cheap T0 PARAMS axis for the ladder (fix_header_decl.py / --fix-def-sig / cast_call_sites). + * Both forms are byte-identical, so the orchestrator may swap the return type back at zero cost. + * + * SYMBOLS (§58 rules 1/2 — all splat spellings, all verified present): + * D_80181914 asm/ov_SC01_077/data/tail.data.s:4355 (the state-handler vtable) + * D_801818A8 asm/ov_SC01_077/data/tail.data.s:4293 + * D_8011F9C4 main-EXE data; spelled `extern s32 D_8011F9C4;` in 5+ already-banked TUs + * jtbl_801D8B74 asm/ov_SC01_077/data/tail14.data.s:15 (compiler jump table — not named in C) + * + * JTBL VERIFIED (§8a gate): compiled .rodata = exactly 0x1C B / 7 words, 7x R_MIPS_32 .text with + * addends [0x58,0x58,0x58,0xE0,0xF0,0x100,0x58] -> +0x8015B950 = [B9A8,B9A8,B9A8,BA30,BA40,BA50, + * B9A8] == the original words at 0x801D8B74..0x801D8B8C. Bound `sltiu $v0,$v1,0x7` matches. + * The raw dlabel's 8th word 0x00000000 is NOT an entry — it is the intra-TU `.align 3` pad of the + * B34/B54/B74 jtbl chain; the object can never emit it (maspsx drops .align), so it must stay in + * the post-carve RAW data piece (the §53/§62/§81 carve chain applies at bank time). + * + * Same family as the TU's own already-matched func_8015AE2C: 7-case switch on ((s32 (*)(s32))func_801619A4)() + * (0/1/2/6 shared, 3/4/5 own, no default block — out-of-range and every `break` fall to the + * after-switch join), then a chain of "state handler" tests, each dispatching + * D_80181914[*(u16*)arg0](arg0) and returning. + * + * THREE LEVERS (draft -> MATCH in 3 compiles): + * + * 1. PROLOGUE CONSTANT = an INITIALIZED LOCAL, not a literal in the compare. + * Target opens with `lui $s2, 0xFFF5` in the *prologue*, used once ~200 ins later in + * `slt $v0,$s2,$s1`. No gcc-2.7.2 pass hoists a (set reg const_int) across basic blocks + * (loop.c needs a loop; cse/combine/sched never move insns between BBs) — so the insn must + * have been EMITTED in the first BB, i.e. the constant is a local initialized at the top of + * the function. cse then cannot fold it back into the compare: the `slt` operand predicate is + * `arith_operand`, which rejects a CONST_INT wider than 16 bits, so validate_change fails and + * the pseudo survives. Its live range spans every call -> global.c gives it a callee-saved reg. + * Writing `z > -0xB0000` inline instead emits the `lui` into the branch delay slot next to the + * compare (caller-saved $v0) and the function is 1 insn short. => `s32 lim = -0xB0000;` at top. + * + * 2. `lh` vs `lhu`: a short->short copy is a pure HImode move and gcc emits `lhu`. The target's + * `lh $v0,0x26($s0)` means the value passed through an SImode (int) temp: expand makes + * (set (reg:SI) (sign_extend (mem:HI))) + (set (mem:HI) (subreg:HI ...)), and combine cannot + * merge them (the merged form is mem<-mem, which no movhi accepts) so the sign-extending load + * survives. => route both halfword copies through the `s32 t` temp. + * + * 3. THE `goto` LAYOUT — dodging jump.c's store-flag conversion (jump.c:1005-1065). + * An if/else chain writing 0/1 into `doit` makes gcc collapse the last pair into + * `sltiu $v0,$v0,1`. jump.c fires that conversion when the insn immediately after a + * conditional jump is a lone `SET pseudo, CONST_INT` whose following simplejump targets the + * SAME label as the branch (jump.c:1038 `reallabelprev == temp || ... JUMP_LABEL(temp4) == + * JUMP_LABEL(insn)`) — exactly the shape of `if (c) x=0; else x=1;`. + * The target instead cross-jumps ALL the `doit=0` exits into ONE shared block placed after the + * `doit=1` fall-through; reorg's fill_slots_from_thread then COPIES that single set into all + * three branch delay slots and redirects each branch past it (which is why `addu $v0,$zero, + * $zero` appears 3x in delay slots and the shared block vanishes). A `goto zero;` / `goto one;` + * chain expresses that layout directly, and each conditional jump is then followed by a + * compare/call rather than a lone const set, so the store-flag conversion never triggers. + * GENERAL RULE: multiple predicates that all assign the SAME constant to one flag => write + * them as `goto` to a shared assignment, never as an if/else ladder. + */ +extern s32 D_8011F9C4; +extern s32 D_801818A8; + +extern s32 func_80161B18(void); +extern s32 func_801619A4(s32*); +extern s32 func_80149AA8(s32*); +extern void func_80149AD4(s32*); +extern s32 func_80149B54(s32*); +extern void func_80149BAC(s32*); +extern s32 func_801498E0(s32*); +extern s32 func_80149954(s32); +extern s32 func_80149A64(s32*); +extern void func_800CCCC0(s32 a0); +extern s32 func_80149CD4(s32 a0); +extern void func_8015E880(s32*); +extern s32 func_80149744(struct S_80149744*); +extern void func_80149788(void); +extern s32 func_801496D4(void*); +extern void func_80149704(void); +extern int func_80148AFC(void*); +extern void func_80146D90(s32 a0); +extern void func_80154150(s32 a0, s32 a1); +extern void func_801541D8(u8*, s32, s32); +extern s32 func_801488A8(u8*); +extern void func_80147078(s32*, s16); +extern void func_8015A264(void*); +extern s32 func_80013294(void*, void*); +extern void func_80159B70(void*); +extern s32 func_8016F1AC(void); +extern s32 func_80029178(s32 a0); +extern void func_80146DB8(s32*, s32*); +extern s32 func_80161CD0(s32, s32); +extern s32 func_80161208(s32 a0); +extern s32 func_801725A4(u8*); + +s32 func_8015B950(s32 arg0) +{ + + extern void (*D_80181914[])(void *); + s16 sp10[4]; + s16 sp18[4]; + s32 t; + s32 z; + s32 doit; + s32 lim = -0xB0000; + + if (func_80161B18() != 0) { + return; + } + switch (((s32 (*)(s32))func_801619A4)(arg0)) { + case 0: + case 1: + case 2: + case 6: + if (((s32 (*)(s32))func_80149AA8)(arg0) != 0) { + D_80181914[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149AD4)(arg0); + return; + } + if (((s32 (*)(s32))func_80149B54)(arg0) != 0) { + D_80181914[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149BAC)(arg0); + return; + } + break; + case 3: + ((void (*)(s32))func_801498E0)(arg0); + break; + case 4: + ((void (*)(s32))func_80149954)(arg0); + break; + case 5: + if (((s32 (*)(s32))func_80149A64)(arg0) != 0) { + D_80181914[*(u16 *)arg0]((void *)arg0); + func_800CCCC0(arg0); + return; + } + break; + } + if (func_80149CD4(arg0) != 0) { + D_80181914[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_8015E880)(arg0); + return; + } + if (((s32 (*)(s32))func_80149744)(arg0) != 0) { + D_80181914[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149788)(arg0); + return; + } + if (((s32 (*)(s32))func_801496D4)(arg0) != 0) { + D_80181914[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149704)(arg0); + if (((u8)((s32 (*)(s32))func_80148AFC)(arg0)) == 0) { + func_80146D90(arg0); + } + if ((*(s32 *)(arg0 + 0x24) | *(s32 *)(arg0 + 0x2C)) != 0) { + func_80154150(arg0, 0xF); + } else { + ((void (*)(s32, s32, s32))func_801541D8)(arg0, 0xD, 6); + } + *(s32 *)(arg0 + 0x238) = 1; + return; + } + if (((s32 (*)(s32))func_801488A8)(arg0) != 0) { + sp10[0] = 0; + sp10[1] = 0; + sp10[2] = 0; + t = *(s16 *)(arg0 + 0x26); + sp18[0] = t; + sp18[1] = 0; + t = *(s16 *)(arg0 + 0x2E); + sp18[2] = t; + D_80181914[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 1); + ((void (*)(s32))func_8015A264)(arg0); + t = -(((s32 (*)(s16 *, s16 *))func_80013294)(sp10, sp18) << 0x10); + if (t < *(s32 *)(arg0 + 0x2C)) { + *(s32 *)(arg0 + 0x2C) = t; + } + return; + } + if (*(u16 *)(arg0 + 0xB8) == 0x8000) { + D_80181914[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 0); + ((void (*)(s32))func_80159B70)(arg0); + return; + } + z = *(s32 *)(arg0 + 0x2C); + if (func_8016F1AC() != 0) { + goto zero; + } + if (z <= lim) { + goto one; + } + if (D_8011F9C4 == 0) { + goto zero; + } + if (((u8)func_80029178(0x21)) != 0) { + goto zero; + } +one: + doit = 1; + goto join; +zero: + doit = 0; +join: + if (doit != 0) { + D_80181914[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 0); + ((void (*)(s32))func_80159B70)(arg0); + func_80154150(arg0, 9); + ((void (*)(s32, s32 *))func_80146DB8)(arg0, &D_801818A8); + ((void (*)(s32, s32))func_80161CD0)(arg0, *(u16 *)(arg0 + 0x16E)); + return; + } + if (func_80161208(arg0) == 0) { + ((void (*)(s32))func_801725A4)(arg0); + } +} DEFINE_func_8015BD8C() /* dedup: shared engine-core @0x8015BD8C (src/shared) */ diff --git a/src/ov_SC05_000/ov_SC05_000_jr_8015AE2C.c b/src/ov_SC05_000/ov_SC05_000_jr_8015AE2C.c index 8d9d26b1f..a71446d12 100644 --- a/src/ov_SC05_000/ov_SC05_000_jr_8015AE2C.c +++ b/src/ov_SC05_000/ov_SC05_000_jr_8015AE2C.c @@ -1510,7 +1510,259 @@ DEFINE_func_8015B858() /* dedup: shared engine-core @0x8015B858 (src/shared) */ DEFINE_func_8015B8F8() /* dedup: shared engine-core @0x8015B8F8 (src/shared) */ -INCLUDE_ASM("asm/ov_SC05_000/nonmatchings/ov_SC05_000_jr_8015AE2C", func_8015B950); +extern s32 func_8015AE2C(); + +// @class: plumbing +// @stuck: none — MATCH (271/271, pin-free, zero asm). The ONLY residual is DEF-SIDE plumbing, and it is now named exactly: the in-TU instantiation `DEFINE_func_8015BEE4()` (engine_core.h:1851-1855) expands to `extern s32 func_8015B950(void);` INSIDE ov_SC01_077_jr_8015AE2C.c, ~14 lines BELOW this definition, so the 1-param def collides with a `(void)` prototype -> `conflicting types for func_8015B950` (.run/bank_func_8015B950.log). §73 PARAMS axis / T0. Surgical fix = §65b de-macroize that ONE instantiation (blast radius: this TU); the fleet-wide `(void)`->`()` header edit is §63 and must be R22-validated. +/* func_8015B950 (ov_SC01_077_jr_8015AE2C, 271 ins, jtbl_801D8B74) — SESSION-21 re-verified + * + * ── ROUND-2 INDEPENDENT RE-VERIFICATION (2026-07-27, fresh agent, §88e discipline) ───────────── + * match_one : MATCH (271 ins) against the CURRENT tree — §87 staleness re-checked today. + * .text size: compiled .text = 0x43C = 1084 B = 271 ins, EXACTLY the target's declared 0x43C + * ("nonmatching func_8015B950, 0x43C"). So this is NOT a §83a length drift hiding + * behind a zero count — the count is over equal-length streams. + * jtbl : RE-DECODED MECHANICALLY, not inherited. Compiled .rodata = 0x1C = 28 B = 7 words, + * 7x R_MIPS_32 -> .text with implicit addends [58,58,58,E0,F0,100,58]; +0x8015B950 + * = [8015B9A8, 8015B9A8, 8015B9A8, 8015BA30, 8015BA40, 8015BA50, 8015B9A8]. + * Diffed word-for-word against asm/ov_SC01_077/data/tail14.data.s:15-23 — 7/7 identical. + * symcheck : SYMS-DIFF target=35 draft=34, sole MISSING = jtbl_801D8B74. This is the §81 jr + * FALSE POSITIVE, re-confirmed here by reading the relocs: gcc emits its OWN table and + * references it with R_MIPS_HI16/LO16 against the SECTION `.rodata` (t.o +0x40/+0x48), + * so the splat's dlabel NAME can never appear in the draft object's relocation set. + * Nothing is dropped and nothing is invented: the draft's other 34 symbols are exactly + * the target's other 34. + * FAMILY : the x138 remap is clean and §84-safe. Every sibling is 271 ins with an IDENTICAL + * callee set; only THREE names vary per overlay — the two data labels and the jtbl: + * ov_SC01_077 D_801808BC / D_80180928 / jtbl_801D8B74 + * ov_SC03_099 D_80185A50 / D_80185ABC / jtbl_801BD898 + * ov_SC06_008 D_80187E44 / D_80187EB0 / jtbl_801A8734 + * The pair is always +0x6C apart, and NO literal in this draft encodes that distance + * (both labels are referenced by name), so there is no §84 derived-offset hazard. + * D_8011F9C4 is fleet-constant (main-EXE data) and must NOT be remapped. + * + * match_one: MATCH (271 ins) against the CURRENT tree (§87 staleness re-checked, 2026-07-27). + * PIN-FREE, zero asm, offset-pure (s32 arg0 + raw offsets) — x138 template-safe. + * Provenance: this is the Phase-26 crack (.run/phase26-cracks/func_8015B950.c) re-gated verbatim, + * with ONE deliberate change: the definition's return type void -> s32. + * - `void func_8015B950(s32 arg0)` : MATCH (271 ins) [the Phase-26 form] + * - `s32 func_8015B950(s32 arg0)` : MATCH (271 ins) [shipped — §3a-1 void->s32 is byte-neutral] + * The fleet/engine_core.h canonical decl is `extern s32 func_8015B950(void);` (engine_core.h:1852), + * and the last bank attempt (.run/bank_func_8015B950.log) died on `conflicting types for + * func_8015B950`. Shipping the s32 return kills the §73 RETURN axis for free and leaves only the + * cheap T0 PARAMS axis for the ladder (fix_header_decl.py / --fix-def-sig / cast_call_sites). + * Both forms are byte-identical, so the orchestrator may swap the return type back at zero cost. + * + * SYMBOLS (§58 rules 1/2 — all splat spellings, all verified present): + * D_80180928 asm/ov_SC01_077/data/tail.data.s:4355 (the state-handler vtable) + * D_801808BC asm/ov_SC01_077/data/tail.data.s:4293 + * D_8011F9C4 main-EXE data; spelled `extern s32 D_8011F9C4;` in 5+ already-banked TUs + * jtbl_801D8B74 asm/ov_SC01_077/data/tail14.data.s:15 (compiler jump table — not named in C) + * + * JTBL VERIFIED (§8a gate): compiled .rodata = exactly 0x1C B / 7 words, 7x R_MIPS_32 .text with + * addends [0x58,0x58,0x58,0xE0,0xF0,0x100,0x58] -> +0x8015B950 = [B9A8,B9A8,B9A8,BA30,BA40,BA50, + * B9A8] == the original words at 0x801D8B74..0x801D8B8C. Bound `sltiu $v0,$v1,0x7` matches. + * The raw dlabel's 8th word 0x00000000 is NOT an entry — it is the intra-TU `.align 3` pad of the + * B34/B54/B74 jtbl chain; the object can never emit it (maspsx drops .align), so it must stay in + * the post-carve RAW data piece (the §53/§62/§81 carve chain applies at bank time). + * + * Same family as the TU's own already-matched func_8015AE2C: 7-case switch on ((s32 (*)(s32))func_801619A4)() + * (0/1/2/6 shared, 3/4/5 own, no default block — out-of-range and every `break` fall to the + * after-switch join), then a chain of "state handler" tests, each dispatching + * D_80180928[*(u16*)arg0](arg0) and returning. + * + * THREE LEVERS (draft -> MATCH in 3 compiles): + * + * 1. PROLOGUE CONSTANT = an INITIALIZED LOCAL, not a literal in the compare. + * Target opens with `lui $s2, 0xFFF5` in the *prologue*, used once ~200 ins later in + * `slt $v0,$s2,$s1`. No gcc-2.7.2 pass hoists a (set reg const_int) across basic blocks + * (loop.c needs a loop; cse/combine/sched never move insns between BBs) — so the insn must + * have been EMITTED in the first BB, i.e. the constant is a local initialized at the top of + * the function. cse then cannot fold it back into the compare: the `slt` operand predicate is + * `arith_operand`, which rejects a CONST_INT wider than 16 bits, so validate_change fails and + * the pseudo survives. Its live range spans every call -> global.c gives it a callee-saved reg. + * Writing `z > -0xB0000` inline instead emits the `lui` into the branch delay slot next to the + * compare (caller-saved $v0) and the function is 1 insn short. => `s32 lim = -0xB0000;` at top. + * + * 2. `lh` vs `lhu`: a short->short copy is a pure HImode move and gcc emits `lhu`. The target's + * `lh $v0,0x26($s0)` means the value passed through an SImode (int) temp: expand makes + * (set (reg:SI) (sign_extend (mem:HI))) + (set (mem:HI) (subreg:HI ...)), and combine cannot + * merge them (the merged form is mem<-mem, which no movhi accepts) so the sign-extending load + * survives. => route both halfword copies through the `s32 t` temp. + * + * 3. THE `goto` LAYOUT — dodging jump.c's store-flag conversion (jump.c:1005-1065). + * An if/else chain writing 0/1 into `doit` makes gcc collapse the last pair into + * `sltiu $v0,$v0,1`. jump.c fires that conversion when the insn immediately after a + * conditional jump is a lone `SET pseudo, CONST_INT` whose following simplejump targets the + * SAME label as the branch (jump.c:1038 `reallabelprev == temp || ... JUMP_LABEL(temp4) == + * JUMP_LABEL(insn)`) — exactly the shape of `if (c) x=0; else x=1;`. + * The target instead cross-jumps ALL the `doit=0` exits into ONE shared block placed after the + * `doit=1` fall-through; reorg's fill_slots_from_thread then COPIES that single set into all + * three branch delay slots and redirects each branch past it (which is why `addu $v0,$zero, + * $zero` appears 3x in delay slots and the shared block vanishes). A `goto zero;` / `goto one;` + * chain expresses that layout directly, and each conditional jump is then followed by a + * compare/call rather than a lone const set, so the store-flag conversion never triggers. + * GENERAL RULE: multiple predicates that all assign the SAME constant to one flag => write + * them as `goto` to a shared assignment, never as an if/else ladder. + */ +extern s32 D_8011F9C4; +extern s32 D_801808BC; + +extern s32 func_80161B18(void); +extern s32 func_801619A4(s32*); +extern s32 func_80149AA8(s32*); +extern void func_80149AD4(s32*); +extern s32 func_80149B54(s32*); +extern void func_80149BAC(s32*); +extern s32 func_801498E0(s32*); +extern s32 func_80149954(s32); +extern s32 func_80149A64(s32*); +extern void func_800CCCC0(s32 a0); +extern s32 func_80149CD4(s32 a0); +extern void func_8015E880(s32*); +extern s32 func_80149744(struct S_80149744*); +extern void func_80149788(void); +extern s32 func_801496D4(void*); +extern void func_80149704(void); +extern int func_80148AFC(void*); +extern void func_80146D90(s32 a0); +extern void func_80154150(s32 a0, s32 a1); +extern void func_801541D8(u8*, s32, s32); +extern s32 func_801488A8(u8*); +extern void func_80147078(s32*, s16); +extern void func_8015A264(void*); +extern s32 func_80013294(void*, void*); +extern void func_80159B70(void*); +extern s32 func_8016F1AC(void); +extern s32 func_80029178(s32 a0); +extern void func_80146DB8(s32*, s32*); +extern s32 func_80161CD0(s32, s32); +extern s32 func_80161208(s32 a0); +extern s32 func_801725A4(u8*); + +s32 func_8015B950(s32 arg0) +{ + + extern void (*D_80180928[])(void *); + s16 sp10[4]; + s16 sp18[4]; + s32 t; + s32 z; + s32 doit; + s32 lim = -0xB0000; + + if (func_80161B18() != 0) { + return; + } + switch (((s32 (*)(s32))func_801619A4)(arg0)) { + case 0: + case 1: + case 2: + case 6: + if (((s32 (*)(s32))func_80149AA8)(arg0) != 0) { + D_80180928[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149AD4)(arg0); + return; + } + if (((s32 (*)(s32))func_80149B54)(arg0) != 0) { + D_80180928[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149BAC)(arg0); + return; + } + break; + case 3: + ((void (*)(s32))func_801498E0)(arg0); + break; + case 4: + ((void (*)(s32))func_80149954)(arg0); + break; + case 5: + if (((s32 (*)(s32))func_80149A64)(arg0) != 0) { + D_80180928[*(u16 *)arg0]((void *)arg0); + func_800CCCC0(arg0); + return; + } + break; + } + if (func_80149CD4(arg0) != 0) { + D_80180928[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_8015E880)(arg0); + return; + } + if (((s32 (*)(s32))func_80149744)(arg0) != 0) { + D_80180928[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149788)(arg0); + return; + } + if (((s32 (*)(s32))func_801496D4)(arg0) != 0) { + D_80180928[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149704)(arg0); + if (((u8)((s32 (*)(s32))func_80148AFC)(arg0)) == 0) { + func_80146D90(arg0); + } + if ((*(s32 *)(arg0 + 0x24) | *(s32 *)(arg0 + 0x2C)) != 0) { + func_80154150(arg0, 0xF); + } else { + ((void (*)(s32, s32, s32))func_801541D8)(arg0, 0xD, 6); + } + *(s32 *)(arg0 + 0x238) = 1; + return; + } + if (((s32 (*)(s32))func_801488A8)(arg0) != 0) { + sp10[0] = 0; + sp10[1] = 0; + sp10[2] = 0; + t = *(s16 *)(arg0 + 0x26); + sp18[0] = t; + sp18[1] = 0; + t = *(s16 *)(arg0 + 0x2E); + sp18[2] = t; + D_80180928[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 1); + ((void (*)(s32))func_8015A264)(arg0); + t = -(((s32 (*)(s16 *, s16 *))func_80013294)(sp10, sp18) << 0x10); + if (t < *(s32 *)(arg0 + 0x2C)) { + *(s32 *)(arg0 + 0x2C) = t; + } + return; + } + if (*(u16 *)(arg0 + 0xB8) == 0x8000) { + D_80180928[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 0); + ((void (*)(s32))func_80159B70)(arg0); + return; + } + z = *(s32 *)(arg0 + 0x2C); + if (func_8016F1AC() != 0) { + goto zero; + } + if (z <= lim) { + goto one; + } + if (D_8011F9C4 == 0) { + goto zero; + } + if (((u8)func_80029178(0x21)) != 0) { + goto zero; + } +one: + doit = 1; + goto join; +zero: + doit = 0; +join: + if (doit != 0) { + D_80180928[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 0); + ((void (*)(s32))func_80159B70)(arg0); + func_80154150(arg0, 9); + ((void (*)(s32, s32 *))func_80146DB8)(arg0, &D_801808BC); + ((void (*)(s32, s32))func_80161CD0)(arg0, *(u16 *)(arg0 + 0x16E)); + return; + } + if (func_80161208(arg0) == 0) { + ((void (*)(s32))func_801725A4)(arg0); + } +} DEFINE_func_8015BD8C() /* dedup: shared engine-core @0x8015BD8C (src/shared) */ diff --git a/src/ov_SC05_001/ov_SC05_001_jr_8015AE2C.c b/src/ov_SC05_001/ov_SC05_001_jr_8015AE2C.c index 554a6c312..6e7647ded 100644 --- a/src/ov_SC05_001/ov_SC05_001_jr_8015AE2C.c +++ b/src/ov_SC05_001/ov_SC05_001_jr_8015AE2C.c @@ -1512,7 +1512,259 @@ DEFINE_func_8015B858() /* dedup: shared engine-core @0x8015B858 (src/shared) */ DEFINE_func_8015B8F8() /* dedup: shared engine-core @0x8015B8F8 (src/shared) */ -INCLUDE_ASM("asm/ov_SC05_001/nonmatchings/ov_SC05_001_jr_8015AE2C", func_8015B950); +extern s32 func_8015AE2C(); + +// @class: plumbing +// @stuck: none — MATCH (271/271, pin-free, zero asm). The ONLY residual is DEF-SIDE plumbing, and it is now named exactly: the in-TU instantiation `DEFINE_func_8015BEE4()` (engine_core.h:1851-1855) expands to `extern s32 func_8015B950(void);` INSIDE ov_SC01_077_jr_8015AE2C.c, ~14 lines BELOW this definition, so the 1-param def collides with a `(void)` prototype -> `conflicting types for func_8015B950` (.run/bank_func_8015B950.log). §73 PARAMS axis / T0. Surgical fix = §65b de-macroize that ONE instantiation (blast radius: this TU); the fleet-wide `(void)`->`()` header edit is §63 and must be R22-validated. +/* func_8015B950 (ov_SC01_077_jr_8015AE2C, 271 ins, jtbl_801D8B74) — SESSION-21 re-verified + * + * ── ROUND-2 INDEPENDENT RE-VERIFICATION (2026-07-27, fresh agent, §88e discipline) ───────────── + * match_one : MATCH (271 ins) against the CURRENT tree — §87 staleness re-checked today. + * .text size: compiled .text = 0x43C = 1084 B = 271 ins, EXACTLY the target's declared 0x43C + * ("nonmatching func_8015B950, 0x43C"). So this is NOT a §83a length drift hiding + * behind a zero count — the count is over equal-length streams. + * jtbl : RE-DECODED MECHANICALLY, not inherited. Compiled .rodata = 0x1C = 28 B = 7 words, + * 7x R_MIPS_32 -> .text with implicit addends [58,58,58,E0,F0,100,58]; +0x8015B950 + * = [8015B9A8, 8015B9A8, 8015B9A8, 8015BA30, 8015BA40, 8015BA50, 8015B9A8]. + * Diffed word-for-word against asm/ov_SC01_077/data/tail14.data.s:15-23 — 7/7 identical. + * symcheck : SYMS-DIFF target=35 draft=34, sole MISSING = jtbl_801D8B74. This is the §81 jr + * FALSE POSITIVE, re-confirmed here by reading the relocs: gcc emits its OWN table and + * references it with R_MIPS_HI16/LO16 against the SECTION `.rodata` (t.o +0x40/+0x48), + * so the splat's dlabel NAME can never appear in the draft object's relocation set. + * Nothing is dropped and nothing is invented: the draft's other 34 symbols are exactly + * the target's other 34. + * FAMILY : the x138 remap is clean and §84-safe. Every sibling is 271 ins with an IDENTICAL + * callee set; only THREE names vary per overlay — the two data labels and the jtbl: + * ov_SC01_077 D_80188098 / D_80188104 / jtbl_801D8B74 + * ov_SC03_099 D_80185A50 / D_80185ABC / jtbl_801BD898 + * ov_SC06_008 D_80187E44 / D_80187EB0 / jtbl_801A8734 + * The pair is always +0x6C apart, and NO literal in this draft encodes that distance + * (both labels are referenced by name), so there is no §84 derived-offset hazard. + * D_8011F9C4 is fleet-constant (main-EXE data) and must NOT be remapped. + * + * match_one: MATCH (271 ins) against the CURRENT tree (§87 staleness re-checked, 2026-07-27). + * PIN-FREE, zero asm, offset-pure (s32 arg0 + raw offsets) — x138 template-safe. + * Provenance: this is the Phase-26 crack (.run/phase26-cracks/func_8015B950.c) re-gated verbatim, + * with ONE deliberate change: the definition's return type void -> s32. + * - `void func_8015B950(s32 arg0)` : MATCH (271 ins) [the Phase-26 form] + * - `s32 func_8015B950(s32 arg0)` : MATCH (271 ins) [shipped — §3a-1 void->s32 is byte-neutral] + * The fleet/engine_core.h canonical decl is `extern s32 func_8015B950(void);` (engine_core.h:1852), + * and the last bank attempt (.run/bank_func_8015B950.log) died on `conflicting types for + * func_8015B950`. Shipping the s32 return kills the §73 RETURN axis for free and leaves only the + * cheap T0 PARAMS axis for the ladder (fix_header_decl.py / --fix-def-sig / cast_call_sites). + * Both forms are byte-identical, so the orchestrator may swap the return type back at zero cost. + * + * SYMBOLS (§58 rules 1/2 — all splat spellings, all verified present): + * D_80188104 asm/ov_SC01_077/data/tail.data.s:4355 (the state-handler vtable) + * D_80188098 asm/ov_SC01_077/data/tail.data.s:4293 + * D_8011F9C4 main-EXE data; spelled `extern s32 D_8011F9C4;` in 5+ already-banked TUs + * jtbl_801D8B74 asm/ov_SC01_077/data/tail14.data.s:15 (compiler jump table — not named in C) + * + * JTBL VERIFIED (§8a gate): compiled .rodata = exactly 0x1C B / 7 words, 7x R_MIPS_32 .text with + * addends [0x58,0x58,0x58,0xE0,0xF0,0x100,0x58] -> +0x8015B950 = [B9A8,B9A8,B9A8,BA30,BA40,BA50, + * B9A8] == the original words at 0x801D8B74..0x801D8B8C. Bound `sltiu $v0,$v1,0x7` matches. + * The raw dlabel's 8th word 0x00000000 is NOT an entry — it is the intra-TU `.align 3` pad of the + * B34/B54/B74 jtbl chain; the object can never emit it (maspsx drops .align), so it must stay in + * the post-carve RAW data piece (the §53/§62/§81 carve chain applies at bank time). + * + * Same family as the TU's own already-matched func_8015AE2C: 7-case switch on ((s32 (*)(s32))func_801619A4)() + * (0/1/2/6 shared, 3/4/5 own, no default block — out-of-range and every `break` fall to the + * after-switch join), then a chain of "state handler" tests, each dispatching + * D_80188104[*(u16*)arg0](arg0) and returning. + * + * THREE LEVERS (draft -> MATCH in 3 compiles): + * + * 1. PROLOGUE CONSTANT = an INITIALIZED LOCAL, not a literal in the compare. + * Target opens with `lui $s2, 0xFFF5` in the *prologue*, used once ~200 ins later in + * `slt $v0,$s2,$s1`. No gcc-2.7.2 pass hoists a (set reg const_int) across basic blocks + * (loop.c needs a loop; cse/combine/sched never move insns between BBs) — so the insn must + * have been EMITTED in the first BB, i.e. the constant is a local initialized at the top of + * the function. cse then cannot fold it back into the compare: the `slt` operand predicate is + * `arith_operand`, which rejects a CONST_INT wider than 16 bits, so validate_change fails and + * the pseudo survives. Its live range spans every call -> global.c gives it a callee-saved reg. + * Writing `z > -0xB0000` inline instead emits the `lui` into the branch delay slot next to the + * compare (caller-saved $v0) and the function is 1 insn short. => `s32 lim = -0xB0000;` at top. + * + * 2. `lh` vs `lhu`: a short->short copy is a pure HImode move and gcc emits `lhu`. The target's + * `lh $v0,0x26($s0)` means the value passed through an SImode (int) temp: expand makes + * (set (reg:SI) (sign_extend (mem:HI))) + (set (mem:HI) (subreg:HI ...)), and combine cannot + * merge them (the merged form is mem<-mem, which no movhi accepts) so the sign-extending load + * survives. => route both halfword copies through the `s32 t` temp. + * + * 3. THE `goto` LAYOUT — dodging jump.c's store-flag conversion (jump.c:1005-1065). + * An if/else chain writing 0/1 into `doit` makes gcc collapse the last pair into + * `sltiu $v0,$v0,1`. jump.c fires that conversion when the insn immediately after a + * conditional jump is a lone `SET pseudo, CONST_INT` whose following simplejump targets the + * SAME label as the branch (jump.c:1038 `reallabelprev == temp || ... JUMP_LABEL(temp4) == + * JUMP_LABEL(insn)`) — exactly the shape of `if (c) x=0; else x=1;`. + * The target instead cross-jumps ALL the `doit=0` exits into ONE shared block placed after the + * `doit=1` fall-through; reorg's fill_slots_from_thread then COPIES that single set into all + * three branch delay slots and redirects each branch past it (which is why `addu $v0,$zero, + * $zero` appears 3x in delay slots and the shared block vanishes). A `goto zero;` / `goto one;` + * chain expresses that layout directly, and each conditional jump is then followed by a + * compare/call rather than a lone const set, so the store-flag conversion never triggers. + * GENERAL RULE: multiple predicates that all assign the SAME constant to one flag => write + * them as `goto` to a shared assignment, never as an if/else ladder. + */ +extern s32 D_8011F9C4; +extern s32 D_80188098; + +extern s32 func_80161B18(void); +extern s32 func_801619A4(s32*); +extern s32 func_80149AA8(s32*); +extern void func_80149AD4(s32*); +extern s32 func_80149B54(s32*); +extern void func_80149BAC(s32*); +extern s32 func_801498E0(s32*); +extern s32 func_80149954(s32); +extern s32 func_80149A64(s32*); +extern void func_800CCCC0(s32 a0); +extern s32 func_80149CD4(s32 a0); +extern void func_8015E880(s32*); +extern s32 func_80149744(struct S_80149744*); +extern void func_80149788(void); +extern s32 func_801496D4(void*); +extern void func_80149704(void); +extern int func_80148AFC(void*); +extern void func_80146D90(s32 a0); +extern void func_80154150(s32 a0, s32 a1); +extern void func_801541D8(u8*, s32, s32); +extern s32 func_801488A8(u8*); +extern void func_80147078(s32*, s16); +extern void func_8015A264(void*); +extern s32 func_80013294(void*, void*); +extern void func_80159B70(void*); +extern s32 func_8016F1AC(void); +extern s32 func_80029178(s32 a0); +extern void func_80146DB8(s32*, s32*); +extern s32 func_80161CD0(s32, s32); +extern s32 func_80161208(s32 a0); +extern s32 func_801725A4(u8*); + +s32 func_8015B950(s32 arg0) +{ + + extern void (*D_80188104[])(void *); + s16 sp10[4]; + s16 sp18[4]; + s32 t; + s32 z; + s32 doit; + s32 lim = -0xB0000; + + if (func_80161B18() != 0) { + return; + } + switch (((s32 (*)(s32))func_801619A4)(arg0)) { + case 0: + case 1: + case 2: + case 6: + if (((s32 (*)(s32))func_80149AA8)(arg0) != 0) { + D_80188104[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149AD4)(arg0); + return; + } + if (((s32 (*)(s32))func_80149B54)(arg0) != 0) { + D_80188104[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149BAC)(arg0); + return; + } + break; + case 3: + ((void (*)(s32))func_801498E0)(arg0); + break; + case 4: + ((void (*)(s32))func_80149954)(arg0); + break; + case 5: + if (((s32 (*)(s32))func_80149A64)(arg0) != 0) { + D_80188104[*(u16 *)arg0]((void *)arg0); + func_800CCCC0(arg0); + return; + } + break; + } + if (func_80149CD4(arg0) != 0) { + D_80188104[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_8015E880)(arg0); + return; + } + if (((s32 (*)(s32))func_80149744)(arg0) != 0) { + D_80188104[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149788)(arg0); + return; + } + if (((s32 (*)(s32))func_801496D4)(arg0) != 0) { + D_80188104[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149704)(arg0); + if (((u8)((s32 (*)(s32))func_80148AFC)(arg0)) == 0) { + func_80146D90(arg0); + } + if ((*(s32 *)(arg0 + 0x24) | *(s32 *)(arg0 + 0x2C)) != 0) { + func_80154150(arg0, 0xF); + } else { + ((void (*)(s32, s32, s32))func_801541D8)(arg0, 0xD, 6); + } + *(s32 *)(arg0 + 0x238) = 1; + return; + } + if (((s32 (*)(s32))func_801488A8)(arg0) != 0) { + sp10[0] = 0; + sp10[1] = 0; + sp10[2] = 0; + t = *(s16 *)(arg0 + 0x26); + sp18[0] = t; + sp18[1] = 0; + t = *(s16 *)(arg0 + 0x2E); + sp18[2] = t; + D_80188104[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 1); + ((void (*)(s32))func_8015A264)(arg0); + t = -(((s32 (*)(s16 *, s16 *))func_80013294)(sp10, sp18) << 0x10); + if (t < *(s32 *)(arg0 + 0x2C)) { + *(s32 *)(arg0 + 0x2C) = t; + } + return; + } + if (*(u16 *)(arg0 + 0xB8) == 0x8000) { + D_80188104[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 0); + ((void (*)(s32))func_80159B70)(arg0); + return; + } + z = *(s32 *)(arg0 + 0x2C); + if (func_8016F1AC() != 0) { + goto zero; + } + if (z <= lim) { + goto one; + } + if (D_8011F9C4 == 0) { + goto zero; + } + if (((u8)func_80029178(0x21)) != 0) { + goto zero; + } +one: + doit = 1; + goto join; +zero: + doit = 0; +join: + if (doit != 0) { + D_80188104[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 0); + ((void (*)(s32))func_80159B70)(arg0); + func_80154150(arg0, 9); + ((void (*)(s32, s32 *))func_80146DB8)(arg0, &D_80188098); + ((void (*)(s32, s32))func_80161CD0)(arg0, *(u16 *)(arg0 + 0x16E)); + return; + } + if (func_80161208(arg0) == 0) { + ((void (*)(s32))func_801725A4)(arg0); + } +} DEFINE_func_8015BD8C() /* dedup: shared engine-core @0x8015BD8C (src/shared) */ diff --git a/src/ov_SC05_002/ov_SC05_002_jr_8015AE2C.c b/src/ov_SC05_002/ov_SC05_002_jr_8015AE2C.c index 91424a0ac..01dee2c5b 100644 --- a/src/ov_SC05_002/ov_SC05_002_jr_8015AE2C.c +++ b/src/ov_SC05_002/ov_SC05_002_jr_8015AE2C.c @@ -1512,7 +1512,259 @@ DEFINE_func_8015B858() /* dedup: shared engine-core @0x8015B858 (src/shared) */ DEFINE_func_8015B8F8() /* dedup: shared engine-core @0x8015B8F8 (src/shared) */ -INCLUDE_ASM("asm/ov_SC05_002/nonmatchings/ov_SC05_002_jr_8015AE2C", func_8015B950); +extern s32 func_8015AE2C(); + +// @class: plumbing +// @stuck: none — MATCH (271/271, pin-free, zero asm). The ONLY residual is DEF-SIDE plumbing, and it is now named exactly: the in-TU instantiation `DEFINE_func_8015BEE4()` (engine_core.h:1851-1855) expands to `extern s32 func_8015B950(void);` INSIDE ov_SC01_077_jr_8015AE2C.c, ~14 lines BELOW this definition, so the 1-param def collides with a `(void)` prototype -> `conflicting types for func_8015B950` (.run/bank_func_8015B950.log). §73 PARAMS axis / T0. Surgical fix = §65b de-macroize that ONE instantiation (blast radius: this TU); the fleet-wide `(void)`->`()` header edit is §63 and must be R22-validated. +/* func_8015B950 (ov_SC01_077_jr_8015AE2C, 271 ins, jtbl_801D8B74) — SESSION-21 re-verified + * + * ── ROUND-2 INDEPENDENT RE-VERIFICATION (2026-07-27, fresh agent, §88e discipline) ───────────── + * match_one : MATCH (271 ins) against the CURRENT tree — §87 staleness re-checked today. + * .text size: compiled .text = 0x43C = 1084 B = 271 ins, EXACTLY the target's declared 0x43C + * ("nonmatching func_8015B950, 0x43C"). So this is NOT a §83a length drift hiding + * behind a zero count — the count is over equal-length streams. + * jtbl : RE-DECODED MECHANICALLY, not inherited. Compiled .rodata = 0x1C = 28 B = 7 words, + * 7x R_MIPS_32 -> .text with implicit addends [58,58,58,E0,F0,100,58]; +0x8015B950 + * = [8015B9A8, 8015B9A8, 8015B9A8, 8015BA30, 8015BA40, 8015BA50, 8015B9A8]. + * Diffed word-for-word against asm/ov_SC01_077/data/tail14.data.s:15-23 — 7/7 identical. + * symcheck : SYMS-DIFF target=35 draft=34, sole MISSING = jtbl_801D8B74. This is the §81 jr + * FALSE POSITIVE, re-confirmed here by reading the relocs: gcc emits its OWN table and + * references it with R_MIPS_HI16/LO16 against the SECTION `.rodata` (t.o +0x40/+0x48), + * so the splat's dlabel NAME can never appear in the draft object's relocation set. + * Nothing is dropped and nothing is invented: the draft's other 34 symbols are exactly + * the target's other 34. + * FAMILY : the x138 remap is clean and §84-safe. Every sibling is 271 ins with an IDENTICAL + * callee set; only THREE names vary per overlay — the two data labels and the jtbl: + * ov_SC01_077 D_80182858 / D_801828C4 / jtbl_801D8B74 + * ov_SC03_099 D_80185A50 / D_80185ABC / jtbl_801BD898 + * ov_SC06_008 D_80187E44 / D_80187EB0 / jtbl_801A8734 + * The pair is always +0x6C apart, and NO literal in this draft encodes that distance + * (both labels are referenced by name), so there is no §84 derived-offset hazard. + * D_8011F9C4 is fleet-constant (main-EXE data) and must NOT be remapped. + * + * match_one: MATCH (271 ins) against the CURRENT tree (§87 staleness re-checked, 2026-07-27). + * PIN-FREE, zero asm, offset-pure (s32 arg0 + raw offsets) — x138 template-safe. + * Provenance: this is the Phase-26 crack (.run/phase26-cracks/func_8015B950.c) re-gated verbatim, + * with ONE deliberate change: the definition's return type void -> s32. + * - `void func_8015B950(s32 arg0)` : MATCH (271 ins) [the Phase-26 form] + * - `s32 func_8015B950(s32 arg0)` : MATCH (271 ins) [shipped — §3a-1 void->s32 is byte-neutral] + * The fleet/engine_core.h canonical decl is `extern s32 func_8015B950(void);` (engine_core.h:1852), + * and the last bank attempt (.run/bank_func_8015B950.log) died on `conflicting types for + * func_8015B950`. Shipping the s32 return kills the §73 RETURN axis for free and leaves only the + * cheap T0 PARAMS axis for the ladder (fix_header_decl.py / --fix-def-sig / cast_call_sites). + * Both forms are byte-identical, so the orchestrator may swap the return type back at zero cost. + * + * SYMBOLS (§58 rules 1/2 — all splat spellings, all verified present): + * D_801828C4 asm/ov_SC01_077/data/tail.data.s:4355 (the state-handler vtable) + * D_80182858 asm/ov_SC01_077/data/tail.data.s:4293 + * D_8011F9C4 main-EXE data; spelled `extern s32 D_8011F9C4;` in 5+ already-banked TUs + * jtbl_801D8B74 asm/ov_SC01_077/data/tail14.data.s:15 (compiler jump table — not named in C) + * + * JTBL VERIFIED (§8a gate): compiled .rodata = exactly 0x1C B / 7 words, 7x R_MIPS_32 .text with + * addends [0x58,0x58,0x58,0xE0,0xF0,0x100,0x58] -> +0x8015B950 = [B9A8,B9A8,B9A8,BA30,BA40,BA50, + * B9A8] == the original words at 0x801D8B74..0x801D8B8C. Bound `sltiu $v0,$v1,0x7` matches. + * The raw dlabel's 8th word 0x00000000 is NOT an entry — it is the intra-TU `.align 3` pad of the + * B34/B54/B74 jtbl chain; the object can never emit it (maspsx drops .align), so it must stay in + * the post-carve RAW data piece (the §53/§62/§81 carve chain applies at bank time). + * + * Same family as the TU's own already-matched func_8015AE2C: 7-case switch on ((s32 (*)(s32))func_801619A4)() + * (0/1/2/6 shared, 3/4/5 own, no default block — out-of-range and every `break` fall to the + * after-switch join), then a chain of "state handler" tests, each dispatching + * D_801828C4[*(u16*)arg0](arg0) and returning. + * + * THREE LEVERS (draft -> MATCH in 3 compiles): + * + * 1. PROLOGUE CONSTANT = an INITIALIZED LOCAL, not a literal in the compare. + * Target opens with `lui $s2, 0xFFF5` in the *prologue*, used once ~200 ins later in + * `slt $v0,$s2,$s1`. No gcc-2.7.2 pass hoists a (set reg const_int) across basic blocks + * (loop.c needs a loop; cse/combine/sched never move insns between BBs) — so the insn must + * have been EMITTED in the first BB, i.e. the constant is a local initialized at the top of + * the function. cse then cannot fold it back into the compare: the `slt` operand predicate is + * `arith_operand`, which rejects a CONST_INT wider than 16 bits, so validate_change fails and + * the pseudo survives. Its live range spans every call -> global.c gives it a callee-saved reg. + * Writing `z > -0xB0000` inline instead emits the `lui` into the branch delay slot next to the + * compare (caller-saved $v0) and the function is 1 insn short. => `s32 lim = -0xB0000;` at top. + * + * 2. `lh` vs `lhu`: a short->short copy is a pure HImode move and gcc emits `lhu`. The target's + * `lh $v0,0x26($s0)` means the value passed through an SImode (int) temp: expand makes + * (set (reg:SI) (sign_extend (mem:HI))) + (set (mem:HI) (subreg:HI ...)), and combine cannot + * merge them (the merged form is mem<-mem, which no movhi accepts) so the sign-extending load + * survives. => route both halfword copies through the `s32 t` temp. + * + * 3. THE `goto` LAYOUT — dodging jump.c's store-flag conversion (jump.c:1005-1065). + * An if/else chain writing 0/1 into `doit` makes gcc collapse the last pair into + * `sltiu $v0,$v0,1`. jump.c fires that conversion when the insn immediately after a + * conditional jump is a lone `SET pseudo, CONST_INT` whose following simplejump targets the + * SAME label as the branch (jump.c:1038 `reallabelprev == temp || ... JUMP_LABEL(temp4) == + * JUMP_LABEL(insn)`) — exactly the shape of `if (c) x=0; else x=1;`. + * The target instead cross-jumps ALL the `doit=0` exits into ONE shared block placed after the + * `doit=1` fall-through; reorg's fill_slots_from_thread then COPIES that single set into all + * three branch delay slots and redirects each branch past it (which is why `addu $v0,$zero, + * $zero` appears 3x in delay slots and the shared block vanishes). A `goto zero;` / `goto one;` + * chain expresses that layout directly, and each conditional jump is then followed by a + * compare/call rather than a lone const set, so the store-flag conversion never triggers. + * GENERAL RULE: multiple predicates that all assign the SAME constant to one flag => write + * them as `goto` to a shared assignment, never as an if/else ladder. + */ +extern s32 D_8011F9C4; +extern s32 D_80182858; + +extern s32 func_80161B18(void); +extern s32 func_801619A4(s32*); +extern s32 func_80149AA8(s32*); +extern void func_80149AD4(s32*); +extern s32 func_80149B54(s32*); +extern void func_80149BAC(s32*); +extern s32 func_801498E0(s32*); +extern s32 func_80149954(s32); +extern s32 func_80149A64(s32*); +extern void func_800CCCC0(s32 a0); +extern s32 func_80149CD4(s32 a0); +extern void func_8015E880(s32*); +extern s32 func_80149744(struct S_80149744*); +extern void func_80149788(void); +extern s32 func_801496D4(void*); +extern void func_80149704(void); +extern int func_80148AFC(void*); +extern void func_80146D90(s32 a0); +extern void func_80154150(s32 a0, s32 a1); +extern void func_801541D8(u8*, s32, s32); +extern s32 func_801488A8(u8*); +extern void func_80147078(s32*, s16); +extern void func_8015A264(void*); +extern s32 func_80013294(void*, void*); +extern void func_80159B70(void*); +extern s32 func_8016F1AC(void); +extern s32 func_80029178(s32 a0); +extern void func_80146DB8(s32*, s32*); +extern s32 func_80161CD0(s32, s32); +extern s32 func_80161208(s32 a0); +extern s32 func_801725A4(u8*); + +s32 func_8015B950(s32 arg0) +{ + + extern void (*D_801828C4[])(void *); + s16 sp10[4]; + s16 sp18[4]; + s32 t; + s32 z; + s32 doit; + s32 lim = -0xB0000; + + if (func_80161B18() != 0) { + return; + } + switch (((s32 (*)(s32))func_801619A4)(arg0)) { + case 0: + case 1: + case 2: + case 6: + if (((s32 (*)(s32))func_80149AA8)(arg0) != 0) { + D_801828C4[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149AD4)(arg0); + return; + } + if (((s32 (*)(s32))func_80149B54)(arg0) != 0) { + D_801828C4[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149BAC)(arg0); + return; + } + break; + case 3: + ((void (*)(s32))func_801498E0)(arg0); + break; + case 4: + ((void (*)(s32))func_80149954)(arg0); + break; + case 5: + if (((s32 (*)(s32))func_80149A64)(arg0) != 0) { + D_801828C4[*(u16 *)arg0]((void *)arg0); + func_800CCCC0(arg0); + return; + } + break; + } + if (func_80149CD4(arg0) != 0) { + D_801828C4[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_8015E880)(arg0); + return; + } + if (((s32 (*)(s32))func_80149744)(arg0) != 0) { + D_801828C4[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149788)(arg0); + return; + } + if (((s32 (*)(s32))func_801496D4)(arg0) != 0) { + D_801828C4[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149704)(arg0); + if (((u8)((s32 (*)(s32))func_80148AFC)(arg0)) == 0) { + func_80146D90(arg0); + } + if ((*(s32 *)(arg0 + 0x24) | *(s32 *)(arg0 + 0x2C)) != 0) { + func_80154150(arg0, 0xF); + } else { + ((void (*)(s32, s32, s32))func_801541D8)(arg0, 0xD, 6); + } + *(s32 *)(arg0 + 0x238) = 1; + return; + } + if (((s32 (*)(s32))func_801488A8)(arg0) != 0) { + sp10[0] = 0; + sp10[1] = 0; + sp10[2] = 0; + t = *(s16 *)(arg0 + 0x26); + sp18[0] = t; + sp18[1] = 0; + t = *(s16 *)(arg0 + 0x2E); + sp18[2] = t; + D_801828C4[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 1); + ((void (*)(s32))func_8015A264)(arg0); + t = -(((s32 (*)(s16 *, s16 *))func_80013294)(sp10, sp18) << 0x10); + if (t < *(s32 *)(arg0 + 0x2C)) { + *(s32 *)(arg0 + 0x2C) = t; + } + return; + } + if (*(u16 *)(arg0 + 0xB8) == 0x8000) { + D_801828C4[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 0); + ((void (*)(s32))func_80159B70)(arg0); + return; + } + z = *(s32 *)(arg0 + 0x2C); + if (func_8016F1AC() != 0) { + goto zero; + } + if (z <= lim) { + goto one; + } + if (D_8011F9C4 == 0) { + goto zero; + } + if (((u8)func_80029178(0x21)) != 0) { + goto zero; + } +one: + doit = 1; + goto join; +zero: + doit = 0; +join: + if (doit != 0) { + D_801828C4[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 0); + ((void (*)(s32))func_80159B70)(arg0); + func_80154150(arg0, 9); + ((void (*)(s32, s32 *))func_80146DB8)(arg0, &D_80182858); + ((void (*)(s32, s32))func_80161CD0)(arg0, *(u16 *)(arg0 + 0x16E)); + return; + } + if (func_80161208(arg0) == 0) { + ((void (*)(s32))func_801725A4)(arg0); + } +} DEFINE_func_8015BD8C() /* dedup: shared engine-core @0x8015BD8C (src/shared) */ diff --git a/src/ov_SC05_003/ov_SC05_003_jr_8015AE2C.c b/src/ov_SC05_003/ov_SC05_003_jr_8015AE2C.c index a9534040b..235774fbb 100644 --- a/src/ov_SC05_003/ov_SC05_003_jr_8015AE2C.c +++ b/src/ov_SC05_003/ov_SC05_003_jr_8015AE2C.c @@ -1512,7 +1512,259 @@ DEFINE_func_8015B858() /* dedup: shared engine-core @0x8015B858 (src/shared) */ DEFINE_func_8015B8F8() /* dedup: shared engine-core @0x8015B8F8 (src/shared) */ -INCLUDE_ASM("asm/ov_SC05_003/nonmatchings/ov_SC05_003_jr_8015AE2C", func_8015B950); +extern s32 func_8015AE2C(); + +// @class: plumbing +// @stuck: none — MATCH (271/271, pin-free, zero asm). The ONLY residual is DEF-SIDE plumbing, and it is now named exactly: the in-TU instantiation `DEFINE_func_8015BEE4()` (engine_core.h:1851-1855) expands to `extern s32 func_8015B950(void);` INSIDE ov_SC01_077_jr_8015AE2C.c, ~14 lines BELOW this definition, so the 1-param def collides with a `(void)` prototype -> `conflicting types for func_8015B950` (.run/bank_func_8015B950.log). §73 PARAMS axis / T0. Surgical fix = §65b de-macroize that ONE instantiation (blast radius: this TU); the fleet-wide `(void)`->`()` header edit is §63 and must be R22-validated. +/* func_8015B950 (ov_SC01_077_jr_8015AE2C, 271 ins, jtbl_801D8B74) — SESSION-21 re-verified + * + * ── ROUND-2 INDEPENDENT RE-VERIFICATION (2026-07-27, fresh agent, §88e discipline) ───────────── + * match_one : MATCH (271 ins) against the CURRENT tree — §87 staleness re-checked today. + * .text size: compiled .text = 0x43C = 1084 B = 271 ins, EXACTLY the target's declared 0x43C + * ("nonmatching func_8015B950, 0x43C"). So this is NOT a §83a length drift hiding + * behind a zero count — the count is over equal-length streams. + * jtbl : RE-DECODED MECHANICALLY, not inherited. Compiled .rodata = 0x1C = 28 B = 7 words, + * 7x R_MIPS_32 -> .text with implicit addends [58,58,58,E0,F0,100,58]; +0x8015B950 + * = [8015B9A8, 8015B9A8, 8015B9A8, 8015BA30, 8015BA40, 8015BA50, 8015B9A8]. + * Diffed word-for-word against asm/ov_SC01_077/data/tail14.data.s:15-23 — 7/7 identical. + * symcheck : SYMS-DIFF target=35 draft=34, sole MISSING = jtbl_801D8B74. This is the §81 jr + * FALSE POSITIVE, re-confirmed here by reading the relocs: gcc emits its OWN table and + * references it with R_MIPS_HI16/LO16 against the SECTION `.rodata` (t.o +0x40/+0x48), + * so the splat's dlabel NAME can never appear in the draft object's relocation set. + * Nothing is dropped and nothing is invented: the draft's other 34 symbols are exactly + * the target's other 34. + * FAMILY : the x138 remap is clean and §84-safe. Every sibling is 271 ins with an IDENTICAL + * callee set; only THREE names vary per overlay — the two data labels and the jtbl: + * ov_SC01_077 D_80184B90 / D_80184BFC / jtbl_801D8B74 + * ov_SC03_099 D_80185A50 / D_80185ABC / jtbl_801BD898 + * ov_SC06_008 D_80187E44 / D_80187EB0 / jtbl_801A8734 + * The pair is always +0x6C apart, and NO literal in this draft encodes that distance + * (both labels are referenced by name), so there is no §84 derived-offset hazard. + * D_8011F9C4 is fleet-constant (main-EXE data) and must NOT be remapped. + * + * match_one: MATCH (271 ins) against the CURRENT tree (§87 staleness re-checked, 2026-07-27). + * PIN-FREE, zero asm, offset-pure (s32 arg0 + raw offsets) — x138 template-safe. + * Provenance: this is the Phase-26 crack (.run/phase26-cracks/func_8015B950.c) re-gated verbatim, + * with ONE deliberate change: the definition's return type void -> s32. + * - `void func_8015B950(s32 arg0)` : MATCH (271 ins) [the Phase-26 form] + * - `s32 func_8015B950(s32 arg0)` : MATCH (271 ins) [shipped — §3a-1 void->s32 is byte-neutral] + * The fleet/engine_core.h canonical decl is `extern s32 func_8015B950(void);` (engine_core.h:1852), + * and the last bank attempt (.run/bank_func_8015B950.log) died on `conflicting types for + * func_8015B950`. Shipping the s32 return kills the §73 RETURN axis for free and leaves only the + * cheap T0 PARAMS axis for the ladder (fix_header_decl.py / --fix-def-sig / cast_call_sites). + * Both forms are byte-identical, so the orchestrator may swap the return type back at zero cost. + * + * SYMBOLS (§58 rules 1/2 — all splat spellings, all verified present): + * D_80184BFC asm/ov_SC01_077/data/tail.data.s:4355 (the state-handler vtable) + * D_80184B90 asm/ov_SC01_077/data/tail.data.s:4293 + * D_8011F9C4 main-EXE data; spelled `extern s32 D_8011F9C4;` in 5+ already-banked TUs + * jtbl_801D8B74 asm/ov_SC01_077/data/tail14.data.s:15 (compiler jump table — not named in C) + * + * JTBL VERIFIED (§8a gate): compiled .rodata = exactly 0x1C B / 7 words, 7x R_MIPS_32 .text with + * addends [0x58,0x58,0x58,0xE0,0xF0,0x100,0x58] -> +0x8015B950 = [B9A8,B9A8,B9A8,BA30,BA40,BA50, + * B9A8] == the original words at 0x801D8B74..0x801D8B8C. Bound `sltiu $v0,$v1,0x7` matches. + * The raw dlabel's 8th word 0x00000000 is NOT an entry — it is the intra-TU `.align 3` pad of the + * B34/B54/B74 jtbl chain; the object can never emit it (maspsx drops .align), so it must stay in + * the post-carve RAW data piece (the §53/§62/§81 carve chain applies at bank time). + * + * Same family as the TU's own already-matched func_8015AE2C: 7-case switch on ((s32 (*)(s32))func_801619A4)() + * (0/1/2/6 shared, 3/4/5 own, no default block — out-of-range and every `break` fall to the + * after-switch join), then a chain of "state handler" tests, each dispatching + * D_80184BFC[*(u16*)arg0](arg0) and returning. + * + * THREE LEVERS (draft -> MATCH in 3 compiles): + * + * 1. PROLOGUE CONSTANT = an INITIALIZED LOCAL, not a literal in the compare. + * Target opens with `lui $s2, 0xFFF5` in the *prologue*, used once ~200 ins later in + * `slt $v0,$s2,$s1`. No gcc-2.7.2 pass hoists a (set reg const_int) across basic blocks + * (loop.c needs a loop; cse/combine/sched never move insns between BBs) — so the insn must + * have been EMITTED in the first BB, i.e. the constant is a local initialized at the top of + * the function. cse then cannot fold it back into the compare: the `slt` operand predicate is + * `arith_operand`, which rejects a CONST_INT wider than 16 bits, so validate_change fails and + * the pseudo survives. Its live range spans every call -> global.c gives it a callee-saved reg. + * Writing `z > -0xB0000` inline instead emits the `lui` into the branch delay slot next to the + * compare (caller-saved $v0) and the function is 1 insn short. => `s32 lim = -0xB0000;` at top. + * + * 2. `lh` vs `lhu`: a short->short copy is a pure HImode move and gcc emits `lhu`. The target's + * `lh $v0,0x26($s0)` means the value passed through an SImode (int) temp: expand makes + * (set (reg:SI) (sign_extend (mem:HI))) + (set (mem:HI) (subreg:HI ...)), and combine cannot + * merge them (the merged form is mem<-mem, which no movhi accepts) so the sign-extending load + * survives. => route both halfword copies through the `s32 t` temp. + * + * 3. THE `goto` LAYOUT — dodging jump.c's store-flag conversion (jump.c:1005-1065). + * An if/else chain writing 0/1 into `doit` makes gcc collapse the last pair into + * `sltiu $v0,$v0,1`. jump.c fires that conversion when the insn immediately after a + * conditional jump is a lone `SET pseudo, CONST_INT` whose following simplejump targets the + * SAME label as the branch (jump.c:1038 `reallabelprev == temp || ... JUMP_LABEL(temp4) == + * JUMP_LABEL(insn)`) — exactly the shape of `if (c) x=0; else x=1;`. + * The target instead cross-jumps ALL the `doit=0` exits into ONE shared block placed after the + * `doit=1` fall-through; reorg's fill_slots_from_thread then COPIES that single set into all + * three branch delay slots and redirects each branch past it (which is why `addu $v0,$zero, + * $zero` appears 3x in delay slots and the shared block vanishes). A `goto zero;` / `goto one;` + * chain expresses that layout directly, and each conditional jump is then followed by a + * compare/call rather than a lone const set, so the store-flag conversion never triggers. + * GENERAL RULE: multiple predicates that all assign the SAME constant to one flag => write + * them as `goto` to a shared assignment, never as an if/else ladder. + */ +extern s32 D_8011F9C4; +extern s32 D_80184B90; + +extern s32 func_80161B18(void); +extern s32 func_801619A4(s32*); +extern s32 func_80149AA8(s32*); +extern void func_80149AD4(s32*); +extern s32 func_80149B54(s32*); +extern void func_80149BAC(s32*); +extern s32 func_801498E0(s32*); +extern s32 func_80149954(s32); +extern s32 func_80149A64(s32*); +extern void func_800CCCC0(s32 a0); +extern s32 func_80149CD4(s32 a0); +extern void func_8015E880(s32*); +extern s32 func_80149744(struct S_80149744*); +extern void func_80149788(void); +extern s32 func_801496D4(void*); +extern void func_80149704(void); +extern int func_80148AFC(void*); +extern void func_80146D90(s32 a0); +extern void func_80154150(s32 a0, s32 a1); +extern void func_801541D8(u8*, s32, s32); +extern s32 func_801488A8(u8*); +extern void func_80147078(s32*, s16); +extern void func_8015A264(void*); +extern s32 func_80013294(void*, void*); +extern void func_80159B70(void*); +extern s32 func_8016F1AC(void); +extern s32 func_80029178(s32 a0); +extern void func_80146DB8(s32*, s32*); +extern s32 func_80161CD0(s32, s32); +extern s32 func_80161208(s32 a0); +extern s32 func_801725A4(u8*); + +s32 func_8015B950(s32 arg0) +{ + + extern void (*D_80184BFC[])(void *); + s16 sp10[4]; + s16 sp18[4]; + s32 t; + s32 z; + s32 doit; + s32 lim = -0xB0000; + + if (func_80161B18() != 0) { + return; + } + switch (((s32 (*)(s32))func_801619A4)(arg0)) { + case 0: + case 1: + case 2: + case 6: + if (((s32 (*)(s32))func_80149AA8)(arg0) != 0) { + D_80184BFC[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149AD4)(arg0); + return; + } + if (((s32 (*)(s32))func_80149B54)(arg0) != 0) { + D_80184BFC[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149BAC)(arg0); + return; + } + break; + case 3: + ((void (*)(s32))func_801498E0)(arg0); + break; + case 4: + ((void (*)(s32))func_80149954)(arg0); + break; + case 5: + if (((s32 (*)(s32))func_80149A64)(arg0) != 0) { + D_80184BFC[*(u16 *)arg0]((void *)arg0); + func_800CCCC0(arg0); + return; + } + break; + } + if (func_80149CD4(arg0) != 0) { + D_80184BFC[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_8015E880)(arg0); + return; + } + if (((s32 (*)(s32))func_80149744)(arg0) != 0) { + D_80184BFC[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149788)(arg0); + return; + } + if (((s32 (*)(s32))func_801496D4)(arg0) != 0) { + D_80184BFC[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149704)(arg0); + if (((u8)((s32 (*)(s32))func_80148AFC)(arg0)) == 0) { + func_80146D90(arg0); + } + if ((*(s32 *)(arg0 + 0x24) | *(s32 *)(arg0 + 0x2C)) != 0) { + func_80154150(arg0, 0xF); + } else { + ((void (*)(s32, s32, s32))func_801541D8)(arg0, 0xD, 6); + } + *(s32 *)(arg0 + 0x238) = 1; + return; + } + if (((s32 (*)(s32))func_801488A8)(arg0) != 0) { + sp10[0] = 0; + sp10[1] = 0; + sp10[2] = 0; + t = *(s16 *)(arg0 + 0x26); + sp18[0] = t; + sp18[1] = 0; + t = *(s16 *)(arg0 + 0x2E); + sp18[2] = t; + D_80184BFC[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 1); + ((void (*)(s32))func_8015A264)(arg0); + t = -(((s32 (*)(s16 *, s16 *))func_80013294)(sp10, sp18) << 0x10); + if (t < *(s32 *)(arg0 + 0x2C)) { + *(s32 *)(arg0 + 0x2C) = t; + } + return; + } + if (*(u16 *)(arg0 + 0xB8) == 0x8000) { + D_80184BFC[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 0); + ((void (*)(s32))func_80159B70)(arg0); + return; + } + z = *(s32 *)(arg0 + 0x2C); + if (func_8016F1AC() != 0) { + goto zero; + } + if (z <= lim) { + goto one; + } + if (D_8011F9C4 == 0) { + goto zero; + } + if (((u8)func_80029178(0x21)) != 0) { + goto zero; + } +one: + doit = 1; + goto join; +zero: + doit = 0; +join: + if (doit != 0) { + D_80184BFC[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 0); + ((void (*)(s32))func_80159B70)(arg0); + func_80154150(arg0, 9); + ((void (*)(s32, s32 *))func_80146DB8)(arg0, &D_80184B90); + ((void (*)(s32, s32))func_80161CD0)(arg0, *(u16 *)(arg0 + 0x16E)); + return; + } + if (func_80161208(arg0) == 0) { + ((void (*)(s32))func_801725A4)(arg0); + } +} DEFINE_func_8015BD8C() /* dedup: shared engine-core @0x8015BD8C (src/shared) */ diff --git a/src/ov_SC05_004/ov_SC05_004_jr_8015AE2C.c b/src/ov_SC05_004/ov_SC05_004_jr_8015AE2C.c index 21c5f6f68..d61e92350 100644 --- a/src/ov_SC05_004/ov_SC05_004_jr_8015AE2C.c +++ b/src/ov_SC05_004/ov_SC05_004_jr_8015AE2C.c @@ -1512,7 +1512,259 @@ DEFINE_func_8015B858() /* dedup: shared engine-core @0x8015B858 (src/shared) */ DEFINE_func_8015B8F8() /* dedup: shared engine-core @0x8015B8F8 (src/shared) */ -INCLUDE_ASM("asm/ov_SC05_004/nonmatchings/ov_SC05_004_jr_8015AE2C", func_8015B950); +extern s32 func_8015AE2C(); + +// @class: plumbing +// @stuck: none — MATCH (271/271, pin-free, zero asm). The ONLY residual is DEF-SIDE plumbing, and it is now named exactly: the in-TU instantiation `DEFINE_func_8015BEE4()` (engine_core.h:1851-1855) expands to `extern s32 func_8015B950(void);` INSIDE ov_SC01_077_jr_8015AE2C.c, ~14 lines BELOW this definition, so the 1-param def collides with a `(void)` prototype -> `conflicting types for func_8015B950` (.run/bank_func_8015B950.log). §73 PARAMS axis / T0. Surgical fix = §65b de-macroize that ONE instantiation (blast radius: this TU); the fleet-wide `(void)`->`()` header edit is §63 and must be R22-validated. +/* func_8015B950 (ov_SC01_077_jr_8015AE2C, 271 ins, jtbl_801D8B74) — SESSION-21 re-verified + * + * ── ROUND-2 INDEPENDENT RE-VERIFICATION (2026-07-27, fresh agent, §88e discipline) ───────────── + * match_one : MATCH (271 ins) against the CURRENT tree — §87 staleness re-checked today. + * .text size: compiled .text = 0x43C = 1084 B = 271 ins, EXACTLY the target's declared 0x43C + * ("nonmatching func_8015B950, 0x43C"). So this is NOT a §83a length drift hiding + * behind a zero count — the count is over equal-length streams. + * jtbl : RE-DECODED MECHANICALLY, not inherited. Compiled .rodata = 0x1C = 28 B = 7 words, + * 7x R_MIPS_32 -> .text with implicit addends [58,58,58,E0,F0,100,58]; +0x8015B950 + * = [8015B9A8, 8015B9A8, 8015B9A8, 8015BA30, 8015BA40, 8015BA50, 8015B9A8]. + * Diffed word-for-word against asm/ov_SC01_077/data/tail14.data.s:15-23 — 7/7 identical. + * symcheck : SYMS-DIFF target=35 draft=34, sole MISSING = jtbl_801D8B74. This is the §81 jr + * FALSE POSITIVE, re-confirmed here by reading the relocs: gcc emits its OWN table and + * references it with R_MIPS_HI16/LO16 against the SECTION `.rodata` (t.o +0x40/+0x48), + * so the splat's dlabel NAME can never appear in the draft object's relocation set. + * Nothing is dropped and nothing is invented: the draft's other 34 symbols are exactly + * the target's other 34. + * FAMILY : the x138 remap is clean and §84-safe. Every sibling is 271 ins with an IDENTICAL + * callee set; only THREE names vary per overlay — the two data labels and the jtbl: + * ov_SC01_077 D_80183C9C / D_80183D08 / jtbl_801D8B74 + * ov_SC03_099 D_80185A50 / D_80185ABC / jtbl_801BD898 + * ov_SC06_008 D_80187E44 / D_80187EB0 / jtbl_801A8734 + * The pair is always +0x6C apart, and NO literal in this draft encodes that distance + * (both labels are referenced by name), so there is no §84 derived-offset hazard. + * D_8011F9C4 is fleet-constant (main-EXE data) and must NOT be remapped. + * + * match_one: MATCH (271 ins) against the CURRENT tree (§87 staleness re-checked, 2026-07-27). + * PIN-FREE, zero asm, offset-pure (s32 arg0 + raw offsets) — x138 template-safe. + * Provenance: this is the Phase-26 crack (.run/phase26-cracks/func_8015B950.c) re-gated verbatim, + * with ONE deliberate change: the definition's return type void -> s32. + * - `void func_8015B950(s32 arg0)` : MATCH (271 ins) [the Phase-26 form] + * - `s32 func_8015B950(s32 arg0)` : MATCH (271 ins) [shipped — §3a-1 void->s32 is byte-neutral] + * The fleet/engine_core.h canonical decl is `extern s32 func_8015B950(void);` (engine_core.h:1852), + * and the last bank attempt (.run/bank_func_8015B950.log) died on `conflicting types for + * func_8015B950`. Shipping the s32 return kills the §73 RETURN axis for free and leaves only the + * cheap T0 PARAMS axis for the ladder (fix_header_decl.py / --fix-def-sig / cast_call_sites). + * Both forms are byte-identical, so the orchestrator may swap the return type back at zero cost. + * + * SYMBOLS (§58 rules 1/2 — all splat spellings, all verified present): + * D_80183D08 asm/ov_SC01_077/data/tail.data.s:4355 (the state-handler vtable) + * D_80183C9C asm/ov_SC01_077/data/tail.data.s:4293 + * D_8011F9C4 main-EXE data; spelled `extern s32 D_8011F9C4;` in 5+ already-banked TUs + * jtbl_801D8B74 asm/ov_SC01_077/data/tail14.data.s:15 (compiler jump table — not named in C) + * + * JTBL VERIFIED (§8a gate): compiled .rodata = exactly 0x1C B / 7 words, 7x R_MIPS_32 .text with + * addends [0x58,0x58,0x58,0xE0,0xF0,0x100,0x58] -> +0x8015B950 = [B9A8,B9A8,B9A8,BA30,BA40,BA50, + * B9A8] == the original words at 0x801D8B74..0x801D8B8C. Bound `sltiu $v0,$v1,0x7` matches. + * The raw dlabel's 8th word 0x00000000 is NOT an entry — it is the intra-TU `.align 3` pad of the + * B34/B54/B74 jtbl chain; the object can never emit it (maspsx drops .align), so it must stay in + * the post-carve RAW data piece (the §53/§62/§81 carve chain applies at bank time). + * + * Same family as the TU's own already-matched func_8015AE2C: 7-case switch on ((s32 (*)(s32))func_801619A4)() + * (0/1/2/6 shared, 3/4/5 own, no default block — out-of-range and every `break` fall to the + * after-switch join), then a chain of "state handler" tests, each dispatching + * D_80183D08[*(u16*)arg0](arg0) and returning. + * + * THREE LEVERS (draft -> MATCH in 3 compiles): + * + * 1. PROLOGUE CONSTANT = an INITIALIZED LOCAL, not a literal in the compare. + * Target opens with `lui $s2, 0xFFF5` in the *prologue*, used once ~200 ins later in + * `slt $v0,$s2,$s1`. No gcc-2.7.2 pass hoists a (set reg const_int) across basic blocks + * (loop.c needs a loop; cse/combine/sched never move insns between BBs) — so the insn must + * have been EMITTED in the first BB, i.e. the constant is a local initialized at the top of + * the function. cse then cannot fold it back into the compare: the `slt` operand predicate is + * `arith_operand`, which rejects a CONST_INT wider than 16 bits, so validate_change fails and + * the pseudo survives. Its live range spans every call -> global.c gives it a callee-saved reg. + * Writing `z > -0xB0000` inline instead emits the `lui` into the branch delay slot next to the + * compare (caller-saved $v0) and the function is 1 insn short. => `s32 lim = -0xB0000;` at top. + * + * 2. `lh` vs `lhu`: a short->short copy is a pure HImode move and gcc emits `lhu`. The target's + * `lh $v0,0x26($s0)` means the value passed through an SImode (int) temp: expand makes + * (set (reg:SI) (sign_extend (mem:HI))) + (set (mem:HI) (subreg:HI ...)), and combine cannot + * merge them (the merged form is mem<-mem, which no movhi accepts) so the sign-extending load + * survives. => route both halfword copies through the `s32 t` temp. + * + * 3. THE `goto` LAYOUT — dodging jump.c's store-flag conversion (jump.c:1005-1065). + * An if/else chain writing 0/1 into `doit` makes gcc collapse the last pair into + * `sltiu $v0,$v0,1`. jump.c fires that conversion when the insn immediately after a + * conditional jump is a lone `SET pseudo, CONST_INT` whose following simplejump targets the + * SAME label as the branch (jump.c:1038 `reallabelprev == temp || ... JUMP_LABEL(temp4) == + * JUMP_LABEL(insn)`) — exactly the shape of `if (c) x=0; else x=1;`. + * The target instead cross-jumps ALL the `doit=0` exits into ONE shared block placed after the + * `doit=1` fall-through; reorg's fill_slots_from_thread then COPIES that single set into all + * three branch delay slots and redirects each branch past it (which is why `addu $v0,$zero, + * $zero` appears 3x in delay slots and the shared block vanishes). A `goto zero;` / `goto one;` + * chain expresses that layout directly, and each conditional jump is then followed by a + * compare/call rather than a lone const set, so the store-flag conversion never triggers. + * GENERAL RULE: multiple predicates that all assign the SAME constant to one flag => write + * them as `goto` to a shared assignment, never as an if/else ladder. + */ +extern s32 D_8011F9C4; +extern s32 D_80183C9C; + +extern s32 func_80161B18(void); +extern s32 func_801619A4(s32*); +extern s32 func_80149AA8(s32*); +extern void func_80149AD4(s32*); +extern s32 func_80149B54(s32*); +extern void func_80149BAC(s32*); +extern s32 func_801498E0(s32*); +extern s32 func_80149954(s32); +extern s32 func_80149A64(s32*); +extern void func_800CCCC0(s32 a0); +extern s32 func_80149CD4(s32 a0); +extern void func_8015E880(s32*); +extern s32 func_80149744(struct S_80149744*); +extern void func_80149788(void); +extern s32 func_801496D4(void*); +extern void func_80149704(void); +extern int func_80148AFC(void*); +extern void func_80146D90(s32 a0); +extern void func_80154150(s32 a0, s32 a1); +extern void func_801541D8(u8*, s32, s32); +extern s32 func_801488A8(u8*); +extern void func_80147078(s32*, s16); +extern void func_8015A264(void*); +extern s32 func_80013294(void*, void*); +extern void func_80159B70(void*); +extern s32 func_8016F1AC(void); +extern s32 func_80029178(s32 a0); +extern void func_80146DB8(s32*, s32*); +extern s32 func_80161CD0(s32, s32); +extern s32 func_80161208(s32 a0); +extern s32 func_801725A4(u8*); + +s32 func_8015B950(s32 arg0) +{ + + extern void (*D_80183D08[])(void *); + s16 sp10[4]; + s16 sp18[4]; + s32 t; + s32 z; + s32 doit; + s32 lim = -0xB0000; + + if (func_80161B18() != 0) { + return; + } + switch (((s32 (*)(s32))func_801619A4)(arg0)) { + case 0: + case 1: + case 2: + case 6: + if (((s32 (*)(s32))func_80149AA8)(arg0) != 0) { + D_80183D08[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149AD4)(arg0); + return; + } + if (((s32 (*)(s32))func_80149B54)(arg0) != 0) { + D_80183D08[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149BAC)(arg0); + return; + } + break; + case 3: + ((void (*)(s32))func_801498E0)(arg0); + break; + case 4: + ((void (*)(s32))func_80149954)(arg0); + break; + case 5: + if (((s32 (*)(s32))func_80149A64)(arg0) != 0) { + D_80183D08[*(u16 *)arg0]((void *)arg0); + func_800CCCC0(arg0); + return; + } + break; + } + if (func_80149CD4(arg0) != 0) { + D_80183D08[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_8015E880)(arg0); + return; + } + if (((s32 (*)(s32))func_80149744)(arg0) != 0) { + D_80183D08[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149788)(arg0); + return; + } + if (((s32 (*)(s32))func_801496D4)(arg0) != 0) { + D_80183D08[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149704)(arg0); + if (((u8)((s32 (*)(s32))func_80148AFC)(arg0)) == 0) { + func_80146D90(arg0); + } + if ((*(s32 *)(arg0 + 0x24) | *(s32 *)(arg0 + 0x2C)) != 0) { + func_80154150(arg0, 0xF); + } else { + ((void (*)(s32, s32, s32))func_801541D8)(arg0, 0xD, 6); + } + *(s32 *)(arg0 + 0x238) = 1; + return; + } + if (((s32 (*)(s32))func_801488A8)(arg0) != 0) { + sp10[0] = 0; + sp10[1] = 0; + sp10[2] = 0; + t = *(s16 *)(arg0 + 0x26); + sp18[0] = t; + sp18[1] = 0; + t = *(s16 *)(arg0 + 0x2E); + sp18[2] = t; + D_80183D08[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 1); + ((void (*)(s32))func_8015A264)(arg0); + t = -(((s32 (*)(s16 *, s16 *))func_80013294)(sp10, sp18) << 0x10); + if (t < *(s32 *)(arg0 + 0x2C)) { + *(s32 *)(arg0 + 0x2C) = t; + } + return; + } + if (*(u16 *)(arg0 + 0xB8) == 0x8000) { + D_80183D08[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 0); + ((void (*)(s32))func_80159B70)(arg0); + return; + } + z = *(s32 *)(arg0 + 0x2C); + if (func_8016F1AC() != 0) { + goto zero; + } + if (z <= lim) { + goto one; + } + if (D_8011F9C4 == 0) { + goto zero; + } + if (((u8)func_80029178(0x21)) != 0) { + goto zero; + } +one: + doit = 1; + goto join; +zero: + doit = 0; +join: + if (doit != 0) { + D_80183D08[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 0); + ((void (*)(s32))func_80159B70)(arg0); + func_80154150(arg0, 9); + ((void (*)(s32, s32 *))func_80146DB8)(arg0, &D_80183C9C); + ((void (*)(s32, s32))func_80161CD0)(arg0, *(u16 *)(arg0 + 0x16E)); + return; + } + if (func_80161208(arg0) == 0) { + ((void (*)(s32))func_801725A4)(arg0); + } +} DEFINE_func_8015BD8C() /* dedup: shared engine-core @0x8015BD8C (src/shared) */ diff --git a/src/ov_SC05_005/ov_SC05_005_jr_8015AE2C.c b/src/ov_SC05_005/ov_SC05_005_jr_8015AE2C.c index 20e709f26..cfd7065e0 100644 --- a/src/ov_SC05_005/ov_SC05_005_jr_8015AE2C.c +++ b/src/ov_SC05_005/ov_SC05_005_jr_8015AE2C.c @@ -1512,7 +1512,259 @@ DEFINE_func_8015B858() /* dedup: shared engine-core @0x8015B858 (src/shared) */ DEFINE_func_8015B8F8() /* dedup: shared engine-core @0x8015B8F8 (src/shared) */ -INCLUDE_ASM("asm/ov_SC05_005/nonmatchings/ov_SC05_005_jr_8015AE2C", func_8015B950); +extern s32 func_8015AE2C(); + +// @class: plumbing +// @stuck: none — MATCH (271/271, pin-free, zero asm). The ONLY residual is DEF-SIDE plumbing, and it is now named exactly: the in-TU instantiation `DEFINE_func_8015BEE4()` (engine_core.h:1851-1855) expands to `extern s32 func_8015B950(void);` INSIDE ov_SC01_077_jr_8015AE2C.c, ~14 lines BELOW this definition, so the 1-param def collides with a `(void)` prototype -> `conflicting types for func_8015B950` (.run/bank_func_8015B950.log). §73 PARAMS axis / T0. Surgical fix = §65b de-macroize that ONE instantiation (blast radius: this TU); the fleet-wide `(void)`->`()` header edit is §63 and must be R22-validated. +/* func_8015B950 (ov_SC01_077_jr_8015AE2C, 271 ins, jtbl_801D8B74) — SESSION-21 re-verified + * + * ── ROUND-2 INDEPENDENT RE-VERIFICATION (2026-07-27, fresh agent, §88e discipline) ───────────── + * match_one : MATCH (271 ins) against the CURRENT tree — §87 staleness re-checked today. + * .text size: compiled .text = 0x43C = 1084 B = 271 ins, EXACTLY the target's declared 0x43C + * ("nonmatching func_8015B950, 0x43C"). So this is NOT a §83a length drift hiding + * behind a zero count — the count is over equal-length streams. + * jtbl : RE-DECODED MECHANICALLY, not inherited. Compiled .rodata = 0x1C = 28 B = 7 words, + * 7x R_MIPS_32 -> .text with implicit addends [58,58,58,E0,F0,100,58]; +0x8015B950 + * = [8015B9A8, 8015B9A8, 8015B9A8, 8015BA30, 8015BA40, 8015BA50, 8015B9A8]. + * Diffed word-for-word against asm/ov_SC01_077/data/tail14.data.s:15-23 — 7/7 identical. + * symcheck : SYMS-DIFF target=35 draft=34, sole MISSING = jtbl_801D8B74. This is the §81 jr + * FALSE POSITIVE, re-confirmed here by reading the relocs: gcc emits its OWN table and + * references it with R_MIPS_HI16/LO16 against the SECTION `.rodata` (t.o +0x40/+0x48), + * so the splat's dlabel NAME can never appear in the draft object's relocation set. + * Nothing is dropped and nothing is invented: the draft's other 34 symbols are exactly + * the target's other 34. + * FAMILY : the x138 remap is clean and §84-safe. Every sibling is 271 ins with an IDENTICAL + * callee set; only THREE names vary per overlay — the two data labels and the jtbl: + * ov_SC01_077 D_80184A70 / D_80184ADC / jtbl_801D8B74 + * ov_SC03_099 D_80185A50 / D_80185ABC / jtbl_801BD898 + * ov_SC06_008 D_80187E44 / D_80187EB0 / jtbl_801A8734 + * The pair is always +0x6C apart, and NO literal in this draft encodes that distance + * (both labels are referenced by name), so there is no §84 derived-offset hazard. + * D_8011F9C4 is fleet-constant (main-EXE data) and must NOT be remapped. + * + * match_one: MATCH (271 ins) against the CURRENT tree (§87 staleness re-checked, 2026-07-27). + * PIN-FREE, zero asm, offset-pure (s32 arg0 + raw offsets) — x138 template-safe. + * Provenance: this is the Phase-26 crack (.run/phase26-cracks/func_8015B950.c) re-gated verbatim, + * with ONE deliberate change: the definition's return type void -> s32. + * - `void func_8015B950(s32 arg0)` : MATCH (271 ins) [the Phase-26 form] + * - `s32 func_8015B950(s32 arg0)` : MATCH (271 ins) [shipped — §3a-1 void->s32 is byte-neutral] + * The fleet/engine_core.h canonical decl is `extern s32 func_8015B950(void);` (engine_core.h:1852), + * and the last bank attempt (.run/bank_func_8015B950.log) died on `conflicting types for + * func_8015B950`. Shipping the s32 return kills the §73 RETURN axis for free and leaves only the + * cheap T0 PARAMS axis for the ladder (fix_header_decl.py / --fix-def-sig / cast_call_sites). + * Both forms are byte-identical, so the orchestrator may swap the return type back at zero cost. + * + * SYMBOLS (§58 rules 1/2 — all splat spellings, all verified present): + * D_80184ADC asm/ov_SC01_077/data/tail.data.s:4355 (the state-handler vtable) + * D_80184A70 asm/ov_SC01_077/data/tail.data.s:4293 + * D_8011F9C4 main-EXE data; spelled `extern s32 D_8011F9C4;` in 5+ already-banked TUs + * jtbl_801D8B74 asm/ov_SC01_077/data/tail14.data.s:15 (compiler jump table — not named in C) + * + * JTBL VERIFIED (§8a gate): compiled .rodata = exactly 0x1C B / 7 words, 7x R_MIPS_32 .text with + * addends [0x58,0x58,0x58,0xE0,0xF0,0x100,0x58] -> +0x8015B950 = [B9A8,B9A8,B9A8,BA30,BA40,BA50, + * B9A8] == the original words at 0x801D8B74..0x801D8B8C. Bound `sltiu $v0,$v1,0x7` matches. + * The raw dlabel's 8th word 0x00000000 is NOT an entry — it is the intra-TU `.align 3` pad of the + * B34/B54/B74 jtbl chain; the object can never emit it (maspsx drops .align), so it must stay in + * the post-carve RAW data piece (the §53/§62/§81 carve chain applies at bank time). + * + * Same family as the TU's own already-matched func_8015AE2C: 7-case switch on ((s32 (*)(s32))func_801619A4)() + * (0/1/2/6 shared, 3/4/5 own, no default block — out-of-range and every `break` fall to the + * after-switch join), then a chain of "state handler" tests, each dispatching + * D_80184ADC[*(u16*)arg0](arg0) and returning. + * + * THREE LEVERS (draft -> MATCH in 3 compiles): + * + * 1. PROLOGUE CONSTANT = an INITIALIZED LOCAL, not a literal in the compare. + * Target opens with `lui $s2, 0xFFF5` in the *prologue*, used once ~200 ins later in + * `slt $v0,$s2,$s1`. No gcc-2.7.2 pass hoists a (set reg const_int) across basic blocks + * (loop.c needs a loop; cse/combine/sched never move insns between BBs) — so the insn must + * have been EMITTED in the first BB, i.e. the constant is a local initialized at the top of + * the function. cse then cannot fold it back into the compare: the `slt` operand predicate is + * `arith_operand`, which rejects a CONST_INT wider than 16 bits, so validate_change fails and + * the pseudo survives. Its live range spans every call -> global.c gives it a callee-saved reg. + * Writing `z > -0xB0000` inline instead emits the `lui` into the branch delay slot next to the + * compare (caller-saved $v0) and the function is 1 insn short. => `s32 lim = -0xB0000;` at top. + * + * 2. `lh` vs `lhu`: a short->short copy is a pure HImode move and gcc emits `lhu`. The target's + * `lh $v0,0x26($s0)` means the value passed through an SImode (int) temp: expand makes + * (set (reg:SI) (sign_extend (mem:HI))) + (set (mem:HI) (subreg:HI ...)), and combine cannot + * merge them (the merged form is mem<-mem, which no movhi accepts) so the sign-extending load + * survives. => route both halfword copies through the `s32 t` temp. + * + * 3. THE `goto` LAYOUT — dodging jump.c's store-flag conversion (jump.c:1005-1065). + * An if/else chain writing 0/1 into `doit` makes gcc collapse the last pair into + * `sltiu $v0,$v0,1`. jump.c fires that conversion when the insn immediately after a + * conditional jump is a lone `SET pseudo, CONST_INT` whose following simplejump targets the + * SAME label as the branch (jump.c:1038 `reallabelprev == temp || ... JUMP_LABEL(temp4) == + * JUMP_LABEL(insn)`) — exactly the shape of `if (c) x=0; else x=1;`. + * The target instead cross-jumps ALL the `doit=0` exits into ONE shared block placed after the + * `doit=1` fall-through; reorg's fill_slots_from_thread then COPIES that single set into all + * three branch delay slots and redirects each branch past it (which is why `addu $v0,$zero, + * $zero` appears 3x in delay slots and the shared block vanishes). A `goto zero;` / `goto one;` + * chain expresses that layout directly, and each conditional jump is then followed by a + * compare/call rather than a lone const set, so the store-flag conversion never triggers. + * GENERAL RULE: multiple predicates that all assign the SAME constant to one flag => write + * them as `goto` to a shared assignment, never as an if/else ladder. + */ +extern s32 D_8011F9C4; +extern s32 D_80184A70; + +extern s32 func_80161B18(void); +extern s32 func_801619A4(s32*); +extern s32 func_80149AA8(s32*); +extern void func_80149AD4(s32*); +extern s32 func_80149B54(s32*); +extern void func_80149BAC(s32*); +extern s32 func_801498E0(s32*); +extern s32 func_80149954(s32); +extern s32 func_80149A64(s32*); +extern void func_800CCCC0(s32 a0); +extern s32 func_80149CD4(s32 a0); +extern void func_8015E880(s32*); +extern s32 func_80149744(struct S_80149744*); +extern void func_80149788(void); +extern s32 func_801496D4(void*); +extern void func_80149704(void); +extern int func_80148AFC(void*); +extern void func_80146D90(s32 a0); +extern void func_80154150(s32 a0, s32 a1); +extern void func_801541D8(u8*, s32, s32); +extern s32 func_801488A8(u8*); +extern void func_80147078(s32*, s16); +extern void func_8015A264(void*); +extern s32 func_80013294(void*, void*); +extern void func_80159B70(void*); +extern s32 func_8016F1AC(void); +extern s32 func_80029178(s32 a0); +extern void func_80146DB8(s32*, s32*); +extern s32 func_80161CD0(s32, s32); +extern s32 func_80161208(s32 a0); +extern s32 func_801725A4(u8*); + +s32 func_8015B950(s32 arg0) +{ + + extern void (*D_80184ADC[])(void *); + s16 sp10[4]; + s16 sp18[4]; + s32 t; + s32 z; + s32 doit; + s32 lim = -0xB0000; + + if (func_80161B18() != 0) { + return; + } + switch (((s32 (*)(s32))func_801619A4)(arg0)) { + case 0: + case 1: + case 2: + case 6: + if (((s32 (*)(s32))func_80149AA8)(arg0) != 0) { + D_80184ADC[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149AD4)(arg0); + return; + } + if (((s32 (*)(s32))func_80149B54)(arg0) != 0) { + D_80184ADC[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149BAC)(arg0); + return; + } + break; + case 3: + ((void (*)(s32))func_801498E0)(arg0); + break; + case 4: + ((void (*)(s32))func_80149954)(arg0); + break; + case 5: + if (((s32 (*)(s32))func_80149A64)(arg0) != 0) { + D_80184ADC[*(u16 *)arg0]((void *)arg0); + func_800CCCC0(arg0); + return; + } + break; + } + if (func_80149CD4(arg0) != 0) { + D_80184ADC[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_8015E880)(arg0); + return; + } + if (((s32 (*)(s32))func_80149744)(arg0) != 0) { + D_80184ADC[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149788)(arg0); + return; + } + if (((s32 (*)(s32))func_801496D4)(arg0) != 0) { + D_80184ADC[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149704)(arg0); + if (((u8)((s32 (*)(s32))func_80148AFC)(arg0)) == 0) { + func_80146D90(arg0); + } + if ((*(s32 *)(arg0 + 0x24) | *(s32 *)(arg0 + 0x2C)) != 0) { + func_80154150(arg0, 0xF); + } else { + ((void (*)(s32, s32, s32))func_801541D8)(arg0, 0xD, 6); + } + *(s32 *)(arg0 + 0x238) = 1; + return; + } + if (((s32 (*)(s32))func_801488A8)(arg0) != 0) { + sp10[0] = 0; + sp10[1] = 0; + sp10[2] = 0; + t = *(s16 *)(arg0 + 0x26); + sp18[0] = t; + sp18[1] = 0; + t = *(s16 *)(arg0 + 0x2E); + sp18[2] = t; + D_80184ADC[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 1); + ((void (*)(s32))func_8015A264)(arg0); + t = -(((s32 (*)(s16 *, s16 *))func_80013294)(sp10, sp18) << 0x10); + if (t < *(s32 *)(arg0 + 0x2C)) { + *(s32 *)(arg0 + 0x2C) = t; + } + return; + } + if (*(u16 *)(arg0 + 0xB8) == 0x8000) { + D_80184ADC[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 0); + ((void (*)(s32))func_80159B70)(arg0); + return; + } + z = *(s32 *)(arg0 + 0x2C); + if (func_8016F1AC() != 0) { + goto zero; + } + if (z <= lim) { + goto one; + } + if (D_8011F9C4 == 0) { + goto zero; + } + if (((u8)func_80029178(0x21)) != 0) { + goto zero; + } +one: + doit = 1; + goto join; +zero: + doit = 0; +join: + if (doit != 0) { + D_80184ADC[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 0); + ((void (*)(s32))func_80159B70)(arg0); + func_80154150(arg0, 9); + ((void (*)(s32, s32 *))func_80146DB8)(arg0, &D_80184A70); + ((void (*)(s32, s32))func_80161CD0)(arg0, *(u16 *)(arg0 + 0x16E)); + return; + } + if (func_80161208(arg0) == 0) { + ((void (*)(s32))func_801725A4)(arg0); + } +} DEFINE_func_8015BD8C() /* dedup: shared engine-core @0x8015BD8C (src/shared) */ diff --git a/src/ov_SC05_006/ov_SC05_006_jr_8015AE2C.c b/src/ov_SC05_006/ov_SC05_006_jr_8015AE2C.c index 364ba5253..2573ad253 100644 --- a/src/ov_SC05_006/ov_SC05_006_jr_8015AE2C.c +++ b/src/ov_SC05_006/ov_SC05_006_jr_8015AE2C.c @@ -1512,7 +1512,259 @@ DEFINE_func_8015B858() /* dedup: shared engine-core @0x8015B858 (src/shared) */ DEFINE_func_8015B8F8() /* dedup: shared engine-core @0x8015B8F8 (src/shared) */ -INCLUDE_ASM("asm/ov_SC05_006/nonmatchings/ov_SC05_006_jr_8015AE2C", func_8015B950); +extern s32 func_8015AE2C(); + +// @class: plumbing +// @stuck: none — MATCH (271/271, pin-free, zero asm). The ONLY residual is DEF-SIDE plumbing, and it is now named exactly: the in-TU instantiation `DEFINE_func_8015BEE4()` (engine_core.h:1851-1855) expands to `extern s32 func_8015B950(void);` INSIDE ov_SC01_077_jr_8015AE2C.c, ~14 lines BELOW this definition, so the 1-param def collides with a `(void)` prototype -> `conflicting types for func_8015B950` (.run/bank_func_8015B950.log). §73 PARAMS axis / T0. Surgical fix = §65b de-macroize that ONE instantiation (blast radius: this TU); the fleet-wide `(void)`->`()` header edit is §63 and must be R22-validated. +/* func_8015B950 (ov_SC01_077_jr_8015AE2C, 271 ins, jtbl_801D8B74) — SESSION-21 re-verified + * + * ── ROUND-2 INDEPENDENT RE-VERIFICATION (2026-07-27, fresh agent, §88e discipline) ───────────── + * match_one : MATCH (271 ins) against the CURRENT tree — §87 staleness re-checked today. + * .text size: compiled .text = 0x43C = 1084 B = 271 ins, EXACTLY the target's declared 0x43C + * ("nonmatching func_8015B950, 0x43C"). So this is NOT a §83a length drift hiding + * behind a zero count — the count is over equal-length streams. + * jtbl : RE-DECODED MECHANICALLY, not inherited. Compiled .rodata = 0x1C = 28 B = 7 words, + * 7x R_MIPS_32 -> .text with implicit addends [58,58,58,E0,F0,100,58]; +0x8015B950 + * = [8015B9A8, 8015B9A8, 8015B9A8, 8015BA30, 8015BA40, 8015BA50, 8015B9A8]. + * Diffed word-for-word against asm/ov_SC01_077/data/tail14.data.s:15-23 — 7/7 identical. + * symcheck : SYMS-DIFF target=35 draft=34, sole MISSING = jtbl_801D8B74. This is the §81 jr + * FALSE POSITIVE, re-confirmed here by reading the relocs: gcc emits its OWN table and + * references it with R_MIPS_HI16/LO16 against the SECTION `.rodata` (t.o +0x40/+0x48), + * so the splat's dlabel NAME can never appear in the draft object's relocation set. + * Nothing is dropped and nothing is invented: the draft's other 34 symbols are exactly + * the target's other 34. + * FAMILY : the x138 remap is clean and §84-safe. Every sibling is 271 ins with an IDENTICAL + * callee set; only THREE names vary per overlay — the two data labels and the jtbl: + * ov_SC01_077 D_80181A90 / D_80181AFC / jtbl_801D8B74 + * ov_SC03_099 D_80185A50 / D_80185ABC / jtbl_801BD898 + * ov_SC06_008 D_80187E44 / D_80187EB0 / jtbl_801A8734 + * The pair is always +0x6C apart, and NO literal in this draft encodes that distance + * (both labels are referenced by name), so there is no §84 derived-offset hazard. + * D_8011F9C4 is fleet-constant (main-EXE data) and must NOT be remapped. + * + * match_one: MATCH (271 ins) against the CURRENT tree (§87 staleness re-checked, 2026-07-27). + * PIN-FREE, zero asm, offset-pure (s32 arg0 + raw offsets) — x138 template-safe. + * Provenance: this is the Phase-26 crack (.run/phase26-cracks/func_8015B950.c) re-gated verbatim, + * with ONE deliberate change: the definition's return type void -> s32. + * - `void func_8015B950(s32 arg0)` : MATCH (271 ins) [the Phase-26 form] + * - `s32 func_8015B950(s32 arg0)` : MATCH (271 ins) [shipped — §3a-1 void->s32 is byte-neutral] + * The fleet/engine_core.h canonical decl is `extern s32 func_8015B950(void);` (engine_core.h:1852), + * and the last bank attempt (.run/bank_func_8015B950.log) died on `conflicting types for + * func_8015B950`. Shipping the s32 return kills the §73 RETURN axis for free and leaves only the + * cheap T0 PARAMS axis for the ladder (fix_header_decl.py / --fix-def-sig / cast_call_sites). + * Both forms are byte-identical, so the orchestrator may swap the return type back at zero cost. + * + * SYMBOLS (§58 rules 1/2 — all splat spellings, all verified present): + * D_80181AFC asm/ov_SC01_077/data/tail.data.s:4355 (the state-handler vtable) + * D_80181A90 asm/ov_SC01_077/data/tail.data.s:4293 + * D_8011F9C4 main-EXE data; spelled `extern s32 D_8011F9C4;` in 5+ already-banked TUs + * jtbl_801D8B74 asm/ov_SC01_077/data/tail14.data.s:15 (compiler jump table — not named in C) + * + * JTBL VERIFIED (§8a gate): compiled .rodata = exactly 0x1C B / 7 words, 7x R_MIPS_32 .text with + * addends [0x58,0x58,0x58,0xE0,0xF0,0x100,0x58] -> +0x8015B950 = [B9A8,B9A8,B9A8,BA30,BA40,BA50, + * B9A8] == the original words at 0x801D8B74..0x801D8B8C. Bound `sltiu $v0,$v1,0x7` matches. + * The raw dlabel's 8th word 0x00000000 is NOT an entry — it is the intra-TU `.align 3` pad of the + * B34/B54/B74 jtbl chain; the object can never emit it (maspsx drops .align), so it must stay in + * the post-carve RAW data piece (the §53/§62/§81 carve chain applies at bank time). + * + * Same family as the TU's own already-matched func_8015AE2C: 7-case switch on ((s32 (*)(s32))func_801619A4)() + * (0/1/2/6 shared, 3/4/5 own, no default block — out-of-range and every `break` fall to the + * after-switch join), then a chain of "state handler" tests, each dispatching + * D_80181AFC[*(u16*)arg0](arg0) and returning. + * + * THREE LEVERS (draft -> MATCH in 3 compiles): + * + * 1. PROLOGUE CONSTANT = an INITIALIZED LOCAL, not a literal in the compare. + * Target opens with `lui $s2, 0xFFF5` in the *prologue*, used once ~200 ins later in + * `slt $v0,$s2,$s1`. No gcc-2.7.2 pass hoists a (set reg const_int) across basic blocks + * (loop.c needs a loop; cse/combine/sched never move insns between BBs) — so the insn must + * have been EMITTED in the first BB, i.e. the constant is a local initialized at the top of + * the function. cse then cannot fold it back into the compare: the `slt` operand predicate is + * `arith_operand`, which rejects a CONST_INT wider than 16 bits, so validate_change fails and + * the pseudo survives. Its live range spans every call -> global.c gives it a callee-saved reg. + * Writing `z > -0xB0000` inline instead emits the `lui` into the branch delay slot next to the + * compare (caller-saved $v0) and the function is 1 insn short. => `s32 lim = -0xB0000;` at top. + * + * 2. `lh` vs `lhu`: a short->short copy is a pure HImode move and gcc emits `lhu`. The target's + * `lh $v0,0x26($s0)` means the value passed through an SImode (int) temp: expand makes + * (set (reg:SI) (sign_extend (mem:HI))) + (set (mem:HI) (subreg:HI ...)), and combine cannot + * merge them (the merged form is mem<-mem, which no movhi accepts) so the sign-extending load + * survives. => route both halfword copies through the `s32 t` temp. + * + * 3. THE `goto` LAYOUT — dodging jump.c's store-flag conversion (jump.c:1005-1065). + * An if/else chain writing 0/1 into `doit` makes gcc collapse the last pair into + * `sltiu $v0,$v0,1`. jump.c fires that conversion when the insn immediately after a + * conditional jump is a lone `SET pseudo, CONST_INT` whose following simplejump targets the + * SAME label as the branch (jump.c:1038 `reallabelprev == temp || ... JUMP_LABEL(temp4) == + * JUMP_LABEL(insn)`) — exactly the shape of `if (c) x=0; else x=1;`. + * The target instead cross-jumps ALL the `doit=0` exits into ONE shared block placed after the + * `doit=1` fall-through; reorg's fill_slots_from_thread then COPIES that single set into all + * three branch delay slots and redirects each branch past it (which is why `addu $v0,$zero, + * $zero` appears 3x in delay slots and the shared block vanishes). A `goto zero;` / `goto one;` + * chain expresses that layout directly, and each conditional jump is then followed by a + * compare/call rather than a lone const set, so the store-flag conversion never triggers. + * GENERAL RULE: multiple predicates that all assign the SAME constant to one flag => write + * them as `goto` to a shared assignment, never as an if/else ladder. + */ +extern s32 D_8011F9C4; +extern s32 D_80181A90; + +extern s32 func_80161B18(void); +extern s32 func_801619A4(s32*); +extern s32 func_80149AA8(s32*); +extern void func_80149AD4(s32*); +extern s32 func_80149B54(s32*); +extern void func_80149BAC(s32*); +extern s32 func_801498E0(s32*); +extern s32 func_80149954(s32); +extern s32 func_80149A64(s32*); +extern void func_800CCCC0(s32 a0); +extern s32 func_80149CD4(s32 a0); +extern void func_8015E880(s32*); +extern s32 func_80149744(struct S_80149744*); +extern void func_80149788(void); +extern s32 func_801496D4(void*); +extern void func_80149704(void); +extern int func_80148AFC(void*); +extern void func_80146D90(s32 a0); +extern void func_80154150(s32 a0, s32 a1); +extern void func_801541D8(u8*, s32, s32); +extern s32 func_801488A8(u8*); +extern void func_80147078(s32*, s16); +extern void func_8015A264(void*); +extern s32 func_80013294(void*, void*); +extern void func_80159B70(void*); +extern s32 func_8016F1AC(void); +extern s32 func_80029178(s32 a0); +extern void func_80146DB8(s32*, s32*); +extern s32 func_80161CD0(s32, s32); +extern s32 func_80161208(s32 a0); +extern s32 func_801725A4(u8*); + +s32 func_8015B950(s32 arg0) +{ + + extern void (*D_80181AFC[])(void *); + s16 sp10[4]; + s16 sp18[4]; + s32 t; + s32 z; + s32 doit; + s32 lim = -0xB0000; + + if (func_80161B18() != 0) { + return; + } + switch (((s32 (*)(s32))func_801619A4)(arg0)) { + case 0: + case 1: + case 2: + case 6: + if (((s32 (*)(s32))func_80149AA8)(arg0) != 0) { + D_80181AFC[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149AD4)(arg0); + return; + } + if (((s32 (*)(s32))func_80149B54)(arg0) != 0) { + D_80181AFC[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149BAC)(arg0); + return; + } + break; + case 3: + ((void (*)(s32))func_801498E0)(arg0); + break; + case 4: + ((void (*)(s32))func_80149954)(arg0); + break; + case 5: + if (((s32 (*)(s32))func_80149A64)(arg0) != 0) { + D_80181AFC[*(u16 *)arg0]((void *)arg0); + func_800CCCC0(arg0); + return; + } + break; + } + if (func_80149CD4(arg0) != 0) { + D_80181AFC[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_8015E880)(arg0); + return; + } + if (((s32 (*)(s32))func_80149744)(arg0) != 0) { + D_80181AFC[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149788)(arg0); + return; + } + if (((s32 (*)(s32))func_801496D4)(arg0) != 0) { + D_80181AFC[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149704)(arg0); + if (((u8)((s32 (*)(s32))func_80148AFC)(arg0)) == 0) { + func_80146D90(arg0); + } + if ((*(s32 *)(arg0 + 0x24) | *(s32 *)(arg0 + 0x2C)) != 0) { + func_80154150(arg0, 0xF); + } else { + ((void (*)(s32, s32, s32))func_801541D8)(arg0, 0xD, 6); + } + *(s32 *)(arg0 + 0x238) = 1; + return; + } + if (((s32 (*)(s32))func_801488A8)(arg0) != 0) { + sp10[0] = 0; + sp10[1] = 0; + sp10[2] = 0; + t = *(s16 *)(arg0 + 0x26); + sp18[0] = t; + sp18[1] = 0; + t = *(s16 *)(arg0 + 0x2E); + sp18[2] = t; + D_80181AFC[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 1); + ((void (*)(s32))func_8015A264)(arg0); + t = -(((s32 (*)(s16 *, s16 *))func_80013294)(sp10, sp18) << 0x10); + if (t < *(s32 *)(arg0 + 0x2C)) { + *(s32 *)(arg0 + 0x2C) = t; + } + return; + } + if (*(u16 *)(arg0 + 0xB8) == 0x8000) { + D_80181AFC[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 0); + ((void (*)(s32))func_80159B70)(arg0); + return; + } + z = *(s32 *)(arg0 + 0x2C); + if (func_8016F1AC() != 0) { + goto zero; + } + if (z <= lim) { + goto one; + } + if (D_8011F9C4 == 0) { + goto zero; + } + if (((u8)func_80029178(0x21)) != 0) { + goto zero; + } +one: + doit = 1; + goto join; +zero: + doit = 0; +join: + if (doit != 0) { + D_80181AFC[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 0); + ((void (*)(s32))func_80159B70)(arg0); + func_80154150(arg0, 9); + ((void (*)(s32, s32 *))func_80146DB8)(arg0, &D_80181A90); + ((void (*)(s32, s32))func_80161CD0)(arg0, *(u16 *)(arg0 + 0x16E)); + return; + } + if (func_80161208(arg0) == 0) { + ((void (*)(s32))func_801725A4)(arg0); + } +} DEFINE_func_8015BD8C() /* dedup: shared engine-core @0x8015BD8C (src/shared) */ diff --git a/src/ov_SC05_007/ov_SC05_007_jr_8015AE2C.c b/src/ov_SC05_007/ov_SC05_007_jr_8015AE2C.c index ff4a6be2f..0ed863b38 100644 --- a/src/ov_SC05_007/ov_SC05_007_jr_8015AE2C.c +++ b/src/ov_SC05_007/ov_SC05_007_jr_8015AE2C.c @@ -1512,7 +1512,259 @@ DEFINE_func_8015B858() /* dedup: shared engine-core @0x8015B858 (src/shared) */ DEFINE_func_8015B8F8() /* dedup: shared engine-core @0x8015B8F8 (src/shared) */ -INCLUDE_ASM("asm/ov_SC05_007/nonmatchings/ov_SC05_007_jr_8015AE2C", func_8015B950); +extern s32 func_8015AE2C(); + +// @class: plumbing +// @stuck: none — MATCH (271/271, pin-free, zero asm). The ONLY residual is DEF-SIDE plumbing, and it is now named exactly: the in-TU instantiation `DEFINE_func_8015BEE4()` (engine_core.h:1851-1855) expands to `extern s32 func_8015B950(void);` INSIDE ov_SC01_077_jr_8015AE2C.c, ~14 lines BELOW this definition, so the 1-param def collides with a `(void)` prototype -> `conflicting types for func_8015B950` (.run/bank_func_8015B950.log). §73 PARAMS axis / T0. Surgical fix = §65b de-macroize that ONE instantiation (blast radius: this TU); the fleet-wide `(void)`->`()` header edit is §63 and must be R22-validated. +/* func_8015B950 (ov_SC01_077_jr_8015AE2C, 271 ins, jtbl_801D8B74) — SESSION-21 re-verified + * + * ── ROUND-2 INDEPENDENT RE-VERIFICATION (2026-07-27, fresh agent, §88e discipline) ───────────── + * match_one : MATCH (271 ins) against the CURRENT tree — §87 staleness re-checked today. + * .text size: compiled .text = 0x43C = 1084 B = 271 ins, EXACTLY the target's declared 0x43C + * ("nonmatching func_8015B950, 0x43C"). So this is NOT a §83a length drift hiding + * behind a zero count — the count is over equal-length streams. + * jtbl : RE-DECODED MECHANICALLY, not inherited. Compiled .rodata = 0x1C = 28 B = 7 words, + * 7x R_MIPS_32 -> .text with implicit addends [58,58,58,E0,F0,100,58]; +0x8015B950 + * = [8015B9A8, 8015B9A8, 8015B9A8, 8015BA30, 8015BA40, 8015BA50, 8015B9A8]. + * Diffed word-for-word against asm/ov_SC01_077/data/tail14.data.s:15-23 — 7/7 identical. + * symcheck : SYMS-DIFF target=35 draft=34, sole MISSING = jtbl_801D8B74. This is the §81 jr + * FALSE POSITIVE, re-confirmed here by reading the relocs: gcc emits its OWN table and + * references it with R_MIPS_HI16/LO16 against the SECTION `.rodata` (t.o +0x40/+0x48), + * so the splat's dlabel NAME can never appear in the draft object's relocation set. + * Nothing is dropped and nothing is invented: the draft's other 34 symbols are exactly + * the target's other 34. + * FAMILY : the x138 remap is clean and §84-safe. Every sibling is 271 ins with an IDENTICAL + * callee set; only THREE names vary per overlay — the two data labels and the jtbl: + * ov_SC01_077 D_8018308C / D_801830F8 / jtbl_801D8B74 + * ov_SC03_099 D_80185A50 / D_80185ABC / jtbl_801BD898 + * ov_SC06_008 D_80187E44 / D_80187EB0 / jtbl_801A8734 + * The pair is always +0x6C apart, and NO literal in this draft encodes that distance + * (both labels are referenced by name), so there is no §84 derived-offset hazard. + * D_8011F9C4 is fleet-constant (main-EXE data) and must NOT be remapped. + * + * match_one: MATCH (271 ins) against the CURRENT tree (§87 staleness re-checked, 2026-07-27). + * PIN-FREE, zero asm, offset-pure (s32 arg0 + raw offsets) — x138 template-safe. + * Provenance: this is the Phase-26 crack (.run/phase26-cracks/func_8015B950.c) re-gated verbatim, + * with ONE deliberate change: the definition's return type void -> s32. + * - `void func_8015B950(s32 arg0)` : MATCH (271 ins) [the Phase-26 form] + * - `s32 func_8015B950(s32 arg0)` : MATCH (271 ins) [shipped — §3a-1 void->s32 is byte-neutral] + * The fleet/engine_core.h canonical decl is `extern s32 func_8015B950(void);` (engine_core.h:1852), + * and the last bank attempt (.run/bank_func_8015B950.log) died on `conflicting types for + * func_8015B950`. Shipping the s32 return kills the §73 RETURN axis for free and leaves only the + * cheap T0 PARAMS axis for the ladder (fix_header_decl.py / --fix-def-sig / cast_call_sites). + * Both forms are byte-identical, so the orchestrator may swap the return type back at zero cost. + * + * SYMBOLS (§58 rules 1/2 — all splat spellings, all verified present): + * D_801830F8 asm/ov_SC01_077/data/tail.data.s:4355 (the state-handler vtable) + * D_8018308C asm/ov_SC01_077/data/tail.data.s:4293 + * D_8011F9C4 main-EXE data; spelled `extern s32 D_8011F9C4;` in 5+ already-banked TUs + * jtbl_801D8B74 asm/ov_SC01_077/data/tail14.data.s:15 (compiler jump table — not named in C) + * + * JTBL VERIFIED (§8a gate): compiled .rodata = exactly 0x1C B / 7 words, 7x R_MIPS_32 .text with + * addends [0x58,0x58,0x58,0xE0,0xF0,0x100,0x58] -> +0x8015B950 = [B9A8,B9A8,B9A8,BA30,BA40,BA50, + * B9A8] == the original words at 0x801D8B74..0x801D8B8C. Bound `sltiu $v0,$v1,0x7` matches. + * The raw dlabel's 8th word 0x00000000 is NOT an entry — it is the intra-TU `.align 3` pad of the + * B34/B54/B74 jtbl chain; the object can never emit it (maspsx drops .align), so it must stay in + * the post-carve RAW data piece (the §53/§62/§81 carve chain applies at bank time). + * + * Same family as the TU's own already-matched func_8015AE2C: 7-case switch on ((s32 (*)(s32))func_801619A4)() + * (0/1/2/6 shared, 3/4/5 own, no default block — out-of-range and every `break` fall to the + * after-switch join), then a chain of "state handler" tests, each dispatching + * D_801830F8[*(u16*)arg0](arg0) and returning. + * + * THREE LEVERS (draft -> MATCH in 3 compiles): + * + * 1. PROLOGUE CONSTANT = an INITIALIZED LOCAL, not a literal in the compare. + * Target opens with `lui $s2, 0xFFF5` in the *prologue*, used once ~200 ins later in + * `slt $v0,$s2,$s1`. No gcc-2.7.2 pass hoists a (set reg const_int) across basic blocks + * (loop.c needs a loop; cse/combine/sched never move insns between BBs) — so the insn must + * have been EMITTED in the first BB, i.e. the constant is a local initialized at the top of + * the function. cse then cannot fold it back into the compare: the `slt` operand predicate is + * `arith_operand`, which rejects a CONST_INT wider than 16 bits, so validate_change fails and + * the pseudo survives. Its live range spans every call -> global.c gives it a callee-saved reg. + * Writing `z > -0xB0000` inline instead emits the `lui` into the branch delay slot next to the + * compare (caller-saved $v0) and the function is 1 insn short. => `s32 lim = -0xB0000;` at top. + * + * 2. `lh` vs `lhu`: a short->short copy is a pure HImode move and gcc emits `lhu`. The target's + * `lh $v0,0x26($s0)` means the value passed through an SImode (int) temp: expand makes + * (set (reg:SI) (sign_extend (mem:HI))) + (set (mem:HI) (subreg:HI ...)), and combine cannot + * merge them (the merged form is mem<-mem, which no movhi accepts) so the sign-extending load + * survives. => route both halfword copies through the `s32 t` temp. + * + * 3. THE `goto` LAYOUT — dodging jump.c's store-flag conversion (jump.c:1005-1065). + * An if/else chain writing 0/1 into `doit` makes gcc collapse the last pair into + * `sltiu $v0,$v0,1`. jump.c fires that conversion when the insn immediately after a + * conditional jump is a lone `SET pseudo, CONST_INT` whose following simplejump targets the + * SAME label as the branch (jump.c:1038 `reallabelprev == temp || ... JUMP_LABEL(temp4) == + * JUMP_LABEL(insn)`) — exactly the shape of `if (c) x=0; else x=1;`. + * The target instead cross-jumps ALL the `doit=0` exits into ONE shared block placed after the + * `doit=1` fall-through; reorg's fill_slots_from_thread then COPIES that single set into all + * three branch delay slots and redirects each branch past it (which is why `addu $v0,$zero, + * $zero` appears 3x in delay slots and the shared block vanishes). A `goto zero;` / `goto one;` + * chain expresses that layout directly, and each conditional jump is then followed by a + * compare/call rather than a lone const set, so the store-flag conversion never triggers. + * GENERAL RULE: multiple predicates that all assign the SAME constant to one flag => write + * them as `goto` to a shared assignment, never as an if/else ladder. + */ +extern s32 D_8011F9C4; +extern s32 D_8018308C; + +extern s32 func_80161B18(void); +extern s32 func_801619A4(s32*); +extern s32 func_80149AA8(s32*); +extern void func_80149AD4(s32*); +extern s32 func_80149B54(s32*); +extern void func_80149BAC(s32*); +extern s32 func_801498E0(s32*); +extern s32 func_80149954(s32); +extern s32 func_80149A64(s32*); +extern void func_800CCCC0(s32 a0); +extern s32 func_80149CD4(s32 a0); +extern void func_8015E880(s32*); +extern s32 func_80149744(struct S_80149744*); +extern void func_80149788(void); +extern s32 func_801496D4(void*); +extern void func_80149704(void); +extern int func_80148AFC(void*); +extern void func_80146D90(s32 a0); +extern void func_80154150(s32 a0, s32 a1); +extern void func_801541D8(u8*, s32, s32); +extern s32 func_801488A8(u8*); +extern void func_80147078(s32*, s16); +extern void func_8015A264(void*); +extern s32 func_80013294(void*, void*); +extern void func_80159B70(void*); +extern s32 func_8016F1AC(void); +extern s32 func_80029178(s32 a0); +extern void func_80146DB8(s32*, s32*); +extern s32 func_80161CD0(s32, s32); +extern s32 func_80161208(s32 a0); +extern s32 func_801725A4(u8*); + +s32 func_8015B950(s32 arg0) +{ + + extern void (*D_801830F8[])(void *); + s16 sp10[4]; + s16 sp18[4]; + s32 t; + s32 z; + s32 doit; + s32 lim = -0xB0000; + + if (func_80161B18() != 0) { + return; + } + switch (((s32 (*)(s32))func_801619A4)(arg0)) { + case 0: + case 1: + case 2: + case 6: + if (((s32 (*)(s32))func_80149AA8)(arg0) != 0) { + D_801830F8[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149AD4)(arg0); + return; + } + if (((s32 (*)(s32))func_80149B54)(arg0) != 0) { + D_801830F8[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149BAC)(arg0); + return; + } + break; + case 3: + ((void (*)(s32))func_801498E0)(arg0); + break; + case 4: + ((void (*)(s32))func_80149954)(arg0); + break; + case 5: + if (((s32 (*)(s32))func_80149A64)(arg0) != 0) { + D_801830F8[*(u16 *)arg0]((void *)arg0); + func_800CCCC0(arg0); + return; + } + break; + } + if (func_80149CD4(arg0) != 0) { + D_801830F8[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_8015E880)(arg0); + return; + } + if (((s32 (*)(s32))func_80149744)(arg0) != 0) { + D_801830F8[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149788)(arg0); + return; + } + if (((s32 (*)(s32))func_801496D4)(arg0) != 0) { + D_801830F8[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149704)(arg0); + if (((u8)((s32 (*)(s32))func_80148AFC)(arg0)) == 0) { + func_80146D90(arg0); + } + if ((*(s32 *)(arg0 + 0x24) | *(s32 *)(arg0 + 0x2C)) != 0) { + func_80154150(arg0, 0xF); + } else { + ((void (*)(s32, s32, s32))func_801541D8)(arg0, 0xD, 6); + } + *(s32 *)(arg0 + 0x238) = 1; + return; + } + if (((s32 (*)(s32))func_801488A8)(arg0) != 0) { + sp10[0] = 0; + sp10[1] = 0; + sp10[2] = 0; + t = *(s16 *)(arg0 + 0x26); + sp18[0] = t; + sp18[1] = 0; + t = *(s16 *)(arg0 + 0x2E); + sp18[2] = t; + D_801830F8[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 1); + ((void (*)(s32))func_8015A264)(arg0); + t = -(((s32 (*)(s16 *, s16 *))func_80013294)(sp10, sp18) << 0x10); + if (t < *(s32 *)(arg0 + 0x2C)) { + *(s32 *)(arg0 + 0x2C) = t; + } + return; + } + if (*(u16 *)(arg0 + 0xB8) == 0x8000) { + D_801830F8[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 0); + ((void (*)(s32))func_80159B70)(arg0); + return; + } + z = *(s32 *)(arg0 + 0x2C); + if (func_8016F1AC() != 0) { + goto zero; + } + if (z <= lim) { + goto one; + } + if (D_8011F9C4 == 0) { + goto zero; + } + if (((u8)func_80029178(0x21)) != 0) { + goto zero; + } +one: + doit = 1; + goto join; +zero: + doit = 0; +join: + if (doit != 0) { + D_801830F8[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 0); + ((void (*)(s32))func_80159B70)(arg0); + func_80154150(arg0, 9); + ((void (*)(s32, s32 *))func_80146DB8)(arg0, &D_8018308C); + ((void (*)(s32, s32))func_80161CD0)(arg0, *(u16 *)(arg0 + 0x16E)); + return; + } + if (func_80161208(arg0) == 0) { + ((void (*)(s32))func_801725A4)(arg0); + } +} DEFINE_func_8015BD8C() /* dedup: shared engine-core @0x8015BD8C (src/shared) */ diff --git a/src/ov_SC05_008/ov_SC05_008_jr_8015AE2C.c b/src/ov_SC05_008/ov_SC05_008_jr_8015AE2C.c index 9aa4c8c56..2aedab090 100644 --- a/src/ov_SC05_008/ov_SC05_008_jr_8015AE2C.c +++ b/src/ov_SC05_008/ov_SC05_008_jr_8015AE2C.c @@ -1512,7 +1512,259 @@ DEFINE_func_8015B858() /* dedup: shared engine-core @0x8015B858 (src/shared) */ DEFINE_func_8015B8F8() /* dedup: shared engine-core @0x8015B8F8 (src/shared) */ -INCLUDE_ASM("asm/ov_SC05_008/nonmatchings/ov_SC05_008_jr_8015AE2C", func_8015B950); +extern s32 func_8015AE2C(); + +// @class: plumbing +// @stuck: none — MATCH (271/271, pin-free, zero asm). The ONLY residual is DEF-SIDE plumbing, and it is now named exactly: the in-TU instantiation `DEFINE_func_8015BEE4()` (engine_core.h:1851-1855) expands to `extern s32 func_8015B950(void);` INSIDE ov_SC01_077_jr_8015AE2C.c, ~14 lines BELOW this definition, so the 1-param def collides with a `(void)` prototype -> `conflicting types for func_8015B950` (.run/bank_func_8015B950.log). §73 PARAMS axis / T0. Surgical fix = §65b de-macroize that ONE instantiation (blast radius: this TU); the fleet-wide `(void)`->`()` header edit is §63 and must be R22-validated. +/* func_8015B950 (ov_SC01_077_jr_8015AE2C, 271 ins, jtbl_801D8B74) — SESSION-21 re-verified + * + * ── ROUND-2 INDEPENDENT RE-VERIFICATION (2026-07-27, fresh agent, §88e discipline) ───────────── + * match_one : MATCH (271 ins) against the CURRENT tree — §87 staleness re-checked today. + * .text size: compiled .text = 0x43C = 1084 B = 271 ins, EXACTLY the target's declared 0x43C + * ("nonmatching func_8015B950, 0x43C"). So this is NOT a §83a length drift hiding + * behind a zero count — the count is over equal-length streams. + * jtbl : RE-DECODED MECHANICALLY, not inherited. Compiled .rodata = 0x1C = 28 B = 7 words, + * 7x R_MIPS_32 -> .text with implicit addends [58,58,58,E0,F0,100,58]; +0x8015B950 + * = [8015B9A8, 8015B9A8, 8015B9A8, 8015BA30, 8015BA40, 8015BA50, 8015B9A8]. + * Diffed word-for-word against asm/ov_SC01_077/data/tail14.data.s:15-23 — 7/7 identical. + * symcheck : SYMS-DIFF target=35 draft=34, sole MISSING = jtbl_801D8B74. This is the §81 jr + * FALSE POSITIVE, re-confirmed here by reading the relocs: gcc emits its OWN table and + * references it with R_MIPS_HI16/LO16 against the SECTION `.rodata` (t.o +0x40/+0x48), + * so the splat's dlabel NAME can never appear in the draft object's relocation set. + * Nothing is dropped and nothing is invented: the draft's other 34 symbols are exactly + * the target's other 34. + * FAMILY : the x138 remap is clean and §84-safe. Every sibling is 271 ins with an IDENTICAL + * callee set; only THREE names vary per overlay — the two data labels and the jtbl: + * ov_SC01_077 D_80184FE4 / D_80185050 / jtbl_801D8B74 + * ov_SC03_099 D_80185A50 / D_80185ABC / jtbl_801BD898 + * ov_SC06_008 D_80187E44 / D_80187EB0 / jtbl_801A8734 + * The pair is always +0x6C apart, and NO literal in this draft encodes that distance + * (both labels are referenced by name), so there is no §84 derived-offset hazard. + * D_8011F9C4 is fleet-constant (main-EXE data) and must NOT be remapped. + * + * match_one: MATCH (271 ins) against the CURRENT tree (§87 staleness re-checked, 2026-07-27). + * PIN-FREE, zero asm, offset-pure (s32 arg0 + raw offsets) — x138 template-safe. + * Provenance: this is the Phase-26 crack (.run/phase26-cracks/func_8015B950.c) re-gated verbatim, + * with ONE deliberate change: the definition's return type void -> s32. + * - `void func_8015B950(s32 arg0)` : MATCH (271 ins) [the Phase-26 form] + * - `s32 func_8015B950(s32 arg0)` : MATCH (271 ins) [shipped — §3a-1 void->s32 is byte-neutral] + * The fleet/engine_core.h canonical decl is `extern s32 func_8015B950(void);` (engine_core.h:1852), + * and the last bank attempt (.run/bank_func_8015B950.log) died on `conflicting types for + * func_8015B950`. Shipping the s32 return kills the §73 RETURN axis for free and leaves only the + * cheap T0 PARAMS axis for the ladder (fix_header_decl.py / --fix-def-sig / cast_call_sites). + * Both forms are byte-identical, so the orchestrator may swap the return type back at zero cost. + * + * SYMBOLS (§58 rules 1/2 — all splat spellings, all verified present): + * D_80185050 asm/ov_SC01_077/data/tail.data.s:4355 (the state-handler vtable) + * D_80184FE4 asm/ov_SC01_077/data/tail.data.s:4293 + * D_8011F9C4 main-EXE data; spelled `extern s32 D_8011F9C4;` in 5+ already-banked TUs + * jtbl_801D8B74 asm/ov_SC01_077/data/tail14.data.s:15 (compiler jump table — not named in C) + * + * JTBL VERIFIED (§8a gate): compiled .rodata = exactly 0x1C B / 7 words, 7x R_MIPS_32 .text with + * addends [0x58,0x58,0x58,0xE0,0xF0,0x100,0x58] -> +0x8015B950 = [B9A8,B9A8,B9A8,BA30,BA40,BA50, + * B9A8] == the original words at 0x801D8B74..0x801D8B8C. Bound `sltiu $v0,$v1,0x7` matches. + * The raw dlabel's 8th word 0x00000000 is NOT an entry — it is the intra-TU `.align 3` pad of the + * B34/B54/B74 jtbl chain; the object can never emit it (maspsx drops .align), so it must stay in + * the post-carve RAW data piece (the §53/§62/§81 carve chain applies at bank time). + * + * Same family as the TU's own already-matched func_8015AE2C: 7-case switch on ((s32 (*)(s32))func_801619A4)() + * (0/1/2/6 shared, 3/4/5 own, no default block — out-of-range and every `break` fall to the + * after-switch join), then a chain of "state handler" tests, each dispatching + * D_80185050[*(u16*)arg0](arg0) and returning. + * + * THREE LEVERS (draft -> MATCH in 3 compiles): + * + * 1. PROLOGUE CONSTANT = an INITIALIZED LOCAL, not a literal in the compare. + * Target opens with `lui $s2, 0xFFF5` in the *prologue*, used once ~200 ins later in + * `slt $v0,$s2,$s1`. No gcc-2.7.2 pass hoists a (set reg const_int) across basic blocks + * (loop.c needs a loop; cse/combine/sched never move insns between BBs) — so the insn must + * have been EMITTED in the first BB, i.e. the constant is a local initialized at the top of + * the function. cse then cannot fold it back into the compare: the `slt` operand predicate is + * `arith_operand`, which rejects a CONST_INT wider than 16 bits, so validate_change fails and + * the pseudo survives. Its live range spans every call -> global.c gives it a callee-saved reg. + * Writing `z > -0xB0000` inline instead emits the `lui` into the branch delay slot next to the + * compare (caller-saved $v0) and the function is 1 insn short. => `s32 lim = -0xB0000;` at top. + * + * 2. `lh` vs `lhu`: a short->short copy is a pure HImode move and gcc emits `lhu`. The target's + * `lh $v0,0x26($s0)` means the value passed through an SImode (int) temp: expand makes + * (set (reg:SI) (sign_extend (mem:HI))) + (set (mem:HI) (subreg:HI ...)), and combine cannot + * merge them (the merged form is mem<-mem, which no movhi accepts) so the sign-extending load + * survives. => route both halfword copies through the `s32 t` temp. + * + * 3. THE `goto` LAYOUT — dodging jump.c's store-flag conversion (jump.c:1005-1065). + * An if/else chain writing 0/1 into `doit` makes gcc collapse the last pair into + * `sltiu $v0,$v0,1`. jump.c fires that conversion when the insn immediately after a + * conditional jump is a lone `SET pseudo, CONST_INT` whose following simplejump targets the + * SAME label as the branch (jump.c:1038 `reallabelprev == temp || ... JUMP_LABEL(temp4) == + * JUMP_LABEL(insn)`) — exactly the shape of `if (c) x=0; else x=1;`. + * The target instead cross-jumps ALL the `doit=0` exits into ONE shared block placed after the + * `doit=1` fall-through; reorg's fill_slots_from_thread then COPIES that single set into all + * three branch delay slots and redirects each branch past it (which is why `addu $v0,$zero, + * $zero` appears 3x in delay slots and the shared block vanishes). A `goto zero;` / `goto one;` + * chain expresses that layout directly, and each conditional jump is then followed by a + * compare/call rather than a lone const set, so the store-flag conversion never triggers. + * GENERAL RULE: multiple predicates that all assign the SAME constant to one flag => write + * them as `goto` to a shared assignment, never as an if/else ladder. + */ +extern s32 D_8011F9C4; +extern s32 D_80184FE4; + +extern s32 func_80161B18(void); +extern s32 func_801619A4(s32*); +extern s32 func_80149AA8(s32*); +extern void func_80149AD4(s32*); +extern s32 func_80149B54(s32*); +extern void func_80149BAC(s32*); +extern s32 func_801498E0(s32*); +extern s32 func_80149954(s32); +extern s32 func_80149A64(s32*); +extern void func_800CCCC0(s32 a0); +extern s32 func_80149CD4(s32 a0); +extern void func_8015E880(s32*); +extern s32 func_80149744(struct S_80149744*); +extern void func_80149788(void); +extern s32 func_801496D4(void*); +extern void func_80149704(void); +extern int func_80148AFC(void*); +extern void func_80146D90(s32 a0); +extern void func_80154150(s32 a0, s32 a1); +extern void func_801541D8(u8*, s32, s32); +extern s32 func_801488A8(u8*); +extern void func_80147078(s32*, s16); +extern void func_8015A264(void*); +extern s32 func_80013294(void*, void*); +extern void func_80159B70(void*); +extern s32 func_8016F1AC(void); +extern s32 func_80029178(s32 a0); +extern void func_80146DB8(s32*, s32*); +extern s32 func_80161CD0(s32, s32); +extern s32 func_80161208(s32 a0); +extern s32 func_801725A4(u8*); + +s32 func_8015B950(s32 arg0) +{ + + extern void (*D_80185050[])(void *); + s16 sp10[4]; + s16 sp18[4]; + s32 t; + s32 z; + s32 doit; + s32 lim = -0xB0000; + + if (func_80161B18() != 0) { + return; + } + switch (((s32 (*)(s32))func_801619A4)(arg0)) { + case 0: + case 1: + case 2: + case 6: + if (((s32 (*)(s32))func_80149AA8)(arg0) != 0) { + D_80185050[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149AD4)(arg0); + return; + } + if (((s32 (*)(s32))func_80149B54)(arg0) != 0) { + D_80185050[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149BAC)(arg0); + return; + } + break; + case 3: + ((void (*)(s32))func_801498E0)(arg0); + break; + case 4: + ((void (*)(s32))func_80149954)(arg0); + break; + case 5: + if (((s32 (*)(s32))func_80149A64)(arg0) != 0) { + D_80185050[*(u16 *)arg0]((void *)arg0); + func_800CCCC0(arg0); + return; + } + break; + } + if (func_80149CD4(arg0) != 0) { + D_80185050[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_8015E880)(arg0); + return; + } + if (((s32 (*)(s32))func_80149744)(arg0) != 0) { + D_80185050[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149788)(arg0); + return; + } + if (((s32 (*)(s32))func_801496D4)(arg0) != 0) { + D_80185050[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149704)(arg0); + if (((u8)((s32 (*)(s32))func_80148AFC)(arg0)) == 0) { + func_80146D90(arg0); + } + if ((*(s32 *)(arg0 + 0x24) | *(s32 *)(arg0 + 0x2C)) != 0) { + func_80154150(arg0, 0xF); + } else { + ((void (*)(s32, s32, s32))func_801541D8)(arg0, 0xD, 6); + } + *(s32 *)(arg0 + 0x238) = 1; + return; + } + if (((s32 (*)(s32))func_801488A8)(arg0) != 0) { + sp10[0] = 0; + sp10[1] = 0; + sp10[2] = 0; + t = *(s16 *)(arg0 + 0x26); + sp18[0] = t; + sp18[1] = 0; + t = *(s16 *)(arg0 + 0x2E); + sp18[2] = t; + D_80185050[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 1); + ((void (*)(s32))func_8015A264)(arg0); + t = -(((s32 (*)(s16 *, s16 *))func_80013294)(sp10, sp18) << 0x10); + if (t < *(s32 *)(arg0 + 0x2C)) { + *(s32 *)(arg0 + 0x2C) = t; + } + return; + } + if (*(u16 *)(arg0 + 0xB8) == 0x8000) { + D_80185050[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 0); + ((void (*)(s32))func_80159B70)(arg0); + return; + } + z = *(s32 *)(arg0 + 0x2C); + if (func_8016F1AC() != 0) { + goto zero; + } + if (z <= lim) { + goto one; + } + if (D_8011F9C4 == 0) { + goto zero; + } + if (((u8)func_80029178(0x21)) != 0) { + goto zero; + } +one: + doit = 1; + goto join; +zero: + doit = 0; +join: + if (doit != 0) { + D_80185050[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 0); + ((void (*)(s32))func_80159B70)(arg0); + func_80154150(arg0, 9); + ((void (*)(s32, s32 *))func_80146DB8)(arg0, &D_80184FE4); + ((void (*)(s32, s32))func_80161CD0)(arg0, *(u16 *)(arg0 + 0x16E)); + return; + } + if (func_80161208(arg0) == 0) { + ((void (*)(s32))func_801725A4)(arg0); + } +} DEFINE_func_8015BD8C() /* dedup: shared engine-core @0x8015BD8C (src/shared) */ diff --git a/src/ov_SC05_009/ov_SC05_009_jr_8015AE2C.c b/src/ov_SC05_009/ov_SC05_009_jr_8015AE2C.c index 78f3bf938..8ed9d579f 100644 --- a/src/ov_SC05_009/ov_SC05_009_jr_8015AE2C.c +++ b/src/ov_SC05_009/ov_SC05_009_jr_8015AE2C.c @@ -1512,7 +1512,259 @@ DEFINE_func_8015B858() /* dedup: shared engine-core @0x8015B858 (src/shared) */ DEFINE_func_8015B8F8() /* dedup: shared engine-core @0x8015B8F8 (src/shared) */ -INCLUDE_ASM("asm/ov_SC05_009/nonmatchings/ov_SC05_009_jr_8015AE2C", func_8015B950); +extern s32 func_8015AE2C(); + +// @class: plumbing +// @stuck: none — MATCH (271/271, pin-free, zero asm). The ONLY residual is DEF-SIDE plumbing, and it is now named exactly: the in-TU instantiation `DEFINE_func_8015BEE4()` (engine_core.h:1851-1855) expands to `extern s32 func_8015B950(void);` INSIDE ov_SC01_077_jr_8015AE2C.c, ~14 lines BELOW this definition, so the 1-param def collides with a `(void)` prototype -> `conflicting types for func_8015B950` (.run/bank_func_8015B950.log). §73 PARAMS axis / T0. Surgical fix = §65b de-macroize that ONE instantiation (blast radius: this TU); the fleet-wide `(void)`->`()` header edit is §63 and must be R22-validated. +/* func_8015B950 (ov_SC01_077_jr_8015AE2C, 271 ins, jtbl_801D8B74) — SESSION-21 re-verified + * + * ── ROUND-2 INDEPENDENT RE-VERIFICATION (2026-07-27, fresh agent, §88e discipline) ───────────── + * match_one : MATCH (271 ins) against the CURRENT tree — §87 staleness re-checked today. + * .text size: compiled .text = 0x43C = 1084 B = 271 ins, EXACTLY the target's declared 0x43C + * ("nonmatching func_8015B950, 0x43C"). So this is NOT a §83a length drift hiding + * behind a zero count — the count is over equal-length streams. + * jtbl : RE-DECODED MECHANICALLY, not inherited. Compiled .rodata = 0x1C = 28 B = 7 words, + * 7x R_MIPS_32 -> .text with implicit addends [58,58,58,E0,F0,100,58]; +0x8015B950 + * = [8015B9A8, 8015B9A8, 8015B9A8, 8015BA30, 8015BA40, 8015BA50, 8015B9A8]. + * Diffed word-for-word against asm/ov_SC01_077/data/tail14.data.s:15-23 — 7/7 identical. + * symcheck : SYMS-DIFF target=35 draft=34, sole MISSING = jtbl_801D8B74. This is the §81 jr + * FALSE POSITIVE, re-confirmed here by reading the relocs: gcc emits its OWN table and + * references it with R_MIPS_HI16/LO16 against the SECTION `.rodata` (t.o +0x40/+0x48), + * so the splat's dlabel NAME can never appear in the draft object's relocation set. + * Nothing is dropped and nothing is invented: the draft's other 34 symbols are exactly + * the target's other 34. + * FAMILY : the x138 remap is clean and §84-safe. Every sibling is 271 ins with an IDENTICAL + * callee set; only THREE names vary per overlay — the two data labels and the jtbl: + * ov_SC01_077 D_801810F4 / D_80181160 / jtbl_801D8B74 + * ov_SC03_099 D_80185A50 / D_80185ABC / jtbl_801BD898 + * ov_SC06_008 D_80187E44 / D_80187EB0 / jtbl_801A8734 + * The pair is always +0x6C apart, and NO literal in this draft encodes that distance + * (both labels are referenced by name), so there is no §84 derived-offset hazard. + * D_8011F9C4 is fleet-constant (main-EXE data) and must NOT be remapped. + * + * match_one: MATCH (271 ins) against the CURRENT tree (§87 staleness re-checked, 2026-07-27). + * PIN-FREE, zero asm, offset-pure (s32 arg0 + raw offsets) — x138 template-safe. + * Provenance: this is the Phase-26 crack (.run/phase26-cracks/func_8015B950.c) re-gated verbatim, + * with ONE deliberate change: the definition's return type void -> s32. + * - `void func_8015B950(s32 arg0)` : MATCH (271 ins) [the Phase-26 form] + * - `s32 func_8015B950(s32 arg0)` : MATCH (271 ins) [shipped — §3a-1 void->s32 is byte-neutral] + * The fleet/engine_core.h canonical decl is `extern s32 func_8015B950(void);` (engine_core.h:1852), + * and the last bank attempt (.run/bank_func_8015B950.log) died on `conflicting types for + * func_8015B950`. Shipping the s32 return kills the §73 RETURN axis for free and leaves only the + * cheap T0 PARAMS axis for the ladder (fix_header_decl.py / --fix-def-sig / cast_call_sites). + * Both forms are byte-identical, so the orchestrator may swap the return type back at zero cost. + * + * SYMBOLS (§58 rules 1/2 — all splat spellings, all verified present): + * D_80181160 asm/ov_SC01_077/data/tail.data.s:4355 (the state-handler vtable) + * D_801810F4 asm/ov_SC01_077/data/tail.data.s:4293 + * D_8011F9C4 main-EXE data; spelled `extern s32 D_8011F9C4;` in 5+ already-banked TUs + * jtbl_801D8B74 asm/ov_SC01_077/data/tail14.data.s:15 (compiler jump table — not named in C) + * + * JTBL VERIFIED (§8a gate): compiled .rodata = exactly 0x1C B / 7 words, 7x R_MIPS_32 .text with + * addends [0x58,0x58,0x58,0xE0,0xF0,0x100,0x58] -> +0x8015B950 = [B9A8,B9A8,B9A8,BA30,BA40,BA50, + * B9A8] == the original words at 0x801D8B74..0x801D8B8C. Bound `sltiu $v0,$v1,0x7` matches. + * The raw dlabel's 8th word 0x00000000 is NOT an entry — it is the intra-TU `.align 3` pad of the + * B34/B54/B74 jtbl chain; the object can never emit it (maspsx drops .align), so it must stay in + * the post-carve RAW data piece (the §53/§62/§81 carve chain applies at bank time). + * + * Same family as the TU's own already-matched func_8015AE2C: 7-case switch on ((s32 (*)(s32))func_801619A4)() + * (0/1/2/6 shared, 3/4/5 own, no default block — out-of-range and every `break` fall to the + * after-switch join), then a chain of "state handler" tests, each dispatching + * D_80181160[*(u16*)arg0](arg0) and returning. + * + * THREE LEVERS (draft -> MATCH in 3 compiles): + * + * 1. PROLOGUE CONSTANT = an INITIALIZED LOCAL, not a literal in the compare. + * Target opens with `lui $s2, 0xFFF5` in the *prologue*, used once ~200 ins later in + * `slt $v0,$s2,$s1`. No gcc-2.7.2 pass hoists a (set reg const_int) across basic blocks + * (loop.c needs a loop; cse/combine/sched never move insns between BBs) — so the insn must + * have been EMITTED in the first BB, i.e. the constant is a local initialized at the top of + * the function. cse then cannot fold it back into the compare: the `slt` operand predicate is + * `arith_operand`, which rejects a CONST_INT wider than 16 bits, so validate_change fails and + * the pseudo survives. Its live range spans every call -> global.c gives it a callee-saved reg. + * Writing `z > -0xB0000` inline instead emits the `lui` into the branch delay slot next to the + * compare (caller-saved $v0) and the function is 1 insn short. => `s32 lim = -0xB0000;` at top. + * + * 2. `lh` vs `lhu`: a short->short copy is a pure HImode move and gcc emits `lhu`. The target's + * `lh $v0,0x26($s0)` means the value passed through an SImode (int) temp: expand makes + * (set (reg:SI) (sign_extend (mem:HI))) + (set (mem:HI) (subreg:HI ...)), and combine cannot + * merge them (the merged form is mem<-mem, which no movhi accepts) so the sign-extending load + * survives. => route both halfword copies through the `s32 t` temp. + * + * 3. THE `goto` LAYOUT — dodging jump.c's store-flag conversion (jump.c:1005-1065). + * An if/else chain writing 0/1 into `doit` makes gcc collapse the last pair into + * `sltiu $v0,$v0,1`. jump.c fires that conversion when the insn immediately after a + * conditional jump is a lone `SET pseudo, CONST_INT` whose following simplejump targets the + * SAME label as the branch (jump.c:1038 `reallabelprev == temp || ... JUMP_LABEL(temp4) == + * JUMP_LABEL(insn)`) — exactly the shape of `if (c) x=0; else x=1;`. + * The target instead cross-jumps ALL the `doit=0` exits into ONE shared block placed after the + * `doit=1` fall-through; reorg's fill_slots_from_thread then COPIES that single set into all + * three branch delay slots and redirects each branch past it (which is why `addu $v0,$zero, + * $zero` appears 3x in delay slots and the shared block vanishes). A `goto zero;` / `goto one;` + * chain expresses that layout directly, and each conditional jump is then followed by a + * compare/call rather than a lone const set, so the store-flag conversion never triggers. + * GENERAL RULE: multiple predicates that all assign the SAME constant to one flag => write + * them as `goto` to a shared assignment, never as an if/else ladder. + */ +extern s32 D_8011F9C4; +extern s32 D_801810F4; + +extern s32 func_80161B18(void); +extern s32 func_801619A4(s32*); +extern s32 func_80149AA8(s32*); +extern void func_80149AD4(s32*); +extern s32 func_80149B54(s32*); +extern void func_80149BAC(s32*); +extern s32 func_801498E0(s32*); +extern s32 func_80149954(s32); +extern s32 func_80149A64(s32*); +extern void func_800CCCC0(s32 a0); +extern s32 func_80149CD4(s32 a0); +extern void func_8015E880(s32*); +extern s32 func_80149744(struct S_80149744*); +extern void func_80149788(void); +extern s32 func_801496D4(void*); +extern void func_80149704(void); +extern int func_80148AFC(void*); +extern void func_80146D90(s32 a0); +extern void func_80154150(s32 a0, s32 a1); +extern void func_801541D8(u8*, s32, s32); +extern s32 func_801488A8(u8*); +extern void func_80147078(s32*, s16); +extern void func_8015A264(void*); +extern s32 func_80013294(void*, void*); +extern void func_80159B70(void*); +extern s32 func_8016F1AC(void); +extern s32 func_80029178(s32 a0); +extern void func_80146DB8(s32*, s32*); +extern s32 func_80161CD0(s32, s32); +extern s32 func_80161208(s32 a0); +extern s32 func_801725A4(u8*); + +s32 func_8015B950(s32 arg0) +{ + + extern void (*D_80181160[])(void *); + s16 sp10[4]; + s16 sp18[4]; + s32 t; + s32 z; + s32 doit; + s32 lim = -0xB0000; + + if (func_80161B18() != 0) { + return; + } + switch (((s32 (*)(s32))func_801619A4)(arg0)) { + case 0: + case 1: + case 2: + case 6: + if (((s32 (*)(s32))func_80149AA8)(arg0) != 0) { + D_80181160[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149AD4)(arg0); + return; + } + if (((s32 (*)(s32))func_80149B54)(arg0) != 0) { + D_80181160[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149BAC)(arg0); + return; + } + break; + case 3: + ((void (*)(s32))func_801498E0)(arg0); + break; + case 4: + ((void (*)(s32))func_80149954)(arg0); + break; + case 5: + if (((s32 (*)(s32))func_80149A64)(arg0) != 0) { + D_80181160[*(u16 *)arg0]((void *)arg0); + func_800CCCC0(arg0); + return; + } + break; + } + if (func_80149CD4(arg0) != 0) { + D_80181160[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_8015E880)(arg0); + return; + } + if (((s32 (*)(s32))func_80149744)(arg0) != 0) { + D_80181160[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149788)(arg0); + return; + } + if (((s32 (*)(s32))func_801496D4)(arg0) != 0) { + D_80181160[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149704)(arg0); + if (((u8)((s32 (*)(s32))func_80148AFC)(arg0)) == 0) { + func_80146D90(arg0); + } + if ((*(s32 *)(arg0 + 0x24) | *(s32 *)(arg0 + 0x2C)) != 0) { + func_80154150(arg0, 0xF); + } else { + ((void (*)(s32, s32, s32))func_801541D8)(arg0, 0xD, 6); + } + *(s32 *)(arg0 + 0x238) = 1; + return; + } + if (((s32 (*)(s32))func_801488A8)(arg0) != 0) { + sp10[0] = 0; + sp10[1] = 0; + sp10[2] = 0; + t = *(s16 *)(arg0 + 0x26); + sp18[0] = t; + sp18[1] = 0; + t = *(s16 *)(arg0 + 0x2E); + sp18[2] = t; + D_80181160[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 1); + ((void (*)(s32))func_8015A264)(arg0); + t = -(((s32 (*)(s16 *, s16 *))func_80013294)(sp10, sp18) << 0x10); + if (t < *(s32 *)(arg0 + 0x2C)) { + *(s32 *)(arg0 + 0x2C) = t; + } + return; + } + if (*(u16 *)(arg0 + 0xB8) == 0x8000) { + D_80181160[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 0); + ((void (*)(s32))func_80159B70)(arg0); + return; + } + z = *(s32 *)(arg0 + 0x2C); + if (func_8016F1AC() != 0) { + goto zero; + } + if (z <= lim) { + goto one; + } + if (D_8011F9C4 == 0) { + goto zero; + } + if (((u8)func_80029178(0x21)) != 0) { + goto zero; + } +one: + doit = 1; + goto join; +zero: + doit = 0; +join: + if (doit != 0) { + D_80181160[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 0); + ((void (*)(s32))func_80159B70)(arg0); + func_80154150(arg0, 9); + ((void (*)(s32, s32 *))func_80146DB8)(arg0, &D_801810F4); + ((void (*)(s32, s32))func_80161CD0)(arg0, *(u16 *)(arg0 + 0x16E)); + return; + } + if (func_80161208(arg0) == 0) { + ((void (*)(s32))func_801725A4)(arg0); + } +} DEFINE_func_8015BD8C() /* dedup: shared engine-core @0x8015BD8C (src/shared) */ diff --git a/src/ov_SC05_010/ov_SC05_010_jr_8015AE2C.c b/src/ov_SC05_010/ov_SC05_010_jr_8015AE2C.c index 33812c4ca..b7391e9fa 100644 --- a/src/ov_SC05_010/ov_SC05_010_jr_8015AE2C.c +++ b/src/ov_SC05_010/ov_SC05_010_jr_8015AE2C.c @@ -1512,7 +1512,259 @@ DEFINE_func_8015B858() /* dedup: shared engine-core @0x8015B858 (src/shared) */ DEFINE_func_8015B8F8() /* dedup: shared engine-core @0x8015B8F8 (src/shared) */ -INCLUDE_ASM("asm/ov_SC05_010/nonmatchings/ov_SC05_010_jr_8015AE2C", func_8015B950); +extern s32 func_8015AE2C(); + +// @class: plumbing +// @stuck: none — MATCH (271/271, pin-free, zero asm). The ONLY residual is DEF-SIDE plumbing, and it is now named exactly: the in-TU instantiation `DEFINE_func_8015BEE4()` (engine_core.h:1851-1855) expands to `extern s32 func_8015B950(void);` INSIDE ov_SC01_077_jr_8015AE2C.c, ~14 lines BELOW this definition, so the 1-param def collides with a `(void)` prototype -> `conflicting types for func_8015B950` (.run/bank_func_8015B950.log). §73 PARAMS axis / T0. Surgical fix = §65b de-macroize that ONE instantiation (blast radius: this TU); the fleet-wide `(void)`->`()` header edit is §63 and must be R22-validated. +/* func_8015B950 (ov_SC01_077_jr_8015AE2C, 271 ins, jtbl_801D8B74) — SESSION-21 re-verified + * + * ── ROUND-2 INDEPENDENT RE-VERIFICATION (2026-07-27, fresh agent, §88e discipline) ───────────── + * match_one : MATCH (271 ins) against the CURRENT tree — §87 staleness re-checked today. + * .text size: compiled .text = 0x43C = 1084 B = 271 ins, EXACTLY the target's declared 0x43C + * ("nonmatching func_8015B950, 0x43C"). So this is NOT a §83a length drift hiding + * behind a zero count — the count is over equal-length streams. + * jtbl : RE-DECODED MECHANICALLY, not inherited. Compiled .rodata = 0x1C = 28 B = 7 words, + * 7x R_MIPS_32 -> .text with implicit addends [58,58,58,E0,F0,100,58]; +0x8015B950 + * = [8015B9A8, 8015B9A8, 8015B9A8, 8015BA30, 8015BA40, 8015BA50, 8015B9A8]. + * Diffed word-for-word against asm/ov_SC01_077/data/tail14.data.s:15-23 — 7/7 identical. + * symcheck : SYMS-DIFF target=35 draft=34, sole MISSING = jtbl_801D8B74. This is the §81 jr + * FALSE POSITIVE, re-confirmed here by reading the relocs: gcc emits its OWN table and + * references it with R_MIPS_HI16/LO16 against the SECTION `.rodata` (t.o +0x40/+0x48), + * so the splat's dlabel NAME can never appear in the draft object's relocation set. + * Nothing is dropped and nothing is invented: the draft's other 34 symbols are exactly + * the target's other 34. + * FAMILY : the x138 remap is clean and §84-safe. Every sibling is 271 ins with an IDENTICAL + * callee set; only THREE names vary per overlay — the two data labels and the jtbl: + * ov_SC01_077 D_8018AFD0 / D_8018B03C / jtbl_801D8B74 + * ov_SC03_099 D_80185A50 / D_80185ABC / jtbl_801BD898 + * ov_SC06_008 D_80187E44 / D_80187EB0 / jtbl_801A8734 + * The pair is always +0x6C apart, and NO literal in this draft encodes that distance + * (both labels are referenced by name), so there is no §84 derived-offset hazard. + * D_8011F9C4 is fleet-constant (main-EXE data) and must NOT be remapped. + * + * match_one: MATCH (271 ins) against the CURRENT tree (§87 staleness re-checked, 2026-07-27). + * PIN-FREE, zero asm, offset-pure (s32 arg0 + raw offsets) — x138 template-safe. + * Provenance: this is the Phase-26 crack (.run/phase26-cracks/func_8015B950.c) re-gated verbatim, + * with ONE deliberate change: the definition's return type void -> s32. + * - `void func_8015B950(s32 arg0)` : MATCH (271 ins) [the Phase-26 form] + * - `s32 func_8015B950(s32 arg0)` : MATCH (271 ins) [shipped — §3a-1 void->s32 is byte-neutral] + * The fleet/engine_core.h canonical decl is `extern s32 func_8015B950(void);` (engine_core.h:1852), + * and the last bank attempt (.run/bank_func_8015B950.log) died on `conflicting types for + * func_8015B950`. Shipping the s32 return kills the §73 RETURN axis for free and leaves only the + * cheap T0 PARAMS axis for the ladder (fix_header_decl.py / --fix-def-sig / cast_call_sites). + * Both forms are byte-identical, so the orchestrator may swap the return type back at zero cost. + * + * SYMBOLS (§58 rules 1/2 — all splat spellings, all verified present): + * D_8018B03C asm/ov_SC01_077/data/tail.data.s:4355 (the state-handler vtable) + * D_8018AFD0 asm/ov_SC01_077/data/tail.data.s:4293 + * D_8011F9C4 main-EXE data; spelled `extern s32 D_8011F9C4;` in 5+ already-banked TUs + * jtbl_801D8B74 asm/ov_SC01_077/data/tail14.data.s:15 (compiler jump table — not named in C) + * + * JTBL VERIFIED (§8a gate): compiled .rodata = exactly 0x1C B / 7 words, 7x R_MIPS_32 .text with + * addends [0x58,0x58,0x58,0xE0,0xF0,0x100,0x58] -> +0x8015B950 = [B9A8,B9A8,B9A8,BA30,BA40,BA50, + * B9A8] == the original words at 0x801D8B74..0x801D8B8C. Bound `sltiu $v0,$v1,0x7` matches. + * The raw dlabel's 8th word 0x00000000 is NOT an entry — it is the intra-TU `.align 3` pad of the + * B34/B54/B74 jtbl chain; the object can never emit it (maspsx drops .align), so it must stay in + * the post-carve RAW data piece (the §53/§62/§81 carve chain applies at bank time). + * + * Same family as the TU's own already-matched func_8015AE2C: 7-case switch on ((s32 (*)(s32))func_801619A4)() + * (0/1/2/6 shared, 3/4/5 own, no default block — out-of-range and every `break` fall to the + * after-switch join), then a chain of "state handler" tests, each dispatching + * D_8018B03C[*(u16*)arg0](arg0) and returning. + * + * THREE LEVERS (draft -> MATCH in 3 compiles): + * + * 1. PROLOGUE CONSTANT = an INITIALIZED LOCAL, not a literal in the compare. + * Target opens with `lui $s2, 0xFFF5` in the *prologue*, used once ~200 ins later in + * `slt $v0,$s2,$s1`. No gcc-2.7.2 pass hoists a (set reg const_int) across basic blocks + * (loop.c needs a loop; cse/combine/sched never move insns between BBs) — so the insn must + * have been EMITTED in the first BB, i.e. the constant is a local initialized at the top of + * the function. cse then cannot fold it back into the compare: the `slt` operand predicate is + * `arith_operand`, which rejects a CONST_INT wider than 16 bits, so validate_change fails and + * the pseudo survives. Its live range spans every call -> global.c gives it a callee-saved reg. + * Writing `z > -0xB0000` inline instead emits the `lui` into the branch delay slot next to the + * compare (caller-saved $v0) and the function is 1 insn short. => `s32 lim = -0xB0000;` at top. + * + * 2. `lh` vs `lhu`: a short->short copy is a pure HImode move and gcc emits `lhu`. The target's + * `lh $v0,0x26($s0)` means the value passed through an SImode (int) temp: expand makes + * (set (reg:SI) (sign_extend (mem:HI))) + (set (mem:HI) (subreg:HI ...)), and combine cannot + * merge them (the merged form is mem<-mem, which no movhi accepts) so the sign-extending load + * survives. => route both halfword copies through the `s32 t` temp. + * + * 3. THE `goto` LAYOUT — dodging jump.c's store-flag conversion (jump.c:1005-1065). + * An if/else chain writing 0/1 into `doit` makes gcc collapse the last pair into + * `sltiu $v0,$v0,1`. jump.c fires that conversion when the insn immediately after a + * conditional jump is a lone `SET pseudo, CONST_INT` whose following simplejump targets the + * SAME label as the branch (jump.c:1038 `reallabelprev == temp || ... JUMP_LABEL(temp4) == + * JUMP_LABEL(insn)`) — exactly the shape of `if (c) x=0; else x=1;`. + * The target instead cross-jumps ALL the `doit=0` exits into ONE shared block placed after the + * `doit=1` fall-through; reorg's fill_slots_from_thread then COPIES that single set into all + * three branch delay slots and redirects each branch past it (which is why `addu $v0,$zero, + * $zero` appears 3x in delay slots and the shared block vanishes). A `goto zero;` / `goto one;` + * chain expresses that layout directly, and each conditional jump is then followed by a + * compare/call rather than a lone const set, so the store-flag conversion never triggers. + * GENERAL RULE: multiple predicates that all assign the SAME constant to one flag => write + * them as `goto` to a shared assignment, never as an if/else ladder. + */ +extern s32 D_8011F9C4; +extern s32 D_8018AFD0; + +extern s32 func_80161B18(void); +extern s32 func_801619A4(s32*); +extern s32 func_80149AA8(s32*); +extern void func_80149AD4(s32*); +extern s32 func_80149B54(s32*); +extern void func_80149BAC(s32*); +extern s32 func_801498E0(s32*); +extern s32 func_80149954(s32); +extern s32 func_80149A64(s32*); +extern void func_800CCCC0(s32 a0); +extern s32 func_80149CD4(s32 a0); +extern void func_8015E880(s32*); +extern s32 func_80149744(struct S_80149744*); +extern void func_80149788(void); +extern s32 func_801496D4(void*); +extern void func_80149704(void); +extern int func_80148AFC(void*); +extern void func_80146D90(s32 a0); +extern void func_80154150(s32 a0, s32 a1); +extern void func_801541D8(u8*, s32, s32); +extern s32 func_801488A8(u8*); +extern void func_80147078(s32*, s16); +extern void func_8015A264(void*); +extern s32 func_80013294(void*, void*); +extern void func_80159B70(void*); +extern s32 func_8016F1AC(void); +extern s32 func_80029178(s32 a0); +extern void func_80146DB8(s32*, s32*); +extern s32 func_80161CD0(s32, s32); +extern s32 func_80161208(s32 a0); +extern s32 func_801725A4(u8*); + +s32 func_8015B950(s32 arg0) +{ + + extern void (*D_8018B03C[])(void *); + s16 sp10[4]; + s16 sp18[4]; + s32 t; + s32 z; + s32 doit; + s32 lim = -0xB0000; + + if (func_80161B18() != 0) { + return; + } + switch (((s32 (*)(s32))func_801619A4)(arg0)) { + case 0: + case 1: + case 2: + case 6: + if (((s32 (*)(s32))func_80149AA8)(arg0) != 0) { + D_8018B03C[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149AD4)(arg0); + return; + } + if (((s32 (*)(s32))func_80149B54)(arg0) != 0) { + D_8018B03C[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149BAC)(arg0); + return; + } + break; + case 3: + ((void (*)(s32))func_801498E0)(arg0); + break; + case 4: + ((void (*)(s32))func_80149954)(arg0); + break; + case 5: + if (((s32 (*)(s32))func_80149A64)(arg0) != 0) { + D_8018B03C[*(u16 *)arg0]((void *)arg0); + func_800CCCC0(arg0); + return; + } + break; + } + if (func_80149CD4(arg0) != 0) { + D_8018B03C[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_8015E880)(arg0); + return; + } + if (((s32 (*)(s32))func_80149744)(arg0) != 0) { + D_8018B03C[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149788)(arg0); + return; + } + if (((s32 (*)(s32))func_801496D4)(arg0) != 0) { + D_8018B03C[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149704)(arg0); + if (((u8)((s32 (*)(s32))func_80148AFC)(arg0)) == 0) { + func_80146D90(arg0); + } + if ((*(s32 *)(arg0 + 0x24) | *(s32 *)(arg0 + 0x2C)) != 0) { + func_80154150(arg0, 0xF); + } else { + ((void (*)(s32, s32, s32))func_801541D8)(arg0, 0xD, 6); + } + *(s32 *)(arg0 + 0x238) = 1; + return; + } + if (((s32 (*)(s32))func_801488A8)(arg0) != 0) { + sp10[0] = 0; + sp10[1] = 0; + sp10[2] = 0; + t = *(s16 *)(arg0 + 0x26); + sp18[0] = t; + sp18[1] = 0; + t = *(s16 *)(arg0 + 0x2E); + sp18[2] = t; + D_8018B03C[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 1); + ((void (*)(s32))func_8015A264)(arg0); + t = -(((s32 (*)(s16 *, s16 *))func_80013294)(sp10, sp18) << 0x10); + if (t < *(s32 *)(arg0 + 0x2C)) { + *(s32 *)(arg0 + 0x2C) = t; + } + return; + } + if (*(u16 *)(arg0 + 0xB8) == 0x8000) { + D_8018B03C[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 0); + ((void (*)(s32))func_80159B70)(arg0); + return; + } + z = *(s32 *)(arg0 + 0x2C); + if (func_8016F1AC() != 0) { + goto zero; + } + if (z <= lim) { + goto one; + } + if (D_8011F9C4 == 0) { + goto zero; + } + if (((u8)func_80029178(0x21)) != 0) { + goto zero; + } +one: + doit = 1; + goto join; +zero: + doit = 0; +join: + if (doit != 0) { + D_8018B03C[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 0); + ((void (*)(s32))func_80159B70)(arg0); + func_80154150(arg0, 9); + ((void (*)(s32, s32 *))func_80146DB8)(arg0, &D_8018AFD0); + ((void (*)(s32, s32))func_80161CD0)(arg0, *(u16 *)(arg0 + 0x16E)); + return; + } + if (func_80161208(arg0) == 0) { + ((void (*)(s32))func_801725A4)(arg0); + } +} DEFINE_func_8015BD8C() /* dedup: shared engine-core @0x8015BD8C (src/shared) */ diff --git a/src/ov_SC05_011/ov_SC05_011_jr_8015AE2C.c b/src/ov_SC05_011/ov_SC05_011_jr_8015AE2C.c index 21bc7ef34..834ba3270 100644 --- a/src/ov_SC05_011/ov_SC05_011_jr_8015AE2C.c +++ b/src/ov_SC05_011/ov_SC05_011_jr_8015AE2C.c @@ -1512,7 +1512,259 @@ DEFINE_func_8015B858() /* dedup: shared engine-core @0x8015B858 (src/shared) */ DEFINE_func_8015B8F8() /* dedup: shared engine-core @0x8015B8F8 (src/shared) */ -INCLUDE_ASM("asm/ov_SC05_011/nonmatchings/ov_SC05_011_jr_8015AE2C", func_8015B950); +extern s32 func_8015AE2C(); + +// @class: plumbing +// @stuck: none — MATCH (271/271, pin-free, zero asm). The ONLY residual is DEF-SIDE plumbing, and it is now named exactly: the in-TU instantiation `DEFINE_func_8015BEE4()` (engine_core.h:1851-1855) expands to `extern s32 func_8015B950(void);` INSIDE ov_SC01_077_jr_8015AE2C.c, ~14 lines BELOW this definition, so the 1-param def collides with a `(void)` prototype -> `conflicting types for func_8015B950` (.run/bank_func_8015B950.log). §73 PARAMS axis / T0. Surgical fix = §65b de-macroize that ONE instantiation (blast radius: this TU); the fleet-wide `(void)`->`()` header edit is §63 and must be R22-validated. +/* func_8015B950 (ov_SC01_077_jr_8015AE2C, 271 ins, jtbl_801D8B74) — SESSION-21 re-verified + * + * ── ROUND-2 INDEPENDENT RE-VERIFICATION (2026-07-27, fresh agent, §88e discipline) ───────────── + * match_one : MATCH (271 ins) against the CURRENT tree — §87 staleness re-checked today. + * .text size: compiled .text = 0x43C = 1084 B = 271 ins, EXACTLY the target's declared 0x43C + * ("nonmatching func_8015B950, 0x43C"). So this is NOT a §83a length drift hiding + * behind a zero count — the count is over equal-length streams. + * jtbl : RE-DECODED MECHANICALLY, not inherited. Compiled .rodata = 0x1C = 28 B = 7 words, + * 7x R_MIPS_32 -> .text with implicit addends [58,58,58,E0,F0,100,58]; +0x8015B950 + * = [8015B9A8, 8015B9A8, 8015B9A8, 8015BA30, 8015BA40, 8015BA50, 8015B9A8]. + * Diffed word-for-word against asm/ov_SC01_077/data/tail14.data.s:15-23 — 7/7 identical. + * symcheck : SYMS-DIFF target=35 draft=34, sole MISSING = jtbl_801D8B74. This is the §81 jr + * FALSE POSITIVE, re-confirmed here by reading the relocs: gcc emits its OWN table and + * references it with R_MIPS_HI16/LO16 against the SECTION `.rodata` (t.o +0x40/+0x48), + * so the splat's dlabel NAME can never appear in the draft object's relocation set. + * Nothing is dropped and nothing is invented: the draft's other 34 symbols are exactly + * the target's other 34. + * FAMILY : the x138 remap is clean and §84-safe. Every sibling is 271 ins with an IDENTICAL + * callee set; only THREE names vary per overlay — the two data labels and the jtbl: + * ov_SC01_077 D_80180348 / D_801803B4 / jtbl_801D8B74 + * ov_SC03_099 D_80185A50 / D_80185ABC / jtbl_801BD898 + * ov_SC06_008 D_80187E44 / D_80187EB0 / jtbl_801A8734 + * The pair is always +0x6C apart, and NO literal in this draft encodes that distance + * (both labels are referenced by name), so there is no §84 derived-offset hazard. + * D_8011F9C4 is fleet-constant (main-EXE data) and must NOT be remapped. + * + * match_one: MATCH (271 ins) against the CURRENT tree (§87 staleness re-checked, 2026-07-27). + * PIN-FREE, zero asm, offset-pure (s32 arg0 + raw offsets) — x138 template-safe. + * Provenance: this is the Phase-26 crack (.run/phase26-cracks/func_8015B950.c) re-gated verbatim, + * with ONE deliberate change: the definition's return type void -> s32. + * - `void func_8015B950(s32 arg0)` : MATCH (271 ins) [the Phase-26 form] + * - `s32 func_8015B950(s32 arg0)` : MATCH (271 ins) [shipped — §3a-1 void->s32 is byte-neutral] + * The fleet/engine_core.h canonical decl is `extern s32 func_8015B950(void);` (engine_core.h:1852), + * and the last bank attempt (.run/bank_func_8015B950.log) died on `conflicting types for + * func_8015B950`. Shipping the s32 return kills the §73 RETURN axis for free and leaves only the + * cheap T0 PARAMS axis for the ladder (fix_header_decl.py / --fix-def-sig / cast_call_sites). + * Both forms are byte-identical, so the orchestrator may swap the return type back at zero cost. + * + * SYMBOLS (§58 rules 1/2 — all splat spellings, all verified present): + * D_801803B4 asm/ov_SC01_077/data/tail.data.s:4355 (the state-handler vtable) + * D_80180348 asm/ov_SC01_077/data/tail.data.s:4293 + * D_8011F9C4 main-EXE data; spelled `extern s32 D_8011F9C4;` in 5+ already-banked TUs + * jtbl_801D8B74 asm/ov_SC01_077/data/tail14.data.s:15 (compiler jump table — not named in C) + * + * JTBL VERIFIED (§8a gate): compiled .rodata = exactly 0x1C B / 7 words, 7x R_MIPS_32 .text with + * addends [0x58,0x58,0x58,0xE0,0xF0,0x100,0x58] -> +0x8015B950 = [B9A8,B9A8,B9A8,BA30,BA40,BA50, + * B9A8] == the original words at 0x801D8B74..0x801D8B8C. Bound `sltiu $v0,$v1,0x7` matches. + * The raw dlabel's 8th word 0x00000000 is NOT an entry — it is the intra-TU `.align 3` pad of the + * B34/B54/B74 jtbl chain; the object can never emit it (maspsx drops .align), so it must stay in + * the post-carve RAW data piece (the §53/§62/§81 carve chain applies at bank time). + * + * Same family as the TU's own already-matched func_8015AE2C: 7-case switch on ((s32 (*)(s32))func_801619A4)() + * (0/1/2/6 shared, 3/4/5 own, no default block — out-of-range and every `break` fall to the + * after-switch join), then a chain of "state handler" tests, each dispatching + * D_801803B4[*(u16*)arg0](arg0) and returning. + * + * THREE LEVERS (draft -> MATCH in 3 compiles): + * + * 1. PROLOGUE CONSTANT = an INITIALIZED LOCAL, not a literal in the compare. + * Target opens with `lui $s2, 0xFFF5` in the *prologue*, used once ~200 ins later in + * `slt $v0,$s2,$s1`. No gcc-2.7.2 pass hoists a (set reg const_int) across basic blocks + * (loop.c needs a loop; cse/combine/sched never move insns between BBs) — so the insn must + * have been EMITTED in the first BB, i.e. the constant is a local initialized at the top of + * the function. cse then cannot fold it back into the compare: the `slt` operand predicate is + * `arith_operand`, which rejects a CONST_INT wider than 16 bits, so validate_change fails and + * the pseudo survives. Its live range spans every call -> global.c gives it a callee-saved reg. + * Writing `z > -0xB0000` inline instead emits the `lui` into the branch delay slot next to the + * compare (caller-saved $v0) and the function is 1 insn short. => `s32 lim = -0xB0000;` at top. + * + * 2. `lh` vs `lhu`: a short->short copy is a pure HImode move and gcc emits `lhu`. The target's + * `lh $v0,0x26($s0)` means the value passed through an SImode (int) temp: expand makes + * (set (reg:SI) (sign_extend (mem:HI))) + (set (mem:HI) (subreg:HI ...)), and combine cannot + * merge them (the merged form is mem<-mem, which no movhi accepts) so the sign-extending load + * survives. => route both halfword copies through the `s32 t` temp. + * + * 3. THE `goto` LAYOUT — dodging jump.c's store-flag conversion (jump.c:1005-1065). + * An if/else chain writing 0/1 into `doit` makes gcc collapse the last pair into + * `sltiu $v0,$v0,1`. jump.c fires that conversion when the insn immediately after a + * conditional jump is a lone `SET pseudo, CONST_INT` whose following simplejump targets the + * SAME label as the branch (jump.c:1038 `reallabelprev == temp || ... JUMP_LABEL(temp4) == + * JUMP_LABEL(insn)`) — exactly the shape of `if (c) x=0; else x=1;`. + * The target instead cross-jumps ALL the `doit=0` exits into ONE shared block placed after the + * `doit=1` fall-through; reorg's fill_slots_from_thread then COPIES that single set into all + * three branch delay slots and redirects each branch past it (which is why `addu $v0,$zero, + * $zero` appears 3x in delay slots and the shared block vanishes). A `goto zero;` / `goto one;` + * chain expresses that layout directly, and each conditional jump is then followed by a + * compare/call rather than a lone const set, so the store-flag conversion never triggers. + * GENERAL RULE: multiple predicates that all assign the SAME constant to one flag => write + * them as `goto` to a shared assignment, never as an if/else ladder. + */ +extern s32 D_8011F9C4; +extern s32 D_80180348; + +extern s32 func_80161B18(void); +extern s32 func_801619A4(s32*); +extern s32 func_80149AA8(s32*); +extern void func_80149AD4(s32*); +extern s32 func_80149B54(s32*); +extern void func_80149BAC(s32*); +extern s32 func_801498E0(s32*); +extern s32 func_80149954(s32); +extern s32 func_80149A64(s32*); +extern void func_800CCCC0(s32 a0); +extern s32 func_80149CD4(s32 a0); +extern void func_8015E880(s32*); +extern s32 func_80149744(struct S_80149744*); +extern void func_80149788(void); +extern s32 func_801496D4(void*); +extern void func_80149704(void); +extern int func_80148AFC(void*); +extern void func_80146D90(s32 a0); +extern void func_80154150(s32 a0, s32 a1); +extern void func_801541D8(u8*, s32, s32); +extern s32 func_801488A8(u8*); +extern void func_80147078(s32*, s16); +extern void func_8015A264(void*); +extern s32 func_80013294(void*, void*); +extern void func_80159B70(void*); +extern s32 func_8016F1AC(void); +extern s32 func_80029178(s32 a0); +extern void func_80146DB8(s32*, s32*); +extern s32 func_80161CD0(s32, s32); +extern s32 func_80161208(s32 a0); +extern s32 func_801725A4(u8*); + +s32 func_8015B950(s32 arg0) +{ + + extern void (*D_801803B4[])(void *); + s16 sp10[4]; + s16 sp18[4]; + s32 t; + s32 z; + s32 doit; + s32 lim = -0xB0000; + + if (func_80161B18() != 0) { + return; + } + switch (((s32 (*)(s32))func_801619A4)(arg0)) { + case 0: + case 1: + case 2: + case 6: + if (((s32 (*)(s32))func_80149AA8)(arg0) != 0) { + D_801803B4[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149AD4)(arg0); + return; + } + if (((s32 (*)(s32))func_80149B54)(arg0) != 0) { + D_801803B4[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149BAC)(arg0); + return; + } + break; + case 3: + ((void (*)(s32))func_801498E0)(arg0); + break; + case 4: + ((void (*)(s32))func_80149954)(arg0); + break; + case 5: + if (((s32 (*)(s32))func_80149A64)(arg0) != 0) { + D_801803B4[*(u16 *)arg0]((void *)arg0); + func_800CCCC0(arg0); + return; + } + break; + } + if (func_80149CD4(arg0) != 0) { + D_801803B4[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_8015E880)(arg0); + return; + } + if (((s32 (*)(s32))func_80149744)(arg0) != 0) { + D_801803B4[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149788)(arg0); + return; + } + if (((s32 (*)(s32))func_801496D4)(arg0) != 0) { + D_801803B4[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149704)(arg0); + if (((u8)((s32 (*)(s32))func_80148AFC)(arg0)) == 0) { + func_80146D90(arg0); + } + if ((*(s32 *)(arg0 + 0x24) | *(s32 *)(arg0 + 0x2C)) != 0) { + func_80154150(arg0, 0xF); + } else { + ((void (*)(s32, s32, s32))func_801541D8)(arg0, 0xD, 6); + } + *(s32 *)(arg0 + 0x238) = 1; + return; + } + if (((s32 (*)(s32))func_801488A8)(arg0) != 0) { + sp10[0] = 0; + sp10[1] = 0; + sp10[2] = 0; + t = *(s16 *)(arg0 + 0x26); + sp18[0] = t; + sp18[1] = 0; + t = *(s16 *)(arg0 + 0x2E); + sp18[2] = t; + D_801803B4[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 1); + ((void (*)(s32))func_8015A264)(arg0); + t = -(((s32 (*)(s16 *, s16 *))func_80013294)(sp10, sp18) << 0x10); + if (t < *(s32 *)(arg0 + 0x2C)) { + *(s32 *)(arg0 + 0x2C) = t; + } + return; + } + if (*(u16 *)(arg0 + 0xB8) == 0x8000) { + D_801803B4[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 0); + ((void (*)(s32))func_80159B70)(arg0); + return; + } + z = *(s32 *)(arg0 + 0x2C); + if (func_8016F1AC() != 0) { + goto zero; + } + if (z <= lim) { + goto one; + } + if (D_8011F9C4 == 0) { + goto zero; + } + if (((u8)func_80029178(0x21)) != 0) { + goto zero; + } +one: + doit = 1; + goto join; +zero: + doit = 0; +join: + if (doit != 0) { + D_801803B4[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 0); + ((void (*)(s32))func_80159B70)(arg0); + func_80154150(arg0, 9); + ((void (*)(s32, s32 *))func_80146DB8)(arg0, &D_80180348); + ((void (*)(s32, s32))func_80161CD0)(arg0, *(u16 *)(arg0 + 0x16E)); + return; + } + if (func_80161208(arg0) == 0) { + ((void (*)(s32))func_801725A4)(arg0); + } +} DEFINE_func_8015BD8C() /* dedup: shared engine-core @0x8015BD8C (src/shared) */ diff --git a/src/ov_SC05_017/ov_SC05_017_jr_8015AE2C.c b/src/ov_SC05_017/ov_SC05_017_jr_8015AE2C.c index 4fa19ac81..84f1bfb62 100644 --- a/src/ov_SC05_017/ov_SC05_017_jr_8015AE2C.c +++ b/src/ov_SC05_017/ov_SC05_017_jr_8015AE2C.c @@ -1512,7 +1512,259 @@ DEFINE_func_8015B858() /* dedup: shared engine-core @0x8015B858 (src/shared) */ DEFINE_func_8015B8F8() /* dedup: shared engine-core @0x8015B8F8 (src/shared) */ -INCLUDE_ASM("asm/ov_SC05_017/nonmatchings/ov_SC05_017_jr_8015AE2C", func_8015B950); +extern s32 func_8015AE2C(); + +// @class: plumbing +// @stuck: none — MATCH (271/271, pin-free, zero asm). The ONLY residual is DEF-SIDE plumbing, and it is now named exactly: the in-TU instantiation `DEFINE_func_8015BEE4()` (engine_core.h:1851-1855) expands to `extern s32 func_8015B950(void);` INSIDE ov_SC01_077_jr_8015AE2C.c, ~14 lines BELOW this definition, so the 1-param def collides with a `(void)` prototype -> `conflicting types for func_8015B950` (.run/bank_func_8015B950.log). §73 PARAMS axis / T0. Surgical fix = §65b de-macroize that ONE instantiation (blast radius: this TU); the fleet-wide `(void)`->`()` header edit is §63 and must be R22-validated. +/* func_8015B950 (ov_SC01_077_jr_8015AE2C, 271 ins, jtbl_801D8B74) — SESSION-21 re-verified + * + * ── ROUND-2 INDEPENDENT RE-VERIFICATION (2026-07-27, fresh agent, §88e discipline) ───────────── + * match_one : MATCH (271 ins) against the CURRENT tree — §87 staleness re-checked today. + * .text size: compiled .text = 0x43C = 1084 B = 271 ins, EXACTLY the target's declared 0x43C + * ("nonmatching func_8015B950, 0x43C"). So this is NOT a §83a length drift hiding + * behind a zero count — the count is over equal-length streams. + * jtbl : RE-DECODED MECHANICALLY, not inherited. Compiled .rodata = 0x1C = 28 B = 7 words, + * 7x R_MIPS_32 -> .text with implicit addends [58,58,58,E0,F0,100,58]; +0x8015B950 + * = [8015B9A8, 8015B9A8, 8015B9A8, 8015BA30, 8015BA40, 8015BA50, 8015B9A8]. + * Diffed word-for-word against asm/ov_SC01_077/data/tail14.data.s:15-23 — 7/7 identical. + * symcheck : SYMS-DIFF target=35 draft=34, sole MISSING = jtbl_801D8B74. This is the §81 jr + * FALSE POSITIVE, re-confirmed here by reading the relocs: gcc emits its OWN table and + * references it with R_MIPS_HI16/LO16 against the SECTION `.rodata` (t.o +0x40/+0x48), + * so the splat's dlabel NAME can never appear in the draft object's relocation set. + * Nothing is dropped and nothing is invented: the draft's other 34 symbols are exactly + * the target's other 34. + * FAMILY : the x138 remap is clean and §84-safe. Every sibling is 271 ins with an IDENTICAL + * callee set; only THREE names vary per overlay — the two data labels and the jtbl: + * ov_SC01_077 D_8018F808 / D_8018F874 / jtbl_801D8B74 + * ov_SC03_099 D_80185A50 / D_80185ABC / jtbl_801BD898 + * ov_SC06_008 D_80187E44 / D_80187EB0 / jtbl_801A8734 + * The pair is always +0x6C apart, and NO literal in this draft encodes that distance + * (both labels are referenced by name), so there is no §84 derived-offset hazard. + * D_8011F9C4 is fleet-constant (main-EXE data) and must NOT be remapped. + * + * match_one: MATCH (271 ins) against the CURRENT tree (§87 staleness re-checked, 2026-07-27). + * PIN-FREE, zero asm, offset-pure (s32 arg0 + raw offsets) — x138 template-safe. + * Provenance: this is the Phase-26 crack (.run/phase26-cracks/func_8015B950.c) re-gated verbatim, + * with ONE deliberate change: the definition's return type void -> s32. + * - `void func_8015B950(s32 arg0)` : MATCH (271 ins) [the Phase-26 form] + * - `s32 func_8015B950(s32 arg0)` : MATCH (271 ins) [shipped — §3a-1 void->s32 is byte-neutral] + * The fleet/engine_core.h canonical decl is `extern s32 func_8015B950(void);` (engine_core.h:1852), + * and the last bank attempt (.run/bank_func_8015B950.log) died on `conflicting types for + * func_8015B950`. Shipping the s32 return kills the §73 RETURN axis for free and leaves only the + * cheap T0 PARAMS axis for the ladder (fix_header_decl.py / --fix-def-sig / cast_call_sites). + * Both forms are byte-identical, so the orchestrator may swap the return type back at zero cost. + * + * SYMBOLS (§58 rules 1/2 — all splat spellings, all verified present): + * D_8018F874 asm/ov_SC01_077/data/tail.data.s:4355 (the state-handler vtable) + * D_8018F808 asm/ov_SC01_077/data/tail.data.s:4293 + * D_8011F9C4 main-EXE data; spelled `extern s32 D_8011F9C4;` in 5+ already-banked TUs + * jtbl_801D8B74 asm/ov_SC01_077/data/tail14.data.s:15 (compiler jump table — not named in C) + * + * JTBL VERIFIED (§8a gate): compiled .rodata = exactly 0x1C B / 7 words, 7x R_MIPS_32 .text with + * addends [0x58,0x58,0x58,0xE0,0xF0,0x100,0x58] -> +0x8015B950 = [B9A8,B9A8,B9A8,BA30,BA40,BA50, + * B9A8] == the original words at 0x801D8B74..0x801D8B8C. Bound `sltiu $v0,$v1,0x7` matches. + * The raw dlabel's 8th word 0x00000000 is NOT an entry — it is the intra-TU `.align 3` pad of the + * B34/B54/B74 jtbl chain; the object can never emit it (maspsx drops .align), so it must stay in + * the post-carve RAW data piece (the §53/§62/§81 carve chain applies at bank time). + * + * Same family as the TU's own already-matched func_8015AE2C: 7-case switch on ((s32 (*)(s32))func_801619A4)() + * (0/1/2/6 shared, 3/4/5 own, no default block — out-of-range and every `break` fall to the + * after-switch join), then a chain of "state handler" tests, each dispatching + * D_8018F874[*(u16*)arg0](arg0) and returning. + * + * THREE LEVERS (draft -> MATCH in 3 compiles): + * + * 1. PROLOGUE CONSTANT = an INITIALIZED LOCAL, not a literal in the compare. + * Target opens with `lui $s2, 0xFFF5` in the *prologue*, used once ~200 ins later in + * `slt $v0,$s2,$s1`. No gcc-2.7.2 pass hoists a (set reg const_int) across basic blocks + * (loop.c needs a loop; cse/combine/sched never move insns between BBs) — so the insn must + * have been EMITTED in the first BB, i.e. the constant is a local initialized at the top of + * the function. cse then cannot fold it back into the compare: the `slt` operand predicate is + * `arith_operand`, which rejects a CONST_INT wider than 16 bits, so validate_change fails and + * the pseudo survives. Its live range spans every call -> global.c gives it a callee-saved reg. + * Writing `z > -0xB0000` inline instead emits the `lui` into the branch delay slot next to the + * compare (caller-saved $v0) and the function is 1 insn short. => `s32 lim = -0xB0000;` at top. + * + * 2. `lh` vs `lhu`: a short->short copy is a pure HImode move and gcc emits `lhu`. The target's + * `lh $v0,0x26($s0)` means the value passed through an SImode (int) temp: expand makes + * (set (reg:SI) (sign_extend (mem:HI))) + (set (mem:HI) (subreg:HI ...)), and combine cannot + * merge them (the merged form is mem<-mem, which no movhi accepts) so the sign-extending load + * survives. => route both halfword copies through the `s32 t` temp. + * + * 3. THE `goto` LAYOUT — dodging jump.c's store-flag conversion (jump.c:1005-1065). + * An if/else chain writing 0/1 into `doit` makes gcc collapse the last pair into + * `sltiu $v0,$v0,1`. jump.c fires that conversion when the insn immediately after a + * conditional jump is a lone `SET pseudo, CONST_INT` whose following simplejump targets the + * SAME label as the branch (jump.c:1038 `reallabelprev == temp || ... JUMP_LABEL(temp4) == + * JUMP_LABEL(insn)`) — exactly the shape of `if (c) x=0; else x=1;`. + * The target instead cross-jumps ALL the `doit=0` exits into ONE shared block placed after the + * `doit=1` fall-through; reorg's fill_slots_from_thread then COPIES that single set into all + * three branch delay slots and redirects each branch past it (which is why `addu $v0,$zero, + * $zero` appears 3x in delay slots and the shared block vanishes). A `goto zero;` / `goto one;` + * chain expresses that layout directly, and each conditional jump is then followed by a + * compare/call rather than a lone const set, so the store-flag conversion never triggers. + * GENERAL RULE: multiple predicates that all assign the SAME constant to one flag => write + * them as `goto` to a shared assignment, never as an if/else ladder. + */ +extern s32 D_8011F9C4; +extern s32 D_8018F808; + +extern s32 func_80161B18(void); +extern s32 func_801619A4(s32*); +extern s32 func_80149AA8(s32*); +extern void func_80149AD4(s32*); +extern s32 func_80149B54(s32*); +extern void func_80149BAC(s32*); +extern s32 func_801498E0(s32*); +extern s32 func_80149954(s32); +extern s32 func_80149A64(s32*); +extern void func_800CCCC0(s32 a0); +extern s32 func_80149CD4(s32 a0); +extern void func_8015E880(s32*); +extern s32 func_80149744(struct S_80149744*); +extern void func_80149788(void); +extern s32 func_801496D4(void*); +extern void func_80149704(void); +extern int func_80148AFC(void*); +extern void func_80146D90(s32 a0); +extern void func_80154150(s32 a0, s32 a1); +extern void func_801541D8(u8*, s32, s32); +extern s32 func_801488A8(u8*); +extern void func_80147078(s32*, s16); +extern void func_8015A264(void*); +extern s32 func_80013294(void*, void*); +extern void func_80159B70(void*); +extern s32 func_8016F1AC(void); +extern s32 func_80029178(s32 a0); +extern void func_80146DB8(s32*, s32*); +extern s32 func_80161CD0(s32, s32); +extern s32 func_80161208(s32 a0); +extern s32 func_801725A4(u8*); + +s32 func_8015B950(s32 arg0) +{ + + extern void (*D_8018F874[])(void *); + s16 sp10[4]; + s16 sp18[4]; + s32 t; + s32 z; + s32 doit; + s32 lim = -0xB0000; + + if (func_80161B18() != 0) { + return; + } + switch (((s32 (*)(s32))func_801619A4)(arg0)) { + case 0: + case 1: + case 2: + case 6: + if (((s32 (*)(s32))func_80149AA8)(arg0) != 0) { + D_8018F874[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149AD4)(arg0); + return; + } + if (((s32 (*)(s32))func_80149B54)(arg0) != 0) { + D_8018F874[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149BAC)(arg0); + return; + } + break; + case 3: + ((void (*)(s32))func_801498E0)(arg0); + break; + case 4: + ((void (*)(s32))func_80149954)(arg0); + break; + case 5: + if (((s32 (*)(s32))func_80149A64)(arg0) != 0) { + D_8018F874[*(u16 *)arg0]((void *)arg0); + func_800CCCC0(arg0); + return; + } + break; + } + if (func_80149CD4(arg0) != 0) { + D_8018F874[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_8015E880)(arg0); + return; + } + if (((s32 (*)(s32))func_80149744)(arg0) != 0) { + D_8018F874[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149788)(arg0); + return; + } + if (((s32 (*)(s32))func_801496D4)(arg0) != 0) { + D_8018F874[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149704)(arg0); + if (((u8)((s32 (*)(s32))func_80148AFC)(arg0)) == 0) { + func_80146D90(arg0); + } + if ((*(s32 *)(arg0 + 0x24) | *(s32 *)(arg0 + 0x2C)) != 0) { + func_80154150(arg0, 0xF); + } else { + ((void (*)(s32, s32, s32))func_801541D8)(arg0, 0xD, 6); + } + *(s32 *)(arg0 + 0x238) = 1; + return; + } + if (((s32 (*)(s32))func_801488A8)(arg0) != 0) { + sp10[0] = 0; + sp10[1] = 0; + sp10[2] = 0; + t = *(s16 *)(arg0 + 0x26); + sp18[0] = t; + sp18[1] = 0; + t = *(s16 *)(arg0 + 0x2E); + sp18[2] = t; + D_8018F874[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 1); + ((void (*)(s32))func_8015A264)(arg0); + t = -(((s32 (*)(s16 *, s16 *))func_80013294)(sp10, sp18) << 0x10); + if (t < *(s32 *)(arg0 + 0x2C)) { + *(s32 *)(arg0 + 0x2C) = t; + } + return; + } + if (*(u16 *)(arg0 + 0xB8) == 0x8000) { + D_8018F874[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 0); + ((void (*)(s32))func_80159B70)(arg0); + return; + } + z = *(s32 *)(arg0 + 0x2C); + if (func_8016F1AC() != 0) { + goto zero; + } + if (z <= lim) { + goto one; + } + if (D_8011F9C4 == 0) { + goto zero; + } + if (((u8)func_80029178(0x21)) != 0) { + goto zero; + } +one: + doit = 1; + goto join; +zero: + doit = 0; +join: + if (doit != 0) { + D_8018F874[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 0); + ((void (*)(s32))func_80159B70)(arg0); + func_80154150(arg0, 9); + ((void (*)(s32, s32 *))func_80146DB8)(arg0, &D_8018F808); + ((void (*)(s32, s32))func_80161CD0)(arg0, *(u16 *)(arg0 + 0x16E)); + return; + } + if (func_80161208(arg0) == 0) { + ((void (*)(s32))func_801725A4)(arg0); + } +} DEFINE_func_8015BD8C() /* dedup: shared engine-core @0x8015BD8C (src/shared) */ diff --git a/src/ov_SC05_018/ov_SC05_018_jr_8015AE2C.c b/src/ov_SC05_018/ov_SC05_018_jr_8015AE2C.c index ad928719a..0b1345b12 100644 --- a/src/ov_SC05_018/ov_SC05_018_jr_8015AE2C.c +++ b/src/ov_SC05_018/ov_SC05_018_jr_8015AE2C.c @@ -1512,7 +1512,259 @@ DEFINE_func_8015B858() /* dedup: shared engine-core @0x8015B858 (src/shared) */ DEFINE_func_8015B8F8() /* dedup: shared engine-core @0x8015B8F8 (src/shared) */ -INCLUDE_ASM("asm/ov_SC05_018/nonmatchings/ov_SC05_018_jr_8015AE2C", func_8015B950); +extern s32 func_8015AE2C(); + +// @class: plumbing +// @stuck: none — MATCH (271/271, pin-free, zero asm). The ONLY residual is DEF-SIDE plumbing, and it is now named exactly: the in-TU instantiation `DEFINE_func_8015BEE4()` (engine_core.h:1851-1855) expands to `extern s32 func_8015B950(void);` INSIDE ov_SC01_077_jr_8015AE2C.c, ~14 lines BELOW this definition, so the 1-param def collides with a `(void)` prototype -> `conflicting types for func_8015B950` (.run/bank_func_8015B950.log). §73 PARAMS axis / T0. Surgical fix = §65b de-macroize that ONE instantiation (blast radius: this TU); the fleet-wide `(void)`->`()` header edit is §63 and must be R22-validated. +/* func_8015B950 (ov_SC01_077_jr_8015AE2C, 271 ins, jtbl_801D8B74) — SESSION-21 re-verified + * + * ── ROUND-2 INDEPENDENT RE-VERIFICATION (2026-07-27, fresh agent, §88e discipline) ───────────── + * match_one : MATCH (271 ins) against the CURRENT tree — §87 staleness re-checked today. + * .text size: compiled .text = 0x43C = 1084 B = 271 ins, EXACTLY the target's declared 0x43C + * ("nonmatching func_8015B950, 0x43C"). So this is NOT a §83a length drift hiding + * behind a zero count — the count is over equal-length streams. + * jtbl : RE-DECODED MECHANICALLY, not inherited. Compiled .rodata = 0x1C = 28 B = 7 words, + * 7x R_MIPS_32 -> .text with implicit addends [58,58,58,E0,F0,100,58]; +0x8015B950 + * = [8015B9A8, 8015B9A8, 8015B9A8, 8015BA30, 8015BA40, 8015BA50, 8015B9A8]. + * Diffed word-for-word against asm/ov_SC01_077/data/tail14.data.s:15-23 — 7/7 identical. + * symcheck : SYMS-DIFF target=35 draft=34, sole MISSING = jtbl_801D8B74. This is the §81 jr + * FALSE POSITIVE, re-confirmed here by reading the relocs: gcc emits its OWN table and + * references it with R_MIPS_HI16/LO16 against the SECTION `.rodata` (t.o +0x40/+0x48), + * so the splat's dlabel NAME can never appear in the draft object's relocation set. + * Nothing is dropped and nothing is invented: the draft's other 34 symbols are exactly + * the target's other 34. + * FAMILY : the x138 remap is clean and §84-safe. Every sibling is 271 ins with an IDENTICAL + * callee set; only THREE names vary per overlay — the two data labels and the jtbl: + * ov_SC01_077 D_80188F64 / D_80188FD0 / jtbl_801D8B74 + * ov_SC03_099 D_80185A50 / D_80185ABC / jtbl_801BD898 + * ov_SC06_008 D_80187E44 / D_80187EB0 / jtbl_801A8734 + * The pair is always +0x6C apart, and NO literal in this draft encodes that distance + * (both labels are referenced by name), so there is no §84 derived-offset hazard. + * D_8011F9C4 is fleet-constant (main-EXE data) and must NOT be remapped. + * + * match_one: MATCH (271 ins) against the CURRENT tree (§87 staleness re-checked, 2026-07-27). + * PIN-FREE, zero asm, offset-pure (s32 arg0 + raw offsets) — x138 template-safe. + * Provenance: this is the Phase-26 crack (.run/phase26-cracks/func_8015B950.c) re-gated verbatim, + * with ONE deliberate change: the definition's return type void -> s32. + * - `void func_8015B950(s32 arg0)` : MATCH (271 ins) [the Phase-26 form] + * - `s32 func_8015B950(s32 arg0)` : MATCH (271 ins) [shipped — §3a-1 void->s32 is byte-neutral] + * The fleet/engine_core.h canonical decl is `extern s32 func_8015B950(void);` (engine_core.h:1852), + * and the last bank attempt (.run/bank_func_8015B950.log) died on `conflicting types for + * func_8015B950`. Shipping the s32 return kills the §73 RETURN axis for free and leaves only the + * cheap T0 PARAMS axis for the ladder (fix_header_decl.py / --fix-def-sig / cast_call_sites). + * Both forms are byte-identical, so the orchestrator may swap the return type back at zero cost. + * + * SYMBOLS (§58 rules 1/2 — all splat spellings, all verified present): + * D_80188FD0 asm/ov_SC01_077/data/tail.data.s:4355 (the state-handler vtable) + * D_80188F64 asm/ov_SC01_077/data/tail.data.s:4293 + * D_8011F9C4 main-EXE data; spelled `extern s32 D_8011F9C4;` in 5+ already-banked TUs + * jtbl_801D8B74 asm/ov_SC01_077/data/tail14.data.s:15 (compiler jump table — not named in C) + * + * JTBL VERIFIED (§8a gate): compiled .rodata = exactly 0x1C B / 7 words, 7x R_MIPS_32 .text with + * addends [0x58,0x58,0x58,0xE0,0xF0,0x100,0x58] -> +0x8015B950 = [B9A8,B9A8,B9A8,BA30,BA40,BA50, + * B9A8] == the original words at 0x801D8B74..0x801D8B8C. Bound `sltiu $v0,$v1,0x7` matches. + * The raw dlabel's 8th word 0x00000000 is NOT an entry — it is the intra-TU `.align 3` pad of the + * B34/B54/B74 jtbl chain; the object can never emit it (maspsx drops .align), so it must stay in + * the post-carve RAW data piece (the §53/§62/§81 carve chain applies at bank time). + * + * Same family as the TU's own already-matched func_8015AE2C: 7-case switch on ((s32 (*)(s32))func_801619A4)() + * (0/1/2/6 shared, 3/4/5 own, no default block — out-of-range and every `break` fall to the + * after-switch join), then a chain of "state handler" tests, each dispatching + * D_80188FD0[*(u16*)arg0](arg0) and returning. + * + * THREE LEVERS (draft -> MATCH in 3 compiles): + * + * 1. PROLOGUE CONSTANT = an INITIALIZED LOCAL, not a literal in the compare. + * Target opens with `lui $s2, 0xFFF5` in the *prologue*, used once ~200 ins later in + * `slt $v0,$s2,$s1`. No gcc-2.7.2 pass hoists a (set reg const_int) across basic blocks + * (loop.c needs a loop; cse/combine/sched never move insns between BBs) — so the insn must + * have been EMITTED in the first BB, i.e. the constant is a local initialized at the top of + * the function. cse then cannot fold it back into the compare: the `slt` operand predicate is + * `arith_operand`, which rejects a CONST_INT wider than 16 bits, so validate_change fails and + * the pseudo survives. Its live range spans every call -> global.c gives it a callee-saved reg. + * Writing `z > -0xB0000` inline instead emits the `lui` into the branch delay slot next to the + * compare (caller-saved $v0) and the function is 1 insn short. => `s32 lim = -0xB0000;` at top. + * + * 2. `lh` vs `lhu`: a short->short copy is a pure HImode move and gcc emits `lhu`. The target's + * `lh $v0,0x26($s0)` means the value passed through an SImode (int) temp: expand makes + * (set (reg:SI) (sign_extend (mem:HI))) + (set (mem:HI) (subreg:HI ...)), and combine cannot + * merge them (the merged form is mem<-mem, which no movhi accepts) so the sign-extending load + * survives. => route both halfword copies through the `s32 t` temp. + * + * 3. THE `goto` LAYOUT — dodging jump.c's store-flag conversion (jump.c:1005-1065). + * An if/else chain writing 0/1 into `doit` makes gcc collapse the last pair into + * `sltiu $v0,$v0,1`. jump.c fires that conversion when the insn immediately after a + * conditional jump is a lone `SET pseudo, CONST_INT` whose following simplejump targets the + * SAME label as the branch (jump.c:1038 `reallabelprev == temp || ... JUMP_LABEL(temp4) == + * JUMP_LABEL(insn)`) — exactly the shape of `if (c) x=0; else x=1;`. + * The target instead cross-jumps ALL the `doit=0` exits into ONE shared block placed after the + * `doit=1` fall-through; reorg's fill_slots_from_thread then COPIES that single set into all + * three branch delay slots and redirects each branch past it (which is why `addu $v0,$zero, + * $zero` appears 3x in delay slots and the shared block vanishes). A `goto zero;` / `goto one;` + * chain expresses that layout directly, and each conditional jump is then followed by a + * compare/call rather than a lone const set, so the store-flag conversion never triggers. + * GENERAL RULE: multiple predicates that all assign the SAME constant to one flag => write + * them as `goto` to a shared assignment, never as an if/else ladder. + */ +extern s32 D_8011F9C4; +extern s32 D_80188F64; + +extern s32 func_80161B18(void); +extern s32 func_801619A4(s32*); +extern s32 func_80149AA8(s32*); +extern void func_80149AD4(s32*); +extern s32 func_80149B54(s32*); +extern void func_80149BAC(s32*); +extern s32 func_801498E0(s32*); +extern s32 func_80149954(s32); +extern s32 func_80149A64(s32*); +extern void func_800CCCC0(s32 a0); +extern s32 func_80149CD4(s32 a0); +extern void func_8015E880(s32*); +extern s32 func_80149744(struct S_80149744*); +extern void func_80149788(void); +extern s32 func_801496D4(void*); +extern void func_80149704(void); +extern int func_80148AFC(void*); +extern void func_80146D90(s32 a0); +extern void func_80154150(s32 a0, s32 a1); +extern void func_801541D8(u8*, s32, s32); +extern s32 func_801488A8(u8*); +extern void func_80147078(s32*, s16); +extern void func_8015A264(void*); +extern s32 func_80013294(void*, void*); +extern void func_80159B70(void*); +extern s32 func_8016F1AC(void); +extern s32 func_80029178(s32 a0); +extern void func_80146DB8(s32*, s32*); +extern s32 func_80161CD0(s32, s32); +extern s32 func_80161208(s32 a0); +extern s32 func_801725A4(u8*); + +s32 func_8015B950(s32 arg0) +{ + + extern void (*D_80188FD0[])(void *); + s16 sp10[4]; + s16 sp18[4]; + s32 t; + s32 z; + s32 doit; + s32 lim = -0xB0000; + + if (func_80161B18() != 0) { + return; + } + switch (((s32 (*)(s32))func_801619A4)(arg0)) { + case 0: + case 1: + case 2: + case 6: + if (((s32 (*)(s32))func_80149AA8)(arg0) != 0) { + D_80188FD0[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149AD4)(arg0); + return; + } + if (((s32 (*)(s32))func_80149B54)(arg0) != 0) { + D_80188FD0[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149BAC)(arg0); + return; + } + break; + case 3: + ((void (*)(s32))func_801498E0)(arg0); + break; + case 4: + ((void (*)(s32))func_80149954)(arg0); + break; + case 5: + if (((s32 (*)(s32))func_80149A64)(arg0) != 0) { + D_80188FD0[*(u16 *)arg0]((void *)arg0); + func_800CCCC0(arg0); + return; + } + break; + } + if (func_80149CD4(arg0) != 0) { + D_80188FD0[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_8015E880)(arg0); + return; + } + if (((s32 (*)(s32))func_80149744)(arg0) != 0) { + D_80188FD0[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149788)(arg0); + return; + } + if (((s32 (*)(s32))func_801496D4)(arg0) != 0) { + D_80188FD0[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149704)(arg0); + if (((u8)((s32 (*)(s32))func_80148AFC)(arg0)) == 0) { + func_80146D90(arg0); + } + if ((*(s32 *)(arg0 + 0x24) | *(s32 *)(arg0 + 0x2C)) != 0) { + func_80154150(arg0, 0xF); + } else { + ((void (*)(s32, s32, s32))func_801541D8)(arg0, 0xD, 6); + } + *(s32 *)(arg0 + 0x238) = 1; + return; + } + if (((s32 (*)(s32))func_801488A8)(arg0) != 0) { + sp10[0] = 0; + sp10[1] = 0; + sp10[2] = 0; + t = *(s16 *)(arg0 + 0x26); + sp18[0] = t; + sp18[1] = 0; + t = *(s16 *)(arg0 + 0x2E); + sp18[2] = t; + D_80188FD0[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 1); + ((void (*)(s32))func_8015A264)(arg0); + t = -(((s32 (*)(s16 *, s16 *))func_80013294)(sp10, sp18) << 0x10); + if (t < *(s32 *)(arg0 + 0x2C)) { + *(s32 *)(arg0 + 0x2C) = t; + } + return; + } + if (*(u16 *)(arg0 + 0xB8) == 0x8000) { + D_80188FD0[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 0); + ((void (*)(s32))func_80159B70)(arg0); + return; + } + z = *(s32 *)(arg0 + 0x2C); + if (func_8016F1AC() != 0) { + goto zero; + } + if (z <= lim) { + goto one; + } + if (D_8011F9C4 == 0) { + goto zero; + } + if (((u8)func_80029178(0x21)) != 0) { + goto zero; + } +one: + doit = 1; + goto join; +zero: + doit = 0; +join: + if (doit != 0) { + D_80188FD0[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 0); + ((void (*)(s32))func_80159B70)(arg0); + func_80154150(arg0, 9); + ((void (*)(s32, s32 *))func_80146DB8)(arg0, &D_80188F64); + ((void (*)(s32, s32))func_80161CD0)(arg0, *(u16 *)(arg0 + 0x16E)); + return; + } + if (func_80161208(arg0) == 0) { + ((void (*)(s32))func_801725A4)(arg0); + } +} DEFINE_func_8015BD8C() /* dedup: shared engine-core @0x8015BD8C (src/shared) */ diff --git a/src/ov_SC05_019/ov_SC05_019_jr_8015AE2C.c b/src/ov_SC05_019/ov_SC05_019_jr_8015AE2C.c index 30b954687..e514f8ad9 100644 --- a/src/ov_SC05_019/ov_SC05_019_jr_8015AE2C.c +++ b/src/ov_SC05_019/ov_SC05_019_jr_8015AE2C.c @@ -1512,7 +1512,259 @@ DEFINE_func_8015B858() /* dedup: shared engine-core @0x8015B858 (src/shared) */ DEFINE_func_8015B8F8() /* dedup: shared engine-core @0x8015B8F8 (src/shared) */ -INCLUDE_ASM("asm/ov_SC05_019/nonmatchings/ov_SC05_019_jr_8015AE2C", func_8015B950); +extern s32 func_8015AE2C(); + +// @class: plumbing +// @stuck: none — MATCH (271/271, pin-free, zero asm). The ONLY residual is DEF-SIDE plumbing, and it is now named exactly: the in-TU instantiation `DEFINE_func_8015BEE4()` (engine_core.h:1851-1855) expands to `extern s32 func_8015B950(void);` INSIDE ov_SC01_077_jr_8015AE2C.c, ~14 lines BELOW this definition, so the 1-param def collides with a `(void)` prototype -> `conflicting types for func_8015B950` (.run/bank_func_8015B950.log). §73 PARAMS axis / T0. Surgical fix = §65b de-macroize that ONE instantiation (blast radius: this TU); the fleet-wide `(void)`->`()` header edit is §63 and must be R22-validated. +/* func_8015B950 (ov_SC01_077_jr_8015AE2C, 271 ins, jtbl_801D8B74) — SESSION-21 re-verified + * + * ── ROUND-2 INDEPENDENT RE-VERIFICATION (2026-07-27, fresh agent, §88e discipline) ───────────── + * match_one : MATCH (271 ins) against the CURRENT tree — §87 staleness re-checked today. + * .text size: compiled .text = 0x43C = 1084 B = 271 ins, EXACTLY the target's declared 0x43C + * ("nonmatching func_8015B950, 0x43C"). So this is NOT a §83a length drift hiding + * behind a zero count — the count is over equal-length streams. + * jtbl : RE-DECODED MECHANICALLY, not inherited. Compiled .rodata = 0x1C = 28 B = 7 words, + * 7x R_MIPS_32 -> .text with implicit addends [58,58,58,E0,F0,100,58]; +0x8015B950 + * = [8015B9A8, 8015B9A8, 8015B9A8, 8015BA30, 8015BA40, 8015BA50, 8015B9A8]. + * Diffed word-for-word against asm/ov_SC01_077/data/tail14.data.s:15-23 — 7/7 identical. + * symcheck : SYMS-DIFF target=35 draft=34, sole MISSING = jtbl_801D8B74. This is the §81 jr + * FALSE POSITIVE, re-confirmed here by reading the relocs: gcc emits its OWN table and + * references it with R_MIPS_HI16/LO16 against the SECTION `.rodata` (t.o +0x40/+0x48), + * so the splat's dlabel NAME can never appear in the draft object's relocation set. + * Nothing is dropped and nothing is invented: the draft's other 34 symbols are exactly + * the target's other 34. + * FAMILY : the x138 remap is clean and §84-safe. Every sibling is 271 ins with an IDENTICAL + * callee set; only THREE names vary per overlay — the two data labels and the jtbl: + * ov_SC01_077 D_801818A8 / D_80181914 / jtbl_801D8B74 + * ov_SC03_099 D_80185A50 / D_80185ABC / jtbl_801BD898 + * ov_SC06_008 D_80187E44 / D_80187EB0 / jtbl_801A8734 + * The pair is always +0x6C apart, and NO literal in this draft encodes that distance + * (both labels are referenced by name), so there is no §84 derived-offset hazard. + * D_8011F9C4 is fleet-constant (main-EXE data) and must NOT be remapped. + * + * match_one: MATCH (271 ins) against the CURRENT tree (§87 staleness re-checked, 2026-07-27). + * PIN-FREE, zero asm, offset-pure (s32 arg0 + raw offsets) — x138 template-safe. + * Provenance: this is the Phase-26 crack (.run/phase26-cracks/func_8015B950.c) re-gated verbatim, + * with ONE deliberate change: the definition's return type void -> s32. + * - `void func_8015B950(s32 arg0)` : MATCH (271 ins) [the Phase-26 form] + * - `s32 func_8015B950(s32 arg0)` : MATCH (271 ins) [shipped — §3a-1 void->s32 is byte-neutral] + * The fleet/engine_core.h canonical decl is `extern s32 func_8015B950(void);` (engine_core.h:1852), + * and the last bank attempt (.run/bank_func_8015B950.log) died on `conflicting types for + * func_8015B950`. Shipping the s32 return kills the §73 RETURN axis for free and leaves only the + * cheap T0 PARAMS axis for the ladder (fix_header_decl.py / --fix-def-sig / cast_call_sites). + * Both forms are byte-identical, so the orchestrator may swap the return type back at zero cost. + * + * SYMBOLS (§58 rules 1/2 — all splat spellings, all verified present): + * D_80181914 asm/ov_SC01_077/data/tail.data.s:4355 (the state-handler vtable) + * D_801818A8 asm/ov_SC01_077/data/tail.data.s:4293 + * D_8011F9C4 main-EXE data; spelled `extern s32 D_8011F9C4;` in 5+ already-banked TUs + * jtbl_801D8B74 asm/ov_SC01_077/data/tail14.data.s:15 (compiler jump table — not named in C) + * + * JTBL VERIFIED (§8a gate): compiled .rodata = exactly 0x1C B / 7 words, 7x R_MIPS_32 .text with + * addends [0x58,0x58,0x58,0xE0,0xF0,0x100,0x58] -> +0x8015B950 = [B9A8,B9A8,B9A8,BA30,BA40,BA50, + * B9A8] == the original words at 0x801D8B74..0x801D8B8C. Bound `sltiu $v0,$v1,0x7` matches. + * The raw dlabel's 8th word 0x00000000 is NOT an entry — it is the intra-TU `.align 3` pad of the + * B34/B54/B74 jtbl chain; the object can never emit it (maspsx drops .align), so it must stay in + * the post-carve RAW data piece (the §53/§62/§81 carve chain applies at bank time). + * + * Same family as the TU's own already-matched func_8015AE2C: 7-case switch on ((s32 (*)(s32))func_801619A4)() + * (0/1/2/6 shared, 3/4/5 own, no default block — out-of-range and every `break` fall to the + * after-switch join), then a chain of "state handler" tests, each dispatching + * D_80181914[*(u16*)arg0](arg0) and returning. + * + * THREE LEVERS (draft -> MATCH in 3 compiles): + * + * 1. PROLOGUE CONSTANT = an INITIALIZED LOCAL, not a literal in the compare. + * Target opens with `lui $s2, 0xFFF5` in the *prologue*, used once ~200 ins later in + * `slt $v0,$s2,$s1`. No gcc-2.7.2 pass hoists a (set reg const_int) across basic blocks + * (loop.c needs a loop; cse/combine/sched never move insns between BBs) — so the insn must + * have been EMITTED in the first BB, i.e. the constant is a local initialized at the top of + * the function. cse then cannot fold it back into the compare: the `slt` operand predicate is + * `arith_operand`, which rejects a CONST_INT wider than 16 bits, so validate_change fails and + * the pseudo survives. Its live range spans every call -> global.c gives it a callee-saved reg. + * Writing `z > -0xB0000` inline instead emits the `lui` into the branch delay slot next to the + * compare (caller-saved $v0) and the function is 1 insn short. => `s32 lim = -0xB0000;` at top. + * + * 2. `lh` vs `lhu`: a short->short copy is a pure HImode move and gcc emits `lhu`. The target's + * `lh $v0,0x26($s0)` means the value passed through an SImode (int) temp: expand makes + * (set (reg:SI) (sign_extend (mem:HI))) + (set (mem:HI) (subreg:HI ...)), and combine cannot + * merge them (the merged form is mem<-mem, which no movhi accepts) so the sign-extending load + * survives. => route both halfword copies through the `s32 t` temp. + * + * 3. THE `goto` LAYOUT — dodging jump.c's store-flag conversion (jump.c:1005-1065). + * An if/else chain writing 0/1 into `doit` makes gcc collapse the last pair into + * `sltiu $v0,$v0,1`. jump.c fires that conversion when the insn immediately after a + * conditional jump is a lone `SET pseudo, CONST_INT` whose following simplejump targets the + * SAME label as the branch (jump.c:1038 `reallabelprev == temp || ... JUMP_LABEL(temp4) == + * JUMP_LABEL(insn)`) — exactly the shape of `if (c) x=0; else x=1;`. + * The target instead cross-jumps ALL the `doit=0` exits into ONE shared block placed after the + * `doit=1` fall-through; reorg's fill_slots_from_thread then COPIES that single set into all + * three branch delay slots and redirects each branch past it (which is why `addu $v0,$zero, + * $zero` appears 3x in delay slots and the shared block vanishes). A `goto zero;` / `goto one;` + * chain expresses that layout directly, and each conditional jump is then followed by a + * compare/call rather than a lone const set, so the store-flag conversion never triggers. + * GENERAL RULE: multiple predicates that all assign the SAME constant to one flag => write + * them as `goto` to a shared assignment, never as an if/else ladder. + */ +extern s32 D_8011F9C4; +extern s32 D_801818A8; + +extern s32 func_80161B18(void); +extern s32 func_801619A4(s32*); +extern s32 func_80149AA8(s32*); +extern void func_80149AD4(s32*); +extern s32 func_80149B54(s32*); +extern void func_80149BAC(s32*); +extern s32 func_801498E0(s32*); +extern s32 func_80149954(s32); +extern s32 func_80149A64(s32*); +extern void func_800CCCC0(s32 a0); +extern s32 func_80149CD4(s32 a0); +extern void func_8015E880(s32*); +extern s32 func_80149744(struct S_80149744*); +extern void func_80149788(void); +extern s32 func_801496D4(void*); +extern void func_80149704(void); +extern int func_80148AFC(void*); +extern void func_80146D90(s32 a0); +extern void func_80154150(s32 a0, s32 a1); +extern void func_801541D8(u8*, s32, s32); +extern s32 func_801488A8(u8*); +extern void func_80147078(s32*, s16); +extern void func_8015A264(void*); +extern s32 func_80013294(void*, void*); +extern void func_80159B70(void*); +extern s32 func_8016F1AC(void); +extern s32 func_80029178(s32 a0); +extern void func_80146DB8(s32*, s32*); +extern s32 func_80161CD0(s32, s32); +extern s32 func_80161208(s32 a0); +extern s32 func_801725A4(u8*); + +s32 func_8015B950(s32 arg0) +{ + + extern void (*D_80181914[])(void *); + s16 sp10[4]; + s16 sp18[4]; + s32 t; + s32 z; + s32 doit; + s32 lim = -0xB0000; + + if (func_80161B18() != 0) { + return; + } + switch (((s32 (*)(s32))func_801619A4)(arg0)) { + case 0: + case 1: + case 2: + case 6: + if (((s32 (*)(s32))func_80149AA8)(arg0) != 0) { + D_80181914[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149AD4)(arg0); + return; + } + if (((s32 (*)(s32))func_80149B54)(arg0) != 0) { + D_80181914[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149BAC)(arg0); + return; + } + break; + case 3: + ((void (*)(s32))func_801498E0)(arg0); + break; + case 4: + ((void (*)(s32))func_80149954)(arg0); + break; + case 5: + if (((s32 (*)(s32))func_80149A64)(arg0) != 0) { + D_80181914[*(u16 *)arg0]((void *)arg0); + func_800CCCC0(arg0); + return; + } + break; + } + if (func_80149CD4(arg0) != 0) { + D_80181914[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_8015E880)(arg0); + return; + } + if (((s32 (*)(s32))func_80149744)(arg0) != 0) { + D_80181914[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149788)(arg0); + return; + } + if (((s32 (*)(s32))func_801496D4)(arg0) != 0) { + D_80181914[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149704)(arg0); + if (((u8)((s32 (*)(s32))func_80148AFC)(arg0)) == 0) { + func_80146D90(arg0); + } + if ((*(s32 *)(arg0 + 0x24) | *(s32 *)(arg0 + 0x2C)) != 0) { + func_80154150(arg0, 0xF); + } else { + ((void (*)(s32, s32, s32))func_801541D8)(arg0, 0xD, 6); + } + *(s32 *)(arg0 + 0x238) = 1; + return; + } + if (((s32 (*)(s32))func_801488A8)(arg0) != 0) { + sp10[0] = 0; + sp10[1] = 0; + sp10[2] = 0; + t = *(s16 *)(arg0 + 0x26); + sp18[0] = t; + sp18[1] = 0; + t = *(s16 *)(arg0 + 0x2E); + sp18[2] = t; + D_80181914[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 1); + ((void (*)(s32))func_8015A264)(arg0); + t = -(((s32 (*)(s16 *, s16 *))func_80013294)(sp10, sp18) << 0x10); + if (t < *(s32 *)(arg0 + 0x2C)) { + *(s32 *)(arg0 + 0x2C) = t; + } + return; + } + if (*(u16 *)(arg0 + 0xB8) == 0x8000) { + D_80181914[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 0); + ((void (*)(s32))func_80159B70)(arg0); + return; + } + z = *(s32 *)(arg0 + 0x2C); + if (func_8016F1AC() != 0) { + goto zero; + } + if (z <= lim) { + goto one; + } + if (D_8011F9C4 == 0) { + goto zero; + } + if (((u8)func_80029178(0x21)) != 0) { + goto zero; + } +one: + doit = 1; + goto join; +zero: + doit = 0; +join: + if (doit != 0) { + D_80181914[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 0); + ((void (*)(s32))func_80159B70)(arg0); + func_80154150(arg0, 9); + ((void (*)(s32, s32 *))func_80146DB8)(arg0, &D_801818A8); + ((void (*)(s32, s32))func_80161CD0)(arg0, *(u16 *)(arg0 + 0x16E)); + return; + } + if (func_80161208(arg0) == 0) { + ((void (*)(s32))func_801725A4)(arg0); + } +} DEFINE_func_8015BD8C() /* dedup: shared engine-core @0x8015BD8C (src/shared) */ diff --git a/src/ov_SC06_000/ov_SC06_000_jr_8015AE2C.c b/src/ov_SC06_000/ov_SC06_000_jr_8015AE2C.c index 8e8559b6b..2bbc811ac 100644 --- a/src/ov_SC06_000/ov_SC06_000_jr_8015AE2C.c +++ b/src/ov_SC06_000/ov_SC06_000_jr_8015AE2C.c @@ -1512,7 +1512,259 @@ DEFINE_func_8015B858() /* dedup: shared engine-core @0x8015B858 (src/shared) */ DEFINE_func_8015B8F8() /* dedup: shared engine-core @0x8015B8F8 (src/shared) */ -INCLUDE_ASM("asm/ov_SC06_000/nonmatchings/ov_SC06_000_jr_8015AE2C", func_8015B950); +extern s32 func_8015AE2C(); + +// @class: plumbing +// @stuck: none — MATCH (271/271, pin-free, zero asm). The ONLY residual is DEF-SIDE plumbing, and it is now named exactly: the in-TU instantiation `DEFINE_func_8015BEE4()` (engine_core.h:1851-1855) expands to `extern s32 func_8015B950(void);` INSIDE ov_SC01_077_jr_8015AE2C.c, ~14 lines BELOW this definition, so the 1-param def collides with a `(void)` prototype -> `conflicting types for func_8015B950` (.run/bank_func_8015B950.log). §73 PARAMS axis / T0. Surgical fix = §65b de-macroize that ONE instantiation (blast radius: this TU); the fleet-wide `(void)`->`()` header edit is §63 and must be R22-validated. +/* func_8015B950 (ov_SC01_077_jr_8015AE2C, 271 ins, jtbl_801D8B74) — SESSION-21 re-verified + * + * ── ROUND-2 INDEPENDENT RE-VERIFICATION (2026-07-27, fresh agent, §88e discipline) ───────────── + * match_one : MATCH (271 ins) against the CURRENT tree — §87 staleness re-checked today. + * .text size: compiled .text = 0x43C = 1084 B = 271 ins, EXACTLY the target's declared 0x43C + * ("nonmatching func_8015B950, 0x43C"). So this is NOT a §83a length drift hiding + * behind a zero count — the count is over equal-length streams. + * jtbl : RE-DECODED MECHANICALLY, not inherited. Compiled .rodata = 0x1C = 28 B = 7 words, + * 7x R_MIPS_32 -> .text with implicit addends [58,58,58,E0,F0,100,58]; +0x8015B950 + * = [8015B9A8, 8015B9A8, 8015B9A8, 8015BA30, 8015BA40, 8015BA50, 8015B9A8]. + * Diffed word-for-word against asm/ov_SC01_077/data/tail14.data.s:15-23 — 7/7 identical. + * symcheck : SYMS-DIFF target=35 draft=34, sole MISSING = jtbl_801D8B74. This is the §81 jr + * FALSE POSITIVE, re-confirmed here by reading the relocs: gcc emits its OWN table and + * references it with R_MIPS_HI16/LO16 against the SECTION `.rodata` (t.o +0x40/+0x48), + * so the splat's dlabel NAME can never appear in the draft object's relocation set. + * Nothing is dropped and nothing is invented: the draft's other 34 symbols are exactly + * the target's other 34. + * FAMILY : the x138 remap is clean and §84-safe. Every sibling is 271 ins with an IDENTICAL + * callee set; only THREE names vary per overlay — the two data labels and the jtbl: + * ov_SC01_077 D_8018A8B8 / D_8018A924 / jtbl_801D8B74 + * ov_SC03_099 D_80185A50 / D_80185ABC / jtbl_801BD898 + * ov_SC06_008 D_80187E44 / D_80187EB0 / jtbl_801A8734 + * The pair is always +0x6C apart, and NO literal in this draft encodes that distance + * (both labels are referenced by name), so there is no §84 derived-offset hazard. + * D_8011F9C4 is fleet-constant (main-EXE data) and must NOT be remapped. + * + * match_one: MATCH (271 ins) against the CURRENT tree (§87 staleness re-checked, 2026-07-27). + * PIN-FREE, zero asm, offset-pure (s32 arg0 + raw offsets) — x138 template-safe. + * Provenance: this is the Phase-26 crack (.run/phase26-cracks/func_8015B950.c) re-gated verbatim, + * with ONE deliberate change: the definition's return type void -> s32. + * - `void func_8015B950(s32 arg0)` : MATCH (271 ins) [the Phase-26 form] + * - `s32 func_8015B950(s32 arg0)` : MATCH (271 ins) [shipped — §3a-1 void->s32 is byte-neutral] + * The fleet/engine_core.h canonical decl is `extern s32 func_8015B950(void);` (engine_core.h:1852), + * and the last bank attempt (.run/bank_func_8015B950.log) died on `conflicting types for + * func_8015B950`. Shipping the s32 return kills the §73 RETURN axis for free and leaves only the + * cheap T0 PARAMS axis for the ladder (fix_header_decl.py / --fix-def-sig / cast_call_sites). + * Both forms are byte-identical, so the orchestrator may swap the return type back at zero cost. + * + * SYMBOLS (§58 rules 1/2 — all splat spellings, all verified present): + * D_8018A924 asm/ov_SC01_077/data/tail.data.s:4355 (the state-handler vtable) + * D_8018A8B8 asm/ov_SC01_077/data/tail.data.s:4293 + * D_8011F9C4 main-EXE data; spelled `extern s32 D_8011F9C4;` in 5+ already-banked TUs + * jtbl_801D8B74 asm/ov_SC01_077/data/tail14.data.s:15 (compiler jump table — not named in C) + * + * JTBL VERIFIED (§8a gate): compiled .rodata = exactly 0x1C B / 7 words, 7x R_MIPS_32 .text with + * addends [0x58,0x58,0x58,0xE0,0xF0,0x100,0x58] -> +0x8015B950 = [B9A8,B9A8,B9A8,BA30,BA40,BA50, + * B9A8] == the original words at 0x801D8B74..0x801D8B8C. Bound `sltiu $v0,$v1,0x7` matches. + * The raw dlabel's 8th word 0x00000000 is NOT an entry — it is the intra-TU `.align 3` pad of the + * B34/B54/B74 jtbl chain; the object can never emit it (maspsx drops .align), so it must stay in + * the post-carve RAW data piece (the §53/§62/§81 carve chain applies at bank time). + * + * Same family as the TU's own already-matched func_8015AE2C: 7-case switch on ((s32 (*)(s32))func_801619A4)() + * (0/1/2/6 shared, 3/4/5 own, no default block — out-of-range and every `break` fall to the + * after-switch join), then a chain of "state handler" tests, each dispatching + * D_8018A924[*(u16*)arg0](arg0) and returning. + * + * THREE LEVERS (draft -> MATCH in 3 compiles): + * + * 1. PROLOGUE CONSTANT = an INITIALIZED LOCAL, not a literal in the compare. + * Target opens with `lui $s2, 0xFFF5` in the *prologue*, used once ~200 ins later in + * `slt $v0,$s2,$s1`. No gcc-2.7.2 pass hoists a (set reg const_int) across basic blocks + * (loop.c needs a loop; cse/combine/sched never move insns between BBs) — so the insn must + * have been EMITTED in the first BB, i.e. the constant is a local initialized at the top of + * the function. cse then cannot fold it back into the compare: the `slt` operand predicate is + * `arith_operand`, which rejects a CONST_INT wider than 16 bits, so validate_change fails and + * the pseudo survives. Its live range spans every call -> global.c gives it a callee-saved reg. + * Writing `z > -0xB0000` inline instead emits the `lui` into the branch delay slot next to the + * compare (caller-saved $v0) and the function is 1 insn short. => `s32 lim = -0xB0000;` at top. + * + * 2. `lh` vs `lhu`: a short->short copy is a pure HImode move and gcc emits `lhu`. The target's + * `lh $v0,0x26($s0)` means the value passed through an SImode (int) temp: expand makes + * (set (reg:SI) (sign_extend (mem:HI))) + (set (mem:HI) (subreg:HI ...)), and combine cannot + * merge them (the merged form is mem<-mem, which no movhi accepts) so the sign-extending load + * survives. => route both halfword copies through the `s32 t` temp. + * + * 3. THE `goto` LAYOUT — dodging jump.c's store-flag conversion (jump.c:1005-1065). + * An if/else chain writing 0/1 into `doit` makes gcc collapse the last pair into + * `sltiu $v0,$v0,1`. jump.c fires that conversion when the insn immediately after a + * conditional jump is a lone `SET pseudo, CONST_INT` whose following simplejump targets the + * SAME label as the branch (jump.c:1038 `reallabelprev == temp || ... JUMP_LABEL(temp4) == + * JUMP_LABEL(insn)`) — exactly the shape of `if (c) x=0; else x=1;`. + * The target instead cross-jumps ALL the `doit=0` exits into ONE shared block placed after the + * `doit=1` fall-through; reorg's fill_slots_from_thread then COPIES that single set into all + * three branch delay slots and redirects each branch past it (which is why `addu $v0,$zero, + * $zero` appears 3x in delay slots and the shared block vanishes). A `goto zero;` / `goto one;` + * chain expresses that layout directly, and each conditional jump is then followed by a + * compare/call rather than a lone const set, so the store-flag conversion never triggers. + * GENERAL RULE: multiple predicates that all assign the SAME constant to one flag => write + * them as `goto` to a shared assignment, never as an if/else ladder. + */ +extern s32 D_8011F9C4; +extern s32 D_8018A8B8; + +extern s32 func_80161B18(void); +extern s32 func_801619A4(s32*); +extern s32 func_80149AA8(s32*); +extern void func_80149AD4(s32*); +extern s32 func_80149B54(s32*); +extern void func_80149BAC(s32*); +extern s32 func_801498E0(s32*); +extern s32 func_80149954(s32); +extern s32 func_80149A64(s32*); +extern void func_800CCCC0(s32 a0); +extern s32 func_80149CD4(s32 a0); +extern void func_8015E880(s32*); +extern s32 func_80149744(struct S_80149744*); +extern void func_80149788(void); +extern s32 func_801496D4(void*); +extern void func_80149704(void); +extern int func_80148AFC(void*); +extern void func_80146D90(s32 a0); +extern void func_80154150(s32 a0, s32 a1); +extern void func_801541D8(u8*, s32, s32); +extern s32 func_801488A8(u8*); +extern void func_80147078(s32*, s16); +extern void func_8015A264(void*); +extern s32 func_80013294(void*, void*); +extern void func_80159B70(void*); +extern s32 func_8016F1AC(void); +extern s32 func_80029178(s32 a0); +extern void func_80146DB8(s32*, s32*); +extern s32 func_80161CD0(s32, s32); +extern s32 func_80161208(s32 a0); +extern s32 func_801725A4(u8*); + +s32 func_8015B950(s32 arg0) +{ + + extern void (*D_8018A924[])(void *); + s16 sp10[4]; + s16 sp18[4]; + s32 t; + s32 z; + s32 doit; + s32 lim = -0xB0000; + + if (func_80161B18() != 0) { + return; + } + switch (((s32 (*)(s32))func_801619A4)(arg0)) { + case 0: + case 1: + case 2: + case 6: + if (((s32 (*)(s32))func_80149AA8)(arg0) != 0) { + D_8018A924[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149AD4)(arg0); + return; + } + if (((s32 (*)(s32))func_80149B54)(arg0) != 0) { + D_8018A924[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149BAC)(arg0); + return; + } + break; + case 3: + ((void (*)(s32))func_801498E0)(arg0); + break; + case 4: + ((void (*)(s32))func_80149954)(arg0); + break; + case 5: + if (((s32 (*)(s32))func_80149A64)(arg0) != 0) { + D_8018A924[*(u16 *)arg0]((void *)arg0); + func_800CCCC0(arg0); + return; + } + break; + } + if (func_80149CD4(arg0) != 0) { + D_8018A924[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_8015E880)(arg0); + return; + } + if (((s32 (*)(s32))func_80149744)(arg0) != 0) { + D_8018A924[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149788)(arg0); + return; + } + if (((s32 (*)(s32))func_801496D4)(arg0) != 0) { + D_8018A924[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149704)(arg0); + if (((u8)((s32 (*)(s32))func_80148AFC)(arg0)) == 0) { + func_80146D90(arg0); + } + if ((*(s32 *)(arg0 + 0x24) | *(s32 *)(arg0 + 0x2C)) != 0) { + func_80154150(arg0, 0xF); + } else { + ((void (*)(s32, s32, s32))func_801541D8)(arg0, 0xD, 6); + } + *(s32 *)(arg0 + 0x238) = 1; + return; + } + if (((s32 (*)(s32))func_801488A8)(arg0) != 0) { + sp10[0] = 0; + sp10[1] = 0; + sp10[2] = 0; + t = *(s16 *)(arg0 + 0x26); + sp18[0] = t; + sp18[1] = 0; + t = *(s16 *)(arg0 + 0x2E); + sp18[2] = t; + D_8018A924[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 1); + ((void (*)(s32))func_8015A264)(arg0); + t = -(((s32 (*)(s16 *, s16 *))func_80013294)(sp10, sp18) << 0x10); + if (t < *(s32 *)(arg0 + 0x2C)) { + *(s32 *)(arg0 + 0x2C) = t; + } + return; + } + if (*(u16 *)(arg0 + 0xB8) == 0x8000) { + D_8018A924[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 0); + ((void (*)(s32))func_80159B70)(arg0); + return; + } + z = *(s32 *)(arg0 + 0x2C); + if (func_8016F1AC() != 0) { + goto zero; + } + if (z <= lim) { + goto one; + } + if (D_8011F9C4 == 0) { + goto zero; + } + if (((u8)func_80029178(0x21)) != 0) { + goto zero; + } +one: + doit = 1; + goto join; +zero: + doit = 0; +join: + if (doit != 0) { + D_8018A924[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 0); + ((void (*)(s32))func_80159B70)(arg0); + func_80154150(arg0, 9); + ((void (*)(s32, s32 *))func_80146DB8)(arg0, &D_8018A8B8); + ((void (*)(s32, s32))func_80161CD0)(arg0, *(u16 *)(arg0 + 0x16E)); + return; + } + if (func_80161208(arg0) == 0) { + ((void (*)(s32))func_801725A4)(arg0); + } +} DEFINE_func_8015BD8C() /* dedup: shared engine-core @0x8015BD8C (src/shared) */ diff --git a/src/ov_SC06_006/ov_SC06_006_jr_8015AE2C.c b/src/ov_SC06_006/ov_SC06_006_jr_8015AE2C.c index 015346fc0..c21938f9f 100644 --- a/src/ov_SC06_006/ov_SC06_006_jr_8015AE2C.c +++ b/src/ov_SC06_006/ov_SC06_006_jr_8015AE2C.c @@ -1512,7 +1512,259 @@ DEFINE_func_8015B858() /* dedup: shared engine-core @0x8015B858 (src/shared) */ DEFINE_func_8015B8F8() /* dedup: shared engine-core @0x8015B8F8 (src/shared) */ -INCLUDE_ASM("asm/ov_SC06_006/nonmatchings/ov_SC06_006_jr_8015AE2C", func_8015B950); +extern s32 func_8015AE2C(); + +// @class: plumbing +// @stuck: none — MATCH (271/271, pin-free, zero asm). The ONLY residual is DEF-SIDE plumbing, and it is now named exactly: the in-TU instantiation `DEFINE_func_8015BEE4()` (engine_core.h:1851-1855) expands to `extern s32 func_8015B950(void);` INSIDE ov_SC01_077_jr_8015AE2C.c, ~14 lines BELOW this definition, so the 1-param def collides with a `(void)` prototype -> `conflicting types for func_8015B950` (.run/bank_func_8015B950.log). §73 PARAMS axis / T0. Surgical fix = §65b de-macroize that ONE instantiation (blast radius: this TU); the fleet-wide `(void)`->`()` header edit is §63 and must be R22-validated. +/* func_8015B950 (ov_SC01_077_jr_8015AE2C, 271 ins, jtbl_801D8B74) — SESSION-21 re-verified + * + * ── ROUND-2 INDEPENDENT RE-VERIFICATION (2026-07-27, fresh agent, §88e discipline) ───────────── + * match_one : MATCH (271 ins) against the CURRENT tree — §87 staleness re-checked today. + * .text size: compiled .text = 0x43C = 1084 B = 271 ins, EXACTLY the target's declared 0x43C + * ("nonmatching func_8015B950, 0x43C"). So this is NOT a §83a length drift hiding + * behind a zero count — the count is over equal-length streams. + * jtbl : RE-DECODED MECHANICALLY, not inherited. Compiled .rodata = 0x1C = 28 B = 7 words, + * 7x R_MIPS_32 -> .text with implicit addends [58,58,58,E0,F0,100,58]; +0x8015B950 + * = [8015B9A8, 8015B9A8, 8015B9A8, 8015BA30, 8015BA40, 8015BA50, 8015B9A8]. + * Diffed word-for-word against asm/ov_SC01_077/data/tail14.data.s:15-23 — 7/7 identical. + * symcheck : SYMS-DIFF target=35 draft=34, sole MISSING = jtbl_801D8B74. This is the §81 jr + * FALSE POSITIVE, re-confirmed here by reading the relocs: gcc emits its OWN table and + * references it with R_MIPS_HI16/LO16 against the SECTION `.rodata` (t.o +0x40/+0x48), + * so the splat's dlabel NAME can never appear in the draft object's relocation set. + * Nothing is dropped and nothing is invented: the draft's other 34 symbols are exactly + * the target's other 34. + * FAMILY : the x138 remap is clean and §84-safe. Every sibling is 271 ins with an IDENTICAL + * callee set; only THREE names vary per overlay — the two data labels and the jtbl: + * ov_SC01_077 D_801843DC / D_80184448 / jtbl_801D8B74 + * ov_SC03_099 D_80185A50 / D_80185ABC / jtbl_801BD898 + * ov_SC06_008 D_80187E44 / D_80187EB0 / jtbl_801A8734 + * The pair is always +0x6C apart, and NO literal in this draft encodes that distance + * (both labels are referenced by name), so there is no §84 derived-offset hazard. + * D_8011F9C4 is fleet-constant (main-EXE data) and must NOT be remapped. + * + * match_one: MATCH (271 ins) against the CURRENT tree (§87 staleness re-checked, 2026-07-27). + * PIN-FREE, zero asm, offset-pure (s32 arg0 + raw offsets) — x138 template-safe. + * Provenance: this is the Phase-26 crack (.run/phase26-cracks/func_8015B950.c) re-gated verbatim, + * with ONE deliberate change: the definition's return type void -> s32. + * - `void func_8015B950(s32 arg0)` : MATCH (271 ins) [the Phase-26 form] + * - `s32 func_8015B950(s32 arg0)` : MATCH (271 ins) [shipped — §3a-1 void->s32 is byte-neutral] + * The fleet/engine_core.h canonical decl is `extern s32 func_8015B950(void);` (engine_core.h:1852), + * and the last bank attempt (.run/bank_func_8015B950.log) died on `conflicting types for + * func_8015B950`. Shipping the s32 return kills the §73 RETURN axis for free and leaves only the + * cheap T0 PARAMS axis for the ladder (fix_header_decl.py / --fix-def-sig / cast_call_sites). + * Both forms are byte-identical, so the orchestrator may swap the return type back at zero cost. + * + * SYMBOLS (§58 rules 1/2 — all splat spellings, all verified present): + * D_80184448 asm/ov_SC01_077/data/tail.data.s:4355 (the state-handler vtable) + * D_801843DC asm/ov_SC01_077/data/tail.data.s:4293 + * D_8011F9C4 main-EXE data; spelled `extern s32 D_8011F9C4;` in 5+ already-banked TUs + * jtbl_801D8B74 asm/ov_SC01_077/data/tail14.data.s:15 (compiler jump table — not named in C) + * + * JTBL VERIFIED (§8a gate): compiled .rodata = exactly 0x1C B / 7 words, 7x R_MIPS_32 .text with + * addends [0x58,0x58,0x58,0xE0,0xF0,0x100,0x58] -> +0x8015B950 = [B9A8,B9A8,B9A8,BA30,BA40,BA50, + * B9A8] == the original words at 0x801D8B74..0x801D8B8C. Bound `sltiu $v0,$v1,0x7` matches. + * The raw dlabel's 8th word 0x00000000 is NOT an entry — it is the intra-TU `.align 3` pad of the + * B34/B54/B74 jtbl chain; the object can never emit it (maspsx drops .align), so it must stay in + * the post-carve RAW data piece (the §53/§62/§81 carve chain applies at bank time). + * + * Same family as the TU's own already-matched func_8015AE2C: 7-case switch on ((s32 (*)(s32))func_801619A4)() + * (0/1/2/6 shared, 3/4/5 own, no default block — out-of-range and every `break` fall to the + * after-switch join), then a chain of "state handler" tests, each dispatching + * D_80184448[*(u16*)arg0](arg0) and returning. + * + * THREE LEVERS (draft -> MATCH in 3 compiles): + * + * 1. PROLOGUE CONSTANT = an INITIALIZED LOCAL, not a literal in the compare. + * Target opens with `lui $s2, 0xFFF5` in the *prologue*, used once ~200 ins later in + * `slt $v0,$s2,$s1`. No gcc-2.7.2 pass hoists a (set reg const_int) across basic blocks + * (loop.c needs a loop; cse/combine/sched never move insns between BBs) — so the insn must + * have been EMITTED in the first BB, i.e. the constant is a local initialized at the top of + * the function. cse then cannot fold it back into the compare: the `slt` operand predicate is + * `arith_operand`, which rejects a CONST_INT wider than 16 bits, so validate_change fails and + * the pseudo survives. Its live range spans every call -> global.c gives it a callee-saved reg. + * Writing `z > -0xB0000` inline instead emits the `lui` into the branch delay slot next to the + * compare (caller-saved $v0) and the function is 1 insn short. => `s32 lim = -0xB0000;` at top. + * + * 2. `lh` vs `lhu`: a short->short copy is a pure HImode move and gcc emits `lhu`. The target's + * `lh $v0,0x26($s0)` means the value passed through an SImode (int) temp: expand makes + * (set (reg:SI) (sign_extend (mem:HI))) + (set (mem:HI) (subreg:HI ...)), and combine cannot + * merge them (the merged form is mem<-mem, which no movhi accepts) so the sign-extending load + * survives. => route both halfword copies through the `s32 t` temp. + * + * 3. THE `goto` LAYOUT — dodging jump.c's store-flag conversion (jump.c:1005-1065). + * An if/else chain writing 0/1 into `doit` makes gcc collapse the last pair into + * `sltiu $v0,$v0,1`. jump.c fires that conversion when the insn immediately after a + * conditional jump is a lone `SET pseudo, CONST_INT` whose following simplejump targets the + * SAME label as the branch (jump.c:1038 `reallabelprev == temp || ... JUMP_LABEL(temp4) == + * JUMP_LABEL(insn)`) — exactly the shape of `if (c) x=0; else x=1;`. + * The target instead cross-jumps ALL the `doit=0` exits into ONE shared block placed after the + * `doit=1` fall-through; reorg's fill_slots_from_thread then COPIES that single set into all + * three branch delay slots and redirects each branch past it (which is why `addu $v0,$zero, + * $zero` appears 3x in delay slots and the shared block vanishes). A `goto zero;` / `goto one;` + * chain expresses that layout directly, and each conditional jump is then followed by a + * compare/call rather than a lone const set, so the store-flag conversion never triggers. + * GENERAL RULE: multiple predicates that all assign the SAME constant to one flag => write + * them as `goto` to a shared assignment, never as an if/else ladder. + */ +extern s32 D_8011F9C4; +extern s32 D_801843DC; + +extern s32 func_80161B18(void); +extern s32 func_801619A4(s32*); +extern s32 func_80149AA8(s32*); +extern void func_80149AD4(s32*); +extern s32 func_80149B54(s32*); +extern void func_80149BAC(s32*); +extern s32 func_801498E0(s32*); +extern s32 func_80149954(s32); +extern s32 func_80149A64(s32*); +extern void func_800CCCC0(s32 a0); +extern s32 func_80149CD4(s32 a0); +extern void func_8015E880(s32*); +extern s32 func_80149744(struct S_80149744*); +extern void func_80149788(void); +extern s32 func_801496D4(void*); +extern void func_80149704(void); +extern int func_80148AFC(void*); +extern void func_80146D90(s32 a0); +extern void func_80154150(s32 a0, s32 a1); +extern void func_801541D8(u8*, s32, s32); +extern s32 func_801488A8(u8*); +extern void func_80147078(s32*, s16); +extern void func_8015A264(void*); +extern s32 func_80013294(void*, void*); +extern void func_80159B70(void*); +extern s32 func_8016F1AC(void); +extern s32 func_80029178(s32 a0); +extern void func_80146DB8(s32*, s32*); +extern s32 func_80161CD0(s32, s32); +extern s32 func_80161208(s32 a0); +extern s32 func_801725A4(u8*); + +s32 func_8015B950(s32 arg0) +{ + + extern void (*D_80184448[])(void *); + s16 sp10[4]; + s16 sp18[4]; + s32 t; + s32 z; + s32 doit; + s32 lim = -0xB0000; + + if (func_80161B18() != 0) { + return; + } + switch (((s32 (*)(s32))func_801619A4)(arg0)) { + case 0: + case 1: + case 2: + case 6: + if (((s32 (*)(s32))func_80149AA8)(arg0) != 0) { + D_80184448[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149AD4)(arg0); + return; + } + if (((s32 (*)(s32))func_80149B54)(arg0) != 0) { + D_80184448[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149BAC)(arg0); + return; + } + break; + case 3: + ((void (*)(s32))func_801498E0)(arg0); + break; + case 4: + ((void (*)(s32))func_80149954)(arg0); + break; + case 5: + if (((s32 (*)(s32))func_80149A64)(arg0) != 0) { + D_80184448[*(u16 *)arg0]((void *)arg0); + func_800CCCC0(arg0); + return; + } + break; + } + if (func_80149CD4(arg0) != 0) { + D_80184448[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_8015E880)(arg0); + return; + } + if (((s32 (*)(s32))func_80149744)(arg0) != 0) { + D_80184448[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149788)(arg0); + return; + } + if (((s32 (*)(s32))func_801496D4)(arg0) != 0) { + D_80184448[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149704)(arg0); + if (((u8)((s32 (*)(s32))func_80148AFC)(arg0)) == 0) { + func_80146D90(arg0); + } + if ((*(s32 *)(arg0 + 0x24) | *(s32 *)(arg0 + 0x2C)) != 0) { + func_80154150(arg0, 0xF); + } else { + ((void (*)(s32, s32, s32))func_801541D8)(arg0, 0xD, 6); + } + *(s32 *)(arg0 + 0x238) = 1; + return; + } + if (((s32 (*)(s32))func_801488A8)(arg0) != 0) { + sp10[0] = 0; + sp10[1] = 0; + sp10[2] = 0; + t = *(s16 *)(arg0 + 0x26); + sp18[0] = t; + sp18[1] = 0; + t = *(s16 *)(arg0 + 0x2E); + sp18[2] = t; + D_80184448[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 1); + ((void (*)(s32))func_8015A264)(arg0); + t = -(((s32 (*)(s16 *, s16 *))func_80013294)(sp10, sp18) << 0x10); + if (t < *(s32 *)(arg0 + 0x2C)) { + *(s32 *)(arg0 + 0x2C) = t; + } + return; + } + if (*(u16 *)(arg0 + 0xB8) == 0x8000) { + D_80184448[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 0); + ((void (*)(s32))func_80159B70)(arg0); + return; + } + z = *(s32 *)(arg0 + 0x2C); + if (func_8016F1AC() != 0) { + goto zero; + } + if (z <= lim) { + goto one; + } + if (D_8011F9C4 == 0) { + goto zero; + } + if (((u8)func_80029178(0x21)) != 0) { + goto zero; + } +one: + doit = 1; + goto join; +zero: + doit = 0; +join: + if (doit != 0) { + D_80184448[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 0); + ((void (*)(s32))func_80159B70)(arg0); + func_80154150(arg0, 9); + ((void (*)(s32, s32 *))func_80146DB8)(arg0, &D_801843DC); + ((void (*)(s32, s32))func_80161CD0)(arg0, *(u16 *)(arg0 + 0x16E)); + return; + } + if (func_80161208(arg0) == 0) { + ((void (*)(s32))func_801725A4)(arg0); + } +} DEFINE_func_8015BD8C() /* dedup: shared engine-core @0x8015BD8C (src/shared) */ diff --git a/src/ov_SC06_008/ov_SC06_008_jr_8015AE2C.c b/src/ov_SC06_008/ov_SC06_008_jr_8015AE2C.c index c71c97f6b..18c245a28 100644 --- a/src/ov_SC06_008/ov_SC06_008_jr_8015AE2C.c +++ b/src/ov_SC06_008/ov_SC06_008_jr_8015AE2C.c @@ -1512,7 +1512,259 @@ DEFINE_func_8015B858() /* dedup: shared engine-core @0x8015B858 (src/shared) */ DEFINE_func_8015B8F8() /* dedup: shared engine-core @0x8015B8F8 (src/shared) */ -INCLUDE_ASM("asm/ov_SC06_008/nonmatchings/ov_SC06_008_jr_8015AE2C", func_8015B950); +extern s32 func_8015AE2C(); + +// @class: plumbing +// @stuck: none — MATCH (271/271, pin-free, zero asm). The ONLY residual is DEF-SIDE plumbing, and it is now named exactly: the in-TU instantiation `DEFINE_func_8015BEE4()` (engine_core.h:1851-1855) expands to `extern s32 func_8015B950(void);` INSIDE ov_SC01_077_jr_8015AE2C.c, ~14 lines BELOW this definition, so the 1-param def collides with a `(void)` prototype -> `conflicting types for func_8015B950` (.run/bank_func_8015B950.log). §73 PARAMS axis / T0. Surgical fix = §65b de-macroize that ONE instantiation (blast radius: this TU); the fleet-wide `(void)`->`()` header edit is §63 and must be R22-validated. +/* func_8015B950 (ov_SC01_077_jr_8015AE2C, 271 ins, jtbl_801D8B74) — SESSION-21 re-verified + * + * ── ROUND-2 INDEPENDENT RE-VERIFICATION (2026-07-27, fresh agent, §88e discipline) ───────────── + * match_one : MATCH (271 ins) against the CURRENT tree — §87 staleness re-checked today. + * .text size: compiled .text = 0x43C = 1084 B = 271 ins, EXACTLY the target's declared 0x43C + * ("nonmatching func_8015B950, 0x43C"). So this is NOT a §83a length drift hiding + * behind a zero count — the count is over equal-length streams. + * jtbl : RE-DECODED MECHANICALLY, not inherited. Compiled .rodata = 0x1C = 28 B = 7 words, + * 7x R_MIPS_32 -> .text with implicit addends [58,58,58,E0,F0,100,58]; +0x8015B950 + * = [8015B9A8, 8015B9A8, 8015B9A8, 8015BA30, 8015BA40, 8015BA50, 8015B9A8]. + * Diffed word-for-word against asm/ov_SC01_077/data/tail14.data.s:15-23 — 7/7 identical. + * symcheck : SYMS-DIFF target=35 draft=34, sole MISSING = jtbl_801D8B74. This is the §81 jr + * FALSE POSITIVE, re-confirmed here by reading the relocs: gcc emits its OWN table and + * references it with R_MIPS_HI16/LO16 against the SECTION `.rodata` (t.o +0x40/+0x48), + * so the splat's dlabel NAME can never appear in the draft object's relocation set. + * Nothing is dropped and nothing is invented: the draft's other 34 symbols are exactly + * the target's other 34. + * FAMILY : the x138 remap is clean and §84-safe. Every sibling is 271 ins with an IDENTICAL + * callee set; only THREE names vary per overlay — the two data labels and the jtbl: + * ov_SC01_077 D_80187E44 / D_80187EB0 / jtbl_801D8B74 + * ov_SC03_099 D_80185A50 / D_80185ABC / jtbl_801BD898 + * ov_SC06_008 D_80187E44 / D_80187EB0 / jtbl_801A8734 + * The pair is always +0x6C apart, and NO literal in this draft encodes that distance + * (both labels are referenced by name), so there is no §84 derived-offset hazard. + * D_8011F9C4 is fleet-constant (main-EXE data) and must NOT be remapped. + * + * match_one: MATCH (271 ins) against the CURRENT tree (§87 staleness re-checked, 2026-07-27). + * PIN-FREE, zero asm, offset-pure (s32 arg0 + raw offsets) — x138 template-safe. + * Provenance: this is the Phase-26 crack (.run/phase26-cracks/func_8015B950.c) re-gated verbatim, + * with ONE deliberate change: the definition's return type void -> s32. + * - `void func_8015B950(s32 arg0)` : MATCH (271 ins) [the Phase-26 form] + * - `s32 func_8015B950(s32 arg0)` : MATCH (271 ins) [shipped — §3a-1 void->s32 is byte-neutral] + * The fleet/engine_core.h canonical decl is `extern s32 func_8015B950(void);` (engine_core.h:1852), + * and the last bank attempt (.run/bank_func_8015B950.log) died on `conflicting types for + * func_8015B950`. Shipping the s32 return kills the §73 RETURN axis for free and leaves only the + * cheap T0 PARAMS axis for the ladder (fix_header_decl.py / --fix-def-sig / cast_call_sites). + * Both forms are byte-identical, so the orchestrator may swap the return type back at zero cost. + * + * SYMBOLS (§58 rules 1/2 — all splat spellings, all verified present): + * D_80187EB0 asm/ov_SC01_077/data/tail.data.s:4355 (the state-handler vtable) + * D_80187E44 asm/ov_SC01_077/data/tail.data.s:4293 + * D_8011F9C4 main-EXE data; spelled `extern s32 D_8011F9C4;` in 5+ already-banked TUs + * jtbl_801D8B74 asm/ov_SC01_077/data/tail14.data.s:15 (compiler jump table — not named in C) + * + * JTBL VERIFIED (§8a gate): compiled .rodata = exactly 0x1C B / 7 words, 7x R_MIPS_32 .text with + * addends [0x58,0x58,0x58,0xE0,0xF0,0x100,0x58] -> +0x8015B950 = [B9A8,B9A8,B9A8,BA30,BA40,BA50, + * B9A8] == the original words at 0x801D8B74..0x801D8B8C. Bound `sltiu $v0,$v1,0x7` matches. + * The raw dlabel's 8th word 0x00000000 is NOT an entry — it is the intra-TU `.align 3` pad of the + * B34/B54/B74 jtbl chain; the object can never emit it (maspsx drops .align), so it must stay in + * the post-carve RAW data piece (the §53/§62/§81 carve chain applies at bank time). + * + * Same family as the TU's own already-matched func_8015AE2C: 7-case switch on ((s32 (*)(s32))func_801619A4)() + * (0/1/2/6 shared, 3/4/5 own, no default block — out-of-range and every `break` fall to the + * after-switch join), then a chain of "state handler" tests, each dispatching + * D_80187EB0[*(u16*)arg0](arg0) and returning. + * + * THREE LEVERS (draft -> MATCH in 3 compiles): + * + * 1. PROLOGUE CONSTANT = an INITIALIZED LOCAL, not a literal in the compare. + * Target opens with `lui $s2, 0xFFF5` in the *prologue*, used once ~200 ins later in + * `slt $v0,$s2,$s1`. No gcc-2.7.2 pass hoists a (set reg const_int) across basic blocks + * (loop.c needs a loop; cse/combine/sched never move insns between BBs) — so the insn must + * have been EMITTED in the first BB, i.e. the constant is a local initialized at the top of + * the function. cse then cannot fold it back into the compare: the `slt` operand predicate is + * `arith_operand`, which rejects a CONST_INT wider than 16 bits, so validate_change fails and + * the pseudo survives. Its live range spans every call -> global.c gives it a callee-saved reg. + * Writing `z > -0xB0000` inline instead emits the `lui` into the branch delay slot next to the + * compare (caller-saved $v0) and the function is 1 insn short. => `s32 lim = -0xB0000;` at top. + * + * 2. `lh` vs `lhu`: a short->short copy is a pure HImode move and gcc emits `lhu`. The target's + * `lh $v0,0x26($s0)` means the value passed through an SImode (int) temp: expand makes + * (set (reg:SI) (sign_extend (mem:HI))) + (set (mem:HI) (subreg:HI ...)), and combine cannot + * merge them (the merged form is mem<-mem, which no movhi accepts) so the sign-extending load + * survives. => route both halfword copies through the `s32 t` temp. + * + * 3. THE `goto` LAYOUT — dodging jump.c's store-flag conversion (jump.c:1005-1065). + * An if/else chain writing 0/1 into `doit` makes gcc collapse the last pair into + * `sltiu $v0,$v0,1`. jump.c fires that conversion when the insn immediately after a + * conditional jump is a lone `SET pseudo, CONST_INT` whose following simplejump targets the + * SAME label as the branch (jump.c:1038 `reallabelprev == temp || ... JUMP_LABEL(temp4) == + * JUMP_LABEL(insn)`) — exactly the shape of `if (c) x=0; else x=1;`. + * The target instead cross-jumps ALL the `doit=0` exits into ONE shared block placed after the + * `doit=1` fall-through; reorg's fill_slots_from_thread then COPIES that single set into all + * three branch delay slots and redirects each branch past it (which is why `addu $v0,$zero, + * $zero` appears 3x in delay slots and the shared block vanishes). A `goto zero;` / `goto one;` + * chain expresses that layout directly, and each conditional jump is then followed by a + * compare/call rather than a lone const set, so the store-flag conversion never triggers. + * GENERAL RULE: multiple predicates that all assign the SAME constant to one flag => write + * them as `goto` to a shared assignment, never as an if/else ladder. + */ +extern s32 D_8011F9C4; +extern s32 D_80187E44; + +extern s32 func_80161B18(void); +extern s32 func_801619A4(s32*); +extern s32 func_80149AA8(s32*); +extern void func_80149AD4(s32*); +extern s32 func_80149B54(s32*); +extern void func_80149BAC(s32*); +extern s32 func_801498E0(s32*); +extern s32 func_80149954(s32); +extern s32 func_80149A64(s32*); +extern void func_800CCCC0(s32 a0); +extern s32 func_80149CD4(s32 a0); +extern void func_8015E880(s32*); +extern s32 func_80149744(struct S_80149744*); +extern void func_80149788(void); +extern s32 func_801496D4(void*); +extern void func_80149704(void); +extern int func_80148AFC(void*); +extern void func_80146D90(s32 a0); +extern void func_80154150(s32 a0, s32 a1); +extern void func_801541D8(u8*, s32, s32); +extern s32 func_801488A8(u8*); +extern void func_80147078(s32*, s16); +extern void func_8015A264(void*); +extern s32 func_80013294(void*, void*); +extern void func_80159B70(void*); +extern s32 func_8016F1AC(void); +extern s32 func_80029178(s32 a0); +extern void func_80146DB8(s32*, s32*); +extern s32 func_80161CD0(s32, s32); +extern s32 func_80161208(s32 a0); +extern s32 func_801725A4(u8*); + +s32 func_8015B950(s32 arg0) +{ + + extern void (*D_80187EB0[])(void *); + s16 sp10[4]; + s16 sp18[4]; + s32 t; + s32 z; + s32 doit; + s32 lim = -0xB0000; + + if (func_80161B18() != 0) { + return; + } + switch (((s32 (*)(s32))func_801619A4)(arg0)) { + case 0: + case 1: + case 2: + case 6: + if (((s32 (*)(s32))func_80149AA8)(arg0) != 0) { + D_80187EB0[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149AD4)(arg0); + return; + } + if (((s32 (*)(s32))func_80149B54)(arg0) != 0) { + D_80187EB0[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149BAC)(arg0); + return; + } + break; + case 3: + ((void (*)(s32))func_801498E0)(arg0); + break; + case 4: + ((void (*)(s32))func_80149954)(arg0); + break; + case 5: + if (((s32 (*)(s32))func_80149A64)(arg0) != 0) { + D_80187EB0[*(u16 *)arg0]((void *)arg0); + func_800CCCC0(arg0); + return; + } + break; + } + if (func_80149CD4(arg0) != 0) { + D_80187EB0[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_8015E880)(arg0); + return; + } + if (((s32 (*)(s32))func_80149744)(arg0) != 0) { + D_80187EB0[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149788)(arg0); + return; + } + if (((s32 (*)(s32))func_801496D4)(arg0) != 0) { + D_80187EB0[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149704)(arg0); + if (((u8)((s32 (*)(s32))func_80148AFC)(arg0)) == 0) { + func_80146D90(arg0); + } + if ((*(s32 *)(arg0 + 0x24) | *(s32 *)(arg0 + 0x2C)) != 0) { + func_80154150(arg0, 0xF); + } else { + ((void (*)(s32, s32, s32))func_801541D8)(arg0, 0xD, 6); + } + *(s32 *)(arg0 + 0x238) = 1; + return; + } + if (((s32 (*)(s32))func_801488A8)(arg0) != 0) { + sp10[0] = 0; + sp10[1] = 0; + sp10[2] = 0; + t = *(s16 *)(arg0 + 0x26); + sp18[0] = t; + sp18[1] = 0; + t = *(s16 *)(arg0 + 0x2E); + sp18[2] = t; + D_80187EB0[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 1); + ((void (*)(s32))func_8015A264)(arg0); + t = -(((s32 (*)(s16 *, s16 *))func_80013294)(sp10, sp18) << 0x10); + if (t < *(s32 *)(arg0 + 0x2C)) { + *(s32 *)(arg0 + 0x2C) = t; + } + return; + } + if (*(u16 *)(arg0 + 0xB8) == 0x8000) { + D_80187EB0[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 0); + ((void (*)(s32))func_80159B70)(arg0); + return; + } + z = *(s32 *)(arg0 + 0x2C); + if (func_8016F1AC() != 0) { + goto zero; + } + if (z <= lim) { + goto one; + } + if (D_8011F9C4 == 0) { + goto zero; + } + if (((u8)func_80029178(0x21)) != 0) { + goto zero; + } +one: + doit = 1; + goto join; +zero: + doit = 0; +join: + if (doit != 0) { + D_80187EB0[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 0); + ((void (*)(s32))func_80159B70)(arg0); + func_80154150(arg0, 9); + ((void (*)(s32, s32 *))func_80146DB8)(arg0, &D_80187E44); + ((void (*)(s32, s32))func_80161CD0)(arg0, *(u16 *)(arg0 + 0x16E)); + return; + } + if (func_80161208(arg0) == 0) { + ((void (*)(s32))func_801725A4)(arg0); + } +} DEFINE_func_8015BD8C() /* dedup: shared engine-core @0x8015BD8C (src/shared) */ diff --git a/src/ov_SC06_010/ov_SC06_010_jr_8015AE2C.c b/src/ov_SC06_010/ov_SC06_010_jr_8015AE2C.c index 1f5214091..e8ef03749 100644 --- a/src/ov_SC06_010/ov_SC06_010_jr_8015AE2C.c +++ b/src/ov_SC06_010/ov_SC06_010_jr_8015AE2C.c @@ -1512,7 +1512,259 @@ DEFINE_func_8015B858() /* dedup: shared engine-core @0x8015B858 (src/shared) */ DEFINE_func_8015B8F8() /* dedup: shared engine-core @0x8015B8F8 (src/shared) */ -INCLUDE_ASM("asm/ov_SC06_010/nonmatchings/ov_SC06_010_jr_8015AE2C", func_8015B950); +extern s32 func_8015AE2C(); + +// @class: plumbing +// @stuck: none — MATCH (271/271, pin-free, zero asm). The ONLY residual is DEF-SIDE plumbing, and it is now named exactly: the in-TU instantiation `DEFINE_func_8015BEE4()` (engine_core.h:1851-1855) expands to `extern s32 func_8015B950(void);` INSIDE ov_SC01_077_jr_8015AE2C.c, ~14 lines BELOW this definition, so the 1-param def collides with a `(void)` prototype -> `conflicting types for func_8015B950` (.run/bank_func_8015B950.log). §73 PARAMS axis / T0. Surgical fix = §65b de-macroize that ONE instantiation (blast radius: this TU); the fleet-wide `(void)`->`()` header edit is §63 and must be R22-validated. +/* func_8015B950 (ov_SC01_077_jr_8015AE2C, 271 ins, jtbl_801D8B74) — SESSION-21 re-verified + * + * ── ROUND-2 INDEPENDENT RE-VERIFICATION (2026-07-27, fresh agent, §88e discipline) ───────────── + * match_one : MATCH (271 ins) against the CURRENT tree — §87 staleness re-checked today. + * .text size: compiled .text = 0x43C = 1084 B = 271 ins, EXACTLY the target's declared 0x43C + * ("nonmatching func_8015B950, 0x43C"). So this is NOT a §83a length drift hiding + * behind a zero count — the count is over equal-length streams. + * jtbl : RE-DECODED MECHANICALLY, not inherited. Compiled .rodata = 0x1C = 28 B = 7 words, + * 7x R_MIPS_32 -> .text with implicit addends [58,58,58,E0,F0,100,58]; +0x8015B950 + * = [8015B9A8, 8015B9A8, 8015B9A8, 8015BA30, 8015BA40, 8015BA50, 8015B9A8]. + * Diffed word-for-word against asm/ov_SC01_077/data/tail14.data.s:15-23 — 7/7 identical. + * symcheck : SYMS-DIFF target=35 draft=34, sole MISSING = jtbl_801D8B74. This is the §81 jr + * FALSE POSITIVE, re-confirmed here by reading the relocs: gcc emits its OWN table and + * references it with R_MIPS_HI16/LO16 against the SECTION `.rodata` (t.o +0x40/+0x48), + * so the splat's dlabel NAME can never appear in the draft object's relocation set. + * Nothing is dropped and nothing is invented: the draft's other 34 symbols are exactly + * the target's other 34. + * FAMILY : the x138 remap is clean and §84-safe. Every sibling is 271 ins with an IDENTICAL + * callee set; only THREE names vary per overlay — the two data labels and the jtbl: + * ov_SC01_077 D_80189020 / D_8018908C / jtbl_801D8B74 + * ov_SC03_099 D_80185A50 / D_80185ABC / jtbl_801BD898 + * ov_SC06_008 D_80187E44 / D_80187EB0 / jtbl_801A8734 + * The pair is always +0x6C apart, and NO literal in this draft encodes that distance + * (both labels are referenced by name), so there is no §84 derived-offset hazard. + * D_8011F9C4 is fleet-constant (main-EXE data) and must NOT be remapped. + * + * match_one: MATCH (271 ins) against the CURRENT tree (§87 staleness re-checked, 2026-07-27). + * PIN-FREE, zero asm, offset-pure (s32 arg0 + raw offsets) — x138 template-safe. + * Provenance: this is the Phase-26 crack (.run/phase26-cracks/func_8015B950.c) re-gated verbatim, + * with ONE deliberate change: the definition's return type void -> s32. + * - `void func_8015B950(s32 arg0)` : MATCH (271 ins) [the Phase-26 form] + * - `s32 func_8015B950(s32 arg0)` : MATCH (271 ins) [shipped — §3a-1 void->s32 is byte-neutral] + * The fleet/engine_core.h canonical decl is `extern s32 func_8015B950(void);` (engine_core.h:1852), + * and the last bank attempt (.run/bank_func_8015B950.log) died on `conflicting types for + * func_8015B950`. Shipping the s32 return kills the §73 RETURN axis for free and leaves only the + * cheap T0 PARAMS axis for the ladder (fix_header_decl.py / --fix-def-sig / cast_call_sites). + * Both forms are byte-identical, so the orchestrator may swap the return type back at zero cost. + * + * SYMBOLS (§58 rules 1/2 — all splat spellings, all verified present): + * D_8018908C asm/ov_SC01_077/data/tail.data.s:4355 (the state-handler vtable) + * D_80189020 asm/ov_SC01_077/data/tail.data.s:4293 + * D_8011F9C4 main-EXE data; spelled `extern s32 D_8011F9C4;` in 5+ already-banked TUs + * jtbl_801D8B74 asm/ov_SC01_077/data/tail14.data.s:15 (compiler jump table — not named in C) + * + * JTBL VERIFIED (§8a gate): compiled .rodata = exactly 0x1C B / 7 words, 7x R_MIPS_32 .text with + * addends [0x58,0x58,0x58,0xE0,0xF0,0x100,0x58] -> +0x8015B950 = [B9A8,B9A8,B9A8,BA30,BA40,BA50, + * B9A8] == the original words at 0x801D8B74..0x801D8B8C. Bound `sltiu $v0,$v1,0x7` matches. + * The raw dlabel's 8th word 0x00000000 is NOT an entry — it is the intra-TU `.align 3` pad of the + * B34/B54/B74 jtbl chain; the object can never emit it (maspsx drops .align), so it must stay in + * the post-carve RAW data piece (the §53/§62/§81 carve chain applies at bank time). + * + * Same family as the TU's own already-matched func_8015AE2C: 7-case switch on ((s32 (*)(s32))func_801619A4)() + * (0/1/2/6 shared, 3/4/5 own, no default block — out-of-range and every `break` fall to the + * after-switch join), then a chain of "state handler" tests, each dispatching + * D_8018908C[*(u16*)arg0](arg0) and returning. + * + * THREE LEVERS (draft -> MATCH in 3 compiles): + * + * 1. PROLOGUE CONSTANT = an INITIALIZED LOCAL, not a literal in the compare. + * Target opens with `lui $s2, 0xFFF5` in the *prologue*, used once ~200 ins later in + * `slt $v0,$s2,$s1`. No gcc-2.7.2 pass hoists a (set reg const_int) across basic blocks + * (loop.c needs a loop; cse/combine/sched never move insns between BBs) — so the insn must + * have been EMITTED in the first BB, i.e. the constant is a local initialized at the top of + * the function. cse then cannot fold it back into the compare: the `slt` operand predicate is + * `arith_operand`, which rejects a CONST_INT wider than 16 bits, so validate_change fails and + * the pseudo survives. Its live range spans every call -> global.c gives it a callee-saved reg. + * Writing `z > -0xB0000` inline instead emits the `lui` into the branch delay slot next to the + * compare (caller-saved $v0) and the function is 1 insn short. => `s32 lim = -0xB0000;` at top. + * + * 2. `lh` vs `lhu`: a short->short copy is a pure HImode move and gcc emits `lhu`. The target's + * `lh $v0,0x26($s0)` means the value passed through an SImode (int) temp: expand makes + * (set (reg:SI) (sign_extend (mem:HI))) + (set (mem:HI) (subreg:HI ...)), and combine cannot + * merge them (the merged form is mem<-mem, which no movhi accepts) so the sign-extending load + * survives. => route both halfword copies through the `s32 t` temp. + * + * 3. THE `goto` LAYOUT — dodging jump.c's store-flag conversion (jump.c:1005-1065). + * An if/else chain writing 0/1 into `doit` makes gcc collapse the last pair into + * `sltiu $v0,$v0,1`. jump.c fires that conversion when the insn immediately after a + * conditional jump is a lone `SET pseudo, CONST_INT` whose following simplejump targets the + * SAME label as the branch (jump.c:1038 `reallabelprev == temp || ... JUMP_LABEL(temp4) == + * JUMP_LABEL(insn)`) — exactly the shape of `if (c) x=0; else x=1;`. + * The target instead cross-jumps ALL the `doit=0` exits into ONE shared block placed after the + * `doit=1` fall-through; reorg's fill_slots_from_thread then COPIES that single set into all + * three branch delay slots and redirects each branch past it (which is why `addu $v0,$zero, + * $zero` appears 3x in delay slots and the shared block vanishes). A `goto zero;` / `goto one;` + * chain expresses that layout directly, and each conditional jump is then followed by a + * compare/call rather than a lone const set, so the store-flag conversion never triggers. + * GENERAL RULE: multiple predicates that all assign the SAME constant to one flag => write + * them as `goto` to a shared assignment, never as an if/else ladder. + */ +extern s32 D_8011F9C4; +extern s32 D_80189020; + +extern s32 func_80161B18(void); +extern s32 func_801619A4(s32*); +extern s32 func_80149AA8(s32*); +extern void func_80149AD4(s32*); +extern s32 func_80149B54(s32*); +extern void func_80149BAC(s32*); +extern s32 func_801498E0(s32*); +extern s32 func_80149954(s32); +extern s32 func_80149A64(s32*); +extern void func_800CCCC0(s32 a0); +extern s32 func_80149CD4(s32 a0); +extern void func_8015E880(s32*); +extern s32 func_80149744(struct S_80149744*); +extern void func_80149788(void); +extern s32 func_801496D4(void*); +extern void func_80149704(void); +extern int func_80148AFC(void*); +extern void func_80146D90(s32 a0); +extern void func_80154150(s32 a0, s32 a1); +extern void func_801541D8(u8*, s32, s32); +extern s32 func_801488A8(u8*); +extern void func_80147078(s32*, s16); +extern void func_8015A264(void*); +extern s32 func_80013294(void*, void*); +extern void func_80159B70(void*); +extern s32 func_8016F1AC(void); +extern s32 func_80029178(s32 a0); +extern void func_80146DB8(s32*, s32*); +extern s32 func_80161CD0(s32, s32); +extern s32 func_80161208(s32 a0); +extern s32 func_801725A4(u8*); + +s32 func_8015B950(s32 arg0) +{ + + extern void (*D_8018908C[])(void *); + s16 sp10[4]; + s16 sp18[4]; + s32 t; + s32 z; + s32 doit; + s32 lim = -0xB0000; + + if (func_80161B18() != 0) { + return; + } + switch (((s32 (*)(s32))func_801619A4)(arg0)) { + case 0: + case 1: + case 2: + case 6: + if (((s32 (*)(s32))func_80149AA8)(arg0) != 0) { + D_8018908C[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149AD4)(arg0); + return; + } + if (((s32 (*)(s32))func_80149B54)(arg0) != 0) { + D_8018908C[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149BAC)(arg0); + return; + } + break; + case 3: + ((void (*)(s32))func_801498E0)(arg0); + break; + case 4: + ((void (*)(s32))func_80149954)(arg0); + break; + case 5: + if (((s32 (*)(s32))func_80149A64)(arg0) != 0) { + D_8018908C[*(u16 *)arg0]((void *)arg0); + func_800CCCC0(arg0); + return; + } + break; + } + if (func_80149CD4(arg0) != 0) { + D_8018908C[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_8015E880)(arg0); + return; + } + if (((s32 (*)(s32))func_80149744)(arg0) != 0) { + D_8018908C[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149788)(arg0); + return; + } + if (((s32 (*)(s32))func_801496D4)(arg0) != 0) { + D_8018908C[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149704)(arg0); + if (((u8)((s32 (*)(s32))func_80148AFC)(arg0)) == 0) { + func_80146D90(arg0); + } + if ((*(s32 *)(arg0 + 0x24) | *(s32 *)(arg0 + 0x2C)) != 0) { + func_80154150(arg0, 0xF); + } else { + ((void (*)(s32, s32, s32))func_801541D8)(arg0, 0xD, 6); + } + *(s32 *)(arg0 + 0x238) = 1; + return; + } + if (((s32 (*)(s32))func_801488A8)(arg0) != 0) { + sp10[0] = 0; + sp10[1] = 0; + sp10[2] = 0; + t = *(s16 *)(arg0 + 0x26); + sp18[0] = t; + sp18[1] = 0; + t = *(s16 *)(arg0 + 0x2E); + sp18[2] = t; + D_8018908C[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 1); + ((void (*)(s32))func_8015A264)(arg0); + t = -(((s32 (*)(s16 *, s16 *))func_80013294)(sp10, sp18) << 0x10); + if (t < *(s32 *)(arg0 + 0x2C)) { + *(s32 *)(arg0 + 0x2C) = t; + } + return; + } + if (*(u16 *)(arg0 + 0xB8) == 0x8000) { + D_8018908C[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 0); + ((void (*)(s32))func_80159B70)(arg0); + return; + } + z = *(s32 *)(arg0 + 0x2C); + if (func_8016F1AC() != 0) { + goto zero; + } + if (z <= lim) { + goto one; + } + if (D_8011F9C4 == 0) { + goto zero; + } + if (((u8)func_80029178(0x21)) != 0) { + goto zero; + } +one: + doit = 1; + goto join; +zero: + doit = 0; +join: + if (doit != 0) { + D_8018908C[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 0); + ((void (*)(s32))func_80159B70)(arg0); + func_80154150(arg0, 9); + ((void (*)(s32, s32 *))func_80146DB8)(arg0, &D_80189020); + ((void (*)(s32, s32))func_80161CD0)(arg0, *(u16 *)(arg0 + 0x16E)); + return; + } + if (func_80161208(arg0) == 0) { + ((void (*)(s32))func_801725A4)(arg0); + } +} DEFINE_func_8015BD8C() /* dedup: shared engine-core @0x8015BD8C (src/shared) */ diff --git a/src/ov_SC06_011/ov_SC06_011_jr_8015AE2C.c b/src/ov_SC06_011/ov_SC06_011_jr_8015AE2C.c index 3d39d2470..4286a696d 100644 --- a/src/ov_SC06_011/ov_SC06_011_jr_8015AE2C.c +++ b/src/ov_SC06_011/ov_SC06_011_jr_8015AE2C.c @@ -1512,7 +1512,259 @@ DEFINE_func_8015B858() /* dedup: shared engine-core @0x8015B858 (src/shared) */ DEFINE_func_8015B8F8() /* dedup: shared engine-core @0x8015B8F8 (src/shared) */ -INCLUDE_ASM("asm/ov_SC06_011/nonmatchings/ov_SC06_011_jr_8015AE2C", func_8015B950); +extern s32 func_8015AE2C(); + +// @class: plumbing +// @stuck: none — MATCH (271/271, pin-free, zero asm). The ONLY residual is DEF-SIDE plumbing, and it is now named exactly: the in-TU instantiation `DEFINE_func_8015BEE4()` (engine_core.h:1851-1855) expands to `extern s32 func_8015B950(void);` INSIDE ov_SC01_077_jr_8015AE2C.c, ~14 lines BELOW this definition, so the 1-param def collides with a `(void)` prototype -> `conflicting types for func_8015B950` (.run/bank_func_8015B950.log). §73 PARAMS axis / T0. Surgical fix = §65b de-macroize that ONE instantiation (blast radius: this TU); the fleet-wide `(void)`->`()` header edit is §63 and must be R22-validated. +/* func_8015B950 (ov_SC01_077_jr_8015AE2C, 271 ins, jtbl_801D8B74) — SESSION-21 re-verified + * + * ── ROUND-2 INDEPENDENT RE-VERIFICATION (2026-07-27, fresh agent, §88e discipline) ───────────── + * match_one : MATCH (271 ins) against the CURRENT tree — §87 staleness re-checked today. + * .text size: compiled .text = 0x43C = 1084 B = 271 ins, EXACTLY the target's declared 0x43C + * ("nonmatching func_8015B950, 0x43C"). So this is NOT a §83a length drift hiding + * behind a zero count — the count is over equal-length streams. + * jtbl : RE-DECODED MECHANICALLY, not inherited. Compiled .rodata = 0x1C = 28 B = 7 words, + * 7x R_MIPS_32 -> .text with implicit addends [58,58,58,E0,F0,100,58]; +0x8015B950 + * = [8015B9A8, 8015B9A8, 8015B9A8, 8015BA30, 8015BA40, 8015BA50, 8015B9A8]. + * Diffed word-for-word against asm/ov_SC01_077/data/tail14.data.s:15-23 — 7/7 identical. + * symcheck : SYMS-DIFF target=35 draft=34, sole MISSING = jtbl_801D8B74. This is the §81 jr + * FALSE POSITIVE, re-confirmed here by reading the relocs: gcc emits its OWN table and + * references it with R_MIPS_HI16/LO16 against the SECTION `.rodata` (t.o +0x40/+0x48), + * so the splat's dlabel NAME can never appear in the draft object's relocation set. + * Nothing is dropped and nothing is invented: the draft's other 34 symbols are exactly + * the target's other 34. + * FAMILY : the x138 remap is clean and §84-safe. Every sibling is 271 ins with an IDENTICAL + * callee set; only THREE names vary per overlay — the two data labels and the jtbl: + * ov_SC01_077 D_80182A80 / D_80182AEC / jtbl_801D8B74 + * ov_SC03_099 D_80185A50 / D_80185ABC / jtbl_801BD898 + * ov_SC06_008 D_80187E44 / D_80187EB0 / jtbl_801A8734 + * The pair is always +0x6C apart, and NO literal in this draft encodes that distance + * (both labels are referenced by name), so there is no §84 derived-offset hazard. + * D_8011F9C4 is fleet-constant (main-EXE data) and must NOT be remapped. + * + * match_one: MATCH (271 ins) against the CURRENT tree (§87 staleness re-checked, 2026-07-27). + * PIN-FREE, zero asm, offset-pure (s32 arg0 + raw offsets) — x138 template-safe. + * Provenance: this is the Phase-26 crack (.run/phase26-cracks/func_8015B950.c) re-gated verbatim, + * with ONE deliberate change: the definition's return type void -> s32. + * - `void func_8015B950(s32 arg0)` : MATCH (271 ins) [the Phase-26 form] + * - `s32 func_8015B950(s32 arg0)` : MATCH (271 ins) [shipped — §3a-1 void->s32 is byte-neutral] + * The fleet/engine_core.h canonical decl is `extern s32 func_8015B950(void);` (engine_core.h:1852), + * and the last bank attempt (.run/bank_func_8015B950.log) died on `conflicting types for + * func_8015B950`. Shipping the s32 return kills the §73 RETURN axis for free and leaves only the + * cheap T0 PARAMS axis for the ladder (fix_header_decl.py / --fix-def-sig / cast_call_sites). + * Both forms are byte-identical, so the orchestrator may swap the return type back at zero cost. + * + * SYMBOLS (§58 rules 1/2 — all splat spellings, all verified present): + * D_80182AEC asm/ov_SC01_077/data/tail.data.s:4355 (the state-handler vtable) + * D_80182A80 asm/ov_SC01_077/data/tail.data.s:4293 + * D_8011F9C4 main-EXE data; spelled `extern s32 D_8011F9C4;` in 5+ already-banked TUs + * jtbl_801D8B74 asm/ov_SC01_077/data/tail14.data.s:15 (compiler jump table — not named in C) + * + * JTBL VERIFIED (§8a gate): compiled .rodata = exactly 0x1C B / 7 words, 7x R_MIPS_32 .text with + * addends [0x58,0x58,0x58,0xE0,0xF0,0x100,0x58] -> +0x8015B950 = [B9A8,B9A8,B9A8,BA30,BA40,BA50, + * B9A8] == the original words at 0x801D8B74..0x801D8B8C. Bound `sltiu $v0,$v1,0x7` matches. + * The raw dlabel's 8th word 0x00000000 is NOT an entry — it is the intra-TU `.align 3` pad of the + * B34/B54/B74 jtbl chain; the object can never emit it (maspsx drops .align), so it must stay in + * the post-carve RAW data piece (the §53/§62/§81 carve chain applies at bank time). + * + * Same family as the TU's own already-matched func_8015AE2C: 7-case switch on ((s32 (*)(s32))func_801619A4)() + * (0/1/2/6 shared, 3/4/5 own, no default block — out-of-range and every `break` fall to the + * after-switch join), then a chain of "state handler" tests, each dispatching + * D_80182AEC[*(u16*)arg0](arg0) and returning. + * + * THREE LEVERS (draft -> MATCH in 3 compiles): + * + * 1. PROLOGUE CONSTANT = an INITIALIZED LOCAL, not a literal in the compare. + * Target opens with `lui $s2, 0xFFF5` in the *prologue*, used once ~200 ins later in + * `slt $v0,$s2,$s1`. No gcc-2.7.2 pass hoists a (set reg const_int) across basic blocks + * (loop.c needs a loop; cse/combine/sched never move insns between BBs) — so the insn must + * have been EMITTED in the first BB, i.e. the constant is a local initialized at the top of + * the function. cse then cannot fold it back into the compare: the `slt` operand predicate is + * `arith_operand`, which rejects a CONST_INT wider than 16 bits, so validate_change fails and + * the pseudo survives. Its live range spans every call -> global.c gives it a callee-saved reg. + * Writing `z > -0xB0000` inline instead emits the `lui` into the branch delay slot next to the + * compare (caller-saved $v0) and the function is 1 insn short. => `s32 lim = -0xB0000;` at top. + * + * 2. `lh` vs `lhu`: a short->short copy is a pure HImode move and gcc emits `lhu`. The target's + * `lh $v0,0x26($s0)` means the value passed through an SImode (int) temp: expand makes + * (set (reg:SI) (sign_extend (mem:HI))) + (set (mem:HI) (subreg:HI ...)), and combine cannot + * merge them (the merged form is mem<-mem, which no movhi accepts) so the sign-extending load + * survives. => route both halfword copies through the `s32 t` temp. + * + * 3. THE `goto` LAYOUT — dodging jump.c's store-flag conversion (jump.c:1005-1065). + * An if/else chain writing 0/1 into `doit` makes gcc collapse the last pair into + * `sltiu $v0,$v0,1`. jump.c fires that conversion when the insn immediately after a + * conditional jump is a lone `SET pseudo, CONST_INT` whose following simplejump targets the + * SAME label as the branch (jump.c:1038 `reallabelprev == temp || ... JUMP_LABEL(temp4) == + * JUMP_LABEL(insn)`) — exactly the shape of `if (c) x=0; else x=1;`. + * The target instead cross-jumps ALL the `doit=0` exits into ONE shared block placed after the + * `doit=1` fall-through; reorg's fill_slots_from_thread then COPIES that single set into all + * three branch delay slots and redirects each branch past it (which is why `addu $v0,$zero, + * $zero` appears 3x in delay slots and the shared block vanishes). A `goto zero;` / `goto one;` + * chain expresses that layout directly, and each conditional jump is then followed by a + * compare/call rather than a lone const set, so the store-flag conversion never triggers. + * GENERAL RULE: multiple predicates that all assign the SAME constant to one flag => write + * them as `goto` to a shared assignment, never as an if/else ladder. + */ +extern s32 D_8011F9C4; +extern s32 D_80182A80; + +extern s32 func_80161B18(void); +extern s32 func_801619A4(s32*); +extern s32 func_80149AA8(s32*); +extern void func_80149AD4(s32*); +extern s32 func_80149B54(s32*); +extern void func_80149BAC(s32*); +extern s32 func_801498E0(s32*); +extern s32 func_80149954(s32); +extern s32 func_80149A64(s32*); +extern void func_800CCCC0(s32 a0); +extern s32 func_80149CD4(s32 a0); +extern void func_8015E880(s32*); +extern s32 func_80149744(struct S_80149744*); +extern void func_80149788(void); +extern s32 func_801496D4(void*); +extern void func_80149704(void); +extern int func_80148AFC(void*); +extern void func_80146D90(s32 a0); +extern void func_80154150(s32 a0, s32 a1); +extern void func_801541D8(u8*, s32, s32); +extern s32 func_801488A8(u8*); +extern void func_80147078(s32*, s16); +extern void func_8015A264(void*); +extern s32 func_80013294(void*, void*); +extern void func_80159B70(void*); +extern s32 func_8016F1AC(void); +extern s32 func_80029178(s32 a0); +extern void func_80146DB8(s32*, s32*); +extern s32 func_80161CD0(s32, s32); +extern s32 func_80161208(s32 a0); +extern s32 func_801725A4(u8*); + +s32 func_8015B950(s32 arg0) +{ + + extern void (*D_80182AEC[])(void *); + s16 sp10[4]; + s16 sp18[4]; + s32 t; + s32 z; + s32 doit; + s32 lim = -0xB0000; + + if (func_80161B18() != 0) { + return; + } + switch (((s32 (*)(s32))func_801619A4)(arg0)) { + case 0: + case 1: + case 2: + case 6: + if (((s32 (*)(s32))func_80149AA8)(arg0) != 0) { + D_80182AEC[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149AD4)(arg0); + return; + } + if (((s32 (*)(s32))func_80149B54)(arg0) != 0) { + D_80182AEC[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149BAC)(arg0); + return; + } + break; + case 3: + ((void (*)(s32))func_801498E0)(arg0); + break; + case 4: + ((void (*)(s32))func_80149954)(arg0); + break; + case 5: + if (((s32 (*)(s32))func_80149A64)(arg0) != 0) { + D_80182AEC[*(u16 *)arg0]((void *)arg0); + func_800CCCC0(arg0); + return; + } + break; + } + if (func_80149CD4(arg0) != 0) { + D_80182AEC[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_8015E880)(arg0); + return; + } + if (((s32 (*)(s32))func_80149744)(arg0) != 0) { + D_80182AEC[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149788)(arg0); + return; + } + if (((s32 (*)(s32))func_801496D4)(arg0) != 0) { + D_80182AEC[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149704)(arg0); + if (((u8)((s32 (*)(s32))func_80148AFC)(arg0)) == 0) { + func_80146D90(arg0); + } + if ((*(s32 *)(arg0 + 0x24) | *(s32 *)(arg0 + 0x2C)) != 0) { + func_80154150(arg0, 0xF); + } else { + ((void (*)(s32, s32, s32))func_801541D8)(arg0, 0xD, 6); + } + *(s32 *)(arg0 + 0x238) = 1; + return; + } + if (((s32 (*)(s32))func_801488A8)(arg0) != 0) { + sp10[0] = 0; + sp10[1] = 0; + sp10[2] = 0; + t = *(s16 *)(arg0 + 0x26); + sp18[0] = t; + sp18[1] = 0; + t = *(s16 *)(arg0 + 0x2E); + sp18[2] = t; + D_80182AEC[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 1); + ((void (*)(s32))func_8015A264)(arg0); + t = -(((s32 (*)(s16 *, s16 *))func_80013294)(sp10, sp18) << 0x10); + if (t < *(s32 *)(arg0 + 0x2C)) { + *(s32 *)(arg0 + 0x2C) = t; + } + return; + } + if (*(u16 *)(arg0 + 0xB8) == 0x8000) { + D_80182AEC[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 0); + ((void (*)(s32))func_80159B70)(arg0); + return; + } + z = *(s32 *)(arg0 + 0x2C); + if (func_8016F1AC() != 0) { + goto zero; + } + if (z <= lim) { + goto one; + } + if (D_8011F9C4 == 0) { + goto zero; + } + if (((u8)func_80029178(0x21)) != 0) { + goto zero; + } +one: + doit = 1; + goto join; +zero: + doit = 0; +join: + if (doit != 0) { + D_80182AEC[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 0); + ((void (*)(s32))func_80159B70)(arg0); + func_80154150(arg0, 9); + ((void (*)(s32, s32 *))func_80146DB8)(arg0, &D_80182A80); + ((void (*)(s32, s32))func_80161CD0)(arg0, *(u16 *)(arg0 + 0x16E)); + return; + } + if (func_80161208(arg0) == 0) { + ((void (*)(s32))func_801725A4)(arg0); + } +} DEFINE_func_8015BD8C() /* dedup: shared engine-core @0x8015BD8C (src/shared) */ diff --git a/src/ov_SC06_013/ov_SC06_013_jr_8015AE2C.c b/src/ov_SC06_013/ov_SC06_013_jr_8015AE2C.c index 2589cc45f..cf393ed76 100644 --- a/src/ov_SC06_013/ov_SC06_013_jr_8015AE2C.c +++ b/src/ov_SC06_013/ov_SC06_013_jr_8015AE2C.c @@ -1512,7 +1512,259 @@ DEFINE_func_8015B858() /* dedup: shared engine-core @0x8015B858 (src/shared) */ DEFINE_func_8015B8F8() /* dedup: shared engine-core @0x8015B8F8 (src/shared) */ -INCLUDE_ASM("asm/ov_SC06_013/nonmatchings/ov_SC06_013_jr_8015AE2C", func_8015B950); +extern s32 func_8015AE2C(); + +// @class: plumbing +// @stuck: none — MATCH (271/271, pin-free, zero asm). The ONLY residual is DEF-SIDE plumbing, and it is now named exactly: the in-TU instantiation `DEFINE_func_8015BEE4()` (engine_core.h:1851-1855) expands to `extern s32 func_8015B950(void);` INSIDE ov_SC01_077_jr_8015AE2C.c, ~14 lines BELOW this definition, so the 1-param def collides with a `(void)` prototype -> `conflicting types for func_8015B950` (.run/bank_func_8015B950.log). §73 PARAMS axis / T0. Surgical fix = §65b de-macroize that ONE instantiation (blast radius: this TU); the fleet-wide `(void)`->`()` header edit is §63 and must be R22-validated. +/* func_8015B950 (ov_SC01_077_jr_8015AE2C, 271 ins, jtbl_801D8B74) — SESSION-21 re-verified + * + * ── ROUND-2 INDEPENDENT RE-VERIFICATION (2026-07-27, fresh agent, §88e discipline) ───────────── + * match_one : MATCH (271 ins) against the CURRENT tree — §87 staleness re-checked today. + * .text size: compiled .text = 0x43C = 1084 B = 271 ins, EXACTLY the target's declared 0x43C + * ("nonmatching func_8015B950, 0x43C"). So this is NOT a §83a length drift hiding + * behind a zero count — the count is over equal-length streams. + * jtbl : RE-DECODED MECHANICALLY, not inherited. Compiled .rodata = 0x1C = 28 B = 7 words, + * 7x R_MIPS_32 -> .text with implicit addends [58,58,58,E0,F0,100,58]; +0x8015B950 + * = [8015B9A8, 8015B9A8, 8015B9A8, 8015BA30, 8015BA40, 8015BA50, 8015B9A8]. + * Diffed word-for-word against asm/ov_SC01_077/data/tail14.data.s:15-23 — 7/7 identical. + * symcheck : SYMS-DIFF target=35 draft=34, sole MISSING = jtbl_801D8B74. This is the §81 jr + * FALSE POSITIVE, re-confirmed here by reading the relocs: gcc emits its OWN table and + * references it with R_MIPS_HI16/LO16 against the SECTION `.rodata` (t.o +0x40/+0x48), + * so the splat's dlabel NAME can never appear in the draft object's relocation set. + * Nothing is dropped and nothing is invented: the draft's other 34 symbols are exactly + * the target's other 34. + * FAMILY : the x138 remap is clean and §84-safe. Every sibling is 271 ins with an IDENTICAL + * callee set; only THREE names vary per overlay — the two data labels and the jtbl: + * ov_SC01_077 D_801811FC / D_80181268 / jtbl_801D8B74 + * ov_SC03_099 D_80185A50 / D_80185ABC / jtbl_801BD898 + * ov_SC06_008 D_80187E44 / D_80187EB0 / jtbl_801A8734 + * The pair is always +0x6C apart, and NO literal in this draft encodes that distance + * (both labels are referenced by name), so there is no §84 derived-offset hazard. + * D_8011F9C4 is fleet-constant (main-EXE data) and must NOT be remapped. + * + * match_one: MATCH (271 ins) against the CURRENT tree (§87 staleness re-checked, 2026-07-27). + * PIN-FREE, zero asm, offset-pure (s32 arg0 + raw offsets) — x138 template-safe. + * Provenance: this is the Phase-26 crack (.run/phase26-cracks/func_8015B950.c) re-gated verbatim, + * with ONE deliberate change: the definition's return type void -> s32. + * - `void func_8015B950(s32 arg0)` : MATCH (271 ins) [the Phase-26 form] + * - `s32 func_8015B950(s32 arg0)` : MATCH (271 ins) [shipped — §3a-1 void->s32 is byte-neutral] + * The fleet/engine_core.h canonical decl is `extern s32 func_8015B950(void);` (engine_core.h:1852), + * and the last bank attempt (.run/bank_func_8015B950.log) died on `conflicting types for + * func_8015B950`. Shipping the s32 return kills the §73 RETURN axis for free and leaves only the + * cheap T0 PARAMS axis for the ladder (fix_header_decl.py / --fix-def-sig / cast_call_sites). + * Both forms are byte-identical, so the orchestrator may swap the return type back at zero cost. + * + * SYMBOLS (§58 rules 1/2 — all splat spellings, all verified present): + * D_80181268 asm/ov_SC01_077/data/tail.data.s:4355 (the state-handler vtable) + * D_801811FC asm/ov_SC01_077/data/tail.data.s:4293 + * D_8011F9C4 main-EXE data; spelled `extern s32 D_8011F9C4;` in 5+ already-banked TUs + * jtbl_801D8B74 asm/ov_SC01_077/data/tail14.data.s:15 (compiler jump table — not named in C) + * + * JTBL VERIFIED (§8a gate): compiled .rodata = exactly 0x1C B / 7 words, 7x R_MIPS_32 .text with + * addends [0x58,0x58,0x58,0xE0,0xF0,0x100,0x58] -> +0x8015B950 = [B9A8,B9A8,B9A8,BA30,BA40,BA50, + * B9A8] == the original words at 0x801D8B74..0x801D8B8C. Bound `sltiu $v0,$v1,0x7` matches. + * The raw dlabel's 8th word 0x00000000 is NOT an entry — it is the intra-TU `.align 3` pad of the + * B34/B54/B74 jtbl chain; the object can never emit it (maspsx drops .align), so it must stay in + * the post-carve RAW data piece (the §53/§62/§81 carve chain applies at bank time). + * + * Same family as the TU's own already-matched func_8015AE2C: 7-case switch on ((s32 (*)(s32))func_801619A4)() + * (0/1/2/6 shared, 3/4/5 own, no default block — out-of-range and every `break` fall to the + * after-switch join), then a chain of "state handler" tests, each dispatching + * D_80181268[*(u16*)arg0](arg0) and returning. + * + * THREE LEVERS (draft -> MATCH in 3 compiles): + * + * 1. PROLOGUE CONSTANT = an INITIALIZED LOCAL, not a literal in the compare. + * Target opens with `lui $s2, 0xFFF5` in the *prologue*, used once ~200 ins later in + * `slt $v0,$s2,$s1`. No gcc-2.7.2 pass hoists a (set reg const_int) across basic blocks + * (loop.c needs a loop; cse/combine/sched never move insns between BBs) — so the insn must + * have been EMITTED in the first BB, i.e. the constant is a local initialized at the top of + * the function. cse then cannot fold it back into the compare: the `slt` operand predicate is + * `arith_operand`, which rejects a CONST_INT wider than 16 bits, so validate_change fails and + * the pseudo survives. Its live range spans every call -> global.c gives it a callee-saved reg. + * Writing `z > -0xB0000` inline instead emits the `lui` into the branch delay slot next to the + * compare (caller-saved $v0) and the function is 1 insn short. => `s32 lim = -0xB0000;` at top. + * + * 2. `lh` vs `lhu`: a short->short copy is a pure HImode move and gcc emits `lhu`. The target's + * `lh $v0,0x26($s0)` means the value passed through an SImode (int) temp: expand makes + * (set (reg:SI) (sign_extend (mem:HI))) + (set (mem:HI) (subreg:HI ...)), and combine cannot + * merge them (the merged form is mem<-mem, which no movhi accepts) so the sign-extending load + * survives. => route both halfword copies through the `s32 t` temp. + * + * 3. THE `goto` LAYOUT — dodging jump.c's store-flag conversion (jump.c:1005-1065). + * An if/else chain writing 0/1 into `doit` makes gcc collapse the last pair into + * `sltiu $v0,$v0,1`. jump.c fires that conversion when the insn immediately after a + * conditional jump is a lone `SET pseudo, CONST_INT` whose following simplejump targets the + * SAME label as the branch (jump.c:1038 `reallabelprev == temp || ... JUMP_LABEL(temp4) == + * JUMP_LABEL(insn)`) — exactly the shape of `if (c) x=0; else x=1;`. + * The target instead cross-jumps ALL the `doit=0` exits into ONE shared block placed after the + * `doit=1` fall-through; reorg's fill_slots_from_thread then COPIES that single set into all + * three branch delay slots and redirects each branch past it (which is why `addu $v0,$zero, + * $zero` appears 3x in delay slots and the shared block vanishes). A `goto zero;` / `goto one;` + * chain expresses that layout directly, and each conditional jump is then followed by a + * compare/call rather than a lone const set, so the store-flag conversion never triggers. + * GENERAL RULE: multiple predicates that all assign the SAME constant to one flag => write + * them as `goto` to a shared assignment, never as an if/else ladder. + */ +extern s32 D_8011F9C4; +extern s32 D_801811FC; + +extern s32 func_80161B18(void); +extern s32 func_801619A4(s32*); +extern s32 func_80149AA8(s32*); +extern void func_80149AD4(s32*); +extern s32 func_80149B54(s32*); +extern void func_80149BAC(s32*); +extern s32 func_801498E0(s32*); +extern s32 func_80149954(s32); +extern s32 func_80149A64(s32*); +extern void func_800CCCC0(s32 a0); +extern s32 func_80149CD4(s32 a0); +extern void func_8015E880(s32*); +extern s32 func_80149744(struct S_80149744*); +extern void func_80149788(void); +extern s32 func_801496D4(void*); +extern void func_80149704(void); +extern int func_80148AFC(void*); +extern void func_80146D90(s32 a0); +extern void func_80154150(s32 a0, s32 a1); +extern void func_801541D8(u8*, s32, s32); +extern s32 func_801488A8(u8*); +extern void func_80147078(s32*, s16); +extern void func_8015A264(void*); +extern s32 func_80013294(void*, void*); +extern void func_80159B70(void*); +extern s32 func_8016F1AC(void); +extern s32 func_80029178(s32 a0); +extern void func_80146DB8(s32*, s32*); +extern s32 func_80161CD0(s32, s32); +extern s32 func_80161208(s32 a0); +extern s32 func_801725A4(u8*); + +s32 func_8015B950(s32 arg0) +{ + + extern void (*D_80181268[])(void *); + s16 sp10[4]; + s16 sp18[4]; + s32 t; + s32 z; + s32 doit; + s32 lim = -0xB0000; + + if (func_80161B18() != 0) { + return; + } + switch (((s32 (*)(s32))func_801619A4)(arg0)) { + case 0: + case 1: + case 2: + case 6: + if (((s32 (*)(s32))func_80149AA8)(arg0) != 0) { + D_80181268[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149AD4)(arg0); + return; + } + if (((s32 (*)(s32))func_80149B54)(arg0) != 0) { + D_80181268[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149BAC)(arg0); + return; + } + break; + case 3: + ((void (*)(s32))func_801498E0)(arg0); + break; + case 4: + ((void (*)(s32))func_80149954)(arg0); + break; + case 5: + if (((s32 (*)(s32))func_80149A64)(arg0) != 0) { + D_80181268[*(u16 *)arg0]((void *)arg0); + func_800CCCC0(arg0); + return; + } + break; + } + if (func_80149CD4(arg0) != 0) { + D_80181268[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_8015E880)(arg0); + return; + } + if (((s32 (*)(s32))func_80149744)(arg0) != 0) { + D_80181268[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149788)(arg0); + return; + } + if (((s32 (*)(s32))func_801496D4)(arg0) != 0) { + D_80181268[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149704)(arg0); + if (((u8)((s32 (*)(s32))func_80148AFC)(arg0)) == 0) { + func_80146D90(arg0); + } + if ((*(s32 *)(arg0 + 0x24) | *(s32 *)(arg0 + 0x2C)) != 0) { + func_80154150(arg0, 0xF); + } else { + ((void (*)(s32, s32, s32))func_801541D8)(arg0, 0xD, 6); + } + *(s32 *)(arg0 + 0x238) = 1; + return; + } + if (((s32 (*)(s32))func_801488A8)(arg0) != 0) { + sp10[0] = 0; + sp10[1] = 0; + sp10[2] = 0; + t = *(s16 *)(arg0 + 0x26); + sp18[0] = t; + sp18[1] = 0; + t = *(s16 *)(arg0 + 0x2E); + sp18[2] = t; + D_80181268[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 1); + ((void (*)(s32))func_8015A264)(arg0); + t = -(((s32 (*)(s16 *, s16 *))func_80013294)(sp10, sp18) << 0x10); + if (t < *(s32 *)(arg0 + 0x2C)) { + *(s32 *)(arg0 + 0x2C) = t; + } + return; + } + if (*(u16 *)(arg0 + 0xB8) == 0x8000) { + D_80181268[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 0); + ((void (*)(s32))func_80159B70)(arg0); + return; + } + z = *(s32 *)(arg0 + 0x2C); + if (func_8016F1AC() != 0) { + goto zero; + } + if (z <= lim) { + goto one; + } + if (D_8011F9C4 == 0) { + goto zero; + } + if (((u8)func_80029178(0x21)) != 0) { + goto zero; + } +one: + doit = 1; + goto join; +zero: + doit = 0; +join: + if (doit != 0) { + D_80181268[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 0); + ((void (*)(s32))func_80159B70)(arg0); + func_80154150(arg0, 9); + ((void (*)(s32, s32 *))func_80146DB8)(arg0, &D_801811FC); + ((void (*)(s32, s32))func_80161CD0)(arg0, *(u16 *)(arg0 + 0x16E)); + return; + } + if (func_80161208(arg0) == 0) { + ((void (*)(s32))func_801725A4)(arg0); + } +} DEFINE_func_8015BD8C() /* dedup: shared engine-core @0x8015BD8C (src/shared) */ diff --git a/src/ov_SC06_014/ov_SC06_014_jr_8015AE2C.c b/src/ov_SC06_014/ov_SC06_014_jr_8015AE2C.c index 6206654b4..d72bbca97 100644 --- a/src/ov_SC06_014/ov_SC06_014_jr_8015AE2C.c +++ b/src/ov_SC06_014/ov_SC06_014_jr_8015AE2C.c @@ -1512,7 +1512,259 @@ DEFINE_func_8015B858() /* dedup: shared engine-core @0x8015B858 (src/shared) */ DEFINE_func_8015B8F8() /* dedup: shared engine-core @0x8015B8F8 (src/shared) */ -INCLUDE_ASM("asm/ov_SC06_014/nonmatchings/ov_SC06_014_jr_8015AE2C", func_8015B950); +extern s32 func_8015AE2C(); + +// @class: plumbing +// @stuck: none — MATCH (271/271, pin-free, zero asm). The ONLY residual is DEF-SIDE plumbing, and it is now named exactly: the in-TU instantiation `DEFINE_func_8015BEE4()` (engine_core.h:1851-1855) expands to `extern s32 func_8015B950(void);` INSIDE ov_SC01_077_jr_8015AE2C.c, ~14 lines BELOW this definition, so the 1-param def collides with a `(void)` prototype -> `conflicting types for func_8015B950` (.run/bank_func_8015B950.log). §73 PARAMS axis / T0. Surgical fix = §65b de-macroize that ONE instantiation (blast radius: this TU); the fleet-wide `(void)`->`()` header edit is §63 and must be R22-validated. +/* func_8015B950 (ov_SC01_077_jr_8015AE2C, 271 ins, jtbl_801D8B74) — SESSION-21 re-verified + * + * ── ROUND-2 INDEPENDENT RE-VERIFICATION (2026-07-27, fresh agent, §88e discipline) ───────────── + * match_one : MATCH (271 ins) against the CURRENT tree — §87 staleness re-checked today. + * .text size: compiled .text = 0x43C = 1084 B = 271 ins, EXACTLY the target's declared 0x43C + * ("nonmatching func_8015B950, 0x43C"). So this is NOT a §83a length drift hiding + * behind a zero count — the count is over equal-length streams. + * jtbl : RE-DECODED MECHANICALLY, not inherited. Compiled .rodata = 0x1C = 28 B = 7 words, + * 7x R_MIPS_32 -> .text with implicit addends [58,58,58,E0,F0,100,58]; +0x8015B950 + * = [8015B9A8, 8015B9A8, 8015B9A8, 8015BA30, 8015BA40, 8015BA50, 8015B9A8]. + * Diffed word-for-word against asm/ov_SC01_077/data/tail14.data.s:15-23 — 7/7 identical. + * symcheck : SYMS-DIFF target=35 draft=34, sole MISSING = jtbl_801D8B74. This is the §81 jr + * FALSE POSITIVE, re-confirmed here by reading the relocs: gcc emits its OWN table and + * references it with R_MIPS_HI16/LO16 against the SECTION `.rodata` (t.o +0x40/+0x48), + * so the splat's dlabel NAME can never appear in the draft object's relocation set. + * Nothing is dropped and nothing is invented: the draft's other 34 symbols are exactly + * the target's other 34. + * FAMILY : the x138 remap is clean and §84-safe. Every sibling is 271 ins with an IDENTICAL + * callee set; only THREE names vary per overlay — the two data labels and the jtbl: + * ov_SC01_077 D_80182560 / D_801825CC / jtbl_801D8B74 + * ov_SC03_099 D_80185A50 / D_80185ABC / jtbl_801BD898 + * ov_SC06_008 D_80187E44 / D_80187EB0 / jtbl_801A8734 + * The pair is always +0x6C apart, and NO literal in this draft encodes that distance + * (both labels are referenced by name), so there is no §84 derived-offset hazard. + * D_8011F9C4 is fleet-constant (main-EXE data) and must NOT be remapped. + * + * match_one: MATCH (271 ins) against the CURRENT tree (§87 staleness re-checked, 2026-07-27). + * PIN-FREE, zero asm, offset-pure (s32 arg0 + raw offsets) — x138 template-safe. + * Provenance: this is the Phase-26 crack (.run/phase26-cracks/func_8015B950.c) re-gated verbatim, + * with ONE deliberate change: the definition's return type void -> s32. + * - `void func_8015B950(s32 arg0)` : MATCH (271 ins) [the Phase-26 form] + * - `s32 func_8015B950(s32 arg0)` : MATCH (271 ins) [shipped — §3a-1 void->s32 is byte-neutral] + * The fleet/engine_core.h canonical decl is `extern s32 func_8015B950(void);` (engine_core.h:1852), + * and the last bank attempt (.run/bank_func_8015B950.log) died on `conflicting types for + * func_8015B950`. Shipping the s32 return kills the §73 RETURN axis for free and leaves only the + * cheap T0 PARAMS axis for the ladder (fix_header_decl.py / --fix-def-sig / cast_call_sites). + * Both forms are byte-identical, so the orchestrator may swap the return type back at zero cost. + * + * SYMBOLS (§58 rules 1/2 — all splat spellings, all verified present): + * D_801825CC asm/ov_SC01_077/data/tail.data.s:4355 (the state-handler vtable) + * D_80182560 asm/ov_SC01_077/data/tail.data.s:4293 + * D_8011F9C4 main-EXE data; spelled `extern s32 D_8011F9C4;` in 5+ already-banked TUs + * jtbl_801D8B74 asm/ov_SC01_077/data/tail14.data.s:15 (compiler jump table — not named in C) + * + * JTBL VERIFIED (§8a gate): compiled .rodata = exactly 0x1C B / 7 words, 7x R_MIPS_32 .text with + * addends [0x58,0x58,0x58,0xE0,0xF0,0x100,0x58] -> +0x8015B950 = [B9A8,B9A8,B9A8,BA30,BA40,BA50, + * B9A8] == the original words at 0x801D8B74..0x801D8B8C. Bound `sltiu $v0,$v1,0x7` matches. + * The raw dlabel's 8th word 0x00000000 is NOT an entry — it is the intra-TU `.align 3` pad of the + * B34/B54/B74 jtbl chain; the object can never emit it (maspsx drops .align), so it must stay in + * the post-carve RAW data piece (the §53/§62/§81 carve chain applies at bank time). + * + * Same family as the TU's own already-matched func_8015AE2C: 7-case switch on ((s32 (*)(s32))func_801619A4)() + * (0/1/2/6 shared, 3/4/5 own, no default block — out-of-range and every `break` fall to the + * after-switch join), then a chain of "state handler" tests, each dispatching + * D_801825CC[*(u16*)arg0](arg0) and returning. + * + * THREE LEVERS (draft -> MATCH in 3 compiles): + * + * 1. PROLOGUE CONSTANT = an INITIALIZED LOCAL, not a literal in the compare. + * Target opens with `lui $s2, 0xFFF5` in the *prologue*, used once ~200 ins later in + * `slt $v0,$s2,$s1`. No gcc-2.7.2 pass hoists a (set reg const_int) across basic blocks + * (loop.c needs a loop; cse/combine/sched never move insns between BBs) — so the insn must + * have been EMITTED in the first BB, i.e. the constant is a local initialized at the top of + * the function. cse then cannot fold it back into the compare: the `slt` operand predicate is + * `arith_operand`, which rejects a CONST_INT wider than 16 bits, so validate_change fails and + * the pseudo survives. Its live range spans every call -> global.c gives it a callee-saved reg. + * Writing `z > -0xB0000` inline instead emits the `lui` into the branch delay slot next to the + * compare (caller-saved $v0) and the function is 1 insn short. => `s32 lim = -0xB0000;` at top. + * + * 2. `lh` vs `lhu`: a short->short copy is a pure HImode move and gcc emits `lhu`. The target's + * `lh $v0,0x26($s0)` means the value passed through an SImode (int) temp: expand makes + * (set (reg:SI) (sign_extend (mem:HI))) + (set (mem:HI) (subreg:HI ...)), and combine cannot + * merge them (the merged form is mem<-mem, which no movhi accepts) so the sign-extending load + * survives. => route both halfword copies through the `s32 t` temp. + * + * 3. THE `goto` LAYOUT — dodging jump.c's store-flag conversion (jump.c:1005-1065). + * An if/else chain writing 0/1 into `doit` makes gcc collapse the last pair into + * `sltiu $v0,$v0,1`. jump.c fires that conversion when the insn immediately after a + * conditional jump is a lone `SET pseudo, CONST_INT` whose following simplejump targets the + * SAME label as the branch (jump.c:1038 `reallabelprev == temp || ... JUMP_LABEL(temp4) == + * JUMP_LABEL(insn)`) — exactly the shape of `if (c) x=0; else x=1;`. + * The target instead cross-jumps ALL the `doit=0` exits into ONE shared block placed after the + * `doit=1` fall-through; reorg's fill_slots_from_thread then COPIES that single set into all + * three branch delay slots and redirects each branch past it (which is why `addu $v0,$zero, + * $zero` appears 3x in delay slots and the shared block vanishes). A `goto zero;` / `goto one;` + * chain expresses that layout directly, and each conditional jump is then followed by a + * compare/call rather than a lone const set, so the store-flag conversion never triggers. + * GENERAL RULE: multiple predicates that all assign the SAME constant to one flag => write + * them as `goto` to a shared assignment, never as an if/else ladder. + */ +extern s32 D_8011F9C4; +extern s32 D_80182560; + +extern s32 func_80161B18(void); +extern s32 func_801619A4(s32*); +extern s32 func_80149AA8(s32*); +extern void func_80149AD4(s32*); +extern s32 func_80149B54(s32*); +extern void func_80149BAC(s32*); +extern s32 func_801498E0(s32*); +extern s32 func_80149954(s32); +extern s32 func_80149A64(s32*); +extern void func_800CCCC0(s32 a0); +extern s32 func_80149CD4(s32 a0); +extern void func_8015E880(s32*); +extern s32 func_80149744(struct S_80149744*); +extern void func_80149788(void); +extern s32 func_801496D4(void*); +extern void func_80149704(void); +extern int func_80148AFC(void*); +extern void func_80146D90(s32 a0); +extern void func_80154150(s32 a0, s32 a1); +extern void func_801541D8(u8*, s32, s32); +extern s32 func_801488A8(u8*); +extern void func_80147078(s32*, s16); +extern void func_8015A264(void*); +extern s32 func_80013294(void*, void*); +extern void func_80159B70(void*); +extern s32 func_8016F1AC(void); +extern s32 func_80029178(s32 a0); +extern void func_80146DB8(s32*, s32*); +extern s32 func_80161CD0(s32, s32); +extern s32 func_80161208(s32 a0); +extern s32 func_801725A4(u8*); + +s32 func_8015B950(s32 arg0) +{ + + extern void (*D_801825CC[])(void *); + s16 sp10[4]; + s16 sp18[4]; + s32 t; + s32 z; + s32 doit; + s32 lim = -0xB0000; + + if (func_80161B18() != 0) { + return; + } + switch (((s32 (*)(s32))func_801619A4)(arg0)) { + case 0: + case 1: + case 2: + case 6: + if (((s32 (*)(s32))func_80149AA8)(arg0) != 0) { + D_801825CC[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149AD4)(arg0); + return; + } + if (((s32 (*)(s32))func_80149B54)(arg0) != 0) { + D_801825CC[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149BAC)(arg0); + return; + } + break; + case 3: + ((void (*)(s32))func_801498E0)(arg0); + break; + case 4: + ((void (*)(s32))func_80149954)(arg0); + break; + case 5: + if (((s32 (*)(s32))func_80149A64)(arg0) != 0) { + D_801825CC[*(u16 *)arg0]((void *)arg0); + func_800CCCC0(arg0); + return; + } + break; + } + if (func_80149CD4(arg0) != 0) { + D_801825CC[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_8015E880)(arg0); + return; + } + if (((s32 (*)(s32))func_80149744)(arg0) != 0) { + D_801825CC[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149788)(arg0); + return; + } + if (((s32 (*)(s32))func_801496D4)(arg0) != 0) { + D_801825CC[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149704)(arg0); + if (((u8)((s32 (*)(s32))func_80148AFC)(arg0)) == 0) { + func_80146D90(arg0); + } + if ((*(s32 *)(arg0 + 0x24) | *(s32 *)(arg0 + 0x2C)) != 0) { + func_80154150(arg0, 0xF); + } else { + ((void (*)(s32, s32, s32))func_801541D8)(arg0, 0xD, 6); + } + *(s32 *)(arg0 + 0x238) = 1; + return; + } + if (((s32 (*)(s32))func_801488A8)(arg0) != 0) { + sp10[0] = 0; + sp10[1] = 0; + sp10[2] = 0; + t = *(s16 *)(arg0 + 0x26); + sp18[0] = t; + sp18[1] = 0; + t = *(s16 *)(arg0 + 0x2E); + sp18[2] = t; + D_801825CC[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 1); + ((void (*)(s32))func_8015A264)(arg0); + t = -(((s32 (*)(s16 *, s16 *))func_80013294)(sp10, sp18) << 0x10); + if (t < *(s32 *)(arg0 + 0x2C)) { + *(s32 *)(arg0 + 0x2C) = t; + } + return; + } + if (*(u16 *)(arg0 + 0xB8) == 0x8000) { + D_801825CC[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 0); + ((void (*)(s32))func_80159B70)(arg0); + return; + } + z = *(s32 *)(arg0 + 0x2C); + if (func_8016F1AC() != 0) { + goto zero; + } + if (z <= lim) { + goto one; + } + if (D_8011F9C4 == 0) { + goto zero; + } + if (((u8)func_80029178(0x21)) != 0) { + goto zero; + } +one: + doit = 1; + goto join; +zero: + doit = 0; +join: + if (doit != 0) { + D_801825CC[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 0); + ((void (*)(s32))func_80159B70)(arg0); + func_80154150(arg0, 9); + ((void (*)(s32, s32 *))func_80146DB8)(arg0, &D_80182560); + ((void (*)(s32, s32))func_80161CD0)(arg0, *(u16 *)(arg0 + 0x16E)); + return; + } + if (func_80161208(arg0) == 0) { + ((void (*)(s32))func_801725A4)(arg0); + } +} DEFINE_func_8015BD8C() /* dedup: shared engine-core @0x8015BD8C (src/shared) */ diff --git a/src/ov_SC06_015/ov_SC06_015_jr_8015AE2C.c b/src/ov_SC06_015/ov_SC06_015_jr_8015AE2C.c index c1c11bc8e..3d418d4cb 100644 --- a/src/ov_SC06_015/ov_SC06_015_jr_8015AE2C.c +++ b/src/ov_SC06_015/ov_SC06_015_jr_8015AE2C.c @@ -1512,7 +1512,259 @@ DEFINE_func_8015B858() /* dedup: shared engine-core @0x8015B858 (src/shared) */ DEFINE_func_8015B8F8() /* dedup: shared engine-core @0x8015B8F8 (src/shared) */ -INCLUDE_ASM("asm/ov_SC06_015/nonmatchings/ov_SC06_015_jr_8015AE2C", func_8015B950); +extern s32 func_8015AE2C(); + +// @class: plumbing +// @stuck: none — MATCH (271/271, pin-free, zero asm). The ONLY residual is DEF-SIDE plumbing, and it is now named exactly: the in-TU instantiation `DEFINE_func_8015BEE4()` (engine_core.h:1851-1855) expands to `extern s32 func_8015B950(void);` INSIDE ov_SC01_077_jr_8015AE2C.c, ~14 lines BELOW this definition, so the 1-param def collides with a `(void)` prototype -> `conflicting types for func_8015B950` (.run/bank_func_8015B950.log). §73 PARAMS axis / T0. Surgical fix = §65b de-macroize that ONE instantiation (blast radius: this TU); the fleet-wide `(void)`->`()` header edit is §63 and must be R22-validated. +/* func_8015B950 (ov_SC01_077_jr_8015AE2C, 271 ins, jtbl_801D8B74) — SESSION-21 re-verified + * + * ── ROUND-2 INDEPENDENT RE-VERIFICATION (2026-07-27, fresh agent, §88e discipline) ───────────── + * match_one : MATCH (271 ins) against the CURRENT tree — §87 staleness re-checked today. + * .text size: compiled .text = 0x43C = 1084 B = 271 ins, EXACTLY the target's declared 0x43C + * ("nonmatching func_8015B950, 0x43C"). So this is NOT a §83a length drift hiding + * behind a zero count — the count is over equal-length streams. + * jtbl : RE-DECODED MECHANICALLY, not inherited. Compiled .rodata = 0x1C = 28 B = 7 words, + * 7x R_MIPS_32 -> .text with implicit addends [58,58,58,E0,F0,100,58]; +0x8015B950 + * = [8015B9A8, 8015B9A8, 8015B9A8, 8015BA30, 8015BA40, 8015BA50, 8015B9A8]. + * Diffed word-for-word against asm/ov_SC01_077/data/tail14.data.s:15-23 — 7/7 identical. + * symcheck : SYMS-DIFF target=35 draft=34, sole MISSING = jtbl_801D8B74. This is the §81 jr + * FALSE POSITIVE, re-confirmed here by reading the relocs: gcc emits its OWN table and + * references it with R_MIPS_HI16/LO16 against the SECTION `.rodata` (t.o +0x40/+0x48), + * so the splat's dlabel NAME can never appear in the draft object's relocation set. + * Nothing is dropped and nothing is invented: the draft's other 34 symbols are exactly + * the target's other 34. + * FAMILY : the x138 remap is clean and §84-safe. Every sibling is 271 ins with an IDENTICAL + * callee set; only THREE names vary per overlay — the two data labels and the jtbl: + * ov_SC01_077 D_801810B8 / D_80181124 / jtbl_801D8B74 + * ov_SC03_099 D_80185A50 / D_80185ABC / jtbl_801BD898 + * ov_SC06_008 D_80187E44 / D_80187EB0 / jtbl_801A8734 + * The pair is always +0x6C apart, and NO literal in this draft encodes that distance + * (both labels are referenced by name), so there is no §84 derived-offset hazard. + * D_8011F9C4 is fleet-constant (main-EXE data) and must NOT be remapped. + * + * match_one: MATCH (271 ins) against the CURRENT tree (§87 staleness re-checked, 2026-07-27). + * PIN-FREE, zero asm, offset-pure (s32 arg0 + raw offsets) — x138 template-safe. + * Provenance: this is the Phase-26 crack (.run/phase26-cracks/func_8015B950.c) re-gated verbatim, + * with ONE deliberate change: the definition's return type void -> s32. + * - `void func_8015B950(s32 arg0)` : MATCH (271 ins) [the Phase-26 form] + * - `s32 func_8015B950(s32 arg0)` : MATCH (271 ins) [shipped — §3a-1 void->s32 is byte-neutral] + * The fleet/engine_core.h canonical decl is `extern s32 func_8015B950(void);` (engine_core.h:1852), + * and the last bank attempt (.run/bank_func_8015B950.log) died on `conflicting types for + * func_8015B950`. Shipping the s32 return kills the §73 RETURN axis for free and leaves only the + * cheap T0 PARAMS axis for the ladder (fix_header_decl.py / --fix-def-sig / cast_call_sites). + * Both forms are byte-identical, so the orchestrator may swap the return type back at zero cost. + * + * SYMBOLS (§58 rules 1/2 — all splat spellings, all verified present): + * D_80181124 asm/ov_SC01_077/data/tail.data.s:4355 (the state-handler vtable) + * D_801810B8 asm/ov_SC01_077/data/tail.data.s:4293 + * D_8011F9C4 main-EXE data; spelled `extern s32 D_8011F9C4;` in 5+ already-banked TUs + * jtbl_801D8B74 asm/ov_SC01_077/data/tail14.data.s:15 (compiler jump table — not named in C) + * + * JTBL VERIFIED (§8a gate): compiled .rodata = exactly 0x1C B / 7 words, 7x R_MIPS_32 .text with + * addends [0x58,0x58,0x58,0xE0,0xF0,0x100,0x58] -> +0x8015B950 = [B9A8,B9A8,B9A8,BA30,BA40,BA50, + * B9A8] == the original words at 0x801D8B74..0x801D8B8C. Bound `sltiu $v0,$v1,0x7` matches. + * The raw dlabel's 8th word 0x00000000 is NOT an entry — it is the intra-TU `.align 3` pad of the + * B34/B54/B74 jtbl chain; the object can never emit it (maspsx drops .align), so it must stay in + * the post-carve RAW data piece (the §53/§62/§81 carve chain applies at bank time). + * + * Same family as the TU's own already-matched func_8015AE2C: 7-case switch on ((s32 (*)(s32))func_801619A4)() + * (0/1/2/6 shared, 3/4/5 own, no default block — out-of-range and every `break` fall to the + * after-switch join), then a chain of "state handler" tests, each dispatching + * D_80181124[*(u16*)arg0](arg0) and returning. + * + * THREE LEVERS (draft -> MATCH in 3 compiles): + * + * 1. PROLOGUE CONSTANT = an INITIALIZED LOCAL, not a literal in the compare. + * Target opens with `lui $s2, 0xFFF5` in the *prologue*, used once ~200 ins later in + * `slt $v0,$s2,$s1`. No gcc-2.7.2 pass hoists a (set reg const_int) across basic blocks + * (loop.c needs a loop; cse/combine/sched never move insns between BBs) — so the insn must + * have been EMITTED in the first BB, i.e. the constant is a local initialized at the top of + * the function. cse then cannot fold it back into the compare: the `slt` operand predicate is + * `arith_operand`, which rejects a CONST_INT wider than 16 bits, so validate_change fails and + * the pseudo survives. Its live range spans every call -> global.c gives it a callee-saved reg. + * Writing `z > -0xB0000` inline instead emits the `lui` into the branch delay slot next to the + * compare (caller-saved $v0) and the function is 1 insn short. => `s32 lim = -0xB0000;` at top. + * + * 2. `lh` vs `lhu`: a short->short copy is a pure HImode move and gcc emits `lhu`. The target's + * `lh $v0,0x26($s0)` means the value passed through an SImode (int) temp: expand makes + * (set (reg:SI) (sign_extend (mem:HI))) + (set (mem:HI) (subreg:HI ...)), and combine cannot + * merge them (the merged form is mem<-mem, which no movhi accepts) so the sign-extending load + * survives. => route both halfword copies through the `s32 t` temp. + * + * 3. THE `goto` LAYOUT — dodging jump.c's store-flag conversion (jump.c:1005-1065). + * An if/else chain writing 0/1 into `doit` makes gcc collapse the last pair into + * `sltiu $v0,$v0,1`. jump.c fires that conversion when the insn immediately after a + * conditional jump is a lone `SET pseudo, CONST_INT` whose following simplejump targets the + * SAME label as the branch (jump.c:1038 `reallabelprev == temp || ... JUMP_LABEL(temp4) == + * JUMP_LABEL(insn)`) — exactly the shape of `if (c) x=0; else x=1;`. + * The target instead cross-jumps ALL the `doit=0` exits into ONE shared block placed after the + * `doit=1` fall-through; reorg's fill_slots_from_thread then COPIES that single set into all + * three branch delay slots and redirects each branch past it (which is why `addu $v0,$zero, + * $zero` appears 3x in delay slots and the shared block vanishes). A `goto zero;` / `goto one;` + * chain expresses that layout directly, and each conditional jump is then followed by a + * compare/call rather than a lone const set, so the store-flag conversion never triggers. + * GENERAL RULE: multiple predicates that all assign the SAME constant to one flag => write + * them as `goto` to a shared assignment, never as an if/else ladder. + */ +extern s32 D_8011F9C4; +extern s32 D_801810B8; + +extern s32 func_80161B18(void); +extern s32 func_801619A4(s32*); +extern s32 func_80149AA8(s32*); +extern void func_80149AD4(s32*); +extern s32 func_80149B54(s32*); +extern void func_80149BAC(s32*); +extern s32 func_801498E0(s32*); +extern s32 func_80149954(s32); +extern s32 func_80149A64(s32*); +extern void func_800CCCC0(s32 a0); +extern s32 func_80149CD4(s32 a0); +extern void func_8015E880(s32*); +extern s32 func_80149744(struct S_80149744*); +extern void func_80149788(void); +extern s32 func_801496D4(void*); +extern void func_80149704(void); +extern int func_80148AFC(void*); +extern void func_80146D90(s32 a0); +extern void func_80154150(s32 a0, s32 a1); +extern void func_801541D8(u8*, s32, s32); +extern s32 func_801488A8(u8*); +extern void func_80147078(s32*, s16); +extern void func_8015A264(void*); +extern s32 func_80013294(void*, void*); +extern void func_80159B70(void*); +extern s32 func_8016F1AC(void); +extern s32 func_80029178(s32 a0); +extern void func_80146DB8(s32*, s32*); +extern s32 func_80161CD0(s32, s32); +extern s32 func_80161208(s32 a0); +extern s32 func_801725A4(u8*); + +s32 func_8015B950(s32 arg0) +{ + + extern void (*D_80181124[])(void *); + s16 sp10[4]; + s16 sp18[4]; + s32 t; + s32 z; + s32 doit; + s32 lim = -0xB0000; + + if (func_80161B18() != 0) { + return; + } + switch (((s32 (*)(s32))func_801619A4)(arg0)) { + case 0: + case 1: + case 2: + case 6: + if (((s32 (*)(s32))func_80149AA8)(arg0) != 0) { + D_80181124[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149AD4)(arg0); + return; + } + if (((s32 (*)(s32))func_80149B54)(arg0) != 0) { + D_80181124[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149BAC)(arg0); + return; + } + break; + case 3: + ((void (*)(s32))func_801498E0)(arg0); + break; + case 4: + ((void (*)(s32))func_80149954)(arg0); + break; + case 5: + if (((s32 (*)(s32))func_80149A64)(arg0) != 0) { + D_80181124[*(u16 *)arg0]((void *)arg0); + func_800CCCC0(arg0); + return; + } + break; + } + if (func_80149CD4(arg0) != 0) { + D_80181124[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_8015E880)(arg0); + return; + } + if (((s32 (*)(s32))func_80149744)(arg0) != 0) { + D_80181124[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149788)(arg0); + return; + } + if (((s32 (*)(s32))func_801496D4)(arg0) != 0) { + D_80181124[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149704)(arg0); + if (((u8)((s32 (*)(s32))func_80148AFC)(arg0)) == 0) { + func_80146D90(arg0); + } + if ((*(s32 *)(arg0 + 0x24) | *(s32 *)(arg0 + 0x2C)) != 0) { + func_80154150(arg0, 0xF); + } else { + ((void (*)(s32, s32, s32))func_801541D8)(arg0, 0xD, 6); + } + *(s32 *)(arg0 + 0x238) = 1; + return; + } + if (((s32 (*)(s32))func_801488A8)(arg0) != 0) { + sp10[0] = 0; + sp10[1] = 0; + sp10[2] = 0; + t = *(s16 *)(arg0 + 0x26); + sp18[0] = t; + sp18[1] = 0; + t = *(s16 *)(arg0 + 0x2E); + sp18[2] = t; + D_80181124[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 1); + ((void (*)(s32))func_8015A264)(arg0); + t = -(((s32 (*)(s16 *, s16 *))func_80013294)(sp10, sp18) << 0x10); + if (t < *(s32 *)(arg0 + 0x2C)) { + *(s32 *)(arg0 + 0x2C) = t; + } + return; + } + if (*(u16 *)(arg0 + 0xB8) == 0x8000) { + D_80181124[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 0); + ((void (*)(s32))func_80159B70)(arg0); + return; + } + z = *(s32 *)(arg0 + 0x2C); + if (func_8016F1AC() != 0) { + goto zero; + } + if (z <= lim) { + goto one; + } + if (D_8011F9C4 == 0) { + goto zero; + } + if (((u8)func_80029178(0x21)) != 0) { + goto zero; + } +one: + doit = 1; + goto join; +zero: + doit = 0; +join: + if (doit != 0) { + D_80181124[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 0); + ((void (*)(s32))func_80159B70)(arg0); + func_80154150(arg0, 9); + ((void (*)(s32, s32 *))func_80146DB8)(arg0, &D_801810B8); + ((void (*)(s32, s32))func_80161CD0)(arg0, *(u16 *)(arg0 + 0x16E)); + return; + } + if (func_80161208(arg0) == 0) { + ((void (*)(s32))func_801725A4)(arg0); + } +} DEFINE_func_8015BD8C() /* dedup: shared engine-core @0x8015BD8C (src/shared) */ diff --git a/src/ov_SC06_016/ov_SC06_016_jr_8015AE2C.c b/src/ov_SC06_016/ov_SC06_016_jr_8015AE2C.c index 114e34e22..89613a7b2 100644 --- a/src/ov_SC06_016/ov_SC06_016_jr_8015AE2C.c +++ b/src/ov_SC06_016/ov_SC06_016_jr_8015AE2C.c @@ -1512,7 +1512,259 @@ DEFINE_func_8015B858() /* dedup: shared engine-core @0x8015B858 (src/shared) */ DEFINE_func_8015B8F8() /* dedup: shared engine-core @0x8015B8F8 (src/shared) */ -INCLUDE_ASM("asm/ov_SC06_016/nonmatchings/ov_SC06_016_jr_8015AE2C", func_8015B950); +extern s32 func_8015AE2C(); + +// @class: plumbing +// @stuck: none — MATCH (271/271, pin-free, zero asm). The ONLY residual is DEF-SIDE plumbing, and it is now named exactly: the in-TU instantiation `DEFINE_func_8015BEE4()` (engine_core.h:1851-1855) expands to `extern s32 func_8015B950(void);` INSIDE ov_SC01_077_jr_8015AE2C.c, ~14 lines BELOW this definition, so the 1-param def collides with a `(void)` prototype -> `conflicting types for func_8015B950` (.run/bank_func_8015B950.log). §73 PARAMS axis / T0. Surgical fix = §65b de-macroize that ONE instantiation (blast radius: this TU); the fleet-wide `(void)`->`()` header edit is §63 and must be R22-validated. +/* func_8015B950 (ov_SC01_077_jr_8015AE2C, 271 ins, jtbl_801D8B74) — SESSION-21 re-verified + * + * ── ROUND-2 INDEPENDENT RE-VERIFICATION (2026-07-27, fresh agent, §88e discipline) ───────────── + * match_one : MATCH (271 ins) against the CURRENT tree — §87 staleness re-checked today. + * .text size: compiled .text = 0x43C = 1084 B = 271 ins, EXACTLY the target's declared 0x43C + * ("nonmatching func_8015B950, 0x43C"). So this is NOT a §83a length drift hiding + * behind a zero count — the count is over equal-length streams. + * jtbl : RE-DECODED MECHANICALLY, not inherited. Compiled .rodata = 0x1C = 28 B = 7 words, + * 7x R_MIPS_32 -> .text with implicit addends [58,58,58,E0,F0,100,58]; +0x8015B950 + * = [8015B9A8, 8015B9A8, 8015B9A8, 8015BA30, 8015BA40, 8015BA50, 8015B9A8]. + * Diffed word-for-word against asm/ov_SC01_077/data/tail14.data.s:15-23 — 7/7 identical. + * symcheck : SYMS-DIFF target=35 draft=34, sole MISSING = jtbl_801D8B74. This is the §81 jr + * FALSE POSITIVE, re-confirmed here by reading the relocs: gcc emits its OWN table and + * references it with R_MIPS_HI16/LO16 against the SECTION `.rodata` (t.o +0x40/+0x48), + * so the splat's dlabel NAME can never appear in the draft object's relocation set. + * Nothing is dropped and nothing is invented: the draft's other 34 symbols are exactly + * the target's other 34. + * FAMILY : the x138 remap is clean and §84-safe. Every sibling is 271 ins with an IDENTICAL + * callee set; only THREE names vary per overlay — the two data labels and the jtbl: + * ov_SC01_077 D_801874C8 / D_80187534 / jtbl_801D8B74 + * ov_SC03_099 D_80185A50 / D_80185ABC / jtbl_801BD898 + * ov_SC06_008 D_80187E44 / D_80187EB0 / jtbl_801A8734 + * The pair is always +0x6C apart, and NO literal in this draft encodes that distance + * (both labels are referenced by name), so there is no §84 derived-offset hazard. + * D_8011F9C4 is fleet-constant (main-EXE data) and must NOT be remapped. + * + * match_one: MATCH (271 ins) against the CURRENT tree (§87 staleness re-checked, 2026-07-27). + * PIN-FREE, zero asm, offset-pure (s32 arg0 + raw offsets) — x138 template-safe. + * Provenance: this is the Phase-26 crack (.run/phase26-cracks/func_8015B950.c) re-gated verbatim, + * with ONE deliberate change: the definition's return type void -> s32. + * - `void func_8015B950(s32 arg0)` : MATCH (271 ins) [the Phase-26 form] + * - `s32 func_8015B950(s32 arg0)` : MATCH (271 ins) [shipped — §3a-1 void->s32 is byte-neutral] + * The fleet/engine_core.h canonical decl is `extern s32 func_8015B950(void);` (engine_core.h:1852), + * and the last bank attempt (.run/bank_func_8015B950.log) died on `conflicting types for + * func_8015B950`. Shipping the s32 return kills the §73 RETURN axis for free and leaves only the + * cheap T0 PARAMS axis for the ladder (fix_header_decl.py / --fix-def-sig / cast_call_sites). + * Both forms are byte-identical, so the orchestrator may swap the return type back at zero cost. + * + * SYMBOLS (§58 rules 1/2 — all splat spellings, all verified present): + * D_80187534 asm/ov_SC01_077/data/tail.data.s:4355 (the state-handler vtable) + * D_801874C8 asm/ov_SC01_077/data/tail.data.s:4293 + * D_8011F9C4 main-EXE data; spelled `extern s32 D_8011F9C4;` in 5+ already-banked TUs + * jtbl_801D8B74 asm/ov_SC01_077/data/tail14.data.s:15 (compiler jump table — not named in C) + * + * JTBL VERIFIED (§8a gate): compiled .rodata = exactly 0x1C B / 7 words, 7x R_MIPS_32 .text with + * addends [0x58,0x58,0x58,0xE0,0xF0,0x100,0x58] -> +0x8015B950 = [B9A8,B9A8,B9A8,BA30,BA40,BA50, + * B9A8] == the original words at 0x801D8B74..0x801D8B8C. Bound `sltiu $v0,$v1,0x7` matches. + * The raw dlabel's 8th word 0x00000000 is NOT an entry — it is the intra-TU `.align 3` pad of the + * B34/B54/B74 jtbl chain; the object can never emit it (maspsx drops .align), so it must stay in + * the post-carve RAW data piece (the §53/§62/§81 carve chain applies at bank time). + * + * Same family as the TU's own already-matched func_8015AE2C: 7-case switch on ((s32 (*)(s32))func_801619A4)() + * (0/1/2/6 shared, 3/4/5 own, no default block — out-of-range and every `break` fall to the + * after-switch join), then a chain of "state handler" tests, each dispatching + * D_80187534[*(u16*)arg0](arg0) and returning. + * + * THREE LEVERS (draft -> MATCH in 3 compiles): + * + * 1. PROLOGUE CONSTANT = an INITIALIZED LOCAL, not a literal in the compare. + * Target opens with `lui $s2, 0xFFF5` in the *prologue*, used once ~200 ins later in + * `slt $v0,$s2,$s1`. No gcc-2.7.2 pass hoists a (set reg const_int) across basic blocks + * (loop.c needs a loop; cse/combine/sched never move insns between BBs) — so the insn must + * have been EMITTED in the first BB, i.e. the constant is a local initialized at the top of + * the function. cse then cannot fold it back into the compare: the `slt` operand predicate is + * `arith_operand`, which rejects a CONST_INT wider than 16 bits, so validate_change fails and + * the pseudo survives. Its live range spans every call -> global.c gives it a callee-saved reg. + * Writing `z > -0xB0000` inline instead emits the `lui` into the branch delay slot next to the + * compare (caller-saved $v0) and the function is 1 insn short. => `s32 lim = -0xB0000;` at top. + * + * 2. `lh` vs `lhu`: a short->short copy is a pure HImode move and gcc emits `lhu`. The target's + * `lh $v0,0x26($s0)` means the value passed through an SImode (int) temp: expand makes + * (set (reg:SI) (sign_extend (mem:HI))) + (set (mem:HI) (subreg:HI ...)), and combine cannot + * merge them (the merged form is mem<-mem, which no movhi accepts) so the sign-extending load + * survives. => route both halfword copies through the `s32 t` temp. + * + * 3. THE `goto` LAYOUT — dodging jump.c's store-flag conversion (jump.c:1005-1065). + * An if/else chain writing 0/1 into `doit` makes gcc collapse the last pair into + * `sltiu $v0,$v0,1`. jump.c fires that conversion when the insn immediately after a + * conditional jump is a lone `SET pseudo, CONST_INT` whose following simplejump targets the + * SAME label as the branch (jump.c:1038 `reallabelprev == temp || ... JUMP_LABEL(temp4) == + * JUMP_LABEL(insn)`) — exactly the shape of `if (c) x=0; else x=1;`. + * The target instead cross-jumps ALL the `doit=0` exits into ONE shared block placed after the + * `doit=1` fall-through; reorg's fill_slots_from_thread then COPIES that single set into all + * three branch delay slots and redirects each branch past it (which is why `addu $v0,$zero, + * $zero` appears 3x in delay slots and the shared block vanishes). A `goto zero;` / `goto one;` + * chain expresses that layout directly, and each conditional jump is then followed by a + * compare/call rather than a lone const set, so the store-flag conversion never triggers. + * GENERAL RULE: multiple predicates that all assign the SAME constant to one flag => write + * them as `goto` to a shared assignment, never as an if/else ladder. + */ +extern s32 D_8011F9C4; +extern s32 D_801874C8; + +extern s32 func_80161B18(void); +extern s32 func_801619A4(s32*); +extern s32 func_80149AA8(s32*); +extern void func_80149AD4(s32*); +extern s32 func_80149B54(s32*); +extern void func_80149BAC(s32*); +extern s32 func_801498E0(s32*); +extern s32 func_80149954(s32); +extern s32 func_80149A64(s32*); +extern void func_800CCCC0(s32 a0); +extern s32 func_80149CD4(s32 a0); +extern void func_8015E880(s32*); +extern s32 func_80149744(struct S_80149744*); +extern void func_80149788(void); +extern s32 func_801496D4(void*); +extern void func_80149704(void); +extern int func_80148AFC(void*); +extern void func_80146D90(s32 a0); +extern void func_80154150(s32 a0, s32 a1); +extern void func_801541D8(u8*, s32, s32); +extern s32 func_801488A8(u8*); +extern void func_80147078(s32*, s16); +extern void func_8015A264(void*); +extern s32 func_80013294(void*, void*); +extern void func_80159B70(void*); +extern s32 func_8016F1AC(void); +extern s32 func_80029178(s32 a0); +extern void func_80146DB8(s32*, s32*); +extern s32 func_80161CD0(s32, s32); +extern s32 func_80161208(s32 a0); +extern s32 func_801725A4(u8*); + +s32 func_8015B950(s32 arg0) +{ + + extern void (*D_80187534[])(void *); + s16 sp10[4]; + s16 sp18[4]; + s32 t; + s32 z; + s32 doit; + s32 lim = -0xB0000; + + if (func_80161B18() != 0) { + return; + } + switch (((s32 (*)(s32))func_801619A4)(arg0)) { + case 0: + case 1: + case 2: + case 6: + if (((s32 (*)(s32))func_80149AA8)(arg0) != 0) { + D_80187534[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149AD4)(arg0); + return; + } + if (((s32 (*)(s32))func_80149B54)(arg0) != 0) { + D_80187534[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149BAC)(arg0); + return; + } + break; + case 3: + ((void (*)(s32))func_801498E0)(arg0); + break; + case 4: + ((void (*)(s32))func_80149954)(arg0); + break; + case 5: + if (((s32 (*)(s32))func_80149A64)(arg0) != 0) { + D_80187534[*(u16 *)arg0]((void *)arg0); + func_800CCCC0(arg0); + return; + } + break; + } + if (func_80149CD4(arg0) != 0) { + D_80187534[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_8015E880)(arg0); + return; + } + if (((s32 (*)(s32))func_80149744)(arg0) != 0) { + D_80187534[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149788)(arg0); + return; + } + if (((s32 (*)(s32))func_801496D4)(arg0) != 0) { + D_80187534[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149704)(arg0); + if (((u8)((s32 (*)(s32))func_80148AFC)(arg0)) == 0) { + func_80146D90(arg0); + } + if ((*(s32 *)(arg0 + 0x24) | *(s32 *)(arg0 + 0x2C)) != 0) { + func_80154150(arg0, 0xF); + } else { + ((void (*)(s32, s32, s32))func_801541D8)(arg0, 0xD, 6); + } + *(s32 *)(arg0 + 0x238) = 1; + return; + } + if (((s32 (*)(s32))func_801488A8)(arg0) != 0) { + sp10[0] = 0; + sp10[1] = 0; + sp10[2] = 0; + t = *(s16 *)(arg0 + 0x26); + sp18[0] = t; + sp18[1] = 0; + t = *(s16 *)(arg0 + 0x2E); + sp18[2] = t; + D_80187534[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 1); + ((void (*)(s32))func_8015A264)(arg0); + t = -(((s32 (*)(s16 *, s16 *))func_80013294)(sp10, sp18) << 0x10); + if (t < *(s32 *)(arg0 + 0x2C)) { + *(s32 *)(arg0 + 0x2C) = t; + } + return; + } + if (*(u16 *)(arg0 + 0xB8) == 0x8000) { + D_80187534[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 0); + ((void (*)(s32))func_80159B70)(arg0); + return; + } + z = *(s32 *)(arg0 + 0x2C); + if (func_8016F1AC() != 0) { + goto zero; + } + if (z <= lim) { + goto one; + } + if (D_8011F9C4 == 0) { + goto zero; + } + if (((u8)func_80029178(0x21)) != 0) { + goto zero; + } +one: + doit = 1; + goto join; +zero: + doit = 0; +join: + if (doit != 0) { + D_80187534[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 0); + ((void (*)(s32))func_80159B70)(arg0); + func_80154150(arg0, 9); + ((void (*)(s32, s32 *))func_80146DB8)(arg0, &D_801874C8); + ((void (*)(s32, s32))func_80161CD0)(arg0, *(u16 *)(arg0 + 0x16E)); + return; + } + if (func_80161208(arg0) == 0) { + ((void (*)(s32))func_801725A4)(arg0); + } +} DEFINE_func_8015BD8C() /* dedup: shared engine-core @0x8015BD8C (src/shared) */ diff --git a/src/ov_SC06_018/ov_SC06_018_jr_8015AE2C.c b/src/ov_SC06_018/ov_SC06_018_jr_8015AE2C.c index 9841e2a83..65eda0206 100644 --- a/src/ov_SC06_018/ov_SC06_018_jr_8015AE2C.c +++ b/src/ov_SC06_018/ov_SC06_018_jr_8015AE2C.c @@ -1512,7 +1512,259 @@ DEFINE_func_8015B858() /* dedup: shared engine-core @0x8015B858 (src/shared) */ DEFINE_func_8015B8F8() /* dedup: shared engine-core @0x8015B8F8 (src/shared) */ -INCLUDE_ASM("asm/ov_SC06_018/nonmatchings/ov_SC06_018_jr_8015AE2C", func_8015B950); +extern s32 func_8015AE2C(); + +// @class: plumbing +// @stuck: none — MATCH (271/271, pin-free, zero asm). The ONLY residual is DEF-SIDE plumbing, and it is now named exactly: the in-TU instantiation `DEFINE_func_8015BEE4()` (engine_core.h:1851-1855) expands to `extern s32 func_8015B950(void);` INSIDE ov_SC01_077_jr_8015AE2C.c, ~14 lines BELOW this definition, so the 1-param def collides with a `(void)` prototype -> `conflicting types for func_8015B950` (.run/bank_func_8015B950.log). §73 PARAMS axis / T0. Surgical fix = §65b de-macroize that ONE instantiation (blast radius: this TU); the fleet-wide `(void)`->`()` header edit is §63 and must be R22-validated. +/* func_8015B950 (ov_SC01_077_jr_8015AE2C, 271 ins, jtbl_801D8B74) — SESSION-21 re-verified + * + * ── ROUND-2 INDEPENDENT RE-VERIFICATION (2026-07-27, fresh agent, §88e discipline) ───────────── + * match_one : MATCH (271 ins) against the CURRENT tree — §87 staleness re-checked today. + * .text size: compiled .text = 0x43C = 1084 B = 271 ins, EXACTLY the target's declared 0x43C + * ("nonmatching func_8015B950, 0x43C"). So this is NOT a §83a length drift hiding + * behind a zero count — the count is over equal-length streams. + * jtbl : RE-DECODED MECHANICALLY, not inherited. Compiled .rodata = 0x1C = 28 B = 7 words, + * 7x R_MIPS_32 -> .text with implicit addends [58,58,58,E0,F0,100,58]; +0x8015B950 + * = [8015B9A8, 8015B9A8, 8015B9A8, 8015BA30, 8015BA40, 8015BA50, 8015B9A8]. + * Diffed word-for-word against asm/ov_SC01_077/data/tail14.data.s:15-23 — 7/7 identical. + * symcheck : SYMS-DIFF target=35 draft=34, sole MISSING = jtbl_801D8B74. This is the §81 jr + * FALSE POSITIVE, re-confirmed here by reading the relocs: gcc emits its OWN table and + * references it with R_MIPS_HI16/LO16 against the SECTION `.rodata` (t.o +0x40/+0x48), + * so the splat's dlabel NAME can never appear in the draft object's relocation set. + * Nothing is dropped and nothing is invented: the draft's other 34 symbols are exactly + * the target's other 34. + * FAMILY : the x138 remap is clean and §84-safe. Every sibling is 271 ins with an IDENTICAL + * callee set; only THREE names vary per overlay — the two data labels and the jtbl: + * ov_SC01_077 D_80195C04 / D_80195C70 / jtbl_801D8B74 + * ov_SC03_099 D_80185A50 / D_80185ABC / jtbl_801BD898 + * ov_SC06_008 D_80187E44 / D_80187EB0 / jtbl_801A8734 + * The pair is always +0x6C apart, and NO literal in this draft encodes that distance + * (both labels are referenced by name), so there is no §84 derived-offset hazard. + * D_8011F9C4 is fleet-constant (main-EXE data) and must NOT be remapped. + * + * match_one: MATCH (271 ins) against the CURRENT tree (§87 staleness re-checked, 2026-07-27). + * PIN-FREE, zero asm, offset-pure (s32 arg0 + raw offsets) — x138 template-safe. + * Provenance: this is the Phase-26 crack (.run/phase26-cracks/func_8015B950.c) re-gated verbatim, + * with ONE deliberate change: the definition's return type void -> s32. + * - `void func_8015B950(s32 arg0)` : MATCH (271 ins) [the Phase-26 form] + * - `s32 func_8015B950(s32 arg0)` : MATCH (271 ins) [shipped — §3a-1 void->s32 is byte-neutral] + * The fleet/engine_core.h canonical decl is `extern s32 func_8015B950(void);` (engine_core.h:1852), + * and the last bank attempt (.run/bank_func_8015B950.log) died on `conflicting types for + * func_8015B950`. Shipping the s32 return kills the §73 RETURN axis for free and leaves only the + * cheap T0 PARAMS axis for the ladder (fix_header_decl.py / --fix-def-sig / cast_call_sites). + * Both forms are byte-identical, so the orchestrator may swap the return type back at zero cost. + * + * SYMBOLS (§58 rules 1/2 — all splat spellings, all verified present): + * D_80195C70 asm/ov_SC01_077/data/tail.data.s:4355 (the state-handler vtable) + * D_80195C04 asm/ov_SC01_077/data/tail.data.s:4293 + * D_8011F9C4 main-EXE data; spelled `extern s32 D_8011F9C4;` in 5+ already-banked TUs + * jtbl_801D8B74 asm/ov_SC01_077/data/tail14.data.s:15 (compiler jump table — not named in C) + * + * JTBL VERIFIED (§8a gate): compiled .rodata = exactly 0x1C B / 7 words, 7x R_MIPS_32 .text with + * addends [0x58,0x58,0x58,0xE0,0xF0,0x100,0x58] -> +0x8015B950 = [B9A8,B9A8,B9A8,BA30,BA40,BA50, + * B9A8] == the original words at 0x801D8B74..0x801D8B8C. Bound `sltiu $v0,$v1,0x7` matches. + * The raw dlabel's 8th word 0x00000000 is NOT an entry — it is the intra-TU `.align 3` pad of the + * B34/B54/B74 jtbl chain; the object can never emit it (maspsx drops .align), so it must stay in + * the post-carve RAW data piece (the §53/§62/§81 carve chain applies at bank time). + * + * Same family as the TU's own already-matched func_8015AE2C: 7-case switch on ((s32 (*)(s32))func_801619A4)() + * (0/1/2/6 shared, 3/4/5 own, no default block — out-of-range and every `break` fall to the + * after-switch join), then a chain of "state handler" tests, each dispatching + * D_80195C70[*(u16*)arg0](arg0) and returning. + * + * THREE LEVERS (draft -> MATCH in 3 compiles): + * + * 1. PROLOGUE CONSTANT = an INITIALIZED LOCAL, not a literal in the compare. + * Target opens with `lui $s2, 0xFFF5` in the *prologue*, used once ~200 ins later in + * `slt $v0,$s2,$s1`. No gcc-2.7.2 pass hoists a (set reg const_int) across basic blocks + * (loop.c needs a loop; cse/combine/sched never move insns between BBs) — so the insn must + * have been EMITTED in the first BB, i.e. the constant is a local initialized at the top of + * the function. cse then cannot fold it back into the compare: the `slt` operand predicate is + * `arith_operand`, which rejects a CONST_INT wider than 16 bits, so validate_change fails and + * the pseudo survives. Its live range spans every call -> global.c gives it a callee-saved reg. + * Writing `z > -0xB0000` inline instead emits the `lui` into the branch delay slot next to the + * compare (caller-saved $v0) and the function is 1 insn short. => `s32 lim = -0xB0000;` at top. + * + * 2. `lh` vs `lhu`: a short->short copy is a pure HImode move and gcc emits `lhu`. The target's + * `lh $v0,0x26($s0)` means the value passed through an SImode (int) temp: expand makes + * (set (reg:SI) (sign_extend (mem:HI))) + (set (mem:HI) (subreg:HI ...)), and combine cannot + * merge them (the merged form is mem<-mem, which no movhi accepts) so the sign-extending load + * survives. => route both halfword copies through the `s32 t` temp. + * + * 3. THE `goto` LAYOUT — dodging jump.c's store-flag conversion (jump.c:1005-1065). + * An if/else chain writing 0/1 into `doit` makes gcc collapse the last pair into + * `sltiu $v0,$v0,1`. jump.c fires that conversion when the insn immediately after a + * conditional jump is a lone `SET pseudo, CONST_INT` whose following simplejump targets the + * SAME label as the branch (jump.c:1038 `reallabelprev == temp || ... JUMP_LABEL(temp4) == + * JUMP_LABEL(insn)`) — exactly the shape of `if (c) x=0; else x=1;`. + * The target instead cross-jumps ALL the `doit=0` exits into ONE shared block placed after the + * `doit=1` fall-through; reorg's fill_slots_from_thread then COPIES that single set into all + * three branch delay slots and redirects each branch past it (which is why `addu $v0,$zero, + * $zero` appears 3x in delay slots and the shared block vanishes). A `goto zero;` / `goto one;` + * chain expresses that layout directly, and each conditional jump is then followed by a + * compare/call rather than a lone const set, so the store-flag conversion never triggers. + * GENERAL RULE: multiple predicates that all assign the SAME constant to one flag => write + * them as `goto` to a shared assignment, never as an if/else ladder. + */ +extern s32 D_8011F9C4; +extern s32 D_80195C04; + +extern s32 func_80161B18(void); +extern s32 func_801619A4(s32*); +extern s32 func_80149AA8(s32*); +extern void func_80149AD4(s32*); +extern s32 func_80149B54(s32*); +extern void func_80149BAC(s32*); +extern s32 func_801498E0(s32*); +extern s32 func_80149954(s32); +extern s32 func_80149A64(s32*); +extern void func_800CCCC0(s32 a0); +extern s32 func_80149CD4(s32 a0); +extern void func_8015E880(s32*); +extern s32 func_80149744(struct S_80149744*); +extern void func_80149788(void); +extern s32 func_801496D4(void*); +extern void func_80149704(void); +extern int func_80148AFC(void*); +extern void func_80146D90(s32 a0); +extern void func_80154150(s32 a0, s32 a1); +extern void func_801541D8(u8*, s32, s32); +extern s32 func_801488A8(u8*); +extern void func_80147078(s32*, s16); +extern void func_8015A264(void*); +extern s32 func_80013294(void*, void*); +extern void func_80159B70(void*); +extern s32 func_8016F1AC(void); +extern s32 func_80029178(s32 a0); +extern void func_80146DB8(s32*, s32*); +extern s32 func_80161CD0(s32, s32); +extern s32 func_80161208(s32 a0); +extern s32 func_801725A4(u8*); + +s32 func_8015B950(s32 arg0) +{ + + extern void (*D_80195C70[])(void *); + s16 sp10[4]; + s16 sp18[4]; + s32 t; + s32 z; + s32 doit; + s32 lim = -0xB0000; + + if (func_80161B18() != 0) { + return; + } + switch (((s32 (*)(s32))func_801619A4)(arg0)) { + case 0: + case 1: + case 2: + case 6: + if (((s32 (*)(s32))func_80149AA8)(arg0) != 0) { + D_80195C70[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149AD4)(arg0); + return; + } + if (((s32 (*)(s32))func_80149B54)(arg0) != 0) { + D_80195C70[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149BAC)(arg0); + return; + } + break; + case 3: + ((void (*)(s32))func_801498E0)(arg0); + break; + case 4: + ((void (*)(s32))func_80149954)(arg0); + break; + case 5: + if (((s32 (*)(s32))func_80149A64)(arg0) != 0) { + D_80195C70[*(u16 *)arg0]((void *)arg0); + func_800CCCC0(arg0); + return; + } + break; + } + if (func_80149CD4(arg0) != 0) { + D_80195C70[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_8015E880)(arg0); + return; + } + if (((s32 (*)(s32))func_80149744)(arg0) != 0) { + D_80195C70[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149788)(arg0); + return; + } + if (((s32 (*)(s32))func_801496D4)(arg0) != 0) { + D_80195C70[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149704)(arg0); + if (((u8)((s32 (*)(s32))func_80148AFC)(arg0)) == 0) { + func_80146D90(arg0); + } + if ((*(s32 *)(arg0 + 0x24) | *(s32 *)(arg0 + 0x2C)) != 0) { + func_80154150(arg0, 0xF); + } else { + ((void (*)(s32, s32, s32))func_801541D8)(arg0, 0xD, 6); + } + *(s32 *)(arg0 + 0x238) = 1; + return; + } + if (((s32 (*)(s32))func_801488A8)(arg0) != 0) { + sp10[0] = 0; + sp10[1] = 0; + sp10[2] = 0; + t = *(s16 *)(arg0 + 0x26); + sp18[0] = t; + sp18[1] = 0; + t = *(s16 *)(arg0 + 0x2E); + sp18[2] = t; + D_80195C70[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 1); + ((void (*)(s32))func_8015A264)(arg0); + t = -(((s32 (*)(s16 *, s16 *))func_80013294)(sp10, sp18) << 0x10); + if (t < *(s32 *)(arg0 + 0x2C)) { + *(s32 *)(arg0 + 0x2C) = t; + } + return; + } + if (*(u16 *)(arg0 + 0xB8) == 0x8000) { + D_80195C70[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 0); + ((void (*)(s32))func_80159B70)(arg0); + return; + } + z = *(s32 *)(arg0 + 0x2C); + if (func_8016F1AC() != 0) { + goto zero; + } + if (z <= lim) { + goto one; + } + if (D_8011F9C4 == 0) { + goto zero; + } + if (((u8)func_80029178(0x21)) != 0) { + goto zero; + } +one: + doit = 1; + goto join; +zero: + doit = 0; +join: + if (doit != 0) { + D_80195C70[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 0); + ((void (*)(s32))func_80159B70)(arg0); + func_80154150(arg0, 9); + ((void (*)(s32, s32 *))func_80146DB8)(arg0, &D_80195C04); + ((void (*)(s32, s32))func_80161CD0)(arg0, *(u16 *)(arg0 + 0x16E)); + return; + } + if (func_80161208(arg0) == 0) { + ((void (*)(s32))func_801725A4)(arg0); + } +} DEFINE_func_8015BD8C() /* dedup: shared engine-core @0x8015BD8C (src/shared) */ diff --git a/src/ov_SC06_020/ov_SC06_020_jr_8015AE2C.c b/src/ov_SC06_020/ov_SC06_020_jr_8015AE2C.c index 0ac124a37..19f539389 100644 --- a/src/ov_SC06_020/ov_SC06_020_jr_8015AE2C.c +++ b/src/ov_SC06_020/ov_SC06_020_jr_8015AE2C.c @@ -1512,7 +1512,259 @@ DEFINE_func_8015B858() /* dedup: shared engine-core @0x8015B858 (src/shared) */ DEFINE_func_8015B8F8() /* dedup: shared engine-core @0x8015B8F8 (src/shared) */ -INCLUDE_ASM("asm/ov_SC06_020/nonmatchings/ov_SC06_020_jr_8015AE2C", func_8015B950); +extern s32 func_8015AE2C(); + +// @class: plumbing +// @stuck: none — MATCH (271/271, pin-free, zero asm). The ONLY residual is DEF-SIDE plumbing, and it is now named exactly: the in-TU instantiation `DEFINE_func_8015BEE4()` (engine_core.h:1851-1855) expands to `extern s32 func_8015B950(void);` INSIDE ov_SC01_077_jr_8015AE2C.c, ~14 lines BELOW this definition, so the 1-param def collides with a `(void)` prototype -> `conflicting types for func_8015B950` (.run/bank_func_8015B950.log). §73 PARAMS axis / T0. Surgical fix = §65b de-macroize that ONE instantiation (blast radius: this TU); the fleet-wide `(void)`->`()` header edit is §63 and must be R22-validated. +/* func_8015B950 (ov_SC01_077_jr_8015AE2C, 271 ins, jtbl_801D8B74) — SESSION-21 re-verified + * + * ── ROUND-2 INDEPENDENT RE-VERIFICATION (2026-07-27, fresh agent, §88e discipline) ───────────── + * match_one : MATCH (271 ins) against the CURRENT tree — §87 staleness re-checked today. + * .text size: compiled .text = 0x43C = 1084 B = 271 ins, EXACTLY the target's declared 0x43C + * ("nonmatching func_8015B950, 0x43C"). So this is NOT a §83a length drift hiding + * behind a zero count — the count is over equal-length streams. + * jtbl : RE-DECODED MECHANICALLY, not inherited. Compiled .rodata = 0x1C = 28 B = 7 words, + * 7x R_MIPS_32 -> .text with implicit addends [58,58,58,E0,F0,100,58]; +0x8015B950 + * = [8015B9A8, 8015B9A8, 8015B9A8, 8015BA30, 8015BA40, 8015BA50, 8015B9A8]. + * Diffed word-for-word against asm/ov_SC01_077/data/tail14.data.s:15-23 — 7/7 identical. + * symcheck : SYMS-DIFF target=35 draft=34, sole MISSING = jtbl_801D8B74. This is the §81 jr + * FALSE POSITIVE, re-confirmed here by reading the relocs: gcc emits its OWN table and + * references it with R_MIPS_HI16/LO16 against the SECTION `.rodata` (t.o +0x40/+0x48), + * so the splat's dlabel NAME can never appear in the draft object's relocation set. + * Nothing is dropped and nothing is invented: the draft's other 34 symbols are exactly + * the target's other 34. + * FAMILY : the x138 remap is clean and §84-safe. Every sibling is 271 ins with an IDENTICAL + * callee set; only THREE names vary per overlay — the two data labels and the jtbl: + * ov_SC01_077 D_8018768C / D_801876F8 / jtbl_801D8B74 + * ov_SC03_099 D_80185A50 / D_80185ABC / jtbl_801BD898 + * ov_SC06_008 D_80187E44 / D_80187EB0 / jtbl_801A8734 + * The pair is always +0x6C apart, and NO literal in this draft encodes that distance + * (both labels are referenced by name), so there is no §84 derived-offset hazard. + * D_8011F9C4 is fleet-constant (main-EXE data) and must NOT be remapped. + * + * match_one: MATCH (271 ins) against the CURRENT tree (§87 staleness re-checked, 2026-07-27). + * PIN-FREE, zero asm, offset-pure (s32 arg0 + raw offsets) — x138 template-safe. + * Provenance: this is the Phase-26 crack (.run/phase26-cracks/func_8015B950.c) re-gated verbatim, + * with ONE deliberate change: the definition's return type void -> s32. + * - `void func_8015B950(s32 arg0)` : MATCH (271 ins) [the Phase-26 form] + * - `s32 func_8015B950(s32 arg0)` : MATCH (271 ins) [shipped — §3a-1 void->s32 is byte-neutral] + * The fleet/engine_core.h canonical decl is `extern s32 func_8015B950(void);` (engine_core.h:1852), + * and the last bank attempt (.run/bank_func_8015B950.log) died on `conflicting types for + * func_8015B950`. Shipping the s32 return kills the §73 RETURN axis for free and leaves only the + * cheap T0 PARAMS axis for the ladder (fix_header_decl.py / --fix-def-sig / cast_call_sites). + * Both forms are byte-identical, so the orchestrator may swap the return type back at zero cost. + * + * SYMBOLS (§58 rules 1/2 — all splat spellings, all verified present): + * D_801876F8 asm/ov_SC01_077/data/tail.data.s:4355 (the state-handler vtable) + * D_8018768C asm/ov_SC01_077/data/tail.data.s:4293 + * D_8011F9C4 main-EXE data; spelled `extern s32 D_8011F9C4;` in 5+ already-banked TUs + * jtbl_801D8B74 asm/ov_SC01_077/data/tail14.data.s:15 (compiler jump table — not named in C) + * + * JTBL VERIFIED (§8a gate): compiled .rodata = exactly 0x1C B / 7 words, 7x R_MIPS_32 .text with + * addends [0x58,0x58,0x58,0xE0,0xF0,0x100,0x58] -> +0x8015B950 = [B9A8,B9A8,B9A8,BA30,BA40,BA50, + * B9A8] == the original words at 0x801D8B74..0x801D8B8C. Bound `sltiu $v0,$v1,0x7` matches. + * The raw dlabel's 8th word 0x00000000 is NOT an entry — it is the intra-TU `.align 3` pad of the + * B34/B54/B74 jtbl chain; the object can never emit it (maspsx drops .align), so it must stay in + * the post-carve RAW data piece (the §53/§62/§81 carve chain applies at bank time). + * + * Same family as the TU's own already-matched func_8015AE2C: 7-case switch on ((s32 (*)(s32))func_801619A4)() + * (0/1/2/6 shared, 3/4/5 own, no default block — out-of-range and every `break` fall to the + * after-switch join), then a chain of "state handler" tests, each dispatching + * D_801876F8[*(u16*)arg0](arg0) and returning. + * + * THREE LEVERS (draft -> MATCH in 3 compiles): + * + * 1. PROLOGUE CONSTANT = an INITIALIZED LOCAL, not a literal in the compare. + * Target opens with `lui $s2, 0xFFF5` in the *prologue*, used once ~200 ins later in + * `slt $v0,$s2,$s1`. No gcc-2.7.2 pass hoists a (set reg const_int) across basic blocks + * (loop.c needs a loop; cse/combine/sched never move insns between BBs) — so the insn must + * have been EMITTED in the first BB, i.e. the constant is a local initialized at the top of + * the function. cse then cannot fold it back into the compare: the `slt` operand predicate is + * `arith_operand`, which rejects a CONST_INT wider than 16 bits, so validate_change fails and + * the pseudo survives. Its live range spans every call -> global.c gives it a callee-saved reg. + * Writing `z > -0xB0000` inline instead emits the `lui` into the branch delay slot next to the + * compare (caller-saved $v0) and the function is 1 insn short. => `s32 lim = -0xB0000;` at top. + * + * 2. `lh` vs `lhu`: a short->short copy is a pure HImode move and gcc emits `lhu`. The target's + * `lh $v0,0x26($s0)` means the value passed through an SImode (int) temp: expand makes + * (set (reg:SI) (sign_extend (mem:HI))) + (set (mem:HI) (subreg:HI ...)), and combine cannot + * merge them (the merged form is mem<-mem, which no movhi accepts) so the sign-extending load + * survives. => route both halfword copies through the `s32 t` temp. + * + * 3. THE `goto` LAYOUT — dodging jump.c's store-flag conversion (jump.c:1005-1065). + * An if/else chain writing 0/1 into `doit` makes gcc collapse the last pair into + * `sltiu $v0,$v0,1`. jump.c fires that conversion when the insn immediately after a + * conditional jump is a lone `SET pseudo, CONST_INT` whose following simplejump targets the + * SAME label as the branch (jump.c:1038 `reallabelprev == temp || ... JUMP_LABEL(temp4) == + * JUMP_LABEL(insn)`) — exactly the shape of `if (c) x=0; else x=1;`. + * The target instead cross-jumps ALL the `doit=0` exits into ONE shared block placed after the + * `doit=1` fall-through; reorg's fill_slots_from_thread then COPIES that single set into all + * three branch delay slots and redirects each branch past it (which is why `addu $v0,$zero, + * $zero` appears 3x in delay slots and the shared block vanishes). A `goto zero;` / `goto one;` + * chain expresses that layout directly, and each conditional jump is then followed by a + * compare/call rather than a lone const set, so the store-flag conversion never triggers. + * GENERAL RULE: multiple predicates that all assign the SAME constant to one flag => write + * them as `goto` to a shared assignment, never as an if/else ladder. + */ +extern s32 D_8011F9C4; +extern s32 D_8018768C; + +extern s32 func_80161B18(void); +extern s32 func_801619A4(s32*); +extern s32 func_80149AA8(s32*); +extern void func_80149AD4(s32*); +extern s32 func_80149B54(s32*); +extern void func_80149BAC(s32*); +extern s32 func_801498E0(s32*); +extern s32 func_80149954(s32); +extern s32 func_80149A64(s32*); +extern void func_800CCCC0(s32 a0); +extern s32 func_80149CD4(s32 a0); +extern void func_8015E880(s32*); +extern s32 func_80149744(struct S_80149744*); +extern void func_80149788(void); +extern s32 func_801496D4(void*); +extern void func_80149704(void); +extern int func_80148AFC(void*); +extern void func_80146D90(s32 a0); +extern void func_80154150(s32 a0, s32 a1); +extern void func_801541D8(u8*, s32, s32); +extern s32 func_801488A8(u8*); +extern void func_80147078(s32*, s16); +extern void func_8015A264(void*); +extern s32 func_80013294(void*, void*); +extern void func_80159B70(void*); +extern s32 func_8016F1AC(void); +extern s32 func_80029178(s32 a0); +extern void func_80146DB8(s32*, s32*); +extern s32 func_80161CD0(s32, s32); +extern s32 func_80161208(s32 a0); +extern s32 func_801725A4(u8*); + +s32 func_8015B950(s32 arg0) +{ + + extern void (*D_801876F8[])(void *); + s16 sp10[4]; + s16 sp18[4]; + s32 t; + s32 z; + s32 doit; + s32 lim = -0xB0000; + + if (func_80161B18() != 0) { + return; + } + switch (((s32 (*)(s32))func_801619A4)(arg0)) { + case 0: + case 1: + case 2: + case 6: + if (((s32 (*)(s32))func_80149AA8)(arg0) != 0) { + D_801876F8[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149AD4)(arg0); + return; + } + if (((s32 (*)(s32))func_80149B54)(arg0) != 0) { + D_801876F8[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149BAC)(arg0); + return; + } + break; + case 3: + ((void (*)(s32))func_801498E0)(arg0); + break; + case 4: + ((void (*)(s32))func_80149954)(arg0); + break; + case 5: + if (((s32 (*)(s32))func_80149A64)(arg0) != 0) { + D_801876F8[*(u16 *)arg0]((void *)arg0); + func_800CCCC0(arg0); + return; + } + break; + } + if (func_80149CD4(arg0) != 0) { + D_801876F8[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_8015E880)(arg0); + return; + } + if (((s32 (*)(s32))func_80149744)(arg0) != 0) { + D_801876F8[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149788)(arg0); + return; + } + if (((s32 (*)(s32))func_801496D4)(arg0) != 0) { + D_801876F8[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149704)(arg0); + if (((u8)((s32 (*)(s32))func_80148AFC)(arg0)) == 0) { + func_80146D90(arg0); + } + if ((*(s32 *)(arg0 + 0x24) | *(s32 *)(arg0 + 0x2C)) != 0) { + func_80154150(arg0, 0xF); + } else { + ((void (*)(s32, s32, s32))func_801541D8)(arg0, 0xD, 6); + } + *(s32 *)(arg0 + 0x238) = 1; + return; + } + if (((s32 (*)(s32))func_801488A8)(arg0) != 0) { + sp10[0] = 0; + sp10[1] = 0; + sp10[2] = 0; + t = *(s16 *)(arg0 + 0x26); + sp18[0] = t; + sp18[1] = 0; + t = *(s16 *)(arg0 + 0x2E); + sp18[2] = t; + D_801876F8[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 1); + ((void (*)(s32))func_8015A264)(arg0); + t = -(((s32 (*)(s16 *, s16 *))func_80013294)(sp10, sp18) << 0x10); + if (t < *(s32 *)(arg0 + 0x2C)) { + *(s32 *)(arg0 + 0x2C) = t; + } + return; + } + if (*(u16 *)(arg0 + 0xB8) == 0x8000) { + D_801876F8[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 0); + ((void (*)(s32))func_80159B70)(arg0); + return; + } + z = *(s32 *)(arg0 + 0x2C); + if (func_8016F1AC() != 0) { + goto zero; + } + if (z <= lim) { + goto one; + } + if (D_8011F9C4 == 0) { + goto zero; + } + if (((u8)func_80029178(0x21)) != 0) { + goto zero; + } +one: + doit = 1; + goto join; +zero: + doit = 0; +join: + if (doit != 0) { + D_801876F8[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 0); + ((void (*)(s32))func_80159B70)(arg0); + func_80154150(arg0, 9); + ((void (*)(s32, s32 *))func_80146DB8)(arg0, &D_8018768C); + ((void (*)(s32, s32))func_80161CD0)(arg0, *(u16 *)(arg0 + 0x16E)); + return; + } + if (func_80161208(arg0) == 0) { + ((void (*)(s32))func_801725A4)(arg0); + } +} DEFINE_func_8015BD8C() /* dedup: shared engine-core @0x8015BD8C (src/shared) */ diff --git a/src/ov_SC06_022/ov_SC06_022_jr_8015AE2C.c b/src/ov_SC06_022/ov_SC06_022_jr_8015AE2C.c index 98f3b544f..e2ae78419 100644 --- a/src/ov_SC06_022/ov_SC06_022_jr_8015AE2C.c +++ b/src/ov_SC06_022/ov_SC06_022_jr_8015AE2C.c @@ -1512,7 +1512,259 @@ DEFINE_func_8015B858() /* dedup: shared engine-core @0x8015B858 (src/shared) */ DEFINE_func_8015B8F8() /* dedup: shared engine-core @0x8015B8F8 (src/shared) */ -INCLUDE_ASM("asm/ov_SC06_022/nonmatchings/ov_SC06_022_jr_8015AE2C", func_8015B950); +extern s32 func_8015AE2C(); + +// @class: plumbing +// @stuck: none — MATCH (271/271, pin-free, zero asm). The ONLY residual is DEF-SIDE plumbing, and it is now named exactly: the in-TU instantiation `DEFINE_func_8015BEE4()` (engine_core.h:1851-1855) expands to `extern s32 func_8015B950(void);` INSIDE ov_SC01_077_jr_8015AE2C.c, ~14 lines BELOW this definition, so the 1-param def collides with a `(void)` prototype -> `conflicting types for func_8015B950` (.run/bank_func_8015B950.log). §73 PARAMS axis / T0. Surgical fix = §65b de-macroize that ONE instantiation (blast radius: this TU); the fleet-wide `(void)`->`()` header edit is §63 and must be R22-validated. +/* func_8015B950 (ov_SC01_077_jr_8015AE2C, 271 ins, jtbl_801D8B74) — SESSION-21 re-verified + * + * ── ROUND-2 INDEPENDENT RE-VERIFICATION (2026-07-27, fresh agent, §88e discipline) ───────────── + * match_one : MATCH (271 ins) against the CURRENT tree — §87 staleness re-checked today. + * .text size: compiled .text = 0x43C = 1084 B = 271 ins, EXACTLY the target's declared 0x43C + * ("nonmatching func_8015B950, 0x43C"). So this is NOT a §83a length drift hiding + * behind a zero count — the count is over equal-length streams. + * jtbl : RE-DECODED MECHANICALLY, not inherited. Compiled .rodata = 0x1C = 28 B = 7 words, + * 7x R_MIPS_32 -> .text with implicit addends [58,58,58,E0,F0,100,58]; +0x8015B950 + * = [8015B9A8, 8015B9A8, 8015B9A8, 8015BA30, 8015BA40, 8015BA50, 8015B9A8]. + * Diffed word-for-word against asm/ov_SC01_077/data/tail14.data.s:15-23 — 7/7 identical. + * symcheck : SYMS-DIFF target=35 draft=34, sole MISSING = jtbl_801D8B74. This is the §81 jr + * FALSE POSITIVE, re-confirmed here by reading the relocs: gcc emits its OWN table and + * references it with R_MIPS_HI16/LO16 against the SECTION `.rodata` (t.o +0x40/+0x48), + * so the splat's dlabel NAME can never appear in the draft object's relocation set. + * Nothing is dropped and nothing is invented: the draft's other 34 symbols are exactly + * the target's other 34. + * FAMILY : the x138 remap is clean and §84-safe. Every sibling is 271 ins with an IDENTICAL + * callee set; only THREE names vary per overlay — the two data labels and the jtbl: + * ov_SC01_077 D_8018F948 / D_8018F9B4 / jtbl_801D8B74 + * ov_SC03_099 D_80185A50 / D_80185ABC / jtbl_801BD898 + * ov_SC06_008 D_80187E44 / D_80187EB0 / jtbl_801A8734 + * The pair is always +0x6C apart, and NO literal in this draft encodes that distance + * (both labels are referenced by name), so there is no §84 derived-offset hazard. + * D_8011F9C4 is fleet-constant (main-EXE data) and must NOT be remapped. + * + * match_one: MATCH (271 ins) against the CURRENT tree (§87 staleness re-checked, 2026-07-27). + * PIN-FREE, zero asm, offset-pure (s32 arg0 + raw offsets) — x138 template-safe. + * Provenance: this is the Phase-26 crack (.run/phase26-cracks/func_8015B950.c) re-gated verbatim, + * with ONE deliberate change: the definition's return type void -> s32. + * - `void func_8015B950(s32 arg0)` : MATCH (271 ins) [the Phase-26 form] + * - `s32 func_8015B950(s32 arg0)` : MATCH (271 ins) [shipped — §3a-1 void->s32 is byte-neutral] + * The fleet/engine_core.h canonical decl is `extern s32 func_8015B950(void);` (engine_core.h:1852), + * and the last bank attempt (.run/bank_func_8015B950.log) died on `conflicting types for + * func_8015B950`. Shipping the s32 return kills the §73 RETURN axis for free and leaves only the + * cheap T0 PARAMS axis for the ladder (fix_header_decl.py / --fix-def-sig / cast_call_sites). + * Both forms are byte-identical, so the orchestrator may swap the return type back at zero cost. + * + * SYMBOLS (§58 rules 1/2 — all splat spellings, all verified present): + * D_8018F9B4 asm/ov_SC01_077/data/tail.data.s:4355 (the state-handler vtable) + * D_8018F948 asm/ov_SC01_077/data/tail.data.s:4293 + * D_8011F9C4 main-EXE data; spelled `extern s32 D_8011F9C4;` in 5+ already-banked TUs + * jtbl_801D8B74 asm/ov_SC01_077/data/tail14.data.s:15 (compiler jump table — not named in C) + * + * JTBL VERIFIED (§8a gate): compiled .rodata = exactly 0x1C B / 7 words, 7x R_MIPS_32 .text with + * addends [0x58,0x58,0x58,0xE0,0xF0,0x100,0x58] -> +0x8015B950 = [B9A8,B9A8,B9A8,BA30,BA40,BA50, + * B9A8] == the original words at 0x801D8B74..0x801D8B8C. Bound `sltiu $v0,$v1,0x7` matches. + * The raw dlabel's 8th word 0x00000000 is NOT an entry — it is the intra-TU `.align 3` pad of the + * B34/B54/B74 jtbl chain; the object can never emit it (maspsx drops .align), so it must stay in + * the post-carve RAW data piece (the §53/§62/§81 carve chain applies at bank time). + * + * Same family as the TU's own already-matched func_8015AE2C: 7-case switch on ((s32 (*)(s32))func_801619A4)() + * (0/1/2/6 shared, 3/4/5 own, no default block — out-of-range and every `break` fall to the + * after-switch join), then a chain of "state handler" tests, each dispatching + * D_8018F9B4[*(u16*)arg0](arg0) and returning. + * + * THREE LEVERS (draft -> MATCH in 3 compiles): + * + * 1. PROLOGUE CONSTANT = an INITIALIZED LOCAL, not a literal in the compare. + * Target opens with `lui $s2, 0xFFF5` in the *prologue*, used once ~200 ins later in + * `slt $v0,$s2,$s1`. No gcc-2.7.2 pass hoists a (set reg const_int) across basic blocks + * (loop.c needs a loop; cse/combine/sched never move insns between BBs) — so the insn must + * have been EMITTED in the first BB, i.e. the constant is a local initialized at the top of + * the function. cse then cannot fold it back into the compare: the `slt` operand predicate is + * `arith_operand`, which rejects a CONST_INT wider than 16 bits, so validate_change fails and + * the pseudo survives. Its live range spans every call -> global.c gives it a callee-saved reg. + * Writing `z > -0xB0000` inline instead emits the `lui` into the branch delay slot next to the + * compare (caller-saved $v0) and the function is 1 insn short. => `s32 lim = -0xB0000;` at top. + * + * 2. `lh` vs `lhu`: a short->short copy is a pure HImode move and gcc emits `lhu`. The target's + * `lh $v0,0x26($s0)` means the value passed through an SImode (int) temp: expand makes + * (set (reg:SI) (sign_extend (mem:HI))) + (set (mem:HI) (subreg:HI ...)), and combine cannot + * merge them (the merged form is mem<-mem, which no movhi accepts) so the sign-extending load + * survives. => route both halfword copies through the `s32 t` temp. + * + * 3. THE `goto` LAYOUT — dodging jump.c's store-flag conversion (jump.c:1005-1065). + * An if/else chain writing 0/1 into `doit` makes gcc collapse the last pair into + * `sltiu $v0,$v0,1`. jump.c fires that conversion when the insn immediately after a + * conditional jump is a lone `SET pseudo, CONST_INT` whose following simplejump targets the + * SAME label as the branch (jump.c:1038 `reallabelprev == temp || ... JUMP_LABEL(temp4) == + * JUMP_LABEL(insn)`) — exactly the shape of `if (c) x=0; else x=1;`. + * The target instead cross-jumps ALL the `doit=0` exits into ONE shared block placed after the + * `doit=1` fall-through; reorg's fill_slots_from_thread then COPIES that single set into all + * three branch delay slots and redirects each branch past it (which is why `addu $v0,$zero, + * $zero` appears 3x in delay slots and the shared block vanishes). A `goto zero;` / `goto one;` + * chain expresses that layout directly, and each conditional jump is then followed by a + * compare/call rather than a lone const set, so the store-flag conversion never triggers. + * GENERAL RULE: multiple predicates that all assign the SAME constant to one flag => write + * them as `goto` to a shared assignment, never as an if/else ladder. + */ +extern s32 D_8011F9C4; +extern s32 D_8018F948; + +extern s32 func_80161B18(void); +extern s32 func_801619A4(s32*); +extern s32 func_80149AA8(s32*); +extern void func_80149AD4(s32*); +extern s32 func_80149B54(s32*); +extern void func_80149BAC(s32*); +extern s32 func_801498E0(s32*); +extern s32 func_80149954(s32); +extern s32 func_80149A64(s32*); +extern void func_800CCCC0(s32 a0); +extern s32 func_80149CD4(s32 a0); +extern void func_8015E880(s32*); +extern s32 func_80149744(struct S_80149744*); +extern void func_80149788(void); +extern s32 func_801496D4(void*); +extern void func_80149704(void); +extern int func_80148AFC(void*); +extern void func_80146D90(s32 a0); +extern void func_80154150(s32 a0, s32 a1); +extern void func_801541D8(u8*, s32, s32); +extern s32 func_801488A8(u8*); +extern void func_80147078(s32*, s16); +extern void func_8015A264(void*); +extern s32 func_80013294(void*, void*); +extern void func_80159B70(void*); +extern s32 func_8016F1AC(void); +extern s32 func_80029178(s32 a0); +extern void func_80146DB8(s32*, s32*); +extern s32 func_80161CD0(s32, s32); +extern s32 func_80161208(s32 a0); +extern s32 func_801725A4(u8*); + +s32 func_8015B950(s32 arg0) +{ + + extern void (*D_8018F9B4[])(void *); + s16 sp10[4]; + s16 sp18[4]; + s32 t; + s32 z; + s32 doit; + s32 lim = -0xB0000; + + if (func_80161B18() != 0) { + return; + } + switch (((s32 (*)(s32))func_801619A4)(arg0)) { + case 0: + case 1: + case 2: + case 6: + if (((s32 (*)(s32))func_80149AA8)(arg0) != 0) { + D_8018F9B4[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149AD4)(arg0); + return; + } + if (((s32 (*)(s32))func_80149B54)(arg0) != 0) { + D_8018F9B4[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149BAC)(arg0); + return; + } + break; + case 3: + ((void (*)(s32))func_801498E0)(arg0); + break; + case 4: + ((void (*)(s32))func_80149954)(arg0); + break; + case 5: + if (((s32 (*)(s32))func_80149A64)(arg0) != 0) { + D_8018F9B4[*(u16 *)arg0]((void *)arg0); + func_800CCCC0(arg0); + return; + } + break; + } + if (func_80149CD4(arg0) != 0) { + D_8018F9B4[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_8015E880)(arg0); + return; + } + if (((s32 (*)(s32))func_80149744)(arg0) != 0) { + D_8018F9B4[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149788)(arg0); + return; + } + if (((s32 (*)(s32))func_801496D4)(arg0) != 0) { + D_8018F9B4[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149704)(arg0); + if (((u8)((s32 (*)(s32))func_80148AFC)(arg0)) == 0) { + func_80146D90(arg0); + } + if ((*(s32 *)(arg0 + 0x24) | *(s32 *)(arg0 + 0x2C)) != 0) { + func_80154150(arg0, 0xF); + } else { + ((void (*)(s32, s32, s32))func_801541D8)(arg0, 0xD, 6); + } + *(s32 *)(arg0 + 0x238) = 1; + return; + } + if (((s32 (*)(s32))func_801488A8)(arg0) != 0) { + sp10[0] = 0; + sp10[1] = 0; + sp10[2] = 0; + t = *(s16 *)(arg0 + 0x26); + sp18[0] = t; + sp18[1] = 0; + t = *(s16 *)(arg0 + 0x2E); + sp18[2] = t; + D_8018F9B4[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 1); + ((void (*)(s32))func_8015A264)(arg0); + t = -(((s32 (*)(s16 *, s16 *))func_80013294)(sp10, sp18) << 0x10); + if (t < *(s32 *)(arg0 + 0x2C)) { + *(s32 *)(arg0 + 0x2C) = t; + } + return; + } + if (*(u16 *)(arg0 + 0xB8) == 0x8000) { + D_8018F9B4[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 0); + ((void (*)(s32))func_80159B70)(arg0); + return; + } + z = *(s32 *)(arg0 + 0x2C); + if (func_8016F1AC() != 0) { + goto zero; + } + if (z <= lim) { + goto one; + } + if (D_8011F9C4 == 0) { + goto zero; + } + if (((u8)func_80029178(0x21)) != 0) { + goto zero; + } +one: + doit = 1; + goto join; +zero: + doit = 0; +join: + if (doit != 0) { + D_8018F9B4[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 0); + ((void (*)(s32))func_80159B70)(arg0); + func_80154150(arg0, 9); + ((void (*)(s32, s32 *))func_80146DB8)(arg0, &D_8018F948); + ((void (*)(s32, s32))func_80161CD0)(arg0, *(u16 *)(arg0 + 0x16E)); + return; + } + if (func_80161208(arg0) == 0) { + ((void (*)(s32))func_801725A4)(arg0); + } +} DEFINE_func_8015BD8C() /* dedup: shared engine-core @0x8015BD8C (src/shared) */ diff --git a/src/ov_SC06_024/ov_SC06_024_jr_8015AE2C.c b/src/ov_SC06_024/ov_SC06_024_jr_8015AE2C.c index aa64e7663..50e7127a0 100644 --- a/src/ov_SC06_024/ov_SC06_024_jr_8015AE2C.c +++ b/src/ov_SC06_024/ov_SC06_024_jr_8015AE2C.c @@ -1512,7 +1512,259 @@ DEFINE_func_8015B858() /* dedup: shared engine-core @0x8015B858 (src/shared) */ DEFINE_func_8015B8F8() /* dedup: shared engine-core @0x8015B8F8 (src/shared) */ -INCLUDE_ASM("asm/ov_SC06_024/nonmatchings/ov_SC06_024_jr_8015AE2C", func_8015B950); +extern s32 func_8015AE2C(); + +// @class: plumbing +// @stuck: none — MATCH (271/271, pin-free, zero asm). The ONLY residual is DEF-SIDE plumbing, and it is now named exactly: the in-TU instantiation `DEFINE_func_8015BEE4()` (engine_core.h:1851-1855) expands to `extern s32 func_8015B950(void);` INSIDE ov_SC01_077_jr_8015AE2C.c, ~14 lines BELOW this definition, so the 1-param def collides with a `(void)` prototype -> `conflicting types for func_8015B950` (.run/bank_func_8015B950.log). §73 PARAMS axis / T0. Surgical fix = §65b de-macroize that ONE instantiation (blast radius: this TU); the fleet-wide `(void)`->`()` header edit is §63 and must be R22-validated. +/* func_8015B950 (ov_SC01_077_jr_8015AE2C, 271 ins, jtbl_801D8B74) — SESSION-21 re-verified + * + * ── ROUND-2 INDEPENDENT RE-VERIFICATION (2026-07-27, fresh agent, §88e discipline) ───────────── + * match_one : MATCH (271 ins) against the CURRENT tree — §87 staleness re-checked today. + * .text size: compiled .text = 0x43C = 1084 B = 271 ins, EXACTLY the target's declared 0x43C + * ("nonmatching func_8015B950, 0x43C"). So this is NOT a §83a length drift hiding + * behind a zero count — the count is over equal-length streams. + * jtbl : RE-DECODED MECHANICALLY, not inherited. Compiled .rodata = 0x1C = 28 B = 7 words, + * 7x R_MIPS_32 -> .text with implicit addends [58,58,58,E0,F0,100,58]; +0x8015B950 + * = [8015B9A8, 8015B9A8, 8015B9A8, 8015BA30, 8015BA40, 8015BA50, 8015B9A8]. + * Diffed word-for-word against asm/ov_SC01_077/data/tail14.data.s:15-23 — 7/7 identical. + * symcheck : SYMS-DIFF target=35 draft=34, sole MISSING = jtbl_801D8B74. This is the §81 jr + * FALSE POSITIVE, re-confirmed here by reading the relocs: gcc emits its OWN table and + * references it with R_MIPS_HI16/LO16 against the SECTION `.rodata` (t.o +0x40/+0x48), + * so the splat's dlabel NAME can never appear in the draft object's relocation set. + * Nothing is dropped and nothing is invented: the draft's other 34 symbols are exactly + * the target's other 34. + * FAMILY : the x138 remap is clean and §84-safe. Every sibling is 271 ins with an IDENTICAL + * callee set; only THREE names vary per overlay — the two data labels and the jtbl: + * ov_SC01_077 D_80191E20 / D_80191E8C / jtbl_801D8B74 + * ov_SC03_099 D_80185A50 / D_80185ABC / jtbl_801BD898 + * ov_SC06_008 D_80187E44 / D_80187EB0 / jtbl_801A8734 + * The pair is always +0x6C apart, and NO literal in this draft encodes that distance + * (both labels are referenced by name), so there is no §84 derived-offset hazard. + * D_8011F9C4 is fleet-constant (main-EXE data) and must NOT be remapped. + * + * match_one: MATCH (271 ins) against the CURRENT tree (§87 staleness re-checked, 2026-07-27). + * PIN-FREE, zero asm, offset-pure (s32 arg0 + raw offsets) — x138 template-safe. + * Provenance: this is the Phase-26 crack (.run/phase26-cracks/func_8015B950.c) re-gated verbatim, + * with ONE deliberate change: the definition's return type void -> s32. + * - `void func_8015B950(s32 arg0)` : MATCH (271 ins) [the Phase-26 form] + * - `s32 func_8015B950(s32 arg0)` : MATCH (271 ins) [shipped — §3a-1 void->s32 is byte-neutral] + * The fleet/engine_core.h canonical decl is `extern s32 func_8015B950(void);` (engine_core.h:1852), + * and the last bank attempt (.run/bank_func_8015B950.log) died on `conflicting types for + * func_8015B950`. Shipping the s32 return kills the §73 RETURN axis for free and leaves only the + * cheap T0 PARAMS axis for the ladder (fix_header_decl.py / --fix-def-sig / cast_call_sites). + * Both forms are byte-identical, so the orchestrator may swap the return type back at zero cost. + * + * SYMBOLS (§58 rules 1/2 — all splat spellings, all verified present): + * D_80191E8C asm/ov_SC01_077/data/tail.data.s:4355 (the state-handler vtable) + * D_80191E20 asm/ov_SC01_077/data/tail.data.s:4293 + * D_8011F9C4 main-EXE data; spelled `extern s32 D_8011F9C4;` in 5+ already-banked TUs + * jtbl_801D8B74 asm/ov_SC01_077/data/tail14.data.s:15 (compiler jump table — not named in C) + * + * JTBL VERIFIED (§8a gate): compiled .rodata = exactly 0x1C B / 7 words, 7x R_MIPS_32 .text with + * addends [0x58,0x58,0x58,0xE0,0xF0,0x100,0x58] -> +0x8015B950 = [B9A8,B9A8,B9A8,BA30,BA40,BA50, + * B9A8] == the original words at 0x801D8B74..0x801D8B8C. Bound `sltiu $v0,$v1,0x7` matches. + * The raw dlabel's 8th word 0x00000000 is NOT an entry — it is the intra-TU `.align 3` pad of the + * B34/B54/B74 jtbl chain; the object can never emit it (maspsx drops .align), so it must stay in + * the post-carve RAW data piece (the §53/§62/§81 carve chain applies at bank time). + * + * Same family as the TU's own already-matched func_8015AE2C: 7-case switch on ((s32 (*)(s32))func_801619A4)() + * (0/1/2/6 shared, 3/4/5 own, no default block — out-of-range and every `break` fall to the + * after-switch join), then a chain of "state handler" tests, each dispatching + * D_80191E8C[*(u16*)arg0](arg0) and returning. + * + * THREE LEVERS (draft -> MATCH in 3 compiles): + * + * 1. PROLOGUE CONSTANT = an INITIALIZED LOCAL, not a literal in the compare. + * Target opens with `lui $s2, 0xFFF5` in the *prologue*, used once ~200 ins later in + * `slt $v0,$s2,$s1`. No gcc-2.7.2 pass hoists a (set reg const_int) across basic blocks + * (loop.c needs a loop; cse/combine/sched never move insns between BBs) — so the insn must + * have been EMITTED in the first BB, i.e. the constant is a local initialized at the top of + * the function. cse then cannot fold it back into the compare: the `slt` operand predicate is + * `arith_operand`, which rejects a CONST_INT wider than 16 bits, so validate_change fails and + * the pseudo survives. Its live range spans every call -> global.c gives it a callee-saved reg. + * Writing `z > -0xB0000` inline instead emits the `lui` into the branch delay slot next to the + * compare (caller-saved $v0) and the function is 1 insn short. => `s32 lim = -0xB0000;` at top. + * + * 2. `lh` vs `lhu`: a short->short copy is a pure HImode move and gcc emits `lhu`. The target's + * `lh $v0,0x26($s0)` means the value passed through an SImode (int) temp: expand makes + * (set (reg:SI) (sign_extend (mem:HI))) + (set (mem:HI) (subreg:HI ...)), and combine cannot + * merge them (the merged form is mem<-mem, which no movhi accepts) so the sign-extending load + * survives. => route both halfword copies through the `s32 t` temp. + * + * 3. THE `goto` LAYOUT — dodging jump.c's store-flag conversion (jump.c:1005-1065). + * An if/else chain writing 0/1 into `doit` makes gcc collapse the last pair into + * `sltiu $v0,$v0,1`. jump.c fires that conversion when the insn immediately after a + * conditional jump is a lone `SET pseudo, CONST_INT` whose following simplejump targets the + * SAME label as the branch (jump.c:1038 `reallabelprev == temp || ... JUMP_LABEL(temp4) == + * JUMP_LABEL(insn)`) — exactly the shape of `if (c) x=0; else x=1;`. + * The target instead cross-jumps ALL the `doit=0` exits into ONE shared block placed after the + * `doit=1` fall-through; reorg's fill_slots_from_thread then COPIES that single set into all + * three branch delay slots and redirects each branch past it (which is why `addu $v0,$zero, + * $zero` appears 3x in delay slots and the shared block vanishes). A `goto zero;` / `goto one;` + * chain expresses that layout directly, and each conditional jump is then followed by a + * compare/call rather than a lone const set, so the store-flag conversion never triggers. + * GENERAL RULE: multiple predicates that all assign the SAME constant to one flag => write + * them as `goto` to a shared assignment, never as an if/else ladder. + */ +extern s32 D_8011F9C4; +extern s32 D_80191E20; + +extern s32 func_80161B18(void); +extern s32 func_801619A4(s32*); +extern s32 func_80149AA8(s32*); +extern void func_80149AD4(s32*); +extern s32 func_80149B54(s32*); +extern void func_80149BAC(s32*); +extern s32 func_801498E0(s32*); +extern s32 func_80149954(s32); +extern s32 func_80149A64(s32*); +extern void func_800CCCC0(s32 a0); +extern s32 func_80149CD4(s32 a0); +extern void func_8015E880(s32*); +extern s32 func_80149744(struct S_80149744*); +extern void func_80149788(void); +extern s32 func_801496D4(void*); +extern void func_80149704(void); +extern int func_80148AFC(void*); +extern void func_80146D90(s32 a0); +extern void func_80154150(s32 a0, s32 a1); +extern void func_801541D8(u8*, s32, s32); +extern s32 func_801488A8(u8*); +extern void func_80147078(s32*, s16); +extern void func_8015A264(void*); +extern s32 func_80013294(void*, void*); +extern void func_80159B70(void*); +extern s32 func_8016F1AC(void); +extern s32 func_80029178(s32 a0); +extern void func_80146DB8(s32*, s32*); +extern s32 func_80161CD0(s32, s32); +extern s32 func_80161208(s32 a0); +extern s32 func_801725A4(u8*); + +s32 func_8015B950(s32 arg0) +{ + + extern void (*D_80191E8C[])(void *); + s16 sp10[4]; + s16 sp18[4]; + s32 t; + s32 z; + s32 doit; + s32 lim = -0xB0000; + + if (func_80161B18() != 0) { + return; + } + switch (((s32 (*)(s32))func_801619A4)(arg0)) { + case 0: + case 1: + case 2: + case 6: + if (((s32 (*)(s32))func_80149AA8)(arg0) != 0) { + D_80191E8C[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149AD4)(arg0); + return; + } + if (((s32 (*)(s32))func_80149B54)(arg0) != 0) { + D_80191E8C[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149BAC)(arg0); + return; + } + break; + case 3: + ((void (*)(s32))func_801498E0)(arg0); + break; + case 4: + ((void (*)(s32))func_80149954)(arg0); + break; + case 5: + if (((s32 (*)(s32))func_80149A64)(arg0) != 0) { + D_80191E8C[*(u16 *)arg0]((void *)arg0); + func_800CCCC0(arg0); + return; + } + break; + } + if (func_80149CD4(arg0) != 0) { + D_80191E8C[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_8015E880)(arg0); + return; + } + if (((s32 (*)(s32))func_80149744)(arg0) != 0) { + D_80191E8C[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149788)(arg0); + return; + } + if (((s32 (*)(s32))func_801496D4)(arg0) != 0) { + D_80191E8C[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149704)(arg0); + if (((u8)((s32 (*)(s32))func_80148AFC)(arg0)) == 0) { + func_80146D90(arg0); + } + if ((*(s32 *)(arg0 + 0x24) | *(s32 *)(arg0 + 0x2C)) != 0) { + func_80154150(arg0, 0xF); + } else { + ((void (*)(s32, s32, s32))func_801541D8)(arg0, 0xD, 6); + } + *(s32 *)(arg0 + 0x238) = 1; + return; + } + if (((s32 (*)(s32))func_801488A8)(arg0) != 0) { + sp10[0] = 0; + sp10[1] = 0; + sp10[2] = 0; + t = *(s16 *)(arg0 + 0x26); + sp18[0] = t; + sp18[1] = 0; + t = *(s16 *)(arg0 + 0x2E); + sp18[2] = t; + D_80191E8C[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 1); + ((void (*)(s32))func_8015A264)(arg0); + t = -(((s32 (*)(s16 *, s16 *))func_80013294)(sp10, sp18) << 0x10); + if (t < *(s32 *)(arg0 + 0x2C)) { + *(s32 *)(arg0 + 0x2C) = t; + } + return; + } + if (*(u16 *)(arg0 + 0xB8) == 0x8000) { + D_80191E8C[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 0); + ((void (*)(s32))func_80159B70)(arg0); + return; + } + z = *(s32 *)(arg0 + 0x2C); + if (func_8016F1AC() != 0) { + goto zero; + } + if (z <= lim) { + goto one; + } + if (D_8011F9C4 == 0) { + goto zero; + } + if (((u8)func_80029178(0x21)) != 0) { + goto zero; + } +one: + doit = 1; + goto join; +zero: + doit = 0; +join: + if (doit != 0) { + D_80191E8C[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 0); + ((void (*)(s32))func_80159B70)(arg0); + func_80154150(arg0, 9); + ((void (*)(s32, s32 *))func_80146DB8)(arg0, &D_80191E20); + ((void (*)(s32, s32))func_80161CD0)(arg0, *(u16 *)(arg0 + 0x16E)); + return; + } + if (func_80161208(arg0) == 0) { + ((void (*)(s32))func_801725A4)(arg0); + } +} DEFINE_func_8015BD8C() /* dedup: shared engine-core @0x8015BD8C (src/shared) */ diff --git a/src/ov_SC06_025/ov_SC06_025_jr_8015AE2C.c b/src/ov_SC06_025/ov_SC06_025_jr_8015AE2C.c index 5460aa306..989f466b4 100644 --- a/src/ov_SC06_025/ov_SC06_025_jr_8015AE2C.c +++ b/src/ov_SC06_025/ov_SC06_025_jr_8015AE2C.c @@ -1512,7 +1512,259 @@ DEFINE_func_8015B858() /* dedup: shared engine-core @0x8015B858 (src/shared) */ DEFINE_func_8015B8F8() /* dedup: shared engine-core @0x8015B8F8 (src/shared) */ -INCLUDE_ASM("asm/ov_SC06_025/nonmatchings/ov_SC06_025_jr_8015AE2C", func_8015B950); +extern s32 func_8015AE2C(); + +// @class: plumbing +// @stuck: none — MATCH (271/271, pin-free, zero asm). The ONLY residual is DEF-SIDE plumbing, and it is now named exactly: the in-TU instantiation `DEFINE_func_8015BEE4()` (engine_core.h:1851-1855) expands to `extern s32 func_8015B950(void);` INSIDE ov_SC01_077_jr_8015AE2C.c, ~14 lines BELOW this definition, so the 1-param def collides with a `(void)` prototype -> `conflicting types for func_8015B950` (.run/bank_func_8015B950.log). §73 PARAMS axis / T0. Surgical fix = §65b de-macroize that ONE instantiation (blast radius: this TU); the fleet-wide `(void)`->`()` header edit is §63 and must be R22-validated. +/* func_8015B950 (ov_SC01_077_jr_8015AE2C, 271 ins, jtbl_801D8B74) — SESSION-21 re-verified + * + * ── ROUND-2 INDEPENDENT RE-VERIFICATION (2026-07-27, fresh agent, §88e discipline) ───────────── + * match_one : MATCH (271 ins) against the CURRENT tree — §87 staleness re-checked today. + * .text size: compiled .text = 0x43C = 1084 B = 271 ins, EXACTLY the target's declared 0x43C + * ("nonmatching func_8015B950, 0x43C"). So this is NOT a §83a length drift hiding + * behind a zero count — the count is over equal-length streams. + * jtbl : RE-DECODED MECHANICALLY, not inherited. Compiled .rodata = 0x1C = 28 B = 7 words, + * 7x R_MIPS_32 -> .text with implicit addends [58,58,58,E0,F0,100,58]; +0x8015B950 + * = [8015B9A8, 8015B9A8, 8015B9A8, 8015BA30, 8015BA40, 8015BA50, 8015B9A8]. + * Diffed word-for-word against asm/ov_SC01_077/data/tail14.data.s:15-23 — 7/7 identical. + * symcheck : SYMS-DIFF target=35 draft=34, sole MISSING = jtbl_801D8B74. This is the §81 jr + * FALSE POSITIVE, re-confirmed here by reading the relocs: gcc emits its OWN table and + * references it with R_MIPS_HI16/LO16 against the SECTION `.rodata` (t.o +0x40/+0x48), + * so the splat's dlabel NAME can never appear in the draft object's relocation set. + * Nothing is dropped and nothing is invented: the draft's other 34 symbols are exactly + * the target's other 34. + * FAMILY : the x138 remap is clean and §84-safe. Every sibling is 271 ins with an IDENTICAL + * callee set; only THREE names vary per overlay — the two data labels and the jtbl: + * ov_SC01_077 D_801872C4 / D_80187330 / jtbl_801D8B74 + * ov_SC03_099 D_80185A50 / D_80185ABC / jtbl_801BD898 + * ov_SC06_008 D_80187E44 / D_80187EB0 / jtbl_801A8734 + * The pair is always +0x6C apart, and NO literal in this draft encodes that distance + * (both labels are referenced by name), so there is no §84 derived-offset hazard. + * D_8011F9C4 is fleet-constant (main-EXE data) and must NOT be remapped. + * + * match_one: MATCH (271 ins) against the CURRENT tree (§87 staleness re-checked, 2026-07-27). + * PIN-FREE, zero asm, offset-pure (s32 arg0 + raw offsets) — x138 template-safe. + * Provenance: this is the Phase-26 crack (.run/phase26-cracks/func_8015B950.c) re-gated verbatim, + * with ONE deliberate change: the definition's return type void -> s32. + * - `void func_8015B950(s32 arg0)` : MATCH (271 ins) [the Phase-26 form] + * - `s32 func_8015B950(s32 arg0)` : MATCH (271 ins) [shipped — §3a-1 void->s32 is byte-neutral] + * The fleet/engine_core.h canonical decl is `extern s32 func_8015B950(void);` (engine_core.h:1852), + * and the last bank attempt (.run/bank_func_8015B950.log) died on `conflicting types for + * func_8015B950`. Shipping the s32 return kills the §73 RETURN axis for free and leaves only the + * cheap T0 PARAMS axis for the ladder (fix_header_decl.py / --fix-def-sig / cast_call_sites). + * Both forms are byte-identical, so the orchestrator may swap the return type back at zero cost. + * + * SYMBOLS (§58 rules 1/2 — all splat spellings, all verified present): + * D_80187330 asm/ov_SC01_077/data/tail.data.s:4355 (the state-handler vtable) + * D_801872C4 asm/ov_SC01_077/data/tail.data.s:4293 + * D_8011F9C4 main-EXE data; spelled `extern s32 D_8011F9C4;` in 5+ already-banked TUs + * jtbl_801D8B74 asm/ov_SC01_077/data/tail14.data.s:15 (compiler jump table — not named in C) + * + * JTBL VERIFIED (§8a gate): compiled .rodata = exactly 0x1C B / 7 words, 7x R_MIPS_32 .text with + * addends [0x58,0x58,0x58,0xE0,0xF0,0x100,0x58] -> +0x8015B950 = [B9A8,B9A8,B9A8,BA30,BA40,BA50, + * B9A8] == the original words at 0x801D8B74..0x801D8B8C. Bound `sltiu $v0,$v1,0x7` matches. + * The raw dlabel's 8th word 0x00000000 is NOT an entry — it is the intra-TU `.align 3` pad of the + * B34/B54/B74 jtbl chain; the object can never emit it (maspsx drops .align), so it must stay in + * the post-carve RAW data piece (the §53/§62/§81 carve chain applies at bank time). + * + * Same family as the TU's own already-matched func_8015AE2C: 7-case switch on ((s32 (*)(s32))func_801619A4)() + * (0/1/2/6 shared, 3/4/5 own, no default block — out-of-range and every `break` fall to the + * after-switch join), then a chain of "state handler" tests, each dispatching + * D_80187330[*(u16*)arg0](arg0) and returning. + * + * THREE LEVERS (draft -> MATCH in 3 compiles): + * + * 1. PROLOGUE CONSTANT = an INITIALIZED LOCAL, not a literal in the compare. + * Target opens with `lui $s2, 0xFFF5` in the *prologue*, used once ~200 ins later in + * `slt $v0,$s2,$s1`. No gcc-2.7.2 pass hoists a (set reg const_int) across basic blocks + * (loop.c needs a loop; cse/combine/sched never move insns between BBs) — so the insn must + * have been EMITTED in the first BB, i.e. the constant is a local initialized at the top of + * the function. cse then cannot fold it back into the compare: the `slt` operand predicate is + * `arith_operand`, which rejects a CONST_INT wider than 16 bits, so validate_change fails and + * the pseudo survives. Its live range spans every call -> global.c gives it a callee-saved reg. + * Writing `z > -0xB0000` inline instead emits the `lui` into the branch delay slot next to the + * compare (caller-saved $v0) and the function is 1 insn short. => `s32 lim = -0xB0000;` at top. + * + * 2. `lh` vs `lhu`: a short->short copy is a pure HImode move and gcc emits `lhu`. The target's + * `lh $v0,0x26($s0)` means the value passed through an SImode (int) temp: expand makes + * (set (reg:SI) (sign_extend (mem:HI))) + (set (mem:HI) (subreg:HI ...)), and combine cannot + * merge them (the merged form is mem<-mem, which no movhi accepts) so the sign-extending load + * survives. => route both halfword copies through the `s32 t` temp. + * + * 3. THE `goto` LAYOUT — dodging jump.c's store-flag conversion (jump.c:1005-1065). + * An if/else chain writing 0/1 into `doit` makes gcc collapse the last pair into + * `sltiu $v0,$v0,1`. jump.c fires that conversion when the insn immediately after a + * conditional jump is a lone `SET pseudo, CONST_INT` whose following simplejump targets the + * SAME label as the branch (jump.c:1038 `reallabelprev == temp || ... JUMP_LABEL(temp4) == + * JUMP_LABEL(insn)`) — exactly the shape of `if (c) x=0; else x=1;`. + * The target instead cross-jumps ALL the `doit=0` exits into ONE shared block placed after the + * `doit=1` fall-through; reorg's fill_slots_from_thread then COPIES that single set into all + * three branch delay slots and redirects each branch past it (which is why `addu $v0,$zero, + * $zero` appears 3x in delay slots and the shared block vanishes). A `goto zero;` / `goto one;` + * chain expresses that layout directly, and each conditional jump is then followed by a + * compare/call rather than a lone const set, so the store-flag conversion never triggers. + * GENERAL RULE: multiple predicates that all assign the SAME constant to one flag => write + * them as `goto` to a shared assignment, never as an if/else ladder. + */ +extern s32 D_8011F9C4; +extern s32 D_801872C4; + +extern s32 func_80161B18(void); +extern s32 func_801619A4(s32*); +extern s32 func_80149AA8(s32*); +extern void func_80149AD4(s32*); +extern s32 func_80149B54(s32*); +extern void func_80149BAC(s32*); +extern s32 func_801498E0(s32*); +extern s32 func_80149954(s32); +extern s32 func_80149A64(s32*); +extern void func_800CCCC0(s32 a0); +extern s32 func_80149CD4(s32 a0); +extern void func_8015E880(s32*); +extern s32 func_80149744(struct S_80149744*); +extern void func_80149788(void); +extern s32 func_801496D4(void*); +extern void func_80149704(void); +extern int func_80148AFC(void*); +extern void func_80146D90(s32 a0); +extern void func_80154150(s32 a0, s32 a1); +extern void func_801541D8(u8*, s32, s32); +extern s32 func_801488A8(u8*); +extern void func_80147078(s32*, s16); +extern void func_8015A264(void*); +extern s32 func_80013294(void*, void*); +extern void func_80159B70(void*); +extern s32 func_8016F1AC(void); +extern s32 func_80029178(s32 a0); +extern void func_80146DB8(s32*, s32*); +extern s32 func_80161CD0(s32, s32); +extern s32 func_80161208(s32 a0); +extern s32 func_801725A4(u8*); + +s32 func_8015B950(s32 arg0) +{ + + extern void (*D_80187330[])(void *); + s16 sp10[4]; + s16 sp18[4]; + s32 t; + s32 z; + s32 doit; + s32 lim = -0xB0000; + + if (func_80161B18() != 0) { + return; + } + switch (((s32 (*)(s32))func_801619A4)(arg0)) { + case 0: + case 1: + case 2: + case 6: + if (((s32 (*)(s32))func_80149AA8)(arg0) != 0) { + D_80187330[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149AD4)(arg0); + return; + } + if (((s32 (*)(s32))func_80149B54)(arg0) != 0) { + D_80187330[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149BAC)(arg0); + return; + } + break; + case 3: + ((void (*)(s32))func_801498E0)(arg0); + break; + case 4: + ((void (*)(s32))func_80149954)(arg0); + break; + case 5: + if (((s32 (*)(s32))func_80149A64)(arg0) != 0) { + D_80187330[*(u16 *)arg0]((void *)arg0); + func_800CCCC0(arg0); + return; + } + break; + } + if (func_80149CD4(arg0) != 0) { + D_80187330[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_8015E880)(arg0); + return; + } + if (((s32 (*)(s32))func_80149744)(arg0) != 0) { + D_80187330[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149788)(arg0); + return; + } + if (((s32 (*)(s32))func_801496D4)(arg0) != 0) { + D_80187330[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149704)(arg0); + if (((u8)((s32 (*)(s32))func_80148AFC)(arg0)) == 0) { + func_80146D90(arg0); + } + if ((*(s32 *)(arg0 + 0x24) | *(s32 *)(arg0 + 0x2C)) != 0) { + func_80154150(arg0, 0xF); + } else { + ((void (*)(s32, s32, s32))func_801541D8)(arg0, 0xD, 6); + } + *(s32 *)(arg0 + 0x238) = 1; + return; + } + if (((s32 (*)(s32))func_801488A8)(arg0) != 0) { + sp10[0] = 0; + sp10[1] = 0; + sp10[2] = 0; + t = *(s16 *)(arg0 + 0x26); + sp18[0] = t; + sp18[1] = 0; + t = *(s16 *)(arg0 + 0x2E); + sp18[2] = t; + D_80187330[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 1); + ((void (*)(s32))func_8015A264)(arg0); + t = -(((s32 (*)(s16 *, s16 *))func_80013294)(sp10, sp18) << 0x10); + if (t < *(s32 *)(arg0 + 0x2C)) { + *(s32 *)(arg0 + 0x2C) = t; + } + return; + } + if (*(u16 *)(arg0 + 0xB8) == 0x8000) { + D_80187330[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 0); + ((void (*)(s32))func_80159B70)(arg0); + return; + } + z = *(s32 *)(arg0 + 0x2C); + if (func_8016F1AC() != 0) { + goto zero; + } + if (z <= lim) { + goto one; + } + if (D_8011F9C4 == 0) { + goto zero; + } + if (((u8)func_80029178(0x21)) != 0) { + goto zero; + } +one: + doit = 1; + goto join; +zero: + doit = 0; +join: + if (doit != 0) { + D_80187330[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 0); + ((void (*)(s32))func_80159B70)(arg0); + func_80154150(arg0, 9); + ((void (*)(s32, s32 *))func_80146DB8)(arg0, &D_801872C4); + ((void (*)(s32, s32))func_80161CD0)(arg0, *(u16 *)(arg0 + 0x16E)); + return; + } + if (func_80161208(arg0) == 0) { + ((void (*)(s32))func_801725A4)(arg0); + } +} DEFINE_func_8015BD8C() /* dedup: shared engine-core @0x8015BD8C (src/shared) */ diff --git a/src/ov_SC06_027/ov_SC06_027_jr_8015AE2C.c b/src/ov_SC06_027/ov_SC06_027_jr_8015AE2C.c index b6c9e2613..f0ab60c13 100644 --- a/src/ov_SC06_027/ov_SC06_027_jr_8015AE2C.c +++ b/src/ov_SC06_027/ov_SC06_027_jr_8015AE2C.c @@ -1512,7 +1512,259 @@ DEFINE_func_8015B858() /* dedup: shared engine-core @0x8015B858 (src/shared) */ DEFINE_func_8015B8F8() /* dedup: shared engine-core @0x8015B8F8 (src/shared) */ -INCLUDE_ASM("asm/ov_SC06_027/nonmatchings/ov_SC06_027_jr_8015AE2C", func_8015B950); +extern s32 func_8015AE2C(); + +// @class: plumbing +// @stuck: none — MATCH (271/271, pin-free, zero asm). The ONLY residual is DEF-SIDE plumbing, and it is now named exactly: the in-TU instantiation `DEFINE_func_8015BEE4()` (engine_core.h:1851-1855) expands to `extern s32 func_8015B950(void);` INSIDE ov_SC01_077_jr_8015AE2C.c, ~14 lines BELOW this definition, so the 1-param def collides with a `(void)` prototype -> `conflicting types for func_8015B950` (.run/bank_func_8015B950.log). §73 PARAMS axis / T0. Surgical fix = §65b de-macroize that ONE instantiation (blast radius: this TU); the fleet-wide `(void)`->`()` header edit is §63 and must be R22-validated. +/* func_8015B950 (ov_SC01_077_jr_8015AE2C, 271 ins, jtbl_801D8B74) — SESSION-21 re-verified + * + * ── ROUND-2 INDEPENDENT RE-VERIFICATION (2026-07-27, fresh agent, §88e discipline) ───────────── + * match_one : MATCH (271 ins) against the CURRENT tree — §87 staleness re-checked today. + * .text size: compiled .text = 0x43C = 1084 B = 271 ins, EXACTLY the target's declared 0x43C + * ("nonmatching func_8015B950, 0x43C"). So this is NOT a §83a length drift hiding + * behind a zero count — the count is over equal-length streams. + * jtbl : RE-DECODED MECHANICALLY, not inherited. Compiled .rodata = 0x1C = 28 B = 7 words, + * 7x R_MIPS_32 -> .text with implicit addends [58,58,58,E0,F0,100,58]; +0x8015B950 + * = [8015B9A8, 8015B9A8, 8015B9A8, 8015BA30, 8015BA40, 8015BA50, 8015B9A8]. + * Diffed word-for-word against asm/ov_SC01_077/data/tail14.data.s:15-23 — 7/7 identical. + * symcheck : SYMS-DIFF target=35 draft=34, sole MISSING = jtbl_801D8B74. This is the §81 jr + * FALSE POSITIVE, re-confirmed here by reading the relocs: gcc emits its OWN table and + * references it with R_MIPS_HI16/LO16 against the SECTION `.rodata` (t.o +0x40/+0x48), + * so the splat's dlabel NAME can never appear in the draft object's relocation set. + * Nothing is dropped and nothing is invented: the draft's other 34 symbols are exactly + * the target's other 34. + * FAMILY : the x138 remap is clean and §84-safe. Every sibling is 271 ins with an IDENTICAL + * callee set; only THREE names vary per overlay — the two data labels and the jtbl: + * ov_SC01_077 D_80180604 / D_80180670 / jtbl_801D8B74 + * ov_SC03_099 D_80185A50 / D_80185ABC / jtbl_801BD898 + * ov_SC06_008 D_80187E44 / D_80187EB0 / jtbl_801A8734 + * The pair is always +0x6C apart, and NO literal in this draft encodes that distance + * (both labels are referenced by name), so there is no §84 derived-offset hazard. + * D_8011F9C4 is fleet-constant (main-EXE data) and must NOT be remapped. + * + * match_one: MATCH (271 ins) against the CURRENT tree (§87 staleness re-checked, 2026-07-27). + * PIN-FREE, zero asm, offset-pure (s32 arg0 + raw offsets) — x138 template-safe. + * Provenance: this is the Phase-26 crack (.run/phase26-cracks/func_8015B950.c) re-gated verbatim, + * with ONE deliberate change: the definition's return type void -> s32. + * - `void func_8015B950(s32 arg0)` : MATCH (271 ins) [the Phase-26 form] + * - `s32 func_8015B950(s32 arg0)` : MATCH (271 ins) [shipped — §3a-1 void->s32 is byte-neutral] + * The fleet/engine_core.h canonical decl is `extern s32 func_8015B950(void);` (engine_core.h:1852), + * and the last bank attempt (.run/bank_func_8015B950.log) died on `conflicting types for + * func_8015B950`. Shipping the s32 return kills the §73 RETURN axis for free and leaves only the + * cheap T0 PARAMS axis for the ladder (fix_header_decl.py / --fix-def-sig / cast_call_sites). + * Both forms are byte-identical, so the orchestrator may swap the return type back at zero cost. + * + * SYMBOLS (§58 rules 1/2 — all splat spellings, all verified present): + * D_80180670 asm/ov_SC01_077/data/tail.data.s:4355 (the state-handler vtable) + * D_80180604 asm/ov_SC01_077/data/tail.data.s:4293 + * D_8011F9C4 main-EXE data; spelled `extern s32 D_8011F9C4;` in 5+ already-banked TUs + * jtbl_801D8B74 asm/ov_SC01_077/data/tail14.data.s:15 (compiler jump table — not named in C) + * + * JTBL VERIFIED (§8a gate): compiled .rodata = exactly 0x1C B / 7 words, 7x R_MIPS_32 .text with + * addends [0x58,0x58,0x58,0xE0,0xF0,0x100,0x58] -> +0x8015B950 = [B9A8,B9A8,B9A8,BA30,BA40,BA50, + * B9A8] == the original words at 0x801D8B74..0x801D8B8C. Bound `sltiu $v0,$v1,0x7` matches. + * The raw dlabel's 8th word 0x00000000 is NOT an entry — it is the intra-TU `.align 3` pad of the + * B34/B54/B74 jtbl chain; the object can never emit it (maspsx drops .align), so it must stay in + * the post-carve RAW data piece (the §53/§62/§81 carve chain applies at bank time). + * + * Same family as the TU's own already-matched func_8015AE2C: 7-case switch on ((s32 (*)(s32))func_801619A4)() + * (0/1/2/6 shared, 3/4/5 own, no default block — out-of-range and every `break` fall to the + * after-switch join), then a chain of "state handler" tests, each dispatching + * D_80180670[*(u16*)arg0](arg0) and returning. + * + * THREE LEVERS (draft -> MATCH in 3 compiles): + * + * 1. PROLOGUE CONSTANT = an INITIALIZED LOCAL, not a literal in the compare. + * Target opens with `lui $s2, 0xFFF5` in the *prologue*, used once ~200 ins later in + * `slt $v0,$s2,$s1`. No gcc-2.7.2 pass hoists a (set reg const_int) across basic blocks + * (loop.c needs a loop; cse/combine/sched never move insns between BBs) — so the insn must + * have been EMITTED in the first BB, i.e. the constant is a local initialized at the top of + * the function. cse then cannot fold it back into the compare: the `slt` operand predicate is + * `arith_operand`, which rejects a CONST_INT wider than 16 bits, so validate_change fails and + * the pseudo survives. Its live range spans every call -> global.c gives it a callee-saved reg. + * Writing `z > -0xB0000` inline instead emits the `lui` into the branch delay slot next to the + * compare (caller-saved $v0) and the function is 1 insn short. => `s32 lim = -0xB0000;` at top. + * + * 2. `lh` vs `lhu`: a short->short copy is a pure HImode move and gcc emits `lhu`. The target's + * `lh $v0,0x26($s0)` means the value passed through an SImode (int) temp: expand makes + * (set (reg:SI) (sign_extend (mem:HI))) + (set (mem:HI) (subreg:HI ...)), and combine cannot + * merge them (the merged form is mem<-mem, which no movhi accepts) so the sign-extending load + * survives. => route both halfword copies through the `s32 t` temp. + * + * 3. THE `goto` LAYOUT — dodging jump.c's store-flag conversion (jump.c:1005-1065). + * An if/else chain writing 0/1 into `doit` makes gcc collapse the last pair into + * `sltiu $v0,$v0,1`. jump.c fires that conversion when the insn immediately after a + * conditional jump is a lone `SET pseudo, CONST_INT` whose following simplejump targets the + * SAME label as the branch (jump.c:1038 `reallabelprev == temp || ... JUMP_LABEL(temp4) == + * JUMP_LABEL(insn)`) — exactly the shape of `if (c) x=0; else x=1;`. + * The target instead cross-jumps ALL the `doit=0` exits into ONE shared block placed after the + * `doit=1` fall-through; reorg's fill_slots_from_thread then COPIES that single set into all + * three branch delay slots and redirects each branch past it (which is why `addu $v0,$zero, + * $zero` appears 3x in delay slots and the shared block vanishes). A `goto zero;` / `goto one;` + * chain expresses that layout directly, and each conditional jump is then followed by a + * compare/call rather than a lone const set, so the store-flag conversion never triggers. + * GENERAL RULE: multiple predicates that all assign the SAME constant to one flag => write + * them as `goto` to a shared assignment, never as an if/else ladder. + */ +extern s32 D_8011F9C4; +extern s32 D_80180604; + +extern s32 func_80161B18(void); +extern s32 func_801619A4(s32*); +extern s32 func_80149AA8(s32*); +extern void func_80149AD4(s32*); +extern s32 func_80149B54(s32*); +extern void func_80149BAC(s32*); +extern s32 func_801498E0(s32*); +extern s32 func_80149954(s32); +extern s32 func_80149A64(s32*); +extern void func_800CCCC0(s32 a0); +extern s32 func_80149CD4(s32 a0); +extern void func_8015E880(s32*); +extern s32 func_80149744(struct S_80149744*); +extern void func_80149788(void); +extern s32 func_801496D4(void*); +extern void func_80149704(void); +extern int func_80148AFC(void*); +extern void func_80146D90(s32 a0); +extern void func_80154150(s32 a0, s32 a1); +extern void func_801541D8(u8*, s32, s32); +extern s32 func_801488A8(u8*); +extern void func_80147078(s32*, s16); +extern void func_8015A264(void*); +extern s32 func_80013294(void*, void*); +extern void func_80159B70(void*); +extern s32 func_8016F1AC(void); +extern s32 func_80029178(s32 a0); +extern void func_80146DB8(s32*, s32*); +extern s32 func_80161CD0(s32, s32); +extern s32 func_80161208(s32 a0); +extern s32 func_801725A4(u8*); + +s32 func_8015B950(s32 arg0) +{ + + extern void (*D_80180670[])(void *); + s16 sp10[4]; + s16 sp18[4]; + s32 t; + s32 z; + s32 doit; + s32 lim = -0xB0000; + + if (func_80161B18() != 0) { + return; + } + switch (((s32 (*)(s32))func_801619A4)(arg0)) { + case 0: + case 1: + case 2: + case 6: + if (((s32 (*)(s32))func_80149AA8)(arg0) != 0) { + D_80180670[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149AD4)(arg0); + return; + } + if (((s32 (*)(s32))func_80149B54)(arg0) != 0) { + D_80180670[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149BAC)(arg0); + return; + } + break; + case 3: + ((void (*)(s32))func_801498E0)(arg0); + break; + case 4: + ((void (*)(s32))func_80149954)(arg0); + break; + case 5: + if (((s32 (*)(s32))func_80149A64)(arg0) != 0) { + D_80180670[*(u16 *)arg0]((void *)arg0); + func_800CCCC0(arg0); + return; + } + break; + } + if (func_80149CD4(arg0) != 0) { + D_80180670[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_8015E880)(arg0); + return; + } + if (((s32 (*)(s32))func_80149744)(arg0) != 0) { + D_80180670[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149788)(arg0); + return; + } + if (((s32 (*)(s32))func_801496D4)(arg0) != 0) { + D_80180670[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149704)(arg0); + if (((u8)((s32 (*)(s32))func_80148AFC)(arg0)) == 0) { + func_80146D90(arg0); + } + if ((*(s32 *)(arg0 + 0x24) | *(s32 *)(arg0 + 0x2C)) != 0) { + func_80154150(arg0, 0xF); + } else { + ((void (*)(s32, s32, s32))func_801541D8)(arg0, 0xD, 6); + } + *(s32 *)(arg0 + 0x238) = 1; + return; + } + if (((s32 (*)(s32))func_801488A8)(arg0) != 0) { + sp10[0] = 0; + sp10[1] = 0; + sp10[2] = 0; + t = *(s16 *)(arg0 + 0x26); + sp18[0] = t; + sp18[1] = 0; + t = *(s16 *)(arg0 + 0x2E); + sp18[2] = t; + D_80180670[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 1); + ((void (*)(s32))func_8015A264)(arg0); + t = -(((s32 (*)(s16 *, s16 *))func_80013294)(sp10, sp18) << 0x10); + if (t < *(s32 *)(arg0 + 0x2C)) { + *(s32 *)(arg0 + 0x2C) = t; + } + return; + } + if (*(u16 *)(arg0 + 0xB8) == 0x8000) { + D_80180670[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 0); + ((void (*)(s32))func_80159B70)(arg0); + return; + } + z = *(s32 *)(arg0 + 0x2C); + if (func_8016F1AC() != 0) { + goto zero; + } + if (z <= lim) { + goto one; + } + if (D_8011F9C4 == 0) { + goto zero; + } + if (((u8)func_80029178(0x21)) != 0) { + goto zero; + } +one: + doit = 1; + goto join; +zero: + doit = 0; +join: + if (doit != 0) { + D_80180670[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 0); + ((void (*)(s32))func_80159B70)(arg0); + func_80154150(arg0, 9); + ((void (*)(s32, s32 *))func_80146DB8)(arg0, &D_80180604); + ((void (*)(s32, s32))func_80161CD0)(arg0, *(u16 *)(arg0 + 0x16E)); + return; + } + if (func_80161208(arg0) == 0) { + ((void (*)(s32))func_801725A4)(arg0); + } +} DEFINE_func_8015BD8C() /* dedup: shared engine-core @0x8015BD8C (src/shared) */ diff --git a/src/ov_SC06_029/ov_SC06_029_jr_8015AE2C.c b/src/ov_SC06_029/ov_SC06_029_jr_8015AE2C.c index 3787ae5fa..2bcbb3908 100644 --- a/src/ov_SC06_029/ov_SC06_029_jr_8015AE2C.c +++ b/src/ov_SC06_029/ov_SC06_029_jr_8015AE2C.c @@ -1512,7 +1512,259 @@ DEFINE_func_8015B858() /* dedup: shared engine-core @0x8015B858 (src/shared) */ DEFINE_func_8015B8F8() /* dedup: shared engine-core @0x8015B8F8 (src/shared) */ -INCLUDE_ASM("asm/ov_SC06_029/nonmatchings/ov_SC06_029_jr_8015AE2C", func_8015B950); +extern s32 func_8015AE2C(); + +// @class: plumbing +// @stuck: none — MATCH (271/271, pin-free, zero asm). The ONLY residual is DEF-SIDE plumbing, and it is now named exactly: the in-TU instantiation `DEFINE_func_8015BEE4()` (engine_core.h:1851-1855) expands to `extern s32 func_8015B950(void);` INSIDE ov_SC01_077_jr_8015AE2C.c, ~14 lines BELOW this definition, so the 1-param def collides with a `(void)` prototype -> `conflicting types for func_8015B950` (.run/bank_func_8015B950.log). §73 PARAMS axis / T0. Surgical fix = §65b de-macroize that ONE instantiation (blast radius: this TU); the fleet-wide `(void)`->`()` header edit is §63 and must be R22-validated. +/* func_8015B950 (ov_SC01_077_jr_8015AE2C, 271 ins, jtbl_801D8B74) — SESSION-21 re-verified + * + * ── ROUND-2 INDEPENDENT RE-VERIFICATION (2026-07-27, fresh agent, §88e discipline) ───────────── + * match_one : MATCH (271 ins) against the CURRENT tree — §87 staleness re-checked today. + * .text size: compiled .text = 0x43C = 1084 B = 271 ins, EXACTLY the target's declared 0x43C + * ("nonmatching func_8015B950, 0x43C"). So this is NOT a §83a length drift hiding + * behind a zero count — the count is over equal-length streams. + * jtbl : RE-DECODED MECHANICALLY, not inherited. Compiled .rodata = 0x1C = 28 B = 7 words, + * 7x R_MIPS_32 -> .text with implicit addends [58,58,58,E0,F0,100,58]; +0x8015B950 + * = [8015B9A8, 8015B9A8, 8015B9A8, 8015BA30, 8015BA40, 8015BA50, 8015B9A8]. + * Diffed word-for-word against asm/ov_SC01_077/data/tail14.data.s:15-23 — 7/7 identical. + * symcheck : SYMS-DIFF target=35 draft=34, sole MISSING = jtbl_801D8B74. This is the §81 jr + * FALSE POSITIVE, re-confirmed here by reading the relocs: gcc emits its OWN table and + * references it with R_MIPS_HI16/LO16 against the SECTION `.rodata` (t.o +0x40/+0x48), + * so the splat's dlabel NAME can never appear in the draft object's relocation set. + * Nothing is dropped and nothing is invented: the draft's other 34 symbols are exactly + * the target's other 34. + * FAMILY : the x138 remap is clean and §84-safe. Every sibling is 271 ins with an IDENTICAL + * callee set; only THREE names vary per overlay — the two data labels and the jtbl: + * ov_SC01_077 D_8018EB98 / D_8018EC04 / jtbl_801D8B74 + * ov_SC03_099 D_80185A50 / D_80185ABC / jtbl_801BD898 + * ov_SC06_008 D_80187E44 / D_80187EB0 / jtbl_801A8734 + * The pair is always +0x6C apart, and NO literal in this draft encodes that distance + * (both labels are referenced by name), so there is no §84 derived-offset hazard. + * D_8011F9C4 is fleet-constant (main-EXE data) and must NOT be remapped. + * + * match_one: MATCH (271 ins) against the CURRENT tree (§87 staleness re-checked, 2026-07-27). + * PIN-FREE, zero asm, offset-pure (s32 arg0 + raw offsets) — x138 template-safe. + * Provenance: this is the Phase-26 crack (.run/phase26-cracks/func_8015B950.c) re-gated verbatim, + * with ONE deliberate change: the definition's return type void -> s32. + * - `void func_8015B950(s32 arg0)` : MATCH (271 ins) [the Phase-26 form] + * - `s32 func_8015B950(s32 arg0)` : MATCH (271 ins) [shipped — §3a-1 void->s32 is byte-neutral] + * The fleet/engine_core.h canonical decl is `extern s32 func_8015B950(void);` (engine_core.h:1852), + * and the last bank attempt (.run/bank_func_8015B950.log) died on `conflicting types for + * func_8015B950`. Shipping the s32 return kills the §73 RETURN axis for free and leaves only the + * cheap T0 PARAMS axis for the ladder (fix_header_decl.py / --fix-def-sig / cast_call_sites). + * Both forms are byte-identical, so the orchestrator may swap the return type back at zero cost. + * + * SYMBOLS (§58 rules 1/2 — all splat spellings, all verified present): + * D_8018EC04 asm/ov_SC01_077/data/tail.data.s:4355 (the state-handler vtable) + * D_8018EB98 asm/ov_SC01_077/data/tail.data.s:4293 + * D_8011F9C4 main-EXE data; spelled `extern s32 D_8011F9C4;` in 5+ already-banked TUs + * jtbl_801D8B74 asm/ov_SC01_077/data/tail14.data.s:15 (compiler jump table — not named in C) + * + * JTBL VERIFIED (§8a gate): compiled .rodata = exactly 0x1C B / 7 words, 7x R_MIPS_32 .text with + * addends [0x58,0x58,0x58,0xE0,0xF0,0x100,0x58] -> +0x8015B950 = [B9A8,B9A8,B9A8,BA30,BA40,BA50, + * B9A8] == the original words at 0x801D8B74..0x801D8B8C. Bound `sltiu $v0,$v1,0x7` matches. + * The raw dlabel's 8th word 0x00000000 is NOT an entry — it is the intra-TU `.align 3` pad of the + * B34/B54/B74 jtbl chain; the object can never emit it (maspsx drops .align), so it must stay in + * the post-carve RAW data piece (the §53/§62/§81 carve chain applies at bank time). + * + * Same family as the TU's own already-matched func_8015AE2C: 7-case switch on ((s32 (*)(s32))func_801619A4)() + * (0/1/2/6 shared, 3/4/5 own, no default block — out-of-range and every `break` fall to the + * after-switch join), then a chain of "state handler" tests, each dispatching + * D_8018EC04[*(u16*)arg0](arg0) and returning. + * + * THREE LEVERS (draft -> MATCH in 3 compiles): + * + * 1. PROLOGUE CONSTANT = an INITIALIZED LOCAL, not a literal in the compare. + * Target opens with `lui $s2, 0xFFF5` in the *prologue*, used once ~200 ins later in + * `slt $v0,$s2,$s1`. No gcc-2.7.2 pass hoists a (set reg const_int) across basic blocks + * (loop.c needs a loop; cse/combine/sched never move insns between BBs) — so the insn must + * have been EMITTED in the first BB, i.e. the constant is a local initialized at the top of + * the function. cse then cannot fold it back into the compare: the `slt` operand predicate is + * `arith_operand`, which rejects a CONST_INT wider than 16 bits, so validate_change fails and + * the pseudo survives. Its live range spans every call -> global.c gives it a callee-saved reg. + * Writing `z > -0xB0000` inline instead emits the `lui` into the branch delay slot next to the + * compare (caller-saved $v0) and the function is 1 insn short. => `s32 lim = -0xB0000;` at top. + * + * 2. `lh` vs `lhu`: a short->short copy is a pure HImode move and gcc emits `lhu`. The target's + * `lh $v0,0x26($s0)` means the value passed through an SImode (int) temp: expand makes + * (set (reg:SI) (sign_extend (mem:HI))) + (set (mem:HI) (subreg:HI ...)), and combine cannot + * merge them (the merged form is mem<-mem, which no movhi accepts) so the sign-extending load + * survives. => route both halfword copies through the `s32 t` temp. + * + * 3. THE `goto` LAYOUT — dodging jump.c's store-flag conversion (jump.c:1005-1065). + * An if/else chain writing 0/1 into `doit` makes gcc collapse the last pair into + * `sltiu $v0,$v0,1`. jump.c fires that conversion when the insn immediately after a + * conditional jump is a lone `SET pseudo, CONST_INT` whose following simplejump targets the + * SAME label as the branch (jump.c:1038 `reallabelprev == temp || ... JUMP_LABEL(temp4) == + * JUMP_LABEL(insn)`) — exactly the shape of `if (c) x=0; else x=1;`. + * The target instead cross-jumps ALL the `doit=0` exits into ONE shared block placed after the + * `doit=1` fall-through; reorg's fill_slots_from_thread then COPIES that single set into all + * three branch delay slots and redirects each branch past it (which is why `addu $v0,$zero, + * $zero` appears 3x in delay slots and the shared block vanishes). A `goto zero;` / `goto one;` + * chain expresses that layout directly, and each conditional jump is then followed by a + * compare/call rather than a lone const set, so the store-flag conversion never triggers. + * GENERAL RULE: multiple predicates that all assign the SAME constant to one flag => write + * them as `goto` to a shared assignment, never as an if/else ladder. + */ +extern s32 D_8011F9C4; +extern s32 D_8018EB98; + +extern s32 func_80161B18(void); +extern s32 func_801619A4(s32*); +extern s32 func_80149AA8(s32*); +extern void func_80149AD4(s32*); +extern s32 func_80149B54(s32*); +extern void func_80149BAC(s32*); +extern s32 func_801498E0(s32*); +extern s32 func_80149954(s32); +extern s32 func_80149A64(s32*); +extern void func_800CCCC0(s32 a0); +extern s32 func_80149CD4(s32 a0); +extern void func_8015E880(s32*); +extern s32 func_80149744(struct S_80149744*); +extern void func_80149788(void); +extern s32 func_801496D4(void*); +extern void func_80149704(void); +extern int func_80148AFC(void*); +extern void func_80146D90(s32 a0); +extern void func_80154150(s32 a0, s32 a1); +extern void func_801541D8(u8*, s32, s32); +extern s32 func_801488A8(u8*); +extern void func_80147078(s32*, s16); +extern void func_8015A264(void*); +extern s32 func_80013294(void*, void*); +extern void func_80159B70(void*); +extern s32 func_8016F1AC(void); +extern s32 func_80029178(s32 a0); +extern void func_80146DB8(s32*, s32*); +extern s32 func_80161CD0(s32, s32); +extern s32 func_80161208(s32 a0); +extern s32 func_801725A4(u8*); + +s32 func_8015B950(s32 arg0) +{ + + extern void (*D_8018EC04[])(void *); + s16 sp10[4]; + s16 sp18[4]; + s32 t; + s32 z; + s32 doit; + s32 lim = -0xB0000; + + if (func_80161B18() != 0) { + return; + } + switch (((s32 (*)(s32))func_801619A4)(arg0)) { + case 0: + case 1: + case 2: + case 6: + if (((s32 (*)(s32))func_80149AA8)(arg0) != 0) { + D_8018EC04[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149AD4)(arg0); + return; + } + if (((s32 (*)(s32))func_80149B54)(arg0) != 0) { + D_8018EC04[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149BAC)(arg0); + return; + } + break; + case 3: + ((void (*)(s32))func_801498E0)(arg0); + break; + case 4: + ((void (*)(s32))func_80149954)(arg0); + break; + case 5: + if (((s32 (*)(s32))func_80149A64)(arg0) != 0) { + D_8018EC04[*(u16 *)arg0]((void *)arg0); + func_800CCCC0(arg0); + return; + } + break; + } + if (func_80149CD4(arg0) != 0) { + D_8018EC04[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_8015E880)(arg0); + return; + } + if (((s32 (*)(s32))func_80149744)(arg0) != 0) { + D_8018EC04[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149788)(arg0); + return; + } + if (((s32 (*)(s32))func_801496D4)(arg0) != 0) { + D_8018EC04[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149704)(arg0); + if (((u8)((s32 (*)(s32))func_80148AFC)(arg0)) == 0) { + func_80146D90(arg0); + } + if ((*(s32 *)(arg0 + 0x24) | *(s32 *)(arg0 + 0x2C)) != 0) { + func_80154150(arg0, 0xF); + } else { + ((void (*)(s32, s32, s32))func_801541D8)(arg0, 0xD, 6); + } + *(s32 *)(arg0 + 0x238) = 1; + return; + } + if (((s32 (*)(s32))func_801488A8)(arg0) != 0) { + sp10[0] = 0; + sp10[1] = 0; + sp10[2] = 0; + t = *(s16 *)(arg0 + 0x26); + sp18[0] = t; + sp18[1] = 0; + t = *(s16 *)(arg0 + 0x2E); + sp18[2] = t; + D_8018EC04[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 1); + ((void (*)(s32))func_8015A264)(arg0); + t = -(((s32 (*)(s16 *, s16 *))func_80013294)(sp10, sp18) << 0x10); + if (t < *(s32 *)(arg0 + 0x2C)) { + *(s32 *)(arg0 + 0x2C) = t; + } + return; + } + if (*(u16 *)(arg0 + 0xB8) == 0x8000) { + D_8018EC04[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 0); + ((void (*)(s32))func_80159B70)(arg0); + return; + } + z = *(s32 *)(arg0 + 0x2C); + if (func_8016F1AC() != 0) { + goto zero; + } + if (z <= lim) { + goto one; + } + if (D_8011F9C4 == 0) { + goto zero; + } + if (((u8)func_80029178(0x21)) != 0) { + goto zero; + } +one: + doit = 1; + goto join; +zero: + doit = 0; +join: + if (doit != 0) { + D_8018EC04[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 0); + ((void (*)(s32))func_80159B70)(arg0); + func_80154150(arg0, 9); + ((void (*)(s32, s32 *))func_80146DB8)(arg0, &D_8018EB98); + ((void (*)(s32, s32))func_80161CD0)(arg0, *(u16 *)(arg0 + 0x16E)); + return; + } + if (func_80161208(arg0) == 0) { + ((void (*)(s32))func_801725A4)(arg0); + } +} DEFINE_func_8015BD8C() /* dedup: shared engine-core @0x8015BD8C (src/shared) */ diff --git a/src/ov_SC06_030/ov_SC06_030_jr_8015AE2C.c b/src/ov_SC06_030/ov_SC06_030_jr_8015AE2C.c index ea73a4490..983179314 100644 --- a/src/ov_SC06_030/ov_SC06_030_jr_8015AE2C.c +++ b/src/ov_SC06_030/ov_SC06_030_jr_8015AE2C.c @@ -1512,7 +1512,259 @@ DEFINE_func_8015B858() /* dedup: shared engine-core @0x8015B858 (src/shared) */ DEFINE_func_8015B8F8() /* dedup: shared engine-core @0x8015B8F8 (src/shared) */ -INCLUDE_ASM("asm/ov_SC06_030/nonmatchings/ov_SC06_030_jr_8015AE2C", func_8015B950); +extern s32 func_8015AE2C(); + +// @class: plumbing +// @stuck: none — MATCH (271/271, pin-free, zero asm). The ONLY residual is DEF-SIDE plumbing, and it is now named exactly: the in-TU instantiation `DEFINE_func_8015BEE4()` (engine_core.h:1851-1855) expands to `extern s32 func_8015B950(void);` INSIDE ov_SC01_077_jr_8015AE2C.c, ~14 lines BELOW this definition, so the 1-param def collides with a `(void)` prototype -> `conflicting types for func_8015B950` (.run/bank_func_8015B950.log). §73 PARAMS axis / T0. Surgical fix = §65b de-macroize that ONE instantiation (blast radius: this TU); the fleet-wide `(void)`->`()` header edit is §63 and must be R22-validated. +/* func_8015B950 (ov_SC01_077_jr_8015AE2C, 271 ins, jtbl_801D8B74) — SESSION-21 re-verified + * + * ── ROUND-2 INDEPENDENT RE-VERIFICATION (2026-07-27, fresh agent, §88e discipline) ───────────── + * match_one : MATCH (271 ins) against the CURRENT tree — §87 staleness re-checked today. + * .text size: compiled .text = 0x43C = 1084 B = 271 ins, EXACTLY the target's declared 0x43C + * ("nonmatching func_8015B950, 0x43C"). So this is NOT a §83a length drift hiding + * behind a zero count — the count is over equal-length streams. + * jtbl : RE-DECODED MECHANICALLY, not inherited. Compiled .rodata = 0x1C = 28 B = 7 words, + * 7x R_MIPS_32 -> .text with implicit addends [58,58,58,E0,F0,100,58]; +0x8015B950 + * = [8015B9A8, 8015B9A8, 8015B9A8, 8015BA30, 8015BA40, 8015BA50, 8015B9A8]. + * Diffed word-for-word against asm/ov_SC01_077/data/tail14.data.s:15-23 — 7/7 identical. + * symcheck : SYMS-DIFF target=35 draft=34, sole MISSING = jtbl_801D8B74. This is the §81 jr + * FALSE POSITIVE, re-confirmed here by reading the relocs: gcc emits its OWN table and + * references it with R_MIPS_HI16/LO16 against the SECTION `.rodata` (t.o +0x40/+0x48), + * so the splat's dlabel NAME can never appear in the draft object's relocation set. + * Nothing is dropped and nothing is invented: the draft's other 34 symbols are exactly + * the target's other 34. + * FAMILY : the x138 remap is clean and §84-safe. Every sibling is 271 ins with an IDENTICAL + * callee set; only THREE names vary per overlay — the two data labels and the jtbl: + * ov_SC01_077 D_80184488 / D_801844F4 / jtbl_801D8B74 + * ov_SC03_099 D_80185A50 / D_80185ABC / jtbl_801BD898 + * ov_SC06_008 D_80187E44 / D_80187EB0 / jtbl_801A8734 + * The pair is always +0x6C apart, and NO literal in this draft encodes that distance + * (both labels are referenced by name), so there is no §84 derived-offset hazard. + * D_8011F9C4 is fleet-constant (main-EXE data) and must NOT be remapped. + * + * match_one: MATCH (271 ins) against the CURRENT tree (§87 staleness re-checked, 2026-07-27). + * PIN-FREE, zero asm, offset-pure (s32 arg0 + raw offsets) — x138 template-safe. + * Provenance: this is the Phase-26 crack (.run/phase26-cracks/func_8015B950.c) re-gated verbatim, + * with ONE deliberate change: the definition's return type void -> s32. + * - `void func_8015B950(s32 arg0)` : MATCH (271 ins) [the Phase-26 form] + * - `s32 func_8015B950(s32 arg0)` : MATCH (271 ins) [shipped — §3a-1 void->s32 is byte-neutral] + * The fleet/engine_core.h canonical decl is `extern s32 func_8015B950(void);` (engine_core.h:1852), + * and the last bank attempt (.run/bank_func_8015B950.log) died on `conflicting types for + * func_8015B950`. Shipping the s32 return kills the §73 RETURN axis for free and leaves only the + * cheap T0 PARAMS axis for the ladder (fix_header_decl.py / --fix-def-sig / cast_call_sites). + * Both forms are byte-identical, so the orchestrator may swap the return type back at zero cost. + * + * SYMBOLS (§58 rules 1/2 — all splat spellings, all verified present): + * D_801844F4 asm/ov_SC01_077/data/tail.data.s:4355 (the state-handler vtable) + * D_80184488 asm/ov_SC01_077/data/tail.data.s:4293 + * D_8011F9C4 main-EXE data; spelled `extern s32 D_8011F9C4;` in 5+ already-banked TUs + * jtbl_801D8B74 asm/ov_SC01_077/data/tail14.data.s:15 (compiler jump table — not named in C) + * + * JTBL VERIFIED (§8a gate): compiled .rodata = exactly 0x1C B / 7 words, 7x R_MIPS_32 .text with + * addends [0x58,0x58,0x58,0xE0,0xF0,0x100,0x58] -> +0x8015B950 = [B9A8,B9A8,B9A8,BA30,BA40,BA50, + * B9A8] == the original words at 0x801D8B74..0x801D8B8C. Bound `sltiu $v0,$v1,0x7` matches. + * The raw dlabel's 8th word 0x00000000 is NOT an entry — it is the intra-TU `.align 3` pad of the + * B34/B54/B74 jtbl chain; the object can never emit it (maspsx drops .align), so it must stay in + * the post-carve RAW data piece (the §53/§62/§81 carve chain applies at bank time). + * + * Same family as the TU's own already-matched func_8015AE2C: 7-case switch on ((s32 (*)(s32))func_801619A4)() + * (0/1/2/6 shared, 3/4/5 own, no default block — out-of-range and every `break` fall to the + * after-switch join), then a chain of "state handler" tests, each dispatching + * D_801844F4[*(u16*)arg0](arg0) and returning. + * + * THREE LEVERS (draft -> MATCH in 3 compiles): + * + * 1. PROLOGUE CONSTANT = an INITIALIZED LOCAL, not a literal in the compare. + * Target opens with `lui $s2, 0xFFF5` in the *prologue*, used once ~200 ins later in + * `slt $v0,$s2,$s1`. No gcc-2.7.2 pass hoists a (set reg const_int) across basic blocks + * (loop.c needs a loop; cse/combine/sched never move insns between BBs) — so the insn must + * have been EMITTED in the first BB, i.e. the constant is a local initialized at the top of + * the function. cse then cannot fold it back into the compare: the `slt` operand predicate is + * `arith_operand`, which rejects a CONST_INT wider than 16 bits, so validate_change fails and + * the pseudo survives. Its live range spans every call -> global.c gives it a callee-saved reg. + * Writing `z > -0xB0000` inline instead emits the `lui` into the branch delay slot next to the + * compare (caller-saved $v0) and the function is 1 insn short. => `s32 lim = -0xB0000;` at top. + * + * 2. `lh` vs `lhu`: a short->short copy is a pure HImode move and gcc emits `lhu`. The target's + * `lh $v0,0x26($s0)` means the value passed through an SImode (int) temp: expand makes + * (set (reg:SI) (sign_extend (mem:HI))) + (set (mem:HI) (subreg:HI ...)), and combine cannot + * merge them (the merged form is mem<-mem, which no movhi accepts) so the sign-extending load + * survives. => route both halfword copies through the `s32 t` temp. + * + * 3. THE `goto` LAYOUT — dodging jump.c's store-flag conversion (jump.c:1005-1065). + * An if/else chain writing 0/1 into `doit` makes gcc collapse the last pair into + * `sltiu $v0,$v0,1`. jump.c fires that conversion when the insn immediately after a + * conditional jump is a lone `SET pseudo, CONST_INT` whose following simplejump targets the + * SAME label as the branch (jump.c:1038 `reallabelprev == temp || ... JUMP_LABEL(temp4) == + * JUMP_LABEL(insn)`) — exactly the shape of `if (c) x=0; else x=1;`. + * The target instead cross-jumps ALL the `doit=0` exits into ONE shared block placed after the + * `doit=1` fall-through; reorg's fill_slots_from_thread then COPIES that single set into all + * three branch delay slots and redirects each branch past it (which is why `addu $v0,$zero, + * $zero` appears 3x in delay slots and the shared block vanishes). A `goto zero;` / `goto one;` + * chain expresses that layout directly, and each conditional jump is then followed by a + * compare/call rather than a lone const set, so the store-flag conversion never triggers. + * GENERAL RULE: multiple predicates that all assign the SAME constant to one flag => write + * them as `goto` to a shared assignment, never as an if/else ladder. + */ +extern s32 D_8011F9C4; +extern s32 D_80184488; + +extern s32 func_80161B18(void); +extern s32 func_801619A4(s32*); +extern s32 func_80149AA8(s32*); +extern void func_80149AD4(s32*); +extern s32 func_80149B54(s32*); +extern void func_80149BAC(s32*); +extern s32 func_801498E0(s32*); +extern s32 func_80149954(s32); +extern s32 func_80149A64(s32*); +extern void func_800CCCC0(s32 a0); +extern s32 func_80149CD4(s32 a0); +extern void func_8015E880(s32*); +extern s32 func_80149744(struct S_80149744*); +extern void func_80149788(void); +extern s32 func_801496D4(void*); +extern void func_80149704(void); +extern int func_80148AFC(void*); +extern void func_80146D90(s32 a0); +extern void func_80154150(s32 a0, s32 a1); +extern void func_801541D8(u8*, s32, s32); +extern s32 func_801488A8(u8*); +extern void func_80147078(s32*, s16); +extern void func_8015A264(void*); +extern s32 func_80013294(void*, void*); +extern void func_80159B70(void*); +extern s32 func_8016F1AC(void); +extern s32 func_80029178(s32 a0); +extern void func_80146DB8(s32*, s32*); +extern s32 func_80161CD0(s32, s32); +extern s32 func_80161208(s32 a0); +extern s32 func_801725A4(u8*); + +s32 func_8015B950(s32 arg0) +{ + + extern void (*D_801844F4[])(void *); + s16 sp10[4]; + s16 sp18[4]; + s32 t; + s32 z; + s32 doit; + s32 lim = -0xB0000; + + if (func_80161B18() != 0) { + return; + } + switch (((s32 (*)(s32))func_801619A4)(arg0)) { + case 0: + case 1: + case 2: + case 6: + if (((s32 (*)(s32))func_80149AA8)(arg0) != 0) { + D_801844F4[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149AD4)(arg0); + return; + } + if (((s32 (*)(s32))func_80149B54)(arg0) != 0) { + D_801844F4[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149BAC)(arg0); + return; + } + break; + case 3: + ((void (*)(s32))func_801498E0)(arg0); + break; + case 4: + ((void (*)(s32))func_80149954)(arg0); + break; + case 5: + if (((s32 (*)(s32))func_80149A64)(arg0) != 0) { + D_801844F4[*(u16 *)arg0]((void *)arg0); + func_800CCCC0(arg0); + return; + } + break; + } + if (func_80149CD4(arg0) != 0) { + D_801844F4[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_8015E880)(arg0); + return; + } + if (((s32 (*)(s32))func_80149744)(arg0) != 0) { + D_801844F4[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149788)(arg0); + return; + } + if (((s32 (*)(s32))func_801496D4)(arg0) != 0) { + D_801844F4[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149704)(arg0); + if (((u8)((s32 (*)(s32))func_80148AFC)(arg0)) == 0) { + func_80146D90(arg0); + } + if ((*(s32 *)(arg0 + 0x24) | *(s32 *)(arg0 + 0x2C)) != 0) { + func_80154150(arg0, 0xF); + } else { + ((void (*)(s32, s32, s32))func_801541D8)(arg0, 0xD, 6); + } + *(s32 *)(arg0 + 0x238) = 1; + return; + } + if (((s32 (*)(s32))func_801488A8)(arg0) != 0) { + sp10[0] = 0; + sp10[1] = 0; + sp10[2] = 0; + t = *(s16 *)(arg0 + 0x26); + sp18[0] = t; + sp18[1] = 0; + t = *(s16 *)(arg0 + 0x2E); + sp18[2] = t; + D_801844F4[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 1); + ((void (*)(s32))func_8015A264)(arg0); + t = -(((s32 (*)(s16 *, s16 *))func_80013294)(sp10, sp18) << 0x10); + if (t < *(s32 *)(arg0 + 0x2C)) { + *(s32 *)(arg0 + 0x2C) = t; + } + return; + } + if (*(u16 *)(arg0 + 0xB8) == 0x8000) { + D_801844F4[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 0); + ((void (*)(s32))func_80159B70)(arg0); + return; + } + z = *(s32 *)(arg0 + 0x2C); + if (func_8016F1AC() != 0) { + goto zero; + } + if (z <= lim) { + goto one; + } + if (D_8011F9C4 == 0) { + goto zero; + } + if (((u8)func_80029178(0x21)) != 0) { + goto zero; + } +one: + doit = 1; + goto join; +zero: + doit = 0; +join: + if (doit != 0) { + D_801844F4[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 0); + ((void (*)(s32))func_80159B70)(arg0); + func_80154150(arg0, 9); + ((void (*)(s32, s32 *))func_80146DB8)(arg0, &D_80184488); + ((void (*)(s32, s32))func_80161CD0)(arg0, *(u16 *)(arg0 + 0x16E)); + return; + } + if (func_80161208(arg0) == 0) { + ((void (*)(s32))func_801725A4)(arg0); + } +} DEFINE_func_8015BD8C() /* dedup: shared engine-core @0x8015BD8C (src/shared) */ diff --git a/src/ov_SC06_032/ov_SC06_032_jr_8015AE2C.c b/src/ov_SC06_032/ov_SC06_032_jr_8015AE2C.c index 9a6065449..38bbe3e79 100644 --- a/src/ov_SC06_032/ov_SC06_032_jr_8015AE2C.c +++ b/src/ov_SC06_032/ov_SC06_032_jr_8015AE2C.c @@ -1512,7 +1512,259 @@ DEFINE_func_8015B858() /* dedup: shared engine-core @0x8015B858 (src/shared) */ DEFINE_func_8015B8F8() /* dedup: shared engine-core @0x8015B8F8 (src/shared) */ -INCLUDE_ASM("asm/ov_SC06_032/nonmatchings/ov_SC06_032_jr_8015AE2C", func_8015B950); +extern s32 func_8015AE2C(); + +// @class: plumbing +// @stuck: none — MATCH (271/271, pin-free, zero asm). The ONLY residual is DEF-SIDE plumbing, and it is now named exactly: the in-TU instantiation `DEFINE_func_8015BEE4()` (engine_core.h:1851-1855) expands to `extern s32 func_8015B950(void);` INSIDE ov_SC01_077_jr_8015AE2C.c, ~14 lines BELOW this definition, so the 1-param def collides with a `(void)` prototype -> `conflicting types for func_8015B950` (.run/bank_func_8015B950.log). §73 PARAMS axis / T0. Surgical fix = §65b de-macroize that ONE instantiation (blast radius: this TU); the fleet-wide `(void)`->`()` header edit is §63 and must be R22-validated. +/* func_8015B950 (ov_SC01_077_jr_8015AE2C, 271 ins, jtbl_801D8B74) — SESSION-21 re-verified + * + * ── ROUND-2 INDEPENDENT RE-VERIFICATION (2026-07-27, fresh agent, §88e discipline) ───────────── + * match_one : MATCH (271 ins) against the CURRENT tree — §87 staleness re-checked today. + * .text size: compiled .text = 0x43C = 1084 B = 271 ins, EXACTLY the target's declared 0x43C + * ("nonmatching func_8015B950, 0x43C"). So this is NOT a §83a length drift hiding + * behind a zero count — the count is over equal-length streams. + * jtbl : RE-DECODED MECHANICALLY, not inherited. Compiled .rodata = 0x1C = 28 B = 7 words, + * 7x R_MIPS_32 -> .text with implicit addends [58,58,58,E0,F0,100,58]; +0x8015B950 + * = [8015B9A8, 8015B9A8, 8015B9A8, 8015BA30, 8015BA40, 8015BA50, 8015B9A8]. + * Diffed word-for-word against asm/ov_SC01_077/data/tail14.data.s:15-23 — 7/7 identical. + * symcheck : SYMS-DIFF target=35 draft=34, sole MISSING = jtbl_801D8B74. This is the §81 jr + * FALSE POSITIVE, re-confirmed here by reading the relocs: gcc emits its OWN table and + * references it with R_MIPS_HI16/LO16 against the SECTION `.rodata` (t.o +0x40/+0x48), + * so the splat's dlabel NAME can never appear in the draft object's relocation set. + * Nothing is dropped and nothing is invented: the draft's other 34 symbols are exactly + * the target's other 34. + * FAMILY : the x138 remap is clean and §84-safe. Every sibling is 271 ins with an IDENTICAL + * callee set; only THREE names vary per overlay — the two data labels and the jtbl: + * ov_SC01_077 D_80195954 / D_801959C0 / jtbl_801D8B74 + * ov_SC03_099 D_80185A50 / D_80185ABC / jtbl_801BD898 + * ov_SC06_008 D_80187E44 / D_80187EB0 / jtbl_801A8734 + * The pair is always +0x6C apart, and NO literal in this draft encodes that distance + * (both labels are referenced by name), so there is no §84 derived-offset hazard. + * D_8011F9C4 is fleet-constant (main-EXE data) and must NOT be remapped. + * + * match_one: MATCH (271 ins) against the CURRENT tree (§87 staleness re-checked, 2026-07-27). + * PIN-FREE, zero asm, offset-pure (s32 arg0 + raw offsets) — x138 template-safe. + * Provenance: this is the Phase-26 crack (.run/phase26-cracks/func_8015B950.c) re-gated verbatim, + * with ONE deliberate change: the definition's return type void -> s32. + * - `void func_8015B950(s32 arg0)` : MATCH (271 ins) [the Phase-26 form] + * - `s32 func_8015B950(s32 arg0)` : MATCH (271 ins) [shipped — §3a-1 void->s32 is byte-neutral] + * The fleet/engine_core.h canonical decl is `extern s32 func_8015B950(void);` (engine_core.h:1852), + * and the last bank attempt (.run/bank_func_8015B950.log) died on `conflicting types for + * func_8015B950`. Shipping the s32 return kills the §73 RETURN axis for free and leaves only the + * cheap T0 PARAMS axis for the ladder (fix_header_decl.py / --fix-def-sig / cast_call_sites). + * Both forms are byte-identical, so the orchestrator may swap the return type back at zero cost. + * + * SYMBOLS (§58 rules 1/2 — all splat spellings, all verified present): + * D_801959C0 asm/ov_SC01_077/data/tail.data.s:4355 (the state-handler vtable) + * D_80195954 asm/ov_SC01_077/data/tail.data.s:4293 + * D_8011F9C4 main-EXE data; spelled `extern s32 D_8011F9C4;` in 5+ already-banked TUs + * jtbl_801D8B74 asm/ov_SC01_077/data/tail14.data.s:15 (compiler jump table — not named in C) + * + * JTBL VERIFIED (§8a gate): compiled .rodata = exactly 0x1C B / 7 words, 7x R_MIPS_32 .text with + * addends [0x58,0x58,0x58,0xE0,0xF0,0x100,0x58] -> +0x8015B950 = [B9A8,B9A8,B9A8,BA30,BA40,BA50, + * B9A8] == the original words at 0x801D8B74..0x801D8B8C. Bound `sltiu $v0,$v1,0x7` matches. + * The raw dlabel's 8th word 0x00000000 is NOT an entry — it is the intra-TU `.align 3` pad of the + * B34/B54/B74 jtbl chain; the object can never emit it (maspsx drops .align), so it must stay in + * the post-carve RAW data piece (the §53/§62/§81 carve chain applies at bank time). + * + * Same family as the TU's own already-matched func_8015AE2C: 7-case switch on ((s32 (*)(s32))func_801619A4)() + * (0/1/2/6 shared, 3/4/5 own, no default block — out-of-range and every `break` fall to the + * after-switch join), then a chain of "state handler" tests, each dispatching + * D_801959C0[*(u16*)arg0](arg0) and returning. + * + * THREE LEVERS (draft -> MATCH in 3 compiles): + * + * 1. PROLOGUE CONSTANT = an INITIALIZED LOCAL, not a literal in the compare. + * Target opens with `lui $s2, 0xFFF5` in the *prologue*, used once ~200 ins later in + * `slt $v0,$s2,$s1`. No gcc-2.7.2 pass hoists a (set reg const_int) across basic blocks + * (loop.c needs a loop; cse/combine/sched never move insns between BBs) — so the insn must + * have been EMITTED in the first BB, i.e. the constant is a local initialized at the top of + * the function. cse then cannot fold it back into the compare: the `slt` operand predicate is + * `arith_operand`, which rejects a CONST_INT wider than 16 bits, so validate_change fails and + * the pseudo survives. Its live range spans every call -> global.c gives it a callee-saved reg. + * Writing `z > -0xB0000` inline instead emits the `lui` into the branch delay slot next to the + * compare (caller-saved $v0) and the function is 1 insn short. => `s32 lim = -0xB0000;` at top. + * + * 2. `lh` vs `lhu`: a short->short copy is a pure HImode move and gcc emits `lhu`. The target's + * `lh $v0,0x26($s0)` means the value passed through an SImode (int) temp: expand makes + * (set (reg:SI) (sign_extend (mem:HI))) + (set (mem:HI) (subreg:HI ...)), and combine cannot + * merge them (the merged form is mem<-mem, which no movhi accepts) so the sign-extending load + * survives. => route both halfword copies through the `s32 t` temp. + * + * 3. THE `goto` LAYOUT — dodging jump.c's store-flag conversion (jump.c:1005-1065). + * An if/else chain writing 0/1 into `doit` makes gcc collapse the last pair into + * `sltiu $v0,$v0,1`. jump.c fires that conversion when the insn immediately after a + * conditional jump is a lone `SET pseudo, CONST_INT` whose following simplejump targets the + * SAME label as the branch (jump.c:1038 `reallabelprev == temp || ... JUMP_LABEL(temp4) == + * JUMP_LABEL(insn)`) — exactly the shape of `if (c) x=0; else x=1;`. + * The target instead cross-jumps ALL the `doit=0` exits into ONE shared block placed after the + * `doit=1` fall-through; reorg's fill_slots_from_thread then COPIES that single set into all + * three branch delay slots and redirects each branch past it (which is why `addu $v0,$zero, + * $zero` appears 3x in delay slots and the shared block vanishes). A `goto zero;` / `goto one;` + * chain expresses that layout directly, and each conditional jump is then followed by a + * compare/call rather than a lone const set, so the store-flag conversion never triggers. + * GENERAL RULE: multiple predicates that all assign the SAME constant to one flag => write + * them as `goto` to a shared assignment, never as an if/else ladder. + */ +extern s32 D_8011F9C4; +extern s32 D_80195954; + +extern s32 func_80161B18(void); +extern s32 func_801619A4(s32*); +extern s32 func_80149AA8(s32*); +extern void func_80149AD4(s32*); +extern s32 func_80149B54(s32*); +extern void func_80149BAC(s32*); +extern s32 func_801498E0(s32*); +extern s32 func_80149954(s32); +extern s32 func_80149A64(s32*); +extern void func_800CCCC0(s32 a0); +extern s32 func_80149CD4(s32 a0); +extern void func_8015E880(s32*); +extern s32 func_80149744(struct S_80149744*); +extern void func_80149788(void); +extern s32 func_801496D4(void*); +extern void func_80149704(void); +extern int func_80148AFC(void*); +extern void func_80146D90(s32 a0); +extern void func_80154150(s32 a0, s32 a1); +extern void func_801541D8(u8*, s32, s32); +extern s32 func_801488A8(u8*); +extern void func_80147078(s32*, s16); +extern void func_8015A264(void*); +extern s32 func_80013294(void*, void*); +extern void func_80159B70(void*); +extern s32 func_8016F1AC(void); +extern s32 func_80029178(s32 a0); +extern void func_80146DB8(s32*, s32*); +extern s32 func_80161CD0(s32, s32); +extern s32 func_80161208(s32 a0); +extern s32 func_801725A4(u8*); + +s32 func_8015B950(s32 arg0) +{ + + extern void (*D_801959C0[])(void *); + s16 sp10[4]; + s16 sp18[4]; + s32 t; + s32 z; + s32 doit; + s32 lim = -0xB0000; + + if (func_80161B18() != 0) { + return; + } + switch (((s32 (*)(s32))func_801619A4)(arg0)) { + case 0: + case 1: + case 2: + case 6: + if (((s32 (*)(s32))func_80149AA8)(arg0) != 0) { + D_801959C0[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149AD4)(arg0); + return; + } + if (((s32 (*)(s32))func_80149B54)(arg0) != 0) { + D_801959C0[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149BAC)(arg0); + return; + } + break; + case 3: + ((void (*)(s32))func_801498E0)(arg0); + break; + case 4: + ((void (*)(s32))func_80149954)(arg0); + break; + case 5: + if (((s32 (*)(s32))func_80149A64)(arg0) != 0) { + D_801959C0[*(u16 *)arg0]((void *)arg0); + func_800CCCC0(arg0); + return; + } + break; + } + if (func_80149CD4(arg0) != 0) { + D_801959C0[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_8015E880)(arg0); + return; + } + if (((s32 (*)(s32))func_80149744)(arg0) != 0) { + D_801959C0[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149788)(arg0); + return; + } + if (((s32 (*)(s32))func_801496D4)(arg0) != 0) { + D_801959C0[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149704)(arg0); + if (((u8)((s32 (*)(s32))func_80148AFC)(arg0)) == 0) { + func_80146D90(arg0); + } + if ((*(s32 *)(arg0 + 0x24) | *(s32 *)(arg0 + 0x2C)) != 0) { + func_80154150(arg0, 0xF); + } else { + ((void (*)(s32, s32, s32))func_801541D8)(arg0, 0xD, 6); + } + *(s32 *)(arg0 + 0x238) = 1; + return; + } + if (((s32 (*)(s32))func_801488A8)(arg0) != 0) { + sp10[0] = 0; + sp10[1] = 0; + sp10[2] = 0; + t = *(s16 *)(arg0 + 0x26); + sp18[0] = t; + sp18[1] = 0; + t = *(s16 *)(arg0 + 0x2E); + sp18[2] = t; + D_801959C0[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 1); + ((void (*)(s32))func_8015A264)(arg0); + t = -(((s32 (*)(s16 *, s16 *))func_80013294)(sp10, sp18) << 0x10); + if (t < *(s32 *)(arg0 + 0x2C)) { + *(s32 *)(arg0 + 0x2C) = t; + } + return; + } + if (*(u16 *)(arg0 + 0xB8) == 0x8000) { + D_801959C0[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 0); + ((void (*)(s32))func_80159B70)(arg0); + return; + } + z = *(s32 *)(arg0 + 0x2C); + if (func_8016F1AC() != 0) { + goto zero; + } + if (z <= lim) { + goto one; + } + if (D_8011F9C4 == 0) { + goto zero; + } + if (((u8)func_80029178(0x21)) != 0) { + goto zero; + } +one: + doit = 1; + goto join; +zero: + doit = 0; +join: + if (doit != 0) { + D_801959C0[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 0); + ((void (*)(s32))func_80159B70)(arg0); + func_80154150(arg0, 9); + ((void (*)(s32, s32 *))func_80146DB8)(arg0, &D_80195954); + ((void (*)(s32, s32))func_80161CD0)(arg0, *(u16 *)(arg0 + 0x16E)); + return; + } + if (func_80161208(arg0) == 0) { + ((void (*)(s32))func_801725A4)(arg0); + } +} DEFINE_func_8015BD8C() /* dedup: shared engine-core @0x8015BD8C (src/shared) */ diff --git a/src/ov_SC06_033/ov_SC06_033_jr_8015AE2C.c b/src/ov_SC06_033/ov_SC06_033_jr_8015AE2C.c index db8c035b7..e2c336e32 100644 --- a/src/ov_SC06_033/ov_SC06_033_jr_8015AE2C.c +++ b/src/ov_SC06_033/ov_SC06_033_jr_8015AE2C.c @@ -1512,7 +1512,259 @@ DEFINE_func_8015B858() /* dedup: shared engine-core @0x8015B858 (src/shared) */ DEFINE_func_8015B8F8() /* dedup: shared engine-core @0x8015B8F8 (src/shared) */ -INCLUDE_ASM("asm/ov_SC06_033/nonmatchings/ov_SC06_033_jr_8015AE2C", func_8015B950); +extern s32 func_8015AE2C(); + +// @class: plumbing +// @stuck: none — MATCH (271/271, pin-free, zero asm). The ONLY residual is DEF-SIDE plumbing, and it is now named exactly: the in-TU instantiation `DEFINE_func_8015BEE4()` (engine_core.h:1851-1855) expands to `extern s32 func_8015B950(void);` INSIDE ov_SC01_077_jr_8015AE2C.c, ~14 lines BELOW this definition, so the 1-param def collides with a `(void)` prototype -> `conflicting types for func_8015B950` (.run/bank_func_8015B950.log). §73 PARAMS axis / T0. Surgical fix = §65b de-macroize that ONE instantiation (blast radius: this TU); the fleet-wide `(void)`->`()` header edit is §63 and must be R22-validated. +/* func_8015B950 (ov_SC01_077_jr_8015AE2C, 271 ins, jtbl_801D8B74) — SESSION-21 re-verified + * + * ── ROUND-2 INDEPENDENT RE-VERIFICATION (2026-07-27, fresh agent, §88e discipline) ───────────── + * match_one : MATCH (271 ins) against the CURRENT tree — §87 staleness re-checked today. + * .text size: compiled .text = 0x43C = 1084 B = 271 ins, EXACTLY the target's declared 0x43C + * ("nonmatching func_8015B950, 0x43C"). So this is NOT a §83a length drift hiding + * behind a zero count — the count is over equal-length streams. + * jtbl : RE-DECODED MECHANICALLY, not inherited. Compiled .rodata = 0x1C = 28 B = 7 words, + * 7x R_MIPS_32 -> .text with implicit addends [58,58,58,E0,F0,100,58]; +0x8015B950 + * = [8015B9A8, 8015B9A8, 8015B9A8, 8015BA30, 8015BA40, 8015BA50, 8015B9A8]. + * Diffed word-for-word against asm/ov_SC01_077/data/tail14.data.s:15-23 — 7/7 identical. + * symcheck : SYMS-DIFF target=35 draft=34, sole MISSING = jtbl_801D8B74. This is the §81 jr + * FALSE POSITIVE, re-confirmed here by reading the relocs: gcc emits its OWN table and + * references it with R_MIPS_HI16/LO16 against the SECTION `.rodata` (t.o +0x40/+0x48), + * so the splat's dlabel NAME can never appear in the draft object's relocation set. + * Nothing is dropped and nothing is invented: the draft's other 34 symbols are exactly + * the target's other 34. + * FAMILY : the x138 remap is clean and §84-safe. Every sibling is 271 ins with an IDENTICAL + * callee set; only THREE names vary per overlay — the two data labels and the jtbl: + * ov_SC01_077 D_80193E64 / D_80193ED0 / jtbl_801D8B74 + * ov_SC03_099 D_80185A50 / D_80185ABC / jtbl_801BD898 + * ov_SC06_008 D_80187E44 / D_80187EB0 / jtbl_801A8734 + * The pair is always +0x6C apart, and NO literal in this draft encodes that distance + * (both labels are referenced by name), so there is no §84 derived-offset hazard. + * D_8011F9C4 is fleet-constant (main-EXE data) and must NOT be remapped. + * + * match_one: MATCH (271 ins) against the CURRENT tree (§87 staleness re-checked, 2026-07-27). + * PIN-FREE, zero asm, offset-pure (s32 arg0 + raw offsets) — x138 template-safe. + * Provenance: this is the Phase-26 crack (.run/phase26-cracks/func_8015B950.c) re-gated verbatim, + * with ONE deliberate change: the definition's return type void -> s32. + * - `void func_8015B950(s32 arg0)` : MATCH (271 ins) [the Phase-26 form] + * - `s32 func_8015B950(s32 arg0)` : MATCH (271 ins) [shipped — §3a-1 void->s32 is byte-neutral] + * The fleet/engine_core.h canonical decl is `extern s32 func_8015B950(void);` (engine_core.h:1852), + * and the last bank attempt (.run/bank_func_8015B950.log) died on `conflicting types for + * func_8015B950`. Shipping the s32 return kills the §73 RETURN axis for free and leaves only the + * cheap T0 PARAMS axis for the ladder (fix_header_decl.py / --fix-def-sig / cast_call_sites). + * Both forms are byte-identical, so the orchestrator may swap the return type back at zero cost. + * + * SYMBOLS (§58 rules 1/2 — all splat spellings, all verified present): + * D_80193ED0 asm/ov_SC01_077/data/tail.data.s:4355 (the state-handler vtable) + * D_80193E64 asm/ov_SC01_077/data/tail.data.s:4293 + * D_8011F9C4 main-EXE data; spelled `extern s32 D_8011F9C4;` in 5+ already-banked TUs + * jtbl_801D8B74 asm/ov_SC01_077/data/tail14.data.s:15 (compiler jump table — not named in C) + * + * JTBL VERIFIED (§8a gate): compiled .rodata = exactly 0x1C B / 7 words, 7x R_MIPS_32 .text with + * addends [0x58,0x58,0x58,0xE0,0xF0,0x100,0x58] -> +0x8015B950 = [B9A8,B9A8,B9A8,BA30,BA40,BA50, + * B9A8] == the original words at 0x801D8B74..0x801D8B8C. Bound `sltiu $v0,$v1,0x7` matches. + * The raw dlabel's 8th word 0x00000000 is NOT an entry — it is the intra-TU `.align 3` pad of the + * B34/B54/B74 jtbl chain; the object can never emit it (maspsx drops .align), so it must stay in + * the post-carve RAW data piece (the §53/§62/§81 carve chain applies at bank time). + * + * Same family as the TU's own already-matched func_8015AE2C: 7-case switch on ((s32 (*)(s32))func_801619A4)() + * (0/1/2/6 shared, 3/4/5 own, no default block — out-of-range and every `break` fall to the + * after-switch join), then a chain of "state handler" tests, each dispatching + * D_80193ED0[*(u16*)arg0](arg0) and returning. + * + * THREE LEVERS (draft -> MATCH in 3 compiles): + * + * 1. PROLOGUE CONSTANT = an INITIALIZED LOCAL, not a literal in the compare. + * Target opens with `lui $s2, 0xFFF5` in the *prologue*, used once ~200 ins later in + * `slt $v0,$s2,$s1`. No gcc-2.7.2 pass hoists a (set reg const_int) across basic blocks + * (loop.c needs a loop; cse/combine/sched never move insns between BBs) — so the insn must + * have been EMITTED in the first BB, i.e. the constant is a local initialized at the top of + * the function. cse then cannot fold it back into the compare: the `slt` operand predicate is + * `arith_operand`, which rejects a CONST_INT wider than 16 bits, so validate_change fails and + * the pseudo survives. Its live range spans every call -> global.c gives it a callee-saved reg. + * Writing `z > -0xB0000` inline instead emits the `lui` into the branch delay slot next to the + * compare (caller-saved $v0) and the function is 1 insn short. => `s32 lim = -0xB0000;` at top. + * + * 2. `lh` vs `lhu`: a short->short copy is a pure HImode move and gcc emits `lhu`. The target's + * `lh $v0,0x26($s0)` means the value passed through an SImode (int) temp: expand makes + * (set (reg:SI) (sign_extend (mem:HI))) + (set (mem:HI) (subreg:HI ...)), and combine cannot + * merge them (the merged form is mem<-mem, which no movhi accepts) so the sign-extending load + * survives. => route both halfword copies through the `s32 t` temp. + * + * 3. THE `goto` LAYOUT — dodging jump.c's store-flag conversion (jump.c:1005-1065). + * An if/else chain writing 0/1 into `doit` makes gcc collapse the last pair into + * `sltiu $v0,$v0,1`. jump.c fires that conversion when the insn immediately after a + * conditional jump is a lone `SET pseudo, CONST_INT` whose following simplejump targets the + * SAME label as the branch (jump.c:1038 `reallabelprev == temp || ... JUMP_LABEL(temp4) == + * JUMP_LABEL(insn)`) — exactly the shape of `if (c) x=0; else x=1;`. + * The target instead cross-jumps ALL the `doit=0` exits into ONE shared block placed after the + * `doit=1` fall-through; reorg's fill_slots_from_thread then COPIES that single set into all + * three branch delay slots and redirects each branch past it (which is why `addu $v0,$zero, + * $zero` appears 3x in delay slots and the shared block vanishes). A `goto zero;` / `goto one;` + * chain expresses that layout directly, and each conditional jump is then followed by a + * compare/call rather than a lone const set, so the store-flag conversion never triggers. + * GENERAL RULE: multiple predicates that all assign the SAME constant to one flag => write + * them as `goto` to a shared assignment, never as an if/else ladder. + */ +extern s32 D_8011F9C4; +extern s32 D_80193E64; + +extern s32 func_80161B18(void); +extern s32 func_801619A4(s32*); +extern s32 func_80149AA8(s32*); +extern void func_80149AD4(s32*); +extern s32 func_80149B54(s32*); +extern void func_80149BAC(s32*); +extern s32 func_801498E0(s32*); +extern s32 func_80149954(s32); +extern s32 func_80149A64(s32*); +extern void func_800CCCC0(s32 a0); +extern s32 func_80149CD4(s32 a0); +extern void func_8015E880(s32*); +extern s32 func_80149744(struct S_80149744*); +extern void func_80149788(void); +extern s32 func_801496D4(void*); +extern void func_80149704(void); +extern int func_80148AFC(void*); +extern void func_80146D90(s32 a0); +extern void func_80154150(s32 a0, s32 a1); +extern void func_801541D8(u8*, s32, s32); +extern s32 func_801488A8(u8*); +extern void func_80147078(s32*, s16); +extern void func_8015A264(void*); +extern s32 func_80013294(void*, void*); +extern void func_80159B70(void*); +extern s32 func_8016F1AC(void); +extern s32 func_80029178(s32 a0); +extern void func_80146DB8(s32*, s32*); +extern s32 func_80161CD0(s32, s32); +extern s32 func_80161208(s32 a0); +extern s32 func_801725A4(u8*); + +s32 func_8015B950(s32 arg0) +{ + + extern void (*D_80193ED0[])(void *); + s16 sp10[4]; + s16 sp18[4]; + s32 t; + s32 z; + s32 doit; + s32 lim = -0xB0000; + + if (func_80161B18() != 0) { + return; + } + switch (((s32 (*)(s32))func_801619A4)(arg0)) { + case 0: + case 1: + case 2: + case 6: + if (((s32 (*)(s32))func_80149AA8)(arg0) != 0) { + D_80193ED0[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149AD4)(arg0); + return; + } + if (((s32 (*)(s32))func_80149B54)(arg0) != 0) { + D_80193ED0[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149BAC)(arg0); + return; + } + break; + case 3: + ((void (*)(s32))func_801498E0)(arg0); + break; + case 4: + ((void (*)(s32))func_80149954)(arg0); + break; + case 5: + if (((s32 (*)(s32))func_80149A64)(arg0) != 0) { + D_80193ED0[*(u16 *)arg0]((void *)arg0); + func_800CCCC0(arg0); + return; + } + break; + } + if (func_80149CD4(arg0) != 0) { + D_80193ED0[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_8015E880)(arg0); + return; + } + if (((s32 (*)(s32))func_80149744)(arg0) != 0) { + D_80193ED0[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149788)(arg0); + return; + } + if (((s32 (*)(s32))func_801496D4)(arg0) != 0) { + D_80193ED0[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149704)(arg0); + if (((u8)((s32 (*)(s32))func_80148AFC)(arg0)) == 0) { + func_80146D90(arg0); + } + if ((*(s32 *)(arg0 + 0x24) | *(s32 *)(arg0 + 0x2C)) != 0) { + func_80154150(arg0, 0xF); + } else { + ((void (*)(s32, s32, s32))func_801541D8)(arg0, 0xD, 6); + } + *(s32 *)(arg0 + 0x238) = 1; + return; + } + if (((s32 (*)(s32))func_801488A8)(arg0) != 0) { + sp10[0] = 0; + sp10[1] = 0; + sp10[2] = 0; + t = *(s16 *)(arg0 + 0x26); + sp18[0] = t; + sp18[1] = 0; + t = *(s16 *)(arg0 + 0x2E); + sp18[2] = t; + D_80193ED0[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 1); + ((void (*)(s32))func_8015A264)(arg0); + t = -(((s32 (*)(s16 *, s16 *))func_80013294)(sp10, sp18) << 0x10); + if (t < *(s32 *)(arg0 + 0x2C)) { + *(s32 *)(arg0 + 0x2C) = t; + } + return; + } + if (*(u16 *)(arg0 + 0xB8) == 0x8000) { + D_80193ED0[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 0); + ((void (*)(s32))func_80159B70)(arg0); + return; + } + z = *(s32 *)(arg0 + 0x2C); + if (func_8016F1AC() != 0) { + goto zero; + } + if (z <= lim) { + goto one; + } + if (D_8011F9C4 == 0) { + goto zero; + } + if (((u8)func_80029178(0x21)) != 0) { + goto zero; + } +one: + doit = 1; + goto join; +zero: + doit = 0; +join: + if (doit != 0) { + D_80193ED0[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 0); + ((void (*)(s32))func_80159B70)(arg0); + func_80154150(arg0, 9); + ((void (*)(s32, s32 *))func_80146DB8)(arg0, &D_80193E64); + ((void (*)(s32, s32))func_80161CD0)(arg0, *(u16 *)(arg0 + 0x16E)); + return; + } + if (func_80161208(arg0) == 0) { + ((void (*)(s32))func_801725A4)(arg0); + } +} DEFINE_func_8015BD8C() /* dedup: shared engine-core @0x8015BD8C (src/shared) */ diff --git a/src/ov_SC07_000/ov_SC07_000_jr_8015AE2C.c b/src/ov_SC07_000/ov_SC07_000_jr_8015AE2C.c index 13989c1b2..07fcab0cb 100644 --- a/src/ov_SC07_000/ov_SC07_000_jr_8015AE2C.c +++ b/src/ov_SC07_000/ov_SC07_000_jr_8015AE2C.c @@ -1512,7 +1512,259 @@ DEFINE_func_8015B858() /* dedup: shared engine-core @0x8015B858 (src/shared) */ DEFINE_func_8015B8F8() /* dedup: shared engine-core @0x8015B8F8 (src/shared) */ -INCLUDE_ASM("asm/ov_SC07_000/nonmatchings/ov_SC07_000_jr_8015AE2C", func_8015B950); +extern s32 func_8015AE2C(); + +// @class: plumbing +// @stuck: none — MATCH (271/271, pin-free, zero asm). The ONLY residual is DEF-SIDE plumbing, and it is now named exactly: the in-TU instantiation `DEFINE_func_8015BEE4()` (engine_core.h:1851-1855) expands to `extern s32 func_8015B950(void);` INSIDE ov_SC01_077_jr_8015AE2C.c, ~14 lines BELOW this definition, so the 1-param def collides with a `(void)` prototype -> `conflicting types for func_8015B950` (.run/bank_func_8015B950.log). §73 PARAMS axis / T0. Surgical fix = §65b de-macroize that ONE instantiation (blast radius: this TU); the fleet-wide `(void)`->`()` header edit is §63 and must be R22-validated. +/* func_8015B950 (ov_SC01_077_jr_8015AE2C, 271 ins, jtbl_801D8B74) — SESSION-21 re-verified + * + * ── ROUND-2 INDEPENDENT RE-VERIFICATION (2026-07-27, fresh agent, §88e discipline) ───────────── + * match_one : MATCH (271 ins) against the CURRENT tree — §87 staleness re-checked today. + * .text size: compiled .text = 0x43C = 1084 B = 271 ins, EXACTLY the target's declared 0x43C + * ("nonmatching func_8015B950, 0x43C"). So this is NOT a §83a length drift hiding + * behind a zero count — the count is over equal-length streams. + * jtbl : RE-DECODED MECHANICALLY, not inherited. Compiled .rodata = 0x1C = 28 B = 7 words, + * 7x R_MIPS_32 -> .text with implicit addends [58,58,58,E0,F0,100,58]; +0x8015B950 + * = [8015B9A8, 8015B9A8, 8015B9A8, 8015BA30, 8015BA40, 8015BA50, 8015B9A8]. + * Diffed word-for-word against asm/ov_SC01_077/data/tail14.data.s:15-23 — 7/7 identical. + * symcheck : SYMS-DIFF target=35 draft=34, sole MISSING = jtbl_801D8B74. This is the §81 jr + * FALSE POSITIVE, re-confirmed here by reading the relocs: gcc emits its OWN table and + * references it with R_MIPS_HI16/LO16 against the SECTION `.rodata` (t.o +0x40/+0x48), + * so the splat's dlabel NAME can never appear in the draft object's relocation set. + * Nothing is dropped and nothing is invented: the draft's other 34 symbols are exactly + * the target's other 34. + * FAMILY : the x138 remap is clean and §84-safe. Every sibling is 271 ins with an IDENTICAL + * callee set; only THREE names vary per overlay — the two data labels and the jtbl: + * ov_SC01_077 D_80184CAC / D_80184D18 / jtbl_801D8B74 + * ov_SC03_099 D_80185A50 / D_80185ABC / jtbl_801BD898 + * ov_SC06_008 D_80187E44 / D_80187EB0 / jtbl_801A8734 + * The pair is always +0x6C apart, and NO literal in this draft encodes that distance + * (both labels are referenced by name), so there is no §84 derived-offset hazard. + * D_8011F9C4 is fleet-constant (main-EXE data) and must NOT be remapped. + * + * match_one: MATCH (271 ins) against the CURRENT tree (§87 staleness re-checked, 2026-07-27). + * PIN-FREE, zero asm, offset-pure (s32 arg0 + raw offsets) — x138 template-safe. + * Provenance: this is the Phase-26 crack (.run/phase26-cracks/func_8015B950.c) re-gated verbatim, + * with ONE deliberate change: the definition's return type void -> s32. + * - `void func_8015B950(s32 arg0)` : MATCH (271 ins) [the Phase-26 form] + * - `s32 func_8015B950(s32 arg0)` : MATCH (271 ins) [shipped — §3a-1 void->s32 is byte-neutral] + * The fleet/engine_core.h canonical decl is `extern s32 func_8015B950(void);` (engine_core.h:1852), + * and the last bank attempt (.run/bank_func_8015B950.log) died on `conflicting types for + * func_8015B950`. Shipping the s32 return kills the §73 RETURN axis for free and leaves only the + * cheap T0 PARAMS axis for the ladder (fix_header_decl.py / --fix-def-sig / cast_call_sites). + * Both forms are byte-identical, so the orchestrator may swap the return type back at zero cost. + * + * SYMBOLS (§58 rules 1/2 — all splat spellings, all verified present): + * D_80184D18 asm/ov_SC01_077/data/tail.data.s:4355 (the state-handler vtable) + * D_80184CAC asm/ov_SC01_077/data/tail.data.s:4293 + * D_8011F9C4 main-EXE data; spelled `extern s32 D_8011F9C4;` in 5+ already-banked TUs + * jtbl_801D8B74 asm/ov_SC01_077/data/tail14.data.s:15 (compiler jump table — not named in C) + * + * JTBL VERIFIED (§8a gate): compiled .rodata = exactly 0x1C B / 7 words, 7x R_MIPS_32 .text with + * addends [0x58,0x58,0x58,0xE0,0xF0,0x100,0x58] -> +0x8015B950 = [B9A8,B9A8,B9A8,BA30,BA40,BA50, + * B9A8] == the original words at 0x801D8B74..0x801D8B8C. Bound `sltiu $v0,$v1,0x7` matches. + * The raw dlabel's 8th word 0x00000000 is NOT an entry — it is the intra-TU `.align 3` pad of the + * B34/B54/B74 jtbl chain; the object can never emit it (maspsx drops .align), so it must stay in + * the post-carve RAW data piece (the §53/§62/§81 carve chain applies at bank time). + * + * Same family as the TU's own already-matched func_8015AE2C: 7-case switch on ((s32 (*)(s32))func_801619A4)() + * (0/1/2/6 shared, 3/4/5 own, no default block — out-of-range and every `break` fall to the + * after-switch join), then a chain of "state handler" tests, each dispatching + * D_80184D18[*(u16*)arg0](arg0) and returning. + * + * THREE LEVERS (draft -> MATCH in 3 compiles): + * + * 1. PROLOGUE CONSTANT = an INITIALIZED LOCAL, not a literal in the compare. + * Target opens with `lui $s2, 0xFFF5` in the *prologue*, used once ~200 ins later in + * `slt $v0,$s2,$s1`. No gcc-2.7.2 pass hoists a (set reg const_int) across basic blocks + * (loop.c needs a loop; cse/combine/sched never move insns between BBs) — so the insn must + * have been EMITTED in the first BB, i.e. the constant is a local initialized at the top of + * the function. cse then cannot fold it back into the compare: the `slt` operand predicate is + * `arith_operand`, which rejects a CONST_INT wider than 16 bits, so validate_change fails and + * the pseudo survives. Its live range spans every call -> global.c gives it a callee-saved reg. + * Writing `z > -0xB0000` inline instead emits the `lui` into the branch delay slot next to the + * compare (caller-saved $v0) and the function is 1 insn short. => `s32 lim = -0xB0000;` at top. + * + * 2. `lh` vs `lhu`: a short->short copy is a pure HImode move and gcc emits `lhu`. The target's + * `lh $v0,0x26($s0)` means the value passed through an SImode (int) temp: expand makes + * (set (reg:SI) (sign_extend (mem:HI))) + (set (mem:HI) (subreg:HI ...)), and combine cannot + * merge them (the merged form is mem<-mem, which no movhi accepts) so the sign-extending load + * survives. => route both halfword copies through the `s32 t` temp. + * + * 3. THE `goto` LAYOUT — dodging jump.c's store-flag conversion (jump.c:1005-1065). + * An if/else chain writing 0/1 into `doit` makes gcc collapse the last pair into + * `sltiu $v0,$v0,1`. jump.c fires that conversion when the insn immediately after a + * conditional jump is a lone `SET pseudo, CONST_INT` whose following simplejump targets the + * SAME label as the branch (jump.c:1038 `reallabelprev == temp || ... JUMP_LABEL(temp4) == + * JUMP_LABEL(insn)`) — exactly the shape of `if (c) x=0; else x=1;`. + * The target instead cross-jumps ALL the `doit=0` exits into ONE shared block placed after the + * `doit=1` fall-through; reorg's fill_slots_from_thread then COPIES that single set into all + * three branch delay slots and redirects each branch past it (which is why `addu $v0,$zero, + * $zero` appears 3x in delay slots and the shared block vanishes). A `goto zero;` / `goto one;` + * chain expresses that layout directly, and each conditional jump is then followed by a + * compare/call rather than a lone const set, so the store-flag conversion never triggers. + * GENERAL RULE: multiple predicates that all assign the SAME constant to one flag => write + * them as `goto` to a shared assignment, never as an if/else ladder. + */ +extern s32 D_8011F9C4; +extern s32 D_80184CAC; + +extern s32 func_80161B18(void); +extern s32 func_801619A4(s32*); +extern s32 func_80149AA8(s32*); +extern void func_80149AD4(s32*); +extern s32 func_80149B54(s32*); +extern void func_80149BAC(s32*); +extern s32 func_801498E0(s32*); +extern s32 func_80149954(s32); +extern s32 func_80149A64(s32*); +extern void func_800CCCC0(s32 a0); +extern s32 func_80149CD4(s32 a0); +extern void func_8015E880(s32*); +extern s32 func_80149744(struct S_80149744*); +extern void func_80149788(void); +extern s32 func_801496D4(void*); +extern void func_80149704(void); +extern int func_80148AFC(void*); +extern void func_80146D90(s32 a0); +extern void func_80154150(s32 a0, s32 a1); +extern void func_801541D8(u8*, s32, s32); +extern s32 func_801488A8(u8*); +extern void func_80147078(s32*, s16); +extern void func_8015A264(void*); +extern s32 func_80013294(void*, void*); +extern void func_80159B70(void*); +extern s32 func_8016F1AC(void); +extern s32 func_80029178(s32 a0); +extern void func_80146DB8(s32*, s32*); +extern s32 func_80161CD0(s32, s32); +extern s32 func_80161208(s32 a0); +extern s32 func_801725A4(u8*); + +s32 func_8015B950(s32 arg0) +{ + + extern void (*D_80184D18[])(void *); + s16 sp10[4]; + s16 sp18[4]; + s32 t; + s32 z; + s32 doit; + s32 lim = -0xB0000; + + if (func_80161B18() != 0) { + return; + } + switch (((s32 (*)(s32))func_801619A4)(arg0)) { + case 0: + case 1: + case 2: + case 6: + if (((s32 (*)(s32))func_80149AA8)(arg0) != 0) { + D_80184D18[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149AD4)(arg0); + return; + } + if (((s32 (*)(s32))func_80149B54)(arg0) != 0) { + D_80184D18[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149BAC)(arg0); + return; + } + break; + case 3: + ((void (*)(s32))func_801498E0)(arg0); + break; + case 4: + ((void (*)(s32))func_80149954)(arg0); + break; + case 5: + if (((s32 (*)(s32))func_80149A64)(arg0) != 0) { + D_80184D18[*(u16 *)arg0]((void *)arg0); + func_800CCCC0(arg0); + return; + } + break; + } + if (func_80149CD4(arg0) != 0) { + D_80184D18[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_8015E880)(arg0); + return; + } + if (((s32 (*)(s32))func_80149744)(arg0) != 0) { + D_80184D18[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149788)(arg0); + return; + } + if (((s32 (*)(s32))func_801496D4)(arg0) != 0) { + D_80184D18[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149704)(arg0); + if (((u8)((s32 (*)(s32))func_80148AFC)(arg0)) == 0) { + func_80146D90(arg0); + } + if ((*(s32 *)(arg0 + 0x24) | *(s32 *)(arg0 + 0x2C)) != 0) { + func_80154150(arg0, 0xF); + } else { + ((void (*)(s32, s32, s32))func_801541D8)(arg0, 0xD, 6); + } + *(s32 *)(arg0 + 0x238) = 1; + return; + } + if (((s32 (*)(s32))func_801488A8)(arg0) != 0) { + sp10[0] = 0; + sp10[1] = 0; + sp10[2] = 0; + t = *(s16 *)(arg0 + 0x26); + sp18[0] = t; + sp18[1] = 0; + t = *(s16 *)(arg0 + 0x2E); + sp18[2] = t; + D_80184D18[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 1); + ((void (*)(s32))func_8015A264)(arg0); + t = -(((s32 (*)(s16 *, s16 *))func_80013294)(sp10, sp18) << 0x10); + if (t < *(s32 *)(arg0 + 0x2C)) { + *(s32 *)(arg0 + 0x2C) = t; + } + return; + } + if (*(u16 *)(arg0 + 0xB8) == 0x8000) { + D_80184D18[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 0); + ((void (*)(s32))func_80159B70)(arg0); + return; + } + z = *(s32 *)(arg0 + 0x2C); + if (func_8016F1AC() != 0) { + goto zero; + } + if (z <= lim) { + goto one; + } + if (D_8011F9C4 == 0) { + goto zero; + } + if (((u8)func_80029178(0x21)) != 0) { + goto zero; + } +one: + doit = 1; + goto join; +zero: + doit = 0; +join: + if (doit != 0) { + D_80184D18[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 0); + ((void (*)(s32))func_80159B70)(arg0); + func_80154150(arg0, 9); + ((void (*)(s32, s32 *))func_80146DB8)(arg0, &D_80184CAC); + ((void (*)(s32, s32))func_80161CD0)(arg0, *(u16 *)(arg0 + 0x16E)); + return; + } + if (func_80161208(arg0) == 0) { + ((void (*)(s32))func_801725A4)(arg0); + } +} DEFINE_func_8015BD8C() /* dedup: shared engine-core @0x8015BD8C (src/shared) */ diff --git a/src/ov_SC07_001/ov_SC07_001_jr_8015AE2C.c b/src/ov_SC07_001/ov_SC07_001_jr_8015AE2C.c index 3d6ffb772..531cb36cd 100644 --- a/src/ov_SC07_001/ov_SC07_001_jr_8015AE2C.c +++ b/src/ov_SC07_001/ov_SC07_001_jr_8015AE2C.c @@ -1512,7 +1512,259 @@ DEFINE_func_8015B858() /* dedup: shared engine-core @0x8015B858 (src/shared) */ DEFINE_func_8015B8F8() /* dedup: shared engine-core @0x8015B8F8 (src/shared) */ -INCLUDE_ASM("asm/ov_SC07_001/nonmatchings/ov_SC07_001_jr_8015AE2C", func_8015B950); +extern s32 func_8015AE2C(); + +// @class: plumbing +// @stuck: none — MATCH (271/271, pin-free, zero asm). The ONLY residual is DEF-SIDE plumbing, and it is now named exactly: the in-TU instantiation `DEFINE_func_8015BEE4()` (engine_core.h:1851-1855) expands to `extern s32 func_8015B950(void);` INSIDE ov_SC01_077_jr_8015AE2C.c, ~14 lines BELOW this definition, so the 1-param def collides with a `(void)` prototype -> `conflicting types for func_8015B950` (.run/bank_func_8015B950.log). §73 PARAMS axis / T0. Surgical fix = §65b de-macroize that ONE instantiation (blast radius: this TU); the fleet-wide `(void)`->`()` header edit is §63 and must be R22-validated. +/* func_8015B950 (ov_SC01_077_jr_8015AE2C, 271 ins, jtbl_801D8B74) — SESSION-21 re-verified + * + * ── ROUND-2 INDEPENDENT RE-VERIFICATION (2026-07-27, fresh agent, §88e discipline) ───────────── + * match_one : MATCH (271 ins) against the CURRENT tree — §87 staleness re-checked today. + * .text size: compiled .text = 0x43C = 1084 B = 271 ins, EXACTLY the target's declared 0x43C + * ("nonmatching func_8015B950, 0x43C"). So this is NOT a §83a length drift hiding + * behind a zero count — the count is over equal-length streams. + * jtbl : RE-DECODED MECHANICALLY, not inherited. Compiled .rodata = 0x1C = 28 B = 7 words, + * 7x R_MIPS_32 -> .text with implicit addends [58,58,58,E0,F0,100,58]; +0x8015B950 + * = [8015B9A8, 8015B9A8, 8015B9A8, 8015BA30, 8015BA40, 8015BA50, 8015B9A8]. + * Diffed word-for-word against asm/ov_SC01_077/data/tail14.data.s:15-23 — 7/7 identical. + * symcheck : SYMS-DIFF target=35 draft=34, sole MISSING = jtbl_801D8B74. This is the §81 jr + * FALSE POSITIVE, re-confirmed here by reading the relocs: gcc emits its OWN table and + * references it with R_MIPS_HI16/LO16 against the SECTION `.rodata` (t.o +0x40/+0x48), + * so the splat's dlabel NAME can never appear in the draft object's relocation set. + * Nothing is dropped and nothing is invented: the draft's other 34 symbols are exactly + * the target's other 34. + * FAMILY : the x138 remap is clean and §84-safe. Every sibling is 271 ins with an IDENTICAL + * callee set; only THREE names vary per overlay — the two data labels and the jtbl: + * ov_SC01_077 D_80183B5C / D_80183BC8 / jtbl_801D8B74 + * ov_SC03_099 D_80185A50 / D_80185ABC / jtbl_801BD898 + * ov_SC06_008 D_80187E44 / D_80187EB0 / jtbl_801A8734 + * The pair is always +0x6C apart, and NO literal in this draft encodes that distance + * (both labels are referenced by name), so there is no §84 derived-offset hazard. + * D_8011F9C4 is fleet-constant (main-EXE data) and must NOT be remapped. + * + * match_one: MATCH (271 ins) against the CURRENT tree (§87 staleness re-checked, 2026-07-27). + * PIN-FREE, zero asm, offset-pure (s32 arg0 + raw offsets) — x138 template-safe. + * Provenance: this is the Phase-26 crack (.run/phase26-cracks/func_8015B950.c) re-gated verbatim, + * with ONE deliberate change: the definition's return type void -> s32. + * - `void func_8015B950(s32 arg0)` : MATCH (271 ins) [the Phase-26 form] + * - `s32 func_8015B950(s32 arg0)` : MATCH (271 ins) [shipped — §3a-1 void->s32 is byte-neutral] + * The fleet/engine_core.h canonical decl is `extern s32 func_8015B950(void);` (engine_core.h:1852), + * and the last bank attempt (.run/bank_func_8015B950.log) died on `conflicting types for + * func_8015B950`. Shipping the s32 return kills the §73 RETURN axis for free and leaves only the + * cheap T0 PARAMS axis for the ladder (fix_header_decl.py / --fix-def-sig / cast_call_sites). + * Both forms are byte-identical, so the orchestrator may swap the return type back at zero cost. + * + * SYMBOLS (§58 rules 1/2 — all splat spellings, all verified present): + * D_80183BC8 asm/ov_SC01_077/data/tail.data.s:4355 (the state-handler vtable) + * D_80183B5C asm/ov_SC01_077/data/tail.data.s:4293 + * D_8011F9C4 main-EXE data; spelled `extern s32 D_8011F9C4;` in 5+ already-banked TUs + * jtbl_801D8B74 asm/ov_SC01_077/data/tail14.data.s:15 (compiler jump table — not named in C) + * + * JTBL VERIFIED (§8a gate): compiled .rodata = exactly 0x1C B / 7 words, 7x R_MIPS_32 .text with + * addends [0x58,0x58,0x58,0xE0,0xF0,0x100,0x58] -> +0x8015B950 = [B9A8,B9A8,B9A8,BA30,BA40,BA50, + * B9A8] == the original words at 0x801D8B74..0x801D8B8C. Bound `sltiu $v0,$v1,0x7` matches. + * The raw dlabel's 8th word 0x00000000 is NOT an entry — it is the intra-TU `.align 3` pad of the + * B34/B54/B74 jtbl chain; the object can never emit it (maspsx drops .align), so it must stay in + * the post-carve RAW data piece (the §53/§62/§81 carve chain applies at bank time). + * + * Same family as the TU's own already-matched func_8015AE2C: 7-case switch on ((s32 (*)(s32))func_801619A4)() + * (0/1/2/6 shared, 3/4/5 own, no default block — out-of-range and every `break` fall to the + * after-switch join), then a chain of "state handler" tests, each dispatching + * D_80183BC8[*(u16*)arg0](arg0) and returning. + * + * THREE LEVERS (draft -> MATCH in 3 compiles): + * + * 1. PROLOGUE CONSTANT = an INITIALIZED LOCAL, not a literal in the compare. + * Target opens with `lui $s2, 0xFFF5` in the *prologue*, used once ~200 ins later in + * `slt $v0,$s2,$s1`. No gcc-2.7.2 pass hoists a (set reg const_int) across basic blocks + * (loop.c needs a loop; cse/combine/sched never move insns between BBs) — so the insn must + * have been EMITTED in the first BB, i.e. the constant is a local initialized at the top of + * the function. cse then cannot fold it back into the compare: the `slt` operand predicate is + * `arith_operand`, which rejects a CONST_INT wider than 16 bits, so validate_change fails and + * the pseudo survives. Its live range spans every call -> global.c gives it a callee-saved reg. + * Writing `z > -0xB0000` inline instead emits the `lui` into the branch delay slot next to the + * compare (caller-saved $v0) and the function is 1 insn short. => `s32 lim = -0xB0000;` at top. + * + * 2. `lh` vs `lhu`: a short->short copy is a pure HImode move and gcc emits `lhu`. The target's + * `lh $v0,0x26($s0)` means the value passed through an SImode (int) temp: expand makes + * (set (reg:SI) (sign_extend (mem:HI))) + (set (mem:HI) (subreg:HI ...)), and combine cannot + * merge them (the merged form is mem<-mem, which no movhi accepts) so the sign-extending load + * survives. => route both halfword copies through the `s32 t` temp. + * + * 3. THE `goto` LAYOUT — dodging jump.c's store-flag conversion (jump.c:1005-1065). + * An if/else chain writing 0/1 into `doit` makes gcc collapse the last pair into + * `sltiu $v0,$v0,1`. jump.c fires that conversion when the insn immediately after a + * conditional jump is a lone `SET pseudo, CONST_INT` whose following simplejump targets the + * SAME label as the branch (jump.c:1038 `reallabelprev == temp || ... JUMP_LABEL(temp4) == + * JUMP_LABEL(insn)`) — exactly the shape of `if (c) x=0; else x=1;`. + * The target instead cross-jumps ALL the `doit=0` exits into ONE shared block placed after the + * `doit=1` fall-through; reorg's fill_slots_from_thread then COPIES that single set into all + * three branch delay slots and redirects each branch past it (which is why `addu $v0,$zero, + * $zero` appears 3x in delay slots and the shared block vanishes). A `goto zero;` / `goto one;` + * chain expresses that layout directly, and each conditional jump is then followed by a + * compare/call rather than a lone const set, so the store-flag conversion never triggers. + * GENERAL RULE: multiple predicates that all assign the SAME constant to one flag => write + * them as `goto` to a shared assignment, never as an if/else ladder. + */ +extern s32 D_8011F9C4; +extern s32 D_80183B5C; + +extern s32 func_80161B18(void); +extern s32 func_801619A4(s32*); +extern s32 func_80149AA8(s32*); +extern void func_80149AD4(s32*); +extern s32 func_80149B54(s32*); +extern void func_80149BAC(s32*); +extern s32 func_801498E0(s32*); +extern s32 func_80149954(s32); +extern s32 func_80149A64(s32*); +extern void func_800CCCC0(s32 a0); +extern s32 func_80149CD4(s32 a0); +extern void func_8015E880(s32*); +extern s32 func_80149744(struct S_80149744*); +extern void func_80149788(void); +extern s32 func_801496D4(void*); +extern void func_80149704(void); +extern int func_80148AFC(void*); +extern void func_80146D90(s32 a0); +extern void func_80154150(s32 a0, s32 a1); +extern void func_801541D8(u8*, s32, s32); +extern s32 func_801488A8(u8*); +extern void func_80147078(s32*, s16); +extern void func_8015A264(void*); +extern s32 func_80013294(void*, void*); +extern void func_80159B70(void*); +extern s32 func_8016F1AC(void); +extern s32 func_80029178(s32 a0); +extern void func_80146DB8(s32*, s32*); +extern s32 func_80161CD0(s32, s32); +extern s32 func_80161208(s32 a0); +extern s32 func_801725A4(u8*); + +s32 func_8015B950(s32 arg0) +{ + + extern void (*D_80183BC8[])(void *); + s16 sp10[4]; + s16 sp18[4]; + s32 t; + s32 z; + s32 doit; + s32 lim = -0xB0000; + + if (func_80161B18() != 0) { + return; + } + switch (((s32 (*)(s32))func_801619A4)(arg0)) { + case 0: + case 1: + case 2: + case 6: + if (((s32 (*)(s32))func_80149AA8)(arg0) != 0) { + D_80183BC8[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149AD4)(arg0); + return; + } + if (((s32 (*)(s32))func_80149B54)(arg0) != 0) { + D_80183BC8[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149BAC)(arg0); + return; + } + break; + case 3: + ((void (*)(s32))func_801498E0)(arg0); + break; + case 4: + ((void (*)(s32))func_80149954)(arg0); + break; + case 5: + if (((s32 (*)(s32))func_80149A64)(arg0) != 0) { + D_80183BC8[*(u16 *)arg0]((void *)arg0); + func_800CCCC0(arg0); + return; + } + break; + } + if (func_80149CD4(arg0) != 0) { + D_80183BC8[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_8015E880)(arg0); + return; + } + if (((s32 (*)(s32))func_80149744)(arg0) != 0) { + D_80183BC8[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149788)(arg0); + return; + } + if (((s32 (*)(s32))func_801496D4)(arg0) != 0) { + D_80183BC8[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149704)(arg0); + if (((u8)((s32 (*)(s32))func_80148AFC)(arg0)) == 0) { + func_80146D90(arg0); + } + if ((*(s32 *)(arg0 + 0x24) | *(s32 *)(arg0 + 0x2C)) != 0) { + func_80154150(arg0, 0xF); + } else { + ((void (*)(s32, s32, s32))func_801541D8)(arg0, 0xD, 6); + } + *(s32 *)(arg0 + 0x238) = 1; + return; + } + if (((s32 (*)(s32))func_801488A8)(arg0) != 0) { + sp10[0] = 0; + sp10[1] = 0; + sp10[2] = 0; + t = *(s16 *)(arg0 + 0x26); + sp18[0] = t; + sp18[1] = 0; + t = *(s16 *)(arg0 + 0x2E); + sp18[2] = t; + D_80183BC8[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 1); + ((void (*)(s32))func_8015A264)(arg0); + t = -(((s32 (*)(s16 *, s16 *))func_80013294)(sp10, sp18) << 0x10); + if (t < *(s32 *)(arg0 + 0x2C)) { + *(s32 *)(arg0 + 0x2C) = t; + } + return; + } + if (*(u16 *)(arg0 + 0xB8) == 0x8000) { + D_80183BC8[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 0); + ((void (*)(s32))func_80159B70)(arg0); + return; + } + z = *(s32 *)(arg0 + 0x2C); + if (func_8016F1AC() != 0) { + goto zero; + } + if (z <= lim) { + goto one; + } + if (D_8011F9C4 == 0) { + goto zero; + } + if (((u8)func_80029178(0x21)) != 0) { + goto zero; + } +one: + doit = 1; + goto join; +zero: + doit = 0; +join: + if (doit != 0) { + D_80183BC8[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 0); + ((void (*)(s32))func_80159B70)(arg0); + func_80154150(arg0, 9); + ((void (*)(s32, s32 *))func_80146DB8)(arg0, &D_80183B5C); + ((void (*)(s32, s32))func_80161CD0)(arg0, *(u16 *)(arg0 + 0x16E)); + return; + } + if (func_80161208(arg0) == 0) { + ((void (*)(s32))func_801725A4)(arg0); + } +} DEFINE_func_8015BD8C() /* dedup: shared engine-core @0x8015BD8C (src/shared) */ diff --git a/src/ov_SC07_002/ov_SC07_002_jr_8015AE2C.c b/src/ov_SC07_002/ov_SC07_002_jr_8015AE2C.c index c9ed99841..a9397ea9f 100644 --- a/src/ov_SC07_002/ov_SC07_002_jr_8015AE2C.c +++ b/src/ov_SC07_002/ov_SC07_002_jr_8015AE2C.c @@ -1512,7 +1512,259 @@ DEFINE_func_8015B858() /* dedup: shared engine-core @0x8015B858 (src/shared) */ DEFINE_func_8015B8F8() /* dedup: shared engine-core @0x8015B8F8 (src/shared) */ -INCLUDE_ASM("asm/ov_SC07_002/nonmatchings/ov_SC07_002_jr_8015AE2C", func_8015B950); +extern s32 func_8015AE2C(); + +// @class: plumbing +// @stuck: none — MATCH (271/271, pin-free, zero asm). The ONLY residual is DEF-SIDE plumbing, and it is now named exactly: the in-TU instantiation `DEFINE_func_8015BEE4()` (engine_core.h:1851-1855) expands to `extern s32 func_8015B950(void);` INSIDE ov_SC01_077_jr_8015AE2C.c, ~14 lines BELOW this definition, so the 1-param def collides with a `(void)` prototype -> `conflicting types for func_8015B950` (.run/bank_func_8015B950.log). §73 PARAMS axis / T0. Surgical fix = §65b de-macroize that ONE instantiation (blast radius: this TU); the fleet-wide `(void)`->`()` header edit is §63 and must be R22-validated. +/* func_8015B950 (ov_SC01_077_jr_8015AE2C, 271 ins, jtbl_801D8B74) — SESSION-21 re-verified + * + * ── ROUND-2 INDEPENDENT RE-VERIFICATION (2026-07-27, fresh agent, §88e discipline) ───────────── + * match_one : MATCH (271 ins) against the CURRENT tree — §87 staleness re-checked today. + * .text size: compiled .text = 0x43C = 1084 B = 271 ins, EXACTLY the target's declared 0x43C + * ("nonmatching func_8015B950, 0x43C"). So this is NOT a §83a length drift hiding + * behind a zero count — the count is over equal-length streams. + * jtbl : RE-DECODED MECHANICALLY, not inherited. Compiled .rodata = 0x1C = 28 B = 7 words, + * 7x R_MIPS_32 -> .text with implicit addends [58,58,58,E0,F0,100,58]; +0x8015B950 + * = [8015B9A8, 8015B9A8, 8015B9A8, 8015BA30, 8015BA40, 8015BA50, 8015B9A8]. + * Diffed word-for-word against asm/ov_SC01_077/data/tail14.data.s:15-23 — 7/7 identical. + * symcheck : SYMS-DIFF target=35 draft=34, sole MISSING = jtbl_801D8B74. This is the §81 jr + * FALSE POSITIVE, re-confirmed here by reading the relocs: gcc emits its OWN table and + * references it with R_MIPS_HI16/LO16 against the SECTION `.rodata` (t.o +0x40/+0x48), + * so the splat's dlabel NAME can never appear in the draft object's relocation set. + * Nothing is dropped and nothing is invented: the draft's other 34 symbols are exactly + * the target's other 34. + * FAMILY : the x138 remap is clean and §84-safe. Every sibling is 271 ins with an IDENTICAL + * callee set; only THREE names vary per overlay — the two data labels and the jtbl: + * ov_SC01_077 D_80188E18 / D_80188E84 / jtbl_801D8B74 + * ov_SC03_099 D_80185A50 / D_80185ABC / jtbl_801BD898 + * ov_SC06_008 D_80187E44 / D_80187EB0 / jtbl_801A8734 + * The pair is always +0x6C apart, and NO literal in this draft encodes that distance + * (both labels are referenced by name), so there is no §84 derived-offset hazard. + * D_8011F9C4 is fleet-constant (main-EXE data) and must NOT be remapped. + * + * match_one: MATCH (271 ins) against the CURRENT tree (§87 staleness re-checked, 2026-07-27). + * PIN-FREE, zero asm, offset-pure (s32 arg0 + raw offsets) — x138 template-safe. + * Provenance: this is the Phase-26 crack (.run/phase26-cracks/func_8015B950.c) re-gated verbatim, + * with ONE deliberate change: the definition's return type void -> s32. + * - `void func_8015B950(s32 arg0)` : MATCH (271 ins) [the Phase-26 form] + * - `s32 func_8015B950(s32 arg0)` : MATCH (271 ins) [shipped — §3a-1 void->s32 is byte-neutral] + * The fleet/engine_core.h canonical decl is `extern s32 func_8015B950(void);` (engine_core.h:1852), + * and the last bank attempt (.run/bank_func_8015B950.log) died on `conflicting types for + * func_8015B950`. Shipping the s32 return kills the §73 RETURN axis for free and leaves only the + * cheap T0 PARAMS axis for the ladder (fix_header_decl.py / --fix-def-sig / cast_call_sites). + * Both forms are byte-identical, so the orchestrator may swap the return type back at zero cost. + * + * SYMBOLS (§58 rules 1/2 — all splat spellings, all verified present): + * D_80188E84 asm/ov_SC01_077/data/tail.data.s:4355 (the state-handler vtable) + * D_80188E18 asm/ov_SC01_077/data/tail.data.s:4293 + * D_8011F9C4 main-EXE data; spelled `extern s32 D_8011F9C4;` in 5+ already-banked TUs + * jtbl_801D8B74 asm/ov_SC01_077/data/tail14.data.s:15 (compiler jump table — not named in C) + * + * JTBL VERIFIED (§8a gate): compiled .rodata = exactly 0x1C B / 7 words, 7x R_MIPS_32 .text with + * addends [0x58,0x58,0x58,0xE0,0xF0,0x100,0x58] -> +0x8015B950 = [B9A8,B9A8,B9A8,BA30,BA40,BA50, + * B9A8] == the original words at 0x801D8B74..0x801D8B8C. Bound `sltiu $v0,$v1,0x7` matches. + * The raw dlabel's 8th word 0x00000000 is NOT an entry — it is the intra-TU `.align 3` pad of the + * B34/B54/B74 jtbl chain; the object can never emit it (maspsx drops .align), so it must stay in + * the post-carve RAW data piece (the §53/§62/§81 carve chain applies at bank time). + * + * Same family as the TU's own already-matched func_8015AE2C: 7-case switch on ((s32 (*)(s32))func_801619A4)() + * (0/1/2/6 shared, 3/4/5 own, no default block — out-of-range and every `break` fall to the + * after-switch join), then a chain of "state handler" tests, each dispatching + * D_80188E84[*(u16*)arg0](arg0) and returning. + * + * THREE LEVERS (draft -> MATCH in 3 compiles): + * + * 1. PROLOGUE CONSTANT = an INITIALIZED LOCAL, not a literal in the compare. + * Target opens with `lui $s2, 0xFFF5` in the *prologue*, used once ~200 ins later in + * `slt $v0,$s2,$s1`. No gcc-2.7.2 pass hoists a (set reg const_int) across basic blocks + * (loop.c needs a loop; cse/combine/sched never move insns between BBs) — so the insn must + * have been EMITTED in the first BB, i.e. the constant is a local initialized at the top of + * the function. cse then cannot fold it back into the compare: the `slt` operand predicate is + * `arith_operand`, which rejects a CONST_INT wider than 16 bits, so validate_change fails and + * the pseudo survives. Its live range spans every call -> global.c gives it a callee-saved reg. + * Writing `z > -0xB0000` inline instead emits the `lui` into the branch delay slot next to the + * compare (caller-saved $v0) and the function is 1 insn short. => `s32 lim = -0xB0000;` at top. + * + * 2. `lh` vs `lhu`: a short->short copy is a pure HImode move and gcc emits `lhu`. The target's + * `lh $v0,0x26($s0)` means the value passed through an SImode (int) temp: expand makes + * (set (reg:SI) (sign_extend (mem:HI))) + (set (mem:HI) (subreg:HI ...)), and combine cannot + * merge them (the merged form is mem<-mem, which no movhi accepts) so the sign-extending load + * survives. => route both halfword copies through the `s32 t` temp. + * + * 3. THE `goto` LAYOUT — dodging jump.c's store-flag conversion (jump.c:1005-1065). + * An if/else chain writing 0/1 into `doit` makes gcc collapse the last pair into + * `sltiu $v0,$v0,1`. jump.c fires that conversion when the insn immediately after a + * conditional jump is a lone `SET pseudo, CONST_INT` whose following simplejump targets the + * SAME label as the branch (jump.c:1038 `reallabelprev == temp || ... JUMP_LABEL(temp4) == + * JUMP_LABEL(insn)`) — exactly the shape of `if (c) x=0; else x=1;`. + * The target instead cross-jumps ALL the `doit=0` exits into ONE shared block placed after the + * `doit=1` fall-through; reorg's fill_slots_from_thread then COPIES that single set into all + * three branch delay slots and redirects each branch past it (which is why `addu $v0,$zero, + * $zero` appears 3x in delay slots and the shared block vanishes). A `goto zero;` / `goto one;` + * chain expresses that layout directly, and each conditional jump is then followed by a + * compare/call rather than a lone const set, so the store-flag conversion never triggers. + * GENERAL RULE: multiple predicates that all assign the SAME constant to one flag => write + * them as `goto` to a shared assignment, never as an if/else ladder. + */ +extern s32 D_8011F9C4; +extern s32 D_80188E18; + +extern s32 func_80161B18(void); +extern s32 func_801619A4(s32*); +extern s32 func_80149AA8(s32*); +extern void func_80149AD4(s32*); +extern s32 func_80149B54(s32*); +extern void func_80149BAC(s32*); +extern s32 func_801498E0(s32*); +extern s32 func_80149954(s32); +extern s32 func_80149A64(s32*); +extern void func_800CCCC0(s32 a0); +extern s32 func_80149CD4(s32 a0); +extern void func_8015E880(s32*); +extern s32 func_80149744(struct S_80149744*); +extern void func_80149788(void); +extern s32 func_801496D4(void*); +extern void func_80149704(void); +extern int func_80148AFC(void*); +extern void func_80146D90(s32 a0); +extern void func_80154150(s32 a0, s32 a1); +extern void func_801541D8(u8*, s32, s32); +extern s32 func_801488A8(u8*); +extern void func_80147078(s32*, s16); +extern void func_8015A264(void*); +extern s32 func_80013294(void*, void*); +extern void func_80159B70(void*); +extern s32 func_8016F1AC(void); +extern s32 func_80029178(s32 a0); +extern void func_80146DB8(s32*, s32*); +extern s32 func_80161CD0(s32, s32); +extern s32 func_80161208(s32 a0); +extern s32 func_801725A4(u8*); + +s32 func_8015B950(s32 arg0) +{ + + extern void (*D_80188E84[])(void *); + s16 sp10[4]; + s16 sp18[4]; + s32 t; + s32 z; + s32 doit; + s32 lim = -0xB0000; + + if (func_80161B18() != 0) { + return; + } + switch (((s32 (*)(s32))func_801619A4)(arg0)) { + case 0: + case 1: + case 2: + case 6: + if (((s32 (*)(s32))func_80149AA8)(arg0) != 0) { + D_80188E84[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149AD4)(arg0); + return; + } + if (((s32 (*)(s32))func_80149B54)(arg0) != 0) { + D_80188E84[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149BAC)(arg0); + return; + } + break; + case 3: + ((void (*)(s32))func_801498E0)(arg0); + break; + case 4: + ((void (*)(s32))func_80149954)(arg0); + break; + case 5: + if (((s32 (*)(s32))func_80149A64)(arg0) != 0) { + D_80188E84[*(u16 *)arg0]((void *)arg0); + func_800CCCC0(arg0); + return; + } + break; + } + if (func_80149CD4(arg0) != 0) { + D_80188E84[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_8015E880)(arg0); + return; + } + if (((s32 (*)(s32))func_80149744)(arg0) != 0) { + D_80188E84[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149788)(arg0); + return; + } + if (((s32 (*)(s32))func_801496D4)(arg0) != 0) { + D_80188E84[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149704)(arg0); + if (((u8)((s32 (*)(s32))func_80148AFC)(arg0)) == 0) { + func_80146D90(arg0); + } + if ((*(s32 *)(arg0 + 0x24) | *(s32 *)(arg0 + 0x2C)) != 0) { + func_80154150(arg0, 0xF); + } else { + ((void (*)(s32, s32, s32))func_801541D8)(arg0, 0xD, 6); + } + *(s32 *)(arg0 + 0x238) = 1; + return; + } + if (((s32 (*)(s32))func_801488A8)(arg0) != 0) { + sp10[0] = 0; + sp10[1] = 0; + sp10[2] = 0; + t = *(s16 *)(arg0 + 0x26); + sp18[0] = t; + sp18[1] = 0; + t = *(s16 *)(arg0 + 0x2E); + sp18[2] = t; + D_80188E84[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 1); + ((void (*)(s32))func_8015A264)(arg0); + t = -(((s32 (*)(s16 *, s16 *))func_80013294)(sp10, sp18) << 0x10); + if (t < *(s32 *)(arg0 + 0x2C)) { + *(s32 *)(arg0 + 0x2C) = t; + } + return; + } + if (*(u16 *)(arg0 + 0xB8) == 0x8000) { + D_80188E84[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 0); + ((void (*)(s32))func_80159B70)(arg0); + return; + } + z = *(s32 *)(arg0 + 0x2C); + if (func_8016F1AC() != 0) { + goto zero; + } + if (z <= lim) { + goto one; + } + if (D_8011F9C4 == 0) { + goto zero; + } + if (((u8)func_80029178(0x21)) != 0) { + goto zero; + } +one: + doit = 1; + goto join; +zero: + doit = 0; +join: + if (doit != 0) { + D_80188E84[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 0); + ((void (*)(s32))func_80159B70)(arg0); + func_80154150(arg0, 9); + ((void (*)(s32, s32 *))func_80146DB8)(arg0, &D_80188E18); + ((void (*)(s32, s32))func_80161CD0)(arg0, *(u16 *)(arg0 + 0x16E)); + return; + } + if (func_80161208(arg0) == 0) { + ((void (*)(s32))func_801725A4)(arg0); + } +} DEFINE_func_8015BD8C() /* dedup: shared engine-core @0x8015BD8C (src/shared) */ diff --git a/src/ov_SC07_006/ov_SC07_006_jr_801588CC.c b/src/ov_SC07_006/ov_SC07_006_jr_801588CC.c index 0a0724392..1dc24326e 100644 --- a/src/ov_SC07_006/ov_SC07_006_jr_801588CC.c +++ b/src/ov_SC07_006/ov_SC07_006_jr_801588CC.c @@ -2588,141 +2588,3 @@ DEFINE_func_8015B858() /* dedup: shared engine-core @0x8015b858 (src/shared) */ DEFINE_func_8015B8F8() /* dedup: shared engine-core @0x8015b8f8 (src/shared) */ - - -INCLUDE_ASM("asm/ov_SC07_006/nonmatchings/ov_SC07_006_jr_801588CC", func_8015B950); - -DEFINE_func_8015BD8C() /* dedup: shared engine-core @0x8015bd8c (src/shared) */ - - -DEFINE_func_8015BDD0() /* dedup: shared engine-core @0x8015bdd0 (src/shared) */ - - -DEFINE_func_8015BE04() /* dedup: shared engine-core @0x8015be04 (src/shared) */ - - - - -void func_8015BE38(struct Obj *a0) { - - extern void (*D_8018CC1C[])(void); - D_8018CC1C[*(u16 *)((s32)a0 + 0x2)](); -} - - -DEFINE_func_8015BE74() /* dedup: shared engine-core @0x8015be74 (src/shared) */ - - -DEFINE_func_8015BE94() /* dedup: shared engine-core @0x8015be94 (src/shared) */ - - -DEFINE_func_8015BEC4() /* dedup: shared engine-core @0x8015bec4 (src/shared) */ - - -DEFINE_func_8015BEE4() /* dedup: shared engine-core @0x8015bee4 (src/shared) */ - - -DEFINE_func_8015BF04() /* dedup: shared engine-core @0x8015bf04 (src/shared) */ - - -DEFINE_func_8015BF48() /* dedup: shared engine-core @0x8015bf48 (src/shared) */ - - -DEFINE_func_8015BF7C() /* dedup: shared engine-core @0x8015bf7c (src/shared) */ - - -DEFINE_func_8015BFB0() /* dedup: shared engine-core @0x8015bfb0 (src/shared) */ - - - - -void func_8015BFF4(void *a0) { - - extern void (*D_8018CC28[])(void); - D_8018CC28[*(u16 *)((s32)a0 + 0x2)](); -} - - -INCLUDE_ASM("asm/ov_SC07_006/nonmatchings/ov_SC07_006_jr_801588CC", func_8015C030); - -DEFINE_func_8015C08C() /* dedup: shared engine-core @0x8015c08c (src/shared) */ - - -DEFINE_func_8015C0C4() /* dedup: shared engine-core @0x8015c0c4 (src/shared) */ - - -extern void func_8001382C(s32 a0, void *a1, void *a2); -extern void func_80146CA0(void *a0); -extern void func_80146DB8(s32 *a0, s32 *a1); -extern void func_80146E90(s32 *a0, s32 a1); -extern s32 func_80146E98(s32 a0); -extern void func_80147078(s32 *a0, s16 a1); -extern void func_80147324(s32 a0); -extern void func_801473EC(s32 *a0); -extern void func_80147A84(s32 arg0); -extern int func_80148AFC(void *a0); -extern s32 func_80149FB0(s32 a0); -extern void func_8014C010(s32 a0, s32 a1); -extern void func_8014CC28(s32 a0); -extern void func_8014D738(void); -extern s32 func_8014F3E8(); -extern s32 func_8015BE94(); -extern void func_8015C0C4(s32 a0); - - - -s32 func_8015C128(s32 param_1) { - - extern u16 D_800B99DA; - extern void func_8015C6E0(int); - extern void (*D_8018CAA8[])(int); - - int sp10[3]; - int sp20[3]; - int temp_s0; - int temp_v0; - - ((void(*)())func_80149FB0)(); - if (((int(*)(int))func_80148AFC)(((int)param_1)) & 0xFF) { - sp10[0] = 0; - sp10[1] = 0; - sp10[2] = -0x4000; - ((void(*)(int, int *, int *))func_8001382C)(*(short *)(*(int *)(((int)param_1) + 0x20) + 0x12), sp10, sp20); - *(int *)(((int)param_1) + 0x234) += sp20[0]; - *(int *)(((int)param_1) + 0x238) += sp20[1]; - *(int *)(((int)param_1) + 0x23C) += sp20[2]; - } - ((void(*)(int, int *, int *))func_8001382C)((short)(-*(unsigned short *)(*(int *)(((int)param_1) + 0x20) + 0x12)), - (int *)(((int)param_1) + 0x234), sp20); - ((void(*)(int, int *))func_80146DB8)(((int)param_1), sp20); - func_80147A84(((int)param_1)); - ((void(*)(int))func_801473EC)(((int)param_1)); - if (!(D_800B99DA & 3)) { - ((void(*)(int, int))func_8014C010)(((int)param_1), 1); - ((void(*)(int))func_80147324)(0x65F); - } - if (((int(*)(int))func_8014D738)(((int)param_1)) != 0) { - D_8018CAA8[*(u16 *)((int)param_1)](((int)param_1)); - func_8015C6E0(((int)param_1)); - return; - } - temp_s0 = ((int(*)(int))func_8014CC28)(((int)param_1)); - temp_v0 = ((int(*)(int))func_8014F3E8)(((int)param_1)); - if (temp_v0 != 0) { - if ((temp_v0 & 0xFF00) != 0x4000) { - ((void(*)(int, int))func_80146E90)(((int)param_1), 6); - ((void(*)(int))func_80146CA0)(((int)param_1)); - return; - } - if ((temp_v0 & 0x4000) && ((int(*)(int))func_80146E98)(((int)param_1)) != 0) { - ((void(*)(int, int))func_80147078)(((int)param_1), 4); - ((void(*)(int))func_8015C0C4)(((int)param_1)); - } - } else if (temp_s0 == 0) { - D_8018CAA8[*(u16 *)((int)param_1)](((int)param_1)); - ((void(*)(int, int))func_80147078)(((int)param_1), 3); - ((void(*)(int))func_8015BE94)(((int)param_1)); - } -} - - diff --git a/src/ov_SC07_006/ov_SC07_006_jr_8015B950.c b/src/ov_SC07_006/ov_SC07_006_jr_8015B950.c new file mode 100644 index 000000000..45eacef92 --- /dev/null +++ b/src/ov_SC07_006/ov_SC07_006_jr_8015B950.c @@ -0,0 +1,2424 @@ +#include "common.h" +#include "../shared/engine_core.h" + +/* ==== Phase-26 §8b carried decl layer (jr_isolate_all.py) =================== + * The file-scope decl environment from earlier code regions of this object — + * file-local types, col-0 decls, DEFINE_func macro externs, and each earlier + * definition's implied prototype (types first, then decls in original order). + * Decls emit no code => byte-neutral. See cookbook §8c. */ +extern void func_80128288(void); +extern void func_80128158(void); +extern void func_801285E4(void); +extern void func_80128178(void); +extern void func_80128678(void); +extern void func_80128198(void); +extern void func_80128714(void); +extern void func_801281B8(void); +extern void func_8013E67C(void); +extern void func_801281D8(void); +extern void func_8013E558(void); +extern void func_801281F8(void); +extern s32 func_80128218(void); +extern void func_80128A28(void); +extern void func_80128228(void); +extern void func_80128AF4(void); +extern void func_80128248(void); +extern void func_801282EC(void); +extern void func_80128268(void); +extern void func_80011B7C(int); +extern void func_801282CC(void); +extern void func_8001C0C8(void); +extern void func_80015310(void); +extern void func_80129258(void); +extern void func_801378F0(void); +extern void func_80010E14(void); +extern s16 currentLocationId; +extern s32 func_80029504(void); +extern s32 func_800CF854(s32); +extern s32 func_80128998(void); +extern s32 func_801289F0(void); +extern s32 func_801288E8(s32); +extern s32 func_80128940(s32); +extern s32 func_80029178(s32); +extern s32 func_801288B0(void); +extern void func_80011C10(void); +extern void func_8012832C(void); +extern void func_80129220(void); +extern void func_80011E24(void); +extern void func_80128C14(void); +extern void func_8002AEF8(void); +extern void func_800CFBBC(void); +extern void SsUtReverbOff(void); +extern void func_8013C98C(void); +extern void func_80129C40(s32 a0); +extern void func_800D0630(void); +extern void func_80145CEC(void); +extern void func_80144B9C(); +extern u8 D_800B9A17; +extern u8 D_800B9A10; +extern void func_80128420(void); +extern s32 func_800D0588(void); +extern void func_801284B8(void); +extern void func_80175308(); +extern void func_8016E8F0(void); +extern void func_80175494(void); +extern u8 D_800B9A64; +extern void func_801284F0(void); +extern void func_80146074(void); +extern void func_8012853C(void); +extern void func_80178608(void); +extern void func_8002D4C8(s32 a0, s32 a1); +extern s32 func_80011A3C(void); +extern short currentLocationId; +extern short D_800B99F2; +extern void func_80128564(void); +extern u8 D_800B9A11; +extern void func_801285D4(void); +extern s32 func_800D18DC(void); +extern void func_8014607C(void); +extern void func_801287B8(void); +extern void func_80029444(void); +extern void func_800D1754(void); +extern void func_8014ED28(s32 _arg0); +extern void func_8001ABBC(s32 a0, s32 a1, void *a2, s32 a3, s32 sp10); +extern int func_801288E8(int arg0); +extern int func_80128940(int arg0); +extern void func_80010AE0(s32 a0); +extern void func_80018450(s32 a0, s32 a1); +extern void func_800183E0(s32 a0); +extern void func_80128D60(s32 a0, s32 *a1, s32 *a2); +extern s32 func_80128DB4(s32 a0, s32 *a1); +extern void func_80128EA8(s32 a0, s32 a1, s32 a2); +extern s32 func_80128ED8(s32 param_1, s32 *param_2); +extern void func_80128FAC(u16 *arg0); +extern s16 D_8011DB2C; +extern s16 D_8011DB30; +extern s32 D_80126AEC; +extern void func_80129010(void); +extern u8 *func_8012913C(s32 a0); +extern u8 * func_801290DC(s32 a0, u8 *a1); +extern void func_8001D074(s32 a, s32 b); +extern u8 *func_801291C0(void); +extern s32 func_8001CC3C(s32 a0, s32 a1, s32 a2, s32 a3); +extern u8 * func_8012913C(s32 arg0); +extern void func_80016714(void *a0, s32 a1); +extern u8 * func_801291C0(void); +extern void func_80129248(s16 a0); +extern void func_801292C8(u8 *a0); +extern void func_8012927C(void); +extern void func_8012931C(struct vec *a0); +extern void func_80129350(s32 a0, s32 a1); +extern void func_80129374(s32 a0, s32 a1); +extern s16 D_800B9AAC[]; +extern s16 D_800B9AAE[]; +extern s16 D_800B9AB0[]; +extern s16 D_800B9AB2[]; +extern s16 D_800B9AB4[]; +extern s16 D_800B9AB6[]; +extern s16 D_800B9AB8[]; +extern s16 D_800B9ABA[]; +extern void func_80129398(void); +extern s16 D_80114EE0; +extern void func_80129428(void); +extern void func_8012943C(void); +extern s32 D_8005128C; +extern u8 D_800B9A78; +extern void func_801298F4(void *arg0); +extern void func_801299C8(s32 a, s32 b, s32 c); +extern void func_8012944C(void); +extern unsigned short D_800B99F0; +extern struct BigCopy D_80126DB8; +extern u8 D_80126948[]; +extern struct BigCopy D_80114EE8; +extern s32 D_80126E60[]; +extern s8 D_801150D6; +extern s8 D_801152C0; +extern u8 D_80127504; +extern void func_800144D4(void); +extern void func_80129C40(s32 _arg0); +extern void func_8012A328(); +extern void func_80053308(s32); +extern s32 func_80012F74(s32, s32, s32, s32); /* canonical s32 (engine_core); (s16)-cast the return for the sll/sra */ +extern void GsSetRefView2L(void *); +extern s8 D_801150D6; /* canonical (engine_core macro): s8 — access via *(u8*)& for lbu */ +extern s32 D_80126F04[]; +extern u8 D_80126948[]; /* canonical (sibling): u8[] — cast (s32*) at use */ +extern s32 D_80126FA8[]; +extern struct BigCopy D_80126DB8;/* canonical (engine_core macro): struct BigCopy — (s32*)& at use */ +extern u8 D_800AF630[]; /* canonical (sibling): u8[] — cast (s32*) at use */ +extern s32 D_800AE688[]; +extern s32 D_801151D4; /* canonical (10 siblings): scalar s32 — store (s32)ptr */ +extern void func_80129CF8(void); +extern void func_8012A018(s32 a, s32 b); +extern void func_80129FF4(void); +extern void func_8012A048(void *a0, s32 a1, u8 a2); +extern void func_8012A018(s32 a0, s32 a1); +extern u16 D_80126B5E; +extern u16 D_80126B62; +extern u16 D_80126B66; +extern s16 D_80126940; +extern s16 D_80126942; +extern s16 D_80126944; +extern void *memcpy(void *, const void *, unsigned int); +extern void func_8012A094(s32 a0); +extern void func_8012A100(s8 a0); +extern void func_8012A0E0(void); +extern s32 D_80120204; +extern s32 D_80120200; +extern s32 D_8012020C; +extern s32 D_80120208; +extern s16 D_80120218; +extern s16 D_80120210; +extern s16 D_8012021A; +extern s16 D_80120212; +extern s16 D_8012021C; +extern s16 D_80120214; +extern s16 D_80120226; +extern s16 D_80120220; +extern s16 D_80120228; +extern s16 D_80120222; +extern s16 D_8012022A; +extern s16 D_80120224; +extern s32 D_80120294; +extern s16 D_80120298; +extern s16 D_8012029A; +extern void func_8012A110(void); +extern void func_8012A2F4(void); +extern s16 D_80127080; +extern s16 D_801152C2; +extern void func_8012A304(s32 a0, s32 a1); +extern void func_8012A464(void); +extern s32 D_801151D4; +extern void func_8012A4BC(void); +extern void func_8012A598(void *a0); +extern void func_8012A568(void (*a0)(void)); +extern void func_8012A62C(s32); +extern void func_8012A5F8(void (*a0)(void), s32 a1); +extern void func_8012A62C(s32 a0); +extern void func_8012A7D4(void *a0, void *a1); +extern s32 func_8012A6D0(void *a0, void *a1); +extern s16 func_8012A68C(void); +extern s32 func_80047D3C(s32 a0); +extern s32 ratan2(s32 a0, s32 a1); +extern s32 func_8012A6D0(void* a0, void* a1); +extern s16 func_8012A79C(s16 *a0, s16 *a1); +extern s16 func_8012A758(void); +extern void func_8012A7D4(void *arg0, void *arg1); +extern void func_8012AAAC(); +extern void func_8012A828(s32 a0, void * a1); +extern int func_8012ACE0(void *a0); +extern void func_8012A860(void *a0, int a1); +extern void func_8012A8B0(u8 *a0, s32 a1); +extern void func_8012A8E8(void); +extern u8 D_801202A0[]; +extern u16 D_801270C0; +extern void func_8012A988(u8 *a0); +extern void func_8012A908(void); +extern s32 func_8012ACE0(void *a0); +extern void func_8012ACA0(void *arg0); +extern void func_8012AD44(s32 *a0, s16 a1); +extern s32 func_8012AD50(void * arg0); +extern void func_8012AD64(s32 *a0, s16 a1); +extern void func_8012AD6C(void *a0); +extern void func_8012AD80(s32 a0); +extern void func_8012ADE4(u8 *a0); +extern s32 *D_80126B78; +extern s32 *D_80126B90; +extern s32 D_80126B58; +extern s32 func_80135888(s32 a0, s32 a1, s32 a2, s32 a3); +extern s32 func_80013478(s32 a0, s32 a1); +extern s32 func_8012AE00(s32 a0); +extern s32 func_8012AF0C(s32 a0, s32 a1); +extern s32 func_80134510(s32 arg); +extern s32 func_8012B030(u8 *a0); +extern int func_80047948(int a0); +extern int func_8004787C(int a0); +extern void func_8012B0B4(unsigned int *param_1, int param_2, int param_3); +extern void func_800484EC(s32 a0, s32 a1, s32 a2); +extern void func_8012B14C(s32 a0, s32 a1); +extern void func_8012B178(s32 a0, s32 a1); +extern void func_8012B1B4(s32 a0, s32 a1); +extern void func_8012B200(u8 *a0); +extern void func_8012B21C(void *a0); +extern void func_8012B23C(s32 a0); +extern void func_8012B260(u8 *a0); +extern void func_80049CAC(s32 a0, s32 a1); +extern void func_8012B2CC(s32 a0); +extern void RotMatrixYXZ(void *m, void *p); +extern void func_8012B370(int a0); +extern void func_8004978C(s16 *a0, void *a1); +extern void func_8012B414(int a0); +extern s32 func_8012B608(s32 a0, s32 a1, s32 a2); +extern s32 func_8012B6D4(s16 *a0, s16 *a1); +extern s32 func_8012B70C(s16 *a0, s16 *a1); +extern s32 ratan2(s32 x, s32 y); +extern s32 func_8012B744(void *a0, void *a1); +extern s16 D_80126CB8; +extern s16 D_80126CB4; +extern s32 func_8012B864(s32 a0); +extern s32 func_8012B8A4(s16 *a0); +extern s32 func_8012B8E4(s32 arg0, s32 arg1); +extern s32 func_8012BA10(s32 arg0, s32 arg1); +extern s32 func_8012BB3C(s32 arg0, s32 arg1, u32 arg2, s32 arg3); +extern void Square0(s32 *a0, s32 *a1); +extern s32 func_8012BC60(struct Vec *a0, struct Vec *a1); +extern s16 D_80126CBA; +extern s32 func_8012BCCC(s32 a0); +extern void func_80013350(s32 a0, void *a1); +extern u8 D_80126B5C; +extern void func_8012BD14(s32 a0); +extern s32 func_8012BDBC(s32 a0, s32 a1); +extern s32 func_8012BD3C(s32 a0, s32 a1, s32 a2); +extern void func_8012BE98(s32 a0, u16 *a1); +extern void func_8012BE54(s32 a0); +extern s32 func_800132BC(s32 a0, s32 a1); +extern void func_8012BE98(s32 arg0, u16 * arg1); +extern s32 func_8012BEE8(s32 a0); +extern s32 func_8012BF10(s32 a0, s32 a1); +extern void func_8012BF4C(s32 *a0, s32 a1); +extern void func_8012BF54(void *a0); +extern void func_8012BF68(void *a0); +extern s16 D_80126CB0; +extern s32 func_8012BF7C(s16 *a0); +extern s16 D_80126CAC; +extern short D_80126CAE; +extern int func_8012BFA8(short *a0); +extern s32 D_801274D4; +extern s32 D_801274E0; +extern s32 func_8012C044(s32 a0); +extern void func_8012C218(void *a0); +extern void func_8012C098(void *param_1); +extern s32 func_8012C0EC(s32 a0); +extern void func_8012C194(void); +extern void func_8001CFDC(s32 a, s32 b); +extern void func_8012C1B8(void); +extern u8 D_800B3DF0[]; +extern s32 func_8012C1DC(s32 a0); +extern u8 D_80126720[]; +extern u16 * func_8012C284(u16 *a0); +extern u8 D_80120194[]; +extern s32 func_8012C2D0(void); +extern s32 func_8012C31C(void); +extern void func_8012CAE4(void *a0); +extern void func_8001C214(s32 a0, s32 a1); +extern u8 D_80078EAE; +extern s32 func_8012C354(s32 a0, s32 a1); +extern void func_8001C810(s32 a0, s32 a1); +extern s32 func_8012C438(s32 a0, s32 a1); +extern s32 func_8012C890(s32 a0, s32 a1, s32 a2); +extern s32 func_8012C51C(void *a0, s32 a1); +extern s32 func_8012C588(s32 a0, s32 a1); +extern void func_8012C724(s32 a0, s32 a1); +extern s32 func_8012C750(s32 a0); +extern s32 func_8012C820(u8 *a0); +extern u16 D_801274E4[]; +extern s32 func_8012CB64(s32 arg0, s32 arg1, s32 arg2, s32 arg3, s32 arg4); +extern s32 func_8012CC88(); +extern u8 D_800D3918[]; +extern void func_8012CBA4(s32 a0); +extern void func_8012CBCC(s32 a0); +extern void func_8012CBF4(s32 a0); +extern void func_8012CC1C(s32 arg0, s32 arg1); +extern void func_8012CC40(s32 arg0, s32 arg1); +extern void func_8012CC64(s32 a0, s32 a1); +extern s32 func_80133784(s32 a0, void *a1, s32 a2); +extern s32 func_8012CE2C(s32 a0); +extern s32 func_8012CEB0(s32 a0, s32 a1, s32 a2); +extern void func_8012CFA8(s32 arg0); +extern void func_8012F214(s32 a0, s32 a1, s32 a2); +extern void func_8012D3B4(s32 arg0, s32 arg1, s32 arg2); +extern void func_8012D098(u16 *param_1, u32 param_2); +extern void func_8012D098(); +extern void func_8012D38C(int a0); +extern void func_8012D3AC(void); +extern s32 AddPrim(s32, void *); +extern s32 RotTransPers(s32, s32, s32 *, s32 *); +extern void SetLineF2(void *); +extern void *func_80010A08(s32); +extern void func_8004914C(void *); +extern void func_800491AC(void *); +extern s32 D_800A651C; +extern u8 D_800AF648; +extern s16 D_800B9A02; +extern void func_8012D4B4(s32 arg0, s32 arg1, s32 arg2, s32 arg3); +extern void func_8012D5DC(void); +extern s16 D_80126B98; +extern s32 func_8012DEB8(s32 a0, s32 a1, s32 a2); +extern s32 func_8012D5E4(s32 a0, s32 a1, s32 a2, s32 a3); +extern int func_8012D664(); +extern void func_8012D624(s32 a0); +extern s32 func_8012D714(s32 param_1, u32 param_2); +extern void func_8012F568(s32 a0, s32 a1, s32 a2, s32 a3, s32 a4, s32 a5); +extern void func_8014C978(void); +extern s32 func_8012DB84(void); +extern s32 func_8012DE2C(s32 a0); +extern s32 func_8012DDA4(void); +extern s32 func_8012DBD0(s32 arg0, s32 arg1, s32 arg2, s32 arg3); +extern s32 func_8012DF34(s32 a0, s32 a1, s32 a2); +extern s16 D_80126B9A; +extern u8 D_801152A8[]; +extern void func_8012DFBC(void); +extern void func_8012DFCC(void); +extern void func_8012E014(); +extern void func_8012E138(); +extern void func_8012DFD4(u8 *a0); +extern s32 func_8012E27C(void); +extern void func_8012E284(void); +extern s32 GetTPage(s32, s32, s32, s32); +extern s32 func_8005A600(s32, s32, s32, s32, s32); +extern void func_8012E28C(s32 arg0, s32 arg1); +extern void func_8004914C(void *a0); +extern void func_800491AC(void *a0); +extern void func_8012E32C(void); +extern s32 func_8012E470(s32 a0); +extern void func_8012E4C8(s32 a0); +extern s32 func_8012E504(s32 a0, s32 a1); +extern s32 func_8012E544(s32 a0); +extern s32 func_8012E57C(s32 a0, s32 a1); +extern s32 RotTransPers(s32 a0, s32 a1, s32 *a2, s32 *a3); +extern void func_8012E5CC(s32 param_1, u16 param_2, u16 param_3); +extern void func_8012E688(s32 param_1, u16 param_2, u16 param_3); +extern s32 func_8012E778(int param_1, int param_2); +extern void func_8012E88C(u8 *a0); +extern void func_8012E8A8(u8 *a0); +extern void func_8012E8C4(u8 *a0); +extern void func_8012E8E0(s32 a0, s32 a1); +extern void func_8012EA90(s32 param_1, s32 param_2, s32 *param_3); +extern void func_8012EC04(s32 param_1, s32 param_2, s32 *param_3); +extern s32 func_8002A4FC(s32 a0); +extern s32 func_8012EECC(s32 a0); +extern void func_8012EFB8(s32 a0); +extern void func_8012EF34(s32 a0, s32 a1); +extern void func_8012EF70(s32 a0, s32 a1); +extern void ApplyTransposeMatrixLV(void *a0, void *a1, void *a2); +extern void func_8012F038(int param_1, short *param_2, short *param_3); +extern void func_8012F0BC(s32 *a0, s32 *a1, s32 *a2); +extern void RotTransSV(s32 a0, s32 a1, void *a2); +extern void func_8012F14C(s32 a0, s32 a1, s32 a2); +extern void func_8012F1A4(s32 *a0, s32 a1, s32 *a2); +extern void func_8012F2E8(s32 a0, s32 a1, s32 a2); +extern s16 D_80126CB6; +extern void func_8012F374(s32 a0, s32 a1); +extern void *memcpy(void *, const void *, u32); +extern u8 D_80126C38; +extern u8 D_80126C40; +extern u16 D_80126B94; +extern u16 D_80126B96; +extern void func_8012F568(s32 param_1, s32 param_2, s32 param_3, s32 param_4, s32 param_5, s32 param_6); +extern void func_80131B14(); +extern void func_80131E00(struct S80131E00 *a0, s32 a1); +extern s32 func_80131A34(s32, s32); +extern void func_80131CA8(int a0, int a1); +extern void func_8012F5F4(s32 arg0); +extern void func_80131C78(s32 a0); +extern void func_8012F68C(s32 arg0); +extern void func_8012F75C(s32 a0); +extern s32 func_8012BEE8(s32); +extern void func_8012F7B4(s32 a0); +extern void func_80131170(); +extern void func_80131CA8(); +extern void func_8012F828(int param_1); +extern void func_80131340(s32 a0); +extern void func_8012F87C(s32 a0); +extern void func_8012F8C8(int param_1); +extern void func_8012F91C(s32 a0); +extern s32 func_80131A34(s32 a0, s32 a1); +extern void func_80131CA8(s32 a0, s32 a1); +extern void func_8012F968(s32 param_1); +extern void func_801319E0(s32 a0); +extern s32 func_80143B6C(s32 a0, s32 a1); +extern void func_8012FB54(s32 a0); +extern void func_8012FC30(s32 a0); +extern void func_8012FCA4(int a0); +extern void func_80131B14(void); +extern void func_8012FCC4(int param_1); +extern void func_8012FDA8(int param_1); +extern void func_80131170(s32 a0, s32 a1, s32 a2); +extern void func_8012FE70(s32 a0); +extern void func_8012FF00(s32 a0); +extern void func_8012FF4C(s32 a0); +extern void func_80130D48(s32 a0); +extern void func_8012FF98(u8 *a0); +extern s32 func_80131AC8(void *a0); +extern void func_8013001C(void *a0); +extern void func_80130088(void *a0); +extern s32 func_8012BCCC(s32); +extern void func_801300F4(s32 a0); +extern void func_801301E8(u8 *a0); +extern void func_80130278(s32 arg0); +extern void func_80130314(s32 a0); +extern void func_80130360(s32 a0); +extern void func_8012E364(void); +extern void func_801303A0(s32 a0); +extern void func_801303EC(void *a0); +extern void func_80143CD4(s32 a0); +extern void func_800CB0E8(s32 a0); +extern void func_80130438(s32 a0); +extern void func_801319E0(int); +extern int func_80131D68(int, int); +extern int func_8012BEE8(int); +extern void func_80131CA8(int, int); +extern void func_80130514(int param_1); +extern void func_801305CC(u8 *a0); +extern void func_8012CBF4(s32); +extern s32 func_80131D68(s32 a0, s32 a1); +extern void func_80130650(s32 a0); +extern s32 func_80146A6C(s32 a0, void *a1, s32 a2, s32 a3, s32 a4, s32 a5, s32 a6); +extern void func_80130740(void *a0, u16 *a1); +extern s32 func_801312D0(s32 a0, void *a1); +extern void func_801307B0(s32 a0); +extern void func_80130858(s32 a0); +extern void func_80130898(u8 *a0); +extern void func_801308DC(s32 a0); +extern void func_80166244(); +extern void func_80130974(int param_1); +extern void func_80130A18(u8 *a0); +extern void func_80130AC4(s32 a0); +extern int func_80131A34(int a0, int a1); +extern void func_80130AF0(int param_1); +extern void func_80130D0C(s32 a0); +extern void func_80131170(s32 p, s32 b, s32 c); +extern s32 func_801312D0(s32 param_1, void *param_2); +extern void func_80131E00(); +extern s32 D_801F4D80; +extern s32 D_801F4D84; +extern void func_8002A04C(s32 a0); +extern void func_801319E0(s32 arg0); +extern s32 func_80131CF4(s32 a0); +extern int func_80131D68(int a0, int a1); +extern void func_80131E38(u8 *a0); +extern void func_80131E7C(s32 a0); +extern void func_80131EE4(void); +extern void func_80131EEC(void *a0); +extern void func_80131F28(void *a0); +extern void func_80131F64(void *a0); +extern void func_80131FA0(void *a0); +extern void func_80131FDC(void *a0); +extern void func_801320D0(void); +extern void func_8001C214(int, int); +extern void func_801320D8(int param_1); +extern void func_80132144(int param_1); +extern void func_801321B0(int param_1); +extern void func_8013221C(int param_1); +extern void func_8005C324(int dst, int src, int n) __asm__("memcpy"); /* Phase-24: 0x8005C324 is named memcpy for overlays (whale needs it); keep the non-builtin C name here (else built-in codegen), emit via asm-label */ +extern void func_801325B8(int a0, int a1, int a2, int a3, int a4); +extern void func_80132288(int *param_1, int *param_2, int param_3); +extern void func_801325B8(s32 a0, s32 a1, s32 a2, s32 a3, s32 a4); +extern void func_8013240C(s32 a0); +extern void func_8013277C(void); +extern void func_80020F34(s32 a0, s32 a1); +extern void func_80054514(s32 a0, s32 a1); +extern void func_80132784(s32 a0, s32 a1, u32 a2); +extern s32 VectorNormalSS(void *a0, void *a1); +extern void func_80132DC4(s32 a0, s32 a1, s32 a2); +extern s32 func_80132E6C(s16 *a0); +extern void func_80132EC4(void *a0, s16 a1); +extern s32 func_80132EF4(s32 a0, s32 a1); +extern void func_801330E0(s16 *a0, s16 *a1, s32 a2); +extern void func_80133060(u8 *a0, s32 *a1, s32 a2); +extern void func_8013339C(short *param_1, short *param_2); +extern s32 func_8013361C(s16 *a0, s16 *a1, s16 *a2, s16 *a3); +extern void func_80136BC4(s32 a0); +extern void func_801336E8(void *a0, int a1, int a2); +extern void func_80136BC4(s32); +extern void func_8013373C(s16 arg0); +extern s32 func_80133784(s32 arg0, void *arg1, s32 arg2); +extern s32 func_80133CD4(); +extern s32 func_80134310(Vec3s *a0, Vec3s *a1, s32 a2); +extern s32 func_8013435C(s16 *a0, s16 *a1, s32 a2, s16 *a3); +extern s32 func_801343C4(s32 angle, s32 p1, s32 p2); +extern s32 func_801345F8(s32 arg); +extern s32 func_80134A28(s32 a0, s32 a1, s32 a2); +extern int func_80134A74(int param_1, s16 param_2, s16 param_3, int param_4); +extern s32 func_80134C20(s32 arg0, s32 arg1, s32 arg2, s32 arg3); +extern s32 func_80134FB8(s32 a0, s32 a1, s32 a2); +extern int func_80134A74(int, s16, s16, int); +extern int func_80135168(u16 arg0, u16 *p1, u16 *p2); +extern s16 func_80135480(void *param_1, s32 param_2, s16 *param_3, s16 *param_4); +extern s32 func_80136334(void *arg0, s32 arg1, s32 arg2); +extern s32 func_801365B8(void *arg0, s32 arg1, s32 arg2); +extern s32 func_80136824(s32 arg0, s32 arg1, s32 arg2); +extern s32 func_80136A94(s32 a0, s32 a1, s32 a2, s32 a3); +extern void func_80136C3C(void); +extern void func_80136C1C(void); +extern void func_80136C44(void); +extern void func_80136C4C(void); +extern void func_80136C54(void); +extern void func_80136D00(void); +extern void SetLineG2(void *); +extern void func_80136D08(s32 arg0, s32 arg1); +extern u16 D_80126CC4; +extern M2C_UNK func_800153CC(M2C_UNK, u16, M2C_UNK, M2C_UNK, s32, s32); +extern void func_80136DFC(void); +extern void func_80136EC4(void); +extern short D_800B9A02; +extern u8 D_800A6518[]; +extern void GsSortLine(void *a0, void *a1, s32 a2); +extern void func_80136ECC(s16 a0, s16 a1, s16 a2, s16 a3, u8 r, u8 g, u8 b); +extern void func_80137030(s16 a0, s16 a1); +extern void ApplyMatrixSV(void *m, Svec_801372B0 *in, Svec_801372B0 *out); +extern void aGsSortLine(Gline_801372B0 *p, void *ot, s32 z) __asm__("GsSortLine"); +extern void aF80137030(s32 x, s32 y) __asm__("func_80137030"); +extern void func_80137178(s32 x, s32 y); +extern u8 D_800AF630[]; +extern u16 aD800B9A02 __asm__("D_800B9A02"); +extern void func_801372B0(void); +extern void func_80137614(s32 a0, s32 a1, s32 a2); +extern void func_801375EC(s32 a0, s16 a1); +extern s32 func_801399A8(void); +extern void func_801377B4(s32 a0, s32 a1, s32 a2); +extern s32 func_8013767C(s32 a0); +extern void func_801376E8(); +extern void func_801376C8(int a0); +extern s32 D_80127524; +extern s32 D_80127528; +extern void func_80137840(s32 a0); +extern void func_80139634(void *); +extern void func_80139DC8(void); +extern s16 D_8012752E; +extern void func_801379D8(void); +extern void func_801379EC(void); +extern void func_80138BE0(s32 a0); +extern void func_80137BD8(s32 a0); +extern void func_8013A380(void); +extern void func_801379FC(void); +extern void func_80138BE0(int p); +extern void func_80137B80(void); +extern void func_801392FC(); +extern void func_801397B0(s32 a0); +extern void func_80137DD4(s32 a0, u8 *a1, u8 *a2); +extern void func_80139680(s32 a0, u8 *a1); +extern u16 D_800B99D8; +extern int func_80137D08(int arg0, int arg1, short arg2); +extern void func_80137FD8(s32 a0, s32 a1, s32 a2, s32 a3); +extern void func_80137DD4(s32 ent, u8 *arg, u8 *work); +extern void func_801387B8(s32 arg0); +extern void func_80138948(void *a0); +extern s16 func_80138DB8(s32 a0, u8 a1, s32 a2); +extern void func_80138B88(s32 a0); +extern void func_8013895C(s32 a0); +extern s16 D_80127540[4]; +extern s32 func_80139D04(s32 a0, s32 a1); +extern s32 func_80138DE0(s32 a0, s32 a1, s32 a2); +extern void func_80139B18(s32 a0); +extern void func_80138AB4(s32 a0); +extern void func_80138C30(void *a0); +extern void func_8013A9F8(s32 a0, s32 a1); +extern void func_80138D58(s32 a0, u16 a1); +extern s32 func_80014E80(s32 a0, s32 a1); +extern s32 func_8013914C(s32 a0, s32 a1); +extern void func_800599B8(u16 *); +extern u16 D_80127C0C[]; +extern s32 D_80127548[]; +extern s32 func_80138ED0(u8 *param_1, u32 param_2, u8 *param_3); +extern s32 func_80139220(s32 a0); +extern void func_801391F0(void *a0); +extern void func_801392C8(void *a0); +extern void func_801395D4(void *); +extern s32 GetTPage(s32 a0, s32 a1, s32 a2, s32 a3); +extern s32 func_80052460(s32 a0, s32 a1, s32 a2); +extern void func_801392FC(s32 arg0, s32 arg1, u8 *arg2); +extern void func_80059888(void *a0, s32 a1, s32 a2, s32 a3); +extern void func_80139634(void *a0); +extern void func_80139680(s32 arg0, u8 * arg1); +extern void func_8001931C(void); +extern s16 D_8012752C; +extern void func_80139788(void); +extern void GsSortSprite(void *a0, u8 *a1, s32 a2); +extern void func_801397B0(s32 arg0); +extern void func_8013A8B0(s32 *a0); +extern void func_80139914(s32 arg0); +extern u16 D_80126A08; +extern s16 D_801269F4; +extern s32 D_801269F0; +extern s32 *D_80126A30; +extern void func_80139954(void); +extern s32 D_80126A3C; +extern s32 func_801399F0(s32 a0); +extern s32 D_80127520; +extern void func_80139A34(s32 a0); +extern s32 D_80127530[4]; +extern void func_80139A44(s32 a0, u16 a1); +extern void func_80139A68(s32 a0, u16 a1); +extern void func_80139A8C(s32 a0); +extern void func_80139C7C(u8 *a0); +extern s16 D_8012811A; +extern void func_80139DEC(void); +extern void func_80139DF4(s32 a0); +extern void func_80139E84(s32 a0); +extern void func_80139F0C(s32 a0); +extern void func_80139FBC(struct obj *a0); +extern s32 func_8001B22C(void *a0); +extern void func_80139FE8(void *a0); +extern void func_8013A0A4(struct S8013A0A4 *a0); +extern void func_8013A164(struct S8013A164 *a0); +extern void func_8013A1E8(s32 a0); +extern void func_8013A250(struct S8013A250 *a0); +extern void func_8013A2BC(s32 a0); +extern void func_8013A378(void); +extern u8 D_8011DA80[]; +extern void func_8013A530(); +extern void func_8013A448(void *a0); +extern void func_8013A4C4(struct S8013A4C4 *a0); +extern void func_80015D4C(); +extern void func_80015F04(); +extern void func_8013AA24(s32 a0, s32 a1); +extern void func_8013A530(int param_1); +extern void func_8013A860(void); +extern s32 func_8013A8BC(void); +extern void func_8013A9B4(s32 a0, s32 a1); +extern s32 func_8013A8FC(s32 arg0); +extern void func_8013AD38(void *a0, s32 a1, void *a2, void *a3); +extern void func_8013B204(s32 a0, s32 a1); +extern void func_8013AF20(); +extern void func_8013B274(s32 a0, s32 a1, void *a2); +extern s32 func_8013AB54(s32 a0, s32 a1, s32 a2, s32 a3); +extern void func_8013AF20(u32 *param_1, u16 *param_2, u16 *param_3, u8 *param_4); +extern void func_8013CA14(void); +extern void func_8013CABC(void); +extern void func_8013CAE8(void); +extern void func_8013CB20(void); +extern void func_8013CB5C(void); +extern void func_8013CF68(); +extern void func_8013D9B0(); +extern void func_8013D064(void); +extern s32 func_8013D13C(void); +extern void func_8013D164(void); +extern void func_8013D178(void); +extern void func_8013D330(void); +extern void func_8013D53C(); +extern void func_8013DD68(); +extern void func_8013D8FC(void); +extern void func_8013CF68(void); +extern void func_8013D3D4(int param_1, int param_2); +extern void func_8013DBE4(int param_1); +extern s32 func_8013E054(void); +extern int SquareRoot12(int a0); +extern int func_8013E064(s16 *a0, s16 *a1); +extern int func_8013E0FC(s16 *a0, s16 *a1); +extern int func_8013E194(s16 *a0, s16 *a1); +extern void Square12(s32 *a0, s32 *a1); +extern s32 func_8013E22C(struct VecA *a0, struct VecB *a1); +extern s32 func_8013E298(s16 *a0); +extern int func_8013E2C4(short *a0); +extern void *D_801274CC; +extern s32 func_8013E410(void); +extern s32 func_8013E448(s32 a0); +extern void func_8013E370(void); +extern s32 (*D_801274D0)(s32); +extern s32 D_801274D8; +extern s32 D_801274DC; +extern s32 func_8013E448(s32 param_1); +extern void func_800D24A0(s32 a0); +extern void func_80141788(void); +extern void *D_8011DB24; +extern s32 func_800D0EC4(void); +extern void func_80141874(void); +extern u8 D_800B9A15; +extern unsigned char D_800B9A13; +extern u16 D_80115110; +extern unsigned short D_80115112; +extern void func_8013E588(void * _arg0); +extern void func_801754A8(void); +extern s32 func_80014ED4(s32); +extern s32 func_80015018(s32); +extern void func_800190AC(void); +extern void func_80141C04(void); +extern void func_8013E5E8(void); +extern void func_8013E83C(void); +extern void func_8013E6AC(void); +extern void func_800D24A0(s32 arg); +extern void func_8013E814(void); +extern void func_8013E83C(); +extern void func_8013E958(); +extern s32 func_80141C50(void); +extern void func_8013F244(void); +extern void func_8013FAF8(s16 a0, s16 a1); +extern void func_8013E958(void); +extern u8 D_801151C8[]; +extern s32 D_801151D0; +extern u16 D_8011511A; +extern u16 D_8011511E; +extern s32 D_80115130; +extern s16 D_8011514C; +extern void func_8013EA54(void); +extern s32 func_8013F350(void); /* §30#2 widened: def returns live $v0; callers discard */ +extern s16 func_8014168C(s16 a0); +extern s32 func_8014032C(s32 a0, s32 a1); +extern unsigned char *func_80141CA4(void); +extern void func_8013EB7C(void); +extern s32 func_8013F350(void); /* §30#2 widened (discarding caller) */ +extern u16 D_80115112; +extern void func_8013ED6C(void); +extern s32 func_8013EE10(); +extern void func_8013F138(void); +extern void func_800D2624(void); +extern unsigned short D_80115114; +extern unsigned short D_80115118; +extern void func_8013F1BC(void); +extern void func_80141C0C(s32); +extern u16 D_8011511C; +extern u16 D_80115120; +extern u16 D_80115122; +extern s16 D_80115128; +extern s16 D_8011512A; +extern u16 D_8011512E; +extern u8 D_80115140[]; +extern s16 D_8011514E; +extern u8 D_80115152; +extern u8 D_80115158[]; /* macro-canonical (§8e) */ +extern u8 D_8011515C; /* macro-canonical (§8e) */ +extern u8 D_8018B4A8[]; +extern u8 D_8018B4C0[]; +extern u16 D_8018B3C4[]; +extern s32 func_80029178(s32 arg); +extern s32 func_800291B4(s32 arg); +extern void func_8014AA04(s32 a0); +extern void func_801415C0(s32 a0, s32 a1); +extern void func_80141C0C(s32 a0); +extern s32 func_80140608(s32 a0); +extern void func_801407F4(void); +extern s32 func_801416D4(s16); /* macro-canonical (§8e) */ +extern s32 func_8013F350(void); +extern void func_80140E6C(void); +extern void func_80140F00(void); +extern s32 *func_80140958(s32 *, s32, s32); +extern int func_80141100(int); +extern s16 func_8014168C(s16); +extern s32 func_8013FFD8(s16, s32, s32 *); +extern void func_80024054(void *a0, void *a1); +extern s32 *func_800D2650(s32 *, void *, s32, s32, s32, s32); +extern s32 func_800D27DC(s32, s32 *, void *, s32, s32); +extern s32 *func_800D29F8(s32, s32, void *, s32, s32); +extern void func_8013FAF8(s16 arg0, s16 arg1); +extern s32 func_80028D58(void); +extern s32 func_80028DE0(void); +extern s32 func_80028FBC(void); +extern s32 func_80029000(void); +extern s32 func_80028D9C(void); +extern int func_800D2CA8(int, int); +extern void func_800D2D10(int, int, void *, int); +extern int func_80029FE4(void); +extern char *func_8002AAB4(void); +extern char *strcpy(char *, const char *); +extern int func_8002A26C(void); +extern int func_8002A2B0(void); +extern int func_8002A4B8(void); +extern int func_8002A998(void); +extern int func_8002A9DC(void); +extern int func_8002A728(void); +extern int func_8002A76C(void); +extern int func_80029FD4(void); +extern s32 func_8002A1B4(void); +extern short func_8002A28C(void); +extern short func_8002A27C(void); +extern s32 func_8002A400(void); +extern short func_8002A4D8(void); +extern short func_8002A4C8(void); +extern s32 func_8002A8E0(void); +extern short func_8002A9B8(void); +extern short func_8002A9A8(void); +extern s32 func_8002A670(void); +extern short func_8002A748(void); +extern short func_8002A738(void); +extern int func_801412A8(int, int, int, int, int, int); +extern int func_80141100(int param_1); +extern void func_800291A0(s32, s32); +extern s32 func_800291DC(s32); +extern void func_800291C8(s32, s32); +extern void func_801415C0(s32 param_1, s32 param_2); +extern u8 D_80115148[]; +extern u8 D_80115149[]; +extern u8 D_80115158[]; +extern u8 D_8011514D; +extern u8 D_8011515C; +extern s32 func_800D11F0(s32 a0); +extern s32 func_800D1658(s32 a0); +extern s32 func_801416D4(s16 param_1); +extern void func_8001903C(void); +extern void func_801417C4(void); +extern u8 D_800B9A16; +extern u16 D_80115114; +extern void func_801417F8(void); +extern volatile u16 D_8011511A; +extern u16 D_8011512E; /* §17a-1: canonical width (jr_8013F350 TUs decl u16); byte-neutral here (only use is store-0) */ +extern s32 func_80029178(s32 a0); +extern void func_801418F8(void); +extern void func_80141A60(void); +extern void func_80141C0C(s32 param_1); +extern s32 func_80015144(void); +extern unsigned char D_80112C04[]; +extern unsigned char D_80112C50[]; +extern unsigned char D_80112C9C[]; +extern unsigned char D_80112CE8[]; +extern unsigned char D_80112D38[]; +extern unsigned char D_80112D78[]; +extern unsigned char D_80112DBC[]; +extern unsigned char D_80112DF4[]; +extern unsigned char D_80112E14[]; +extern unsigned char D_80112E40[]; +extern unsigned char D_80112E6C[]; +extern unsigned char D_80112EBC[]; +extern unsigned char D_80112F0C[]; +extern unsigned char D_80112F48[]; +extern unsigned char D_80112F9C[]; +extern unsigned char D_80112FDC[]; +extern unsigned char D_8011302C[]; +extern unsigned char D_80113074[]; +extern unsigned char D_801130B8[]; +extern unsigned char D_801130E8[]; +extern unsigned char D_80113138[]; +extern unsigned char D_8011317C[]; +extern unsigned char D_801131A8[]; +extern unsigned char D_801131E8[]; +extern unsigned char D_80113214[]; +extern unsigned char D_80113254[]; +extern unsigned char D_80113278[]; +extern unsigned char D_801132B8[]; +extern unsigned char D_801132E4[]; +extern unsigned char D_80113324[]; +extern unsigned char D_80113360[]; +extern unsigned char D_801133A4[]; +extern unsigned char D_801133F4[]; +extern unsigned char D_80113440[]; +extern unsigned char D_80113474[]; +extern unsigned char D_801134B0[]; +extern unsigned char D_801134FC[]; +extern unsigned char D_80113530[]; +extern unsigned char D_80113554[]; +extern unsigned char D_801135A8[]; +extern unsigned char D_80113600[]; +extern unsigned char D_80113650[]; +extern unsigned char D_80113694[]; +extern unsigned char D_801136DC[]; +extern unsigned char D_80113724[]; +extern unsigned char D_80113744[]; +extern unsigned char D_80113770[]; +extern unsigned char D_80113794[]; +extern unsigned char D_801137D8[]; +extern unsigned char D_8011381C[]; +extern unsigned char D_8011383C[]; +extern unsigned char D_8011386C[]; +extern unsigned char D_801138A4[]; +extern unsigned char D_801138D0[]; +extern unsigned char D_80113900[]; +extern unsigned char D_80113944[]; +extern unsigned char D_80113964[]; +extern unsigned char D_8011399C[]; +extern unsigned char D_801139E8[]; +extern unsigned char D_80113A28[]; +extern unsigned char D_80113A50[]; +extern unsigned char D_80113A84[]; +extern unsigned char D_80113AB0[]; +extern unsigned char D_80113AE0[]; +extern unsigned char D_80113B34[]; +extern unsigned char D_80113B68[]; +extern unsigned char D_80113BA4[]; +extern unsigned char D_80113BC0[]; +extern unsigned char D_80113BF0[]; +extern unsigned char D_80113C20[]; +extern unsigned char D_80113C3C[]; +extern unsigned char D_80113C7C[]; +extern unsigned char * func_80141CA4(void); +extern void func_80142414(s32 a0, s16 a1); +extern void func_80142454(s32 a0); +extern void func_801424E4(short *param_1); +extern void func_801425CC(void *a0); +extern void func_8001CA1C(s32 a0, s32 a1); +extern s32 func_8012AD50(void *a0); +extern void func_80142608(s32 param_1); +extern void func_801426D4(s32 a0); +extern void func_80142740(int param_1); +extern void func_80142778(u8 *a1); +extern void func_801427DC(void); +extern void func_801427E4(void); +extern void func_801427EC(int param_1); +extern s32 func_80142DB8(s32 *a0); +extern s32 func_80142D38(s32 *a0); +extern void func_80142BB4(s32 *a0, s32 a1, s32 a2); +extern void func_801428CC(s32 *a0); +extern void func_8014292C(int param_1); +extern void func_80142978(int param_1); +extern void func_801429C4(int param_1); +extern void func_80142A80(void); +extern void func_80142C7C(void); +extern void func_80142C84(s32 a0); +extern void func_80142C9C(s32 * arg0); +extern void func_80142B2C(); +extern void func_80142DC4(int param_1); +extern void func_80142E38(int param_1); +extern void func_8012A828(s32 a0, void *a1); +extern void func_80142EC0(s32 param_1); +extern void func_80142FFC(s32 *a0); +extern void func_8014305C(int param_1); +extern void func_80143188(s32 *a0); +extern int func_8001CA88(int, void *); +extern void func_800233CC(void *, unsigned short); +extern void func_801431E8(s32 param_1); +extern void func_80142C9C(s32 *a0); +extern void func_801432FC(s32 *a0); +extern void func_80143390(s32 *a0); +extern void func_80143458(s32 param_1); +extern void func_8014358C(s32 param_1); +extern s32 rand(void); +extern void func_80143640(s32 a0, s32 a1, s32 a2, s32 a3); +extern void func_801437D8(s32 a0, s32 a1, s32 a2, s32 a3); +extern s32 func_80143970(s32 a0); +extern s32 func_8012C658(s32 a0, s32 a1, s32 a2); +extern void func_80143994(s32 a0, s32 a1); +extern void func_801439C0(u8 *a0); +extern s16 D_801152AC; +extern s16 D_801152AA; +extern void func_801439FC(s32 a0); +extern void func_80143B30(void *a0); +extern s32 func_8012C658(s32 arg0, s32 arg1, s32 arg2); +extern s32 func_80143B6C(s32 arg0, s32 arg1); +extern void func_80143BDC(u16 *a0); +extern void func_80143C38(void *a0); +extern void func_80143C74(s32 a0, s32 a1); +extern void func_80143C98(void *a0); +extern void func_80143E68(void *a0); +extern void func_80143EA4(void); +extern void func_80143EAC(void); +extern void func_80143EB4(void); +extern s32 func_8004787C(s32 a0); +extern void func_80143EBC(s32 a0); +extern void func_80144054(void *a0); +extern void func_801442F8(int param_1); +extern void func_8001CB6C(u8 *a0, s32 a1, s32 a2, s32 a3); +extern void func_80144364(int param_1); +extern u8 D_800D387C[]; +extern u8 D_800D3888[]; +extern void func_80144558(u8 *param_1); +extern void func_801446A4(int param_1); +extern void func_8014477C(void *param_1); +extern void func_80144880(s32 param_1); +extern void func_80144988(s32 a0); +extern void func_801449C8(void *a0); +extern void func_80144A04(s32 *a0); +extern void func_80144A2C(void *a0); +extern void func_80144A68(s32 *a0); +extern void func_80144A90(void); +extern void func_80144A98(u8 *a0); +extern void func_80144B14(); +extern void func_80144AEC(s32 *a0); +extern void func_801458E0(void); +extern s32 D_800AE6AC; +extern s32 D_800AE6B0; +extern s16 D_800B9A0A; +extern u8 D_80078E50; +extern void func_800D185C(u8 *a0); +extern void func_801458E8(void); +extern void func_80145B24(void); +extern void func_80145934(void); +extern void func_80145A2C(void); +extern void func_80162120(void); +extern void func_80029124(s32, s32); +extern s32 func_80165A50(s32); +extern void func_80029514(s32); +extern u8 D_80078EC0; +extern void func_80145BF8(void); +extern void func_80145C54(void); +extern void func_80146014(s32 a0); +extern void func_80145EE8(s32 param_1); +extern void MoveImage(void *a0, s32 a1, s32 a2); +extern s32 func_80146128(void); +extern void func_80146360(void); +extern void func_801463A0(); +extern u8 D_80078EC1; +extern s32 D_80078EC8; +extern s32 D_80126B9C; +extern s32 D_8011F730; +extern u16 D_801152B8; +extern u16 D_8012693A; +extern u8 D_80126BE0[]; +extern u8 D_801150F0[]; +extern void *memcpy(void *dst, const void *src, u32 n); +extern void func_80146FC4(s32 a0); +extern void func_80150A70(s32 a0); +extern void func_80147098(s32 *a0); +extern void func_8014A638(s32 arg0); +extern s32 func_80155458(s32 a0); +extern s32 func_80029104(void); +extern void func_80029344(void); +extern void func_8014ADE0(s32 a0); +extern void func_8014B350(s32 a0); +extern void func_8014B7A4(s16 *param_1); +extern s32 func_80161D58(s32 a0); +extern void func_80161A90(s32 a0); +extern void func_8014B504(u16 *a0); +extern void func_80149BEC(s32 a0); +extern void func_8014B5D0(s32 *a0); +extern void func_8014C99C(u8 *a0); +extern void func_8014B190(s32 s0); +extern void func_80148648(s32 a0, s32 a1); +extern s32 func_80149228(s32 a0); +extern void func_8014A59C(s32 a0); +extern void func_8016F14C(void *a0); +extern void func_80154418(void *a0); +extern void func_80154BE4(s32 a0); +extern void func_80165694(s32 arg0); +extern void func_801654A8(s32 a0); +extern void func_8014A680(s32 a0); +extern void func_8014A6A8(s32 a0); +extern void func_8014A71C(s32 a0); +extern void func_80172588(s32 *a0); +extern void func_801473DC(s32 *a0); +extern void func_80015978(s32 a0, s32 *a1); +extern s32 D_80127098; +extern s32 D_80127094; +extern s32 D_80127090; +extern void func_80146534(void); +extern void func_8001D074(s32 a0, s32 a1); +extern void func_80146554(void); +extern void func_80146578(void); +extern void func_8001CFDC(s32, s32); +extern void func_8014659C(void); +extern void func_8001D074(s32, s32); +extern void func_801465C0(void); +extern void func_801465E4(void); +extern void func_801466F0(s32 a0, s32 a1, s32 a2, s32 a3, s32 sp5, s32 sp6, s32 sp7, s32 sp8); +extern s32 D_8011F9D0; +extern s32 func_80146608(s32 a0, s32 a1, s32 a2, s32 a3, s16 arg9, s32 arg10, s32 arg11, s32 arg12, s32 arg13); +extern void func_801466B4(u16 a0, s32 a1, s32 a2, s32 a3, s32 arg5); +extern s32 D_8011F750; +extern s32 D_8011F754; +extern u8 * func_801468C8(s32 arg0, u8 arg1); +extern s32 D_8011D030; +extern s32 func_80146994(s32 a0, s32 a1, s32 a2, s32 a3); +extern s32 func_80146924(s32 a0, s32 a1, s32 a2, s32 a3, s32 arg5); +extern s32 func_80146994(s32 arg0, s32 arg1, s32 arg2, s32 arg3); +extern s32 func_801469C8(int a0, void *a1, int a2, int a3, u16 arg5, int arg6, int arg7, int arg8); +extern s32 func_80146B9C(void *a0); +extern void func_80146AB4(s16 a0, s32 a1, s16 a2, s16 a3, u16 a4, s32 a5, s32 a6); +extern u16 D_8011DA28; +extern s32 func_80146B9C(void * arg0); +extern void func_80146C3C(u8 *a0); +extern void func_80146C98(s32 *a0, s16 a1); +extern void func_80146CA0(void *a0); +extern void func_80146CB4(void *a0); +extern void func_80146CC8(s32 a0); +extern void func_80146D30(s32 a0); +extern void func_80146D80(s32 *a0); +extern void func_80146DE8(s32 *a0, s32 a1, s32 a2, s32 a3); +extern void func_80146D90(s32 a0); +extern void func_80146DB8(s32 *a0, s32 *a1); +extern void func_80146DF8(s32 *a0, s32 a1, s32 a2, s32 a3, s32 t0); +extern void func_80146E90(s32 *a0, s32 a1); +extern s32 func_80146E98(s32 a0); +extern void func_80015954(s32 a0, s32 a1); +extern void func_80149374(s32 a0, s32 a1); +extern void func_80146F58(s32 a0, s32 a1); +extern void func_80146EC0(s32 a0, s32 a1, s32 a2, s32 a3); +extern u8 D_80126DB0[]; +extern u16 D_80126DB6; +extern void func_8014704C(s32 *a0); +extern s32 func_80147054(void *a0); +extern void func_80147060(u8 * a0); +extern void func_8014706C(void *arg0); +extern void func_80147078(s32 *a0, s16 a1); +extern void func_80147084(s32 *a0); +extern void func_8014708C(void *arg0); +extern s32 func_801470A0(void *a0); +extern void func_801470AC(s32 *a0); +extern void func_801470B4(s32 arg0); +extern void func_801470C0(s32 a0); +extern void func_80147118(s32 a0); +extern s16 D_80126BB8; +extern s16 D_80126BBA; +extern s16 D_80126BBC; +extern void func_80147264(s32 a0); +extern void func_80147290(void); +extern void func_801472B4(void *a0); +extern s32 func_801472C8(struct S *a0); +extern void *D_8012707C; +extern void func_801472DC(void); +extern void func_801472F0(void *a0); +extern void func_80147364(u16, s32); +extern void func_80147300(u16 arg0); +extern void func_80147324(s32 arg0); +extern void func_801473EC(s32 *a0); +extern void func_80147460(s32 a0); +extern void func_80147514(); +extern void func_80147628(s32 a0); +extern void func_80147478(s32 a0); +extern void func_801474D8(s32 *a0); +extern void func_801474EC(s32 *a0); +extern s32 func_80012C6C(s32 a0, s32 a1, s32 a2); +extern s32 func_800129CC(s32 a0, s32 a1); +extern void func_80147514(s32 arg0); +extern void func_80013F3C(s32 a0); +extern void func_80012558(s32 a0, s32 a1); +extern void func_800126C4(s32 a0, s32 a1); +extern void func_800123F0(s32 a0, s32 a1); +extern void func_80147718(s32 a0); +extern void func_80147788(void *a0, s32 a1); +extern void func_801477A8(void *a0, s32 a1); +extern void func_801477C8(void *a0, s32 a1); +extern void func_801477E8(s32 *a0, s32 a1); +extern void func_80147814(s32 a0, s32 a1); +extern void func_80147928(int a0, int a1); +extern void func_8014799C(int a0, int a1); +extern void func_80147A10(int a0, int a1); +extern void func_80147860(int a0, int a1, int a2, int a3); +extern void func_80147948(s32 a0, s32 a1, s32 a2); +extern void func_801479BC(s32 a0, s32 a1, s32 a2); +extern void func_80147A30(s32 a0, s32 a1, s32 a2); +extern void func_801478B8(s32 a0, s32 a1, s32 a2, s32 a3); +extern void func_80147948(int a0, int a1, int a2); +extern void func_801479BC(int a0, int a1, int a2); +extern void func_80147A30(int a0, int a1, int a2); +extern void func_80147AD4(s32 arg0, s32 arg1, s32 arg2, s32 arg3); +extern void func_80147A84(s32 arg0); +extern void func_80147C30(s32 arg0, s32 arg1, s32 arg2, s32 arg3); +extern void func_80147AAC(s32 arg0); +extern void func_80147CC8(s32 a0, s32 a1, s32 a2, s32 a3, s32 a4); +extern void func_80147B5C(s32 a0, void *a1); +extern void func_80147AD4(s32 a0, s32 a1, s32 a2, s32 a3); +extern void func_80147D38(s32 a0, s32 a1, s32 a2, s32 a3, void *a4); +extern void func_80147B18(s32 a0); +extern void func_80147B5C(s32 arg0, void *arg1); +extern void func_80147C30(s32 a0, s32 a1, s32 a2, s32 a3); +extern void func_80147DC0(s32 a0, s32 a1); +extern void func_80147D38(s32 a0, s32 a1, s32 a2, s32 a3, void * a4); +extern void func_80147E44(s32 a0, s32 a1, s32 a2, s32 a3); +extern void func_80147F78(s32 arg0, s32 arg1, s32 arg2, s32 arg3); +extern void func_80147F50(s32 arg0); +extern volatile s32 D_80127090; +extern volatile s32 D_80127094; +extern volatile s32 D_80127098; +extern void func_80147F78(s32 a0, s32 a1, s32 a2, s32 a3); +extern void func_80148038(s32 a0, s32 a1); +extern s32 csqrt(s32 a0); +extern s32 func_80012A60(s32 a0, s32 a1); +extern void func_80148094(int param_1, short *param_2, int *param_3); +extern void func_801485B8(s32 a0, s32 a1, s32 a2); +extern void func_801484B0(s32 a0, s32 a1); +extern s32 func_80154358(void *a0); +extern void func_801484E8(s32 a0, s32 a1); +extern void func_80148534(s32 a0, s32 a1); +extern void func_8014856C(s32 a0, s32 a1); +extern void func_801485B8(s32 arg0, s32 arg1, s32 arg2); +extern void func_80148634(void *a0); +extern s32 func_80014DC0(); +extern s32 func_80014D68(); +extern s32 func_80014D94(); +extern s32 func_80014CF8(); +extern void func_800120DC(); +extern s32 func_800CF8B4(); +extern u16 func_801487F4(s32 *a0); +extern u16 func_80148800(s32 *a0); +extern u8 func_8014880C(s32 *a0); +extern u16 func_80148818(s32 *a0); +extern s32 func_80148824(void *arg0); +extern s32 func_801488A8(u8 *a0); +extern s32 func_8014891C(s32 a0); +extern s32 func_80148980(u8 *a0); +extern s32 func_801489E8(s32 a0); +extern s32 func_80148A48(s32 a0); +extern int func_80148AFC(void *a0); +extern void func_80148AAC(u8 *a0); +extern s32 func_80148C18(void); +extern s32 func_80148C20(s32 a0, s16 a1); +extern s32 func_80148C34(s32 a0, s32 a1); +extern s32 func_80148C4C(s32 a0, s32 a1); +extern s32 func_80148C64(s32 a0, s32 a1); +extern s32 func_80148C7C(void); +extern s32 func_80148C84(s32 a0, s32 a1); +extern s32 func_80148C9C(s32 a0, s32 a1); +extern s32 func_80148CB4(s32 a0, s32 a1); +extern s32 func_80148CCC(s32 a0, s32 a1); +extern s32 func_80148CE4(void); +extern s32 func_80148CEC(void); +extern s32 func_80148CF4(s32 a0, s32 a1); +extern s32 func_80148D0C(s32 a0, s32 a1); +extern s32 func_80148D24(void *a0, int a1); +extern s32 func_80148D3C(void); +extern s32 func_80148D44(void); +extern s32 func_80148F60(void); +extern s32 func_80148F68(s32 a0); +extern s32 func_80148F74(s32 a0); +extern s32 func_80148F80(s32 a0); +extern s32 func_80148F8C(s32 a0); +extern s32 func_80148F98(void); +extern s32 func_80148FA0(s32 a0); +extern s32 func_80148FAC(s32 a0); +extern s32 func_80148FB8(s32 a0); +extern s32 func_80148FC4(s32 a0); +extern s32 func_80148FD0(void); +extern s32 func_80148FD8(void); +extern s32 func_80148FE0(s32 a0); +extern s32 func_80148FEC(s32 a0); +extern s32 func_80148FF8(s32 a0); +extern s32 func_80149004(void); +extern void func_8014900C(s32 *a0); +extern void func_80149020(s32 *a0); +extern void func_80149034(s32 *a0); +extern void func_80149048(s32 *a0); +extern void func_8014905C(u8 *a0); +extern void func_801490E0(s32 *a0, s16 a1); +extern void func_801490E8(s32 *a0, s16 a1); +extern void func_801490F0(s32 *a0, s16 a1); +extern void func_80149078(s32 *a0, s32 a1, s32 a2, s32 a3); +extern s32 func_80012B04(s32 a0, s32 a1, s32 a2); +extern void func_801490F8(s32 a0, s32 a1); +extern s32 func_801491C4(s32 a0); +extern s32 func_80149184(s32 a0); +extern void func_80149204(s32 *a0); +extern void func_80149210(s32 a0, s32 a1); +extern s32 func_80149284(s32 *a0, s32 a1); +extern void func_80149350(s32 arg0); +extern void func_80149290(s32 a0); +extern s32 func_801496D4(void *a0); +extern void func_8015AD08(); +extern void func_80149704(void); +extern void func_8015ACC4(); +extern void func_80149724(void); +extern u8 D_80078EBF; +extern s32 func_80149744(struct S_80149744 *a0); +extern void func_8015F7A0(); +extern void func_80149788(void); +extern void func_801653B8(); +extern void func_80149864(void); +extern s32 func_8016F1AC(void); +extern s32 func_80149884(void); +extern void func_80160B00(); +extern void func_801498C0(void); +extern s32 func_80149AA8(s32 *a0); +extern s32 func_80149B54(s32 *a0); +extern void func_80146750(); +extern s32 func_801498E0(s32 *a0); +extern s32 func_80149A64(s32 *a0); +extern void func_8015DAC4(s32 *a0); +extern void func_8015554C(s32 *a0); +extern void func_80149AD4(s32 *a0); +extern void func_80149B14(s32 *a0); +extern u8 func_8014BEF8(void); +extern s32 func_80149B54(s32 * arg0); +extern void func_8015DE24(s32 *a0); +extern void func_80157510(s32 *a0); +extern void func_80149BAC(s32 *a0); +extern s32 func_80149C08(s32 arg0); +extern void func_801577C8(); +extern void func_80149C94(void); +extern void func_80157D20(void); +extern void func_80149CB4(void); +extern s32 func_80149CD4(s32 a0); +extern u8 func_8014B5B8(s32 *a0); +extern s32 func_80149D10(s32 a0); +extern s32 func_80149E94(s32 a0); +extern s32 func_80149DD8(s32 a0); +extern s32 func_80149D9C(s32 a0); +extern s32 func_80149F2C(s32 a0, s32 a1); +extern s32 func_80149E94(s32 arg0); +extern void func_80149FA8(void); +extern s32 func_80149FB0(s32 a0); +extern u16 func_80156370(u16 a0); +extern void func_8014C4AC(s32 a0, s32 a1, s32 a2, s16 *a3, s32 a4); +extern void func_8014A1B0(s32 a0, s32 a1); +extern void func_8015D4B4(); +extern void func_8014A218(void); +extern s32 func_8014C278(s32 a0, s32 a1, s32 a2); +extern s32 func_8014C2B0(void *a0, void *a1, s32 a2); +extern s32 func_8014A238(s32 arg0); +extern s32 func_8014A2E4(s32 a0); +extern void func_8014A380(s32 a0, s32 a1); +extern s16 D_801152B0; +extern s16 D_801152B4; +extern s32 func_8014A3E0(struct S_8014A3E0 *a0); +extern s32 func_8014A454(s32 a0); +extern s32 func_8014A4B4(void *a0); +extern void func_8015EDD4(); +extern void func_8014A4FC(void); +extern s32 func_8014A674(s32 *a0); +extern s32 func_8014A69C(s32 *a0); +extern s32 func_8014A6C4(s32 a0); +extern void func_8015E184(); +extern void func_8014A830(void); +extern s32 func_80029AF4(void); +extern s32 func_8014A850(s32 param_1); +extern void func_801599A4(void *a0); +extern void func_80159B3C(void *a0); +extern s32 func_80165A20(s32 a0); +extern void func_8014AB7C(); +extern void func_8014AC10(); +extern void func_8014AA28(void); +extern void func_8014AB5C(void); +extern void func_80162CCC(void); +extern void func_8014AB7C(s32 arg0); +extern void func_8014ABF0(void); +extern void func_8014AC10(s32 arg0); +extern void func_8014ACC0(s32 a0, s32 a1); +extern void func_8014AD30(s32 a0, u16 *a1, s32 a2, s32 a3); +extern void func_8014ACE8(void *a0, s32 a1, s32 a2); +extern void func_80146AFC(void *a0); +extern void func_8014ADA8(s32 a0, s32 a1); +extern void func_8014AD7C(s32 a0); +extern s32 D_80078E8C; +extern u8 D_80078E78[]; +extern s32 func_8016F1C4(void); +extern s32 func_8014B154(s32 *a0); +extern void func_8014BD24(s32 a0, s32 a1); +extern void func_8014BB24(s32 a0, s32 a1, s32 a2); +extern void func_8014BC80(s32 a0, s32 a1); +extern void func_8014BD60(s32 a0, s32 a1); +extern void func_8014B084(void); +extern void func_8014B034(s32 arg0); +extern void func_8014B00C(s32 arg0); +extern s16 D_80078E90; +extern void func_8014B034(s32 a0); +extern u16 D_80078EAC; +extern u8 D_80078EBA; +extern void func_800D10EC(void); +extern void func_8002AC98(void); +extern void func_8014B12C(void); +extern void func_8014B2F8(void); +extern void func_8014B4C4(void); +extern void func_8014B160(s32 a0); +extern s16 D_80078E96; +extern s16 D_80078EB8; +extern u16 D_80078EA6; +extern void func_8014B2A8(void); +extern void func_8014B310(void); +extern void func_8014B2D0(void); +extern s32 D_80078E94; +extern s32 D_80078ECC; +extern void func_8014B33C(void); +extern u8 D_80062BF4[]; +extern void func_80019064(void *a0); +extern s32 D_80078E98; +extern void func_8014B4D4(void *a0); +extern s16 D_80078E9A; +extern u8 D_80126D1C; +extern s32 D_80126D74; +extern void func_8014B598(s32 a0, s32 a1); +extern void func_8014B5B0(s32 *a0); +extern void func_8014B5C4(s32 *a0, s32 a1, s32 a2); +extern void func_8014B5D8(s32 s1); +extern s32 D_80078E9C; +extern s32 D_80078ED0; +extern void func_8014B6F0(s32 a0, s32 a1); +extern void func_8014B768(s32 a0, s32 a1); +extern void func_8014B944(s32 a0, s32 a1, s32 a2); +extern s32 D_80078EA4; +extern u16 D_80078EB2; +extern s16 D_80078EB4; +extern void func_8014BB0C(void); +extern void func_8014BC0C(s32 a0, s32 a1); +extern void func_8014BC44(s32 a0, s32 a1); +extern void func_8014BCC0(s32 a0, s32 a1); +extern u16 D_80078EB6; +extern s32 func_8014BCEC(s32 a0, s32 a1); +extern void func_8014BD60(s32 param_1, s32 param_2); +extern void func_8014BD98(s32 a0, u16 a1); +extern void func_8014BDC8(void); +extern void func_8014BDE0(void); +extern s32 func_8017267C(s32 *a0); +extern s32 func_80013294(void *a0, void *a1); +extern void func_80029ED4(s32 a0); +extern void func_8014BDE8(s32 a0); +extern void func_8014BE78(void); +extern void func_8014BE9C(void); +extern void func_80029124(s32 a0, s32 a1); +extern void func_8014BEC0(void); +extern void func_8014BF18(s32 a0); +extern void func_8014BF48(void); +extern u8 func_8014BF6C(void); +extern void func_8014BF8C(u8 arg0); +extern void func_8014BFB0(void); +extern u8 func_8014BFD4(void); +extern void func_8014BFF4(s32 a0, s32 a1); +extern void func_8014C010(s32 a0, s32 a1); +extern s32 func_8014C050(s32 a0, s32 a1); +extern s32 func_8014C088(s32 a0, s32 a1); +extern s32 func_8014C0C8(s32 a0_unused, s32 a1, s32 a2); +extern s32 func_8014C118(void * a0, s32 a1, s32 a2); +extern s32 func_8014C168(s32 * param_1, s32 param_2); +extern void func_8014C1C8(s32 a0, s32 a1, void* a2); +extern s32 func_80013328(s32 a0, s32 a1); +extern s32 func_8014C59C(void *a0, void *a1); +extern s32 func_8014C308(s32 arg0, s32 arg1, s32 arg2, s32 arg3); +extern s32 func_8014C43C(void *a0, s32 a1, s32 a2, s32 a3, s16 a5); +extern s32 func_8014C3A4(void *a0, s32 a1, s32 a2, s32 a3); +extern s32 func_8014C3D0(void *a0, s32 a1, s32 a2, s32 a3); +extern s32 func_8014C43C(void * a0, s32 a1, s32 a2, s32 a3, s16 a4); +extern s32 ratan2(s32 dx, s32 dy); +extern s32 func_8014C5FC(s32 a0, s32 a1, void *a2); +extern s16 func_8014C5D0(s32 a0, s32 a1); +extern s32 func_8014C5FC(s32 a0, s32 a1, void * a2); +extern u8 D_80126D17; +extern void func_8014C6AC(void); +extern void func_8014C6C0(void); +extern u8 D_80126D1E; +extern void func_8014C6D0(void); +extern void func_8014C6E0(void); +extern s32 func_8014C860(s32 a0, s32 a1); +extern void func_8014C8C8(s32 a0, s32 *a1); +extern void func_8014C88C(s32 a0); +extern void func_8014C8C8(s32 dst, s32 * src); +extern void func_8014C8F0(s32 arg0); +extern u8 D_801151F0[]; +extern s32 func_8014C918(s32 a0, s32 a1); +extern s32 D_80126B50; +extern void func_8014C968(void); +extern s32 func_8014C98C(void); +extern void func_80139914(s32 a0); +extern s32 func_8014CA00(s32 a0); +extern u16 func_8014CA70(s32 a0, s32 a1); +extern s32 func_8014CA14(s32 a0, s32 a1); +extern u16 func_8014CAE4(s32 *a0, s32 a1); +extern s32 func_8014CA88(s32 *a0, s32 a1); +extern s32 func_8014CAFC(void); +extern s32 func_8014CB0C(void); +extern s32 func_8014CB1C(void); +extern u8 D_80126D1F; +extern s32 func_8014CB2C(void); +extern s32 func_8014CB58(void); +extern u8 D_80126D1D; +extern void func_8014CB68(void); +extern s32 func_8014CB7C(void); +extern s32 func_8014CB8C(void); +extern struct Packed8 D_80126C98; +extern short D_80126C9E; +extern void func_8014CB9C(struct Packed8 *a0); +extern s32 D_80126CDC; +extern void func_8014CBD8(void); +extern void func_8014CBF8(void *a0); +extern void func_8014D3E0(s32 a0); +extern void func_8014D04C(void); +extern void func_8014CCB4(void); +extern void func_8014CC28(s32 a0); +extern void func_8014CD0C(u8 *a0); +extern void func_8014CF04(); +extern void func_8014CD80(); +extern s32 func_8014D2A0(); +extern s32 func_8014D12C(); +extern void func_8014D0A4(s32 a0); +extern void func_8014D610(); +extern s32 func_8014D4C0(); +extern void func_8014D438(s32 a0); +extern s32 func_8014DD8C(s32 a0, void *a1, void *a2); +extern s32 func_8014D820(s32 a0, u16 *a1, u16 *a2); +extern void func_8014D790(s32 a0); +extern s32 func_8014DCE0(s32 arg0, s32 arg1, s32 arg2); +extern s32 func_8014DD8C(s32 arg0, void *arg1, void *arg2); +extern s32 func_8014E284(s32 a0, s16 *a1, s16 *a2); +extern s32 func_8014E048(s32 a0, u16 *a1, u16 *a2); /* u16*: def lhu semantics (T5b reconcile; ptr param type codegen-neutral for the caller) */ +extern void func_8014DF94(s32 arg0); +extern s32 func_80135A4C(s32 a0, s32 a1, s32 *a2, s32 a3); +extern u8 D_801152A8[]; /* canonical TU type (engine_core) — read via *(u16*) cast */ +extern s32 func_8014E048(s32 param_1, u16 * param_2, u16 * param_3); +extern s32 func_80135A4C(s32 a0, s32 a1, s32 *a2, s32 a3); /* canonical (engine_core.h:11555) */ +extern s32 func_8014E284(s32 a0, s16 *arg1, s16 *arg2); +extern void func_8014E5B4(s32 a0, void *a1, void *a2); +extern s32 func_8014E514(u8 *a0, s32 a1, s32 a2); +extern void func_8014E48C(s32 a0); +extern s32 func_8014E83C(s32 a0, s16 *a1, s16 *a2); +extern s32 func_8014E790(s32 a0, s16 *a1, s16 *a2); +extern void func_8014E6F8(struct SubE6F8 *a0); +extern s32 func_8014E790(s32 arg0, s16 * arg1, s16 * arg2); +extern s32 func_8014E83C(s32 arg0, s16 * arg1, s16 * arg2); +extern s32 func_8014EA4C(void *a0, void *a1, void *a2, s32 a3); +extern s32 func_8014E98C(void *a0); +extern u16 D_800B99DA; +extern s32 D_801150D8; +extern s16 D_80126724; +extern s32 func_8014EA4C(void * a0, void * a1, void * a2, s32 _arg3); +extern s32 func_8014EE14(s32 a0, s16 *a1, s16 *a2); +extern s32 func_8014ED80(struct SubED80 *a0); +extern s32 func_8014EE14(s32 arg0, s16 * arg1, s16 * arg2); +extern s32 func_8014F2E0(s32 a0, s16 *a1, s16 *a2); +extern s32 func_8014F24C(struct SubF24C *a0); +extern s32 func_8014F2E0(s32 arg0, s16 * arg1, s16 * arg2); +extern void func_8014F4C0(); +extern s32 func_8014F468(void); +extern s32 D_801152BC; +extern int func_8014F74C(s32 arg0); +extern s32 func_8014FA70(s32 a0); +extern void func_8014FA04(s32 a0); +extern s32 func_8014FC18(u8 *self); +extern int func_8014FD54(int param_1); +extern s32 func_80150170(void *a0); +extern s32 func_8014FE60(); +extern void func_8014FDF4(struct S8014FDF4 *a0); +extern s32 func_80150150(s32 a, s32 b); +extern s32 func_801502EC(s32 e, void *a1, void *a2); +extern s32 func_80150460(s32 e, s32 a1); +extern s32 func_80150170(void *e); +extern s32 func_80150460(s32 a, s32 b); +extern s32 func_80150528(void *a0, void *a1, void *a2); +extern void func_801504D8(u16 *a0); +extern s32 func_80150528(void *arg0, void *arg1, void *arg2); +extern s32 func_801506A4(s32 a0, s32 a1); +extern s32 func_801505FC(s32 a0); +extern void func_80150820(s32 a0, s32 a1); +extern void func_8015086C(int param_1); +extern s32 func_801508B4(s32 a0); +extern s32 func_8015094C(s32 a0); +extern short func_801508F8(s32 a0); +extern s32 func_80021174(s32 a0, s32 a1); +extern s32 func_8015094C(s32 param_1); +extern void func_80150B28(int param_1); +extern void func_80150B9C(void); +extern s32 func_80151184(s32 a0, s32 a1, s32 a2); +extern s32 func_80150BA4(s32 a0); +extern s32 func_801619D0(void *a0); +extern void func_80150BC8(s32 *a0); +extern s32 func_80150480(s32 a0); +extern u16 D_800AE6DC; +extern void func_80150C48(s32 a0); +extern int func_80151184(int arg, int a1, int a2); +extern int func_80150CA0(int arg); +extern void func_80150EC4(s32 a, s32 b); +extern void func_80150CC4(s32 a); +extern void func_80150CE4(s32 a); +extern void func_80150D04(s32 a); +extern void func_80150D24(s32 a); +extern void func_80150D44(s32 a); +extern void func_80150D64(s32 a); +extern void func_80150D84(s32 a); +extern void func_80150DA4(s32 a); +extern void func_80150DC4(s32 a); +extern void func_80150DE4(s32 a); +extern void func_80150E04(s32 a); +extern void func_80150E24(s32 a); +extern void func_80150E44(s32 a); +extern void func_80150EC4(s32 a0, s32 a1); +extern void func_80150E64(s32 a0); +extern void func_80150E84(s32 a0); +extern void func_80150EA4(s32 a0); +extern u8 D_800AE6C0; +extern s16 D_800AE6C8; +extern s16 D_800AE6CA; +extern s16 D_800AE6CC; +extern s32 D_800AE6C4; +extern s16 D_800AE6CE; +extern u8 D_800AE6BE; +extern u8 D_801201F8[]; +extern void func_80150F78(void); +extern void func_80150F80(s32 a0); +extern int func_80150FB4(int arg); +extern void func_80150FD8(s32 a0); +extern int func_80151014(int arg); +extern void func_80151038(s32 a0); +extern int func_80151070(int arg); +extern int func_80151094(int arg); +extern void func_801510B8(void); +extern void func_801510C0(void); +extern int func_801510C8(int arg); +extern int func_801510EC(int arg); +extern s32 func_80151110(void); +extern void func_80151130(void); +extern int func_80151138(int arg); +extern void func_8015115C(s32 *a0, s16 a1); +extern s32 func_80151164(s32 a0, s32 a1); +extern s32 func_80151184(s32 arg0, s32 arg1, s32 arg2); +extern void func_801511A8(u8 *a0); +extern void func_801511C4(u8 *a0); +extern int func_80151204(int arg, int a1); +extern int func_801511E0(int arg); +extern int func_80151204(int a0, int a1); +extern void func_80151238(void *a0); +extern void func_8015126C(u16 *p); +extern void func_80151780(s32 a0); +extern void func_801516F0(s32 *a0); +extern void func_8015173C(s32 *a0); +extern s16 D_8011DB1A; +extern s32 D_80127518; +extern s32 D_801151FC; +extern s32 func_801725CC(u8 *a0); +extern s32 func_80029D3C(void); +extern void func_80151878(void); +extern void func_80153B58(s32 *a0); +extern s32 func_80151880(s32 a0); +extern s32 func_801518D8(s32 a0); +extern s32 func_80151944(void); +extern s32 func_80151924(void); +extern void func_8014E934(s32 a0); +extern s32 func_8014F3E8(); +extern void func_801519C8(s32 a0); +extern void func_80151980(s32 a0); +extern M2C_UNK D_800D5880; +extern s32 D_800D58AC; +extern void func_80154274(s32 *a0, s32 a1); +extern void func_80154A74(s32 a0, s32 a1); +extern void func_801519C8(s32 arg0); +extern void func_80151C54(s32 a0); +extern void func_801542DC(s32 *a0, s32 a1); +extern void func_8015BDD0(s32 *a0); +extern void func_80165718(s32 a0); +extern u8 D_800D46E4[]; +extern void func_80151AE4(s32 arg0); +extern void func_80151D24(void *a0); +extern void func_80151DB0(s32 a0); +extern void func_80151D60(void *a0); +extern s32 func_80172630(u8 *a0); +extern s32 D_80062C14; +extern void func_80151DB0(s32 param_1); +extern void func_80151E78(s32 *a0); +extern void func_80151ECC(struct S80151ECC *a0); +extern void func_80151FB4(s32 a0); +extern void func_80151F38(s32 *a0); +extern void func_801553C0(s32 a0); +extern void func_80153C18(); +extern void func_80152058(void *a0); +extern void func_801520DC(s32 a0); +extern void func_80152094(s32 a0); +extern void func_80147324(s32 a0); +extern void func_801520DC(s32 arg0); +extern void func_801470B4(s32 a0); +extern void func_8015369C(s32 a0); +extern void func_80152194(s32 *a0); +extern s32 func_801536DC(s32 a0); +extern void func_8015220C(s32 a0); +extern s32 func_80153800(s32 a0); +extern void func_801522CC(s32 a0); +extern void func_80152254(s32 *a0); +extern void func_80152370(void *a0); +extern void func_801523F4(s32 a0); +extern void func_801523AC(s32 a0); +extern void func_8001382C(s32 a0, void *a1, void *a2); +extern void func_801523F4(s32 arg0); +extern void func_801525F4(int); +extern s32 func_801535F4(void *arg0); +extern void func_8015BF48(s32 *a0); +extern void func_80152500(int param_1); +extern void func_801525F4(s32 a0); +extern void func_80152698(void *a0); +extern void func_80152714(s32 a0); +extern void func_801526D4(s32 a0); +extern void func_80152790(s32 a0); +extern void func_8015282C(void *a0); +extern void func_801528B0(s32 a0); +extern void func_80152868(s32 a0); +extern void func_801528B0(s32 arg0); +extern void func_8015294C(s32 a0); +extern void func_80152A08(s32 a0); +extern void func_80152AC8(s32 a0); +extern void func_80152A50(s32 *a0); +extern void func_80152B6C(void *a0); +extern void func_80152BF0(s32 a0); +extern void func_80152BA8(s32 a0); +extern void func_80152C80(s32 *a0); +extern void func_80152C40(s32 *a0); +extern void func_80152C80(s32* a0); +extern void func_80152D24(void *a0); +extern void func_80152DA8(s32 a0); +extern void func_80152D60(s32 a0); +extern void func_80152DA8(s32 arg0); +extern void func_80152E4C(s32 a0); +extern void func_80152EFC(s32 a0); +extern void func_80152FBC(s32 a0); +extern void func_80152F44(s32 *a0); +extern void func_80153060(void *a0); +extern void func_801530E4(s32 a0); +extern void func_8015309C(s32 a0); +extern void func_80155440(s32 *a0); +extern u8 D_80062C04[]; +extern void func_801530E4(s32 arg0); +extern void func_80153150(struct S80153150 *a0); +extern void func_801531BC(s32 a0); +extern void func_8015327C(s32 a0); +extern void func_80153204(s32 *a0); +extern void func_80153320(void *a0); +extern void func_801533A4(s32 a0); +extern void func_8015335C(s32 a0); +extern void func_80153410(s32 *a0); +extern void func_80153490(s32 a0); +extern void func_80153550(s32 a0); +extern void func_801534D8(s32 *a0); +extern void (*D_8011DB28)(s32 a0); +extern s32 func_801536DC(s32 param_1); +extern void func_800139C8(s32 a0, void *a1, void *a2); +extern s32 func_80153978(s32 a0, u16 *src); +extern s32 func_80133784(s32 a0, void *src, s32 dst); +extern s32 func_801539F8(s32 a0, void *a1); +extern s32 func_801539F8(s32 a0, void * a1); +extern s32 func_8016DA04(s32 a0); +extern s32 func_80153BD8(s32 a0); +extern s32 func_80153BF0(s32 a0); +extern void func_80153C18(void); +extern u16 D_8011F748; +extern void func_80153C30(void); +extern void func_80153C74(s16 a0, s16 a1); +extern s16 D_8011DB18; +extern void func_80153C44(int a0, int a1, s16 a2); +extern s16 D_8011DB0C; +extern s32 D_80115210; +extern void func_80153C8C(void); +extern void func_80153C9C(void); +extern s32 func_80153CBC(void); +extern void func_80153CCC(S80153CCC *a0); +extern void func_80153D7C(s32 a0); +extern void func_80153D34(s32 a0); +extern void func_80153D7C(s32 param_1); +extern void func_8015410C(void); +extern void func_80153E00(s32 param_1); +extern void func_80151664(void); +extern void func_80154134(u8 *a0); +extern void func_80154190(u8 *a0, s32 a1); +extern void func_80154150(s32 a0, s32 a1); +extern void func_80154218(u8 *a0, s32 a1, s32 a2); +extern void func_801541D8(u8 *a0, s32 a1, s32 a2); +extern s32 func_801549F8(s32 a0, s32 a1, s32 a2); +extern void func_801542A4(); +extern void func_801542A4(s32 *a0, s32 a1); +extern void func_8015430C(); +extern void func_8015430C(u8 *arg0, s32 arg1, s32 arg2); +extern void func_8015444C(void *a0, s32 *a1, s32 *a2, s32 *a3); +extern s32 func_80154358(void * arg0); +extern void func_80154AB4(s32 a0, s32 a1); +extern void func_80154B20(s32 a0, s32 a1, s32 a2); +extern void func_80154AE0(s32 a0, s32 a1, s32 a2); +extern void func_80154B7C(u8 *a0, s32 a1); +extern void func_80154B4C(u8 *a0, s32 a1); +extern void func_80154BC8(void *a0, s32 a1, s32 a2); +extern void func_80154B98(void *a0, s32 a1, s32 a2); +extern void func_80154ED8(s32 a0, s32 a1); +extern void func_80154C24(s32 param_1, s32 *param_2, s32 *param_3); +extern u8 D_800D8D10[]; +extern s16 D_80078E9E; +extern void func_801550FC(s32 a0); +extern void func_80154F9C(s32 a0); +extern void func_801550FC(s32 arg0); +extern void func_8001D150(s32, s32); +extern void func_8001D130(int, int); +extern void func_80155150(int param_1); +extern s32 D_800DE2A4[]; +extern void func_801552F4(s32 a0); +extern void func_80155344(s32 a0); +extern s32 func_80155394(s32 *a0); +extern void func_801553A8(s32 *a0); +extern s32 func_80155458(s32 param_1); +extern s32 func_801659DC(u8 *a0); +extern s32 func_801554B8(void *arg0); +extern void func_801555F4(void *a0); +extern void func_80155518(s32 *a0); +extern void func_80155580(void *a0); +extern s32 func_80161104(void); +extern void func_801555F4(void *); +extern void func_801555BC(void *a0); +extern int func_80155A44(int param_1); +extern int func_80161208(); +extern u8 D_800D4DA8[]; +extern void func_80155B20(s32 *a0); +extern s32 D_800D4DB4; +extern void func_80155B9C(s32 a0); +extern u8 D_800D4DD4[]; +extern void func_80155C0C(s32 *a0); +extern void func_8014ED28(s32 a0); +extern int func_80155FF8(int arg, int a1); +extern s32 D_800D4DF4; +extern void func_80155C64(s32 a0); +extern void func_8015E880(s32 *a0); +extern void func_80155D70(s32 param_1); +extern void func_80155E30(void *a0); +extern s32 func_80161208(); +extern void func_80155EA4(void *arg0); +extern void func_80155F58(void); +extern s32 func_80155F80(); +extern s32 func_80155F60(void); +extern s32 func_80155F80(s32 a0); +extern int func_80155FB0(int arg, int a1); +extern int func_80155FD4(int arg, int a1); +extern int func_80156044(int arg, int a1); +extern S801563EC *func_801563EC(u16 idx); +extern s32 func_80029B4C(s32 a0, s32 a1); +extern s32 func_80029BC8(s32 a0, s32 a1); +extern s32 func_80029C44(s32 a0, s32 a1); +extern s32 func_8015640C(s32 a0, s32 a1); +extern u32 func_8015616C(s32 param_1, u16 param_2); +extern u16 func_80156370(u16 param_1); +extern S801563EC * func_801563EC(u16 idx); +extern s32 func_801564B0(s32 a0); +extern s32 D_801151E0[]; +extern s32 func_801565C0(void); +extern void func_80156A14(s32 *a0); +extern void func_80156648(s32 *a0); +extern u8 D_8011DAD8[]; +extern s32 func_8014C568(void *a0); +extern void func_801567BC(s32 a0); +extern B8 D_80128120[]; +extern B8 D_80128138[]; +extern S8 D_80126AF0[]; +extern u8 D_80126730[]; +extern void func_80156848(s32 param_1, s32 param_2); +extern void func_80156A1C(s32 param_1, s32 param_2); +extern s32 D_801150E0[]; +extern void func_80156A88(s32 a0, s32 a1); +extern void func_80156B74(s32 param_1, u32 param_2, u8 *param_3); +extern void func_80156ECC(int param_1, int param_2, int param_3, int param_4, int param_5); +extern void func_80156FA8(s16 *param_1, s16 *param_2, s16 *param_3); +extern void func_80157158(s32 a0, u16 a1, u16 a2, s32 a3, s32 a4, s32 a5, s32 a6, s32 a7, s32 a8, s32 a9, u16 a10, s32 a11, s32 a12); +extern s32 func_80135004(s32 a0, void *a1, s32 a2); +extern s32 func_80135260(s32 a0, s32 a1, s32 a2, s32 a3); +extern u32 func_801571C4(s32 a0, u16 a1, u16 a2, s32 a3, s32 a4, s32 a5, s32 a6, s32 a7, s32 a8, s32 a9, u16 a10, s32 a11, s32 a12); +extern void func_801575E4(void *a0); +extern void func_801574DC(s32 *a0); +extern void func_80157544(void *a0); +extern void func_8014CC28(s32 a0); /* defined */ +extern s32 func_8014F3E8(); /* declared */ +extern void func_8015BDD0(s32 *a0); /* defined */ +extern void func_801575E4(void *a0); /* defined */ +extern void func_80157580(s32 arg0); +extern u8 D_800D4F14[]; +extern void func_801576A8(void *arg0); +extern s32 func_8015773C(u8 *a0); +extern s32 func_8015771C(u8 *a0); +extern s32 func_8015773C(u8 * arg0); +extern void func_801578C0(s32 a0); +extern void func_80157788(int param_1); +extern void func_80157808(s32 a0); +extern void func_801577C8(int param_1); +extern void func_80157880(s32 a0); +extern s32 func_801725A4(u8 *a0); +extern void func_801578C0(s32 param_1); +extern void func_80147A84(int); +extern void func_80148038(int, int); +extern void func_80147460(int); +extern void func_80146D90(int); +extern void func_80161450(void *a0); +extern void func_80157A8C(int); +extern void func_80154A74(int, int); +extern void func_8015795C(int param_1); +extern void func_80161D20(s32 a0, s32 a1); +extern void func_80157A8C(s32 a0); +extern void func_8016706C(s32 a0); +extern u8 D_800D51AC[]; +extern void func_80157AC8(s32 param_1); +extern void func_80157B74(int param_1); +extern void func_8016158C(void *a0); +extern void func_8015BE04(s32 *a0); +extern void func_80157BC8(s32 a0); +extern void func_80157CCC(s32 a0); +extern void func_80157DC4(void *a0); +extern void func_80157FC4(void *a0); +extern void func_80157D74(u16 *a0); +extern void func_80157E38(void *); +extern void func_80157E00(void *a0); +extern void func_80157E38(void * a0); +extern s32 func_80157F64(s32 *a0); +extern s32 func_80156600(void *a0); +extern void func_80157EA4(void *a0); +extern void func_80158038(void *); +extern void func_80158000(void *a0); +extern void func_80158038(void * param); +extern u8 D_800D524C[]; +extern void func_80161418(void *a0); +extern void func_801580B4(s32 a0); +extern void func_801581AC(s32 a0); +extern void func_8015824C(void *a0); +extern void func_801582C0(void *); +extern void func_80158288(void *a0); +extern u8 D_800D52A8[]; +extern void func_801585A4(s32 *a0); +extern void func_801582C0(void *a0); +extern s32 func_801585AC(s32 *a0); +extern u8 D_800D52E8[]; +extern void func_80158344(s32 *a0); +extern s32 func_801615C4(void *a0, s32 a1); +extern void func_80158434(s32 param_1); +extern void func_80158548(s32 param_1); +extern void func_801585EC(u8 *a0); +extern void func_80158794(void); +extern void func_80158880(s32 *param); +extern void func_8015879C(s32 param_1); +extern void func_80158814(void *arg0); +extern int func_800D0CA0(int); +extern int func_8001AAA0(int); +extern int SsGetMute(void); +extern s32 func_80159464(void); +extern void func_801588CC(int param_1); +extern void func_80158AE4(void *a0); +extern void func_80158AB4(void *a0); +extern void func_8016F264(void); +extern void func_80165840(void); +extern void func_801658DC(void); +extern void func_80165A78(s32); +extern void func_80158AE4(void * a0); +extern void func_80158BB0(void *arg0); +extern s32 func_80159404(s32 a0, s32 a1); +extern void func_80158C40(s32 *a0); +extern void func_80158CD8(s32 *a0); +extern s32 func_80159434(s32 a0, s32 a1); +extern void func_80158D60(s32 a0); +extern M2C_UNK D_800D5904; +extern void func_80158E24(s32 *a0); +extern int rand(void); +extern void func_80158F00(int param_1); +extern s32 func_801399F0(s32); +extern void func_80139914(s32); +extern void func_801594E8(s32, s32); +extern void func_80158FA4(s32 param_1); +extern u8 D_80110C94[]; +extern u8 D_80110CD4[]; +extern void func_80159070(void *a0); +extern s32 func_80029A94(s32); +extern void func_80175454(void); +extern void func_800298BC(void *); +extern void func_8002992C(s32); +extern void func_800CF804(void); +extern void func_800CF818(void); +extern u8 D_80110D0C[]; +extern u8 D_80110C3C[]; +extern void func_80159120(s32 a0); +extern void func_801592CC(s32 *a0); +extern void func_8015934C(void *arg0); +extern void func_801593E4(A801593E4 *a0); +extern s32 func_800291B4(s32); +extern void func_80029274(void); +extern void func_80029044(void); +extern void func_8002906C(void); +extern void func_80029094(void); +extern void func_8002941C(void); +extern void func_8002AB64(void); +extern void func_800D185C(u8 *); +extern void func_800D1F90(void); +extern void func_801594E8(s32 param_1, s32 param_2); +extern void func_80159698(void *a0); +extern s32 func_801596D4(void *a0); +extern void func_80174B6C(void); +extern void func_8013C938(void); +extern void func_8002850C(s32, s32, s32); +extern void func_80028620(s32, void *); +extern s32 func_801596F0(s32 param_1); +extern s32 func_80159874(void); +extern void func_800167B8(s32 a0); +extern s32 func_8015987C(s32 a0); +extern int func_800167F0(int arg); +extern int func_801598BC(void); +extern void func_80159968(void *a0); +extern void func_801598E0(u8 *a0); +extern void func_80159A20(void *a0); +extern void func_801599E0(void *a0); +extern void func_80159A18(void); +extern void func_80159BE4(s32); +extern void func_80159B08(s32 *a0); +extern void func_80159B70(void *a0); +extern void func_80159B3C(void * a0); +extern void func_80159BAC(s32 a0); +extern s32 func_80172590(u8 *a0); +extern void func_80159BE4(s32 arg0); +extern void func_8015A1C8(s32 a0); +extern void func_8015A2D8(s32); +extern void func_8015A1FC(s32 *a0); +extern void func_8015A264(void *a0); +extern void func_8015A230(s32 *a0); +extern void func_8015A2A0(s32 a0); +extern s32 func_80172608(u8 *a0); +extern void func_8015A2D8(s32 param_1); +extern u8 D_800D48DC; +extern s32 func_8015AB7C(s32 a0); +extern s32 D_8011F9C4; +extern s32 func_8015ABD4(s32 a0, s32 a1, s32 a2); +extern s32 func_80161CD0(s32 a0, s32 a1); +extern void func_8015AC48(s32 arg0); +extern void func_8015AC90(s32 a0); +extern void func_8015ADB0(s32 a0); +extern void func_8015ACC4(s32 *arg0); +extern void func_8015AD3C(void *a0); +extern void func_8015AD08(void *arg0); +extern void func_8015ADB0(s32); +extern void func_8015AD78(s32 a0); +extern void func_8015ADB0(s32 arg0); +extern s32 D_800D4A9C; +extern int func_8015B6F4(int param_1); +extern u8 D_800D4F8C[]; +extern s32 func_8015B7B4(s32 a0); +extern u8 D_800D4BE0[]; +extern s32 func_8014A51C(); +extern s32 func_8015B858(u8 *a0); +extern s32 D_800D4B48; +extern void func_8015B8F8(s32 *a0); +/* ==== end §8b carried decl layer ==== */ + + +extern s32 func_8015AE2C(); + +// @class: plumbing +// @stuck: none — MATCH (271/271, pin-free, zero asm). The ONLY residual is DEF-SIDE plumbing, and it is now named exactly: the in-TU instantiation `DEFINE_func_8015BEE4()` (engine_core.h:1851-1855) expands to `extern s32 func_8015B950(void);` INSIDE ov_SC01_077_jr_8015AE2C.c, ~14 lines BELOW this definition, so the 1-param def collides with a `(void)` prototype -> `conflicting types for func_8015B950` (.run/bank_func_8015B950.log). §73 PARAMS axis / T0. Surgical fix = §65b de-macroize that ONE instantiation (blast radius: this TU); the fleet-wide `(void)`->`()` header edit is §63 and must be R22-validated. +/* func_8015B950 (ov_SC01_077_jr_8015AE2C, 271 ins, jtbl_801D8B74) — SESSION-21 re-verified + * + * ── ROUND-2 INDEPENDENT RE-VERIFICATION (2026-07-27, fresh agent, §88e discipline) ───────────── + * match_one : MATCH (271 ins) against the CURRENT tree — §87 staleness re-checked today. + * .text size: compiled .text = 0x43C = 1084 B = 271 ins, EXACTLY the target's declared 0x43C + * ("nonmatching func_8015B950, 0x43C"). So this is NOT a §83a length drift hiding + * behind a zero count — the count is over equal-length streams. + * jtbl : RE-DECODED MECHANICALLY, not inherited. Compiled .rodata = 0x1C = 28 B = 7 words, + * 7x R_MIPS_32 -> .text with implicit addends [58,58,58,E0,F0,100,58]; +0x8015B950 + * = [8015B9A8, 8015B9A8, 8015B9A8, 8015BA30, 8015BA40, 8015BA50, 8015B9A8]. + * Diffed word-for-word against asm/ov_SC01_077/data/tail14.data.s:15-23 — 7/7 identical. + * symcheck : SYMS-DIFF target=35 draft=34, sole MISSING = jtbl_801D8B74. This is the §81 jr + * FALSE POSITIVE, re-confirmed here by reading the relocs: gcc emits its OWN table and + * references it with R_MIPS_HI16/LO16 against the SECTION `.rodata` (t.o +0x40/+0x48), + * so the splat's dlabel NAME can never appear in the draft object's relocation set. + * Nothing is dropped and nothing is invented: the draft's other 34 symbols are exactly + * the target's other 34. + * FAMILY : the x138 remap is clean and §84-safe. Every sibling is 271 ins with an IDENTICAL + * callee set; only THREE names vary per overlay — the two data labels and the jtbl: + * ov_SC01_077 D_8018CA3C / D_8018CAA8 / jtbl_801D8B74 + * ov_SC03_099 D_80185A50 / D_80185ABC / jtbl_801BD898 + * ov_SC06_008 D_80187E44 / D_80187EB0 / jtbl_801A8734 + * The pair is always +0x6C apart, and NO literal in this draft encodes that distance + * (both labels are referenced by name), so there is no §84 derived-offset hazard. + * D_8011F9C4 is fleet-constant (main-EXE data) and must NOT be remapped. + * + * match_one: MATCH (271 ins) against the CURRENT tree (§87 staleness re-checked, 2026-07-27). + * PIN-FREE, zero asm, offset-pure (s32 arg0 + raw offsets) — x138 template-safe. + * Provenance: this is the Phase-26 crack (.run/phase26-cracks/func_8015B950.c) re-gated verbatim, + * with ONE deliberate change: the definition's return type void -> s32. + * - `void func_8015B950(s32 arg0)` : MATCH (271 ins) [the Phase-26 form] + * - `s32 func_8015B950(s32 arg0)` : MATCH (271 ins) [shipped — §3a-1 void->s32 is byte-neutral] + * The fleet/engine_core.h canonical decl is `extern s32 func_8015B950(void);` (engine_core.h:1852), + * and the last bank attempt (.run/bank_func_8015B950.log) died on `conflicting types for + * func_8015B950`. Shipping the s32 return kills the §73 RETURN axis for free and leaves only the + * cheap T0 PARAMS axis for the ladder (fix_header_decl.py / --fix-def-sig / cast_call_sites). + * Both forms are byte-identical, so the orchestrator may swap the return type back at zero cost. + * + * SYMBOLS (§58 rules 1/2 — all splat spellings, all verified present): + * D_8018CAA8 asm/ov_SC01_077/data/tail.data.s:4355 (the state-handler vtable) + * D_8018CA3C asm/ov_SC01_077/data/tail.data.s:4293 + * D_8011F9C4 main-EXE data; spelled `extern s32 D_8011F9C4;` in 5+ already-banked TUs + * jtbl_801D8B74 asm/ov_SC01_077/data/tail14.data.s:15 (compiler jump table — not named in C) + * + * JTBL VERIFIED (§8a gate): compiled .rodata = exactly 0x1C B / 7 words, 7x R_MIPS_32 .text with + * addends [0x58,0x58,0x58,0xE0,0xF0,0x100,0x58] -> +0x8015B950 = [B9A8,B9A8,B9A8,BA30,BA40,BA50, + * B9A8] == the original words at 0x801D8B74..0x801D8B8C. Bound `sltiu $v0,$v1,0x7` matches. + * The raw dlabel's 8th word 0x00000000 is NOT an entry — it is the intra-TU `.align 3` pad of the + * B34/B54/B74 jtbl chain; the object can never emit it (maspsx drops .align), so it must stay in + * the post-carve RAW data piece (the §53/§62/§81 carve chain applies at bank time). + * + * Same family as the TU's own already-matched func_8015AE2C: 7-case switch on ((s32 (*)(s32))func_801619A4)() + * (0/1/2/6 shared, 3/4/5 own, no default block — out-of-range and every `break` fall to the + * after-switch join), then a chain of "state handler" tests, each dispatching + * D_8018CAA8[*(u16*)arg0](arg0) and returning. + * + * THREE LEVERS (draft -> MATCH in 3 compiles): + * + * 1. PROLOGUE CONSTANT = an INITIALIZED LOCAL, not a literal in the compare. + * Target opens with `lui $s2, 0xFFF5` in the *prologue*, used once ~200 ins later in + * `slt $v0,$s2,$s1`. No gcc-2.7.2 pass hoists a (set reg const_int) across basic blocks + * (loop.c needs a loop; cse/combine/sched never move insns between BBs) — so the insn must + * have been EMITTED in the first BB, i.e. the constant is a local initialized at the top of + * the function. cse then cannot fold it back into the compare: the `slt` operand predicate is + * `arith_operand`, which rejects a CONST_INT wider than 16 bits, so validate_change fails and + * the pseudo survives. Its live range spans every call -> global.c gives it a callee-saved reg. + * Writing `z > -0xB0000` inline instead emits the `lui` into the branch delay slot next to the + * compare (caller-saved $v0) and the function is 1 insn short. => `s32 lim = -0xB0000;` at top. + * + * 2. `lh` vs `lhu`: a short->short copy is a pure HImode move and gcc emits `lhu`. The target's + * `lh $v0,0x26($s0)` means the value passed through an SImode (int) temp: expand makes + * (set (reg:SI) (sign_extend (mem:HI))) + (set (mem:HI) (subreg:HI ...)), and combine cannot + * merge them (the merged form is mem<-mem, which no movhi accepts) so the sign-extending load + * survives. => route both halfword copies through the `s32 t` temp. + * + * 3. THE `goto` LAYOUT — dodging jump.c's store-flag conversion (jump.c:1005-1065). + * An if/else chain writing 0/1 into `doit` makes gcc collapse the last pair into + * `sltiu $v0,$v0,1`. jump.c fires that conversion when the insn immediately after a + * conditional jump is a lone `SET pseudo, CONST_INT` whose following simplejump targets the + * SAME label as the branch (jump.c:1038 `reallabelprev == temp || ... JUMP_LABEL(temp4) == + * JUMP_LABEL(insn)`) — exactly the shape of `if (c) x=0; else x=1;`. + * The target instead cross-jumps ALL the `doit=0` exits into ONE shared block placed after the + * `doit=1` fall-through; reorg's fill_slots_from_thread then COPIES that single set into all + * three branch delay slots and redirects each branch past it (which is why `addu $v0,$zero, + * $zero` appears 3x in delay slots and the shared block vanishes). A `goto zero;` / `goto one;` + * chain expresses that layout directly, and each conditional jump is then followed by a + * compare/call rather than a lone const set, so the store-flag conversion never triggers. + * GENERAL RULE: multiple predicates that all assign the SAME constant to one flag => write + * them as `goto` to a shared assignment, never as an if/else ladder. + */ +extern s32 D_8011F9C4; + +extern s32 func_80161B18(void); +extern s32 func_801619A4(s32*); +extern s32 func_80149AA8(s32*); +extern void func_80149AD4(s32*); +extern s32 func_80149B54(s32*); +extern void func_80149BAC(s32*); +extern s32 func_801498E0(s32*); +extern s32 func_80149954(s32); +extern s32 func_80149A64(s32*); +extern void func_800CCCC0(s32 a0); +extern s32 func_80149CD4(s32 a0); +extern void func_8015E880(s32*); +extern s32 func_80149744(struct S_80149744*); +extern void func_80149788(void); +extern s32 func_801496D4(void*); +extern void func_80149704(void); +extern int func_80148AFC(void*); +extern void func_80146D90(s32 a0); +extern void func_80154150(s32 a0, s32 a1); +extern void func_801541D8(u8*, s32, s32); +extern s32 func_801488A8(u8*); +extern void func_80147078(s32*, s16); +extern void func_8015A264(void*); +extern s32 func_80013294(void*, void*); +extern void func_80159B70(void*); +extern s32 func_8016F1AC(void); +extern s32 func_80029178(s32 a0); +extern void func_80146DB8(s32*, s32*); +extern s32 func_80161CD0(s32, s32); +extern s32 func_80161208(s32 a0); +extern s32 func_801725A4(u8*); + +s32 func_8015B950(s32 arg0) +{ + + extern void (*D_8018CAA8[])(void *); + extern s32 D_8018CA3C; + s16 sp10[4]; + s16 sp18[4]; + s32 t; + s32 z; + s32 doit; + s32 lim = -0xB0000; + + if (func_80161B18() != 0) { + return; + } + switch (((s32 (*)(s32))func_801619A4)(arg0)) { + case 0: + case 1: + case 2: + case 6: + if (((s32 (*)(s32))func_80149AA8)(arg0) != 0) { + D_8018CAA8[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149AD4)(arg0); + return; + } + if (((s32 (*)(s32))func_80149B54)(arg0) != 0) { + D_8018CAA8[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149BAC)(arg0); + return; + } + break; + case 3: + ((void (*)(s32))func_801498E0)(arg0); + break; + case 4: + ((void (*)(s32))func_80149954)(arg0); + break; + case 5: + if (((s32 (*)(s32))func_80149A64)(arg0) != 0) { + D_8018CAA8[*(u16 *)arg0]((void *)arg0); + func_800CCCC0(arg0); + return; + } + break; + } + if (func_80149CD4(arg0) != 0) { + D_8018CAA8[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_8015E880)(arg0); + return; + } + if (((s32 (*)(s32))func_80149744)(arg0) != 0) { + D_8018CAA8[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149788)(arg0); + return; + } + if (((s32 (*)(s32))func_801496D4)(arg0) != 0) { + D_8018CAA8[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149704)(arg0); + if (((u8)((s32 (*)(s32))func_80148AFC)(arg0)) == 0) { + func_80146D90(arg0); + } + if ((*(s32 *)(arg0 + 0x24) | *(s32 *)(arg0 + 0x2C)) != 0) { + func_80154150(arg0, 0xF); + } else { + ((void (*)(s32, s32, s32))func_801541D8)(arg0, 0xD, 6); + } + *(s32 *)(arg0 + 0x238) = 1; + return; + } + if (((s32 (*)(s32))func_801488A8)(arg0) != 0) { + sp10[0] = 0; + sp10[1] = 0; + sp10[2] = 0; + t = *(s16 *)(arg0 + 0x26); + sp18[0] = t; + sp18[1] = 0; + t = *(s16 *)(arg0 + 0x2E); + sp18[2] = t; + D_8018CAA8[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 1); + ((void (*)(s32))func_8015A264)(arg0); + t = -(((s32 (*)(s16 *, s16 *))func_80013294)(sp10, sp18) << 0x10); + if (t < *(s32 *)(arg0 + 0x2C)) { + *(s32 *)(arg0 + 0x2C) = t; + } + return; + } + if (*(u16 *)(arg0 + 0xB8) == 0x8000) { + D_8018CAA8[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 0); + ((void (*)(s32))func_80159B70)(arg0); + return; + } + z = *(s32 *)(arg0 + 0x2C); + if (func_8016F1AC() != 0) { + goto zero; + } + if (z <= lim) { + goto one; + } + if (D_8011F9C4 == 0) { + goto zero; + } + if (((u8)func_80029178(0x21)) != 0) { + goto zero; + } +one: + doit = 1; + goto join; +zero: + doit = 0; +join: + if (doit != 0) { + D_8018CAA8[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 0); + ((void (*)(s32))func_80159B70)(arg0); + func_80154150(arg0, 9); + ((void (*)(s32, s32 *))func_80146DB8)(arg0, &D_8018CA3C); + ((void (*)(s32, s32))func_80161CD0)(arg0, *(u16 *)(arg0 + 0x16E)); + return; + } + if (func_80161208(arg0) == 0) { + ((void (*)(s32))func_801725A4)(arg0); + } +} + +DEFINE_func_8015BD8C() /* dedup: shared engine-core @0x8015bd8c (src/shared) */ + + +DEFINE_func_8015BDD0() /* dedup: shared engine-core @0x8015bdd0 (src/shared) */ + + +DEFINE_func_8015BE04() /* dedup: shared engine-core @0x8015be04 (src/shared) */ + + + + +void func_8015BE38(struct Obj *a0) { + + extern void (*D_8018CC1C[])(void); + D_8018CC1C[*(u16 *)((s32)a0 + 0x2)](); +} + + +DEFINE_func_8015BE74() /* dedup: shared engine-core @0x8015be74 (src/shared) */ + + +DEFINE_func_8015BE94() /* dedup: shared engine-core @0x8015be94 (src/shared) */ + + +DEFINE_func_8015BEC4() /* dedup: shared engine-core @0x8015bec4 (src/shared) */ + + +DEFINE_func_8015BEE4() /* dedup: shared engine-core @0x8015bee4 (src/shared) */ + + +DEFINE_func_8015BF04() /* dedup: shared engine-core @0x8015bf04 (src/shared) */ + + +DEFINE_func_8015BF48() /* dedup: shared engine-core @0x8015bf48 (src/shared) */ + + +DEFINE_func_8015BF7C() /* dedup: shared engine-core @0x8015bf7c (src/shared) */ + + +DEFINE_func_8015BFB0() /* dedup: shared engine-core @0x8015bfb0 (src/shared) */ + + + + +void func_8015BFF4(void *a0) { + + extern void (*D_8018CC28[])(void); + D_8018CC28[*(u16 *)((s32)a0 + 0x2)](); +} + + +INCLUDE_ASM("asm/ov_SC07_006/nonmatchings/ov_SC07_006_jr_8015B950", func_8015C030); + +DEFINE_func_8015C08C() /* dedup: shared engine-core @0x8015c08c (src/shared) */ + + +DEFINE_func_8015C0C4() /* dedup: shared engine-core @0x8015c0c4 (src/shared) */ + + +extern void func_8001382C(s32 a0, void *a1, void *a2); +extern void func_80146CA0(void *a0); +extern void func_80146DB8(s32 *a0, s32 *a1); +extern void func_80146E90(s32 *a0, s32 a1); +extern s32 func_80146E98(s32 a0); +extern void func_80147078(s32 *a0, s16 a1); +extern void func_80147324(s32 a0); +extern void func_801473EC(s32 *a0); +extern void func_80147A84(s32 arg0); +extern int func_80148AFC(void *a0); +extern s32 func_80149FB0(s32 a0); +extern void func_8014C010(s32 a0, s32 a1); +extern void func_8014CC28(s32 a0); +extern void func_8014D738(void); +extern s32 func_8014F3E8(); +extern s32 func_8015BE94(); +extern void func_8015C0C4(s32 a0); + + + +s32 func_8015C128(s32 param_1) { + + extern u16 D_800B99DA; + extern void func_8015C6E0(int); + extern void (*D_8018CAA8[])(int); + + int sp10[3]; + int sp20[3]; + int temp_s0; + int temp_v0; + + ((void(*)())func_80149FB0)(); + if (((int(*)(int))func_80148AFC)(((int)param_1)) & 0xFF) { + sp10[0] = 0; + sp10[1] = 0; + sp10[2] = -0x4000; + ((void(*)(int, int *, int *))func_8001382C)(*(short *)(*(int *)(((int)param_1) + 0x20) + 0x12), sp10, sp20); + *(int *)(((int)param_1) + 0x234) += sp20[0]; + *(int *)(((int)param_1) + 0x238) += sp20[1]; + *(int *)(((int)param_1) + 0x23C) += sp20[2]; + } + ((void(*)(int, int *, int *))func_8001382C)((short)(-*(unsigned short *)(*(int *)(((int)param_1) + 0x20) + 0x12)), + (int *)(((int)param_1) + 0x234), sp20); + ((void(*)(int, int *))func_80146DB8)(((int)param_1), sp20); + func_80147A84(((int)param_1)); + ((void(*)(int))func_801473EC)(((int)param_1)); + if (!(D_800B99DA & 3)) { + ((void(*)(int, int))func_8014C010)(((int)param_1), 1); + ((void(*)(int))func_80147324)(0x65F); + } + if (((int(*)(int))func_8014D738)(((int)param_1)) != 0) { + D_8018CAA8[*(u16 *)((int)param_1)](((int)param_1)); + func_8015C6E0(((int)param_1)); + return; + } + temp_s0 = ((int(*)(int))func_8014CC28)(((int)param_1)); + temp_v0 = ((int(*)(int))func_8014F3E8)(((int)param_1)); + if (temp_v0 != 0) { + if ((temp_v0 & 0xFF00) != 0x4000) { + ((void(*)(int, int))func_80146E90)(((int)param_1), 6); + ((void(*)(int))func_80146CA0)(((int)param_1)); + return; + } + if ((temp_v0 & 0x4000) && ((int(*)(int))func_80146E98)(((int)param_1)) != 0) { + ((void(*)(int, int))func_80147078)(((int)param_1), 4); + ((void(*)(int))func_8015C0C4)(((int)param_1)); + } + } else if (temp_s0 == 0) { + D_8018CAA8[*(u16 *)((int)param_1)](((int)param_1)); + ((void(*)(int, int))func_80147078)(((int)param_1), 3); + ((void(*)(int))func_8015BE94)(((int)param_1)); + } +} + + + diff --git a/src/ov_SC07_007/ov_SC07_007_jr_801588CC.c b/src/ov_SC07_007/ov_SC07_007_jr_801588CC.c index 8108d7c3e..9723c303f 100644 --- a/src/ov_SC07_007/ov_SC07_007_jr_801588CC.c +++ b/src/ov_SC07_007/ov_SC07_007_jr_801588CC.c @@ -2588,141 +2588,3 @@ DEFINE_func_8015B858() /* dedup: shared engine-core @0x8015b858 (src/shared) */ DEFINE_func_8015B8F8() /* dedup: shared engine-core @0x8015b8f8 (src/shared) */ - - -INCLUDE_ASM("asm/ov_SC07_007/nonmatchings/ov_SC07_007_jr_801588CC", func_8015B950); - -DEFINE_func_8015BD8C() /* dedup: shared engine-core @0x8015bd8c (src/shared) */ - - -DEFINE_func_8015BDD0() /* dedup: shared engine-core @0x8015bdd0 (src/shared) */ - - -DEFINE_func_8015BE04() /* dedup: shared engine-core @0x8015be04 (src/shared) */ - - - - -void func_8015BE38(struct Obj *a0) { - - extern void (*D_80185740[])(void); - D_80185740[*(u16 *)((s32)a0 + 0x2)](); -} - - -DEFINE_func_8015BE74() /* dedup: shared engine-core @0x8015be74 (src/shared) */ - - -DEFINE_func_8015BE94() /* dedup: shared engine-core @0x8015be94 (src/shared) */ - - -DEFINE_func_8015BEC4() /* dedup: shared engine-core @0x8015bec4 (src/shared) */ - - -DEFINE_func_8015BEE4() /* dedup: shared engine-core @0x8015bee4 (src/shared) */ - - -DEFINE_func_8015BF04() /* dedup: shared engine-core @0x8015bf04 (src/shared) */ - - -DEFINE_func_8015BF48() /* dedup: shared engine-core @0x8015bf48 (src/shared) */ - - -DEFINE_func_8015BF7C() /* dedup: shared engine-core @0x8015bf7c (src/shared) */ - - -DEFINE_func_8015BFB0() /* dedup: shared engine-core @0x8015bfb0 (src/shared) */ - - - - -void func_8015BFF4(void *a0) { - - extern void (*D_8018574C[])(void); - D_8018574C[*(u16 *)((s32)a0 + 0x2)](); -} - - -INCLUDE_ASM("asm/ov_SC07_007/nonmatchings/ov_SC07_007_jr_801588CC", func_8015C030); - -DEFINE_func_8015C08C() /* dedup: shared engine-core @0x8015c08c (src/shared) */ - - -DEFINE_func_8015C0C4() /* dedup: shared engine-core @0x8015c0c4 (src/shared) */ - - -extern void func_8001382C(s32 a0, void *a1, void *a2); -extern void func_80146CA0(void *a0); -extern void func_80146DB8(s32 *a0, s32 *a1); -extern void func_80146E90(s32 *a0, s32 a1); -extern s32 func_80146E98(s32 a0); -extern void func_80147078(s32 *a0, s16 a1); -extern void func_80147324(s32 a0); -extern void func_801473EC(s32 *a0); -extern void func_80147A84(s32 arg0); -extern int func_80148AFC(void *a0); -extern s32 func_80149FB0(s32 a0); -extern void func_8014C010(s32 a0, s32 a1); -extern void func_8014CC28(s32 a0); -extern void func_8014D738(void); -extern s32 func_8014F3E8(s32 a0); -extern s32 func_8015BE94(); -extern void func_8015C0C4(s32 a0); - - - -s32 func_8015C128(s32 param_1) { - - extern u16 D_800B99DA; - extern void func_8015C6E0(int); - extern void (*D_801855CC[])(int); - - int sp10[3]; - int sp20[3]; - int temp_s0; - int temp_v0; - - ((void(*)())func_80149FB0)(); - if (((int(*)(int))func_80148AFC)(((int)param_1)) & 0xFF) { - sp10[0] = 0; - sp10[1] = 0; - sp10[2] = -0x4000; - ((void(*)(int, int *, int *))func_8001382C)(*(short *)(*(int *)(((int)param_1) + 0x20) + 0x12), sp10, sp20); - *(int *)(((int)param_1) + 0x234) += sp20[0]; - *(int *)(((int)param_1) + 0x238) += sp20[1]; - *(int *)(((int)param_1) + 0x23C) += sp20[2]; - } - ((void(*)(int, int *, int *))func_8001382C)((short)(-*(unsigned short *)(*(int *)(((int)param_1) + 0x20) + 0x12)), - (int *)(((int)param_1) + 0x234), sp20); - ((void(*)(int, int *))func_80146DB8)(((int)param_1), sp20); - func_80147A84(((int)param_1)); - ((void(*)(int))func_801473EC)(((int)param_1)); - if (!(D_800B99DA & 3)) { - ((void(*)(int, int))func_8014C010)(((int)param_1), 1); - ((void(*)(int))func_80147324)(0x65F); - } - if (((int(*)(int))func_8014D738)(((int)param_1)) != 0) { - D_801855CC[*(u16 *)((int)param_1)](((int)param_1)); - func_8015C6E0(((int)param_1)); - return; - } - temp_s0 = ((int(*)(int))func_8014CC28)(((int)param_1)); - temp_v0 = ((int(*)(int))func_8014F3E8)(((int)param_1)); - if (temp_v0 != 0) { - if ((temp_v0 & 0xFF00) != 0x4000) { - ((void(*)(int, int))func_80146E90)(((int)param_1), 6); - ((void(*)(int))func_80146CA0)(((int)param_1)); - return; - } - if ((temp_v0 & 0x4000) && ((int(*)(int))func_80146E98)(((int)param_1)) != 0) { - ((void(*)(int, int))func_80147078)(((int)param_1), 4); - ((void(*)(int))func_8015C0C4)(((int)param_1)); - } - } else if (temp_s0 == 0) { - D_801855CC[*(u16 *)((int)param_1)](((int)param_1)); - ((void(*)(int, int))func_80147078)(((int)param_1), 3); - ((void(*)(int))func_8015BE94)(((int)param_1)); - } -} - - diff --git a/src/ov_SC07_007/ov_SC07_007_jr_8015B950.c b/src/ov_SC07_007/ov_SC07_007_jr_8015B950.c new file mode 100644 index 000000000..d7769ecf3 --- /dev/null +++ b/src/ov_SC07_007/ov_SC07_007_jr_8015B950.c @@ -0,0 +1,2425 @@ +#include "common.h" +#include "../shared/engine_core.h" + +/* ==== Phase-26 §8b carried decl layer (jr_isolate_all.py) =================== + * The file-scope decl environment from earlier code regions of this object — + * file-local types, col-0 decls, DEFINE_func macro externs, and each earlier + * definition's implied prototype (types first, then decls in original order). + * Decls emit no code => byte-neutral. See cookbook §8c. */ +extern void func_80128288(void); +extern void func_80128158(void); +extern void func_801285E4(void); +extern void func_80128178(void); +extern void func_80128678(void); +extern void func_80128198(void); +extern void func_80128714(void); +extern void func_801281B8(void); +extern void func_8013E67C(void); +extern void func_801281D8(void); +extern void func_8013E558(void); +extern void func_801281F8(void); +extern s32 func_80128218(void); +extern void func_80128A28(void); +extern void func_80128228(void); +extern void func_80128AF4(void); +extern void func_80128248(void); +extern void func_801282EC(void); +extern void func_80128268(void); +extern void func_80011B7C(int); +extern void func_801282CC(void); +extern void func_8001C0C8(void); +extern void func_80015310(void); +extern void func_80129258(void); +extern void func_801378F0(void); +extern void func_80010E14(void); +extern s16 currentLocationId; +extern s32 func_80029504(void); +extern s32 func_800CF854(s32); +extern s32 func_80128998(void); +extern s32 func_801289F0(void); +extern s32 func_801288E8(s32); +extern s32 func_80128940(s32); +extern s32 func_80029178(s32); +extern s32 func_801288B0(void); +extern void func_80011C10(void); +extern void func_8012832C(void); +extern void func_80129220(void); +extern void func_80011E24(void); +extern void func_80128C14(void); +extern void func_8002AEF8(void); +extern void func_800CFBBC(void); +extern void SsUtReverbOff(void); +extern void func_8013C98C(void); +extern void func_80129C40(s32 a0); +extern void func_800D0630(void); +extern void func_80145CEC(void); +extern void func_80144B9C(void); +extern u8 D_800B9A17; +extern u8 D_800B9A10; +extern void func_80128420(void); +extern s32 func_800D0588(void); +extern void func_801284B8(void); +extern void func_80175308(void); +extern void func_8016E8F0(void); +extern void func_80175494(void); +extern u8 D_800B9A64; +extern void func_801284F0(void); +extern void func_80146074(void); +extern void func_8012853C(void); +extern void func_80178608(void); +extern void func_8002D4C8(s32 a0, s32 a1); +extern s32 func_80011A3C(void); +extern short currentLocationId; +extern short D_800B99F2; +extern void func_80128564(void); +extern u8 D_800B9A11; +extern void func_801285D4(void); +extern s32 func_800D18DC(void); +extern void func_8014607C(void); +extern void func_801287B8(void); +extern void func_80029444(void); +extern void func_800D1754(void); +extern void func_8014ED28(s32 _arg0); +extern void func_8001ABBC(s32 a0, s32 a1, void *a2, s32 a3, s32 sp10); +extern int func_801288E8(int arg0); +extern int func_80128940(int arg0); +extern void func_80010AE0(s32 a0); +extern void func_80018450(s32 a0, s32 a1); +extern void func_800183E0(s32 a0); +extern void func_80128D60(s32 a0, s32 *a1, s32 *a2); +extern s32 func_80128DB4(s32 a0, s32 *a1); +extern void func_80128EA8(s32 a0, s32 a1, s32 a2); +extern s32 func_80128ED8(s32 param_1, s32 *param_2); +extern void func_80128FAC(u16 *arg0); +extern s16 D_8011DB2C; +extern s16 D_8011DB30; +extern s32 D_80126AEC; +extern void func_80129010(void); +extern u8 *func_8012913C(s32 a0); +extern u8 * func_801290DC(s32 a0, u8 *a1); +extern void func_8001D074(s32 a, s32 b); +extern u8 *func_801291C0(void); +extern s32 func_8001CC3C(s32 a0, s32 a1, s32 a2, s32 a3); +extern u8 * func_8012913C(s32 arg0); +extern void func_80016714(void *a0, s32 a1); +extern u8 * func_801291C0(void); +extern void func_80129248(s16 a0); +extern void func_801292C8(u8 *a0); +extern void func_8012927C(void); +extern void func_8012931C(struct vec *a0); +extern void func_80129350(s32 a0, s32 a1); +extern void func_80129374(s32 a0, s32 a1); +extern s16 D_800B9AAC[]; +extern s16 D_800B9AAE[]; +extern s16 D_800B9AB0[]; +extern s16 D_800B9AB2[]; +extern s16 D_800B9AB4[]; +extern s16 D_800B9AB6[]; +extern s16 D_800B9AB8[]; +extern s16 D_800B9ABA[]; +extern void func_80129398(void); +extern s16 D_80114EE0; +extern void func_80129428(void); +extern void func_8012943C(void); +extern s32 D_8005128C; +extern u8 D_800B9A78; +extern void func_801298F4(void *arg0); +extern void func_801299C8(s32 a, s32 b, s32 c); +extern void func_8012944C(void); +extern unsigned short D_800B99F0; +extern struct BigCopy D_80126DB8; +extern u8 D_80126948[]; +extern struct BigCopy D_80114EE8; +extern s32 D_80126E60[]; +extern s8 D_801150D6; +extern s8 D_801152C0; +extern u8 D_80127504; +extern void func_800144D4(void); +extern void func_80129C40(s32 _arg0); +extern void func_8012A328(void); +extern void func_80053308(s32); +extern s32 func_80012F74(s32, s32, s32, s32); /* canonical s32 (engine_core); (s16)-cast the return for the sll/sra */ +extern void GsSetRefView2L(void *); +extern s8 D_801150D6; /* canonical (engine_core macro): s8 — access via *(u8*)& for lbu */ +extern s32 D_80126F04[]; +extern u8 D_80126948[]; /* canonical (sibling): u8[] — cast (s32*) at use */ +extern s32 D_80126FA8[]; +extern struct BigCopy D_80126DB8;/* canonical (engine_core macro): struct BigCopy — (s32*)& at use */ +extern u8 D_800AF630[]; /* canonical (sibling): u8[] — cast (s32*) at use */ +extern s32 D_800AE688[]; +extern s32 D_801151D4; /* canonical (10 siblings): scalar s32 — store (s32)ptr */ +extern void func_80129CF8(void); +extern void func_8012A018(s32 a, s32 b); +extern void func_80129FF4(void); +extern void func_8012A048(void *a0, s32 a1, u8 a2); +extern void func_8012A018(s32 a0, s32 a1); +extern u16 D_80126B5E; +extern u16 D_80126B62; +extern u16 D_80126B66; +extern s16 D_80126940; +extern s16 D_80126942; +extern s16 D_80126944; +extern void *memcpy(void *, const void *, unsigned int); +extern void func_8012A094(s32 a0); +extern void func_8012A100(s8 a0); +extern void func_8012A0E0(void); +extern s32 D_80120204; +extern s32 D_80120200; +extern s32 D_8012020C; +extern s32 D_80120208; +extern s16 D_80120218; +extern s16 D_80120210; +extern s16 D_8012021A; +extern s16 D_80120212; +extern s16 D_8012021C; +extern s16 D_80120214; +extern s16 D_80120226; +extern s16 D_80120220; +extern s16 D_80120228; +extern s16 D_80120222; +extern s16 D_8012022A; +extern s16 D_80120224; +extern s32 D_80120294; +extern s16 D_80120298; +extern s16 D_8012029A; +extern void func_8012A110(void); +extern void func_8012A2F4(void); +extern s16 D_80127080; +extern s16 D_801152C2; +extern void func_8012A304(s32 a0, s32 a1); +extern void func_8012A464(void); +extern s32 D_801151D4; +extern void func_8012A4BC(void); +extern void func_8012A598(void *a0); +extern void func_8012A568(void (*a0)(void)); +extern void func_8012A62C(s32); +extern void func_8012A5F8(void (*a0)(void), s32 a1); +extern void func_8012A62C(s32 a0); +extern void func_8012A7D4(void *a0, void *a1); +extern s32 func_8012A6D0(void *a0, void *a1); +extern s16 func_8012A68C(void); +extern s32 func_80047D3C(s32 a0); +extern s32 ratan2(s32 a0, s32 a1); +extern s32 func_8012A6D0(void* a0, void* a1); +extern s16 func_8012A79C(s16 *a0, s16 *a1); +extern s16 func_8012A758(void); +extern void func_8012A7D4(void *arg0, void *arg1); +extern void func_8012AAAC(); +extern void func_8012A828(s32 a0, void * a1); +extern int func_8012ACE0(void *a0); +extern void func_8012A860(void *a0, int a1); +extern void func_8012A8B0(u8 *a0, s32 a1); +extern void func_8012A8E8(void); +extern u8 D_801202A0[]; +extern u16 D_801270C0; +extern void func_8012A988(u8 *a0); +extern void func_8012A908(void); +extern s32 func_8012ACE0(void *a0); +extern void func_8012ACA0(void *arg0); +extern void func_8012AD44(s32 *a0, s16 a1); +extern s32 func_8012AD50(void * arg0); +extern void func_8012AD64(s32 *a0, s16 a1); +extern void func_8012AD6C(void *a0); +extern void func_8012AD80(s32 a0); +extern void func_8012ADE4(u8 *a0); +extern s32 *D_80126B78; +extern s32 *D_80126B90; +extern s32 D_80126B58; +extern s32 func_80135888(s32 a0, s32 a1, s32 a2, s32 a3); +extern s32 func_80013478(s32 a0, s32 a1); +extern s32 func_8012AE00(s32 a0); +extern s32 func_8012AF0C(s32 a0, s32 a1); +extern s32 func_80134510(s32 arg); +extern s32 func_8012B030(u8 *a0); +extern int func_80047948(int a0); +extern int func_8004787C(int a0); +extern void func_8012B0B4(unsigned int *param_1, int param_2, int param_3); +extern void func_800484EC(s32 a0, s32 a1, s32 a2); +extern void func_8012B14C(s32 a0, s32 a1); +extern void func_8012B178(s32 a0, s32 a1); +extern void func_8012B1B4(s32 a0, s32 a1); +extern void func_8012B200(u8 *a0); +extern void func_8012B21C(void *a0); +extern void func_8012B23C(s32 a0); +extern void func_8012B260(u8 *a0); +extern void func_80049CAC(s32 a0, s32 a1); +extern void func_8012B2CC(s32 a0); +extern void RotMatrixYXZ(void *m, void *p); +extern void func_8012B370(int a0); +extern void func_8004978C(s16 *a0, void *a1); +extern void func_8012B414(int a0); +extern s32 func_8012B608(s32 a0, s32 a1, s32 a2); +extern s32 func_8012B6D4(s16 *a0, s16 *a1); +extern s32 func_8012B70C(s16 *a0, s16 *a1); +extern s32 ratan2(s32 x, s32 y); +extern s32 func_8012B744(void *a0, void *a1); +extern s16 D_80126CB8; +extern s16 D_80126CB4; +extern s32 func_8012B864(s32 a0); +extern s32 func_8012B8A4(s16 *a0); +extern s32 func_8012B8E4(s32 arg0, s32 arg1); +extern s32 func_8012BA10(s32 arg0, s32 arg1); +extern s32 func_8012BB3C(s32 arg0, s32 arg1, u32 arg2, s32 arg3); +extern void Square0(s32 *a0, s32 *a1); +extern s32 func_8012BC60(struct Vec *a0, struct Vec *a1); +extern s16 D_80126CBA; +extern s32 func_8012BCCC(s32 a0); +extern void func_80013350(s32 a0, void *a1); +extern u8 D_80126B5C; +extern void func_8012BD14(s32 a0); +extern s32 func_8012BDBC(s32 a0, s32 a1); +extern s32 func_8012BD3C(s32 a0, s32 a1, s32 a2); +extern void func_8012BE98(s32 a0, u16 *a1); +extern void func_8012BE54(s32 a0); +extern s32 func_800132BC(s32 a0, s32 a1); +extern void func_8012BE98(s32 arg0, u16 * arg1); +extern s32 func_8012BEE8(s32 a0); +extern s32 func_8012BF10(s32 a0, s32 a1); +extern void func_8012BF4C(s32 *a0, s32 a1); +extern void func_8012BF54(void *a0); +extern void func_8012BF68(void *a0); +extern s16 D_80126CB0; +extern s32 func_8012BF7C(s16 *a0); +extern s16 D_80126CAC; +extern short D_80126CAE; +extern int func_8012BFA8(short *a0); +extern s32 D_801274D4; +extern s32 D_801274E0; +extern s32 func_8012C044(s32 a0); +extern void func_8012C218(void *a0); +extern void func_8012C098(void *param_1); +extern s32 func_8012C0EC(s32 a0); +extern void func_8012C194(void); +extern void func_8001CFDC(s32 a, s32 b); +extern void func_8012C1B8(void); +extern u8 D_800B3DF0[]; +extern s32 func_8012C1DC(s32 a0); +extern u8 D_80126720[]; +extern u16 * func_8012C284(u16 *a0); +extern u8 D_80120194[]; +extern s32 func_8012C2D0(void); +extern s32 func_8012C31C(void); +extern void func_8012CAE4(void *a0); +extern void func_8001C214(s32 a0, s32 a1); +extern u8 D_80078EAE; +extern s32 func_8012C354(s32 a0, s32 a1); +extern void func_8001C810(s32 a0, s32 a1); +extern s32 func_8012C438(s32 a0, s32 a1); +extern s32 func_8012C890(s32 a0, s32 a1, s32 a2); +extern s32 func_8012C51C(void *a0, s32 a1); +extern s32 func_8012C588(s32 a0, s32 a1); +extern void func_8012C724(s32 a0, s32 a1); +extern s32 func_8012C750(s32 a0); +extern s32 func_8012C820(u8 *a0); +extern u16 D_801274E4[]; +extern s32 func_8012CB64(s32 arg0, s32 arg1, s32 arg2, s32 arg3, s32 arg4); +extern s32 func_8012CC88(s32 a, s32 b, s32 c); +extern u8 D_800D3918[]; +extern void func_8012CBA4(s32 a0); +extern void func_8012CBCC(s32 a0); +extern void func_8012CBF4(s32 a0); +extern void func_8012CC1C(s32 arg0, s32 arg1); +extern void func_8012CC40(s32 arg0, s32 arg1); +extern s32 func_8012CC88(s32 a0, s32 a1, s32 a2); +extern void func_8012CC64(s32 a0, s32 a1); +extern s32 func_80133784(s32 a0, void *a1, s32 a2); +extern s32 func_8012CE2C(s32 a0); +extern s32 func_8012CEB0(s32 a0, s32 a1, s32 a2); +extern void func_8012CFA8(s32 arg0); +extern void func_8012F214(s32 a0, s32 a1, s32 a2); +extern void func_8012D3B4(s32 arg0, s32 arg1, s32 arg2); +extern void func_8012D098(u16 *param_1, u32 param_2); +extern void func_8012D098(); +extern void func_8012D38C(int a0); +extern void func_8012D3AC(void); +extern s32 AddPrim(s32, void *); +extern s32 RotTransPers(s32, s32, s32 *, s32 *); +extern void SetLineF2(void *); +extern void *func_80010A08(s32); +extern void func_8004914C(void *); +extern void func_800491AC(void *); +extern s32 D_800A651C; +extern u8 D_800AF648; +extern s16 D_800B9A02; +extern void func_8012D4B4(s32 arg0, s32 arg1, s32 arg2, s32 arg3); +extern void func_8012D5DC(void); +extern s16 D_80126B98; +extern s32 func_8012DEB8(s32 a0, s32 a1, s32 a2); +extern s32 func_8012D5E4(s32 a0, s32 a1, s32 a2, s32 a3); +extern int func_8012D664(); +extern void func_8012D624(s32 a0); +extern s32 func_8012D714(s32 param_1, u32 param_2); +extern void func_8012F568(s32 a0, s32 a1, s32 a2, s32 a3, s32 a4, s32 a5); +extern void func_8014C978(void); +extern s32 func_8012DB84(void); +extern s32 func_8012DE2C(s32 a0); +extern s32 func_8012DDA4(void); +extern s32 func_8012DBD0(s32 arg0, s32 arg1, s32 arg2, s32 arg3); +extern s32 func_8012DF34(s32 a0, s32 a1, s32 a2); +extern s16 D_80126B9A; +extern u8 D_801152A8[]; +extern void func_8012DFBC(void); +extern void func_8012DFCC(void); +extern void func_8012E014(void); +extern void func_8012E138(void); +extern void func_8012DFD4(u8 *a0); +extern s32 func_8012E27C(void); +extern void func_8012E284(void); +extern s32 GetTPage(s32, s32, s32, s32); +extern s32 func_8005A600(s32, s32, s32, s32, s32); +extern void func_8012E28C(s32 arg0, s32 arg1); +extern void func_8004914C(void *a0); +extern void func_800491AC(void *a0); +extern void func_8012E32C(void); +extern s32 func_8012E470(s32 a0); +extern void func_8012E4C8(s32 a0); +extern s32 func_8012E504(s32 a0, s32 a1); +extern s32 func_8012E544(s32 a0); +extern s32 func_8012E57C(s32 a0, s32 a1); +extern s32 RotTransPers(s32 a0, s32 a1, s32 *a2, s32 *a3); +extern void func_8012E5CC(s32 param_1, u16 param_2, u16 param_3); +extern void func_8012E688(s32 param_1, u16 param_2, u16 param_3); +extern s32 func_8012E778(int param_1, int param_2); +extern void func_8012E88C(u8 *a0); +extern void func_8012E8A8(u8 *a0); +extern void func_8012E8C4(u8 *a0); +extern void func_8012E8E0(s32 a0, s32 a1); +extern void func_8012EA90(s32 param_1, s32 param_2, s32 *param_3); +extern void func_8012EC04(s32 param_1, s32 param_2, s32 *param_3); +extern s32 func_8002A4FC(s32 a0); +extern s32 func_8012EECC(s32 a0); +extern void func_8012EFB8(s32 a0); +extern void func_8012EF34(s32 a0, s32 a1); +extern void func_8012EF70(s32 a0, s32 a1); +extern void ApplyTransposeMatrixLV(void *a0, void *a1, void *a2); +extern void func_8012F038(int param_1, short *param_2, short *param_3); +extern void func_8012F0BC(s32 *a0, s32 *a1, s32 *a2); +extern void RotTransSV(s32 a0, s32 a1, void *a2); +extern void func_8012F14C(s32 a0, s32 a1, s32 a2); +extern void func_8012F1A4(s32 *a0, s32 a1, s32 *a2); +extern void func_8012F2E8(s32 a0, s32 a1, s32 a2); +extern s16 D_80126CB6; +extern void func_8012F374(s32 a0, s32 a1); +extern void *memcpy(void *, const void *, u32); +extern u8 D_80126C38; +extern u8 D_80126C40; +extern u16 D_80126B94; +extern u16 D_80126B96; +extern void func_8012F568(s32 param_1, s32 param_2, s32 param_3, s32 param_4, s32 param_5, s32 param_6); +extern void func_80131B14(); +extern void func_80131E00(struct S80131E00 *a0, s32 a1); +extern s32 func_80131A34(s32, s32); +extern void func_80131CA8(int a0, int a1); +extern void func_8012F5F4(s32 arg0); +extern void func_80131C78(s32 a0); +extern void func_8012F68C(s32 arg0); +extern void func_8012F75C(s32 a0); +extern s32 func_8012BEE8(s32); +extern void func_8012F7B4(s32 a0); +extern void func_80131170(); +extern void func_80131CA8(); +extern void func_8012F828(int param_1); +extern void func_80131340(s32 a0); +extern void func_8012F87C(s32 a0); +extern void func_8012F8C8(int param_1); +extern void func_8012F91C(s32 a0); +extern s32 func_80131A34(s32 a0, s32 a1); +extern void func_80131CA8(s32 a0, s32 a1); +extern void func_8012F968(s32 param_1); +extern void func_801319E0(s32 a0); +extern s32 func_80143B6C(s32 a0, s32 a1); +extern void func_8012FB54(s32 a0); +extern void func_8012FC30(s32 a0); +extern void func_8012FCA4(int a0); +extern void func_80131B14(void); +extern void func_8012FCC4(int param_1); +extern void func_8012FDA8(int param_1); +extern void func_80131170(s32 a0, s32 a1, s32 a2); +extern void func_8012FE70(s32 a0); +extern void func_8012FF00(s32 a0); +extern void func_8012FF4C(s32 a0); +extern void func_80130D48(s32 a0); +extern void func_8012FF98(u8 *a0); +extern s32 func_80131AC8(void *a0); +extern void func_8013001C(void *a0); +extern void func_80130088(void *a0); +extern s32 func_8012BCCC(s32); +extern void func_801300F4(s32 a0); +extern void func_801301E8(u8 *a0); +extern void func_80130278(s32 arg0); +extern void func_80130314(s32 a0); +extern void func_80130360(s32 a0); +extern void func_8012E364(void); +extern void func_801303A0(s32 a0); +extern void func_801303EC(void *a0); +extern void func_80143CD4(s32 a0); +extern void func_800CB0E8(s32 a0); +extern void func_80130438(s32 a0); +extern void func_801319E0(int); +extern int func_80131D68(int, int); +extern int func_8012BEE8(int); +extern void func_80131CA8(int, int); +extern void func_80130514(int param_1); +extern void func_801305CC(u8 *a0); +extern void func_8012CBF4(s32); +extern s32 func_80131D68(s32 a0, s32 a1); +extern void func_80130650(s32 a0); +extern s32 func_80146A6C(s32 a0, void *a1, s32 a2, s32 a3, s32 a4, s32 a5, s32 a6); +extern void func_80130740(void *a0, u16 *a1); +extern s32 func_801312D0(s32 a0, void *a1); +extern void func_801307B0(s32 a0); +extern void func_80130858(s32 a0); +extern void func_80130898(u8 *a0); +extern void func_801308DC(s32 a0); +extern void func_80166244(); +extern void func_80130974(int param_1); +extern void func_80130A18(u8 *a0); +extern void func_80130AC4(s32 a0); +extern int func_80131A34(int a0, int a1); +extern void func_80130AF0(int param_1); +extern void func_80130D0C(s32 a0); +extern void func_80131170(s32 p, s32 b, s32 c); +extern s32 func_801312D0(s32 param_1, void *param_2); +extern void func_80131E00(); +extern s32 D_801C64E8; +extern s32 D_801C64EC; +extern void func_8002A04C(s32 a0); +extern void func_801319E0(s32 arg0); +extern s32 func_80131CF4(s32 a0); +extern int func_80131D68(int a0, int a1); +extern void func_80131E38(u8 *a0); +extern void func_80131E7C(s32 a0); +extern void func_80131EE4(void); +extern void func_80131EEC(void *a0); +extern void func_80131F28(void *a0); +extern void func_80131F64(void *a0); +extern void func_80131FA0(void *a0); +extern void func_80131FDC(void *a0); +extern void func_801320D0(void); +extern void func_8001C214(int, int); +extern void func_801320D8(int param_1); +extern void func_80132144(int param_1); +extern void func_801321B0(int param_1); +extern void func_8013221C(int param_1); +extern void func_8005C324(int dst, int src, int n) __asm__("memcpy"); /* Phase-24: 0x8005C324 is named memcpy for overlays (whale needs it); keep the non-builtin C name here (else built-in codegen), emit via asm-label */ +extern void func_801325B8(int a0, int a1, int a2, int a3, int a4); +extern void func_80132288(int *param_1, int *param_2, int param_3); +extern void func_801325B8(s32 a0, s32 a1, s32 a2, s32 a3, s32 a4); +extern void func_8013240C(s32 a0); +extern void func_8013277C(void); +extern void func_80020F34(s32 a0, s32 a1); +extern void func_80054514(s32 a0, s32 a1); +extern void func_80132784(s32 a0, s32 a1, u32 a2); +extern s32 VectorNormalSS(void *a0, void *a1); +extern void func_80132DC4(s32 a0, s32 a1, s32 a2); +extern s32 func_80132E6C(s16 *a0); +extern void func_80132EC4(void *a0, s16 a1); +extern s32 func_80132EF4(s32 a0, s32 a1); +extern void func_801330E0(s16 *a0, s16 *a1, s32 a2); +extern void func_80133060(u8 *a0, s32 *a1, s32 a2); +extern void func_8013339C(short *param_1, short *param_2); +extern s32 func_8013361C(s16 *a0, s16 *a1, s16 *a2, s16 *a3); +extern void func_80136BC4(s32 a0); +extern void func_801336E8(void *a0, int a1, int a2); +extern void func_80136BC4(s32); +extern void func_8013373C(s16 arg0); +extern s32 func_80133784(s32 arg0, void *arg1, s32 arg2); +extern s32 func_80133CD4(); +extern s32 func_80134310(Vec3s *a0, Vec3s *a1, s32 a2); +extern s32 func_8013435C(s16 *a0, s16 *a1, s32 a2, s16 *a3); +extern s32 func_801343C4(s32 angle, s32 p1, s32 p2); +extern s32 func_801345F8(s32 arg); +extern s32 func_80134A28(s32 a0, s32 a1, s32 a2); +extern int func_80134A74(int param_1, s16 param_2, s16 param_3, int param_4); +extern s32 func_80134C20(s32 arg0, s32 arg1, s32 arg2, s32 arg3); +extern s32 func_80134FB8(s32 a0, s32 a1, s32 a2); +extern int func_80134A74(int, s16, s16, int); +extern int func_80135168(u16 arg0, u16 *p1, u16 *p2); +extern s16 func_80135480(void *param_1, s32 param_2, s16 *param_3, s16 *param_4); +extern s32 func_80136334(void *arg0, s32 arg1, s32 arg2); +extern s32 func_801365B8(void *arg0, s32 arg1, s32 arg2); +extern s32 func_80136824(s32 arg0, s32 arg1, s32 arg2); +extern s32 func_80136A94(s32 a0, s32 a1, s32 a2, s32 a3); +extern void func_80136C3C(void); +extern void func_80136C1C(void); +extern void func_80136C44(void); +extern void func_80136C4C(void); +extern void func_80136C54(void); +extern void func_80136D00(void); +extern void SetLineG2(void *); +extern void func_80136D08(s32 arg0, s32 arg1); +extern u16 D_80126CC4; +extern M2C_UNK func_800153CC(M2C_UNK, u16, M2C_UNK, M2C_UNK, s32, s32); +extern void func_80136DFC(void); +extern void func_80136EC4(void); +extern short D_800B9A02; +extern u8 D_800A6518[]; +extern void GsSortLine(void *a0, void *a1, s32 a2); +extern void func_80136ECC(s16 a0, s16 a1, s16 a2, s16 a3, u8 r, u8 g, u8 b); +extern void func_80137030(s16 a0, s16 a1); +extern void ApplyMatrixSV(void *m, Svec_801372B0 *in, Svec_801372B0 *out); +extern void aGsSortLine(Gline_801372B0 *p, void *ot, s32 z) __asm__("GsSortLine"); +extern void aF80137030(s32 x, s32 y) __asm__("func_80137030"); +extern void func_80137178(s32 x, s32 y); +extern u8 D_800AF630[]; +extern u16 aD800B9A02 __asm__("D_800B9A02"); +extern void func_801372B0(void); +extern void func_80137614(s32 a0, s32 a1, s32 a2); +extern void func_801375EC(s32 a0, s16 a1); +extern s32 func_801399A8(void); +extern void func_801377B4(s32 a0, s32 a1, s32 a2); +extern s32 func_8013767C(s32 a0); +extern void func_801376E8(int a0, int a1); +extern void func_801376C8(int a0); +extern s32 D_80127524; +extern s32 D_80127528; +extern void func_80137840(s32 a0); +extern void func_80139634(void *); +extern void func_80139DC8(void); +extern s16 D_8012752E; +extern void func_801379D8(void); +extern void func_801379EC(void); +extern void func_80138BE0(s32 a0); +extern void func_80137BD8(s32 a0); +extern void func_8013A380(void); +extern void func_801379FC(void); +extern void func_80138BE0(int p); +extern void func_80137B80(void); +extern void func_801392FC(); +extern void func_801397B0(s32 a0); +extern void func_80137DD4(s32 a0, u8 *a1, u8 *a2); +extern void func_80139680(s32 a0, u8 *a1); +extern u16 D_800B99D8; +extern int func_80137D08(int arg0, int arg1, short arg2); +extern void func_80137FD8(s32 a0, s32 a1, s32 a2, s32 a3); +extern void func_80137DD4(s32 ent, u8 *arg, u8 *work); +extern void func_801387B8(s32 arg0); +extern void func_80138948(void *a0); +extern s16 func_80138DB8(s32 a0, u8 a1, s32 a2); +extern void func_80138B88(s32 a0); +extern void func_8013895C(s32 a0); +extern s16 D_80127540[4]; +extern s32 func_80139D04(s32 a0, s32 a1); +extern s32 func_80138DE0(s32 a0, s32 a1, s32 a2); +extern void func_80139B18(s32 a0); +extern void func_80138AB4(s32 a0); +extern void func_80138C30(void *a0); +extern void func_8013A9F8(s32 a0, s32 a1); +extern void func_80138D58(s32 a0, u16 a1); +extern s32 func_80014E80(s32 a0, s32 a1); +extern s32 func_8013914C(s32 a0, s32 a1); +extern void func_800599B8(u16 *); +extern u16 D_80127C0C[]; +extern s32 D_80127548[]; +extern s32 func_80138ED0(u8 *param_1, u32 param_2, u8 *param_3); +extern s32 func_80139220(s32 a0); +extern void func_801391F0(void *a0); +extern void func_801392C8(void *a0); +extern void func_801395D4(void *); +extern s32 GetTPage(s32 a0, s32 a1, s32 a2, s32 a3); +extern s32 func_80052460(s32 a0, s32 a1, s32 a2); +extern void func_801392FC(s32 arg0, s32 arg1, u8 *arg2); +extern void func_80059888(void *a0, s32 a1, s32 a2, s32 a3); +extern void func_80139634(void *a0); +extern void func_80139680(s32 arg0, u8 * arg1); +extern void func_8001931C(void); +extern s16 D_8012752C; +extern void func_80139788(void); +extern void GsSortSprite(void *a0, u8 *a1, s32 a2); +extern void func_801397B0(s32 arg0); +extern void func_8013A8B0(s32 *a0); +extern void func_80139914(s32 arg0); +extern u16 D_80126A08; +extern s16 D_801269F4; +extern s32 D_801269F0; +extern s32 *D_80126A30; +extern void func_80139954(void); +extern s32 D_80126A3C; +extern s32 func_801399F0(s32 a0); +extern s32 D_80127520; +extern void func_80139A34(s32 a0); +extern s32 D_80127530[4]; +extern void func_80139A44(s32 a0, u16 a1); +extern void func_80139A68(s32 a0, u16 a1); +extern void func_80139A8C(s32 a0); +extern void func_80139C7C(u8 *a0); +extern s16 D_8012811A; +extern void func_80139DEC(void); +extern void func_80139DF4(s32 a0); +extern void func_80139E84(s32 a0); +extern void func_80139F0C(s32 a0); +extern void func_80139FBC(struct obj *a0); +extern s32 func_8001B22C(void *a0); +extern void func_80139FE8(void *a0); +extern void func_8013A0A4(struct S8013A0A4 *a0); +extern void func_8013A164(struct S8013A164 *a0); +extern void func_8013A1E8(s32 a0); +extern void func_8013A250(struct S8013A250 *a0); +extern void func_8013A2BC(s32 a0); +extern void func_8013A378(void); +extern u8 D_8011DA80[]; +extern void func_8013A530(); +extern void func_8013A448(void *a0); +extern void func_8013A4C4(struct S8013A4C4 *a0); +extern void func_80015D4C(); +extern void func_80015F04(); +extern void func_8013AA24(s32 a0, s32 a1); +extern void func_8013A530(int param_1); +extern void func_8013A860(void); +extern s32 func_8013A8BC(void); +extern void func_8013A9B4(s32 a0, s32 a1); +extern s32 func_8013A8FC(s32 arg0); +extern void func_8013AD38(void *a0, s32 a1, void *a2, void *a3); +extern void func_8013B204(s32 a0, s32 a1); +extern void func_8013AF20(); +extern void func_8013B274(s32 a0, s32 a1, void *a2); +extern s32 func_8013AB54(s32 a0, s32 a1, s32 a2, s32 a3); +extern void func_8013AF20(u32 *param_1, u16 *param_2, u16 *param_3, u8 *param_4); +extern void func_8013CA14(void); +extern void func_8013CABC(void); +extern void func_8013CAE8(void); +extern void func_8013CB20(void); +extern void func_8013CB5C(void); +extern void func_8013CF68(); +extern void func_8013D9B0(); +extern void func_8013D064(void); +extern s32 func_8013D13C(void); +extern void func_8013D164(void); +extern void func_8013D178(void); +extern void func_8013D330(void); +extern void func_8013D53C(void); +extern void func_8013DD68(void); +extern void func_8013D8FC(void); +extern void func_8013CF68(void); +extern void func_8013D3D4(int param_1, int param_2); +extern void func_8013DBE4(int param_1); +extern s32 func_8013E054(void); +extern int SquareRoot12(int a0); +extern int func_8013E064(s16 *a0, s16 *a1); +extern int func_8013E0FC(s16 *a0, s16 *a1); +extern int func_8013E194(s16 *a0, s16 *a1); +extern void Square12(s32 *a0, s32 *a1); +extern s32 func_8013E22C(struct VecA *a0, struct VecB *a1); +extern s32 func_8013E298(s16 *a0); +extern int func_8013E2C4(short *a0); +extern void *D_801274CC; +extern s32 func_8013E410(void); +extern s32 func_8013E448(s32 a0); +extern void func_8013E370(void); +extern s32 (*D_801274D0)(s32); +extern s32 D_801274D8; +extern s32 D_801274DC; +extern s32 func_8013E448(s32 param_1); +extern void func_800D24A0(s32 a0); +extern void func_80141788(void); +extern void *D_8011DB24; +extern s32 func_800D0EC4(void); +extern void func_80141874(void); +extern u8 D_800B9A15; +extern unsigned char D_800B9A13; +extern u16 D_80115110; +extern unsigned short D_80115112; +extern void func_8013E588(void * _arg0); +extern void func_801754A8(void); +extern s32 func_80014ED4(s32); +extern s32 func_80015018(s32); +extern void func_800190AC(void); +extern void func_80141C04(void); +extern void func_8013E5E8(void); +extern void func_8013E83C(void); +extern void func_8013E6AC(void); +extern void func_800D24A0(s32 arg); +extern void func_8013E814(void); +extern void func_8013E83C(); +extern void func_8013E958(); +extern s32 func_80141C50(void); +extern void func_8013F244(void); +extern void func_8013FAF8(s16 a0, s16 a1); +extern void func_8013E958(void); +extern u8 D_801151C8[]; +extern s32 D_801151D0; +extern u16 D_8011511A; +extern u16 D_8011511E; +extern s32 D_80115130; +extern s16 D_8011514C; +extern void func_8013EA54(void); +extern s32 func_8013F350(void); /* §30#2 widened: def returns live $v0; callers discard */ +extern s16 func_8014168C(s16 a0); +extern s32 func_8014032C(s32 a0, s32 a1); +extern unsigned char *func_80141CA4(void); +extern void func_8013EB7C(void); +extern s32 func_8013F350(void); /* §30#2 widened (discarding caller) */ +extern u16 D_80115112; +extern void func_8013ED6C(void); +extern s32 func_8013EE10(); +extern void func_8013F138(void); +extern void func_800D2624(void); +extern unsigned short D_80115114; +extern unsigned short D_80115118; +extern void func_8013F1BC(void); +extern void func_80141C0C(s32); +extern u16 D_8011511C; +extern u16 D_80115120; +extern u16 D_80115122; +extern s16 D_80115128; +extern s16 D_8011512A; +extern u16 D_8011512E; +extern u8 D_80115140[]; +extern s16 D_8011514E; +extern u8 D_80115152; +extern u8 D_80115158[]; /* macro-canonical (§8e) */ +extern u8 D_8011515C; /* macro-canonical (§8e) */ +extern u8 D_80183FCC[]; +extern u8 D_80183FE4[]; +extern u16 D_80183EE8[]; +extern s32 func_80029178(s32 arg); +extern s32 func_800291B4(s32 arg); +extern void func_8014AA04(s32 a0); +extern void func_801415C0(s32 a0, s32 a1); +extern void func_80141C0C(s32 a0); +extern s32 func_80140608(s32 a0); +extern void func_801407F4(void); +extern s32 func_801416D4(s16); /* macro-canonical (§8e) */ +extern s32 func_8013F350(void); +extern void func_80140E6C(void); +extern void func_80140F00(void); +extern s32 *func_80140958(s32 *, s32, s32); +extern int func_80141100(int); +extern s16 func_8014168C(s16); +extern s32 func_8013FFD8(s16, s32, s32 *); +extern void func_80024054(void *a0, void *a1); +extern s32 *func_800D2650(s32 *, void *, s32, s32, s32, s32); +extern s32 func_800D27DC(s32, s32 *, void *, s32, s32); +extern s32 *func_800D29F8(s32, s32, void *, s32, s32); +extern void func_8013FAF8(s16 arg0, s16 arg1); +extern s32 func_80028D58(void); +extern s32 func_80028DE0(void); +extern s32 func_80028FBC(void); +extern s32 func_80029000(void); +extern s32 func_80028D9C(void); +extern int func_800D2CA8(int, int); +extern void func_800D2D10(int, int, void *, int); +extern int func_80029FE4(void); +extern char *func_8002AAB4(void); +extern char *strcpy(char *, const char *); +extern int func_8002A26C(void); +extern int func_8002A2B0(void); +extern int func_8002A4B8(void); +extern int func_8002A998(void); +extern int func_8002A9DC(void); +extern int func_8002A728(void); +extern int func_8002A76C(void); +extern int func_80029FD4(void); +extern s32 func_8002A1B4(void); +extern short func_8002A28C(void); +extern short func_8002A27C(void); +extern s32 func_8002A400(void); +extern short func_8002A4D8(void); +extern short func_8002A4C8(void); +extern s32 func_8002A8E0(void); +extern short func_8002A9B8(void); +extern short func_8002A9A8(void); +extern s32 func_8002A670(void); +extern short func_8002A748(void); +extern short func_8002A738(void); +extern int func_801412A8(int, int, int, int, int, int); +extern int func_80141100(int param_1); +extern void func_800291A0(s32, s32); +extern s32 func_800291DC(s32); +extern void func_800291C8(s32, s32); +extern void func_801415C0(s32 param_1, s32 param_2); +extern u8 D_80115148[]; +extern u8 D_80115149[]; +extern u8 D_80115158[]; +extern u8 D_8011514D; +extern u8 D_8011515C; +extern s32 func_800D11F0(s32 a0); +extern s32 func_800D1658(s32 a0); +extern s32 func_801416D4(s16 param_1); +extern void func_8001903C(void); +extern void func_801417C4(void); +extern u8 D_800B9A16; +extern u16 D_80115114; +extern void func_801417F8(void); +extern volatile u16 D_8011511A; +extern u16 D_8011512E; /* §17a-1: canonical width (jr_8013F350 TUs decl u16); byte-neutral here (only use is store-0) */ +extern s32 func_80029178(s32 a0); +extern void func_801418F8(void); +extern void func_80141A60(void); +extern void func_80141C0C(s32 param_1); +extern s32 func_80015144(void); +extern unsigned char D_80112C04[]; +extern unsigned char D_80112C50[]; +extern unsigned char D_80112C9C[]; +extern unsigned char D_80112CE8[]; +extern unsigned char D_80112D38[]; +extern unsigned char D_80112D78[]; +extern unsigned char D_80112DBC[]; +extern unsigned char D_80112DF4[]; +extern unsigned char D_80112E14[]; +extern unsigned char D_80112E40[]; +extern unsigned char D_80112E6C[]; +extern unsigned char D_80112EBC[]; +extern unsigned char D_80112F0C[]; +extern unsigned char D_80112F48[]; +extern unsigned char D_80112F9C[]; +extern unsigned char D_80112FDC[]; +extern unsigned char D_8011302C[]; +extern unsigned char D_80113074[]; +extern unsigned char D_801130B8[]; +extern unsigned char D_801130E8[]; +extern unsigned char D_80113138[]; +extern unsigned char D_8011317C[]; +extern unsigned char D_801131A8[]; +extern unsigned char D_801131E8[]; +extern unsigned char D_80113214[]; +extern unsigned char D_80113254[]; +extern unsigned char D_80113278[]; +extern unsigned char D_801132B8[]; +extern unsigned char D_801132E4[]; +extern unsigned char D_80113324[]; +extern unsigned char D_80113360[]; +extern unsigned char D_801133A4[]; +extern unsigned char D_801133F4[]; +extern unsigned char D_80113440[]; +extern unsigned char D_80113474[]; +extern unsigned char D_801134B0[]; +extern unsigned char D_801134FC[]; +extern unsigned char D_80113530[]; +extern unsigned char D_80113554[]; +extern unsigned char D_801135A8[]; +extern unsigned char D_80113600[]; +extern unsigned char D_80113650[]; +extern unsigned char D_80113694[]; +extern unsigned char D_801136DC[]; +extern unsigned char D_80113724[]; +extern unsigned char D_80113744[]; +extern unsigned char D_80113770[]; +extern unsigned char D_80113794[]; +extern unsigned char D_801137D8[]; +extern unsigned char D_8011381C[]; +extern unsigned char D_8011383C[]; +extern unsigned char D_8011386C[]; +extern unsigned char D_801138A4[]; +extern unsigned char D_801138D0[]; +extern unsigned char D_80113900[]; +extern unsigned char D_80113944[]; +extern unsigned char D_80113964[]; +extern unsigned char D_8011399C[]; +extern unsigned char D_801139E8[]; +extern unsigned char D_80113A28[]; +extern unsigned char D_80113A50[]; +extern unsigned char D_80113A84[]; +extern unsigned char D_80113AB0[]; +extern unsigned char D_80113AE0[]; +extern unsigned char D_80113B34[]; +extern unsigned char D_80113B68[]; +extern unsigned char D_80113BA4[]; +extern unsigned char D_80113BC0[]; +extern unsigned char D_80113BF0[]; +extern unsigned char D_80113C20[]; +extern unsigned char D_80113C3C[]; +extern unsigned char D_80113C7C[]; +extern unsigned char * func_80141CA4(void); +extern void func_80142414(s32 a0, s16 a1); +extern void func_80142454(s32 a0); +extern void func_801424E4(short *param_1); +extern void func_801425CC(void *a0); +extern void func_8001CA1C(s32 a0, s32 a1); +extern s32 func_8012AD50(void *a0); +extern void func_80142608(s32 param_1); +extern void func_801426D4(s32 a0); +extern void func_80142740(int param_1); +extern void func_80142778(u8 *a1); +extern void func_801427DC(void); +extern void func_801427E4(void); +extern void func_801427EC(int param_1); +extern s32 func_80142DB8(s32 *a0); +extern s32 func_80142D38(s32 *a0); +extern void func_80142BB4(s32 *a0, s32 a1, s32 a2); +extern void func_801428CC(s32 *a0); +extern void func_8014292C(int param_1); +extern void func_80142978(int param_1); +extern void func_801429C4(int param_1); +extern void func_80142A80(void); +extern void func_80142C7C(void); +extern void func_80142C84(s32 a0); +extern void func_80142C9C(s32 * arg0); +extern void func_80142B2C(void *arg0); +extern void func_80142DC4(int param_1); +extern void func_80142E38(int param_1); +extern void func_8012A828(s32 a0, void *a1); +extern void func_80142EC0(s32 param_1); +extern void func_80142FFC(s32 *a0); +extern void func_8014305C(int param_1); +extern void func_80143188(s32 *a0); +extern int func_8001CA88(int, void *); +extern void func_800233CC(void *, unsigned short); +extern void func_801431E8(s32 param_1); +extern void func_80142C9C(s32 *a0); +extern void func_801432FC(s32 *a0); +extern void func_80143390(s32 *a0); +extern void func_80143458(s32 param_1); +extern void func_8014358C(s32 param_1); +extern s32 rand(void); +extern void func_80143640(s32 a0, s32 a1, s32 a2, s32 a3); +extern void func_801437D8(s32 a0, s32 a1, s32 a2, s32 a3); +extern s32 func_80143970(s32 a0); +extern s32 func_8012C658(s32 a0, s32 a1, s32 a2); +extern void func_80143994(s32 a0, s32 a1); +extern void func_801439C0(u8 *a0); +extern s16 D_801152AC; +extern s16 D_801152AA; +extern void func_801439FC(s32 a0); +extern void func_80143B30(void *a0); +extern s32 func_8012C658(s32 arg0, s32 arg1, s32 arg2); +extern s32 func_80143B6C(s32 arg0, s32 arg1); +extern void func_80143BDC(u16 *a0); +extern void func_80143C38(void *a0); +extern void func_80143C74(s32 a0, s32 a1); +extern void func_80143C98(void *a0); +extern void func_80143E68(void *a0); +extern void func_80143EA4(void); +extern void func_80143EAC(void); +extern void func_80143EB4(void); +extern s32 func_8004787C(s32 a0); +extern void func_80143EBC(s32 a0); +extern void func_80144054(void *a0); +extern void func_801442F8(int param_1); +extern void func_8001CB6C(u8 *a0, s32 a1, s32 a2, s32 a3); +extern void func_80144364(int param_1); +extern u8 D_800D387C[]; +extern u8 D_800D3888[]; +extern void func_80144558(u8 *param_1); +extern void func_801446A4(int param_1); +extern void func_8014477C(void *param_1); +extern void func_80144880(s32 param_1); +extern void func_80144988(s32 a0); +extern void func_801449C8(void *a0); +extern void func_80144A04(s32 *a0); +extern void func_80144A2C(void *a0); +extern void func_80144A68(s32 *a0); +extern void func_80144A90(void); +extern void func_80144A98(u8 *a0); +extern void func_80144B14(void); +extern void func_80144AEC(s32 *a0); +extern void func_801458E0(void); +extern s32 D_800AE6AC; +extern s32 D_800AE6B0; +extern s16 D_800B9A0A; +extern u8 D_80078E50; +extern void func_800D185C(u8 *a0); +extern void func_801458E8(void); +extern void func_80145B24(void); +extern void func_80145934(void); +extern void func_80145A2C(void); +extern void func_80162120(void); +extern void func_80029124(s32, s32); +extern s32 func_80165A50(s32); +extern void func_80029514(s32); +extern u8 D_80078EC0; +extern void func_80145BF8(void); +extern void func_80145C54(void); +extern void func_80146014(s32 a0); +extern void func_80145EE8(s32 param_1); +extern void MoveImage(void *a0, s32 a1, s32 a2); +extern s32 func_80146128(void); +extern void func_80146360(void); +extern void func_801463A0(); +extern u8 D_80078EC1; +extern s32 D_80078EC8; +extern s32 D_80126B9C; +extern s32 D_8011F730; +extern u16 D_801152B8; +extern u16 D_8012693A; +extern u8 D_80126BE0[]; +extern u8 D_801150F0[]; +extern void *memcpy(void *dst, const void *src, u32 n); +extern void func_80146FC4(s32 a0); +extern void func_80150A70(s32 a0); +extern void func_80147098(s32 *a0); +extern void func_8014A638(s32 arg0); +extern s32 func_80155458(s32 a0); +extern s32 func_80029104(void); +extern void func_80029344(void); +extern void func_8014ADE0(s32 a0); +extern void func_8014B350(s32 a0); +extern void func_8014B7A4(s16 *param_1); +extern s32 func_80161D58(s32 a0); +extern void func_80161A90(s32 a0); +extern void func_8014B504(u16 *a0); +extern void func_80149BEC(s32 a0); +extern void func_8014B5D0(s32 *a0); +extern void func_8014C99C(u8 *a0); +extern void func_8014B190(s32 s0); +extern void func_80148648(s32 a0, s32 a1); +extern s32 func_80149228(s32 a0); +extern void func_8014A59C(s32 a0); +extern void func_8016F14C(void *a0); +extern void func_80154418(void *a0); +extern void func_80154BE4(s32 a0); +extern void func_80165694(s32 arg0); +extern void func_801654A8(s32 a0); +extern void func_8014A680(s32 a0); +extern void func_8014A6A8(s32 a0); +extern void func_8014A71C(s32 a0); +extern void func_80172588(s32 *a0); +extern void func_801473DC(s32 *a0); +extern void func_80015978(s32 a0, s32 *a1); +extern s32 D_80127098; +extern s32 D_80127094; +extern s32 D_80127090; +extern void func_80146534(void); +extern void func_8001D074(s32 a0, s32 a1); +extern void func_80146554(void); +extern void func_80146578(void); +extern void func_8001CFDC(s32, s32); +extern void func_8014659C(void); +extern void func_8001D074(s32, s32); +extern void func_801465C0(void); +extern void func_801465E4(void); +extern void func_801466F0(s32 a0, s32 a1, s32 a2, s32 a3, s32 sp5, s32 sp6, s32 sp7, s32 sp8); +extern s32 D_8011F9D0; +extern s32 func_80146608(s32 a0, s32 a1, s32 a2, s32 a3, s16 arg9, s32 arg10, s32 arg11, s32 arg12, s32 arg13); +extern void func_801466B4(u16 a0, s32 a1, s32 a2, s32 a3, s32 arg5); +extern s32 D_8011F750; +extern s32 D_8011F754; +extern u8 * func_801468C8(s32 arg0, u8 arg1); +extern s32 D_8011D030; +extern s32 func_80146994(s32 a0, s32 a1, s32 a2, s32 a3); +extern s32 func_80146924(s32 a0, s32 a1, s32 a2, s32 a3, s32 arg5); +extern s32 func_80146994(s32 arg0, s32 arg1, s32 arg2, s32 arg3); +extern s32 func_801469C8(int a0, void *a1, int a2, int a3, u16 arg5, int arg6, int arg7, int arg8); +extern s32 func_80146B9C(void *a0); +extern void func_80146AB4(s16 a0, s32 a1, s16 a2, s16 a3, u16 a4, s32 a5, s32 a6); +extern u16 D_8011DA28; +extern s32 func_80146B9C(void * arg0); +extern void func_80146C3C(u8 *a0); +extern void func_80146C98(s32 *a0, s16 a1); +extern void func_80146CA0(void *a0); +extern void func_80146CB4(void *a0); +extern void func_80146CC8(s32 a0); +extern void func_80146D30(s32 a0); +extern void func_80146D80(s32 *a0); +extern void func_80146DE8(s32 *a0, s32 a1, s32 a2, s32 a3); +extern void func_80146D90(s32 a0); +extern void func_80146DB8(s32 *a0, s32 *a1); +extern void func_80146DF8(s32 *a0, s32 a1, s32 a2, s32 a3, s32 t0); +extern void func_80146E90(s32 *a0, s32 a1); +extern s32 func_80146E98(s32 a0); +extern void func_80015954(s32 a0, s32 a1); +extern void func_80149374(s32 a0, s32 a1); +extern void func_80146F58(s32 a0, s32 a1); +extern void func_80146EC0(s32 a0, s32 a1, s32 a2, s32 a3); +extern u8 D_80126DB0[]; +extern u16 D_80126DB6; +extern void func_8014704C(s32 *a0); +extern s32 func_80147054(void *a0); +extern void func_80147060(u8 * a0); +extern void func_8014706C(void *arg0); +extern void func_80147078(s32 *a0, s16 a1); +extern void func_80147084(s32 *a0); +extern void func_8014708C(void *arg0); +extern s32 func_801470A0(void *a0); +extern void func_801470AC(s32 *a0); +extern void func_801470B4(s32 arg0); +extern void func_801470C0(s32 a0); +extern void func_80147118(s32 a0); +extern s16 D_80126BB8; +extern s16 D_80126BBA; +extern s16 D_80126BBC; +extern void func_80147264(s32 a0); +extern void func_80147290(void); +extern void func_801472B4(void *a0); +extern s32 func_801472C8(struct S *a0); +extern void *D_8012707C; +extern void func_801472DC(void); +extern void func_801472F0(void *a0); +extern void func_80147364(u16, s32); +extern void func_80147300(u16 arg0); +extern void func_80147324(s32 arg0); +extern void func_801473EC(s32 *a0); +extern void func_80147460(s32 a0); +extern void func_80147514(); +extern void func_80147628(s32 a0); +extern void func_80147478(s32 a0); +extern void func_801474D8(s32 *a0); +extern void func_801474EC(s32 *a0); +extern s32 func_80012C6C(s32 a0, s32 a1, s32 a2); +extern s32 func_800129CC(s32 a0, s32 a1); +extern void func_80147514(s32 arg0); +extern void func_80013F3C(s32 a0); +extern void func_80012558(s32 a0, s32 a1); +extern void func_800126C4(s32 a0, s32 a1); +extern void func_800123F0(s32 a0, s32 a1); +extern void func_80147718(s32 a0); +extern void func_80147788(void *a0, s32 a1); +extern void func_801477A8(void *a0, s32 a1); +extern void func_801477C8(void *a0, s32 a1); +extern void func_801477E8(s32 *a0, s32 a1); +extern void func_80147814(s32 a0, s32 a1); +extern void func_80147928(int a0, int a1); +extern void func_8014799C(int a0, int a1); +extern void func_80147A10(int a0, int a1); +extern void func_80147860(int a0, int a1, int a2, int a3); +extern void func_80147948(s32 a0, s32 a1, s32 a2); +extern void func_801479BC(s32 a0, s32 a1, s32 a2); +extern void func_80147A30(s32 a0, s32 a1, s32 a2); +extern void func_801478B8(s32 a0, s32 a1, s32 a2, s32 a3); +extern void func_80147948(int a0, int a1, int a2); +extern void func_801479BC(int a0, int a1, int a2); +extern void func_80147A30(int a0, int a1, int a2); +extern void func_80147AD4(s32 arg0, s32 arg1, s32 arg2, s32 arg3); +extern void func_80147A84(s32 arg0); +extern void func_80147C30(s32 arg0, s32 arg1, s32 arg2, s32 arg3); +extern void func_80147AAC(s32 arg0); +extern void func_80147CC8(s32 a0, s32 a1, s32 a2, s32 a3, s32 a4); +extern void func_80147B5C(s32 a0, void *a1); +extern void func_80147AD4(s32 a0, s32 a1, s32 a2, s32 a3); +extern void func_80147D38(s32 a0, s32 a1, s32 a2, s32 a3, void *a4); +extern void func_80147B18(s32 a0); +extern void func_80147B5C(s32 arg0, void *arg1); +extern void func_80147C30(s32 a0, s32 a1, s32 a2, s32 a3); +extern void func_80147DC0(s32 a0, s32 a1); +extern void func_80147D38(s32 a0, s32 a1, s32 a2, s32 a3, void * a4); +extern void func_80147E44(s32 a0, s32 a1, s32 a2, s32 a3); +extern void func_80147F78(s32 arg0, s32 arg1, s32 arg2, s32 arg3); +extern void func_80147F50(s32 arg0); +extern volatile s32 D_80127090; +extern volatile s32 D_80127094; +extern volatile s32 D_80127098; +extern void func_80147F78(s32 a0, s32 a1, s32 a2, s32 a3); +extern void func_80148038(s32 a0, s32 a1); +extern s32 csqrt(s32 a0); +extern s32 func_80012A60(s32 a0, s32 a1); +extern void func_80148094(int param_1, short *param_2, int *param_3); +extern void func_801485B8(s32 a0, s32 a1, s32 a2); +extern void func_801484B0(s32 a0, s32 a1); +extern s32 func_80154358(void *a0); +extern void func_801484E8(s32 a0, s32 a1); +extern void func_80148534(s32 a0, s32 a1); +extern void func_8014856C(s32 a0, s32 a1); +extern void func_801485B8(s32 arg0, s32 arg1, s32 arg2); +extern void func_80148634(void *a0); +extern s32 func_80014DC0(); +extern s32 func_80014D68(); +extern s32 func_80014D94(); +extern s32 func_80014CF8(); +extern void func_800120DC(); +extern s32 func_800CF8B4(); +extern u16 func_801487F4(s32 *a0); +extern u16 func_80148800(s32 *a0); +extern u8 func_8014880C(s32 *a0); +extern u16 func_80148818(s32 *a0); +extern s32 func_80148824(void *arg0); +extern s32 func_801488A8(u8 *a0); +extern s32 func_8014891C(s32 a0); +extern s32 func_80148980(u8 *a0); +extern s32 func_801489E8(s32 a0); +extern s32 func_80148A48(s32 a0); +extern int func_80148AFC(void *a0); +extern void func_80148AAC(u8 *a0); +extern s32 func_80148C18(void); +extern s32 func_80148C20(s32 a0, s16 a1); +extern s32 func_80148C34(s32 a0, s32 a1); +extern s32 func_80148C4C(s32 a0, s32 a1); +extern s32 func_80148C64(s32 a0, s32 a1); +extern s32 func_80148C7C(void); +extern s32 func_80148C84(s32 a0, s32 a1); +extern s32 func_80148C9C(s32 a0, s32 a1); +extern s32 func_80148CB4(s32 a0, s32 a1); +extern s32 func_80148CCC(s32 a0, s32 a1); +extern s32 func_80148CE4(void); +extern s32 func_80148CEC(void); +extern s32 func_80148CF4(s32 a0, s32 a1); +extern s32 func_80148D0C(s32 a0, s32 a1); +extern s32 func_80148D24(void *a0, int a1); +extern s32 func_80148D3C(void); +extern s32 func_80148D44(void); +extern s32 func_80148F60(void); +extern s32 func_80148F68(s32 a0); +extern s32 func_80148F74(s32 a0); +extern s32 func_80148F80(s32 a0); +extern s32 func_80148F8C(s32 a0); +extern s32 func_80148F98(void); +extern s32 func_80148FA0(s32 a0); +extern s32 func_80148FAC(s32 a0); +extern s32 func_80148FB8(s32 a0); +extern s32 func_80148FC4(s32 a0); +extern s32 func_80148FD0(void); +extern s32 func_80148FD8(void); +extern s32 func_80148FE0(s32 a0); +extern s32 func_80148FEC(s32 a0); +extern s32 func_80148FF8(s32 a0); +extern s32 func_80149004(void); +extern void func_8014900C(s32 *a0); +extern void func_80149020(s32 *a0); +extern void func_80149034(s32 *a0); +extern void func_80149048(s32 *a0); +extern void func_8014905C(u8 *a0); +extern void func_801490E0(s32 *a0, s16 a1); +extern void func_801490E8(s32 *a0, s16 a1); +extern void func_801490F0(s32 *a0, s16 a1); +extern void func_80149078(s32 *a0, s32 a1, s32 a2, s32 a3); +extern s32 func_80012B04(s32 a0, s32 a1, s32 a2); +extern void func_801490F8(s32 a0, s32 a1); +extern s32 func_801491C4(s32 a0); +extern s32 func_80149184(s32 a0); +extern void func_80149204(s32 *a0); +extern void func_80149210(s32 a0, s32 a1); +extern s32 func_80149284(s32 *a0, s32 a1); +extern void func_80149350(s32 arg0); +extern void func_80149290(s32 a0); +extern s32 func_801496D4(void *a0); +extern void func_8015AD08(); +extern void func_80149704(void); +extern void func_8015ACC4(); +extern void func_80149724(void); +extern u8 D_80078EBF; +extern s32 func_80149744(struct S_80149744 *a0); +extern void func_8015F7A0(); +extern void func_80149788(void); +extern void func_801653B8(); +extern void func_80149864(void); +extern s32 func_8016F1AC(void); +extern s32 func_80149884(void); +extern void func_80160B00(); +extern void func_801498C0(void); +extern s32 func_80149AA8(s32 *a0); +extern s32 func_80149B54(s32 *a0); +extern void func_80146750(void *a0); +extern s32 func_801498E0(s32 *a0); +extern s32 func_80149A64(s32 *a0); +extern void func_8015DAC4(s32 *a0); +extern void func_8015554C(s32 *a0); +extern void func_80149AD4(s32 *a0); +extern void func_80149B14(s32 *a0); +extern u8 func_8014BEF8(void); +extern s32 func_80149B54(s32 * arg0); +extern void func_8015DE24(s32 *a0); +extern void func_80157510(s32 *a0); +extern void func_80149BAC(s32 *a0); +extern s32 func_80149C08(s32 arg0); +extern void func_801577C8(); +extern void func_80149C94(void); +extern void func_80157D20(void); +extern void func_80149CB4(void); +extern s32 func_80149CD4(s32 a0); +extern u8 func_8014B5B8(s32 *a0); +extern s32 func_80149D10(s32 a0); +extern s32 func_80149E94(s32 a0); +extern s32 func_80149DD8(s32 a0); +extern s32 func_80149D9C(s32 a0); +extern s32 func_80149F2C(s32 a0, s32 a1); +extern s32 func_80149E94(s32 arg0); +extern void func_80149FA8(void); +extern s32 func_80149FB0(s32 a0); +extern u16 func_80156370(u16 a0); +extern void func_8014C4AC(s32 a0, s32 a1, s32 a2, s16 *a3, s32 a4); +extern void func_8014A1B0(s32 a0, s32 a1); +extern void func_8015D4B4(); +extern void func_8014A218(void); +extern s32 func_8014C278(s32 a0, s32 a1, s32 a2); +extern s32 func_8014C2B0(void *a0, void *a1, s32 a2); +extern s32 func_8014A238(s32 arg0); +extern s32 func_8014A2E4(s32 a0); +extern void func_8014A380(s32 a0, s32 a1); +extern s16 D_801152B0; +extern s16 D_801152B4; +extern s32 func_8014A3E0(struct S_8014A3E0 *a0); +extern s32 func_8014A454(s32 a0); +extern s32 func_8014A4B4(void *a0); +extern void func_8015EDD4(); +extern void func_8014A4FC(void); +extern s32 func_8014A674(s32 *a0); +extern s32 func_8014A69C(s32 *a0); +extern s32 func_8014A6C4(s32 a0); +extern void func_8015E184(); +extern void func_8014A830(void); +extern s32 func_80029AF4(void); +extern s32 func_8014A850(s32 param_1); +extern void func_801599A4(void *a0); +extern void func_80159B3C(void *a0); +extern s32 func_80165A20(s32 a0); +extern void func_8014AB7C(); +extern void func_8014AC10(); +extern void func_8014AA28(void); +extern void func_8014AB5C(void); +extern void func_80162CCC(void); +extern void func_8014AB7C(s32 arg0); +extern void func_8014ABF0(void); +extern void func_8014AC10(s32 arg0); +extern void func_8014ACC0(s32 a0, s32 a1); +extern void func_8014AD30(s32 a0, u16 *a1, s32 a2, s32 a3); +extern void func_8014ACE8(void *a0, s32 a1, s32 a2); +extern void func_80146AFC(void *a0); +extern void func_8014ADA8(s32 a0, s32 a1); +extern void func_8014AD7C(s32 a0); +extern s32 D_80078E8C; +extern u8 D_80078E78[]; +extern s32 func_8016F1C4(void); +extern s32 func_8014B154(s32 *a0); +extern void func_8014BD24(s32 a0, s32 a1); +extern void func_8014BB24(s32 a0, s32 a1, s32 a2); +extern void func_8014BC80(s32 a0, s32 a1); +extern void func_8014BD60(s32 a0, s32 a1); +extern void func_8014B084(void); +extern void func_8014B034(s32 arg0); +extern void func_8014B00C(s32 arg0); +extern s16 D_80078E90; +extern void func_8014B034(s32 a0); +extern u16 D_80078EAC; +extern u8 D_80078EBA; +extern void func_800D10EC(void); +extern void func_8002AC98(void); +extern void func_8014B12C(void); +extern void func_8014B2F8(void); +extern void func_8014B4C4(void); +extern void func_8014B160(s32 a0); +extern s16 D_80078E96; +extern s16 D_80078EB8; +extern u16 D_80078EA6; +extern void func_8014B2A8(void); +extern void func_8014B310(void); +extern void func_8014B2D0(void); +extern s32 D_80078E94; +extern s32 D_80078ECC; +extern void func_8014B33C(void); +extern u8 D_80062BF4[]; +extern void func_80019064(void *a0); +extern s32 D_80078E98; +extern void func_8014B4D4(void *a0); +extern s16 D_80078E9A; +extern u8 D_80126D1C; +extern s32 D_80126D74; +extern void func_8014B598(s32 a0, s32 a1); +extern void func_8014B5B0(s32 *a0); +extern void func_8014B5C4(s32 *a0, s32 a1, s32 a2); +extern void func_8014B5D8(s32 s1); +extern s32 D_80078E9C; +extern s32 D_80078ED0; +extern void func_8014B6F0(s32 a0, s32 a1); +extern void func_8014B768(s32 a0, s32 a1); +extern void func_8014B944(s32 a0, s32 a1, s32 a2); +extern s32 D_80078EA4; +extern u16 D_80078EB2; +extern s16 D_80078EB4; +extern void func_8014BB0C(void); +extern void func_8014BC0C(s32 a0, s32 a1); +extern void func_8014BC44(s32 a0, s32 a1); +extern void func_8014BCC0(s32 a0, s32 a1); +extern u16 D_80078EB6; +extern s32 func_8014BCEC(s32 a0, s32 a1); +extern void func_8014BD60(s32 param_1, s32 param_2); +extern void func_8014BD98(s32 a0, u16 a1); +extern void func_8014BDC8(void); +extern void func_8014BDE0(void); +extern s32 func_8017267C(s32 *a0); +extern s32 func_80013294(void *a0, void *a1); +extern void func_80029ED4(s32 a0); +extern void func_8014BDE8(s32 a0); +extern void func_8014BE78(void); +extern void func_8014BE9C(void); +extern void func_80029124(s32 a0, s32 a1); +extern void func_8014BEC0(void); +extern void func_8014BF18(s32 a0); +extern void func_8014BF48(void); +extern u8 func_8014BF6C(void); +extern void func_8014BF8C(u8 arg0); +extern void func_8014BFB0(void); +extern u8 func_8014BFD4(void); +extern void func_8014BFF4(s32 a0, s32 a1); +extern void func_8014C010(s32 a0, s32 a1); +extern s32 func_8014C050(s32 a0, s32 a1); +extern s32 func_8014C088(s32 a0, s32 a1); +extern s32 func_8014C0C8(s32 a0_unused, s32 a1, s32 a2); +extern s32 func_8014C118(void * a0, s32 a1, s32 a2); +extern s32 func_8014C168(s32 * param_1, s32 param_2); +extern void func_8014C1C8(s32 a0, s32 a1, void* a2); +extern s32 func_80013328(s32 a0, s32 a1); +extern s32 func_8014C59C(void *a0, void *a1); +extern s32 func_8014C308(s32 arg0, s32 arg1, s32 arg2, s32 arg3); +extern s32 func_8014C43C(void *a0, s32 a1, s32 a2, s32 a3, s16 a5); +extern s32 func_8014C3A4(void *a0, s32 a1, s32 a2, s32 a3); +extern s32 func_8014C3D0(void *a0, s32 a1, s32 a2, s32 a3); +extern s32 func_8014C43C(void * a0, s32 a1, s32 a2, s32 a3, s16 a4); +extern s32 ratan2(s32 dx, s32 dy); +extern s32 func_8014C5FC(s32 a0, s32 a1, void *a2); +extern s16 func_8014C5D0(s32 a0, s32 a1); +extern s32 func_8014C5FC(s32 a0, s32 a1, void * a2); +extern u8 D_80126D17; +extern void func_8014C6AC(void); +extern void func_8014C6C0(void); +extern u8 D_80126D1E; +extern void func_8014C6D0(void); +extern void func_8014C6E0(void); +extern s32 func_8014C860(s32 a0, s32 a1); +extern void func_8014C8C8(s32 a0, s32 *a1); +extern void func_8014C88C(s32 a0); +extern void func_8014C8C8(s32 dst, s32 * src); +extern void func_8014C8F0(s32 arg0); +extern u8 D_801151F0[]; +extern s32 func_8014C918(s32 a0, s32 a1); +extern s32 D_80126B50; +extern void func_8014C968(void); +extern s32 func_8014C98C(void); +extern void func_80139914(s32 a0); +extern s32 func_8014CA00(s32 a0); +extern u16 func_8014CA70(s32 a0, s32 a1); +extern s32 func_8014CA14(s32 a0, s32 a1); +extern u16 func_8014CAE4(s32 *a0, s32 a1); +extern s32 func_8014CA88(s32 *a0, s32 a1); +extern s32 func_8014CAFC(void); +extern s32 func_8014CB0C(void); +extern s32 func_8014CB1C(void); +extern u8 D_80126D1F; +extern s32 func_8014CB2C(void); +extern s32 func_8014CB58(void); +extern u8 D_80126D1D; +extern void func_8014CB68(void); +extern s32 func_8014CB7C(void); +extern s32 func_8014CB8C(void); +extern struct Packed8 D_80126C98; +extern short D_80126C9E; +extern void func_8014CB9C(struct Packed8 *a0); +extern s32 D_80126CDC; +extern void func_8014CBD8(void); +extern void func_8014CBF8(void *a0); +extern void func_8014D3E0(s32 a0); +extern void func_8014D04C(void); +extern void func_8014CCB4(void); +extern void func_8014CC28(s32 a0); +extern void func_8014CD0C(u8 *a0); +extern void func_8014CF04(); +extern void func_8014CD80(s32 a0, void *a1, void *a2); +extern s32 func_8014D2A0(s32 a0, void *a1, void *a2); +extern s32 func_8014D12C(s32 a0, void *a1, void *a2); +extern void func_8014D0A4(s32 a0); +extern void func_8014D610(s32 a0, void *a1, void *a2); +extern s32 func_8014D4C0(s32 a0, void *a1, void *a2); +extern void func_8014D438(s32 a0); +extern s32 func_8014DD8C(s32 a0, void *a1, void *a2); +extern s32 func_8014D820(s32 a0, u16 *a1, u16 *a2); +extern void func_8014D790(s32 a0); +extern s32 func_8014DCE0(s32 arg0, s32 arg1, s32 arg2); +extern s32 func_8014DD8C(s32 arg0, void *arg1, void *arg2); +extern s32 func_8014E284(s32 a0, s16 *a1, s16 *a2); +extern s32 func_8014E048(s32 a0, u16 *a1, u16 *a2); /* u16*: def lhu semantics (T5b reconcile; ptr param type codegen-neutral for the caller) */ +extern void func_8014DF94(s32 arg0); +extern s32 func_80135A4C(s32 a0, s32 a1, s32 *a2, s32 a3); +extern u8 D_801152A8[]; /* canonical TU type (engine_core) — read via *(u16*) cast */ +extern s32 func_8014E048(s32 param_1, u16 * param_2, u16 * param_3); +extern s32 func_80135A4C(s32 a0, s32 a1, s32 *a2, s32 a3); /* canonical (engine_core.h:11555) */ +extern s32 func_8014E284(s32 a0, s16 *arg1, s16 *arg2); +extern void func_8014E5B4(s32 a0, void *a1, void *a2); +extern s32 func_8014E514(u8 *a0, s32 a1, s32 a2); +extern void func_8014E48C(s32 a0); +extern s32 func_8014E83C(s32 a0, s16 *a1, s16 *a2); +extern s32 func_8014E790(s32 a0, s16 *a1, s16 *a2); +extern void func_8014E6F8(struct SubE6F8 *a0); +extern s32 func_8014E790(s32 arg0, s16 * arg1, s16 * arg2); +extern s32 func_8014E83C(s32 arg0, s16 * arg1, s16 * arg2); +extern s32 func_8014EA4C(void *a0, void *a1, void *a2, s32 a3); +extern s32 func_8014E98C(void *a0); +extern u16 D_800B99DA; +extern s32 D_801150D8; +extern s16 D_80126724; +extern s32 func_8014EA4C(void * a0, void * a1, void * a2, s32 _arg3); +extern s32 func_8014EE14(s32 a0, s16 *a1, s16 *a2); +extern s32 func_8014ED80(struct SubED80 *a0); +extern s32 func_8014EE14(s32 arg0, s16 * arg1, s16 * arg2); +extern s32 func_8014F2E0(s32 a0, s16 *a1, s16 *a2); +extern s32 func_8014F24C(struct SubF24C *a0); +extern s32 func_8014F2E0(s32 arg0, s16 * arg1, s16 * arg2); +extern void func_8014F4C0(u8 *a0); +extern s32 func_8014F468(void); +extern s32 D_801152BC; +extern int func_8014F74C(s32 arg0); +extern s32 func_8014FA70(s32 a0); +extern void func_8014FA04(s32 a0); +extern s32 func_8014FC18(u8 *self); +extern int func_8014FD54(int param_1); +extern s32 func_80150170(void *a0); +extern s32 func_8014FE60(void *a0); +extern void func_8014FDF4(struct S8014FDF4 *a0); +extern s32 func_80150150(s32 a, s32 b); +extern s32 func_801502EC(s32 e, void *a1, void *a2); +extern s32 func_80150460(s32 e, s32 a1); +extern s32 func_80150170(void *e); +extern s32 func_80150460(s32 a, s32 b); +extern s32 func_80150528(void *a0, void *a1, void *a2); +extern void func_801504D8(u16 *a0); +extern s32 func_80150528(void *arg0, void *arg1, void *arg2); +extern s32 func_801506A4(s32 a0, s32 a1); +extern s32 func_801505FC(s32 a0); +extern void func_80150820(s32 a0, s32 a1); +extern void func_8015086C(int param_1); +extern s32 func_801508B4(s32 a0); +extern s32 func_8015094C(s32 a0); +extern short func_801508F8(s32 a0); +extern s32 func_80021174(s32 a0, s32 a1); +extern s32 func_8015094C(s32 param_1); +extern void func_80150B28(int param_1); +extern void func_80150B9C(void); +extern s32 func_80151184(s32 a0, s32 a1, s32 a2); +extern s32 func_80150BA4(s32 a0); +extern s32 func_801619D0(void *a0); +extern void func_80150BC8(s32 *a0); +extern s32 func_80150480(s32 a0); +extern u16 D_800AE6DC; +extern void func_80150C48(s32 a0); +extern int func_80151184(int arg, int a1, int a2); +extern int func_80150CA0(int arg); +extern void func_80150EC4(s32 a, s32 b); +extern void func_80150CC4(s32 a); +extern void func_80150CE4(s32 a); +extern void func_80150D04(s32 a); +extern void func_80150D24(s32 a); +extern void func_80150D44(s32 a); +extern void func_80150D64(s32 a); +extern void func_80150D84(s32 a); +extern void func_80150DA4(s32 a); +extern void func_80150DC4(s32 a); +extern void func_80150DE4(s32 a); +extern void func_80150E04(s32 a); +extern void func_80150E24(s32 a); +extern void func_80150E44(s32 a); +extern void func_80150EC4(s32 a0, s32 a1); +extern void func_80150E64(s32 a0); +extern void func_80150E84(s32 a0); +extern void func_80150EA4(s32 a0); +extern u8 D_800AE6C0; +extern s16 D_800AE6C8; +extern s16 D_800AE6CA; +extern s16 D_800AE6CC; +extern s32 D_800AE6C4; +extern s16 D_800AE6CE; +extern u8 D_800AE6BE; +extern u8 D_801201F8[]; +extern void func_80150F78(void); +extern void func_80150F80(s32 a0); +extern int func_80150FB4(int arg); +extern void func_80150FD8(s32 a0); +extern int func_80151014(int arg); +extern void func_80151038(s32 a0); +extern int func_80151070(int arg); +extern int func_80151094(int arg); +extern void func_801510B8(void); +extern void func_801510C0(void); +extern int func_801510C8(int arg); +extern int func_801510EC(int arg); +extern s32 func_80151110(void); +extern void func_80151130(void); +extern int func_80151138(int arg); +extern void func_8015115C(s32 *a0, s16 a1); +extern s32 func_80151164(s32 a0, s32 a1); +extern s32 func_80151184(s32 arg0, s32 arg1, s32 arg2); +extern void func_801511A8(u8 *a0); +extern void func_801511C4(u8 *a0); +extern int func_80151204(int arg, int a1); +extern int func_801511E0(int arg); +extern int func_80151204(int a0, int a1); +extern void func_80151238(void *a0); +extern void func_8015126C(u16 *p); +extern void func_80151780(s32 a0); +extern void func_801516F0(s32 *a0); +extern void func_8015173C(s32 *a0); +extern s16 D_8011DB1A; +extern s32 D_80127518; +extern s32 D_801151FC; +extern s32 func_801725CC(u8 *a0); +extern s32 func_80029D3C(void); +extern void func_80151878(void); +extern void func_80153B58(s32 *a0); +extern s32 func_80151880(s32 a0); +extern s32 func_801518D8(s32 a0); +extern s32 func_80151944(void); +extern s32 func_80151924(void); +extern void func_8014E934(s32 a0); +extern s32 func_8014F3E8(s32 a0); +extern void func_801519C8(s32 a0); +extern void func_80151980(s32 a0); +extern M2C_UNK D_800D5880; +extern s32 D_800D58AC; +extern void func_80154274(s32 *a0, s32 a1); +extern void func_80154A74(s32 a0, s32 a1); +extern void func_801519C8(s32 arg0); +extern void func_80151C54(s32 a0); +extern void func_801542DC(s32 *a0, s32 a1); +extern void func_8015BDD0(s32 *a0); +extern void func_80165718(s32 a0); +extern u8 D_800D46E4[]; +extern void func_80151AE4(s32 arg0); +extern void func_80151D24(void *a0); +extern void func_80151DB0(s32 a0); +extern void func_80151D60(void *a0); +extern s32 func_80172630(u8 *a0); +extern s32 D_80062C14; +extern void func_80151DB0(s32 param_1); +extern void func_80151E78(s32 *a0); +extern void func_80151ECC(struct S80151ECC *a0); +extern void func_80151FB4(s32 a0); +extern void func_80151F38(s32 *a0); +extern void func_801553C0(s32 a0); +extern void func_80153C18(); +extern void func_80152058(void *a0); +extern void func_801520DC(s32 a0); +extern void func_80152094(s32 a0); +extern void func_80147324(s32 a0); +extern void func_801520DC(s32 arg0); +extern void func_801470B4(s32 a0); +extern void func_8015369C(s32 a0); +extern void func_80152194(s32 *a0); +extern s32 func_801536DC(s32 a0); +extern void func_8015220C(s32 a0); +extern s32 func_80153800(s32 a0); +extern void func_801522CC(s32 a0); +extern void func_80152254(s32 *a0); +extern void func_80152370(void *a0); +extern void func_801523F4(s32 a0); +extern void func_801523AC(s32 a0); +extern void func_8001382C(s32 a0, void *a1, void *a2); +extern void func_801523F4(s32 arg0); +extern void func_801525F4(int); +extern s32 func_801535F4(void *arg0); +extern void func_8015BF48(s32 *a0); +extern void func_80152500(int param_1); +extern void func_801525F4(s32 a0); +extern void func_80152698(void *a0); +extern void func_80152714(s32 a0); +extern void func_801526D4(s32 a0); +extern void func_80152790(s32 a0); +extern void func_8015282C(void *a0); +extern void func_801528B0(s32 a0); +extern void func_80152868(s32 a0); +extern void func_801528B0(s32 arg0); +extern void func_8015294C(s32 a0); +extern void func_80152A08(s32 a0); +extern void func_80152AC8(s32 a0); +extern void func_80152A50(s32 *a0); +extern void func_80152B6C(void *a0); +extern void func_80152BF0(s32 a0); +extern void func_80152BA8(s32 a0); +extern void func_80152C80(s32 *a0); +extern void func_80152C40(s32 *a0); +extern void func_80152C80(s32* a0); +extern void func_80152D24(void *a0); +extern void func_80152DA8(s32 a0); +extern void func_80152D60(s32 a0); +extern void func_80152DA8(s32 arg0); +extern void func_80152E4C(s32 a0); +extern void func_80152EFC(s32 a0); +extern void func_80152FBC(s32 a0); +extern void func_80152F44(s32 *a0); +extern void func_80153060(void *a0); +extern void func_801530E4(s32 a0); +extern void func_8015309C(s32 a0); +extern void func_80155440(s32 *a0); +extern u8 D_80062C04[]; +extern void func_801530E4(s32 arg0); +extern void func_80153150(struct S80153150 *a0); +extern void func_801531BC(s32 a0); +extern void func_8015327C(s32 a0); +extern void func_80153204(s32 *a0); +extern void func_80153320(void *a0); +extern void func_801533A4(s32 a0); +extern void func_8015335C(s32 a0); +extern void func_80153410(s32 *a0); +extern void func_80153490(s32 a0); +extern void func_80153550(s32 a0); +extern void func_801534D8(s32 *a0); +extern void (*D_8011DB28)(s32 a0); +extern s32 func_801536DC(s32 param_1); +extern void func_800139C8(s32 a0, void *a1, void *a2); +extern s32 func_80153978(s32 a0, u16 *src); +extern s32 func_80133784(s32 a0, void *src, s32 dst); +extern s32 func_801539F8(s32 a0, void *a1); +extern s32 func_801539F8(s32 a0, void * a1); +extern s32 func_8016DA04(s32 a0); +extern s32 func_80153BD8(s32 a0); +extern s32 func_80153BF0(s32 a0); +extern void func_80153C18(void); +extern u16 D_8011F748; +extern void func_80153C30(void); +extern void func_80153C74(s16 a0, s16 a1); +extern s16 D_8011DB18; +extern void func_80153C44(int a0, int a1, s16 a2); +extern s16 D_8011DB0C; +extern s32 D_80115210; +extern void func_80153C8C(void); +extern void func_80153C9C(void); +extern s32 func_80153CBC(void); +extern void func_80153CCC(S80153CCC *a0); +extern void func_80153D7C(s32 a0); +extern void func_80153D34(s32 a0); +extern void func_80153D7C(s32 param_1); +extern void func_8015410C(void); +extern void func_80153E00(s32 param_1); +extern void func_80151664(void); +extern void func_80154134(u8 *a0); +extern void func_80154190(u8 *a0, s32 a1); +extern void func_80154150(s32 a0, s32 a1); +extern void func_80154218(u8 *a0, s32 a1, s32 a2); +extern void func_801541D8(u8 *a0, s32 a1, s32 a2); +extern s32 func_801549F8(s32 a0, s32 a1, s32 a2); +extern void func_801542A4(); +extern void func_801542A4(s32 *a0, s32 a1); +extern void func_8015430C(); +extern void func_8015430C(u8 *arg0, s32 arg1, s32 arg2); +extern void func_8015444C(void *a0, s32 *a1, s32 *a2, s32 *a3); +extern s32 func_80154358(void * arg0); +extern void func_80154AB4(s32 a0, s32 a1); +extern void func_80154B20(s32 a0, s32 a1, s32 a2); +extern void func_80154AE0(s32 a0, s32 a1, s32 a2); +extern void func_80154B7C(u8 *a0, s32 a1); +extern void func_80154B4C(u8 *a0, s32 a1); +extern void func_80154BC8(void *a0, s32 a1, s32 a2); +extern void func_80154B98(void *a0, s32 a1, s32 a2); +extern void func_80154ED8(s32 a0, s32 a1); +extern void func_80154C24(s32 param_1, s32 *param_2, s32 *param_3); +extern u8 D_800D8D10[]; +extern s16 D_80078E9E; +extern void func_801550FC(s32 a0); +extern void func_80154F9C(s32 a0); +extern void func_801550FC(s32 arg0); +extern void func_8001D150(s32, s32); +extern void func_8001D130(int, int); +extern void func_80155150(int param_1); +extern s32 D_800DE2A4[]; +extern void func_801552F4(s32 a0); +extern void func_80155344(s32 a0); +extern s32 func_80155394(s32 *a0); +extern void func_801553A8(s32 *a0); +extern s32 func_80155458(s32 param_1); +extern s32 func_801659DC(u8 *a0); +extern s32 func_801554B8(void *arg0); +extern void func_801555F4(void *a0); +extern void func_80155518(s32 *a0); +extern void func_80155580(void *a0); +extern s32 func_80161104(void); +extern void func_801555F4(void *); +extern void func_801555BC(void *a0); +extern int func_80155A44(int param_1); +extern int func_80161208(); +extern u8 D_800D4DA8[]; +extern void func_80155B20(s32 *a0); +extern s32 D_800D4DB4; +extern void func_80155B9C(s32 a0); +extern u8 D_800D4DD4[]; +extern void func_80155C0C(s32 *a0); +extern void func_8014ED28(s32 a0); +extern int func_80155FF8(int arg, int a1); +extern s32 D_800D4DF4; +extern void func_80155C64(s32 a0); +extern void func_8015E880(s32 *a0); +extern void func_80155D70(s32 param_1); +extern void func_80155E30(void *a0); +extern s32 func_80161208(); +extern void func_80155EA4(void *arg0); +extern void func_80155F58(void); +extern s32 func_80155F80(); +extern s32 func_80155F60(void); +extern s32 func_80155F80(s32 a0); +extern int func_80155FB0(int arg, int a1); +extern int func_80155FD4(int arg, int a1); +extern int func_80156044(int arg, int a1); +extern S801563EC *func_801563EC(u16 idx); +extern s32 func_80029B4C(s32 a0, s32 a1); +extern s32 func_80029BC8(s32 a0, s32 a1); +extern s32 func_80029C44(s32 a0, s32 a1); +extern s32 func_8015640C(s32 a0, s32 a1); +extern u32 func_8015616C(s32 param_1, u16 param_2); +extern u16 func_80156370(u16 param_1); +extern S801563EC * func_801563EC(u16 idx); +extern s32 func_801564B0(s32 a0); +extern s32 D_801151E0[]; +extern s32 func_801565C0(void); +extern void func_80156A14(s32 *a0); +extern void func_80156648(s32 *a0); +extern u8 D_8011DAD8[]; +extern s32 func_8014C568(void *a0); +extern void func_801567BC(s32 a0); +extern B8 D_80128120[]; +extern B8 D_80128138[]; +extern S8 D_80126AF0[]; +extern u8 D_80126730[]; +extern void func_80156848(s32 param_1, s32 param_2); +extern void func_80156A1C(s32 param_1, s32 param_2); +extern s32 D_801150E0[]; +extern void func_80156A88(s32 a0, s32 a1); +extern void func_80156B74(s32 param_1, u32 param_2, u8 *param_3); +extern void func_80156ECC(int param_1, int param_2, int param_3, int param_4, int param_5); +extern void func_80156FA8(s16 *param_1, s16 *param_2, s16 *param_3); +extern void func_80157158(s32 a0, u16 a1, u16 a2, s32 a3, s32 a4, s32 a5, s32 a6, s32 a7, s32 a8, s32 a9, u16 a10, s32 a11, s32 a12); +extern s32 func_80135004(s32 a0, void *a1, s32 a2); +extern s32 func_80135260(s32 a0, s32 a1, s32 a2, s32 a3); +extern u32 func_801571C4(s32 a0, u16 a1, u16 a2, s32 a3, s32 a4, s32 a5, s32 a6, s32 a7, s32 a8, s32 a9, u16 a10, s32 a11, s32 a12); +extern void func_801575E4(void *a0); +extern void func_801574DC(s32 *a0); +extern void func_80157544(void *a0); +extern void func_8014CC28(s32 a0); /* defined */ +extern s32 func_8014F3E8(s32 a0); /* declared */ +extern void func_8015BDD0(s32 *a0); /* defined */ +extern void func_801575E4(void *a0); /* defined */ +extern void func_80157580(s32 arg0); +extern u8 D_800D4F14[]; +extern void func_801576A8(void *arg0); +extern s32 func_8015773C(u8 *a0); +extern s32 func_8015771C(u8 *a0); +extern s32 func_8015773C(u8 * arg0); +extern void func_801578C0(s32 a0); +extern void func_80157788(int param_1); +extern void func_80157808(s32 a0); +extern void func_801577C8(int param_1); +extern void func_80157880(s32 a0); +extern s32 func_801725A4(u8 *a0); +extern void func_801578C0(s32 param_1); +extern void func_80147A84(int); +extern void func_80148038(int, int); +extern void func_80147460(int); +extern void func_80146D90(int); +extern void func_80161450(void *a0); +extern void func_80157A8C(int); +extern void func_80154A74(int, int); +extern void func_8015795C(int param_1); +extern void func_80161D20(s32 a0, s32 a1); +extern void func_80157A8C(s32 a0); +extern void func_8016706C(s32 a0); +extern u8 D_800D51AC[]; +extern void func_80157AC8(s32 param_1); +extern void func_80157B74(int param_1); +extern void func_8016158C(void *a0); +extern void func_8015BE04(s32 *a0); +extern void func_80157BC8(s32 a0); +extern void func_80157CCC(s32 a0); +extern void func_80157DC4(void *a0); +extern void func_80157FC4(void *a0); +extern void func_80157D74(u16 *a0); +extern void func_80157E38(void *); +extern void func_80157E00(void *a0); +extern void func_80157E38(void * a0); +extern s32 func_80157F64(s32 *a0); +extern s32 func_80156600(void *a0); +extern void func_80157EA4(void *a0); +extern void func_80158038(void *); +extern void func_80158000(void *a0); +extern void func_80158038(void * param); +extern u8 D_800D524C[]; +extern void func_80161418(void *a0); +extern void func_801580B4(s32 a0); +extern void func_801581AC(s32 a0); +extern void func_8015824C(void *a0); +extern void func_801582C0(void *); +extern void func_80158288(void *a0); +extern u8 D_800D52A8[]; +extern void func_801585A4(s32 *a0); +extern void func_801582C0(void *a0); +extern s32 func_801585AC(s32 *a0); +extern u8 D_800D52E8[]; +extern void func_80158344(s32 *a0); +extern s32 func_801615C4(void *a0, s32 a1); +extern void func_80158434(s32 param_1); +extern void func_80158548(s32 param_1); +extern void func_801585EC(u8 *a0); +extern void func_80158794(void); +extern void func_80158880(s32 *param); +extern void func_8015879C(s32 param_1); +extern void func_80158814(void *arg0); +extern int func_800D0CA0(int); +extern int func_8001AAA0(int); +extern int SsGetMute(void); +extern s32 func_80159464(void); +extern void func_801588CC(int param_1); +extern void func_80158AE4(void *a0); +extern void func_80158AB4(void *a0); +extern void func_8016F264(void); +extern void func_80165840(void); +extern void func_801658DC(void); +extern void func_80165A78(s32); +extern void func_80158AE4(void * a0); +extern void func_80158BB0(void *arg0); +extern s32 func_80159404(s32 a0, s32 a1); +extern void func_80158C40(s32 *a0); +extern void func_80158CD8(s32 *a0); +extern s32 func_80159434(s32 a0, s32 a1); +extern void func_80158D60(s32 a0); +extern M2C_UNK D_800D5904; +extern void func_80158E24(s32 *a0); +extern int rand(void); +extern void func_80158F00(int param_1); +extern s32 func_801399F0(s32); +extern void func_80139914(s32); +extern void func_801594E8(s32, s32); +extern void func_80158FA4(s32 param_1); +extern u8 D_80110C94[]; +extern u8 D_80110CD4[]; +extern void func_80159070(void *a0); +extern s32 func_80029A94(s32); +extern void func_80175454(void); +extern void func_800298BC(void *); +extern void func_8002992C(s32); +extern void func_800CF804(void); +extern void func_800CF818(void); +extern u8 D_80110D0C[]; +extern u8 D_80110C3C[]; +extern void func_80159120(s32 a0); +extern void func_801592CC(s32 *a0); +extern void func_8015934C(void *arg0); +extern void func_801593E4(A801593E4 *a0); +extern s32 func_800291B4(s32); +extern void func_80029274(void); +extern void func_80029044(void); +extern void func_8002906C(void); +extern void func_80029094(void); +extern void func_8002941C(void); +extern void func_8002AB64(void); +extern void func_800D185C(u8 *); +extern void func_800D1F90(void); +extern void func_801594E8(s32 param_1, s32 param_2); +extern void func_80159698(void *a0); +extern s32 func_801596D4(void *a0); +extern void func_80174B6C(void); +extern void func_8013C938(void); +extern void func_8002850C(s32, s32, s32); +extern void func_80028620(s32, void *); +extern s32 func_801596F0(s32 param_1); +extern s32 func_80159874(void); +extern void func_800167B8(s32 a0); +extern s32 func_8015987C(s32 a0); +extern int func_800167F0(int arg); +extern int func_801598BC(void); +extern void func_80159968(void *a0); +extern void func_801598E0(u8 *a0); +extern void func_80159A20(void *a0); +extern void func_801599E0(void *a0); +extern void func_80159A18(void); +extern void func_80159BE4(s32); +extern void func_80159B08(s32 *a0); +extern void func_80159B70(void *a0); +extern void func_80159B3C(void * a0); +extern void func_80159BAC(s32 a0); +extern s32 func_80172590(u8 *a0); +extern void func_80159BE4(s32 arg0); +extern void func_8015A1C8(s32 a0); +extern void func_8015A2D8(s32); +extern void func_8015A1FC(s32 *a0); +extern void func_8015A264(void *a0); +extern void func_8015A230(s32 *a0); +extern void func_8015A2A0(s32 a0); +extern s32 func_80172608(u8 *a0); +extern void func_8015A2D8(s32 param_1); +extern u8 D_800D48DC; +extern s32 func_8015AB7C(s32 a0); +extern s32 D_8011F9C4; +extern s32 func_8015ABD4(s32 a0, s32 a1, s32 a2); +extern s32 func_80161CD0(s32 a0, s32 a1); +extern void func_8015AC48(s32 arg0); +extern void func_8015AC90(s32 a0); +extern void func_8015ADB0(s32 a0); +extern void func_8015ACC4(s32 *arg0); +extern void func_8015AD3C(void *a0); +extern void func_8015AD08(void *arg0); +extern void func_8015ADB0(s32); +extern void func_8015AD78(s32 a0); +extern void func_8015ADB0(s32 arg0); +extern s32 D_800D4A9C; +extern int func_8015B6F4(int param_1); +extern u8 D_800D4F8C[]; +extern s32 func_8015B7B4(s32 a0); +extern u8 D_800D4BE0[]; +extern s32 func_8014A51C(); +extern s32 func_8015B858(u8 *a0); +extern s32 D_800D4B48; +extern void func_8015B8F8(s32 *a0); +/* ==== end §8b carried decl layer ==== */ + + +extern s32 func_8015AE2C(); + +// @class: plumbing +// @stuck: none — MATCH (271/271, pin-free, zero asm). The ONLY residual is DEF-SIDE plumbing, and it is now named exactly: the in-TU instantiation `DEFINE_func_8015BEE4()` (engine_core.h:1851-1855) expands to `extern s32 func_8015B950(void);` INSIDE ov_SC01_077_jr_8015AE2C.c, ~14 lines BELOW this definition, so the 1-param def collides with a `(void)` prototype -> `conflicting types for func_8015B950` (.run/bank_func_8015B950.log). §73 PARAMS axis / T0. Surgical fix = §65b de-macroize that ONE instantiation (blast radius: this TU); the fleet-wide `(void)`->`()` header edit is §63 and must be R22-validated. +/* func_8015B950 (ov_SC01_077_jr_8015AE2C, 271 ins, jtbl_801D8B74) — SESSION-21 re-verified + * + * ── ROUND-2 INDEPENDENT RE-VERIFICATION (2026-07-27, fresh agent, §88e discipline) ───────────── + * match_one : MATCH (271 ins) against the CURRENT tree — §87 staleness re-checked today. + * .text size: compiled .text = 0x43C = 1084 B = 271 ins, EXACTLY the target's declared 0x43C + * ("nonmatching func_8015B950, 0x43C"). So this is NOT a §83a length drift hiding + * behind a zero count — the count is over equal-length streams. + * jtbl : RE-DECODED MECHANICALLY, not inherited. Compiled .rodata = 0x1C = 28 B = 7 words, + * 7x R_MIPS_32 -> .text with implicit addends [58,58,58,E0,F0,100,58]; +0x8015B950 + * = [8015B9A8, 8015B9A8, 8015B9A8, 8015BA30, 8015BA40, 8015BA50, 8015B9A8]. + * Diffed word-for-word against asm/ov_SC01_077/data/tail14.data.s:15-23 — 7/7 identical. + * symcheck : SYMS-DIFF target=35 draft=34, sole MISSING = jtbl_801D8B74. This is the §81 jr + * FALSE POSITIVE, re-confirmed here by reading the relocs: gcc emits its OWN table and + * references it with R_MIPS_HI16/LO16 against the SECTION `.rodata` (t.o +0x40/+0x48), + * so the splat's dlabel NAME can never appear in the draft object's relocation set. + * Nothing is dropped and nothing is invented: the draft's other 34 symbols are exactly + * the target's other 34. + * FAMILY : the x138 remap is clean and §84-safe. Every sibling is 271 ins with an IDENTICAL + * callee set; only THREE names vary per overlay — the two data labels and the jtbl: + * ov_SC01_077 D_80185560 / D_801855CC / jtbl_801D8B74 + * ov_SC03_099 D_80185A50 / D_80185ABC / jtbl_801BD898 + * ov_SC06_008 D_80187E44 / D_80187EB0 / jtbl_801A8734 + * The pair is always +0x6C apart, and NO literal in this draft encodes that distance + * (both labels are referenced by name), so there is no §84 derived-offset hazard. + * D_8011F9C4 is fleet-constant (main-EXE data) and must NOT be remapped. + * + * match_one: MATCH (271 ins) against the CURRENT tree (§87 staleness re-checked, 2026-07-27). + * PIN-FREE, zero asm, offset-pure (s32 arg0 + raw offsets) — x138 template-safe. + * Provenance: this is the Phase-26 crack (.run/phase26-cracks/func_8015B950.c) re-gated verbatim, + * with ONE deliberate change: the definition's return type void -> s32. + * - `void func_8015B950(s32 arg0)` : MATCH (271 ins) [the Phase-26 form] + * - `s32 func_8015B950(s32 arg0)` : MATCH (271 ins) [shipped — §3a-1 void->s32 is byte-neutral] + * The fleet/engine_core.h canonical decl is `extern s32 func_8015B950(void);` (engine_core.h:1852), + * and the last bank attempt (.run/bank_func_8015B950.log) died on `conflicting types for + * func_8015B950`. Shipping the s32 return kills the §73 RETURN axis for free and leaves only the + * cheap T0 PARAMS axis for the ladder (fix_header_decl.py / --fix-def-sig / cast_call_sites). + * Both forms are byte-identical, so the orchestrator may swap the return type back at zero cost. + * + * SYMBOLS (§58 rules 1/2 — all splat spellings, all verified present): + * D_801855CC asm/ov_SC01_077/data/tail.data.s:4355 (the state-handler vtable) + * D_80185560 asm/ov_SC01_077/data/tail.data.s:4293 + * D_8011F9C4 main-EXE data; spelled `extern s32 D_8011F9C4;` in 5+ already-banked TUs + * jtbl_801D8B74 asm/ov_SC01_077/data/tail14.data.s:15 (compiler jump table — not named in C) + * + * JTBL VERIFIED (§8a gate): compiled .rodata = exactly 0x1C B / 7 words, 7x R_MIPS_32 .text with + * addends [0x58,0x58,0x58,0xE0,0xF0,0x100,0x58] -> +0x8015B950 = [B9A8,B9A8,B9A8,BA30,BA40,BA50, + * B9A8] == the original words at 0x801D8B74..0x801D8B8C. Bound `sltiu $v0,$v1,0x7` matches. + * The raw dlabel's 8th word 0x00000000 is NOT an entry — it is the intra-TU `.align 3` pad of the + * B34/B54/B74 jtbl chain; the object can never emit it (maspsx drops .align), so it must stay in + * the post-carve RAW data piece (the §53/§62/§81 carve chain applies at bank time). + * + * Same family as the TU's own already-matched func_8015AE2C: 7-case switch on ((s32 (*)(s32))func_801619A4)() + * (0/1/2/6 shared, 3/4/5 own, no default block — out-of-range and every `break` fall to the + * after-switch join), then a chain of "state handler" tests, each dispatching + * D_801855CC[*(u16*)arg0](arg0) and returning. + * + * THREE LEVERS (draft -> MATCH in 3 compiles): + * + * 1. PROLOGUE CONSTANT = an INITIALIZED LOCAL, not a literal in the compare. + * Target opens with `lui $s2, 0xFFF5` in the *prologue*, used once ~200 ins later in + * `slt $v0,$s2,$s1`. No gcc-2.7.2 pass hoists a (set reg const_int) across basic blocks + * (loop.c needs a loop; cse/combine/sched never move insns between BBs) — so the insn must + * have been EMITTED in the first BB, i.e. the constant is a local initialized at the top of + * the function. cse then cannot fold it back into the compare: the `slt` operand predicate is + * `arith_operand`, which rejects a CONST_INT wider than 16 bits, so validate_change fails and + * the pseudo survives. Its live range spans every call -> global.c gives it a callee-saved reg. + * Writing `z > -0xB0000` inline instead emits the `lui` into the branch delay slot next to the + * compare (caller-saved $v0) and the function is 1 insn short. => `s32 lim = -0xB0000;` at top. + * + * 2. `lh` vs `lhu`: a short->short copy is a pure HImode move and gcc emits `lhu`. The target's + * `lh $v0,0x26($s0)` means the value passed through an SImode (int) temp: expand makes + * (set (reg:SI) (sign_extend (mem:HI))) + (set (mem:HI) (subreg:HI ...)), and combine cannot + * merge them (the merged form is mem<-mem, which no movhi accepts) so the sign-extending load + * survives. => route both halfword copies through the `s32 t` temp. + * + * 3. THE `goto` LAYOUT — dodging jump.c's store-flag conversion (jump.c:1005-1065). + * An if/else chain writing 0/1 into `doit` makes gcc collapse the last pair into + * `sltiu $v0,$v0,1`. jump.c fires that conversion when the insn immediately after a + * conditional jump is a lone `SET pseudo, CONST_INT` whose following simplejump targets the + * SAME label as the branch (jump.c:1038 `reallabelprev == temp || ... JUMP_LABEL(temp4) == + * JUMP_LABEL(insn)`) — exactly the shape of `if (c) x=0; else x=1;`. + * The target instead cross-jumps ALL the `doit=0` exits into ONE shared block placed after the + * `doit=1` fall-through; reorg's fill_slots_from_thread then COPIES that single set into all + * three branch delay slots and redirects each branch past it (which is why `addu $v0,$zero, + * $zero` appears 3x in delay slots and the shared block vanishes). A `goto zero;` / `goto one;` + * chain expresses that layout directly, and each conditional jump is then followed by a + * compare/call rather than a lone const set, so the store-flag conversion never triggers. + * GENERAL RULE: multiple predicates that all assign the SAME constant to one flag => write + * them as `goto` to a shared assignment, never as an if/else ladder. + */ +extern s32 D_8011F9C4; + +extern s32 func_80161B18(void); +extern s32 func_801619A4(s32*); +extern s32 func_80149AA8(s32*); +extern void func_80149AD4(s32*); +extern s32 func_80149B54(s32*); +extern void func_80149BAC(s32*); +extern s32 func_801498E0(s32*); +extern s32 func_80149954(s32); +extern s32 func_80149A64(s32*); +extern void func_800CCCC0(s32 a0); +extern s32 func_80149CD4(s32 a0); +extern void func_8015E880(s32*); +extern s32 func_80149744(struct S_80149744*); +extern void func_80149788(void); +extern s32 func_801496D4(void*); +extern void func_80149704(void); +extern int func_80148AFC(void*); +extern void func_80146D90(s32 a0); +extern void func_80154150(s32 a0, s32 a1); +extern void func_801541D8(u8*, s32, s32); +extern s32 func_801488A8(u8*); +extern void func_80147078(s32*, s16); +extern void func_8015A264(void*); +extern s32 func_80013294(void*, void*); +extern void func_80159B70(void*); +extern s32 func_8016F1AC(void); +extern s32 func_80029178(s32 a0); +extern void func_80146DB8(s32*, s32*); +extern s32 func_80161CD0(s32, s32); +extern s32 func_80161208(s32 a0); +extern s32 func_801725A4(u8*); + +s32 func_8015B950(s32 arg0) +{ + + extern void (*D_801855CC[])(void *); + extern s32 D_80185560; + s16 sp10[4]; + s16 sp18[4]; + s32 t; + s32 z; + s32 doit; + s32 lim = -0xB0000; + + if (func_80161B18() != 0) { + return; + } + switch (((s32 (*)(s32))func_801619A4)(arg0)) { + case 0: + case 1: + case 2: + case 6: + if (((s32 (*)(s32))func_80149AA8)(arg0) != 0) { + D_801855CC[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149AD4)(arg0); + return; + } + if (((s32 (*)(s32))func_80149B54)(arg0) != 0) { + D_801855CC[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149BAC)(arg0); + return; + } + break; + case 3: + ((void (*)(s32))func_801498E0)(arg0); + break; + case 4: + ((void (*)(s32))func_80149954)(arg0); + break; + case 5: + if (((s32 (*)(s32))func_80149A64)(arg0) != 0) { + D_801855CC[*(u16 *)arg0]((void *)arg0); + func_800CCCC0(arg0); + return; + } + break; + } + if (func_80149CD4(arg0) != 0) { + D_801855CC[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_8015E880)(arg0); + return; + } + if (((s32 (*)(s32))func_80149744)(arg0) != 0) { + D_801855CC[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149788)(arg0); + return; + } + if (((s32 (*)(s32))func_801496D4)(arg0) != 0) { + D_801855CC[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149704)(arg0); + if (((u8)((s32 (*)(s32))func_80148AFC)(arg0)) == 0) { + func_80146D90(arg0); + } + if ((*(s32 *)(arg0 + 0x24) | *(s32 *)(arg0 + 0x2C)) != 0) { + func_80154150(arg0, 0xF); + } else { + ((void (*)(s32, s32, s32))func_801541D8)(arg0, 0xD, 6); + } + *(s32 *)(arg0 + 0x238) = 1; + return; + } + if (((s32 (*)(s32))func_801488A8)(arg0) != 0) { + sp10[0] = 0; + sp10[1] = 0; + sp10[2] = 0; + t = *(s16 *)(arg0 + 0x26); + sp18[0] = t; + sp18[1] = 0; + t = *(s16 *)(arg0 + 0x2E); + sp18[2] = t; + D_801855CC[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 1); + ((void (*)(s32))func_8015A264)(arg0); + t = -(((s32 (*)(s16 *, s16 *))func_80013294)(sp10, sp18) << 0x10); + if (t < *(s32 *)(arg0 + 0x2C)) { + *(s32 *)(arg0 + 0x2C) = t; + } + return; + } + if (*(u16 *)(arg0 + 0xB8) == 0x8000) { + D_801855CC[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 0); + ((void (*)(s32))func_80159B70)(arg0); + return; + } + z = *(s32 *)(arg0 + 0x2C); + if (func_8016F1AC() != 0) { + goto zero; + } + if (z <= lim) { + goto one; + } + if (D_8011F9C4 == 0) { + goto zero; + } + if (((u8)func_80029178(0x21)) != 0) { + goto zero; + } +one: + doit = 1; + goto join; +zero: + doit = 0; +join: + if (doit != 0) { + D_801855CC[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 0); + ((void (*)(s32))func_80159B70)(arg0); + func_80154150(arg0, 9); + ((void (*)(s32, s32 *))func_80146DB8)(arg0, &D_80185560); + ((void (*)(s32, s32))func_80161CD0)(arg0, *(u16 *)(arg0 + 0x16E)); + return; + } + if (func_80161208(arg0) == 0) { + ((void (*)(s32))func_801725A4)(arg0); + } +} + +DEFINE_func_8015BD8C() /* dedup: shared engine-core @0x8015bd8c (src/shared) */ + + +DEFINE_func_8015BDD0() /* dedup: shared engine-core @0x8015bdd0 (src/shared) */ + + +DEFINE_func_8015BE04() /* dedup: shared engine-core @0x8015be04 (src/shared) */ + + + + +void func_8015BE38(struct Obj *a0) { + + extern void (*D_80185740[])(void); + D_80185740[*(u16 *)((s32)a0 + 0x2)](); +} + + +DEFINE_func_8015BE74() /* dedup: shared engine-core @0x8015be74 (src/shared) */ + + +DEFINE_func_8015BE94() /* dedup: shared engine-core @0x8015be94 (src/shared) */ + + +DEFINE_func_8015BEC4() /* dedup: shared engine-core @0x8015bec4 (src/shared) */ + + +DEFINE_func_8015BEE4() /* dedup: shared engine-core @0x8015bee4 (src/shared) */ + + +DEFINE_func_8015BF04() /* dedup: shared engine-core @0x8015bf04 (src/shared) */ + + +DEFINE_func_8015BF48() /* dedup: shared engine-core @0x8015bf48 (src/shared) */ + + +DEFINE_func_8015BF7C() /* dedup: shared engine-core @0x8015bf7c (src/shared) */ + + +DEFINE_func_8015BFB0() /* dedup: shared engine-core @0x8015bfb0 (src/shared) */ + + + + +void func_8015BFF4(void *a0) { + + extern void (*D_8018574C[])(void); + D_8018574C[*(u16 *)((s32)a0 + 0x2)](); +} + + +INCLUDE_ASM("asm/ov_SC07_007/nonmatchings/ov_SC07_007_jr_8015B950", func_8015C030); + +DEFINE_func_8015C08C() /* dedup: shared engine-core @0x8015c08c (src/shared) */ + + +DEFINE_func_8015C0C4() /* dedup: shared engine-core @0x8015c0c4 (src/shared) */ + + +extern void func_8001382C(s32 a0, void *a1, void *a2); +extern void func_80146CA0(void *a0); +extern void func_80146DB8(s32 *a0, s32 *a1); +extern void func_80146E90(s32 *a0, s32 a1); +extern s32 func_80146E98(s32 a0); +extern void func_80147078(s32 *a0, s16 a1); +extern void func_80147324(s32 a0); +extern void func_801473EC(s32 *a0); +extern void func_80147A84(s32 arg0); +extern int func_80148AFC(void *a0); +extern s32 func_80149FB0(s32 a0); +extern void func_8014C010(s32 a0, s32 a1); +extern void func_8014CC28(s32 a0); +extern void func_8014D738(void); +extern s32 func_8014F3E8(s32 a0); +extern s32 func_8015BE94(); +extern void func_8015C0C4(s32 a0); + + + +s32 func_8015C128(s32 param_1) { + + extern u16 D_800B99DA; + extern void func_8015C6E0(int); + extern void (*D_801855CC[])(int); + + int sp10[3]; + int sp20[3]; + int temp_s0; + int temp_v0; + + ((void(*)())func_80149FB0)(); + if (((int(*)(int))func_80148AFC)(((int)param_1)) & 0xFF) { + sp10[0] = 0; + sp10[1] = 0; + sp10[2] = -0x4000; + ((void(*)(int, int *, int *))func_8001382C)(*(short *)(*(int *)(((int)param_1) + 0x20) + 0x12), sp10, sp20); + *(int *)(((int)param_1) + 0x234) += sp20[0]; + *(int *)(((int)param_1) + 0x238) += sp20[1]; + *(int *)(((int)param_1) + 0x23C) += sp20[2]; + } + ((void(*)(int, int *, int *))func_8001382C)((short)(-*(unsigned short *)(*(int *)(((int)param_1) + 0x20) + 0x12)), + (int *)(((int)param_1) + 0x234), sp20); + ((void(*)(int, int *))func_80146DB8)(((int)param_1), sp20); + func_80147A84(((int)param_1)); + ((void(*)(int))func_801473EC)(((int)param_1)); + if (!(D_800B99DA & 3)) { + ((void(*)(int, int))func_8014C010)(((int)param_1), 1); + ((void(*)(int))func_80147324)(0x65F); + } + if (((int(*)(int))func_8014D738)(((int)param_1)) != 0) { + D_801855CC[*(u16 *)((int)param_1)](((int)param_1)); + func_8015C6E0(((int)param_1)); + return; + } + temp_s0 = ((int(*)(int))func_8014CC28)(((int)param_1)); + temp_v0 = ((int(*)(int))func_8014F3E8)(((int)param_1)); + if (temp_v0 != 0) { + if ((temp_v0 & 0xFF00) != 0x4000) { + ((void(*)(int, int))func_80146E90)(((int)param_1), 6); + ((void(*)(int))func_80146CA0)(((int)param_1)); + return; + } + if ((temp_v0 & 0x4000) && ((int(*)(int))func_80146E98)(((int)param_1)) != 0) { + ((void(*)(int, int))func_80147078)(((int)param_1), 4); + ((void(*)(int))func_8015C0C4)(((int)param_1)); + } + } else if (temp_s0 == 0) { + D_801855CC[*(u16 *)((int)param_1)](((int)param_1)); + ((void(*)(int, int))func_80147078)(((int)param_1), 3); + ((void(*)(int))func_8015BE94)(((int)param_1)); + } +} + + + diff --git a/src/ov_SC07_008/ov_SC07_008_jr_8015AE2C.c b/src/ov_SC07_008/ov_SC07_008_jr_8015AE2C.c index 6ad39489e..47d7e7a15 100644 --- a/src/ov_SC07_008/ov_SC07_008_jr_8015AE2C.c +++ b/src/ov_SC07_008/ov_SC07_008_jr_8015AE2C.c @@ -1512,7 +1512,259 @@ DEFINE_func_8015B858() /* dedup: shared engine-core @0x8015B858 (src/shared) */ DEFINE_func_8015B8F8() /* dedup: shared engine-core @0x8015B8F8 (src/shared) */ -INCLUDE_ASM("asm/ov_SC07_008/nonmatchings/ov_SC07_008_jr_8015AE2C", func_8015B950); +extern s32 func_8015AE2C(); + +// @class: plumbing +// @stuck: none — MATCH (271/271, pin-free, zero asm). The ONLY residual is DEF-SIDE plumbing, and it is now named exactly: the in-TU instantiation `DEFINE_func_8015BEE4()` (engine_core.h:1851-1855) expands to `extern s32 func_8015B950(void);` INSIDE ov_SC01_077_jr_8015AE2C.c, ~14 lines BELOW this definition, so the 1-param def collides with a `(void)` prototype -> `conflicting types for func_8015B950` (.run/bank_func_8015B950.log). §73 PARAMS axis / T0. Surgical fix = §65b de-macroize that ONE instantiation (blast radius: this TU); the fleet-wide `(void)`->`()` header edit is §63 and must be R22-validated. +/* func_8015B950 (ov_SC01_077_jr_8015AE2C, 271 ins, jtbl_801D8B74) — SESSION-21 re-verified + * + * ── ROUND-2 INDEPENDENT RE-VERIFICATION (2026-07-27, fresh agent, §88e discipline) ───────────── + * match_one : MATCH (271 ins) against the CURRENT tree — §87 staleness re-checked today. + * .text size: compiled .text = 0x43C = 1084 B = 271 ins, EXACTLY the target's declared 0x43C + * ("nonmatching func_8015B950, 0x43C"). So this is NOT a §83a length drift hiding + * behind a zero count — the count is over equal-length streams. + * jtbl : RE-DECODED MECHANICALLY, not inherited. Compiled .rodata = 0x1C = 28 B = 7 words, + * 7x R_MIPS_32 -> .text with implicit addends [58,58,58,E0,F0,100,58]; +0x8015B950 + * = [8015B9A8, 8015B9A8, 8015B9A8, 8015BA30, 8015BA40, 8015BA50, 8015B9A8]. + * Diffed word-for-word against asm/ov_SC01_077/data/tail14.data.s:15-23 — 7/7 identical. + * symcheck : SYMS-DIFF target=35 draft=34, sole MISSING = jtbl_801D8B74. This is the §81 jr + * FALSE POSITIVE, re-confirmed here by reading the relocs: gcc emits its OWN table and + * references it with R_MIPS_HI16/LO16 against the SECTION `.rodata` (t.o +0x40/+0x48), + * so the splat's dlabel NAME can never appear in the draft object's relocation set. + * Nothing is dropped and nothing is invented: the draft's other 34 symbols are exactly + * the target's other 34. + * FAMILY : the x138 remap is clean and §84-safe. Every sibling is 271 ins with an IDENTICAL + * callee set; only THREE names vary per overlay — the two data labels and the jtbl: + * ov_SC01_077 D_8017F930 / D_8017F99C / jtbl_801D8B74 + * ov_SC03_099 D_80185A50 / D_80185ABC / jtbl_801BD898 + * ov_SC06_008 D_80187E44 / D_80187EB0 / jtbl_801A8734 + * The pair is always +0x6C apart, and NO literal in this draft encodes that distance + * (both labels are referenced by name), so there is no §84 derived-offset hazard. + * D_8011F9C4 is fleet-constant (main-EXE data) and must NOT be remapped. + * + * match_one: MATCH (271 ins) against the CURRENT tree (§87 staleness re-checked, 2026-07-27). + * PIN-FREE, zero asm, offset-pure (s32 arg0 + raw offsets) — x138 template-safe. + * Provenance: this is the Phase-26 crack (.run/phase26-cracks/func_8015B950.c) re-gated verbatim, + * with ONE deliberate change: the definition's return type void -> s32. + * - `void func_8015B950(s32 arg0)` : MATCH (271 ins) [the Phase-26 form] + * - `s32 func_8015B950(s32 arg0)` : MATCH (271 ins) [shipped — §3a-1 void->s32 is byte-neutral] + * The fleet/engine_core.h canonical decl is `extern s32 func_8015B950(void);` (engine_core.h:1852), + * and the last bank attempt (.run/bank_func_8015B950.log) died on `conflicting types for + * func_8015B950`. Shipping the s32 return kills the §73 RETURN axis for free and leaves only the + * cheap T0 PARAMS axis for the ladder (fix_header_decl.py / --fix-def-sig / cast_call_sites). + * Both forms are byte-identical, so the orchestrator may swap the return type back at zero cost. + * + * SYMBOLS (§58 rules 1/2 — all splat spellings, all verified present): + * D_8017F99C asm/ov_SC01_077/data/tail.data.s:4355 (the state-handler vtable) + * D_8017F930 asm/ov_SC01_077/data/tail.data.s:4293 + * D_8011F9C4 main-EXE data; spelled `extern s32 D_8011F9C4;` in 5+ already-banked TUs + * jtbl_801D8B74 asm/ov_SC01_077/data/tail14.data.s:15 (compiler jump table — not named in C) + * + * JTBL VERIFIED (§8a gate): compiled .rodata = exactly 0x1C B / 7 words, 7x R_MIPS_32 .text with + * addends [0x58,0x58,0x58,0xE0,0xF0,0x100,0x58] -> +0x8015B950 = [B9A8,B9A8,B9A8,BA30,BA40,BA50, + * B9A8] == the original words at 0x801D8B74..0x801D8B8C. Bound `sltiu $v0,$v1,0x7` matches. + * The raw dlabel's 8th word 0x00000000 is NOT an entry — it is the intra-TU `.align 3` pad of the + * B34/B54/B74 jtbl chain; the object can never emit it (maspsx drops .align), so it must stay in + * the post-carve RAW data piece (the §53/§62/§81 carve chain applies at bank time). + * + * Same family as the TU's own already-matched func_8015AE2C: 7-case switch on ((s32 (*)(s32))func_801619A4)() + * (0/1/2/6 shared, 3/4/5 own, no default block — out-of-range and every `break` fall to the + * after-switch join), then a chain of "state handler" tests, each dispatching + * D_8017F99C[*(u16*)arg0](arg0) and returning. + * + * THREE LEVERS (draft -> MATCH in 3 compiles): + * + * 1. PROLOGUE CONSTANT = an INITIALIZED LOCAL, not a literal in the compare. + * Target opens with `lui $s2, 0xFFF5` in the *prologue*, used once ~200 ins later in + * `slt $v0,$s2,$s1`. No gcc-2.7.2 pass hoists a (set reg const_int) across basic blocks + * (loop.c needs a loop; cse/combine/sched never move insns between BBs) — so the insn must + * have been EMITTED in the first BB, i.e. the constant is a local initialized at the top of + * the function. cse then cannot fold it back into the compare: the `slt` operand predicate is + * `arith_operand`, which rejects a CONST_INT wider than 16 bits, so validate_change fails and + * the pseudo survives. Its live range spans every call -> global.c gives it a callee-saved reg. + * Writing `z > -0xB0000` inline instead emits the `lui` into the branch delay slot next to the + * compare (caller-saved $v0) and the function is 1 insn short. => `s32 lim = -0xB0000;` at top. + * + * 2. `lh` vs `lhu`: a short->short copy is a pure HImode move and gcc emits `lhu`. The target's + * `lh $v0,0x26($s0)` means the value passed through an SImode (int) temp: expand makes + * (set (reg:SI) (sign_extend (mem:HI))) + (set (mem:HI) (subreg:HI ...)), and combine cannot + * merge them (the merged form is mem<-mem, which no movhi accepts) so the sign-extending load + * survives. => route both halfword copies through the `s32 t` temp. + * + * 3. THE `goto` LAYOUT — dodging jump.c's store-flag conversion (jump.c:1005-1065). + * An if/else chain writing 0/1 into `doit` makes gcc collapse the last pair into + * `sltiu $v0,$v0,1`. jump.c fires that conversion when the insn immediately after a + * conditional jump is a lone `SET pseudo, CONST_INT` whose following simplejump targets the + * SAME label as the branch (jump.c:1038 `reallabelprev == temp || ... JUMP_LABEL(temp4) == + * JUMP_LABEL(insn)`) — exactly the shape of `if (c) x=0; else x=1;`. + * The target instead cross-jumps ALL the `doit=0` exits into ONE shared block placed after the + * `doit=1` fall-through; reorg's fill_slots_from_thread then COPIES that single set into all + * three branch delay slots and redirects each branch past it (which is why `addu $v0,$zero, + * $zero` appears 3x in delay slots and the shared block vanishes). A `goto zero;` / `goto one;` + * chain expresses that layout directly, and each conditional jump is then followed by a + * compare/call rather than a lone const set, so the store-flag conversion never triggers. + * GENERAL RULE: multiple predicates that all assign the SAME constant to one flag => write + * them as `goto` to a shared assignment, never as an if/else ladder. + */ +extern s32 D_8011F9C4; +extern s32 D_8017F930; + +extern s32 func_80161B18(void); +extern s32 func_801619A4(s32*); +extern s32 func_80149AA8(s32*); +extern void func_80149AD4(s32*); +extern s32 func_80149B54(s32*); +extern void func_80149BAC(s32*); +extern s32 func_801498E0(s32*); +extern s32 func_80149954(s32); +extern s32 func_80149A64(s32*); +extern void func_800CCCC0(s32 a0); +extern s32 func_80149CD4(s32 a0); +extern void func_8015E880(s32*); +extern s32 func_80149744(struct S_80149744*); +extern void func_80149788(void); +extern s32 func_801496D4(void*); +extern void func_80149704(void); +extern int func_80148AFC(void*); +extern void func_80146D90(s32 a0); +extern void func_80154150(s32 a0, s32 a1); +extern void func_801541D8(u8*, s32, s32); +extern s32 func_801488A8(u8*); +extern void func_80147078(s32*, s16); +extern void func_8015A264(void*); +extern s32 func_80013294(void*, void*); +extern void func_80159B70(void*); +extern s32 func_8016F1AC(void); +extern s32 func_80029178(s32 a0); +extern void func_80146DB8(s32*, s32*); +extern s32 func_80161CD0(s32, s32); +extern s32 func_80161208(s32 a0); +extern s32 func_801725A4(u8*); + +s32 func_8015B950(s32 arg0) +{ + + extern void (*D_8017F99C[])(void *); + s16 sp10[4]; + s16 sp18[4]; + s32 t; + s32 z; + s32 doit; + s32 lim = -0xB0000; + + if (func_80161B18() != 0) { + return; + } + switch (((s32 (*)(s32))func_801619A4)(arg0)) { + case 0: + case 1: + case 2: + case 6: + if (((s32 (*)(s32))func_80149AA8)(arg0) != 0) { + D_8017F99C[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149AD4)(arg0); + return; + } + if (((s32 (*)(s32))func_80149B54)(arg0) != 0) { + D_8017F99C[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149BAC)(arg0); + return; + } + break; + case 3: + ((void (*)(s32))func_801498E0)(arg0); + break; + case 4: + ((void (*)(s32))func_80149954)(arg0); + break; + case 5: + if (((s32 (*)(s32))func_80149A64)(arg0) != 0) { + D_8017F99C[*(u16 *)arg0]((void *)arg0); + func_800CCCC0(arg0); + return; + } + break; + } + if (func_80149CD4(arg0) != 0) { + D_8017F99C[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_8015E880)(arg0); + return; + } + if (((s32 (*)(s32))func_80149744)(arg0) != 0) { + D_8017F99C[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149788)(arg0); + return; + } + if (((s32 (*)(s32))func_801496D4)(arg0) != 0) { + D_8017F99C[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149704)(arg0); + if (((u8)((s32 (*)(s32))func_80148AFC)(arg0)) == 0) { + func_80146D90(arg0); + } + if ((*(s32 *)(arg0 + 0x24) | *(s32 *)(arg0 + 0x2C)) != 0) { + func_80154150(arg0, 0xF); + } else { + ((void (*)(s32, s32, s32))func_801541D8)(arg0, 0xD, 6); + } + *(s32 *)(arg0 + 0x238) = 1; + return; + } + if (((s32 (*)(s32))func_801488A8)(arg0) != 0) { + sp10[0] = 0; + sp10[1] = 0; + sp10[2] = 0; + t = *(s16 *)(arg0 + 0x26); + sp18[0] = t; + sp18[1] = 0; + t = *(s16 *)(arg0 + 0x2E); + sp18[2] = t; + D_8017F99C[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 1); + ((void (*)(s32))func_8015A264)(arg0); + t = -(((s32 (*)(s16 *, s16 *))func_80013294)(sp10, sp18) << 0x10); + if (t < *(s32 *)(arg0 + 0x2C)) { + *(s32 *)(arg0 + 0x2C) = t; + } + return; + } + if (*(u16 *)(arg0 + 0xB8) == 0x8000) { + D_8017F99C[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 0); + ((void (*)(s32))func_80159B70)(arg0); + return; + } + z = *(s32 *)(arg0 + 0x2C); + if (func_8016F1AC() != 0) { + goto zero; + } + if (z <= lim) { + goto one; + } + if (D_8011F9C4 == 0) { + goto zero; + } + if (((u8)func_80029178(0x21)) != 0) { + goto zero; + } +one: + doit = 1; + goto join; +zero: + doit = 0; +join: + if (doit != 0) { + D_8017F99C[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 0); + ((void (*)(s32))func_80159B70)(arg0); + func_80154150(arg0, 9); + ((void (*)(s32, s32 *))func_80146DB8)(arg0, &D_8017F930); + ((void (*)(s32, s32))func_80161CD0)(arg0, *(u16 *)(arg0 + 0x16E)); + return; + } + if (func_80161208(arg0) == 0) { + ((void (*)(s32))func_801725A4)(arg0); + } +} DEFINE_func_8015BD8C() /* dedup: shared engine-core @0x8015BD8C (src/shared) */ diff --git a/src/ov_SC07_009/ov_SC07_009_jr_8015AE2C.c b/src/ov_SC07_009/ov_SC07_009_jr_8015AE2C.c index 9eddb4711..7d388e080 100644 --- a/src/ov_SC07_009/ov_SC07_009_jr_8015AE2C.c +++ b/src/ov_SC07_009/ov_SC07_009_jr_8015AE2C.c @@ -1512,7 +1512,259 @@ DEFINE_func_8015B858() /* dedup: shared engine-core @0x8015B858 (src/shared) */ DEFINE_func_8015B8F8() /* dedup: shared engine-core @0x8015B8F8 (src/shared) */ -INCLUDE_ASM("asm/ov_SC07_009/nonmatchings/ov_SC07_009_jr_8015AE2C", func_8015B950); +extern s32 func_8015AE2C(); + +// @class: plumbing +// @stuck: none — MATCH (271/271, pin-free, zero asm). The ONLY residual is DEF-SIDE plumbing, and it is now named exactly: the in-TU instantiation `DEFINE_func_8015BEE4()` (engine_core.h:1851-1855) expands to `extern s32 func_8015B950(void);` INSIDE ov_SC01_077_jr_8015AE2C.c, ~14 lines BELOW this definition, so the 1-param def collides with a `(void)` prototype -> `conflicting types for func_8015B950` (.run/bank_func_8015B950.log). §73 PARAMS axis / T0. Surgical fix = §65b de-macroize that ONE instantiation (blast radius: this TU); the fleet-wide `(void)`->`()` header edit is §63 and must be R22-validated. +/* func_8015B950 (ov_SC01_077_jr_8015AE2C, 271 ins, jtbl_801D8B74) — SESSION-21 re-verified + * + * ── ROUND-2 INDEPENDENT RE-VERIFICATION (2026-07-27, fresh agent, §88e discipline) ───────────── + * match_one : MATCH (271 ins) against the CURRENT tree — §87 staleness re-checked today. + * .text size: compiled .text = 0x43C = 1084 B = 271 ins, EXACTLY the target's declared 0x43C + * ("nonmatching func_8015B950, 0x43C"). So this is NOT a §83a length drift hiding + * behind a zero count — the count is over equal-length streams. + * jtbl : RE-DECODED MECHANICALLY, not inherited. Compiled .rodata = 0x1C = 28 B = 7 words, + * 7x R_MIPS_32 -> .text with implicit addends [58,58,58,E0,F0,100,58]; +0x8015B950 + * = [8015B9A8, 8015B9A8, 8015B9A8, 8015BA30, 8015BA40, 8015BA50, 8015B9A8]. + * Diffed word-for-word against asm/ov_SC01_077/data/tail14.data.s:15-23 — 7/7 identical. + * symcheck : SYMS-DIFF target=35 draft=34, sole MISSING = jtbl_801D8B74. This is the §81 jr + * FALSE POSITIVE, re-confirmed here by reading the relocs: gcc emits its OWN table and + * references it with R_MIPS_HI16/LO16 against the SECTION `.rodata` (t.o +0x40/+0x48), + * so the splat's dlabel NAME can never appear in the draft object's relocation set. + * Nothing is dropped and nothing is invented: the draft's other 34 symbols are exactly + * the target's other 34. + * FAMILY : the x138 remap is clean and §84-safe. Every sibling is 271 ins with an IDENTICAL + * callee set; only THREE names vary per overlay — the two data labels and the jtbl: + * ov_SC01_077 D_801803D4 / D_80180440 / jtbl_801D8B74 + * ov_SC03_099 D_80185A50 / D_80185ABC / jtbl_801BD898 + * ov_SC06_008 D_80187E44 / D_80187EB0 / jtbl_801A8734 + * The pair is always +0x6C apart, and NO literal in this draft encodes that distance + * (both labels are referenced by name), so there is no §84 derived-offset hazard. + * D_8011F9C4 is fleet-constant (main-EXE data) and must NOT be remapped. + * + * match_one: MATCH (271 ins) against the CURRENT tree (§87 staleness re-checked, 2026-07-27). + * PIN-FREE, zero asm, offset-pure (s32 arg0 + raw offsets) — x138 template-safe. + * Provenance: this is the Phase-26 crack (.run/phase26-cracks/func_8015B950.c) re-gated verbatim, + * with ONE deliberate change: the definition's return type void -> s32. + * - `void func_8015B950(s32 arg0)` : MATCH (271 ins) [the Phase-26 form] + * - `s32 func_8015B950(s32 arg0)` : MATCH (271 ins) [shipped — §3a-1 void->s32 is byte-neutral] + * The fleet/engine_core.h canonical decl is `extern s32 func_8015B950(void);` (engine_core.h:1852), + * and the last bank attempt (.run/bank_func_8015B950.log) died on `conflicting types for + * func_8015B950`. Shipping the s32 return kills the §73 RETURN axis for free and leaves only the + * cheap T0 PARAMS axis for the ladder (fix_header_decl.py / --fix-def-sig / cast_call_sites). + * Both forms are byte-identical, so the orchestrator may swap the return type back at zero cost. + * + * SYMBOLS (§58 rules 1/2 — all splat spellings, all verified present): + * D_80180440 asm/ov_SC01_077/data/tail.data.s:4355 (the state-handler vtable) + * D_801803D4 asm/ov_SC01_077/data/tail.data.s:4293 + * D_8011F9C4 main-EXE data; spelled `extern s32 D_8011F9C4;` in 5+ already-banked TUs + * jtbl_801D8B74 asm/ov_SC01_077/data/tail14.data.s:15 (compiler jump table — not named in C) + * + * JTBL VERIFIED (§8a gate): compiled .rodata = exactly 0x1C B / 7 words, 7x R_MIPS_32 .text with + * addends [0x58,0x58,0x58,0xE0,0xF0,0x100,0x58] -> +0x8015B950 = [B9A8,B9A8,B9A8,BA30,BA40,BA50, + * B9A8] == the original words at 0x801D8B74..0x801D8B8C. Bound `sltiu $v0,$v1,0x7` matches. + * The raw dlabel's 8th word 0x00000000 is NOT an entry — it is the intra-TU `.align 3` pad of the + * B34/B54/B74 jtbl chain; the object can never emit it (maspsx drops .align), so it must stay in + * the post-carve RAW data piece (the §53/§62/§81 carve chain applies at bank time). + * + * Same family as the TU's own already-matched func_8015AE2C: 7-case switch on ((s32 (*)(s32))func_801619A4)() + * (0/1/2/6 shared, 3/4/5 own, no default block — out-of-range and every `break` fall to the + * after-switch join), then a chain of "state handler" tests, each dispatching + * D_80180440[*(u16*)arg0](arg0) and returning. + * + * THREE LEVERS (draft -> MATCH in 3 compiles): + * + * 1. PROLOGUE CONSTANT = an INITIALIZED LOCAL, not a literal in the compare. + * Target opens with `lui $s2, 0xFFF5` in the *prologue*, used once ~200 ins later in + * `slt $v0,$s2,$s1`. No gcc-2.7.2 pass hoists a (set reg const_int) across basic blocks + * (loop.c needs a loop; cse/combine/sched never move insns between BBs) — so the insn must + * have been EMITTED in the first BB, i.e. the constant is a local initialized at the top of + * the function. cse then cannot fold it back into the compare: the `slt` operand predicate is + * `arith_operand`, which rejects a CONST_INT wider than 16 bits, so validate_change fails and + * the pseudo survives. Its live range spans every call -> global.c gives it a callee-saved reg. + * Writing `z > -0xB0000` inline instead emits the `lui` into the branch delay slot next to the + * compare (caller-saved $v0) and the function is 1 insn short. => `s32 lim = -0xB0000;` at top. + * + * 2. `lh` vs `lhu`: a short->short copy is a pure HImode move and gcc emits `lhu`. The target's + * `lh $v0,0x26($s0)` means the value passed through an SImode (int) temp: expand makes + * (set (reg:SI) (sign_extend (mem:HI))) + (set (mem:HI) (subreg:HI ...)), and combine cannot + * merge them (the merged form is mem<-mem, which no movhi accepts) so the sign-extending load + * survives. => route both halfword copies through the `s32 t` temp. + * + * 3. THE `goto` LAYOUT — dodging jump.c's store-flag conversion (jump.c:1005-1065). + * An if/else chain writing 0/1 into `doit` makes gcc collapse the last pair into + * `sltiu $v0,$v0,1`. jump.c fires that conversion when the insn immediately after a + * conditional jump is a lone `SET pseudo, CONST_INT` whose following simplejump targets the + * SAME label as the branch (jump.c:1038 `reallabelprev == temp || ... JUMP_LABEL(temp4) == + * JUMP_LABEL(insn)`) — exactly the shape of `if (c) x=0; else x=1;`. + * The target instead cross-jumps ALL the `doit=0` exits into ONE shared block placed after the + * `doit=1` fall-through; reorg's fill_slots_from_thread then COPIES that single set into all + * three branch delay slots and redirects each branch past it (which is why `addu $v0,$zero, + * $zero` appears 3x in delay slots and the shared block vanishes). A `goto zero;` / `goto one;` + * chain expresses that layout directly, and each conditional jump is then followed by a + * compare/call rather than a lone const set, so the store-flag conversion never triggers. + * GENERAL RULE: multiple predicates that all assign the SAME constant to one flag => write + * them as `goto` to a shared assignment, never as an if/else ladder. + */ +extern s32 D_8011F9C4; +extern s32 D_801803D4; + +extern s32 func_80161B18(void); +extern s32 func_801619A4(s32*); +extern s32 func_80149AA8(s32*); +extern void func_80149AD4(s32*); +extern s32 func_80149B54(s32*); +extern void func_80149BAC(s32*); +extern s32 func_801498E0(s32*); +extern s32 func_80149954(s32); +extern s32 func_80149A64(s32*); +extern void func_800CCCC0(s32 a0); +extern s32 func_80149CD4(s32 a0); +extern void func_8015E880(s32*); +extern s32 func_80149744(struct S_80149744*); +extern void func_80149788(void); +extern s32 func_801496D4(void*); +extern void func_80149704(void); +extern int func_80148AFC(void*); +extern void func_80146D90(s32 a0); +extern void func_80154150(s32 a0, s32 a1); +extern void func_801541D8(u8*, s32, s32); +extern s32 func_801488A8(u8*); +extern void func_80147078(s32*, s16); +extern void func_8015A264(void*); +extern s32 func_80013294(void*, void*); +extern void func_80159B70(void*); +extern s32 func_8016F1AC(void); +extern s32 func_80029178(s32 a0); +extern void func_80146DB8(s32*, s32*); +extern s32 func_80161CD0(s32, s32); +extern s32 func_80161208(s32 a0); +extern s32 func_801725A4(u8*); + +s32 func_8015B950(s32 arg0) +{ + + extern void (*D_80180440[])(void *); + s16 sp10[4]; + s16 sp18[4]; + s32 t; + s32 z; + s32 doit; + s32 lim = -0xB0000; + + if (func_80161B18() != 0) { + return; + } + switch (((s32 (*)(s32))func_801619A4)(arg0)) { + case 0: + case 1: + case 2: + case 6: + if (((s32 (*)(s32))func_80149AA8)(arg0) != 0) { + D_80180440[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149AD4)(arg0); + return; + } + if (((s32 (*)(s32))func_80149B54)(arg0) != 0) { + D_80180440[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149BAC)(arg0); + return; + } + break; + case 3: + ((void (*)(s32))func_801498E0)(arg0); + break; + case 4: + ((void (*)(s32))func_80149954)(arg0); + break; + case 5: + if (((s32 (*)(s32))func_80149A64)(arg0) != 0) { + D_80180440[*(u16 *)arg0]((void *)arg0); + func_800CCCC0(arg0); + return; + } + break; + } + if (func_80149CD4(arg0) != 0) { + D_80180440[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_8015E880)(arg0); + return; + } + if (((s32 (*)(s32))func_80149744)(arg0) != 0) { + D_80180440[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149788)(arg0); + return; + } + if (((s32 (*)(s32))func_801496D4)(arg0) != 0) { + D_80180440[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149704)(arg0); + if (((u8)((s32 (*)(s32))func_80148AFC)(arg0)) == 0) { + func_80146D90(arg0); + } + if ((*(s32 *)(arg0 + 0x24) | *(s32 *)(arg0 + 0x2C)) != 0) { + func_80154150(arg0, 0xF); + } else { + ((void (*)(s32, s32, s32))func_801541D8)(arg0, 0xD, 6); + } + *(s32 *)(arg0 + 0x238) = 1; + return; + } + if (((s32 (*)(s32))func_801488A8)(arg0) != 0) { + sp10[0] = 0; + sp10[1] = 0; + sp10[2] = 0; + t = *(s16 *)(arg0 + 0x26); + sp18[0] = t; + sp18[1] = 0; + t = *(s16 *)(arg0 + 0x2E); + sp18[2] = t; + D_80180440[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 1); + ((void (*)(s32))func_8015A264)(arg0); + t = -(((s32 (*)(s16 *, s16 *))func_80013294)(sp10, sp18) << 0x10); + if (t < *(s32 *)(arg0 + 0x2C)) { + *(s32 *)(arg0 + 0x2C) = t; + } + return; + } + if (*(u16 *)(arg0 + 0xB8) == 0x8000) { + D_80180440[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 0); + ((void (*)(s32))func_80159B70)(arg0); + return; + } + z = *(s32 *)(arg0 + 0x2C); + if (func_8016F1AC() != 0) { + goto zero; + } + if (z <= lim) { + goto one; + } + if (D_8011F9C4 == 0) { + goto zero; + } + if (((u8)func_80029178(0x21)) != 0) { + goto zero; + } +one: + doit = 1; + goto join; +zero: + doit = 0; +join: + if (doit != 0) { + D_80180440[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 0); + ((void (*)(s32))func_80159B70)(arg0); + func_80154150(arg0, 9); + ((void (*)(s32, s32 *))func_80146DB8)(arg0, &D_801803D4); + ((void (*)(s32, s32))func_80161CD0)(arg0, *(u16 *)(arg0 + 0x16E)); + return; + } + if (func_80161208(arg0) == 0) { + ((void (*)(s32))func_801725A4)(arg0); + } +} DEFINE_func_8015BD8C() /* dedup: shared engine-core @0x8015BD8C (src/shared) */ diff --git a/src/ov_SC07_010/ov_SC07_010_jr_801588CC.c b/src/ov_SC07_010/ov_SC07_010_jr_801588CC.c index 8c37d7bec..8d03505aa 100644 --- a/src/ov_SC07_010/ov_SC07_010_jr_801588CC.c +++ b/src/ov_SC07_010/ov_SC07_010_jr_801588CC.c @@ -2011,141 +2011,3 @@ DEFINE_func_8015B858() /* dedup: shared engine-core @0x8015b858 (src/shared) */ DEFINE_func_8015B8F8() /* dedup: shared engine-core @0x8015b8f8 (src/shared) */ - - -INCLUDE_ASM("asm/ov_SC07_010/nonmatchings/ov_SC07_010_jr_801588CC", func_8015B950); - -DEFINE_func_8015BD8C() /* dedup: shared engine-core @0x8015bd8c (src/shared) */ - - -DEFINE_func_8015BDD0() /* dedup: shared engine-core @0x8015bdd0 (src/shared) */ - - -DEFINE_func_8015BE04() /* dedup: shared engine-core @0x8015be04 (src/shared) */ - - - - -void func_8015BE38(struct Obj *a0) { - - extern void (*D_801847D0[])(void); - D_801847D0[*(u16 *)((s32)a0 + 0x2)](); -} - - -DEFINE_func_8015BE74() /* dedup: shared engine-core @0x8015be74 (src/shared) */ - - -DEFINE_func_8015BE94() /* dedup: shared engine-core @0x8015be94 (src/shared) */ - - -DEFINE_func_8015BEC4() /* dedup: shared engine-core @0x8015bec4 (src/shared) */ - - -DEFINE_func_8015BEE4() /* dedup: shared engine-core @0x8015bee4 (src/shared) */ - - -DEFINE_func_8015BF04() /* dedup: shared engine-core @0x8015bf04 (src/shared) */ - - -DEFINE_func_8015BF48() /* dedup: shared engine-core @0x8015bf48 (src/shared) */ - - -DEFINE_func_8015BF7C() /* dedup: shared engine-core @0x8015bf7c (src/shared) */ - - -DEFINE_func_8015BFB0() /* dedup: shared engine-core @0x8015bfb0 (src/shared) */ - - - - -void func_8015BFF4(void *a0) { - - extern void (*D_801847DC[])(void); - D_801847DC[*(u16 *)((s32)a0 + 0x2)](); -} - - -INCLUDE_ASM("asm/ov_SC07_010/nonmatchings/ov_SC07_010_jr_801588CC", func_8015C030); - -DEFINE_func_8015C08C() /* dedup: shared engine-core @0x8015c08c (src/shared) */ - - -DEFINE_func_8015C0C4() /* dedup: shared engine-core @0x8015c0c4 (src/shared) */ - - -extern void func_8001382C(s32 a0, void *a1, void *a2); -extern void func_80146CA0(void *a0); -extern void func_80146DB8(s32 *a0, s32 *a1); -extern void func_80146E90(s32 *a0, s32 a1); -extern s32 func_80146E98(s32 a0); -extern void func_80147078(s32 *a0, s16 a1); -extern void func_80147324(s32 a0); -extern void func_801473EC(s32 *a0); -extern void func_80147A84(s32 arg0); -extern int func_80148AFC(void *a0); -extern s32 func_80149FB0(s32 a0); -extern void func_8014C010(s32 a0, s32 a1); -extern void func_8014CC28(s32 a0); -extern void func_8014D738(void); -extern s32 func_8014F3E8(s32 a0); -extern s32 func_8015BE94(); -extern void func_8015C0C4(s32 a0); - - - -s32 func_8015C128(s32 param_1) { - - extern u16 D_800B99DA; - extern void func_8015C6E0(int); - extern void (*D_8018465C[])(int); - - int sp10[3]; - int sp20[3]; - int temp_s0; - int temp_v0; - - ((void(*)())func_80149FB0)(); - if (((int(*)(int))func_80148AFC)(((int)param_1)) & 0xFF) { - sp10[0] = 0; - sp10[1] = 0; - sp10[2] = -0x4000; - ((void(*)(int, int *, int *))func_8001382C)(*(short *)(*(int *)(((int)param_1) + 0x20) + 0x12), sp10, sp20); - *(int *)(((int)param_1) + 0x234) += sp20[0]; - *(int *)(((int)param_1) + 0x238) += sp20[1]; - *(int *)(((int)param_1) + 0x23C) += sp20[2]; - } - ((void(*)(int, int *, int *))func_8001382C)((short)(-*(unsigned short *)(*(int *)(((int)param_1) + 0x20) + 0x12)), - (int *)(((int)param_1) + 0x234), sp20); - ((void(*)(int, int *))func_80146DB8)(((int)param_1), sp20); - func_80147A84(((int)param_1)); - ((void(*)(int))func_801473EC)(((int)param_1)); - if (!(D_800B99DA & 3)) { - ((void(*)(int, int))func_8014C010)(((int)param_1), 1); - ((void(*)(int))func_80147324)(0x65F); - } - if (((int(*)(int))func_8014D738)(((int)param_1)) != 0) { - D_8018465C[*(u16 *)((int)param_1)](((int)param_1)); - func_8015C6E0(((int)param_1)); - return; - } - temp_s0 = ((int(*)(int))func_8014CC28)(((int)param_1)); - temp_v0 = ((int(*)(int))func_8014F3E8)(((int)param_1)); - if (temp_v0 != 0) { - if ((temp_v0 & 0xFF00) != 0x4000) { - ((void(*)(int, int))func_80146E90)(((int)param_1), 6); - ((void(*)(int))func_80146CA0)(((int)param_1)); - return; - } - if ((temp_v0 & 0x4000) && ((int(*)(int))func_80146E98)(((int)param_1)) != 0) { - ((void(*)(int, int))func_80147078)(((int)param_1), 4); - ((void(*)(int))func_8015C0C4)(((int)param_1)); - } - } else if (temp_s0 == 0) { - D_8018465C[*(u16 *)((int)param_1)](((int)param_1)); - ((void(*)(int, int))func_80147078)(((int)param_1), 3); - ((void(*)(int))func_8015BE94)(((int)param_1)); - } -} - - diff --git a/src/ov_SC07_010/ov_SC07_010_jr_8015B950.c b/src/ov_SC07_010/ov_SC07_010_jr_8015B950.c new file mode 100644 index 000000000..d83b5e52f --- /dev/null +++ b/src/ov_SC07_010/ov_SC07_010_jr_8015B950.c @@ -0,0 +1,1852 @@ +#include "common.h" +#include "../shared/engine_core.h" + +/* ==== Phase-26 §8b carried decl layer (jr_isolate_all.py) =================== + * The file-scope decl environment from earlier code regions of this object — + * file-local types, col-0 decls, DEFINE_func macro externs, and each earlier + * definition's implied prototype (types first, then decls in original order). + * Decls emit no code => byte-neutral. See cookbook §8c. */ +extern void func_80016714(void *a0, s32 a1); +extern void func_8013C98C(void); +extern void func_80019064(void *a0); +extern void func_8013C9C4(void * arg0); +extern void func_8013CA14(void); +extern void func_8013CABC(void); +extern void func_8013CAE8(void); +extern void func_8013CB20(void); +extern void func_8013CB5C(void); +extern s16 currentLocationId; +extern void func_8013DBE4(); +extern void func_8013D9B0(); +extern void func_8013D330(void); +extern void func_8013D178(void); +extern void func_8013CF68(void); +extern void func_8013CB84(void); +extern void func_8013CF68(); +extern void func_8013D064(void); +extern s32 func_8013D13C(void); +extern void func_8013D164(void); +extern void func_8013D53C(); +extern void func_8013DD68(void); +extern void func_8013D8FC(void); +extern void func_8013D3D4(int param_1, int param_2); +extern void func_800599B8(s32 a0, s32 a1); +extern void func_8013D9B0(int param_1); +extern void func_8013DBE4(int param_1); +extern s32 func_8013E054(void); +extern int SquareRoot12(int a0); +extern int func_8013E064(s16 *a0, s16 *a1); +extern int func_8013E0FC(s16 *a0, s16 *a1); +extern int func_8013E194(s16 *a0, s16 *a1); +extern void Square12(s32 *a0, s32 *a1); +extern s32 func_8013E22C(struct VecA *a0, struct VecB *a1); +extern s16 D_80126CB0; +extern s32 func_8013E298(s16 *a0); +extern s16 D_80126CAC; +extern short D_80126CAE; +extern int func_8013E2C4(short *a0); +extern void *D_801274CC; +extern s32 func_8013E410(void); +extern s32 func_8013E448(s32 a0); +extern void func_8012C724(s32 a0, s32 a1); +extern void func_8013E370(void); +extern u8 D_801202A0[]; +extern s32 (*D_801274D0)(s32); +extern s32 D_801274D8; +extern s32 D_801274DC; +extern s32 func_800132BC(s32 a0, s32 a1); +extern s32 func_8013E448(s32 param_1); +extern void func_800D24A0(s32 a0); +extern void func_80141788(void); +extern void *D_8011DB24; +extern void func_8013E558(void); +extern s32 func_800D0EC4(void); +extern void func_80141874(void); +extern u8 D_800B9A15; +extern unsigned char D_800B9A13; +extern u16 D_80115110; +extern unsigned short D_80115112; +extern void func_8013E588(void * _arg0); +extern void func_80029444(void); +extern void func_801754A8(void); +extern s32 func_80014ED4(s32); +extern s32 func_80015018(s32); +extern void func_800190AC(void); +extern void func_80141C04(void); +extern void func_8013E5E8(void); +extern void func_8013E67C(void); +extern void func_8013E83C(void); +extern s32 func_80029504(void); +extern void func_8013E6AC(void); +extern void func_800D24A0(s32 arg); +extern void func_8013E814(void); +extern void func_8013E83C(); +extern void func_8013E958(); +extern s32 func_80141C50(void); +extern void func_8013F244(void); +extern void func_8013FAF8(s16 a0, s16 a1); +extern void func_80137B80(void); +extern void func_8013E958(void); +extern void func_8002D4C8(s32 a0, s32 a1); +extern short D_800B9A02; +extern u8 D_801151C8[]; +extern s32 D_801151D0; +extern u16 D_8011511A; +extern u16 D_8011511E; +extern s32 D_80115130; +extern s16 D_8011514C; +extern void func_8013EA54(void); +extern s32 func_8013F350(void); /* §30#2 widened: def returns live $v0; callers discard */ +extern s16 func_8014168C(s16 a0); +extern s32 func_8014032C(s32 a0, s32 a1); +extern void func_80139954(void); +extern void func_801376E8(int a0, int a1); +extern unsigned char *func_80141CA4(void); +extern void func_8013EB7C(void); +extern s32 func_8013F350(void); /* §30#2 widened (discarding caller) */ +extern u16 D_80115112; +extern void func_8013ED6C(void); +extern s32 func_8013EE10(); +extern s32 func_800D0488(s16 a0); +extern void func_800D2624(void); +extern void func_8013EF88(void); +extern void func_8013F138(void); +extern unsigned short D_80115114; +extern unsigned short D_80115118; +extern void func_8013F1BC(void); +extern void func_80141C0C(s32); +extern u16 D_8011511C; +extern u16 D_80115120; +extern u16 D_80115122; +extern s16 D_80115128; +extern s16 D_8011512A; +extern u16 D_8011512E; +extern u8 D_80115140[]; +extern s16 D_8011514E; +extern u8 D_80115152; +extern u8 D_80115158[]; /* macro-canonical (§8e) */ +extern u8 D_8011515C; /* macro-canonical (§8e) */ +extern u8 D_8018305C[]; +extern u8 D_80183074[]; +extern u16 D_80182F78[]; +extern s32 func_80029178(s32 arg); +extern s32 func_800291B4(s32 arg); +extern void func_8014AA04(s32 a0); +extern void func_801415C0(s32 a0, s32 a1); +extern void func_80141C0C(s32 a0); +extern s32 func_80140608(s32 a0); +extern void func_801407F4(void); +extern s32 func_801416D4(s16); /* macro-canonical (§8e) */ +extern s32 func_8013F350(void); +extern void func_80140E6C(void); +extern void func_80140F00(void); +extern s32 *func_80140958(s32 *, s32, s32); +extern int func_80141100(int); +extern s16 func_8014168C(s16); +extern s32 func_8013FFD8(s16, s32, s32 *); +extern void func_80024054(void *a0, void *a1); +extern s32 *func_800D2650(s32 *, void *, s32, s32, s32, s32); +extern s32 func_8005A600(s32, s32, s32, s32, s32); +extern s32 func_800D27DC(s32, s32 *, void *, s32, s32); +extern s32 *func_800D29F8(s32, s32, void *, s32, s32); +extern int func_80137D08(int arg0, int arg1, short arg2); +extern s32 func_8013AB54(s32 a0, s32 a1, s32 a2, s32 a3); +extern void func_8013FAF8(s16 arg0, s16 arg1); +extern s32 func_80028D58(void); +extern s32 func_80028DE0(void); +extern s32 func_80028FBC(void); +extern s32 func_80029000(void); +extern s32 func_80028D9C(void); +extern int func_800D2CA8(int, int); +extern void func_800D2D10(int, int, void *, int); +extern int func_80029FE4(void); +extern char *func_8002AAB4(void); +extern char *strcpy(char *, const char *); +extern int func_8002A26C(void); +extern int func_8002A2B0(void); +extern int func_8002A4B8(void); +extern s32 func_8002A4FC(s32 a0); +extern int func_8002A998(void); +extern int func_8002A9DC(void); +extern int func_8002A728(void); +extern int func_8002A76C(void); +extern int func_80029FD4(void); +extern s32 func_8002A1B4(void); +extern short func_8002A28C(void); +extern short func_8002A27C(void); +extern s32 func_8002A400(void); +extern short func_8002A4D8(void); +extern short func_8002A4C8(void); +extern s32 func_8002A8E0(void); +extern short func_8002A9B8(void); +extern short func_8002A9A8(void); +extern s32 func_8002A670(void); +extern short func_8002A748(void); +extern short func_8002A738(void); +extern int func_801412A8(int, int, int, int, int, int); +extern int func_80141100(int param_1); +extern void func_800291A0(s32, s32); +extern s32 func_800291DC(s32); +extern void func_800291C8(s32, s32); +extern void func_801415C0(s32 param_1, s32 param_2); +extern u8 D_80115148[]; +extern u8 D_80115149[]; +extern u8 D_80115158[]; +extern u8 D_8011514D; +extern u8 D_8011515C; +extern s32 func_800D11F0(s32 a0); +extern s32 func_800D1658(s32 a0); +extern s32 func_801416D4(s16 param_1); +extern void func_8001903C(void); +extern void func_801417C4(void); +extern u8 D_800B9A16; +extern u16 D_80115114; +extern void func_801417F8(void); +extern volatile u16 D_8011511A; +extern u16 D_8011512E; /* §17a-1: canonical width (jr_8013F350 TUs decl u16); byte-neutral here (only use is store-0) */ +extern s32 func_80029178(s32 a0); +extern void func_801418F8(void); +extern void func_80141A60(void); +extern void func_80141C0C(s32 param_1); +extern s32 func_80015144(void); +extern unsigned char D_80112C04[]; +extern unsigned char D_80112C50[]; +extern unsigned char D_80112C9C[]; +extern unsigned char D_80112CE8[]; +extern unsigned char D_80112D38[]; +extern unsigned char D_80112D78[]; +extern unsigned char D_80112DBC[]; +extern unsigned char D_80112DF4[]; +extern unsigned char D_80112E14[]; +extern unsigned char D_80112E40[]; +extern unsigned char D_80112E6C[]; +extern unsigned char D_80112EBC[]; +extern unsigned char D_80112F0C[]; +extern unsigned char D_80112F48[]; +extern unsigned char D_80112F9C[]; +extern unsigned char D_80112FDC[]; +extern unsigned char D_8011302C[]; +extern unsigned char D_80113074[]; +extern unsigned char D_801130B8[]; +extern unsigned char D_801130E8[]; +extern unsigned char D_80113138[]; +extern unsigned char D_8011317C[]; +extern unsigned char D_801131A8[]; +extern unsigned char D_801131E8[]; +extern unsigned char D_80113214[]; +extern unsigned char D_80113254[]; +extern unsigned char D_80113278[]; +extern unsigned char D_801132B8[]; +extern unsigned char D_801132E4[]; +extern unsigned char D_80113324[]; +extern unsigned char D_80113360[]; +extern unsigned char D_801133A4[]; +extern unsigned char D_801133F4[]; +extern unsigned char D_80113440[]; +extern unsigned char D_80113474[]; +extern unsigned char D_801134B0[]; +extern unsigned char D_801134FC[]; +extern unsigned char D_80113530[]; +extern unsigned char D_80113554[]; +extern unsigned char D_801135A8[]; +extern unsigned char D_80113600[]; +extern unsigned char D_80113650[]; +extern unsigned char D_80113694[]; +extern unsigned char D_801136DC[]; +extern unsigned char D_80113724[]; +extern unsigned char D_80113744[]; +extern unsigned char D_80113770[]; +extern unsigned char D_80113794[]; +extern unsigned char D_801137D8[]; +extern unsigned char D_8011381C[]; +extern unsigned char D_8011383C[]; +extern unsigned char D_8011386C[]; +extern unsigned char D_801138A4[]; +extern unsigned char D_801138D0[]; +extern unsigned char D_80113900[]; +extern unsigned char D_80113944[]; +extern unsigned char D_80113964[]; +extern unsigned char D_8011399C[]; +extern unsigned char D_801139E8[]; +extern unsigned char D_80113A28[]; +extern unsigned char D_80113A50[]; +extern unsigned char D_80113A84[]; +extern unsigned char D_80113AB0[]; +extern unsigned char D_80113AE0[]; +extern unsigned char D_80113B34[]; +extern unsigned char D_80113B68[]; +extern unsigned char D_80113BA4[]; +extern unsigned char D_80113BC0[]; +extern unsigned char D_80113BF0[]; +extern unsigned char D_80113C20[]; +extern unsigned char D_80113C3C[]; +extern unsigned char D_80113C7C[]; +extern unsigned char * func_80141CA4(void); +extern s32 func_8012C588(s32 a0, s32 a1); +extern void func_80142414(s32 a0, s16 a1); +extern u16 D_80126B5E; +extern u16 D_80126B62; +extern u16 D_80126B66; +extern s32 func_8012C51C(void *a0, s32 a1); +extern void func_80142454(s32 a0); +extern void func_8012C218(void *a0); +extern void func_801424E4(short *param_1); +extern void func_801425CC(void *a0); +extern void func_8012C1B8(void); +extern s32 func_8012C1DC(s32 a0); +extern void func_8001CA1C(s32 a0, s32 a1); +extern void func_8012CAE4(void *a0); +extern s32 func_8012AD50(void *a0); +extern void func_80142608(s32 param_1); +extern void func_801426D4(s32 a0); +extern s32 func_8012BEE8(s32 a0); +extern void func_80142740(int param_1); +extern void func_80142778(u8 *a1); +extern void func_801427DC(void); +extern void func_801427E4(void); +extern void func_801427EC(int param_1); +extern s32 func_80142DB8(s32 *a0); +extern s32 func_80142D38(s32 *a0); +extern void func_80142BB4(s32 *a0, s32 a1, s32 a2); +extern void func_801428CC(s32 *a0); +extern void func_8014292C(int param_1); +extern void func_80142978(int param_1); +extern void func_801429C4(int param_1); +extern void func_80142A80(void); +extern void func_80142C7C(void); +extern void func_80142C84(s32 a0); +extern void func_8012CBF4(s32 a0); +extern void func_80142C9C(s32 * arg0); +extern void func_80142B2C(void *arg0); +extern void func_80142DC4(int param_1); +extern void func_80142E38(int param_1); +extern void func_8012A828(s32 a0, void *a1); +extern void func_80142EC0(s32 param_1); +extern void func_80142FFC(s32 *a0); +extern void func_8014305C(int param_1); +extern void func_80143188(s32 *a0); +extern void *memcpy(void *, const void *, u32); +extern int func_8001CA88(int, void *); +extern s32 func_8012E504(s32 a0, s32 a1); +extern void func_800233CC(void *, unsigned short); +extern void func_801431E8(s32 param_1); +extern s32 func_8012C044(s32 a0); +extern void func_80142C9C(s32 *a0); +extern s32 func_8012BF10(s32 a0, s32 a1); +extern void func_8012AD44(s32 *a0, s16 a1); +extern void func_801432FC(s32 *a0); +extern void func_80143390(s32 *a0); +extern void func_80128EA8(s32 a0, s32 a1, s32 a2); +extern void func_80143458(s32 param_1); +extern void func_8014358C(s32 param_1); +extern u8 *func_8012913C(s32 a0); +extern s32 rand(void); +extern void func_80143640(s32 a0, s32 a1, s32 a2, s32 a3); +extern void func_801437D8(s32 a0, s32 a1, s32 a2, s32 a3); +extern s32 func_80143970(s32 a0); +extern s32 func_8012C658(s32 a0, s32 a1, s32 a2); +extern void func_80143994(s32 a0, s32 a1); +extern void func_801439C0(u8 *a0); +extern s32 func_80134510(s32 arg); +extern s32 ratan2(s32 a0, s32 a1); +extern s16 D_801152AC; +extern s16 D_801152AA; +extern u8 D_801152A8[]; +extern void func_801439FC(s32 a0); +extern void func_80143B30(void *a0); +extern s32 func_8012C658(s32 arg0, s32 arg1, s32 arg2); +extern s32 func_80143B6C(s32 arg0, s32 arg1); +extern void func_80143BDC(u16 *a0); +extern void func_80143C38(void *a0); +extern void func_80143C74(s32 a0, s32 a1); +extern void func_80143C98(void *a0); +extern void func_80143CD4(s32 a0); +extern void ApplyMatrixSV(void *a0, void *a1, void *a2); +extern void func_80143D28(s32 param_1); +extern void func_80143E68(void *a0); +extern void func_80143EA4(void); +extern void func_80143EAC(void); +extern void func_80143EB4(void); +extern s32 func_8004787C(s32 a0); +extern void func_80143EBC(s32 a0); +extern void func_80144054(void *a0); +extern void *func_80010A08(s32); +extern void func_8004914C(void *a0); +extern void func_800491AC(void *a0); +extern s32 RotTransPers(s32, s32, s32 *, s32 *); +extern s32 func_80047948(s32 a0); +extern s32 AddPrim(s32, void *); +extern void func_80144090(s32 param_1); +extern void func_801442F8(int param_1); +extern void func_8012C194(void); +extern void func_8001CB6C(u8 *a0, s32 a1, s32 a2, s32 a3); +extern void func_80144364(int param_1); +extern s32 func_8001CC3C(s32 a0, s32 a1, s32 a2, s32 a3); +extern void func_8012B200(u8 *a0); +extern u8 D_800D387C[]; +extern u8 D_800D3888[]; +extern void func_80144558(u8 *param_1); +extern void func_801446A4(int param_1); +extern void func_8014477C(void *param_1); +extern void func_80144880(s32 param_1); +extern void func_80144988(s32 a0); +extern void func_801449C8(void *a0); +extern void func_80144A04(s32 *a0); +extern void func_80144A2C(void *a0); +extern void func_80144A68(s32 *a0); +extern void func_80144A90(void); +extern void func_8001C214(s32 a0, s32 a1); +extern void func_80144A98(u8 *a0); +extern void func_80144B14(void); +extern void func_80144AEC(s32 *a0); +extern void func_801458E0(void); +extern s32 D_800AE6AC; +extern s32 D_800AE6B0; +extern s16 D_800B9A0A; +extern u8 D_80078E50; +extern void func_800D185C(u8 *a0); +extern void func_801458E8(void); +extern void func_80145B24(void); +extern void func_80145934(void); +extern void func_80145A2C(void); +extern void func_80162120(void); +extern void func_80029124(s32, s32); +extern s32 func_80165A50(s32); +extern void func_80029514(s32); +extern u8 D_800AF630[]; +extern u8 D_80078EC0; +extern s32 D_80126B58; +extern void func_80145BF8(void); +extern void func_80145C54(void); +extern void func_80146014(s32 a0); +extern void func_80145EE8(s32 param_1); +extern void MoveImage(void *a0, s32 a1, s32 a2); +extern void func_80146074(void); +extern s32 func_80146128(void); +extern void func_80146360(void); +extern void func_801463A0(); +extern void func_8014607C(void); +extern s32 *D_80126B78; +extern u8 D_80078EC1; +extern s32 D_80078EC8; +extern s32 D_80126B9C; +extern s32 D_8011F730; +extern u16 D_801152B8; +extern u16 D_8012693A; +extern u8 D_80126BE0[]; +extern u8 D_801150F0[]; +extern void *memcpy(void *dst, const void *src, u32 n); +extern void func_80146FC4(s32 a0); +extern void func_80150A70(s32 a0); +extern void func_80147098(s32 *a0); +extern void func_8014A638(s32 arg0); +extern s32 func_80155458(s32 a0); +extern s32 func_80029104(void); +extern void func_80029344(void); +extern void func_8014ADE0(s32 a0); +extern void func_8014B350(s32 a0); +extern void func_8014B7A4(s16 *param_1); +extern s32 func_80161D58(s32 a0); +extern void func_80161A90(s32 a0); +extern void func_8014B504(u16 *a0); +extern void func_80149BEC(s32 a0); +extern void func_8014B5D0(s32 *a0); +extern void func_8014C99C(u8 *a0); +extern void func_8014B190(s32 s0); +extern void func_80148648(s32 a0, s32 a1); +extern s32 func_80149228(s32 a0); +extern void func_8014A59C(s32 a0); +extern void func_8016F14C(void *a0); +extern void func_80154418(void *a0); +extern void func_80154BE4(s32 a0); +extern void func_80165694(s32 arg0); +extern void func_801654A8(s32 a0); +extern void func_8014A680(s32 a0); +extern void func_8014A6A8(s32 a0); +extern void func_8014A71C(s32 a0); +extern void func_80172588(s32 *a0); +extern void func_801473DC(s32 *a0); +extern void func_80015978(s32 a0, s32 *a1); +extern s32 D_80127098; +extern s32 D_80127094; +extern s32 D_80127090; +extern void func_80146534(void); +extern void func_8001D074(s32 a0, s32 a1); +extern void func_80146554(void); +extern void func_80146578(void); +extern void func_8001CFDC(s32, s32); +extern void func_8014659C(void); +extern void func_8001D074(s32, s32); +extern void func_801465C0(void); +extern void func_801465E4(void); +extern void func_801466F0(s32 a0, s32 a1, s32 a2, s32 a3, s32 sp5, s32 sp6, s32 sp7, s32 sp8); +extern s32 D_8011F9D0; +extern s32 func_80146608(s32 a0, s32 a1, s32 a2, s32 a3, s16 arg9, s32 arg10, s32 arg11, s32 arg12, s32 arg13); +extern void func_801466B4(u16 a0, s32 a1, s32 a2, s32 a3, s32 arg5); +extern s32 D_8011F750; +extern s32 D_8011F754; +extern u8 * func_801468C8(s32 arg0, u8 arg1); +extern s32 D_8011D030; +extern s32 func_80146994(s32 a0, s32 a1, s32 a2, s32 a3); +extern s32 func_80146924(s32 a0, s32 a1, s32 a2, s32 a3, s32 arg5); +extern s32 func_80146A6C(s32 a0, void *a1, s32 a2, s32 a3, s32 a4, s32 a5, s32 a6); +extern s32 func_80146994(s32 arg0, s32 arg1, s32 arg2, s32 arg3); +extern s32 func_801469C8(int a0, void *a1, int a2, int a3, u16 arg5, int arg6, int arg7, int arg8); +extern s32 func_80146B9C(void *a0); +extern void func_80146AB4(s16 a0, s32 a1, s16 a2, s16 a3, u16 a4, s32 a5, s32 a6); +extern u16 D_8011DA28; +extern s32 func_80146B9C(void * arg0); +extern void func_80146C3C(u8 *a0); +extern void func_80146C98(s32 *a0, s16 a1); +extern void func_80146CA0(void *a0); +extern void func_80146CB4(void *a0); +extern void func_80146CC8(s32 a0); +extern void func_80146D30(s32 a0); +extern void func_80146D80(s32 *a0); +extern void func_80146DE8(s32 *a0, s32 a1, s32 a2, s32 a3); +extern void func_80146D90(s32 a0); +extern void func_80146DB8(s32 *a0, s32 *a1); +extern void func_80146DF8(s32 *a0, s32 a1, s32 a2, s32 a3, s32 t0); +extern void func_80146E90(s32 *a0, s32 a1); +extern s32 func_80146E98(s32 a0); +extern void func_80015954(s32 a0, s32 a1); +extern void func_80149374(s32 a0, s32 a1); +extern void func_80146F58(s32 a0, s32 a1); +extern void func_80146EC0(s32 a0, s32 a1, s32 a2, s32 a3); +extern u8 D_80126DB0[]; +extern u16 D_80126DB6; +extern void func_8014704C(s32 *a0); +extern s32 func_80147054(void *a0); +extern void func_80147060(u8 * a0); +extern void func_8014706C(void *arg0); +extern void func_80147078(s32 *a0, s16 a1); +extern void func_80147084(s32 *a0); +extern void func_8014708C(void *arg0); +extern s32 func_801470A0(void *a0); +extern void func_801470AC(s32 *a0); +extern void func_801470B4(s32 arg0); +extern void func_801470C0(s32 a0); +extern void func_80147118(s32 a0); +extern s16 D_80126BB8; +extern s16 D_80126BBA; +extern s16 D_80126BBC; +extern void func_80147264(s32 a0); +extern void func_80147290(void); +extern void func_801472B4(void *a0); +extern s32 func_801472C8(struct S *a0); +extern void *D_8012707C; +extern void func_801472DC(void); +extern void func_801472F0(void *a0); +extern void func_80147364(u16, s32); +extern void func_80147300(u16 arg0); +extern void func_80147324(s32 arg0); +extern void func_801473EC(s32 *a0); +extern void func_80147460(s32 a0); +extern void func_80147514(); +extern void func_80147628(s32 a0); +extern void func_80147478(s32 a0); +extern void func_801474D8(s32 *a0); +extern void func_801474EC(s32 *a0); +extern s32 func_80012C6C(s32 a0, s32 a1, s32 a2); +extern s32 func_800129CC(s32 a0, s32 a1); +extern void func_80147514(s32 arg0); +extern void func_80013F3C(s32 a0); +extern void func_80012558(s32 a0, s32 a1); +extern void func_800126C4(s32 a0, s32 a1); +extern void func_800123F0(s32 a0, s32 a1); +extern void func_80147718(s32 a0); +extern void func_80147788(void *a0, s32 a1); +extern void func_801477A8(void *a0, s32 a1); +extern void func_801477C8(void *a0, s32 a1); +extern void func_801477E8(s32 *a0, s32 a1); +extern void func_80147814(s32 a0, s32 a1); +extern void func_80147928(int a0, int a1); +extern void func_8014799C(int a0, int a1); +extern void func_80147A10(int a0, int a1); +extern void func_80147860(int a0, int a1, int a2, int a3); +extern void func_80147948(s32 a0, s32 a1, s32 a2); +extern void func_801479BC(s32 a0, s32 a1, s32 a2); +extern void func_80147A30(s32 a0, s32 a1, s32 a2); +extern void func_801478B8(s32 a0, s32 a1, s32 a2, s32 a3); +extern void func_80147948(int a0, int a1, int a2); +extern void func_801479BC(int a0, int a1, int a2); +extern void func_80147A30(int a0, int a1, int a2); +extern void func_80147AD4(s32 arg0, s32 arg1, s32 arg2, s32 arg3); +extern void func_80147A84(s32 arg0); +extern void func_80147C30(s32 arg0, s32 arg1, s32 arg2, s32 arg3); +extern void func_80147AAC(s32 arg0); +extern void func_80147CC8(s32 a0, s32 a1, s32 a2, s32 a3, s32 a4); +extern void func_80147B5C(s32 a0, void *a1); +extern void func_80147AD4(s32 a0, s32 a1, s32 a2, s32 a3); +extern void func_80147D38(s32 a0, s32 a1, s32 a2, s32 a3, void *a4); +extern void func_80147B18(s32 a0); +extern void func_80147B5C(s32 arg0, void *arg1); +extern void func_80147C30(s32 a0, s32 a1, s32 a2, s32 a3); +extern void func_80147DC0(s32 a0, s32 a1); +extern void func_80147D38(s32 a0, s32 a1, s32 a2, s32 a3, void * a4); +extern void func_800484EC(s32 a0, s32 a1, s32 a2); +extern void func_80147E44(s32 a0, s32 a1, s32 a2, s32 a3); +extern void func_80147F78(s32 arg0, s32 arg1, s32 arg2, s32 arg3); +extern void func_80147F50(s32 arg0); +extern volatile s32 D_80127090; +extern volatile s32 D_80127094; +extern volatile s32 D_80127098; +extern void func_80147F78(s32 a0, s32 a1, s32 a2, s32 a3); +extern void func_80148038(s32 a0, s32 a1); +extern s32 csqrt(s32 a0); +extern s32 func_80012A60(s32 a0, s32 a1); +extern void func_80148094(int param_1, short *param_2, int *param_3); +extern void func_801485B8(s32 a0, s32 a1, s32 a2); +extern void func_801484B0(s32 a0, s32 a1); +extern s32 func_80154358(void *a0); +extern void func_801484E8(s32 a0, s32 a1); +extern void func_80148534(s32 a0, s32 a1); +extern void func_8014856C(s32 a0, s32 a1); +extern void func_801485B8(s32 arg0, s32 arg1, s32 arg2); +extern void func_80148634(void *a0); +extern u8 D_800B9A64; +extern s32 func_80014DC0(); +extern s32 func_80014D68(); +extern s32 func_80014D94(); +extern s32 func_80014CF8(); +extern void func_800120DC(); +extern s32 func_800CF8B4(); +extern u16 func_801487F4(s32 *a0); +extern u16 func_80148800(s32 *a0); +extern u8 func_8014880C(s32 *a0); +extern u16 func_80148818(s32 *a0); +extern s32 func_80047D3C(s32 a0); +extern s32 func_80148824(void *arg0); +extern s32 func_801488A8(u8 *a0); +extern s32 func_8014891C(s32 a0); +extern s32 func_80148980(u8 *a0); +extern s32 func_801489E8(s32 a0); +extern s32 func_80148A48(s32 a0); +extern int func_80148AFC(void *a0); +extern void func_80148AAC(u8 *a0); +extern s32 func_80148C18(void); +extern s32 func_80148C20(s32 a0, s16 a1); +extern s32 func_80148C34(s32 a0, s32 a1); +extern s32 func_80148C4C(s32 a0, s32 a1); +extern s32 func_80148C64(s32 a0, s32 a1); +extern s32 func_80148C7C(void); +extern s32 func_80148C84(s32 a0, s32 a1); +extern s32 func_80148C9C(s32 a0, s32 a1); +extern s32 func_80148CB4(s32 a0, s32 a1); +extern s32 func_80148CCC(s32 a0, s32 a1); +extern s32 func_80148CE4(void); +extern s32 func_80148CEC(void); +extern s32 func_80148CF4(s32 a0, s32 a1); +extern s32 func_80148D0C(s32 a0, s32 a1); +extern s32 func_80148D24(void *a0, int a1); +extern s32 func_80148D3C(void); +extern s32 func_80148D44(void); +extern s32 func_80148F60(void); +extern s32 func_80148F68(s32 a0); +extern s32 func_80148F74(s32 a0); +extern s32 func_80148F80(s32 a0); +extern s32 func_80148F8C(s32 a0); +extern s32 func_80148F98(void); +extern s32 func_80148FA0(s32 a0); +extern s32 func_80148FAC(s32 a0); +extern s32 func_80148FB8(s32 a0); +extern s32 func_80148FC4(s32 a0); +extern s32 func_80148FD0(void); +extern s32 func_80148FD8(void); +extern s32 func_80148FE0(s32 a0); +extern s32 func_80148FEC(s32 a0); +extern s32 func_80148FF8(s32 a0); +extern s32 func_80149004(void); +extern void func_8014900C(s32 *a0); +extern void func_80149020(s32 *a0); +extern void func_80149034(s32 *a0); +extern void func_80149048(s32 *a0); +extern void func_8014905C(u8 *a0); +extern void func_801490E0(s32 *a0, s16 a1); +extern void func_801490E8(s32 *a0, s16 a1); +extern void func_801490F0(s32 *a0, s16 a1); +extern void func_80149078(s32 *a0, s32 a1, s32 a2, s32 a3); +extern s32 func_80012B04(s32 a0, s32 a1, s32 a2); +extern void func_801490F8(s32 a0, s32 a1); +extern s32 func_801491C4(s32 a0); +extern s32 func_80149184(s32 a0); +extern s32 D_801151D4; +extern void func_80149204(s32 *a0); +extern void func_80149210(s32 a0, s32 a1); +extern s32 func_80149284(s32 *a0, s32 a1); +extern void func_80149350(s32 arg0); +extern void func_80149290(s32 a0); +extern void func_8012F14C(s32); +extern void func_8012F038(s32); +extern void func_8014942C(s32 arg0); +extern s32 func_801496D4(void *a0); +extern void func_8015AD08(); +extern void func_80149704(void); +extern void func_8015ACC4(); +extern void func_80149724(void); +extern u8 D_80078EBF; +extern s32 func_80149744(struct S_80149744 *a0); +extern void func_8015F7A0(); +extern void func_80149788(void); +extern void func_801653B8(); +extern void func_80149864(void); +extern s32 func_8016F1AC(void); +extern s32 func_80149884(void); +extern void func_80160B00(); +extern void func_801498C0(void); +extern s32 func_80149AA8(s32 *a0); +extern s32 func_80149B54(s32 *a0); +extern void func_80146750(void *a0); +extern s32 func_801498E0(s32 *a0); +extern s32 func_80149A64(s32 *a0); +extern void func_8015DAC4(s32 *a0); +extern void func_8015554C(s32 *a0); +extern void func_80149AD4(s32 *a0); +extern void func_80149B14(s32 *a0); +extern u8 func_8014BEF8(void); +extern s32 func_80149B54(s32 * arg0); +extern void func_8015DE24(s32 *a0); +extern void func_80157510(s32 *a0); +extern void func_80149BAC(s32 *a0); +extern s32 func_80149C08(s32 arg0); +extern void func_801577C8(); +extern void func_80149C94(void); +extern void func_80157D20(void); +extern void func_80149CB4(void); +extern s32 func_80149CD4(s32 a0); +extern u8 func_8014B5B8(s32 *a0); +extern s32 func_80149D10(s32 a0); +extern s32 func_80149E94(s32 a0); +extern s32 func_80149DD8(s32 a0); +extern s32 func_80149D9C(s32 a0); +extern s32 func_80149F2C(s32 a0, s32 a1); +extern s32 func_80149E94(s32 arg0); +extern void func_80149FA8(void); +extern s32 func_80149FB0(s32 a0); +extern s32 func_80135260(s32, s32, s32, s32); +extern void func_8014A1B0(s32 a0, s32 a1); +extern s32 func_8014A048(s32 param_1); +extern u16 func_80156370(u16 a0); +extern void func_8014C4AC(s32 a0, s32 a1, s32 a2, s16 *a3, s32 a4); +extern void func_8015D4B4(); +extern void func_8014A218(void); +extern s32 func_8014C278(s32 a0, s32 a1, s32 a2); +extern s32 func_8014C2B0(void *a0, void *a1, s32 a2); +extern s32 func_8014A238(s32 arg0); +extern s32 func_8014A2E4(s32 a0); +extern void func_8014A380(s32 a0, s32 a1); +extern s16 D_801152B0; +extern s16 D_801152B4; +extern s32 func_8014A3E0(struct S_8014A3E0 *a0); +extern s32 func_8014A454(s32 a0); +extern s32 func_8014A4B4(void *a0); +extern void func_8015EDD4(); +extern void func_8014A4FC(void); +extern s32 func_8014A674(s32 *a0); +extern s32 func_8014A69C(s32 *a0); +extern s32 func_8014A6C4(s32 a0); +extern void func_8015E184(); +extern void func_8014A830(void); +extern s32 func_80029AF4(void); +extern s32 func_8014A850(s32 param_1); +extern void func_801599A4(void *a0); +extern void func_80159B3C(void *a0); +extern s32 func_80165A20(s32 a0); +extern void func_8014AB7C(); +extern void func_8014AC10(); +extern void func_8014AA28(void); +extern void func_8014AB5C(void); +extern void func_80162CCC(void); +extern void func_8014AB7C(s32 arg0); +extern void func_8014ABF0(void); +extern void func_8014AC10(s32 arg0); +extern void func_8014ACC0(s32 a0, s32 a1); +extern void func_8014AD30(s32 a0, u16 *a1, s32 a2, s32 a3); +extern void func_8014ACE8(void *a0, s32 a1, s32 a2); +extern void func_80146AFC(void *a0); +extern void func_8014ADA8(s32 a0, s32 a1); +extern void func_8014AD7C(s32 a0); +extern s32 D_80078E8C; +extern u8 D_80078E78[]; +extern s32 func_8016F1C4(void); +extern s32 func_8014B154(s32 *a0); +extern void func_8014BD24(s32 a0, s32 a1); +extern void func_8014BB24(s32 a0, s32 a1, s32 a2); +extern void func_8014BC80(s32 a0, s32 a1); +extern void func_8014BD60(s32 a0, s32 a1); +extern void func_8014B084(void); +extern void func_8014B034(s32 arg0); +extern void func_8014B00C(s32 arg0); +extern s16 D_80078E90; +extern void func_8014B034(s32 a0); +extern u16 D_80078EAC; +extern u8 D_80078EBA; +extern void func_800D10EC(void); +extern void func_8002AC98(void); +extern void func_8014B12C(void); +extern void func_8014B2F8(void); +extern void func_8014B4C4(void); +extern void func_8014B160(s32 a0); +extern s16 D_80078E96; +extern s16 D_80078EB8; +extern u16 D_80078EA6; +extern void func_8014B2A8(void); +extern void func_8014B310(void); +extern void func_8014B2D0(void); +extern s32 D_80078E94; +extern s32 D_80078ECC; +extern void func_8014B33C(void); +extern u8 D_80062BF4[]; +extern s32 D_80078E98; +extern void func_80166244(); +extern void func_8014B4D4(void *a0); +extern s16 D_80078E9A; +extern u8 D_80126D1C; +extern s32 D_80126D74; +extern void func_8014B598(s32 a0, s32 a1); +extern void func_8014B5B0(s32 *a0); +extern void func_8014B5C4(s32 *a0, s32 a1, s32 a2); +extern void func_8014B5D8(s32 s1); +extern s32 D_80078E9C; +extern s32 D_80078ED0; +extern void func_8014B6F0(s32 a0, s32 a1); +extern void func_8014B768(s32 a0, s32 a1); +extern void func_8014B944(s32 a0, s32 a1, s32 a2); +extern s32 D_80078EA4; +extern u16 D_80078EB2; +extern s16 D_80078EB4; +extern void func_8014BB0C(void); +extern void func_8014BC0C(s32 a0, s32 a1); +extern void func_8014BC44(s32 a0, s32 a1); +extern u8 D_800B9A17; +extern void func_8014BCC0(s32 a0, s32 a1); +extern u16 D_80078EB6; +extern s32 func_8014BCEC(s32 a0, s32 a1); +extern void func_8014BD60(s32 param_1, s32 param_2); +extern void func_8014BD98(s32 a0, u16 a1); +extern void func_8014BDC8(void); +extern void func_8014BDE0(void); +extern s32 func_8017267C(s32 *a0); +extern s32 func_80013294(void *a0, void *a1); +extern void func_80029ED4(s32 a0); +extern void func_8014BDE8(s32 a0); +extern void func_8014BE78(void); +extern void func_8014BE9C(void); +extern void func_80029124(s32 a0, s32 a1); +extern void func_8014BEC0(void); +extern void func_8014BF18(s32 a0); +extern void func_8014BF48(void); +extern u8 func_8014BF6C(void); +extern void func_8014BF8C(u8 arg0); +extern void func_8014BFB0(void); +extern u8 func_8014BFD4(void); +extern void func_8014BFF4(s32 a0, s32 a1); +extern void func_8014C010(s32 a0, s32 a1); +extern s32 func_8014C050(s32 a0, s32 a1); +extern s32 func_8014C088(s32 a0, s32 a1); +extern s32 func_8014C0C8(s32 a0_unused, s32 a1, s32 a2); +extern s32 func_8014C118(void * a0, s32 a1, s32 a2); +extern s32 func_8014C168(s32 * param_1, s32 param_2); +extern s32 func_80133784(s32 a0, void *a1, s32 a2); +extern void func_8014C1C8(s32 a0, s32 a1, void* a2); +extern s32 func_80013328(s32 a0, s32 a1); +extern s32 func_8014C59C(void *a0, void *a1); +extern s32 func_8014C308(s32 arg0, s32 arg1, s32 arg2, s32 arg3); +extern s32 func_8014C43C(void *a0, s32 a1, s32 a2, s32 a3, s16 a5); +extern s32 func_8014C3A4(void *a0, s32 a1, s32 a2, s32 a3); +extern s32 func_8014C3D0(void *a0, s32 a1, s32 a2, s32 a3); +extern s32 func_8014C43C(void * a0, s32 a1, s32 a2, s32 a3, s16 a4); +extern s32 ratan2(s32 dx, s32 dy); +extern s32 func_8014C5FC(s32 a0, s32 a1, void *a2); +extern s16 func_8014C5D0(s32 a0, s32 a1); +extern s32 func_8014C5FC(s32 a0, s32 a1, void * a2); +extern u8 D_80126D17; +extern void func_8014C6AC(void); +extern void func_8014C6C0(void); +extern u8 D_80126D1E; +extern void func_8014C6D0(void); +extern void func_8014C6E0(void); +extern s32 func_8014C860(s32 a0, s32 a1); +extern void func_8014C8C8(s32 a0, s32 *a1); +extern void func_8014C88C(s32 a0); +extern void func_8014C8C8(s32 dst, s32 * src); +extern void func_8014C8F0(s32 arg0); +extern u8 D_801151F0[]; +extern s32 func_8014C918(s32 a0, s32 a1); +extern s32 D_80126B50; +extern void func_8014C968(void); +extern void func_8014C978(void); +extern s32 func_8014C98C(void); +extern void func_80139914(s32 a0); +extern s32 func_8014CA00(s32 a0); +extern u16 func_8014CA70(s32 a0, s32 a1); +extern s32 func_8014CA14(s32 a0, s32 a1); +extern u16 func_8014CAE4(s32 *a0, s32 a1); +extern s32 func_8014CA88(s32 *a0, s32 a1); +extern s32 func_8014CAFC(void); +extern s32 func_8014CB0C(void); +extern s32 func_8014CB1C(void); +extern u8 D_80126D1F; +extern s32 func_8014CB2C(void); +extern s32 func_8014CB58(void); +extern u8 D_80126D1D; +extern void func_8014CB68(void); +extern s32 func_8014CB7C(void); +extern s32 func_8014CB8C(void); +extern struct Packed8 D_80126C98; +extern short D_80126C9E; +extern void func_8014CB9C(struct Packed8 *a0); +extern s32 D_80126CDC; +extern void func_8014CBD8(void); +extern void func_8014CBF8(void *a0); +extern void func_8014D3E0(s32 a0); +extern void func_8014D04C(void); +extern void func_8014CCB4(void); +extern void func_8014CC28(s32 a0); +extern void func_8014CD0C(u8 *a0); +extern void func_8014CF04(); +extern void func_8014CD80(s32 a0, void *a1, void *a2); +extern s32 func_8014D2A0(s32 a0, void *a1, void *a2); +extern s32 func_8014D12C(s32 a0, void *a1, void *a2); +extern void func_8014D0A4(s32 a0); +extern void func_8014D610(s32 a0, void *a1, void *a2); +extern s32 func_8014D4C0(s32 a0, void *a1, void *a2); +extern void func_8014D438(s32 a0); +extern s32 func_8014DD8C(s32 a0, void *a1, void *a2); +extern s32 func_8014D820(s32 a0, u16 *a1, u16 *a2); +extern void func_8014D790(s32 a0); +extern s32 func_80135888(s32 a0, s32 a1, s32 a2, s32 a3); +extern s32 func_8014DCE0(s32 arg0, s32 arg1, s32 arg2); +extern s32 func_8014DD8C(s32 arg0, void *arg1, void *arg2); +extern s32 func_8014E284(s32 a0, s16 *a1, s16 *a2); +extern s32 func_8014E048(s32 a0, u16 *a1, u16 *a2); /* u16*: def lhu semantics (T5b reconcile; ptr param type codegen-neutral for the caller) */ +extern void func_8014DF94(s32 arg0); +extern s32 func_80135A4C(s32 a0, s32 a1, s32 *a2, s32 a3); +extern u8 D_801152A8[]; /* canonical TU type (engine_core) — read via *(u16*) cast */ +extern s32 func_8014E048(s32 param_1, u16 * param_2, u16 * param_3); +extern s32 func_80135A4C(s32 a0, s32 a1, s32 *a2, s32 a3); /* canonical (engine_core.h:11555) */ +extern s32 func_8014E284(s32 a0, s16 *arg1, s16 *arg2); +extern void func_8014E5B4(s32 a0, void *a1, void *a2); +extern s32 func_8014E514(u8 *a0, s32 a1, s32 a2); +extern void func_8014E48C(s32 a0); +extern s32 func_8014E83C(s32 a0, s16 *a1, s16 *a2); +extern s32 func_8014E790(s32 a0, s16 *a1, s16 *a2); +extern void func_8014E6F8(struct SubE6F8 *a0); +extern s32 func_8014E790(s32 arg0, s16 * arg1, s16 * arg2); +extern s32 func_8014E83C(s32 arg0, s16 * arg1, s16 * arg2); +extern s32 func_8014EA4C(void *a0, void *a1, void *a2, s32 a3); +extern s32 func_8014E98C(void *a0); +extern u16 D_800B99DA; +extern s32 D_801150D8; +extern u8 D_80126720[]; +extern s16 D_80126724; +extern s32 func_8014EA4C(void * a0, void * a1, void * a2, s32 _arg3); +extern s32 func_8014EE14(s32 a0, s16 *a1, s16 *a2); +extern s32 func_8014ED80(struct SubED80 *a0); +extern s32 func_8014EE14(s32 arg0, s16 * arg1, s16 * arg2); +extern s32 func_8014F2E0(s32 a0, s16 *a1, s16 *a2); +extern s32 func_8014F24C(struct SubF24C *a0); +extern s32 func_8014F2E0(s32 arg0, s16 * arg1, s16 * arg2); +extern void func_8014F4C0(u8 *a0); +extern s32 func_8014F468(void); +extern u8 D_800D3918[]; +extern s32 D_801152BC; +extern int func_8014F74C(s32 arg0); +extern s32 func_8014FA70(s32 a0); +extern void func_8014FA04(s32 a0); +extern s32 func_8014FC18(u8 *self); +extern int func_8014FD54(int param_1); +extern s32 func_80150170(void *a0); +extern s32 func_8014FE60(void *a0); +extern void func_8014FDF4(struct S8014FDF4 *a0); +extern s32 func_80135D20(s32 a0, s32 a1, void *a2); +extern s32 func_8014FFDC(s32 e, void *a1, void *a2); +extern s32 func_80150150(s32 a, s32 b); +extern s32 func_801502EC(s32 e, void *a1, void *a2); +extern s32 func_80150460(s32 e, s32 a1); +extern s32 func_80150170(void *e); +extern s32 func_80150460(s32 a, s32 b); +extern s32 func_80150528(void *a0, void *a1, void *a2); +extern void func_801504D8(u16 *a0); +extern s32 func_80150528(void *arg0, void *arg1, void *arg2); +extern s32 func_801506A4(s32 a0, s32 a1); +extern s32 func_801505FC(s32 a0); +extern void func_80150820(s32 a0, s32 a1); +extern void func_8015086C(int param_1); +extern s32 func_801508B4(s32 a0); +extern s32 func_8015094C(s32 a0); +extern short func_801508F8(s32 a0); +extern s32 func_80021174(s32 a0, s32 a1); +extern s32 func_8015094C(s32 param_1); +extern void func_80150B28(int param_1); +extern void func_80150B9C(void); +extern s32 func_80151184(s32 a0, s32 a1, s32 a2); +extern s32 func_80150BA4(s32 a0); +extern s32 func_801619D0(void *a0); +extern void func_80150BC8(s32 *a0); +extern s32 func_80150480(s32 a0); +extern u16 D_800AE6DC; +extern void func_80150C48(s32 a0); +extern int func_80151184(int arg, int a1, int a2); +extern int func_80150CA0(int arg); +extern void func_80150EC4(s32 a, s32 b); +extern void func_80150CC4(s32 a); +extern void func_80150CE4(s32 a); +extern void func_80150D04(s32 a); +extern void func_80150D24(s32 a); +extern void func_80150D44(s32 a); +extern void func_80150D64(s32 a); +extern void func_80150D84(s32 a); +extern void func_80150DA4(s32 a); +extern void func_80150DC4(s32 a); +extern void func_80150DE4(s32 a); +extern void func_80150E04(s32 a); +extern void func_80150E24(s32 a); +extern void func_80150E44(s32 a); +extern void func_80150EC4(s32 a0, s32 a1); +extern void func_80150E64(s32 a0); +extern void func_80150E84(s32 a0); +extern void func_80150EA4(s32 a0); +extern u8 D_800AE6C0; +extern s16 D_800AE6C8; +extern s16 D_800AE6CA; +extern u8 D_80126948[]; +extern s16 D_800AE6CC; +extern s32 D_800AE6C4; +extern s16 D_800AE6CE; +extern u8 D_800AE6BE; +extern u8 D_801201F8[]; +extern void func_80150F78(void); +extern void func_80150F80(s32 a0); +extern int func_80150FB4(int arg); +extern void func_80150FD8(s32 a0); +extern int func_80151014(int arg); +extern void func_80151038(s32 a0); +extern int func_80151070(int arg); +extern int func_80151094(int arg); +extern void func_801510B8(void); +extern void func_801510C0(void); +extern int func_801510C8(int arg); +extern int func_801510EC(int arg); +extern s32 func_8012DB84(void); +extern s32 func_80151110(void); +extern void func_80151130(void); +extern int func_80151138(int arg); +extern void func_8015115C(s32 *a0, s16 a1); +extern s32 func_80151164(s32 a0, s32 a1); +extern s32 func_80151184(s32 arg0, s32 arg1, s32 arg2); +extern void func_801511A8(u8 *a0); +extern void func_801511C4(u8 *a0); +extern int func_80151204(int arg, int a1); +extern int func_801511E0(int arg); +extern int func_80151204(int a0, int a1); +extern void func_80151238(void *a0); +extern void func_8015126C(u16 *p); +extern void func_80151780(s32 a0); +extern void func_801516F0(s32 *a0); +extern void func_8015173C(s32 *a0); +extern s16 D_8011DB1A; +extern s32 D_80127518; +extern s32 D_801151FC; +extern s32 func_801725CC(u8 *a0); +extern s32 func_80029D3C(void); +extern void func_80151878(void); +extern void func_80153B58(s32 *a0); +extern s32 func_80151880(s32 a0); +extern s32 func_801518D8(s32 a0); +extern s32 func_80151944(void); +extern s32 func_80151924(void); +extern void func_8014E934(s32 a0); +extern s32 func_8014F3E8(s32 a0); +extern void func_801519C8(s32 a0); +extern void func_80151980(s32 a0); +extern M2C_UNK D_800D5880; +extern s32 D_800D58AC; +extern void func_80154274(s32 *a0, s32 a1); +extern void func_80154A74(s32 a0, s32 a1); +extern void func_801519C8(s32 arg0); +extern void func_80151C54(s32 a0); +extern void func_801542DC(s32 *a0, s32 a1); +extern void func_8015BDD0(s32 *a0); +extern void func_80165718(s32 a0); +extern u8 D_800D46E4[]; +extern void func_80151AE4(s32 arg0); +extern void func_80151D24(void *a0); +extern void func_80151DB0(s32 a0); +extern void func_80151D60(void *a0); +extern s32 func_80172630(u8 *a0); +extern s32 D_80062C14; +extern void func_80151DB0(s32 param_1); +extern void func_80151E78(s32 *a0); +extern void func_80151ECC(struct S80151ECC *a0); +extern void func_80151FB4(s32 a0); +extern void func_80151F38(s32 *a0); +extern void func_801553C0(s32 a0); +extern void func_80153C18(); +extern void func_80152058(void *a0); +extern void func_801520DC(s32 a0); +extern void func_80152094(s32 a0); +extern void func_80147324(s32 a0); +extern void func_801520DC(s32 arg0); +extern void func_801470B4(s32 a0); +extern void func_8015369C(s32 a0); +extern void func_80152194(s32 *a0); +extern s32 func_801536DC(s32 a0); +extern void func_8015220C(s32 a0); +extern s32 func_80153800(s32 a0); +extern void func_801522CC(s32 a0); +extern void func_80152254(s32 *a0); +extern void func_80152370(void *a0); +extern void func_801523F4(s32 a0); +extern void func_801523AC(s32 a0); +extern void func_8001382C(s32 a0, void *a1, void *a2); +extern void func_801523F4(s32 arg0); +extern void func_801525F4(int); +extern s32 func_801535F4(void *arg0); +extern void func_8015BF48(s32 *a0); +extern void func_80152500(int param_1); +extern void func_801525F4(s32 a0); +extern void func_80152698(void *a0); +extern void func_80152714(s32 a0); +extern void func_801526D4(s32 a0); +extern void func_80152790(s32 a0); +extern void func_8015282C(void *a0); +extern void func_801528B0(s32 a0); +extern void func_80152868(s32 a0); +extern void func_801528B0(s32 arg0); +extern void func_8015294C(s32 a0); +extern void func_80152A08(s32 a0); +extern void func_80152AC8(s32 a0); +extern void func_80152A50(s32 *a0); +extern void func_80152B6C(void *a0); +extern void func_80152BF0(s32 a0); +extern void func_80152BA8(s32 a0); +extern void func_80152C80(s32 *a0); +extern void func_80152C40(s32 *a0); +extern void func_80152C80(s32* a0); +extern void func_80152D24(void *a0); +extern void func_80152DA8(s32 a0); +extern void func_80152D60(s32 a0); +extern void func_80152DA8(s32 arg0); +extern void func_80152E4C(s32 a0); +extern void func_80152EFC(s32 a0); +extern void func_80152FBC(s32 a0); +extern void func_80152F44(s32 *a0); +extern void func_80153060(void *a0); +extern void func_801530E4(s32 a0); +extern void func_8015309C(s32 a0); +extern void func_80155440(s32 *a0); +extern u8 D_80062C04[]; +extern void func_801530E4(s32 arg0); +extern void func_80153150(struct S80153150 *a0); +extern void func_801531BC(s32 a0); +extern void func_8015327C(s32 a0); +extern void func_80153204(s32 *a0); +extern void func_80153320(void *a0); +extern void func_801533A4(s32 a0); +extern void func_8015335C(s32 a0); +extern void func_80153410(s32 *a0); +extern void func_80153490(s32 a0); +extern void func_80153550(s32 a0); +extern void func_801534D8(s32 *a0); +extern void func_8014ED28(s32 _arg0); +extern void (*D_8011DB28)(s32 a0); +extern s32 func_801536DC(s32 param_1); +extern void func_800139C8(s32 a0, void *a1, void *a2); +extern s32 func_80153978(s32 a0, u16 *src); +extern s32 func_80133784(s32 a0, void *src, s32 dst); +extern s32 func_801539F8(s32 a0, void *a1); +extern s32 func_801539F8(s32 a0, void * a1); +extern s32 func_8016DA04(s32 a0); +extern s32 func_80153BD8(s32 a0); +extern s32 func_80153BF0(s32 a0); +extern void func_80153C18(void); +extern u16 D_8011F748; +extern void func_80153C30(void); +extern void func_80153C74(s16 a0, s16 a1); +extern s16 D_8011DB18; +extern void func_80153C44(int a0, int a1, s16 a2); +extern s16 D_8011DB0C; +extern s32 D_80115210; +extern void func_80153C8C(void); +extern void func_80153C9C(void); +extern s32 func_80153CBC(void); +extern void func_80153CCC(S80153CCC *a0); +extern void func_80153D7C(s32 a0); +extern void func_80153D34(s32 a0); +extern void func_80153D7C(s32 param_1); +extern void func_8015410C(void); +extern void func_80153E00(s32 param_1); +extern void func_80151664(void); +extern void func_80154134(u8 *a0); +extern void func_80154190(u8 *a0, s32 a1); +extern void func_80154150(s32 a0, s32 a1); +extern void func_80154218(u8 *a0, s32 a1, s32 a2); +extern void func_801541D8(u8 *a0, s32 a1, s32 a2); +extern s32 func_801549F8(s32 a0, s32 a1, s32 a2); +extern void func_801542A4(); +extern void func_801542A4(s32 *a0, s32 a1); +extern void func_8015430C(); +extern void func_8015430C(u8 *arg0, s32 arg1, s32 arg2); +extern void func_8015444C(void *a0, s32 *a1, s32 *a2, s32 *a3); +extern s32 func_80154358(void * arg0); +extern void func_80154AB4(s32 a0, s32 a1); +extern void func_80154B20(s32 a0, s32 a1, s32 a2); +extern void func_80154AE0(s32 a0, s32 a1, s32 a2); +extern void func_80154B7C(u8 *a0, s32 a1); +extern void func_80154B4C(u8 *a0, s32 a1); +extern void func_80154BC8(void *a0, s32 a1, s32 a2); +extern void func_80154B98(void *a0, s32 a1, s32 a2); +extern void func_80154ED8(s32 a0, s32 a1); +extern void func_80154C24(s32 param_1, s32 *param_2, s32 *param_3); +extern u8 D_800D8D10[]; +extern s16 D_80078E9E; +extern void func_801550FC(s32 a0); +extern void func_80154F9C(s32 a0); +extern void func_800183E0(s32 a0); +extern void func_801550FC(s32 arg0); +extern void func_8001D150(s32, s32); +extern void func_8001D130(int, int); +extern void func_80155150(int param_1); +extern s32 D_800DE2A4[]; +extern void func_801552F4(s32 a0); +extern void func_80155344(s32 a0); +extern s32 func_80155394(s32 *a0); +extern void func_801553A8(s32 *a0); +extern s32 func_80029178(s32); +extern s32 func_80155458(s32 param_1); +extern s32 func_801659DC(u8 *a0); +extern s32 func_801554B8(void *arg0); +extern void func_801555F4(void *a0); +extern void func_80155518(s32 *a0); +extern void func_80155580(void *a0); +extern s32 func_80161104(void); +extern void func_801555F4(void *); +extern void func_801555BC(void *a0); +extern int func_80155A44(int param_1); +extern int func_80161208(); +extern u8 D_800D4DA8[]; +extern void func_80155B20(s32 *a0); +extern s32 D_800D4DB4; +extern void func_80155B9C(s32 a0); +extern u8 D_800D4DD4[]; +extern void func_80155C0C(s32 *a0); +extern void func_8014ED28(s32 a0); +extern int func_80155FF8(int arg, int a1); +extern s32 D_800D4DF4; +extern void func_80155C64(s32 a0); +extern void func_8015E880(s32 *a0); +extern void func_80155D70(s32 param_1); +extern void func_80155E30(void *a0); +extern s32 func_80161208(); +extern void func_80155EA4(void *arg0); +extern void func_80155F58(void); +extern s32 func_80155F80(); +extern s32 func_80155F60(void); +extern s32 func_80155F80(s32 a0); +extern int func_80155FB0(int arg, int a1); +extern int func_80155FD4(int arg, int a1); +extern int func_80156044(int arg, int a1); +extern S801563EC *func_801563EC(u16 idx); +extern s32 func_80029B4C(s32 a0, s32 a1); +extern s32 func_80029BC8(s32 a0, s32 a1); +extern s32 func_80029C44(s32 a0, s32 a1); +extern s32 func_8015640C(s32 a0, s32 a1); +extern u32 func_8015616C(s32 param_1, u16 param_2); +extern u16 func_80156370(u16 param_1); +extern S801563EC * func_801563EC(u16 idx); +extern s32 func_801564B0(s32 a0); +extern s32 D_801151E0[]; +extern s32 func_801565C0(void); +extern void func_80156A14(s32 *a0); +extern void func_80156648(s32 *a0); +extern u8 D_8011DAD8[]; +extern s32 func_8014C568(void *a0); +extern void func_801567BC(s32 a0); +extern B8 D_80128120[]; +extern B8 D_80128138[]; +extern S8 D_80126AF0[]; +extern u8 D_80126730[]; +extern void func_80156848(s32 param_1, s32 param_2); +extern void func_80156A1C(s32 param_1, s32 param_2); +extern s32 D_801150E0[]; +extern void func_80156A88(s32 a0, s32 a1); +extern void func_80156B74(s32 param_1, u32 param_2, u8 *param_3); +extern void func_80156ECC(int param_1, int param_2, int param_3, int param_4, int param_5); +extern void func_80156FA8(s16 *param_1, s16 *param_2, s16 *param_3); +extern void func_80157158(s32 a0, u16 a1, u16 a2, s32 a3, s32 a4, s32 a5, s32 a6, s32 a7, s32 a8, s32 a9, u16 a10, s32 a11, s32 a12); +extern s32 func_80135004(s32 a0, void *a1, s32 a2); +extern s32 func_80135260(s32 a0, s32 a1, s32 a2, s32 a3); +extern u32 func_801571C4(s32 a0, u16 a1, u16 a2, s32 a3, s32 a4, s32 a5, s32 a6, s32 a7, s32 a8, s32 a9, u16 a10, s32 a11, s32 a12); +extern void func_801575E4(void *a0); +extern void func_801574DC(s32 *a0); +extern void func_80157544(void *a0); +extern void func_8014CC28(s32 a0); /* defined */ +extern s32 func_8014F3E8(s32 a0); /* declared */ +extern void func_8015BDD0(s32 *a0); /* defined */ +extern void func_801575E4(void *a0); /* defined */ +extern void func_80157580(s32 arg0); +extern u8 D_800D4F14[]; +extern void func_801576A8(void *arg0); +extern s32 func_8015773C(u8 *a0); +extern s32 func_8015771C(u8 *a0); +extern s32 func_8015773C(u8 * arg0); +extern void func_801578C0(s32 a0); +extern void func_80157788(int param_1); +extern void func_80157808(s32 a0); +extern void func_801577C8(int param_1); +extern void func_80157880(s32 a0); +extern s32 func_801725A4(u8 *a0); +extern void func_801578C0(s32 param_1); +extern void func_80147A84(int); +extern void func_80148038(int, int); +extern void func_80147460(int); +extern void func_80146D90(int); +extern void func_80161450(void *a0); +extern void func_80157A8C(int); +extern void func_80154A74(int, int); +extern void func_8015795C(int param_1); +extern void func_80161D20(s32 a0, s32 a1); +extern void func_80157A8C(s32 a0); +extern void func_8016706C(s32 a0); +extern u8 D_800D51AC[]; +extern void func_80157AC8(s32 param_1); +extern void func_80157B74(int param_1); +extern void func_8016158C(void *a0); +extern void func_8015BE04(s32 *a0); +extern void func_80157BC8(s32 a0); +extern void func_80157CCC(s32 a0); +extern void func_80157DC4(void *a0); +extern void func_80157FC4(void *a0); +extern void func_80157D74(u16 *a0); +extern void func_80157E38(void *); +extern void func_80157E00(void *a0); +extern void func_80157E38(void * a0); +extern s32 func_80157F64(s32 *a0); +extern s32 func_80156600(void *a0); +extern void func_80157EA4(void *a0); +extern void func_80158038(void *); +extern void func_80158000(void *a0); +extern void func_80158038(void * param); +extern u8 D_800D524C[]; +extern void func_80161418(void *a0); +extern void func_801580B4(s32 a0); +extern void func_801581AC(s32 a0); +extern void func_8015824C(void *a0); +extern void func_801582C0(void *); +extern void func_80158288(void *a0); +extern u8 D_800D52A8[]; +extern void func_801585A4(s32 *a0); +extern void func_801582C0(void *a0); +extern s32 func_801585AC(s32 *a0); +extern u8 D_800D52E8[]; +extern void func_80158344(s32 *a0); +extern s32 func_801615C4(void *a0, s32 a1); +extern void func_80158434(s32 param_1); +extern void func_80158548(s32 param_1); +extern void func_801585EC(u8 *a0); +extern void func_80158794(void); +extern void func_80158880(s32 *param); +extern void func_8015879C(s32 param_1); +extern void func_80158814(void *arg0); +extern int func_800D0CA0(int); +extern int func_8001AAA0(int); +extern int SsGetMute(void); +extern s32 func_80159464(void); +extern void func_801588CC(int param_1); +extern void func_80158AE4(void *a0); +extern void func_80158AB4(void *a0); +extern void func_8016F264(void); +extern void func_80165840(void); +extern void func_801658DC(void); +extern void func_80165A78(s32); +extern void func_80158AE4(void * a0); +extern void func_80158BB0(void *arg0); +extern s32 func_80159404(s32 a0, s32 a1); +extern void func_80158C40(s32 *a0); +extern void func_80158CD8(s32 *a0); +extern s32 func_80159434(s32 a0, s32 a1); +extern void func_80158D60(s32 a0); +extern M2C_UNK D_800D5904; +extern void func_80158E24(s32 *a0); +extern int rand(void); +extern s32 func_8013767C(s32 a0); +extern void func_80158F00(int param_1); +extern s32 func_801399F0(s32); +extern void func_80139914(s32); +extern void func_801594E8(s32, s32); +extern void func_80158FA4(s32 param_1); +extern s32 func_801399F0(s32 a0); +extern u8 D_80110C94[]; +extern u8 D_80110CD4[]; +extern void func_80159070(void *a0); +extern s32 func_80029A94(s32); +extern void func_80175454(void); +extern void func_800298BC(void *); +extern void func_8002992C(s32); +extern void func_800CF804(void); +extern void func_800CF818(void); +extern u8 D_80110D0C[]; +extern u8 D_80110C3C[]; +extern void func_80159120(s32 a0); +extern void func_801592CC(s32 *a0); +extern void func_8015934C(void *arg0); +extern void func_801593E4(A801593E4 *a0); +extern s32 func_800291B4(s32); +extern void func_80029274(void); +extern void func_80029044(void); +extern void func_8002906C(void); +extern void func_80029094(void); +extern void func_8002941C(void); +extern void func_8002AB64(void); +extern void func_800D185C(u8 *); +extern void func_800D1F90(void); +extern void func_801594E8(s32 param_1, s32 param_2); +extern void func_80159698(void *a0); +extern s32 func_801596D4(void *a0); +extern void func_80174B6C(void); +extern void func_80129248(s16 a0); +extern void func_8013C938(void); +extern void func_8002850C(s32, s32, s32); +extern void func_80028620(s32, void *); +extern s32 func_801596F0(s32 param_1); +extern s32 func_80159874(void); +extern void func_800167B8(s32 a0); +extern s32 func_8015987C(s32 a0); +extern int func_800167F0(int arg); +extern int func_801598BC(void); +extern void func_80159968(void *a0); +extern void func_801598E0(u8 *a0); +extern void func_80159A20(void *a0); +extern void func_801599E0(void *a0); +extern void func_80159A18(void); +extern void func_80159BE4(s32); +extern void func_80159B08(s32 *a0); +extern void func_80159B70(void *a0); +extern void func_80159B3C(void * a0); +extern void func_80159BAC(s32 a0); +extern s32 func_80172590(u8 *a0); +extern void func_80159BE4(s32 arg0); +extern void func_8015A1C8(s32 a0); +extern void func_8015A2D8(s32); +extern void func_8015A1FC(s32 *a0); +extern void func_8015A264(void *a0); +extern void func_8015A230(s32 *a0); +extern void func_8015A2A0(s32 a0); +extern s32 func_80172608(u8 *a0); +extern void func_8015A2D8(s32 param_1); +extern u8 D_800D48DC; +extern s32 func_8015AB7C(s32 a0); +extern s32 D_8011F9C4; +extern s32 func_8015ABD4(s32 a0, s32 a1, s32 a2); +extern s32 func_80161CD0(s32 a0, s32 a1); +extern void func_8015AC48(s32 arg0); +extern void func_8015AC90(s32 a0); +extern void func_8015ADB0(s32 a0); +extern void func_8015ACC4(s32 *arg0); +extern void func_8015AD3C(void *a0); +extern void func_8015AD08(void *arg0); +extern void func_8015ADB0(s32); +extern void func_8015AD78(s32 a0); +extern void func_8015ADB0(s32 arg0); +extern s32 D_800D4A9C; +extern int func_8015B6F4(int param_1); +extern u8 D_800D4F8C[]; +extern s32 func_8015B7B4(s32 a0); +extern u8 D_800D4BE0[]; +extern s32 func_8014A51C(); +extern s32 func_8015B858(u8 *a0); +extern s32 D_800D4B48; +extern void func_8015B8F8(s32 *a0); +/* ==== end §8b carried decl layer ==== */ + + +extern s32 func_8015AE2C(); + +// @class: plumbing +// @stuck: none — MATCH (271/271, pin-free, zero asm). The ONLY residual is DEF-SIDE plumbing, and it is now named exactly: the in-TU instantiation `DEFINE_func_8015BEE4()` (engine_core.h:1851-1855) expands to `extern s32 func_8015B950(void);` INSIDE ov_SC01_077_jr_8015AE2C.c, ~14 lines BELOW this definition, so the 1-param def collides with a `(void)` prototype -> `conflicting types for func_8015B950` (.run/bank_func_8015B950.log). §73 PARAMS axis / T0. Surgical fix = §65b de-macroize that ONE instantiation (blast radius: this TU); the fleet-wide `(void)`->`()` header edit is §63 and must be R22-validated. +/* func_8015B950 (ov_SC01_077_jr_8015AE2C, 271 ins, jtbl_801D8B74) — SESSION-21 re-verified + * + * ── ROUND-2 INDEPENDENT RE-VERIFICATION (2026-07-27, fresh agent, §88e discipline) ───────────── + * match_one : MATCH (271 ins) against the CURRENT tree — §87 staleness re-checked today. + * .text size: compiled .text = 0x43C = 1084 B = 271 ins, EXACTLY the target's declared 0x43C + * ("nonmatching func_8015B950, 0x43C"). So this is NOT a §83a length drift hiding + * behind a zero count — the count is over equal-length streams. + * jtbl : RE-DECODED MECHANICALLY, not inherited. Compiled .rodata = 0x1C = 28 B = 7 words, + * 7x R_MIPS_32 -> .text with implicit addends [58,58,58,E0,F0,100,58]; +0x8015B950 + * = [8015B9A8, 8015B9A8, 8015B9A8, 8015BA30, 8015BA40, 8015BA50, 8015B9A8]. + * Diffed word-for-word against asm/ov_SC01_077/data/tail14.data.s:15-23 — 7/7 identical. + * symcheck : SYMS-DIFF target=35 draft=34, sole MISSING = jtbl_801D8B74. This is the §81 jr + * FALSE POSITIVE, re-confirmed here by reading the relocs: gcc emits its OWN table and + * references it with R_MIPS_HI16/LO16 against the SECTION `.rodata` (t.o +0x40/+0x48), + * so the splat's dlabel NAME can never appear in the draft object's relocation set. + * Nothing is dropped and nothing is invented: the draft's other 34 symbols are exactly + * the target's other 34. + * FAMILY : the x138 remap is clean and §84-safe. Every sibling is 271 ins with an IDENTICAL + * callee set; only THREE names vary per overlay — the two data labels and the jtbl: + * ov_SC01_077 D_801845F0 / D_8018465C / jtbl_801D8B74 + * ov_SC03_099 D_80185A50 / D_80185ABC / jtbl_801BD898 + * ov_SC06_008 D_80187E44 / D_80187EB0 / jtbl_801A8734 + * The pair is always +0x6C apart, and NO literal in this draft encodes that distance + * (both labels are referenced by name), so there is no §84 derived-offset hazard. + * D_8011F9C4 is fleet-constant (main-EXE data) and must NOT be remapped. + * + * match_one: MATCH (271 ins) against the CURRENT tree (§87 staleness re-checked, 2026-07-27). + * PIN-FREE, zero asm, offset-pure (s32 arg0 + raw offsets) — x138 template-safe. + * Provenance: this is the Phase-26 crack (.run/phase26-cracks/func_8015B950.c) re-gated verbatim, + * with ONE deliberate change: the definition's return type void -> s32. + * - `void func_8015B950(s32 arg0)` : MATCH (271 ins) [the Phase-26 form] + * - `s32 func_8015B950(s32 arg0)` : MATCH (271 ins) [shipped — §3a-1 void->s32 is byte-neutral] + * The fleet/engine_core.h canonical decl is `extern s32 func_8015B950(void);` (engine_core.h:1852), + * and the last bank attempt (.run/bank_func_8015B950.log) died on `conflicting types for + * func_8015B950`. Shipping the s32 return kills the §73 RETURN axis for free and leaves only the + * cheap T0 PARAMS axis for the ladder (fix_header_decl.py / --fix-def-sig / cast_call_sites). + * Both forms are byte-identical, so the orchestrator may swap the return type back at zero cost. + * + * SYMBOLS (§58 rules 1/2 — all splat spellings, all verified present): + * D_8018465C asm/ov_SC01_077/data/tail.data.s:4355 (the state-handler vtable) + * D_801845F0 asm/ov_SC01_077/data/tail.data.s:4293 + * D_8011F9C4 main-EXE data; spelled `extern s32 D_8011F9C4;` in 5+ already-banked TUs + * jtbl_801D8B74 asm/ov_SC01_077/data/tail14.data.s:15 (compiler jump table — not named in C) + * + * JTBL VERIFIED (§8a gate): compiled .rodata = exactly 0x1C B / 7 words, 7x R_MIPS_32 .text with + * addends [0x58,0x58,0x58,0xE0,0xF0,0x100,0x58] -> +0x8015B950 = [B9A8,B9A8,B9A8,BA30,BA40,BA50, + * B9A8] == the original words at 0x801D8B74..0x801D8B8C. Bound `sltiu $v0,$v1,0x7` matches. + * The raw dlabel's 8th word 0x00000000 is NOT an entry — it is the intra-TU `.align 3` pad of the + * B34/B54/B74 jtbl chain; the object can never emit it (maspsx drops .align), so it must stay in + * the post-carve RAW data piece (the §53/§62/§81 carve chain applies at bank time). + * + * Same family as the TU's own already-matched func_8015AE2C: 7-case switch on ((s32 (*)(s32))func_801619A4)() + * (0/1/2/6 shared, 3/4/5 own, no default block — out-of-range and every `break` fall to the + * after-switch join), then a chain of "state handler" tests, each dispatching + * D_8018465C[*(u16*)arg0](arg0) and returning. + * + * THREE LEVERS (draft -> MATCH in 3 compiles): + * + * 1. PROLOGUE CONSTANT = an INITIALIZED LOCAL, not a literal in the compare. + * Target opens with `lui $s2, 0xFFF5` in the *prologue*, used once ~200 ins later in + * `slt $v0,$s2,$s1`. No gcc-2.7.2 pass hoists a (set reg const_int) across basic blocks + * (loop.c needs a loop; cse/combine/sched never move insns between BBs) — so the insn must + * have been EMITTED in the first BB, i.e. the constant is a local initialized at the top of + * the function. cse then cannot fold it back into the compare: the `slt` operand predicate is + * `arith_operand`, which rejects a CONST_INT wider than 16 bits, so validate_change fails and + * the pseudo survives. Its live range spans every call -> global.c gives it a callee-saved reg. + * Writing `z > -0xB0000` inline instead emits the `lui` into the branch delay slot next to the + * compare (caller-saved $v0) and the function is 1 insn short. => `s32 lim = -0xB0000;` at top. + * + * 2. `lh` vs `lhu`: a short->short copy is a pure HImode move and gcc emits `lhu`. The target's + * `lh $v0,0x26($s0)` means the value passed through an SImode (int) temp: expand makes + * (set (reg:SI) (sign_extend (mem:HI))) + (set (mem:HI) (subreg:HI ...)), and combine cannot + * merge them (the merged form is mem<-mem, which no movhi accepts) so the sign-extending load + * survives. => route both halfword copies through the `s32 t` temp. + * + * 3. THE `goto` LAYOUT — dodging jump.c's store-flag conversion (jump.c:1005-1065). + * An if/else chain writing 0/1 into `doit` makes gcc collapse the last pair into + * `sltiu $v0,$v0,1`. jump.c fires that conversion when the insn immediately after a + * conditional jump is a lone `SET pseudo, CONST_INT` whose following simplejump targets the + * SAME label as the branch (jump.c:1038 `reallabelprev == temp || ... JUMP_LABEL(temp4) == + * JUMP_LABEL(insn)`) — exactly the shape of `if (c) x=0; else x=1;`. + * The target instead cross-jumps ALL the `doit=0` exits into ONE shared block placed after the + * `doit=1` fall-through; reorg's fill_slots_from_thread then COPIES that single set into all + * three branch delay slots and redirects each branch past it (which is why `addu $v0,$zero, + * $zero` appears 3x in delay slots and the shared block vanishes). A `goto zero;` / `goto one;` + * chain expresses that layout directly, and each conditional jump is then followed by a + * compare/call rather than a lone const set, so the store-flag conversion never triggers. + * GENERAL RULE: multiple predicates that all assign the SAME constant to one flag => write + * them as `goto` to a shared assignment, never as an if/else ladder. + */ +extern s32 D_8011F9C4; + +extern s32 func_80161B18(void); +extern s32 func_801619A4(s32*); +extern s32 func_80149AA8(s32*); +extern void func_80149AD4(s32*); +extern s32 func_80149B54(s32*); +extern void func_80149BAC(s32*); +extern s32 func_801498E0(s32*); +extern s32 func_80149954(s32); +extern s32 func_80149A64(s32*); +extern void func_800CCCC0(s32 a0); +extern s32 func_80149CD4(s32 a0); +extern void func_8015E880(s32*); +extern s32 func_80149744(struct S_80149744*); +extern void func_80149788(void); +extern s32 func_801496D4(void*); +extern void func_80149704(void); +extern int func_80148AFC(void*); +extern void func_80146D90(s32 a0); +extern void func_80154150(s32 a0, s32 a1); +extern void func_801541D8(u8*, s32, s32); +extern s32 func_801488A8(u8*); +extern void func_80147078(s32*, s16); +extern void func_8015A264(void*); +extern s32 func_80013294(void*, void*); +extern void func_80159B70(void*); +extern s32 func_8016F1AC(void); +extern s32 func_80029178(s32 a0); +extern void func_80146DB8(s32*, s32*); +extern s32 func_80161CD0(s32, s32); +extern s32 func_80161208(s32 a0); +extern s32 func_801725A4(u8*); + +s32 func_8015B950(s32 arg0) +{ + + extern void (*D_8018465C[])(void *); + extern s32 D_801845F0; + s16 sp10[4]; + s16 sp18[4]; + s32 t; + s32 z; + s32 doit; + s32 lim = -0xB0000; + + if (func_80161B18() != 0) { + return; + } + switch (((s32 (*)(s32))func_801619A4)(arg0)) { + case 0: + case 1: + case 2: + case 6: + if (((s32 (*)(s32))func_80149AA8)(arg0) != 0) { + D_8018465C[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149AD4)(arg0); + return; + } + if (((s32 (*)(s32))func_80149B54)(arg0) != 0) { + D_8018465C[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149BAC)(arg0); + return; + } + break; + case 3: + ((void (*)(s32))func_801498E0)(arg0); + break; + case 4: + ((void (*)(s32))func_80149954)(arg0); + break; + case 5: + if (((s32 (*)(s32))func_80149A64)(arg0) != 0) { + D_8018465C[*(u16 *)arg0]((void *)arg0); + func_800CCCC0(arg0); + return; + } + break; + } + if (func_80149CD4(arg0) != 0) { + D_8018465C[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_8015E880)(arg0); + return; + } + if (((s32 (*)(s32))func_80149744)(arg0) != 0) { + D_8018465C[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149788)(arg0); + return; + } + if (((s32 (*)(s32))func_801496D4)(arg0) != 0) { + D_8018465C[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149704)(arg0); + if (((u8)((s32 (*)(s32))func_80148AFC)(arg0)) == 0) { + func_80146D90(arg0); + } + if ((*(s32 *)(arg0 + 0x24) | *(s32 *)(arg0 + 0x2C)) != 0) { + func_80154150(arg0, 0xF); + } else { + ((void (*)(s32, s32, s32))func_801541D8)(arg0, 0xD, 6); + } + *(s32 *)(arg0 + 0x238) = 1; + return; + } + if (((s32 (*)(s32))func_801488A8)(arg0) != 0) { + sp10[0] = 0; + sp10[1] = 0; + sp10[2] = 0; + t = *(s16 *)(arg0 + 0x26); + sp18[0] = t; + sp18[1] = 0; + t = *(s16 *)(arg0 + 0x2E); + sp18[2] = t; + D_8018465C[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 1); + ((void (*)(s32))func_8015A264)(arg0); + t = -(((s32 (*)(s16 *, s16 *))func_80013294)(sp10, sp18) << 0x10); + if (t < *(s32 *)(arg0 + 0x2C)) { + *(s32 *)(arg0 + 0x2C) = t; + } + return; + } + if (*(u16 *)(arg0 + 0xB8) == 0x8000) { + D_8018465C[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 0); + ((void (*)(s32))func_80159B70)(arg0); + return; + } + z = *(s32 *)(arg0 + 0x2C); + if (func_8016F1AC() != 0) { + goto zero; + } + if (z <= lim) { + goto one; + } + if (D_8011F9C4 == 0) { + goto zero; + } + if (((u8)func_80029178(0x21)) != 0) { + goto zero; + } +one: + doit = 1; + goto join; +zero: + doit = 0; +join: + if (doit != 0) { + D_8018465C[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 0); + ((void (*)(s32))func_80159B70)(arg0); + func_80154150(arg0, 9); + ((void (*)(s32, s32 *))func_80146DB8)(arg0, &D_801845F0); + ((void (*)(s32, s32))func_80161CD0)(arg0, *(u16 *)(arg0 + 0x16E)); + return; + } + if (func_80161208(arg0) == 0) { + ((void (*)(s32))func_801725A4)(arg0); + } +} + +DEFINE_func_8015BD8C() /* dedup: shared engine-core @0x8015bd8c (src/shared) */ + + +DEFINE_func_8015BDD0() /* dedup: shared engine-core @0x8015bdd0 (src/shared) */ + + +DEFINE_func_8015BE04() /* dedup: shared engine-core @0x8015be04 (src/shared) */ + + + + +void func_8015BE38(struct Obj *a0) { + + extern void (*D_801847D0[])(void); + D_801847D0[*(u16 *)((s32)a0 + 0x2)](); +} + + +DEFINE_func_8015BE74() /* dedup: shared engine-core @0x8015be74 (src/shared) */ + + +DEFINE_func_8015BE94() /* dedup: shared engine-core @0x8015be94 (src/shared) */ + + +DEFINE_func_8015BEC4() /* dedup: shared engine-core @0x8015bec4 (src/shared) */ + + +DEFINE_func_8015BEE4() /* dedup: shared engine-core @0x8015bee4 (src/shared) */ + + +DEFINE_func_8015BF04() /* dedup: shared engine-core @0x8015bf04 (src/shared) */ + + +DEFINE_func_8015BF48() /* dedup: shared engine-core @0x8015bf48 (src/shared) */ + + +DEFINE_func_8015BF7C() /* dedup: shared engine-core @0x8015bf7c (src/shared) */ + + +DEFINE_func_8015BFB0() /* dedup: shared engine-core @0x8015bfb0 (src/shared) */ + + + + +void func_8015BFF4(void *a0) { + + extern void (*D_801847DC[])(void); + D_801847DC[*(u16 *)((s32)a0 + 0x2)](); +} + + +INCLUDE_ASM("asm/ov_SC07_010/nonmatchings/ov_SC07_010_jr_8015B950", func_8015C030); + +DEFINE_func_8015C08C() /* dedup: shared engine-core @0x8015c08c (src/shared) */ + + +DEFINE_func_8015C0C4() /* dedup: shared engine-core @0x8015c0c4 (src/shared) */ + + +extern void func_8001382C(s32 a0, void *a1, void *a2); +extern void func_80146CA0(void *a0); +extern void func_80146DB8(s32 *a0, s32 *a1); +extern void func_80146E90(s32 *a0, s32 a1); +extern s32 func_80146E98(s32 a0); +extern void func_80147078(s32 *a0, s16 a1); +extern void func_80147324(s32 a0); +extern void func_801473EC(s32 *a0); +extern void func_80147A84(s32 arg0); +extern int func_80148AFC(void *a0); +extern s32 func_80149FB0(s32 a0); +extern void func_8014C010(s32 a0, s32 a1); +extern void func_8014CC28(s32 a0); +extern void func_8014D738(void); +extern s32 func_8014F3E8(s32 a0); +extern s32 func_8015BE94(); +extern void func_8015C0C4(s32 a0); + + + +s32 func_8015C128(s32 param_1) { + + extern u16 D_800B99DA; + extern void func_8015C6E0(int); + extern void (*D_8018465C[])(int); + + int sp10[3]; + int sp20[3]; + int temp_s0; + int temp_v0; + + ((void(*)())func_80149FB0)(); + if (((int(*)(int))func_80148AFC)(((int)param_1)) & 0xFF) { + sp10[0] = 0; + sp10[1] = 0; + sp10[2] = -0x4000; + ((void(*)(int, int *, int *))func_8001382C)(*(short *)(*(int *)(((int)param_1) + 0x20) + 0x12), sp10, sp20); + *(int *)(((int)param_1) + 0x234) += sp20[0]; + *(int *)(((int)param_1) + 0x238) += sp20[1]; + *(int *)(((int)param_1) + 0x23C) += sp20[2]; + } + ((void(*)(int, int *, int *))func_8001382C)((short)(-*(unsigned short *)(*(int *)(((int)param_1) + 0x20) + 0x12)), + (int *)(((int)param_1) + 0x234), sp20); + ((void(*)(int, int *))func_80146DB8)(((int)param_1), sp20); + func_80147A84(((int)param_1)); + ((void(*)(int))func_801473EC)(((int)param_1)); + if (!(D_800B99DA & 3)) { + ((void(*)(int, int))func_8014C010)(((int)param_1), 1); + ((void(*)(int))func_80147324)(0x65F); + } + if (((int(*)(int))func_8014D738)(((int)param_1)) != 0) { + D_8018465C[*(u16 *)((int)param_1)](((int)param_1)); + func_8015C6E0(((int)param_1)); + return; + } + temp_s0 = ((int(*)(int))func_8014CC28)(((int)param_1)); + temp_v0 = ((int(*)(int))func_8014F3E8)(((int)param_1)); + if (temp_v0 != 0) { + if ((temp_v0 & 0xFF00) != 0x4000) { + ((void(*)(int, int))func_80146E90)(((int)param_1), 6); + ((void(*)(int))func_80146CA0)(((int)param_1)); + return; + } + if ((temp_v0 & 0x4000) && ((int(*)(int))func_80146E98)(((int)param_1)) != 0) { + ((void(*)(int, int))func_80147078)(((int)param_1), 4); + ((void(*)(int))func_8015C0C4)(((int)param_1)); + } + } else if (temp_s0 == 0) { + D_8018465C[*(u16 *)((int)param_1)](((int)param_1)); + ((void(*)(int, int))func_80147078)(((int)param_1), 3); + ((void(*)(int))func_8015BE94)(((int)param_1)); + } +} + + + diff --git a/src/ov_SC07_011/ov_SC07_011_jr_801588CC.c b/src/ov_SC07_011/ov_SC07_011_jr_801588CC.c index abe933483..ff90cf522 100644 --- a/src/ov_SC07_011/ov_SC07_011_jr_801588CC.c +++ b/src/ov_SC07_011/ov_SC07_011_jr_801588CC.c @@ -2589,141 +2589,3 @@ DEFINE_func_8015B858() /* dedup: shared engine-core @0x8015b858 (src/shared) */ DEFINE_func_8015B8F8() /* dedup: shared engine-core @0x8015b8f8 (src/shared) */ - - -INCLUDE_ASM("asm/ov_SC07_011/nonmatchings/ov_SC07_011_jr_801588CC", func_8015B950); - -DEFINE_func_8015BD8C() /* dedup: shared engine-core @0x8015bd8c (src/shared) */ - - -DEFINE_func_8015BDD0() /* dedup: shared engine-core @0x8015bdd0 (src/shared) */ - - -DEFINE_func_8015BE04() /* dedup: shared engine-core @0x8015be04 (src/shared) */ - - - - -void func_8015BE38(struct Obj *a0) { - - extern void (*D_80180E90[])(void); - D_80180E90[*(u16 *)((s32)a0 + 0x2)](); -} - - -DEFINE_func_8015BE74() /* dedup: shared engine-core @0x8015be74 (src/shared) */ - - -DEFINE_func_8015BE94() /* dedup: shared engine-core @0x8015be94 (src/shared) */ - - -DEFINE_func_8015BEC4() /* dedup: shared engine-core @0x8015bec4 (src/shared) */ - - -DEFINE_func_8015BEE4() /* dedup: shared engine-core @0x8015bee4 (src/shared) */ - - -DEFINE_func_8015BF04() /* dedup: shared engine-core @0x8015bf04 (src/shared) */ - - -DEFINE_func_8015BF48() /* dedup: shared engine-core @0x8015bf48 (src/shared) */ - - -DEFINE_func_8015BF7C() /* dedup: shared engine-core @0x8015bf7c (src/shared) */ - - -DEFINE_func_8015BFB0() /* dedup: shared engine-core @0x8015bfb0 (src/shared) */ - - - - -void func_8015BFF4(void *a0) { - - extern void (*D_80180E9C[])(void); - D_80180E9C[*(u16 *)((s32)a0 + 0x2)](); -} - - -INCLUDE_ASM("asm/ov_SC07_011/nonmatchings/ov_SC07_011_jr_801588CC", func_8015C030); - -DEFINE_func_8015C08C() /* dedup: shared engine-core @0x8015c08c (src/shared) */ - - -DEFINE_func_8015C0C4() /* dedup: shared engine-core @0x8015c0c4 (src/shared) */ - - -extern void func_8001382C(s32 a0, void *a1, void *a2); -extern void func_80146CA0(void *a0); -extern void func_80146DB8(s32 *a0, s32 *a1); -extern void func_80146E90(s32 *a0, s32 a1); -extern s32 func_80146E98(s32 a0); -extern void func_80147078(s32 *a0, s16 a1); -extern void func_80147324(s32 a0); -extern void func_801473EC(s32 *a0); -extern void func_80147A84(s32 arg0); -extern int func_80148AFC(void *a0); -extern s32 func_80149FB0(s32 a0); -extern void func_8014C010(s32 a0, s32 a1); -extern void func_8014CC28(s32 a0); -extern void func_8014D738(void); -extern s32 func_8014F3E8(s32 a0); -extern s32 func_8015BE94(); -extern void func_8015C0C4(s32 a0); - - - -s32 func_8015C128(s32 param_1) { - - extern u16 D_800B99DA; - extern void func_8015C6E0(int); - extern void (*D_80180D1C[])(int); - - int sp10[3]; - int sp20[3]; - int temp_s0; - int temp_v0; - - ((void(*)())func_80149FB0)(); - if (((int(*)(int))func_80148AFC)(((int)param_1)) & 0xFF) { - sp10[0] = 0; - sp10[1] = 0; - sp10[2] = -0x4000; - ((void(*)(int, int *, int *))func_8001382C)(*(short *)(*(int *)(((int)param_1) + 0x20) + 0x12), sp10, sp20); - *(int *)(((int)param_1) + 0x234) += sp20[0]; - *(int *)(((int)param_1) + 0x238) += sp20[1]; - *(int *)(((int)param_1) + 0x23C) += sp20[2]; - } - ((void(*)(int, int *, int *))func_8001382C)((short)(-*(unsigned short *)(*(int *)(((int)param_1) + 0x20) + 0x12)), - (int *)(((int)param_1) + 0x234), sp20); - ((void(*)(int, int *))func_80146DB8)(((int)param_1), sp20); - func_80147A84(((int)param_1)); - ((void(*)(int))func_801473EC)(((int)param_1)); - if (!(D_800B99DA & 3)) { - ((void(*)(int, int))func_8014C010)(((int)param_1), 1); - ((void(*)(int))func_80147324)(0x65F); - } - if (((int(*)(int))func_8014D738)(((int)param_1)) != 0) { - D_80180D1C[*(u16 *)((int)param_1)](((int)param_1)); - func_8015C6E0(((int)param_1)); - return; - } - temp_s0 = ((int(*)(int))func_8014CC28)(((int)param_1)); - temp_v0 = ((int(*)(int))func_8014F3E8)(((int)param_1)); - if (temp_v0 != 0) { - if ((temp_v0 & 0xFF00) != 0x4000) { - ((void(*)(int, int))func_80146E90)(((int)param_1), 6); - ((void(*)(int))func_80146CA0)(((int)param_1)); - return; - } - if ((temp_v0 & 0x4000) && ((int(*)(int))func_80146E98)(((int)param_1)) != 0) { - ((void(*)(int, int))func_80147078)(((int)param_1), 4); - ((void(*)(int))func_8015C0C4)(((int)param_1)); - } - } else if (temp_s0 == 0) { - D_80180D1C[*(u16 *)((int)param_1)](((int)param_1)); - ((void(*)(int, int))func_80147078)(((int)param_1), 3); - ((void(*)(int))func_8015BE94)(((int)param_1)); - } -} - - diff --git a/src/ov_SC07_011/ov_SC07_011_jr_8015B950.c b/src/ov_SC07_011/ov_SC07_011_jr_8015B950.c new file mode 100644 index 000000000..ef44d74ce --- /dev/null +++ b/src/ov_SC07_011/ov_SC07_011_jr_8015B950.c @@ -0,0 +1,2426 @@ +#include "common.h" +#include "../shared/engine_core.h" + +/* ==== Phase-26 §8b carried decl layer (jr_isolate_all.py) =================== + * The file-scope decl environment from earlier code regions of this object — + * file-local types, col-0 decls, DEFINE_func macro externs, and each earlier + * definition's implied prototype (types first, then decls in original order). + * Decls emit no code => byte-neutral. See cookbook §8c. */ +extern void func_80128288(void); +extern void func_80128158(void); +extern void func_801285E4(void); +extern void func_80128178(void); +extern void func_80128678(void); +extern void func_80128198(void); +extern void func_80128714(void); +extern void func_801281B8(void); +extern void func_8013E67C(void); +extern void func_801281D8(void); +extern void func_8013E558(void); +extern void func_801281F8(void); +extern s32 func_80128218(void); +extern void func_80128A28(void); +extern void func_80128228(void); +extern void func_80128AF4(void); +extern void func_80128248(void); +extern void func_801282EC(void); +extern void func_80128268(void); +extern void func_80011B7C(int); +extern void func_801282CC(void); +extern void func_8001C0C8(void); +extern void func_80015310(void); +extern void func_80129258(void); +extern void func_801378F0(void); +extern void func_80010E14(void); +extern s16 currentLocationId; +extern s32 func_80029504(void); +extern s32 func_800CF854(s32); +extern s32 func_80128998(void); +extern s32 func_801289F0(void); +extern s32 func_801288E8(s32); +extern s32 func_80128940(s32); +extern s32 func_80029178(s32); +extern s32 func_801288B0(void); +extern void func_80011C10(void); +extern void func_8012832C(void); +extern void func_80129220(void); +extern void func_80011E24(void); +extern void func_80128C14(void); +extern void func_8002AEF8(void); +extern void func_800CFBBC(void); +extern void SsUtReverbOff(void); +extern void func_8013C98C(void); +extern void func_80129C40(s32 a0); +extern void func_800D0630(void); +extern void func_80145CEC(void); +extern void func_80144B9C(void); +extern u8 D_800B9A17; +extern u8 D_800B9A10; +extern void func_80128420(void); +extern s32 func_800D0588(void); +extern void func_801284B8(void); +extern void func_80175308(void); +extern void func_8016E8F0(void); +extern void func_80175494(void); +extern u8 D_800B9A64; +extern void func_801284F0(void); +extern void func_80146074(void); +extern void func_8012853C(void); +extern void func_80178608(void); +extern void func_8002D4C8(s32 a0, s32 a1); +extern s32 func_80011A3C(void); +extern short currentLocationId; +extern short D_800B99F2; +extern void func_80128564(void); +extern u8 D_800B9A11; +extern void func_801285D4(void); +extern s32 func_800D18DC(void); +extern void func_8014607C(void); +extern void func_801287B8(void); +extern void func_80029444(void); +extern void func_800D1754(void); +extern void func_8014ED28(s32 _arg0); +extern void func_8001ABBC(s32 a0, s32 a1, void *a2, s32 a3, s32 sp10); +extern int func_801288E8(int arg0); +extern int func_80128940(int arg0); +extern void func_80010AE0(s32 a0); +extern void func_80018450(s32 a0, s32 a1); +extern void func_800183E0(s32 a0); +extern void func_80128D60(s32 a0, s32 *a1, s32 *a2); +extern s32 func_80128DB4(s32 a0, s32 *a1); +extern void func_80128EA8(s32 a0, s32 a1, s32 a2); +extern s32 func_80128ED8(s32 param_1, s32 *param_2); +extern void func_80128FAC(u16 *arg0); +extern s16 D_8011DB2C; +extern s16 D_8011DB30; +extern s32 D_80126AEC; +extern void func_80129010(void); +extern u8 *func_8012913C(s32 a0); +extern u8 * func_801290DC(s32 a0, u8 *a1); +extern void func_8001D074(s32 a, s32 b); +extern u8 *func_801291C0(void); +extern s32 func_8001CC3C(s32 a0, s32 a1, s32 a2, s32 a3); +extern u8 * func_8012913C(s32 arg0); +extern void func_80016714(void *a0, s32 a1); +extern u8 * func_801291C0(void); +extern void func_80129248(s16 a0); +extern void func_801292C8(u8 *a0); +extern void func_8012927C(void); +extern void func_8012931C(struct vec *a0); +extern void func_80129350(s32 a0, s32 a1); +extern void func_80129374(s32 a0, s32 a1); +extern s16 D_800B9AAC[]; +extern s16 D_800B9AAE[]; +extern s16 D_800B9AB0[]; +extern s16 D_800B9AB2[]; +extern s16 D_800B9AB4[]; +extern s16 D_800B9AB6[]; +extern s16 D_800B9AB8[]; +extern s16 D_800B9ABA[]; +extern void func_80129398(void); +extern s16 D_80114EE0; +extern void func_80129428(void); +extern void func_8012943C(void); +extern s32 D_8005128C; +extern u8 D_800B9A78; +extern void func_801298F4(void *arg0); +extern void func_801299C8(s32 a, s32 b, s32 c); +extern void func_8012944C(void); +extern unsigned short D_800B99F0; +extern struct BigCopy D_80126DB8; +extern u8 D_80126948[]; +extern struct BigCopy D_80114EE8; +extern s32 D_80126E60[]; +extern s8 D_801150D6; +extern s8 D_801152C0; +extern u8 D_80127504; +extern void func_800144D4(void); +extern void func_80129C40(s32 _arg0); +extern void func_8012A328(void); +extern void func_80053308(s32); +extern s32 func_80012F74(s32, s32, s32, s32); /* canonical s32 (engine_core); (s16)-cast the return for the sll/sra */ +extern void GsSetRefView2L(void *); +extern s8 D_801150D6; /* canonical (engine_core macro): s8 — access via *(u8*)& for lbu */ +extern s32 D_80126F04[]; +extern u8 D_80126948[]; /* canonical (sibling): u8[] — cast (s32*) at use */ +extern s32 D_80126FA8[]; +extern struct BigCopy D_80126DB8;/* canonical (engine_core macro): struct BigCopy — (s32*)& at use */ +extern u8 D_800AF630[]; /* canonical (sibling): u8[] — cast (s32*) at use */ +extern s32 D_800AE688[]; +extern s32 D_801151D4; /* canonical (10 siblings): scalar s32 — store (s32)ptr */ +extern void func_80129CF8(void); +extern void func_8012A018(s32 a, s32 b); +extern void func_80129FF4(void); +extern void func_8012A048(void *a0, s32 a1, u8 a2); +extern void func_8012A018(s32 a0, s32 a1); +extern u16 D_80126B5E; +extern u16 D_80126B62; +extern u16 D_80126B66; +extern s16 D_80126940; +extern s16 D_80126942; +extern s16 D_80126944; +extern void *memcpy(void *, const void *, unsigned int); +extern void func_8012A094(s32 a0); +extern void func_8012A100(s8 a0); +extern void func_8012A0E0(void); +extern s32 D_80120204; +extern s32 D_80120200; +extern s32 D_8012020C; +extern s32 D_80120208; +extern s16 D_80120218; +extern s16 D_80120210; +extern s16 D_8012021A; +extern s16 D_80120212; +extern s16 D_8012021C; +extern s16 D_80120214; +extern s16 D_80120226; +extern s16 D_80120220; +extern s16 D_80120228; +extern s16 D_80120222; +extern s16 D_8012022A; +extern s16 D_80120224; +extern s32 D_80120294; +extern s16 D_80120298; +extern s16 D_8012029A; +extern void func_8012A110(void); +extern void func_8012A2F4(void); +extern s16 D_80127080; +extern s16 D_801152C2; +extern void func_8012A304(s32 a0, s32 a1); +extern void func_8012A464(void); +extern s32 D_801151D4; +extern void func_8012A4BC(void); +extern void func_8012A598(void *a0); +extern void func_8012A568(void (*a0)(void)); +extern void func_8012A62C(s32); +extern void func_8012A5F8(void (*a0)(void), s32 a1); +extern void func_8012A62C(s32 a0); +extern void func_8012A7D4(void *a0, void *a1); +extern s32 func_8012A6D0(void *a0, void *a1); +extern s16 func_8012A68C(void); +extern s32 func_80047D3C(s32 a0); +extern s32 ratan2(s32 a0, s32 a1); +extern s32 func_8012A6D0(void* a0, void* a1); +extern s16 func_8012A79C(s16 *a0, s16 *a1); +extern s16 func_8012A758(void); +extern void func_8012A7D4(void *arg0, void *arg1); +extern void func_8012AAAC(); +extern void func_8012A828(s32 a0, void * a1); +extern int func_8012ACE0(void *a0); +extern void func_8012A860(void *a0, int a1); +extern void func_8012A8B0(u8 *a0, s32 a1); +extern void func_8012A8E8(void); +extern u8 D_801202A0[]; +extern u16 D_801270C0; +extern void func_8012A988(u8 *a0); +extern void func_8012A908(void); +extern s32 func_8012ACE0(void *a0); +extern void func_8012ACA0(void *arg0); +extern void func_8012AD44(s32 *a0, s16 a1); +extern s32 func_8012AD50(void * arg0); +extern void func_8012AD64(s32 *a0, s16 a1); +extern void func_8012AD6C(void *a0); +extern void func_8012AD80(s32 a0); +extern void func_8012ADE4(u8 *a0); +extern s32 *D_80126B78; +extern s32 *D_80126B90; +extern s32 D_80126B58; +extern s32 func_80135888(s32 a0, s32 a1, s32 a2, s32 a3); +extern s32 func_80013478(s32 a0, s32 a1); +extern s32 func_8012AE00(s32 a0); +extern s32 func_8012AF0C(s32 a0, s32 a1); +extern s32 func_80134510(s32 arg); +extern s32 func_8012B030(u8 *a0); +extern int func_80047948(int a0); +extern int func_8004787C(int a0); +extern void func_8012B0B4(unsigned int *param_1, int param_2, int param_3); +extern void func_800484EC(s32 a0, s32 a1, s32 a2); +extern void func_8012B14C(s32 a0, s32 a1); +extern void func_8012B178(s32 a0, s32 a1); +extern void func_8012B1B4(s32 a0, s32 a1); +extern void func_8012B200(u8 *a0); +extern void func_8012B21C(void *a0); +extern void func_8012B23C(s32 a0); +extern void func_8012B260(u8 *a0); +extern void func_80049CAC(s32 a0, s32 a1); +extern void func_8012B2CC(s32 a0); +extern void RotMatrixYXZ(void *m, void *p); +extern void func_8012B370(int a0); +extern void func_8004978C(s16 *a0, void *a1); +extern void func_8012B414(int a0); +extern s32 func_8012B608(s32 a0, s32 a1, s32 a2); +extern s32 func_8012B6D4(s16 *a0, s16 *a1); +extern s32 func_8012B70C(s16 *a0, s16 *a1); +extern s32 ratan2(s32 x, s32 y); +extern s32 func_8012B744(void *a0, void *a1); +extern s16 D_80126CB8; +extern s16 D_80126CB4; +extern s32 func_8012B864(s32 a0); +extern s32 func_8012B8A4(s16 *a0); +extern s32 func_8012B8E4(s32 arg0, s32 arg1); +extern s32 func_8012BA10(s32 arg0, s32 arg1); +extern s32 func_8012BB3C(s32 arg0, s32 arg1, u32 arg2, s32 arg3); +extern void Square0(s32 *a0, s32 *a1); +extern s32 func_8012BC60(struct Vec *a0, struct Vec *a1); +extern s16 D_80126CBA; +extern s32 func_8012BCCC(s32 a0); +extern void func_80013350(s32 a0, void *a1); +extern u8 D_80126B5C; +extern void func_8012BD14(s32 a0); +extern s32 func_8012BDBC(s32 a0, s32 a1); +extern s32 func_8012BD3C(s32 a0, s32 a1, s32 a2); +extern void func_8012BE98(s32 a0, u16 *a1); +extern void func_8012BE54(s32 a0); +extern s32 func_800132BC(s32 a0, s32 a1); +extern void func_8012BE98(s32 arg0, u16 * arg1); +extern s32 func_8012BEE8(s32 a0); +extern s32 func_8012BF10(s32 a0, s32 a1); +extern void func_8012BF4C(s32 *a0, s32 a1); +extern void func_8012BF54(void *a0); +extern void func_8012BF68(void *a0); +extern s16 D_80126CB0; +extern s32 func_8012BF7C(s16 *a0); +extern s16 D_80126CAC; +extern short D_80126CAE; +extern int func_8012BFA8(short *a0); +extern s32 D_801274D4; +extern s32 D_801274E0; +extern s32 func_8012C044(s32 a0); +extern void func_8012C218(void *a0); +extern void func_8012C098(void *param_1); +extern s32 func_8012C0EC(s32 a0); +extern void func_8012C194(void); +extern void func_8001CFDC(s32 a, s32 b); +extern void func_8012C1B8(void); +extern u8 D_800B3DF0[]; +extern s32 func_8012C1DC(s32 a0); +extern u8 D_80126720[]; +extern u16 * func_8012C284(u16 *a0); +extern u8 D_80120194[]; +extern s32 func_8012C2D0(void); +extern s32 func_8012C31C(void); +extern void func_8012CAE4(void *a0); +extern void func_8001C214(s32 a0, s32 a1); +extern u8 D_80078EAE; +extern s32 func_8012C354(s32 a0, s32 a1); +extern void func_8001C810(s32 a0, s32 a1); +extern s32 func_8012C438(s32 a0, s32 a1); +extern s32 func_8012C890(s32 a0, s32 a1, s32 a2); +extern s32 func_8012C51C(void *a0, s32 a1); +extern s32 func_8012C588(s32 a0, s32 a1); +extern void func_8012C724(s32 a0, s32 a1); +extern s32 func_8012C750(s32 a0); +extern s32 func_8012C820(u8 *a0); +extern u16 D_801274E4[]; +extern s32 func_8012CB64(s32 arg0, s32 arg1, s32 arg2, s32 arg3, s32 arg4); +extern s32 func_8012CC88(s32 a, s32 b, s32 c); +extern u8 D_800D3918[]; +extern void func_8012CBA4(s32 a0); +extern void func_8012CBCC(s32 a0); +extern void func_8012CBF4(s32 a0); +extern void func_8012CC1C(s32 arg0, s32 arg1); +extern void func_8012CC40(s32 arg0, s32 arg1); +extern s32 func_8012CC88(s32 a0, s32 a1, s32 a2); +extern void func_8012CC64(s32 a0, s32 a1); +extern s32 func_80133784(s32 a0, void *a1, s32 a2); +extern s32 func_8012CE2C(s32 a0); +extern s32 func_8012CEB0(s32 a0, s32 a1, s32 a2); +extern void func_8012CFA8(s32 arg0); +extern void func_8012F214(s32 a0, s32 a1, s32 a2); +extern void func_8012D3B4(s32 arg0, s32 arg1, s32 arg2); +extern void func_8012D098(u16 *param_1, u32 param_2); +extern void func_8012D098(); +extern void func_8012D38C(int a0); +extern void func_8012D3AC(void); +extern s32 AddPrim(s32, void *); +extern s32 RotTransPers(s32, s32, s32 *, s32 *); +extern void SetLineF2(void *); +extern void *func_80010A08(s32); +extern void func_8004914C(void *); +extern void func_800491AC(void *); +extern s32 D_800A651C; +extern u8 D_800AF648; +extern s16 D_800B9A02; +extern void func_8012D4B4(s32 arg0, s32 arg1, s32 arg2, s32 arg3); +extern void func_8012D5DC(void); +extern s16 D_80126B98; +extern s32 func_8012DEB8(s32 a0, s32 a1, s32 a2); +extern s32 func_8012D5E4(s32 a0, s32 a1, s32 a2, s32 a3); +extern int func_8012D664(); +extern void func_8012D624(s32 a0); +extern s32 func_8012D714(s32 param_1, u32 param_2); +extern void func_8012F568(s32 a0, s32 a1, s32 a2, s32 a3, s32 a4, s32 a5); +extern void func_8014C978(void); +extern s32 func_8012DB84(void); +extern s32 func_8012DE2C(s32 a0); +extern s32 func_8012DDA4(void); +extern s32 func_8012DBD0(s32 arg0, s32 arg1, s32 arg2, s32 arg3); +extern s32 func_8012DF34(s32 a0, s32 a1, s32 a2); +extern s16 D_80126B9A; +extern u8 D_801152A8[]; +extern void func_8012DFBC(void); +extern void func_8012DFCC(void); +extern void func_8012E014(void); +extern void func_8012E138(void); +extern void func_8012DFD4(u8 *a0); +extern s32 func_8012E27C(void); +extern void func_8012E284(void); +extern s32 GetTPage(s32, s32, s32, s32); +extern s32 func_8005A600(s32, s32, s32, s32, s32); +extern void func_8012E28C(s32 arg0, s32 arg1); +extern void func_8004914C(void *a0); +extern void func_800491AC(void *a0); +extern void func_8012E32C(void); +extern s32 func_8012E470(s32 a0); +extern void func_8012E4C8(s32 a0); +extern s32 func_8012E504(s32 a0, s32 a1); +extern s32 func_8012E544(s32 a0); +extern s32 func_8012E57C(s32 a0, s32 a1); +extern s32 RotTransPers(s32 a0, s32 a1, s32 *a2, s32 *a3); +extern void func_8012E5CC(s32 param_1, u16 param_2, u16 param_3); +extern void func_8012E688(s32 param_1, u16 param_2, u16 param_3); +extern s32 func_8012E778(int param_1, int param_2); +extern void func_8012E88C(u8 *a0); +extern void func_8012E8A8(u8 *a0); +extern void func_8012E8C4(u8 *a0); +extern void func_8012E8E0(s32 a0, s32 a1); +extern void func_8012EA90(s32 param_1, s32 param_2, s32 *param_3); +extern void func_8012EC04(s32 param_1, s32 param_2, s32 *param_3); +extern s32 func_8002A4FC(s32 a0); +extern s32 func_8012EECC(s32 a0); +extern void func_8012EFB8(s32 a0); +extern void func_8012EF34(s32 a0, s32 a1); +extern void func_8012EF70(s32 a0, s32 a1); +extern void ApplyTransposeMatrixLV(void *a0, void *a1, void *a2); +extern void func_8012F038(int param_1, short *param_2, short *param_3); +extern void func_8012F0BC(s32 *a0, s32 *a1, s32 *a2); +extern void RotTransSV(s32 a0, s32 a1, void *a2); +extern void func_8012F14C(s32 a0, s32 a1, s32 a2); +extern void func_8012F1A4(s32 *a0, s32 a1, s32 *a2); +extern void func_8012F2E8(s32 a0, s32 a1, s32 a2); +extern s16 D_80126CB6; +extern void func_8012F374(s32 a0, s32 a1); +extern void *memcpy(void *, const void *, u32); +extern u8 D_80126C38; +extern u8 D_80126C40; +extern u16 D_80126B94; +extern u16 D_80126B96; +extern void func_8012F568(s32 param_1, s32 param_2, s32 param_3, s32 param_4, s32 param_5, s32 param_6); +extern void func_80131B14(); +extern void func_80131E00(struct S80131E00 *a0, s32 a1); +extern s32 func_80131A34(s32, s32); +extern void func_80131CA8(int a0, int a1); +extern void func_8012F5F4(s32 arg0); +extern void func_80131C78(s32 a0); +extern void func_8012F68C(s32 arg0); +extern void func_8012F75C(s32 a0); +extern s32 func_8012BEE8(s32); +extern void func_8012F7B4(s32 a0); +extern void func_80131170(); +extern void func_80131CA8(); +extern void func_8012F828(int param_1); +extern void func_80131340(s32 a0); +extern void func_8012F87C(s32 a0); +extern void func_8012F8C8(int param_1); +extern void func_8012F91C(s32 a0); +extern s32 func_80131A34(s32 a0, s32 a1); +extern void func_80131CA8(s32 a0, s32 a1); +extern void func_8012F968(s32 param_1); +extern void func_801319E0(s32 a0); +extern s32 func_80143B6C(s32 a0, s32 a1); +extern void func_8012FB54(s32 a0); +extern void func_8012FC30(s32 a0); +extern void func_8012FCA4(int a0); +extern void func_80131B14(void); +extern void func_8012FCC4(int param_1); +extern void func_8012FDA8(int param_1); +extern void func_80131170(s32 a0, s32 a1, s32 a2); +extern void func_8012FE70(s32 a0); +extern void func_8012FF00(s32 a0); +extern void func_8012FF4C(s32 a0); +extern void func_80130D48(s32 a0); +extern void func_8012FF98(u8 *a0); +extern s32 func_80131AC8(void *a0); +extern void func_8013001C(void *a0); +extern void func_80130088(void *a0); +extern s32 func_8012BCCC(s32); +extern void func_801300F4(s32 a0); +extern void func_801301E8(u8 *a0); +extern void func_80130278(s32 arg0); +extern void func_80130314(s32 a0); +extern void func_80130360(s32 a0); +extern void func_8012E364(void); +extern void func_801303A0(s32 a0); +extern void func_801303EC(void *a0); +extern void func_80143CD4(s32 a0); +extern void func_800CB0E8(s32 a0); +extern void func_80130438(s32 a0); +extern void func_801319E0(int); +extern int func_80131D68(int, int); +extern int func_8012BEE8(int); +extern void func_80131CA8(int, int); +extern void func_80130514(int param_1); +extern void func_801305CC(u8 *a0); +extern void func_8012CBF4(s32); +extern s32 func_80131D68(s32 a0, s32 a1); +extern void func_80130650(s32 a0); +extern s32 func_80146A6C(s32 a0, void *a1, s32 a2, s32 a3, s32 a4, s32 a5, s32 a6); +extern void func_80130740(void *a0, u16 *a1); +extern s32 func_801312D0(s32 a0, void *a1); +extern void func_801307B0(s32 a0); +extern void func_80130858(s32 a0); +extern void func_80130898(u8 *a0); +extern void func_801308DC(s32 a0); +extern void func_80166244(); +extern void func_80130974(int param_1); +extern void func_80130A18(u8 *a0); +extern void func_80130AC4(s32 a0); +extern int func_80131A34(int a0, int a1); +extern void func_80130AF0(int param_1); +extern void func_80130D0C(s32 a0); +extern void func_80131170(s32 p, s32 b, s32 c); +extern s32 func_801312D0(s32 param_1, void *param_2); +extern void func_80131E00(); +extern s32 D_8018F078; +extern s32 D_8018F07C; +extern void func_8002A04C(s32 a0); +extern void func_801319E0(s32 arg0); +extern s32 func_80131CF4(s32 a0); +extern int func_80131D68(int a0, int a1); +extern void func_80131E38(u8 *a0); +extern void func_80131E7C(s32 a0); +extern void func_80131EE4(void); +extern void func_80131EEC(void *a0); +extern void func_80131F28(void *a0); +extern void func_80131F64(void *a0); +extern void func_80131FA0(void *a0); +extern void func_80131FDC(void *a0); +extern void func_801320D0(void); +extern void func_8001C214(int, int); +extern void func_801320D8(int param_1); +extern void func_80132144(int param_1); +extern void func_801321B0(int param_1); +extern void func_8013221C(int param_1); +extern void func_8005C324(int dst, int src, int n) __asm__("memcpy"); /* Phase-24: 0x8005C324 is named memcpy for overlays (whale needs it); keep the non-builtin C name here (else built-in codegen), emit via asm-label */ +extern void func_801325B8(int a0, int a1, int a2, int a3, int a4); +extern void func_80132288(int *param_1, int *param_2, int param_3); +extern void func_801325B8(s32 a0, s32 a1, s32 a2, s32 a3, s32 a4); +extern void func_8013240C(s32 a0); +extern void func_8013277C(void); +extern void func_80020F34(s32 a0, s32 a1); +extern void func_80054514(s32 a0, s32 a1); +extern void func_80132784(s32 a0, s32 a1, u32 a2); +extern s32 VectorNormalSS(void *a0, void *a1); +extern void func_80132DC4(s32 a0, s32 a1, s32 a2); +extern s32 func_80132E6C(s16 *a0); +extern void func_80132EC4(void *a0, s16 a1); +extern s32 func_80132EF4(s32 a0, s32 a1); +extern void func_801330E0(s16 *a0, s16 *a1, s32 a2); +extern void func_80133060(u8 *a0, s32 *a1, s32 a2); +extern void func_8013339C(short *param_1, short *param_2); +extern s32 func_8013361C(s16 *a0, s16 *a1, s16 *a2, s16 *a3); +extern void func_80136BC4(s32 a0); +extern void func_801336E8(void *a0, int a1, int a2); +extern void func_80136BC4(s32); +extern void func_8013373C(s16 arg0); +extern s32 func_80133784(s32 arg0, void *arg1, s32 arg2); +extern s32 func_80133CD4(); +extern s32 func_80134310(Vec3s *a0, Vec3s *a1, s32 a2); +extern s32 func_8013435C(s16 *a0, s16 *a1, s32 a2, s16 *a3); +extern s32 func_801343C4(s32 angle, s32 p1, s32 p2); +extern s32 func_801345F8(s32 arg); +extern s32 func_80134A28(s32 a0, s32 a1, s32 a2); +extern int func_80134A74(int param_1, s16 param_2, s16 param_3, int param_4); +extern s32 func_80134C20(s32 arg0, s32 arg1, s32 arg2, s32 arg3); +extern s32 func_80134FB8(s32 a0, s32 a1, s32 a2); +extern int func_80134A74(int, s16, s16, int); +extern int func_80135168(u16 arg0, u16 *p1, u16 *p2); +extern s16 func_80135480(void *param_1, s32 param_2, s16 *param_3, s16 *param_4); +extern s32 func_80136334(void *arg0, s32 arg1, s32 arg2); +extern s32 func_801365B8(void *arg0, s32 arg1, s32 arg2); +extern s32 func_80136824(s32 arg0, s32 arg1, s32 arg2); +extern s32 func_80136A94(s32 a0, s32 a1, s32 a2, s32 a3); +extern void func_80136C3C(void); +extern void func_80136C1C(void); +extern void func_80136C44(void); +extern void func_80136C4C(void); +extern void func_80136C54(void); +extern void func_80136D00(void); +extern void SetLineG2(void *); +extern void func_80136D08(s32 arg0, s32 arg1); +extern u16 D_80126CC4; +extern M2C_UNK func_800153CC(M2C_UNK, u16, M2C_UNK, M2C_UNK, s32, s32); +extern void func_80136DFC(void); +extern void func_80136EC4(void); +extern short D_800B9A02; +extern u8 D_800A6518[]; +extern void GsSortLine(void *a0, void *a1, s32 a2); +extern void func_80136ECC(s16 a0, s16 a1, s16 a2, s16 a3, u8 r, u8 g, u8 b); +extern void func_80137030(s16 a0, s16 a1); +extern void ApplyMatrixSV(void *m, Svec_801372B0 *in, Svec_801372B0 *out); +extern void aGsSortLine(Gline_801372B0 *p, void *ot, s32 z) __asm__("GsSortLine"); +extern void aF80137030(s32 x, s32 y) __asm__("func_80137030"); +extern void func_80137178(s32 x, s32 y); +extern u8 D_800AF630[]; +extern u16 aD800B9A02 __asm__("D_800B9A02"); +extern void func_801372B0(void); +extern void func_80137614(s32 a0, s32 a1, s32 a2); +extern void func_801375EC(s32 a0, s16 a1); +extern s32 func_801399A8(void); +extern void func_801377B4(s32 a0, s32 a1, s32 a2); +extern s32 func_8013767C(s32 a0); +extern void func_801376E8(int a0, int a1); +extern void func_801376C8(int a0); +extern s32 D_80127524; +extern s32 D_80127528; +extern void func_80137840(s32 a0); +extern void func_80139634(void *); +extern void func_80139DC8(void); +extern s16 D_8012752E; +extern void func_801379D8(void); +extern void func_801379EC(void); +extern void func_80138BE0(s32 a0); +extern void func_80137BD8(s32 a0); +extern void func_8013A380(void); +extern void func_801379FC(void); +extern void func_80138BE0(int p); +extern void func_80137B80(void); +extern void func_801392FC(); +extern void func_801397B0(s32 a0); +extern void func_80137DD4(s32 a0, u8 *a1, u8 *a2); +extern void func_80139680(s32 a0, u8 *a1); +extern u16 D_800B99D8; +extern int func_80137D08(int arg0, int arg1, short arg2); +extern void func_80137FD8(s32 a0, s32 a1, s32 a2, s32 a3); +extern void func_80137DD4(s32 ent, u8 *arg, u8 *work); +extern void func_801387B8(s32 arg0); +extern void func_80138948(void *a0); +extern s16 func_80138DB8(s32 a0, u8 a1, s32 a2); +extern void func_80138B88(s32 a0); +extern void func_8013895C(s32 a0); +extern s16 D_80127540[4]; +extern s32 func_80139D04(s32 a0, s32 a1); +extern s32 func_80138DE0(s32 a0, s32 a1, s32 a2); +extern void func_80139B18(s32 a0); +extern void func_80138AB4(s32 a0); +extern void func_80138C30(void *a0); +extern void func_8013A9F8(s32 a0, s32 a1); +extern void func_80138D58(s32 a0, u16 a1); +extern s32 func_80014E80(s32 a0, s32 a1); +extern s32 func_8013914C(s32 a0, s32 a1); +extern void func_800599B8(u16 *); +extern u16 D_80127C0C[]; +extern s32 D_80127548[]; +extern s32 func_80138ED0(u8 *param_1, u32 param_2, u8 *param_3); +extern s32 func_80139220(s32 a0); +extern void func_801391F0(void *a0); +extern void func_801392C8(void *a0); +extern void func_801395D4(void *); +extern s32 GetTPage(s32 a0, s32 a1, s32 a2, s32 a3); +extern s32 func_80052460(s32 a0, s32 a1, s32 a2); +extern void func_801392FC(s32 arg0, s32 arg1, u8 *arg2); +extern void func_80059888(void *a0, s32 a1, s32 a2, s32 a3); +extern void func_80139634(void *a0); +extern void func_80139680(s32 arg0, u8 * arg1); +extern void func_8001931C(void); +extern s16 D_8012752C; +extern void func_80139788(void); +extern void GsSortSprite(void *a0, u8 *a1, s32 a2); +extern void func_801397B0(s32 arg0); +extern void func_8013A8B0(s32 *a0); +extern void func_80139914(s32 arg0); +extern u16 D_80126A08; +extern s16 D_801269F4; +extern s32 D_801269F0; +extern s32 *D_80126A30; +extern void func_80139954(void); +extern s32 D_80126A3C; +extern s32 func_801399F0(s32 a0); +extern s32 D_80127520; +extern void func_80139A34(s32 a0); +extern s32 D_80127530[4]; +extern void func_80139A44(s32 a0, u16 a1); +extern void func_80139A68(s32 a0, u16 a1); +extern void func_80139A8C(s32 a0); +extern void func_80139C7C(u8 *a0); +extern s16 D_8012811A; +extern void func_80139DEC(void); +extern void func_80139DF4(s32 a0); +extern void func_80139E84(s32 a0); +extern void func_80139F0C(s32 a0); +extern void func_80139FBC(struct obj *a0); +extern s32 func_8001B22C(void *a0); +extern void func_80139FE8(void *a0); +extern void func_8013A0A4(struct S8013A0A4 *a0); +extern void func_8013A164(struct S8013A164 *a0); +extern void func_8013A1E8(s32 a0); +extern void func_8013A250(struct S8013A250 *a0); +extern void func_8013A2BC(s32 a0); +extern void func_8013A378(void); +extern u8 D_8011DA80[]; +extern void func_8013A530(); +extern void func_8013A448(void *a0); +extern void func_8013A4C4(struct S8013A4C4 *a0); +extern void func_80015D4C(); +extern void func_80015F04(); +extern void func_8013AA24(s32 a0, s32 a1); +extern void func_8013A530(int param_1); +extern void func_8013A860(void); +extern s32 func_8013A8BC(void); +extern void func_8013A9B4(s32 a0, s32 a1); +extern s32 func_8013A8FC(s32 arg0); +extern void func_8013AD38(void *a0, s32 a1, void *a2, void *a3); +extern void func_8013B204(s32 a0, s32 a1); +extern void func_8013AF20(); +extern void func_8013B274(s32 a0, s32 a1, void *a2); +extern s32 func_8013AB54(s32 a0, s32 a1, s32 a2, s32 a3); +extern void func_8013AF20(u32 *param_1, u16 *param_2, u16 *param_3, u8 *param_4); +extern void func_80019064(void *a0); +extern void func_8013C9C4(void * arg0); +extern void func_8013CA14(void); +extern void func_8013CABC(void); +extern void func_8013CAE8(void); +extern void func_8013CB20(void); +extern void func_8013CB5C(void); +extern void func_8013CF68(); +extern void func_8013D9B0(); +extern void func_8013D064(void); +extern s32 func_8013D13C(void); +extern void func_8013D164(void); +extern void func_8013D178(void); +extern void func_8013D330(void); +extern void func_8013D53C(); +extern void func_8013DD68(void); +extern void func_8013D8FC(void); +extern void func_8013CF68(void); +extern void func_8013D3D4(int param_1, int param_2); +extern void func_8013DBE4(int param_1); +extern s32 func_8013E054(void); +extern int SquareRoot12(int a0); +extern int func_8013E064(s16 *a0, s16 *a1); +extern int func_8013E0FC(s16 *a0, s16 *a1); +extern int func_8013E194(s16 *a0, s16 *a1); +extern void Square12(s32 *a0, s32 *a1); +extern s32 func_8013E22C(struct VecA *a0, struct VecB *a1); +extern s32 func_8013E298(s16 *a0); +extern int func_8013E2C4(short *a0); +extern void *D_801274CC; +extern s32 func_8013E410(void); +extern s32 func_8013E448(s32 a0); +extern void func_8013E370(void); +extern s32 (*D_801274D0)(s32); +extern s32 D_801274D8; +extern s32 D_801274DC; +extern s32 func_8013E448(s32 param_1); +extern void func_800D24A0(s32 a0); +extern void func_80141788(void); +extern void *D_8011DB24; +extern s32 func_800D0EC4(void); +extern void func_80141874(void); +extern u8 D_800B9A15; +extern unsigned char D_800B9A13; +extern u16 D_80115110; +extern unsigned short D_80115112; +extern void func_8013E588(void * _arg0); +extern void func_801754A8(void); +extern s32 func_80014ED4(s32); +extern s32 func_80015018(s32); +extern void func_800190AC(void); +extern void func_80141C04(void); +extern void func_8013E5E8(void); +extern void func_8013E83C(void); +extern void func_8013E6AC(void); +extern void func_800D24A0(s32 arg); +extern void func_8013E814(void); +extern void func_8013E83C(); +extern void func_8013E958(); +extern s32 func_80141C50(void); +extern void func_8013F244(void); +extern void func_8013FAF8(s16 a0, s16 a1); +extern void func_8013E958(void); +extern u8 D_801151C8[]; +extern s32 D_801151D0; +extern u16 D_8011511A; +extern u16 D_8011511E; +extern s32 D_80115130; +extern s16 D_8011514C; +extern void func_8013EA54(void); +extern s32 func_8013F350(void); /* §30#2 widened: def returns live $v0; callers discard */ +extern s16 func_8014168C(s16 a0); +extern s32 func_8014032C(s32 a0, s32 a1); +extern unsigned char *func_80141CA4(void); +extern void func_8013EB7C(void); +extern s32 func_8013F350(void); /* §30#2 widened (discarding caller) */ +extern u16 D_80115112; +extern void func_8013ED6C(void); +extern s32 func_8013EE10(); +extern void func_8013F138(void); +extern void func_800D2624(void); +extern unsigned short D_80115114; +extern unsigned short D_80115118; +extern void func_8013F1BC(void); +extern void func_80141C0C(s32); +extern u16 D_8011511C; +extern u16 D_80115120; +extern u16 D_80115122; +extern s16 D_80115128; +extern s16 D_8011512A; +extern u16 D_8011512E; +extern u8 D_80115140[]; +extern s16 D_8011514E; +extern u8 D_80115152; +extern u8 D_80115158[]; /* macro-canonical (§8e) */ +extern u8 D_8011515C; /* macro-canonical (§8e) */ +extern u8 D_8017F71C[]; +extern u8 D_8017F734[]; +extern u16 D_8017F638[]; +extern s32 func_80029178(s32 arg); +extern s32 func_800291B4(s32 arg); +extern void func_8014AA04(s32 a0); +extern void func_801415C0(s32 a0, s32 a1); +extern void func_80141C0C(s32 a0); +extern s32 func_80140608(s32 a0); +extern void func_801407F4(void); +extern s32 func_801416D4(s16); /* macro-canonical (§8e) */ +extern s32 func_8013F350(void); +extern void func_80140E6C(void); +extern void func_80140F00(void); +extern s32 *func_80140958(s32 *, s32, s32); +extern int func_80141100(int); +extern s16 func_8014168C(s16); +extern s32 func_8013FFD8(s16, s32, s32 *); +extern void func_80024054(void *a0, void *a1); +extern s32 *func_800D2650(s32 *, void *, s32, s32, s32, s32); +extern s32 func_800D27DC(s32, s32 *, void *, s32, s32); +extern s32 *func_800D29F8(s32, s32, void *, s32, s32); +extern void func_8013FAF8(s16 arg0, s16 arg1); +extern s32 func_80028D58(void); +extern s32 func_80028DE0(void); +extern s32 func_80028FBC(void); +extern s32 func_80029000(void); +extern s32 func_80028D9C(void); +extern int func_800D2CA8(int, int); +extern void func_800D2D10(int, int, void *, int); +extern int func_80029FE4(void); +extern char *func_8002AAB4(void); +extern char *strcpy(char *, const char *); +extern int func_8002A26C(void); +extern int func_8002A2B0(void); +extern int func_8002A4B8(void); +extern int func_8002A998(void); +extern int func_8002A9DC(void); +extern int func_8002A728(void); +extern int func_8002A76C(void); +extern int func_80029FD4(void); +extern s32 func_8002A1B4(void); +extern short func_8002A28C(void); +extern short func_8002A27C(void); +extern s32 func_8002A400(void); +extern short func_8002A4D8(void); +extern short func_8002A4C8(void); +extern s32 func_8002A8E0(void); +extern short func_8002A9B8(void); +extern short func_8002A9A8(void); +extern s32 func_8002A670(void); +extern short func_8002A748(void); +extern short func_8002A738(void); +extern int func_801412A8(int, int, int, int, int, int); +extern int func_80141100(int param_1); +extern void func_800291A0(s32, s32); +extern s32 func_800291DC(s32); +extern void func_800291C8(s32, s32); +extern void func_801415C0(s32 param_1, s32 param_2); +extern u8 D_80115148[]; +extern u8 D_80115149[]; +extern u8 D_80115158[]; +extern u8 D_8011514D; +extern u8 D_8011515C; +extern s32 func_800D11F0(s32 a0); +extern s32 func_800D1658(s32 a0); +extern s32 func_801416D4(s16 param_1); +extern void func_8001903C(void); +extern void func_801417C4(void); +extern u8 D_800B9A16; +extern u16 D_80115114; +extern void func_801417F8(void); +extern volatile u16 D_8011511A; +extern u16 D_8011512E; /* §17a-1: canonical width (jr_8013F350 TUs decl u16); byte-neutral here (only use is store-0) */ +extern s32 func_80029178(s32 a0); +extern void func_801418F8(void); +extern void func_80141A60(void); +extern void func_80141C0C(s32 param_1); +extern s32 func_80015144(void); +extern unsigned char D_80112C04[]; +extern unsigned char D_80112C50[]; +extern unsigned char D_80112C9C[]; +extern unsigned char D_80112CE8[]; +extern unsigned char D_80112D38[]; +extern unsigned char D_80112D78[]; +extern unsigned char D_80112DBC[]; +extern unsigned char D_80112DF4[]; +extern unsigned char D_80112E14[]; +extern unsigned char D_80112E40[]; +extern unsigned char D_80112E6C[]; +extern unsigned char D_80112EBC[]; +extern unsigned char D_80112F0C[]; +extern unsigned char D_80112F48[]; +extern unsigned char D_80112F9C[]; +extern unsigned char D_80112FDC[]; +extern unsigned char D_8011302C[]; +extern unsigned char D_80113074[]; +extern unsigned char D_801130B8[]; +extern unsigned char D_801130E8[]; +extern unsigned char D_80113138[]; +extern unsigned char D_8011317C[]; +extern unsigned char D_801131A8[]; +extern unsigned char D_801131E8[]; +extern unsigned char D_80113214[]; +extern unsigned char D_80113254[]; +extern unsigned char D_80113278[]; +extern unsigned char D_801132B8[]; +extern unsigned char D_801132E4[]; +extern unsigned char D_80113324[]; +extern unsigned char D_80113360[]; +extern unsigned char D_801133A4[]; +extern unsigned char D_801133F4[]; +extern unsigned char D_80113440[]; +extern unsigned char D_80113474[]; +extern unsigned char D_801134B0[]; +extern unsigned char D_801134FC[]; +extern unsigned char D_80113530[]; +extern unsigned char D_80113554[]; +extern unsigned char D_801135A8[]; +extern unsigned char D_80113600[]; +extern unsigned char D_80113650[]; +extern unsigned char D_80113694[]; +extern unsigned char D_801136DC[]; +extern unsigned char D_80113724[]; +extern unsigned char D_80113744[]; +extern unsigned char D_80113770[]; +extern unsigned char D_80113794[]; +extern unsigned char D_801137D8[]; +extern unsigned char D_8011381C[]; +extern unsigned char D_8011383C[]; +extern unsigned char D_8011386C[]; +extern unsigned char D_801138A4[]; +extern unsigned char D_801138D0[]; +extern unsigned char D_80113900[]; +extern unsigned char D_80113944[]; +extern unsigned char D_80113964[]; +extern unsigned char D_8011399C[]; +extern unsigned char D_801139E8[]; +extern unsigned char D_80113A28[]; +extern unsigned char D_80113A50[]; +extern unsigned char D_80113A84[]; +extern unsigned char D_80113AB0[]; +extern unsigned char D_80113AE0[]; +extern unsigned char D_80113B34[]; +extern unsigned char D_80113B68[]; +extern unsigned char D_80113BA4[]; +extern unsigned char D_80113BC0[]; +extern unsigned char D_80113BF0[]; +extern unsigned char D_80113C20[]; +extern unsigned char D_80113C3C[]; +extern unsigned char D_80113C7C[]; +extern unsigned char * func_80141CA4(void); +extern void func_80142414(s32 a0, s16 a1); +extern void func_80142454(s32 a0); +extern void func_801424E4(short *param_1); +extern void func_801425CC(void *a0); +extern void func_8001CA1C(s32 a0, s32 a1); +extern s32 func_8012AD50(void *a0); +extern void func_80142608(s32 param_1); +extern void func_801426D4(s32 a0); +extern void func_80142740(int param_1); +extern void func_80142778(u8 *a1); +extern void func_801427DC(void); +extern void func_801427E4(void); +extern void func_801427EC(int param_1); +extern s32 func_80142DB8(s32 *a0); +extern s32 func_80142D38(s32 *a0); +extern void func_80142BB4(s32 *a0, s32 a1, s32 a2); +extern void func_801428CC(s32 *a0); +extern void func_8014292C(int param_1); +extern void func_80142978(int param_1); +extern void func_801429C4(int param_1); +extern void func_80142A80(void); +extern void func_80142C7C(void); +extern void func_80142C84(s32 a0); +extern void func_80142C9C(s32 * arg0); +extern void func_80142B2C(void *arg0); +extern void func_80142DC4(int param_1); +extern void func_80142E38(int param_1); +extern void func_8012A828(s32 a0, void *a1); +extern void func_80142EC0(s32 param_1); +extern void func_80142FFC(s32 *a0); +extern void func_8014305C(int param_1); +extern void func_80143188(s32 *a0); +extern int func_8001CA88(int, void *); +extern void func_800233CC(void *, unsigned short); +extern void func_801431E8(s32 param_1); +extern void func_80142C9C(s32 *a0); +extern void func_801432FC(s32 *a0); +extern void func_80143390(s32 *a0); +extern void func_80143458(s32 param_1); +extern void func_8014358C(s32 param_1); +extern s32 rand(void); +extern void func_80143640(s32 a0, s32 a1, s32 a2, s32 a3); +extern void func_801437D8(s32 a0, s32 a1, s32 a2, s32 a3); +extern s32 func_80143970(s32 a0); +extern s32 func_8012C658(s32 a0, s32 a1, s32 a2); +extern void func_80143994(s32 a0, s32 a1); +extern void func_801439C0(u8 *a0); +extern s16 D_801152AC; +extern s16 D_801152AA; +extern void func_801439FC(s32 a0); +extern void func_80143B30(void *a0); +extern s32 func_8012C658(s32 arg0, s32 arg1, s32 arg2); +extern s32 func_80143B6C(s32 arg0, s32 arg1); +extern void func_80143BDC(u16 *a0); +extern void func_80143C38(void *a0); +extern void func_80143C74(s32 a0, s32 a1); +extern void func_80143C98(void *a0); +extern void func_80143E68(void *a0); +extern void func_80143EA4(void); +extern void func_80143EAC(void); +extern void func_80143EB4(void); +extern s32 func_8004787C(s32 a0); +extern void func_80143EBC(s32 a0); +extern void func_80144054(void *a0); +extern void func_801442F8(int param_1); +extern void func_8001CB6C(u8 *a0, s32 a1, s32 a2, s32 a3); +extern void func_80144364(int param_1); +extern u8 D_800D387C[]; +extern u8 D_800D3888[]; +extern void func_80144558(u8 *param_1); +extern void func_801446A4(int param_1); +extern void func_8014477C(void *param_1); +extern void func_80144880(s32 param_1); +extern void func_80144988(s32 a0); +extern void func_801449C8(void *a0); +extern void func_80144A04(s32 *a0); +extern void func_80144A2C(void *a0); +extern void func_80144A68(s32 *a0); +extern void func_80144A90(void); +extern void func_80144A98(u8 *a0); +extern void func_80144B14(void); +extern void func_80144AEC(s32 *a0); +extern void func_801458E0(void); +extern s32 D_800AE6AC; +extern s32 D_800AE6B0; +extern s16 D_800B9A0A; +extern u8 D_80078E50; +extern void func_800D185C(u8 *a0); +extern void func_801458E8(void); +extern void func_80145B24(void); +extern void func_80145934(void); +extern void func_80145A2C(void); +extern void func_80162120(void); +extern void func_80029124(s32, s32); +extern s32 func_80165A50(s32); +extern void func_80029514(s32); +extern u8 D_80078EC0; +extern void func_80145BF8(void); +extern void func_80145C54(void); +extern void func_80146014(s32 a0); +extern void func_80145EE8(s32 param_1); +extern void MoveImage(void *a0, s32 a1, s32 a2); +extern s32 func_80146128(void); +extern void func_80146360(void); +extern void func_801463A0(); +extern u8 D_80078EC1; +extern s32 D_80078EC8; +extern s32 D_80126B9C; +extern s32 D_8011F730; +extern u16 D_801152B8; +extern u16 D_8012693A; +extern u8 D_80126BE0[]; +extern u8 D_801150F0[]; +extern void *memcpy(void *dst, const void *src, u32 n); +extern void func_80146FC4(s32 a0); +extern void func_80150A70(s32 a0); +extern void func_80147098(s32 *a0); +extern void func_8014A638(s32 arg0); +extern s32 func_80155458(s32 a0); +extern s32 func_80029104(void); +extern void func_80029344(void); +extern void func_8014ADE0(s32 a0); +extern void func_8014B350(s32 a0); +extern void func_8014B7A4(s16 *param_1); +extern s32 func_80161D58(s32 a0); +extern void func_80161A90(s32 a0); +extern void func_8014B504(u16 *a0); +extern void func_80149BEC(s32 a0); +extern void func_8014B5D0(s32 *a0); +extern void func_8014C99C(u8 *a0); +extern void func_8014B190(s32 s0); +extern void func_80148648(s32 a0, s32 a1); +extern s32 func_80149228(s32 a0); +extern void func_8014A59C(s32 a0); +extern void func_8016F14C(void *a0); +extern void func_80154418(void *a0); +extern void func_80154BE4(s32 a0); +extern void func_80165694(s32 arg0); +extern void func_801654A8(s32 a0); +extern void func_8014A680(s32 a0); +extern void func_8014A6A8(s32 a0); +extern void func_8014A71C(s32 a0); +extern void func_80172588(s32 *a0); +extern void func_801473DC(s32 *a0); +extern void func_80015978(s32 a0, s32 *a1); +extern s32 D_80127098; +extern s32 D_80127094; +extern s32 D_80127090; +extern void func_80146534(void); +extern void func_8001D074(s32 a0, s32 a1); +extern void func_80146554(void); +extern void func_80146578(void); +extern void func_8001CFDC(s32, s32); +extern void func_8014659C(void); +extern void func_8001D074(s32, s32); +extern void func_801465C0(void); +extern void func_801465E4(void); +extern void func_801466F0(s32 a0, s32 a1, s32 a2, s32 a3, s32 sp5, s32 sp6, s32 sp7, s32 sp8); +extern s32 D_8011F9D0; +extern s32 func_80146608(s32 a0, s32 a1, s32 a2, s32 a3, s16 arg9, s32 arg10, s32 arg11, s32 arg12, s32 arg13); +extern void func_801466B4(u16 a0, s32 a1, s32 a2, s32 a3, s32 arg5); +extern s32 D_8011F750; +extern s32 D_8011F754; +extern u8 * func_801468C8(s32 arg0, u8 arg1); +extern s32 D_8011D030; +extern s32 func_80146994(s32 a0, s32 a1, s32 a2, s32 a3); +extern s32 func_80146924(s32 a0, s32 a1, s32 a2, s32 a3, s32 arg5); +extern s32 func_80146994(s32 arg0, s32 arg1, s32 arg2, s32 arg3); +extern s32 func_801469C8(int a0, void *a1, int a2, int a3, u16 arg5, int arg6, int arg7, int arg8); +extern s32 func_80146B9C(void *a0); +extern void func_80146AB4(s16 a0, s32 a1, s16 a2, s16 a3, u16 a4, s32 a5, s32 a6); +extern u16 D_8011DA28; +extern s32 func_80146B9C(void * arg0); +extern void func_80146C3C(u8 *a0); +extern void func_80146C98(s32 *a0, s16 a1); +extern void func_80146CA0(void *a0); +extern void func_80146CB4(void *a0); +extern void func_80146CC8(s32 a0); +extern void func_80146D30(s32 a0); +extern void func_80146D80(s32 *a0); +extern void func_80146DE8(s32 *a0, s32 a1, s32 a2, s32 a3); +extern void func_80146D90(s32 a0); +extern void func_80146DB8(s32 *a0, s32 *a1); +extern void func_80146DF8(s32 *a0, s32 a1, s32 a2, s32 a3, s32 t0); +extern void func_80146E90(s32 *a0, s32 a1); +extern s32 func_80146E98(s32 a0); +extern void func_80015954(s32 a0, s32 a1); +extern void func_80149374(s32 a0, s32 a1); +extern void func_80146F58(s32 a0, s32 a1); +extern void func_80146EC0(s32 a0, s32 a1, s32 a2, s32 a3); +extern u8 D_80126DB0[]; +extern u16 D_80126DB6; +extern void func_8014704C(s32 *a0); +extern s32 func_80147054(void *a0); +extern void func_80147060(u8 * a0); +extern void func_8014706C(void *arg0); +extern void func_80147078(s32 *a0, s16 a1); +extern void func_80147084(s32 *a0); +extern void func_8014708C(void *arg0); +extern s32 func_801470A0(void *a0); +extern void func_801470AC(s32 *a0); +extern void func_801470B4(s32 arg0); +extern void func_801470C0(s32 a0); +extern void func_80147118(s32 a0); +extern s16 D_80126BB8; +extern s16 D_80126BBA; +extern s16 D_80126BBC; +extern void func_80147264(s32 a0); +extern void func_80147290(void); +extern void func_801472B4(void *a0); +extern s32 func_801472C8(struct S *a0); +extern void *D_8012707C; +extern void func_801472DC(void); +extern void func_801472F0(void *a0); +extern void func_80147364(u16, s32); +extern void func_80147300(u16 arg0); +extern void func_80147324(s32 arg0); +extern void func_801473EC(s32 *a0); +extern void func_80147460(s32 a0); +extern void func_80147514(); +extern void func_80147628(s32 a0); +extern void func_80147478(s32 a0); +extern void func_801474D8(s32 *a0); +extern void func_801474EC(s32 *a0); +extern s32 func_80012C6C(s32 a0, s32 a1, s32 a2); +extern s32 func_800129CC(s32 a0, s32 a1); +extern void func_80147514(s32 arg0); +extern void func_80013F3C(s32 a0); +extern void func_80012558(s32 a0, s32 a1); +extern void func_800126C4(s32 a0, s32 a1); +extern void func_800123F0(s32 a0, s32 a1); +extern void func_80147718(s32 a0); +extern void func_80147788(void *a0, s32 a1); +extern void func_801477A8(void *a0, s32 a1); +extern void func_801477C8(void *a0, s32 a1); +extern void func_801477E8(s32 *a0, s32 a1); +extern void func_80147814(s32 a0, s32 a1); +extern void func_80147928(int a0, int a1); +extern void func_8014799C(int a0, int a1); +extern void func_80147A10(int a0, int a1); +extern void func_80147860(int a0, int a1, int a2, int a3); +extern void func_80147948(s32 a0, s32 a1, s32 a2); +extern void func_801479BC(s32 a0, s32 a1, s32 a2); +extern void func_80147A30(s32 a0, s32 a1, s32 a2); +extern void func_801478B8(s32 a0, s32 a1, s32 a2, s32 a3); +extern void func_80147948(int a0, int a1, int a2); +extern void func_801479BC(int a0, int a1, int a2); +extern void func_80147A30(int a0, int a1, int a2); +extern void func_80147AD4(s32 arg0, s32 arg1, s32 arg2, s32 arg3); +extern void func_80147A84(s32 arg0); +extern void func_80147C30(s32 arg0, s32 arg1, s32 arg2, s32 arg3); +extern void func_80147AAC(s32 arg0); +extern void func_80147CC8(s32 a0, s32 a1, s32 a2, s32 a3, s32 a4); +extern void func_80147B5C(s32 a0, void *a1); +extern void func_80147AD4(s32 a0, s32 a1, s32 a2, s32 a3); +extern void func_80147D38(s32 a0, s32 a1, s32 a2, s32 a3, void *a4); +extern void func_80147B18(s32 a0); +extern void func_80147B5C(s32 arg0, void *arg1); +extern void func_80147C30(s32 a0, s32 a1, s32 a2, s32 a3); +extern void func_80147DC0(s32 a0, s32 a1); +extern void func_80147D38(s32 a0, s32 a1, s32 a2, s32 a3, void * a4); +extern void func_80147E44(s32 a0, s32 a1, s32 a2, s32 a3); +extern void func_80147F78(s32 arg0, s32 arg1, s32 arg2, s32 arg3); +extern void func_80147F50(s32 arg0); +extern volatile s32 D_80127090; +extern volatile s32 D_80127094; +extern volatile s32 D_80127098; +extern void func_80147F78(s32 a0, s32 a1, s32 a2, s32 a3); +extern void func_80148038(s32 a0, s32 a1); +extern s32 csqrt(s32 a0); +extern s32 func_80012A60(s32 a0, s32 a1); +extern void func_80148094(int param_1, short *param_2, int *param_3); +extern void func_801485B8(s32 a0, s32 a1, s32 a2); +extern void func_801484B0(s32 a0, s32 a1); +extern s32 func_80154358(void *a0); +extern void func_801484E8(s32 a0, s32 a1); +extern void func_80148534(s32 a0, s32 a1); +extern void func_8014856C(s32 a0, s32 a1); +extern void func_801485B8(s32 arg0, s32 arg1, s32 arg2); +extern void func_80148634(void *a0); +extern s32 func_80014DC0(); +extern s32 func_80014D68(); +extern s32 func_80014D94(); +extern s32 func_80014CF8(); +extern void func_800120DC(); +extern s32 func_800CF8B4(); +extern u16 func_801487F4(s32 *a0); +extern u16 func_80148800(s32 *a0); +extern u8 func_8014880C(s32 *a0); +extern u16 func_80148818(s32 *a0); +extern s32 func_80148824(void *arg0); +extern s32 func_801488A8(u8 *a0); +extern s32 func_8014891C(s32 a0); +extern s32 func_80148980(u8 *a0); +extern s32 func_801489E8(s32 a0); +extern s32 func_80148A48(s32 a0); +extern int func_80148AFC(void *a0); +extern void func_80148AAC(u8 *a0); +extern s32 func_80148C18(void); +extern s32 func_80148C20(s32 a0, s16 a1); +extern s32 func_80148C34(s32 a0, s32 a1); +extern s32 func_80148C4C(s32 a0, s32 a1); +extern s32 func_80148C64(s32 a0, s32 a1); +extern s32 func_80148C7C(void); +extern s32 func_80148C84(s32 a0, s32 a1); +extern s32 func_80148C9C(s32 a0, s32 a1); +extern s32 func_80148CB4(s32 a0, s32 a1); +extern s32 func_80148CCC(s32 a0, s32 a1); +extern s32 func_80148CE4(void); +extern s32 func_80148CEC(void); +extern s32 func_80148CF4(s32 a0, s32 a1); +extern s32 func_80148D0C(s32 a0, s32 a1); +extern s32 func_80148D24(void *a0, int a1); +extern s32 func_80148D3C(void); +extern s32 func_80148D44(void); +extern s32 func_80148F60(void); +extern s32 func_80148F68(s32 a0); +extern s32 func_80148F74(s32 a0); +extern s32 func_80148F80(s32 a0); +extern s32 func_80148F8C(s32 a0); +extern s32 func_80148F98(void); +extern s32 func_80148FA0(s32 a0); +extern s32 func_80148FAC(s32 a0); +extern s32 func_80148FB8(s32 a0); +extern s32 func_80148FC4(s32 a0); +extern s32 func_80148FD0(void); +extern s32 func_80148FD8(void); +extern s32 func_80148FE0(s32 a0); +extern s32 func_80148FEC(s32 a0); +extern s32 func_80148FF8(s32 a0); +extern s32 func_80149004(void); +extern void func_8014900C(s32 *a0); +extern void func_80149020(s32 *a0); +extern void func_80149034(s32 *a0); +extern void func_80149048(s32 *a0); +extern void func_8014905C(u8 *a0); +extern void func_801490E0(s32 *a0, s16 a1); +extern void func_801490E8(s32 *a0, s16 a1); +extern void func_801490F0(s32 *a0, s16 a1); +extern void func_80149078(s32 *a0, s32 a1, s32 a2, s32 a3); +extern s32 func_80012B04(s32 a0, s32 a1, s32 a2); +extern void func_801490F8(s32 a0, s32 a1); +extern s32 func_801491C4(s32 a0); +extern s32 func_80149184(s32 a0); +extern void func_80149204(s32 *a0); +extern void func_80149210(s32 a0, s32 a1); +extern s32 func_80149284(s32 *a0, s32 a1); +extern void func_80149350(s32 arg0); +extern void func_80149290(s32 a0); +extern s32 func_801496D4(void *a0); +extern void func_8015AD08(); +extern void func_80149704(void); +extern void func_8015ACC4(); +extern void func_80149724(void); +extern u8 D_80078EBF; +extern s32 func_80149744(struct S_80149744 *a0); +extern void func_8015F7A0(); +extern void func_80149788(void); +extern void func_801653B8(); +extern void func_80149864(void); +extern s32 func_8016F1AC(void); +extern s32 func_80149884(void); +extern void func_80160B00(); +extern void func_801498C0(void); +extern s32 func_80149AA8(s32 *a0); +extern s32 func_80149B54(s32 *a0); +extern void func_80146750(void *a0); +extern s32 func_801498E0(s32 *a0); +extern s32 func_80149A64(s32 *a0); +extern void func_8015DAC4(s32 *a0); +extern void func_8015554C(s32 *a0); +extern void func_80149AD4(s32 *a0); +extern void func_80149B14(s32 *a0); +extern u8 func_8014BEF8(void); +extern s32 func_80149B54(s32 * arg0); +extern void func_8015DE24(s32 *a0); +extern void func_80157510(s32 *a0); +extern void func_80149BAC(s32 *a0); +extern s32 func_80149C08(s32 arg0); +extern void func_801577C8(); +extern void func_80149C94(void); +extern void func_80157D20(void); +extern void func_80149CB4(void); +extern s32 func_80149CD4(s32 a0); +extern u8 func_8014B5B8(s32 *a0); +extern s32 func_80149D10(s32 a0); +extern s32 func_80149E94(s32 a0); +extern s32 func_80149DD8(s32 a0); +extern s32 func_80149D9C(s32 a0); +extern s32 func_80149F2C(s32 a0, s32 a1); +extern s32 func_80149E94(s32 arg0); +extern void func_80149FA8(void); +extern s32 func_80149FB0(s32 a0); +extern u16 func_80156370(u16 a0); +extern void func_8014C4AC(s32 a0, s32 a1, s32 a2, s16 *a3, s32 a4); +extern void func_8014A1B0(s32 a0, s32 a1); +extern void func_8015D4B4(); +extern void func_8014A218(void); +extern s32 func_8014C278(s32 a0, s32 a1, s32 a2); +extern s32 func_8014C2B0(void *a0, void *a1, s32 a2); +extern s32 func_8014A238(s32 arg0); +extern s32 func_8014A2E4(s32 a0); +extern void func_8014A380(s32 a0, s32 a1); +extern s16 D_801152B0; +extern s16 D_801152B4; +extern s32 func_8014A3E0(struct S_8014A3E0 *a0); +extern s32 func_8014A454(s32 a0); +extern s32 func_8014A4B4(void *a0); +extern void func_8015EDD4(); +extern void func_8014A4FC(void); +extern s32 func_8014A674(s32 *a0); +extern s32 func_8014A69C(s32 *a0); +extern s32 func_8014A6C4(s32 a0); +extern void func_8015E184(); +extern void func_8014A830(void); +extern s32 func_80029AF4(void); +extern s32 func_8014A850(s32 param_1); +extern void func_801599A4(void *a0); +extern void func_80159B3C(void *a0); +extern s32 func_80165A20(s32 a0); +extern void func_8014AB7C(); +extern void func_8014AC10(); +extern void func_8014AA28(void); +extern void func_8014AB5C(void); +extern void func_80162CCC(void); +extern void func_8014AB7C(s32 arg0); +extern void func_8014ABF0(void); +extern void func_8014AC10(s32 arg0); +extern void func_8014ACC0(s32 a0, s32 a1); +extern void func_8014AD30(s32 a0, u16 *a1, s32 a2, s32 a3); +extern void func_8014ACE8(void *a0, s32 a1, s32 a2); +extern void func_80146AFC(void *a0); +extern void func_8014ADA8(s32 a0, s32 a1); +extern void func_8014AD7C(s32 a0); +extern s32 D_80078E8C; +extern u8 D_80078E78[]; +extern s32 func_8016F1C4(void); +extern s32 func_8014B154(s32 *a0); +extern void func_8014BD24(s32 a0, s32 a1); +extern void func_8014BB24(s32 a0, s32 a1, s32 a2); +extern void func_8014BC80(s32 a0, s32 a1); +extern void func_8014BD60(s32 a0, s32 a1); +extern void func_8014B084(void); +extern void func_8014B034(s32 arg0); +extern void func_8014B00C(s32 arg0); +extern s16 D_80078E90; +extern void func_8014B034(s32 a0); +extern u16 D_80078EAC; +extern u8 D_80078EBA; +extern void func_800D10EC(void); +extern void func_8002AC98(void); +extern void func_8014B12C(void); +extern void func_8014B2F8(void); +extern void func_8014B4C4(void); +extern void func_8014B160(s32 a0); +extern s16 D_80078E96; +extern s16 D_80078EB8; +extern u16 D_80078EA6; +extern void func_8014B2A8(void); +extern void func_8014B310(void); +extern void func_8014B2D0(void); +extern s32 D_80078E94; +extern s32 D_80078ECC; +extern void func_8014B33C(void); +extern u8 D_80062BF4[]; +extern s32 D_80078E98; +extern void func_8014B4D4(void *a0); +extern s16 D_80078E9A; +extern u8 D_80126D1C; +extern s32 D_80126D74; +extern void func_8014B598(s32 a0, s32 a1); +extern void func_8014B5B0(s32 *a0); +extern void func_8014B5C4(s32 *a0, s32 a1, s32 a2); +extern void func_8014B5D8(s32 s1); +extern s32 D_80078E9C; +extern s32 D_80078ED0; +extern void func_8014B6F0(s32 a0, s32 a1); +extern void func_8014B768(s32 a0, s32 a1); +extern void func_8014B944(s32 a0, s32 a1, s32 a2); +extern s32 D_80078EA4; +extern u16 D_80078EB2; +extern s16 D_80078EB4; +extern void func_8014BB0C(void); +extern void func_8014BC0C(s32 a0, s32 a1); +extern void func_8014BC44(s32 a0, s32 a1); +extern void func_8014BCC0(s32 a0, s32 a1); +extern u16 D_80078EB6; +extern s32 func_8014BCEC(s32 a0, s32 a1); +extern void func_8014BD60(s32 param_1, s32 param_2); +extern void func_8014BD98(s32 a0, u16 a1); +extern void func_8014BDC8(void); +extern void func_8014BDE0(void); +extern s32 func_8017267C(s32 *a0); +extern s32 func_80013294(void *a0, void *a1); +extern void func_80029ED4(s32 a0); +extern void func_8014BDE8(s32 a0); +extern void func_8014BE78(void); +extern void func_8014BE9C(void); +extern void func_80029124(s32 a0, s32 a1); +extern void func_8014BEC0(void); +extern void func_8014BF18(s32 a0); +extern void func_8014BF48(void); +extern u8 func_8014BF6C(void); +extern void func_8014BF8C(u8 arg0); +extern void func_8014BFB0(void); +extern u8 func_8014BFD4(void); +extern void func_8014BFF4(s32 a0, s32 a1); +extern void func_8014C010(s32 a0, s32 a1); +extern s32 func_8014C050(s32 a0, s32 a1); +extern s32 func_8014C088(s32 a0, s32 a1); +extern s32 func_8014C0C8(s32 a0_unused, s32 a1, s32 a2); +extern s32 func_8014C118(void * a0, s32 a1, s32 a2); +extern s32 func_8014C168(s32 * param_1, s32 param_2); +extern void func_8014C1C8(s32 a0, s32 a1, void* a2); +extern s32 func_80013328(s32 a0, s32 a1); +extern s32 func_8014C59C(void *a0, void *a1); +extern s32 func_8014C308(s32 arg0, s32 arg1, s32 arg2, s32 arg3); +extern s32 func_8014C43C(void *a0, s32 a1, s32 a2, s32 a3, s16 a5); +extern s32 func_8014C3A4(void *a0, s32 a1, s32 a2, s32 a3); +extern s32 func_8014C3D0(void *a0, s32 a1, s32 a2, s32 a3); +extern s32 func_8014C43C(void * a0, s32 a1, s32 a2, s32 a3, s16 a4); +extern s32 ratan2(s32 dx, s32 dy); +extern s32 func_8014C5FC(s32 a0, s32 a1, void *a2); +extern s16 func_8014C5D0(s32 a0, s32 a1); +extern s32 func_8014C5FC(s32 a0, s32 a1, void * a2); +extern u8 D_80126D17; +extern void func_8014C6AC(void); +extern void func_8014C6C0(void); +extern u8 D_80126D1E; +extern void func_8014C6D0(void); +extern void func_8014C6E0(void); +extern s32 func_8014C860(s32 a0, s32 a1); +extern void func_8014C8C8(s32 a0, s32 *a1); +extern void func_8014C88C(s32 a0); +extern void func_8014C8C8(s32 dst, s32 * src); +extern void func_8014C8F0(s32 arg0); +extern u8 D_801151F0[]; +extern s32 func_8014C918(s32 a0, s32 a1); +extern s32 D_80126B50; +extern void func_8014C968(void); +extern s32 func_8014C98C(void); +extern void func_80139914(s32 a0); +extern s32 func_8014CA00(s32 a0); +extern u16 func_8014CA70(s32 a0, s32 a1); +extern s32 func_8014CA14(s32 a0, s32 a1); +extern u16 func_8014CAE4(s32 *a0, s32 a1); +extern s32 func_8014CA88(s32 *a0, s32 a1); +extern s32 func_8014CAFC(void); +extern s32 func_8014CB0C(void); +extern s32 func_8014CB1C(void); +extern u8 D_80126D1F; +extern s32 func_8014CB2C(void); +extern s32 func_8014CB58(void); +extern u8 D_80126D1D; +extern void func_8014CB68(void); +extern s32 func_8014CB7C(void); +extern s32 func_8014CB8C(void); +extern struct Packed8 D_80126C98; +extern short D_80126C9E; +extern void func_8014CB9C(struct Packed8 *a0); +extern s32 D_80126CDC; +extern void func_8014CBD8(void); +extern void func_8014CBF8(void *a0); +extern void func_8014D3E0(s32 a0); +extern void func_8014D04C(void); +extern void func_8014CCB4(void); +extern void func_8014CC28(s32 a0); +extern void func_8014CD0C(u8 *a0); +extern void func_8014CF04(); +extern void func_8014CD80(s32 a0, void *a1, void *a2); +extern s32 func_8014D2A0(s32 a0, void *a1, void *a2); +extern s32 func_8014D12C(s32 a0, void *a1, void *a2); +extern void func_8014D0A4(s32 a0); +extern void func_8014D610(s32 a0, void *a1, void *a2); +extern s32 func_8014D4C0(s32 a0, void *a1, void *a2); +extern void func_8014D438(s32 a0); +extern s32 func_8014DD8C(s32 a0, void *a1, void *a2); +extern s32 func_8014D820(s32 a0, u16 *a1, u16 *a2); +extern void func_8014D790(s32 a0); +extern s32 func_8014DCE0(s32 arg0, s32 arg1, s32 arg2); +extern s32 func_8014DD8C(s32 arg0, void *arg1, void *arg2); +extern s32 func_8014E284(s32 a0, s16 *a1, s16 *a2); +extern s32 func_8014E048(s32 a0, u16 *a1, u16 *a2); /* u16*: def lhu semantics (T5b reconcile; ptr param type codegen-neutral for the caller) */ +extern void func_8014DF94(s32 arg0); +extern s32 func_80135A4C(s32 a0, s32 a1, s32 *a2, s32 a3); +extern u8 D_801152A8[]; /* canonical TU type (engine_core) — read via *(u16*) cast */ +extern s32 func_8014E048(s32 param_1, u16 * param_2, u16 * param_3); +extern s32 func_80135A4C(s32 a0, s32 a1, s32 *a2, s32 a3); /* canonical (engine_core.h:11555) */ +extern s32 func_8014E284(s32 a0, s16 *arg1, s16 *arg2); +extern void func_8014E5B4(s32 a0, void *a1, void *a2); +extern s32 func_8014E514(u8 *a0, s32 a1, s32 a2); +extern void func_8014E48C(s32 a0); +extern s32 func_8014E83C(s32 a0, s16 *a1, s16 *a2); +extern s32 func_8014E790(s32 a0, s16 *a1, s16 *a2); +extern void func_8014E6F8(struct SubE6F8 *a0); +extern s32 func_8014E790(s32 arg0, s16 * arg1, s16 * arg2); +extern s32 func_8014E83C(s32 arg0, s16 * arg1, s16 * arg2); +extern s32 func_8014EA4C(void *a0, void *a1, void *a2, s32 a3); +extern s32 func_8014E98C(void *a0); +extern u16 D_800B99DA; +extern s32 D_801150D8; +extern s16 D_80126724; +extern s32 func_8014EA4C(void * a0, void * a1, void * a2, s32 _arg3); +extern s32 func_8014EE14(s32 a0, s16 *a1, s16 *a2); +extern s32 func_8014ED80(struct SubED80 *a0); +extern s32 func_8014EE14(s32 arg0, s16 * arg1, s16 * arg2); +extern s32 func_8014F2E0(s32 a0, s16 *a1, s16 *a2); +extern s32 func_8014F24C(struct SubF24C *a0); +extern s32 func_8014F2E0(s32 arg0, s16 * arg1, s16 * arg2); +extern void func_8014F4C0(u8 *a0); +extern s32 func_8014F468(void); +extern s32 D_801152BC; +extern int func_8014F74C(s32 arg0); +extern s32 func_8014FA70(s32 a0); +extern void func_8014FA04(s32 a0); +extern s32 func_8014FC18(u8 *self); +extern int func_8014FD54(int param_1); +extern s32 func_80150170(void *a0); +extern s32 func_8014FE60(void *a0); +extern void func_8014FDF4(struct S8014FDF4 *a0); +extern s32 func_80150150(s32 a, s32 b); +extern s32 func_801502EC(s32 e, void *a1, void *a2); +extern s32 func_80150460(s32 e, s32 a1); +extern s32 func_80150170(void *e); +extern s32 func_80150460(s32 a, s32 b); +extern s32 func_80150528(void *a0, void *a1, void *a2); +extern void func_801504D8(u16 *a0); +extern s32 func_80150528(void *arg0, void *arg1, void *arg2); +extern s32 func_801506A4(s32 a0, s32 a1); +extern s32 func_801505FC(s32 a0); +extern void func_80150820(s32 a0, s32 a1); +extern void func_8015086C(int param_1); +extern s32 func_801508B4(s32 a0); +extern s32 func_8015094C(s32 a0); +extern short func_801508F8(s32 a0); +extern s32 func_80021174(s32 a0, s32 a1); +extern s32 func_8015094C(s32 param_1); +extern void func_80150B28(int param_1); +extern void func_80150B9C(void); +extern s32 func_80151184(s32 a0, s32 a1, s32 a2); +extern s32 func_80150BA4(s32 a0); +extern s32 func_801619D0(void *a0); +extern void func_80150BC8(s32 *a0); +extern s32 func_80150480(s32 a0); +extern u16 D_800AE6DC; +extern void func_80150C48(s32 a0); +extern int func_80151184(int arg, int a1, int a2); +extern int func_80150CA0(int arg); +extern void func_80150EC4(s32 a, s32 b); +extern void func_80150CC4(s32 a); +extern void func_80150CE4(s32 a); +extern void func_80150D04(s32 a); +extern void func_80150D24(s32 a); +extern void func_80150D44(s32 a); +extern void func_80150D64(s32 a); +extern void func_80150D84(s32 a); +extern void func_80150DA4(s32 a); +extern void func_80150DC4(s32 a); +extern void func_80150DE4(s32 a); +extern void func_80150E04(s32 a); +extern void func_80150E24(s32 a); +extern void func_80150E44(s32 a); +extern void func_80150EC4(s32 a0, s32 a1); +extern void func_80150E64(s32 a0); +extern void func_80150E84(s32 a0); +extern void func_80150EA4(s32 a0); +extern u8 D_800AE6C0; +extern s16 D_800AE6C8; +extern s16 D_800AE6CA; +extern s16 D_800AE6CC; +extern s32 D_800AE6C4; +extern s16 D_800AE6CE; +extern u8 D_800AE6BE; +extern u8 D_801201F8[]; +extern void func_80150F78(void); +extern void func_80150F80(s32 a0); +extern int func_80150FB4(int arg); +extern void func_80150FD8(s32 a0); +extern int func_80151014(int arg); +extern void func_80151038(s32 a0); +extern int func_80151070(int arg); +extern int func_80151094(int arg); +extern void func_801510B8(void); +extern void func_801510C0(void); +extern int func_801510C8(int arg); +extern int func_801510EC(int arg); +extern s32 func_80151110(void); +extern void func_80151130(void); +extern int func_80151138(int arg); +extern void func_8015115C(s32 *a0, s16 a1); +extern s32 func_80151164(s32 a0, s32 a1); +extern s32 func_80151184(s32 arg0, s32 arg1, s32 arg2); +extern void func_801511A8(u8 *a0); +extern void func_801511C4(u8 *a0); +extern int func_80151204(int arg, int a1); +extern int func_801511E0(int arg); +extern int func_80151204(int a0, int a1); +extern void func_80151238(void *a0); +extern void func_8015126C(u16 *p); +extern void func_80151780(s32 a0); +extern void func_801516F0(s32 *a0); +extern void func_8015173C(s32 *a0); +extern s16 D_8011DB1A; +extern s32 D_80127518; +extern s32 D_801151FC; +extern s32 func_801725CC(u8 *a0); +extern s32 func_80029D3C(void); +extern void func_80151878(void); +extern void func_80153B58(s32 *a0); +extern s32 func_80151880(s32 a0); +extern s32 func_801518D8(s32 a0); +extern s32 func_80151944(void); +extern s32 func_80151924(void); +extern void func_8014E934(s32 a0); +extern s32 func_8014F3E8(s32 a0); +extern void func_801519C8(s32 a0); +extern void func_80151980(s32 a0); +extern M2C_UNK D_800D5880; +extern s32 D_800D58AC; +extern void func_80154274(s32 *a0, s32 a1); +extern void func_80154A74(s32 a0, s32 a1); +extern void func_801519C8(s32 arg0); +extern void func_80151C54(s32 a0); +extern void func_801542DC(s32 *a0, s32 a1); +extern void func_8015BDD0(s32 *a0); +extern void func_80165718(s32 a0); +extern u8 D_800D46E4[]; +extern void func_80151AE4(s32 arg0); +extern void func_80151D24(void *a0); +extern void func_80151DB0(s32 a0); +extern void func_80151D60(void *a0); +extern s32 func_80172630(u8 *a0); +extern s32 D_80062C14; +extern void func_80151DB0(s32 param_1); +extern void func_80151E78(s32 *a0); +extern void func_80151ECC(struct S80151ECC *a0); +extern void func_80151FB4(s32 a0); +extern void func_80151F38(s32 *a0); +extern void func_801553C0(s32 a0); +extern void func_80153C18(); +extern void func_80152058(void *a0); +extern void func_801520DC(s32 a0); +extern void func_80152094(s32 a0); +extern void func_80147324(s32 a0); +extern void func_801520DC(s32 arg0); +extern void func_801470B4(s32 a0); +extern void func_8015369C(s32 a0); +extern void func_80152194(s32 *a0); +extern s32 func_801536DC(s32 a0); +extern void func_8015220C(s32 a0); +extern s32 func_80153800(s32 a0); +extern void func_801522CC(s32 a0); +extern void func_80152254(s32 *a0); +extern void func_80152370(void *a0); +extern void func_801523F4(s32 a0); +extern void func_801523AC(s32 a0); +extern void func_8001382C(s32 a0, void *a1, void *a2); +extern void func_801523F4(s32 arg0); +extern void func_801525F4(int); +extern s32 func_801535F4(void *arg0); +extern void func_8015BF48(s32 *a0); +extern void func_80152500(int param_1); +extern void func_801525F4(s32 a0); +extern void func_80152698(void *a0); +extern void func_80152714(s32 a0); +extern void func_801526D4(s32 a0); +extern void func_80152790(s32 a0); +extern void func_8015282C(void *a0); +extern void func_801528B0(s32 a0); +extern void func_80152868(s32 a0); +extern void func_801528B0(s32 arg0); +extern void func_8015294C(s32 a0); +extern void func_80152A08(s32 a0); +extern void func_80152AC8(s32 a0); +extern void func_80152A50(s32 *a0); +extern void func_80152B6C(void *a0); +extern void func_80152BF0(s32 a0); +extern void func_80152BA8(s32 a0); +extern void func_80152C80(s32 *a0); +extern void func_80152C40(s32 *a0); +extern void func_80152C80(s32* a0); +extern void func_80152D24(void *a0); +extern void func_80152DA8(s32 a0); +extern void func_80152D60(s32 a0); +extern void func_80152DA8(s32 arg0); +extern void func_80152E4C(s32 a0); +extern void func_80152EFC(s32 a0); +extern void func_80152FBC(s32 a0); +extern void func_80152F44(s32 *a0); +extern void func_80153060(void *a0); +extern void func_801530E4(s32 a0); +extern void func_8015309C(s32 a0); +extern void func_80155440(s32 *a0); +extern u8 D_80062C04[]; +extern void func_801530E4(s32 arg0); +extern void func_80153150(struct S80153150 *a0); +extern void func_801531BC(s32 a0); +extern void func_8015327C(s32 a0); +extern void func_80153204(s32 *a0); +extern void func_80153320(void *a0); +extern void func_801533A4(s32 a0); +extern void func_8015335C(s32 a0); +extern void func_80153410(s32 *a0); +extern void func_80153490(s32 a0); +extern void func_80153550(s32 a0); +extern void func_801534D8(s32 *a0); +extern void (*D_8011DB28)(s32 a0); +extern s32 func_801536DC(s32 param_1); +extern void func_800139C8(s32 a0, void *a1, void *a2); +extern s32 func_80153978(s32 a0, u16 *src); +extern s32 func_80133784(s32 a0, void *src, s32 dst); +extern s32 func_801539F8(s32 a0, void *a1); +extern s32 func_801539F8(s32 a0, void * a1); +extern s32 func_8016DA04(s32 a0); +extern s32 func_80153BD8(s32 a0); +extern s32 func_80153BF0(s32 a0); +extern void func_80153C18(void); +extern u16 D_8011F748; +extern void func_80153C30(void); +extern void func_80153C74(s16 a0, s16 a1); +extern s16 D_8011DB18; +extern void func_80153C44(int a0, int a1, s16 a2); +extern s16 D_8011DB0C; +extern s32 D_80115210; +extern void func_80153C8C(void); +extern void func_80153C9C(void); +extern s32 func_80153CBC(void); +extern void func_80153CCC(S80153CCC *a0); +extern void func_80153D7C(s32 a0); +extern void func_80153D34(s32 a0); +extern void func_80153D7C(s32 param_1); +extern void func_8015410C(void); +extern void func_80153E00(s32 param_1); +extern void func_80151664(void); +extern void func_80154134(u8 *a0); +extern void func_80154190(u8 *a0, s32 a1); +extern void func_80154150(s32 a0, s32 a1); +extern void func_80154218(u8 *a0, s32 a1, s32 a2); +extern void func_801541D8(u8 *a0, s32 a1, s32 a2); +extern s32 func_801549F8(s32 a0, s32 a1, s32 a2); +extern void func_801542A4(); +extern void func_801542A4(s32 *a0, s32 a1); +extern void func_8015430C(); +extern void func_8015430C(u8 *arg0, s32 arg1, s32 arg2); +extern void func_8015444C(void *a0, s32 *a1, s32 *a2, s32 *a3); +extern s32 func_80154358(void * arg0); +extern void func_80154AB4(s32 a0, s32 a1); +extern void func_80154B20(s32 a0, s32 a1, s32 a2); +extern void func_80154AE0(s32 a0, s32 a1, s32 a2); +extern void func_80154B7C(u8 *a0, s32 a1); +extern void func_80154B4C(u8 *a0, s32 a1); +extern void func_80154BC8(void *a0, s32 a1, s32 a2); +extern void func_80154B98(void *a0, s32 a1, s32 a2); +extern void func_80154ED8(s32 a0, s32 a1); +extern void func_80154C24(s32 param_1, s32 *param_2, s32 *param_3); +extern u8 D_800D8D10[]; +extern s16 D_80078E9E; +extern void func_801550FC(s32 a0); +extern void func_80154F9C(s32 a0); +extern void func_801550FC(s32 arg0); +extern void func_8001D150(s32, s32); +extern void func_8001D130(int, int); +extern void func_80155150(int param_1); +extern s32 D_800DE2A4[]; +extern void func_801552F4(s32 a0); +extern void func_80155344(s32 a0); +extern s32 func_80155394(s32 *a0); +extern void func_801553A8(s32 *a0); +extern s32 func_80155458(s32 param_1); +extern s32 func_801659DC(u8 *a0); +extern s32 func_801554B8(void *arg0); +extern void func_801555F4(void *a0); +extern void func_80155518(s32 *a0); +extern void func_80155580(void *a0); +extern s32 func_80161104(void); +extern void func_801555F4(void *); +extern void func_801555BC(void *a0); +extern int func_80155A44(int param_1); +extern int func_80161208(); +extern u8 D_800D4DA8[]; +extern void func_80155B20(s32 *a0); +extern s32 D_800D4DB4; +extern void func_80155B9C(s32 a0); +extern u8 D_800D4DD4[]; +extern void func_80155C0C(s32 *a0); +extern void func_8014ED28(s32 a0); +extern int func_80155FF8(int arg, int a1); +extern s32 D_800D4DF4; +extern void func_80155C64(s32 a0); +extern void func_8015E880(s32 *a0); +extern void func_80155D70(s32 param_1); +extern void func_80155E30(void *a0); +extern s32 func_80161208(); +extern void func_80155EA4(void *arg0); +extern void func_80155F58(void); +extern s32 func_80155F80(); +extern s32 func_80155F60(void); +extern s32 func_80155F80(s32 a0); +extern int func_80155FB0(int arg, int a1); +extern int func_80155FD4(int arg, int a1); +extern int func_80156044(int arg, int a1); +extern S801563EC *func_801563EC(u16 idx); +extern s32 func_80029B4C(s32 a0, s32 a1); +extern s32 func_80029BC8(s32 a0, s32 a1); +extern s32 func_80029C44(s32 a0, s32 a1); +extern s32 func_8015640C(s32 a0, s32 a1); +extern u32 func_8015616C(s32 param_1, u16 param_2); +extern u16 func_80156370(u16 param_1); +extern S801563EC * func_801563EC(u16 idx); +extern s32 func_801564B0(s32 a0); +extern s32 D_801151E0[]; +extern s32 func_801565C0(void); +extern void func_80156A14(s32 *a0); +extern void func_80156648(s32 *a0); +extern u8 D_8011DAD8[]; +extern s32 func_8014C568(void *a0); +extern void func_801567BC(s32 a0); +extern B8 D_80128120[]; +extern B8 D_80128138[]; +extern S8 D_80126AF0[]; +extern u8 D_80126730[]; +extern void func_80156848(s32 param_1, s32 param_2); +extern void func_80156A1C(s32 param_1, s32 param_2); +extern s32 D_801150E0[]; +extern void func_80156A88(s32 a0, s32 a1); +extern void func_80156B74(s32 param_1, u32 param_2, u8 *param_3); +extern void func_80156ECC(int param_1, int param_2, int param_3, int param_4, int param_5); +extern void func_80156FA8(s16 *param_1, s16 *param_2, s16 *param_3); +extern void func_80157158(s32 a0, u16 a1, u16 a2, s32 a3, s32 a4, s32 a5, s32 a6, s32 a7, s32 a8, s32 a9, u16 a10, s32 a11, s32 a12); +extern s32 func_80135004(s32 a0, void *a1, s32 a2); +extern s32 func_80135260(s32 a0, s32 a1, s32 a2, s32 a3); +extern u32 func_801571C4(s32 a0, u16 a1, u16 a2, s32 a3, s32 a4, s32 a5, s32 a6, s32 a7, s32 a8, s32 a9, u16 a10, s32 a11, s32 a12); +extern void func_801575E4(void *a0); +extern void func_801574DC(s32 *a0); +extern void func_80157544(void *a0); +extern void func_8014CC28(s32 a0); /* defined */ +extern s32 func_8014F3E8(s32 a0); /* declared */ +extern void func_8015BDD0(s32 *a0); /* defined */ +extern void func_801575E4(void *a0); /* defined */ +extern void func_80157580(s32 arg0); +extern u8 D_800D4F14[]; +extern void func_801576A8(void *arg0); +extern s32 func_8015773C(u8 *a0); +extern s32 func_8015771C(u8 *a0); +extern s32 func_8015773C(u8 * arg0); +extern void func_801578C0(s32 a0); +extern void func_80157788(int param_1); +extern void func_80157808(s32 a0); +extern void func_801577C8(int param_1); +extern void func_80157880(s32 a0); +extern s32 func_801725A4(u8 *a0); +extern void func_801578C0(s32 param_1); +extern void func_80147A84(int); +extern void func_80148038(int, int); +extern void func_80147460(int); +extern void func_80146D90(int); +extern void func_80161450(void *a0); +extern void func_80157A8C(int); +extern void func_80154A74(int, int); +extern void func_8015795C(int param_1); +extern void func_80161D20(s32 a0, s32 a1); +extern void func_80157A8C(s32 a0); +extern void func_8016706C(s32 a0); +extern u8 D_800D51AC[]; +extern void func_80157AC8(s32 param_1); +extern void func_80157B74(int param_1); +extern void func_8016158C(void *a0); +extern void func_8015BE04(s32 *a0); +extern void func_80157BC8(s32 a0); +extern void func_80157CCC(s32 a0); +extern void func_80157DC4(void *a0); +extern void func_80157FC4(void *a0); +extern void func_80157D74(u16 *a0); +extern void func_80157E38(void *); +extern void func_80157E00(void *a0); +extern void func_80157E38(void * a0); +extern s32 func_80157F64(s32 *a0); +extern s32 func_80156600(void *a0); +extern void func_80157EA4(void *a0); +extern void func_80158038(void *); +extern void func_80158000(void *a0); +extern void func_80158038(void * param); +extern u8 D_800D524C[]; +extern void func_80161418(void *a0); +extern void func_801580B4(s32 a0); +extern void func_801581AC(s32 a0); +extern void func_8015824C(void *a0); +extern void func_801582C0(void *); +extern void func_80158288(void *a0); +extern u8 D_800D52A8[]; +extern void func_801585A4(s32 *a0); +extern void func_801582C0(void *a0); +extern s32 func_801585AC(s32 *a0); +extern u8 D_800D52E8[]; +extern void func_80158344(s32 *a0); +extern s32 func_801615C4(void *a0, s32 a1); +extern void func_80158434(s32 param_1); +extern void func_80158548(s32 param_1); +extern void func_801585EC(u8 *a0); +extern void func_80158794(void); +extern void func_80158880(s32 *param); +extern void func_8015879C(s32 param_1); +extern void func_80158814(void *arg0); +extern int func_800D0CA0(int); +extern int func_8001AAA0(int); +extern int SsGetMute(void); +extern s32 func_80159464(void); +extern void func_801588CC(int param_1); +extern void func_80158AE4(void *a0); +extern void func_80158AB4(void *a0); +extern void func_8016F264(void); +extern void func_80165840(void); +extern void func_801658DC(void); +extern void func_80165A78(s32); +extern void func_80158AE4(void * a0); +extern void func_80158BB0(void *arg0); +extern s32 func_80159404(s32 a0, s32 a1); +extern void func_80158C40(s32 *a0); +extern void func_80158CD8(s32 *a0); +extern s32 func_80159434(s32 a0, s32 a1); +extern void func_80158D60(s32 a0); +extern M2C_UNK D_800D5904; +extern void func_80158E24(s32 *a0); +extern int rand(void); +extern void func_80158F00(int param_1); +extern s32 func_801399F0(s32); +extern void func_80139914(s32); +extern void func_801594E8(s32, s32); +extern void func_80158FA4(s32 param_1); +extern u8 D_80110C94[]; +extern u8 D_80110CD4[]; +extern void func_80159070(void *a0); +extern s32 func_80029A94(s32); +extern void func_80175454(void); +extern void func_800298BC(void *); +extern void func_8002992C(s32); +extern void func_800CF804(void); +extern void func_800CF818(void); +extern u8 D_80110D0C[]; +extern u8 D_80110C3C[]; +extern void func_80159120(s32 a0); +extern void func_801592CC(s32 *a0); +extern void func_8015934C(void *arg0); +extern void func_801593E4(A801593E4 *a0); +extern s32 func_800291B4(s32); +extern void func_80029274(void); +extern void func_80029044(void); +extern void func_8002906C(void); +extern void func_80029094(void); +extern void func_8002941C(void); +extern void func_8002AB64(void); +extern void func_800D185C(u8 *); +extern void func_800D1F90(void); +extern void func_801594E8(s32 param_1, s32 param_2); +extern void func_80159698(void *a0); +extern s32 func_801596D4(void *a0); +extern void func_80174B6C(void); +extern void func_8013C938(void); +extern void func_8002850C(s32, s32, s32); +extern void func_80028620(s32, void *); +extern s32 func_801596F0(s32 param_1); +extern s32 func_80159874(void); +extern void func_800167B8(s32 a0); +extern s32 func_8015987C(s32 a0); +extern int func_800167F0(int arg); +extern int func_801598BC(void); +extern void func_80159968(void *a0); +extern void func_801598E0(u8 *a0); +extern void func_80159A20(void *a0); +extern void func_801599E0(void *a0); +extern void func_80159A18(void); +extern void func_80159BE4(s32); +extern void func_80159B08(s32 *a0); +extern void func_80159B70(void *a0); +extern void func_80159B3C(void * a0); +extern void func_80159BAC(s32 a0); +extern s32 func_80172590(u8 *a0); +extern void func_80159BE4(s32 arg0); +extern void func_8015A1C8(s32 a0); +extern void func_8015A2D8(s32); +extern void func_8015A1FC(s32 *a0); +extern void func_8015A264(void *a0); +extern void func_8015A230(s32 *a0); +extern void func_8015A2A0(s32 a0); +extern s32 func_80172608(u8 *a0); +extern void func_8015A2D8(s32 param_1); +extern u8 D_800D48DC; +extern s32 func_8015AB7C(s32 a0); +extern s32 D_8011F9C4; +extern s32 func_8015ABD4(s32 a0, s32 a1, s32 a2); +extern s32 func_80161CD0(s32 a0, s32 a1); +extern void func_8015AC48(s32 arg0); +extern void func_8015AC90(s32 a0); +extern void func_8015ADB0(s32 a0); +extern void func_8015ACC4(s32 *arg0); +extern void func_8015AD3C(void *a0); +extern void func_8015AD08(void *arg0); +extern void func_8015ADB0(s32); +extern void func_8015AD78(s32 a0); +extern void func_8015ADB0(s32 arg0); +extern s32 D_800D4A9C; +extern int func_8015B6F4(int param_1); +extern u8 D_800D4F8C[]; +extern s32 func_8015B7B4(s32 a0); +extern u8 D_800D4BE0[]; +extern s32 func_8014A51C(); +extern s32 func_8015B858(u8 *a0); +extern s32 D_800D4B48; +extern void func_8015B8F8(s32 *a0); +/* ==== end §8b carried decl layer ==== */ + + +extern s32 func_8015AE2C(); + +// @class: plumbing +// @stuck: none — MATCH (271/271, pin-free, zero asm). The ONLY residual is DEF-SIDE plumbing, and it is now named exactly: the in-TU instantiation `DEFINE_func_8015BEE4()` (engine_core.h:1851-1855) expands to `extern s32 func_8015B950(void);` INSIDE ov_SC01_077_jr_8015AE2C.c, ~14 lines BELOW this definition, so the 1-param def collides with a `(void)` prototype -> `conflicting types for func_8015B950` (.run/bank_func_8015B950.log). §73 PARAMS axis / T0. Surgical fix = §65b de-macroize that ONE instantiation (blast radius: this TU); the fleet-wide `(void)`->`()` header edit is §63 and must be R22-validated. +/* func_8015B950 (ov_SC01_077_jr_8015AE2C, 271 ins, jtbl_801D8B74) — SESSION-21 re-verified + * + * ── ROUND-2 INDEPENDENT RE-VERIFICATION (2026-07-27, fresh agent, §88e discipline) ───────────── + * match_one : MATCH (271 ins) against the CURRENT tree — §87 staleness re-checked today. + * .text size: compiled .text = 0x43C = 1084 B = 271 ins, EXACTLY the target's declared 0x43C + * ("nonmatching func_8015B950, 0x43C"). So this is NOT a §83a length drift hiding + * behind a zero count — the count is over equal-length streams. + * jtbl : RE-DECODED MECHANICALLY, not inherited. Compiled .rodata = 0x1C = 28 B = 7 words, + * 7x R_MIPS_32 -> .text with implicit addends [58,58,58,E0,F0,100,58]; +0x8015B950 + * = [8015B9A8, 8015B9A8, 8015B9A8, 8015BA30, 8015BA40, 8015BA50, 8015B9A8]. + * Diffed word-for-word against asm/ov_SC01_077/data/tail14.data.s:15-23 — 7/7 identical. + * symcheck : SYMS-DIFF target=35 draft=34, sole MISSING = jtbl_801D8B74. This is the §81 jr + * FALSE POSITIVE, re-confirmed here by reading the relocs: gcc emits its OWN table and + * references it with R_MIPS_HI16/LO16 against the SECTION `.rodata` (t.o +0x40/+0x48), + * so the splat's dlabel NAME can never appear in the draft object's relocation set. + * Nothing is dropped and nothing is invented: the draft's other 34 symbols are exactly + * the target's other 34. + * FAMILY : the x138 remap is clean and §84-safe. Every sibling is 271 ins with an IDENTICAL + * callee set; only THREE names vary per overlay — the two data labels and the jtbl: + * ov_SC01_077 D_80180CB0 / D_80180D1C / jtbl_801D8B74 + * ov_SC03_099 D_80185A50 / D_80185ABC / jtbl_801BD898 + * ov_SC06_008 D_80187E44 / D_80187EB0 / jtbl_801A8734 + * The pair is always +0x6C apart, and NO literal in this draft encodes that distance + * (both labels are referenced by name), so there is no §84 derived-offset hazard. + * D_8011F9C4 is fleet-constant (main-EXE data) and must NOT be remapped. + * + * match_one: MATCH (271 ins) against the CURRENT tree (§87 staleness re-checked, 2026-07-27). + * PIN-FREE, zero asm, offset-pure (s32 arg0 + raw offsets) — x138 template-safe. + * Provenance: this is the Phase-26 crack (.run/phase26-cracks/func_8015B950.c) re-gated verbatim, + * with ONE deliberate change: the definition's return type void -> s32. + * - `void func_8015B950(s32 arg0)` : MATCH (271 ins) [the Phase-26 form] + * - `s32 func_8015B950(s32 arg0)` : MATCH (271 ins) [shipped — §3a-1 void->s32 is byte-neutral] + * The fleet/engine_core.h canonical decl is `extern s32 func_8015B950(void);` (engine_core.h:1852), + * and the last bank attempt (.run/bank_func_8015B950.log) died on `conflicting types for + * func_8015B950`. Shipping the s32 return kills the §73 RETURN axis for free and leaves only the + * cheap T0 PARAMS axis for the ladder (fix_header_decl.py / --fix-def-sig / cast_call_sites). + * Both forms are byte-identical, so the orchestrator may swap the return type back at zero cost. + * + * SYMBOLS (§58 rules 1/2 — all splat spellings, all verified present): + * D_80180D1C asm/ov_SC01_077/data/tail.data.s:4355 (the state-handler vtable) + * D_80180CB0 asm/ov_SC01_077/data/tail.data.s:4293 + * D_8011F9C4 main-EXE data; spelled `extern s32 D_8011F9C4;` in 5+ already-banked TUs + * jtbl_801D8B74 asm/ov_SC01_077/data/tail14.data.s:15 (compiler jump table — not named in C) + * + * JTBL VERIFIED (§8a gate): compiled .rodata = exactly 0x1C B / 7 words, 7x R_MIPS_32 .text with + * addends [0x58,0x58,0x58,0xE0,0xF0,0x100,0x58] -> +0x8015B950 = [B9A8,B9A8,B9A8,BA30,BA40,BA50, + * B9A8] == the original words at 0x801D8B74..0x801D8B8C. Bound `sltiu $v0,$v1,0x7` matches. + * The raw dlabel's 8th word 0x00000000 is NOT an entry — it is the intra-TU `.align 3` pad of the + * B34/B54/B74 jtbl chain; the object can never emit it (maspsx drops .align), so it must stay in + * the post-carve RAW data piece (the §53/§62/§81 carve chain applies at bank time). + * + * Same family as the TU's own already-matched func_8015AE2C: 7-case switch on ((s32 (*)(s32))func_801619A4)() + * (0/1/2/6 shared, 3/4/5 own, no default block — out-of-range and every `break` fall to the + * after-switch join), then a chain of "state handler" tests, each dispatching + * D_80180D1C[*(u16*)arg0](arg0) and returning. + * + * THREE LEVERS (draft -> MATCH in 3 compiles): + * + * 1. PROLOGUE CONSTANT = an INITIALIZED LOCAL, not a literal in the compare. + * Target opens with `lui $s2, 0xFFF5` in the *prologue*, used once ~200 ins later in + * `slt $v0,$s2,$s1`. No gcc-2.7.2 pass hoists a (set reg const_int) across basic blocks + * (loop.c needs a loop; cse/combine/sched never move insns between BBs) — so the insn must + * have been EMITTED in the first BB, i.e. the constant is a local initialized at the top of + * the function. cse then cannot fold it back into the compare: the `slt` operand predicate is + * `arith_operand`, which rejects a CONST_INT wider than 16 bits, so validate_change fails and + * the pseudo survives. Its live range spans every call -> global.c gives it a callee-saved reg. + * Writing `z > -0xB0000` inline instead emits the `lui` into the branch delay slot next to the + * compare (caller-saved $v0) and the function is 1 insn short. => `s32 lim = -0xB0000;` at top. + * + * 2. `lh` vs `lhu`: a short->short copy is a pure HImode move and gcc emits `lhu`. The target's + * `lh $v0,0x26($s0)` means the value passed through an SImode (int) temp: expand makes + * (set (reg:SI) (sign_extend (mem:HI))) + (set (mem:HI) (subreg:HI ...)), and combine cannot + * merge them (the merged form is mem<-mem, which no movhi accepts) so the sign-extending load + * survives. => route both halfword copies through the `s32 t` temp. + * + * 3. THE `goto` LAYOUT — dodging jump.c's store-flag conversion (jump.c:1005-1065). + * An if/else chain writing 0/1 into `doit` makes gcc collapse the last pair into + * `sltiu $v0,$v0,1`. jump.c fires that conversion when the insn immediately after a + * conditional jump is a lone `SET pseudo, CONST_INT` whose following simplejump targets the + * SAME label as the branch (jump.c:1038 `reallabelprev == temp || ... JUMP_LABEL(temp4) == + * JUMP_LABEL(insn)`) — exactly the shape of `if (c) x=0; else x=1;`. + * The target instead cross-jumps ALL the `doit=0` exits into ONE shared block placed after the + * `doit=1` fall-through; reorg's fill_slots_from_thread then COPIES that single set into all + * three branch delay slots and redirects each branch past it (which is why `addu $v0,$zero, + * $zero` appears 3x in delay slots and the shared block vanishes). A `goto zero;` / `goto one;` + * chain expresses that layout directly, and each conditional jump is then followed by a + * compare/call rather than a lone const set, so the store-flag conversion never triggers. + * GENERAL RULE: multiple predicates that all assign the SAME constant to one flag => write + * them as `goto` to a shared assignment, never as an if/else ladder. + */ +extern s32 D_8011F9C4; + +extern s32 func_80161B18(void); +extern s32 func_801619A4(s32*); +extern s32 func_80149AA8(s32*); +extern void func_80149AD4(s32*); +extern s32 func_80149B54(s32*); +extern void func_80149BAC(s32*); +extern s32 func_801498E0(s32*); +extern s32 func_80149954(s32); +extern s32 func_80149A64(s32*); +extern void func_800CCCC0(s32 a0); +extern s32 func_80149CD4(s32 a0); +extern void func_8015E880(s32*); +extern s32 func_80149744(struct S_80149744*); +extern void func_80149788(void); +extern s32 func_801496D4(void*); +extern void func_80149704(void); +extern int func_80148AFC(void*); +extern void func_80146D90(s32 a0); +extern void func_80154150(s32 a0, s32 a1); +extern void func_801541D8(u8*, s32, s32); +extern s32 func_801488A8(u8*); +extern void func_80147078(s32*, s16); +extern void func_8015A264(void*); +extern s32 func_80013294(void*, void*); +extern void func_80159B70(void*); +extern s32 func_8016F1AC(void); +extern s32 func_80029178(s32 a0); +extern void func_80146DB8(s32*, s32*); +extern s32 func_80161CD0(s32, s32); +extern s32 func_80161208(s32 a0); +extern s32 func_801725A4(u8*); + +s32 func_8015B950(s32 arg0) +{ + + extern void (*D_80180D1C[])(void *); + extern s32 D_80180CB0; + s16 sp10[4]; + s16 sp18[4]; + s32 t; + s32 z; + s32 doit; + s32 lim = -0xB0000; + + if (func_80161B18() != 0) { + return; + } + switch (((s32 (*)(s32))func_801619A4)(arg0)) { + case 0: + case 1: + case 2: + case 6: + if (((s32 (*)(s32))func_80149AA8)(arg0) != 0) { + D_80180D1C[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149AD4)(arg0); + return; + } + if (((s32 (*)(s32))func_80149B54)(arg0) != 0) { + D_80180D1C[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149BAC)(arg0); + return; + } + break; + case 3: + ((void (*)(s32))func_801498E0)(arg0); + break; + case 4: + ((void (*)(s32))func_80149954)(arg0); + break; + case 5: + if (((s32 (*)(s32))func_80149A64)(arg0) != 0) { + D_80180D1C[*(u16 *)arg0]((void *)arg0); + func_800CCCC0(arg0); + return; + } + break; + } + if (func_80149CD4(arg0) != 0) { + D_80180D1C[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_8015E880)(arg0); + return; + } + if (((s32 (*)(s32))func_80149744)(arg0) != 0) { + D_80180D1C[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149788)(arg0); + return; + } + if (((s32 (*)(s32))func_801496D4)(arg0) != 0) { + D_80180D1C[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32))func_80149704)(arg0); + if (((u8)((s32 (*)(s32))func_80148AFC)(arg0)) == 0) { + func_80146D90(arg0); + } + if ((*(s32 *)(arg0 + 0x24) | *(s32 *)(arg0 + 0x2C)) != 0) { + func_80154150(arg0, 0xF); + } else { + ((void (*)(s32, s32, s32))func_801541D8)(arg0, 0xD, 6); + } + *(s32 *)(arg0 + 0x238) = 1; + return; + } + if (((s32 (*)(s32))func_801488A8)(arg0) != 0) { + sp10[0] = 0; + sp10[1] = 0; + sp10[2] = 0; + t = *(s16 *)(arg0 + 0x26); + sp18[0] = t; + sp18[1] = 0; + t = *(s16 *)(arg0 + 0x2E); + sp18[2] = t; + D_80180D1C[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 1); + ((void (*)(s32))func_8015A264)(arg0); + t = -(((s32 (*)(s16 *, s16 *))func_80013294)(sp10, sp18) << 0x10); + if (t < *(s32 *)(arg0 + 0x2C)) { + *(s32 *)(arg0 + 0x2C) = t; + } + return; + } + if (*(u16 *)(arg0 + 0xB8) == 0x8000) { + D_80180D1C[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 0); + ((void (*)(s32))func_80159B70)(arg0); + return; + } + z = *(s32 *)(arg0 + 0x2C); + if (func_8016F1AC() != 0) { + goto zero; + } + if (z <= lim) { + goto one; + } + if (D_8011F9C4 == 0) { + goto zero; + } + if (((u8)func_80029178(0x21)) != 0) { + goto zero; + } +one: + doit = 1; + goto join; +zero: + doit = 0; +join: + if (doit != 0) { + D_80180D1C[*(u16 *)arg0]((void *)arg0); + ((void (*)(s32, s32))func_80147078)(arg0, 0); + ((void (*)(s32))func_80159B70)(arg0); + func_80154150(arg0, 9); + ((void (*)(s32, s32 *))func_80146DB8)(arg0, &D_80180CB0); + ((void (*)(s32, s32))func_80161CD0)(arg0, *(u16 *)(arg0 + 0x16E)); + return; + } + if (func_80161208(arg0) == 0) { + ((void (*)(s32))func_801725A4)(arg0); + } +} + +DEFINE_func_8015BD8C() /* dedup: shared engine-core @0x8015bd8c (src/shared) */ + + +DEFINE_func_8015BDD0() /* dedup: shared engine-core @0x8015bdd0 (src/shared) */ + + +DEFINE_func_8015BE04() /* dedup: shared engine-core @0x8015be04 (src/shared) */ + + + + +void func_8015BE38(struct Obj *a0) { + + extern void (*D_80180E90[])(void); + D_80180E90[*(u16 *)((s32)a0 + 0x2)](); +} + + +DEFINE_func_8015BE74() /* dedup: shared engine-core @0x8015be74 (src/shared) */ + + +DEFINE_func_8015BE94() /* dedup: shared engine-core @0x8015be94 (src/shared) */ + + +DEFINE_func_8015BEC4() /* dedup: shared engine-core @0x8015bec4 (src/shared) */ + + +DEFINE_func_8015BEE4() /* dedup: shared engine-core @0x8015bee4 (src/shared) */ + + +DEFINE_func_8015BF04() /* dedup: shared engine-core @0x8015bf04 (src/shared) */ + + +DEFINE_func_8015BF48() /* dedup: shared engine-core @0x8015bf48 (src/shared) */ + + +DEFINE_func_8015BF7C() /* dedup: shared engine-core @0x8015bf7c (src/shared) */ + + +DEFINE_func_8015BFB0() /* dedup: shared engine-core @0x8015bfb0 (src/shared) */ + + + + +void func_8015BFF4(void *a0) { + + extern void (*D_80180E9C[])(void); + D_80180E9C[*(u16 *)((s32)a0 + 0x2)](); +} + + +INCLUDE_ASM("asm/ov_SC07_011/nonmatchings/ov_SC07_011_jr_8015B950", func_8015C030); + +DEFINE_func_8015C08C() /* dedup: shared engine-core @0x8015c08c (src/shared) */ + + +DEFINE_func_8015C0C4() /* dedup: shared engine-core @0x8015c0c4 (src/shared) */ + + +extern void func_8001382C(s32 a0, void *a1, void *a2); +extern void func_80146CA0(void *a0); +extern void func_80146DB8(s32 *a0, s32 *a1); +extern void func_80146E90(s32 *a0, s32 a1); +extern s32 func_80146E98(s32 a0); +extern void func_80147078(s32 *a0, s16 a1); +extern void func_80147324(s32 a0); +extern void func_801473EC(s32 *a0); +extern void func_80147A84(s32 arg0); +extern int func_80148AFC(void *a0); +extern s32 func_80149FB0(s32 a0); +extern void func_8014C010(s32 a0, s32 a1); +extern void func_8014CC28(s32 a0); +extern void func_8014D738(void); +extern s32 func_8014F3E8(s32 a0); +extern s32 func_8015BE94(); +extern void func_8015C0C4(s32 a0); + + + +s32 func_8015C128(s32 param_1) { + + extern u16 D_800B99DA; + extern void func_8015C6E0(int); + extern void (*D_80180D1C[])(int); + + int sp10[3]; + int sp20[3]; + int temp_s0; + int temp_v0; + + ((void(*)())func_80149FB0)(); + if (((int(*)(int))func_80148AFC)(((int)param_1)) & 0xFF) { + sp10[0] = 0; + sp10[1] = 0; + sp10[2] = -0x4000; + ((void(*)(int, int *, int *))func_8001382C)(*(short *)(*(int *)(((int)param_1) + 0x20) + 0x12), sp10, sp20); + *(int *)(((int)param_1) + 0x234) += sp20[0]; + *(int *)(((int)param_1) + 0x238) += sp20[1]; + *(int *)(((int)param_1) + 0x23C) += sp20[2]; + } + ((void(*)(int, int *, int *))func_8001382C)((short)(-*(unsigned short *)(*(int *)(((int)param_1) + 0x20) + 0x12)), + (int *)(((int)param_1) + 0x234), sp20); + ((void(*)(int, int *))func_80146DB8)(((int)param_1), sp20); + func_80147A84(((int)param_1)); + ((void(*)(int))func_801473EC)(((int)param_1)); + if (!(D_800B99DA & 3)) { + ((void(*)(int, int))func_8014C010)(((int)param_1), 1); + ((void(*)(int))func_80147324)(0x65F); + } + if (((int(*)(int))func_8014D738)(((int)param_1)) != 0) { + D_80180D1C[*(u16 *)((int)param_1)](((int)param_1)); + func_8015C6E0(((int)param_1)); + return; + } + temp_s0 = ((int(*)(int))func_8014CC28)(((int)param_1)); + temp_v0 = ((int(*)(int))func_8014F3E8)(((int)param_1)); + if (temp_v0 != 0) { + if ((temp_v0 & 0xFF00) != 0x4000) { + ((void(*)(int, int))func_80146E90)(((int)param_1), 6); + ((void(*)(int))func_80146CA0)(((int)param_1)); + return; + } + if ((temp_v0 & 0x4000) && ((int(*)(int))func_80146E98)(((int)param_1)) != 0) { + ((void(*)(int, int))func_80147078)(((int)param_1), 4); + ((void(*)(int))func_8015C0C4)(((int)param_1)); + } + } else if (temp_s0 == 0) { + D_80180D1C[*(u16 *)((int)param_1)](((int)param_1)); + ((void(*)(int, int))func_80147078)(((int)param_1), 3); + ((void(*)(int))func_8015BE94)(((int)param_1)); + } +} + + +