mirror of
https://github.com/Druthulu/BFM-decomp
synced 2026-09-28 23:00:29 -04:00
docs(cookbook): 260-262 — the island split, the -O0 oracle, and size-matched lane yield
260 the 154-A leading-island split: one inserted .rodata line + jr_isolate_all --only,
the object-level sh_size control that separates 'it worked' from 'it did nothing',
the island-is-a-stack census, and the two md_*-only tool blindnesses it exposed.
261 the -O0 oracle: derive the opt level from the target (prologue tell + subseg flags),
311 $fp mentions vs 167 real -O0 prologues, and why a match is not a bank for the
116 functions stranded in -O2 subsegs.
262 a lane's yield is only a lane fact if it is size-matched — the band and size-mix
confounds that produced 'the tells lane is broken', with the bucket table.
This commit is contained in:
+234
-16
@@ -2,7 +2,7 @@
|
||||
|
||||
> **Generated by `tools/cookbook_index.py` — do not hand-edit** (R33). Regenerate after adding a cookbook section.
|
||||
>
|
||||
> `docs/matching-cookbook.md` is ~716 KB / 651 sections. Grepping it blind is how three P30 wave-1 agents each "discovered" an idiom that was already written down. **Start here, then read the section.** A section appears under every symptom it addresses.
|
||||
> `docs/matching-cookbook.md` is ~716 KB / 746 sections. Grepping it blind is how three P30 wave-1 agents each "discovered" an idiom that was already written down. **Start here, then read the section.** A section appears under every symptom it addresses.
|
||||
|
||||
**How to use:** name what you SEE in the diff (a stolen delay slot, an extra `la`, a swapped register pair, a `conflicting types` error), find that symptom below, read those sections first. If nothing fits, THEN grind — and add a section when you win.
|
||||
|
||||
@@ -34,7 +34,7 @@
|
||||
## By symptom
|
||||
|
||||
|
||||
### delay slots & branches (21)
|
||||
### delay slots & branches (30)
|
||||
|
||||
- **§3-T4** — Branch polarity: invert the source condition to flip gcc's chosen branch <sub>L90</sub>
|
||||
- **§5a** — Cross-jump tail-merge — gcc collapses two byte-identical blocks the original kept separate (FIX FOUND) <sub>L211</sub>
|
||||
@@ -57,8 +57,17 @@
|
||||
- **§199-F** — §164-36b — THE TARGET-HEAD FENCE IS A DELAY-SLOT THREAD SELECTOR, AND IT ONLY FIRES WHEN `mostly_true_jump > 0` (amendment to §164-36; its "−1 instruction" tell is falsified) <sub>L20942</sub>
|
||||
- **§199-G** — At TWO case nodes the switch-vs-if oracle is not blind — but the tell is ALL tests positive + a trailing `j default`, NOT the first test's polarity <sub>L20996</sub>
|
||||
- **§201-C** — §X — A CALL'S OWN DELAY SLOT AND THE UPSTREAM CONDITIONAL BRANCH'S SLOT COMPETE FOR ONE INSN (the call's argument copy), AND ONE STATEMENT'S POSITION RELATIVE TO THE CALL DECIDES BOTH — the residual is visible at the BRANCH, not at the call <sub>L21233</sub>
|
||||
- **§204-A** — A COMPARE THAT APPEARS BOTH IN A BRANCH'S DELAY SLOT AND AGAIN ON THE FALL-THROUGH IS A JOIN WITH TWO INCOMING EDGES: THE TWO GUARDS ARE SEQUENTIAL `if`s, NEVER `if/else if` <sub>L21529</sub>
|
||||
- **§211** — HOIST THE LOOP INIT ABOVE THE DOMINATING GUARD: it fills the guard's delay slot AND flips the counter/pointer register pair (P31 S58) <sub>L22337</sub>
|
||||
- **§221** — A CONSTANT SHARED BY TWO STORES DIES AT THE CALL WHOSE DELAY SLOT REFILLS ITS REGISTER **(single observation — not yet cross-confirmed)** (P31 S58) <sub>L22724</sub>
|
||||
- **§223** — READING A `jal` DELAY SLOT: the value in it was produced BEFORE the call, so it is NEVER that call's return (P31 S58) <sub>L22782</sub>
|
||||
- **§224** — CROSS-JUMP: WRITE THE DUPLICATE, AND READ A SHARED DELAY SLOT AS THE MERGE SIGNATURE (P31 S58) <sub>L22844</sub>
|
||||
- **§232** — WHEN THE `jr` DELAY SLOT'S STORE STORES THE RETURN VALUE, TIE THEM WITH ONE PSEUDO **(single observation — not yet cross-confirmed)** (P31 S58) <sub>L23126</sub>
|
||||
- **§243** — SPELL THE CSE BARRIER AS A REASSIGNED POINTER; AND THE `nop`-AFTER-EVERY-`lh` SIGNATURE (P31 S58b) <sub>L23626</sub>
|
||||
- **§247** — TWO BRANCHES TO **ONE** LABEL MEANS THE SOURCE CONDITION IS NEGATED (P31 S58b) <sub>L23778</sub>
|
||||
- **§224** — addendum (P31 S58b) — CROSS-JUMP MERGES *CALLS*, AND THE DELAY SLOT IS THE DISCRIMINATOR <sub>L24465</sub>
|
||||
|
||||
### instruction scheduling (36)
|
||||
### instruction scheduling (45)
|
||||
|
||||
- **§3-T2** — Source statement order drives instruction scheduling <sub>L78</sub>
|
||||
- **§3** — When a diff is pure scheduling → decomp-permuter (harness built, Phase 6) <sub>L107</sub>
|
||||
@@ -96,8 +105,17 @@
|
||||
- **§195-D** — §195 — `masked_diff.mask_for` returns 0 for EVERY `j`/`jal` word, so an internal `j` destination is invisible to match_one, the permuter scorer AND every similarity tier: a control-flow semantic error (which calls execute) surfaces as a 1-instruction residual mislabelled `DELAY-SLOT / profile=schedule`, or as an outright false MATCH <sub>L19852</sub>
|
||||
- **§199-A** — §189-A's asm→source inference is byte-FALSE: an interloper between a split constant's `lui`/`ori` is a SCHEDULE fact, not a source fact — and the separator is the BIRTHING BOOST, not a "priority floor" (§189-A's split-timing half survives; its "no statement order / no pin" absolute and the candidate's own forward-scheduler narrative both fall) <sub>L20681</sub>
|
||||
- **§199-F** — §164-36b — THE TARGET-HEAD FENCE IS A DELAY-SLOT THREAD SELECTOR, AND IT ONLY FIRES WHEN `mostly_true_jump > 0` (amendment to §164-36; its "−1 instruction" tell is falsified) <sub>L20942</sub>
|
||||
- **§205** — THE CHAINED ASSIGNMENT IS ITS OWN SCHEDULING DIAL: `*b = *a = v;` moves an argument copy that no local, no pin and no statement reorder will move (P31 S56) <sub>L22020</sub>
|
||||
- **§211** — HOIST THE LOOP INIT ABOVE THE DOMINATING GUARD: it fills the guard's delay slot AND flips the counter/pointer register pair (P31 S58) <sub>L22337</sub>
|
||||
- **§219** — COMPOUND `+=`, FULL ASSIGNMENT, AND AN EXPLICIT TEMP ARE THREE DIFFERENT SCHEDULES OF ONE READ-MODIFY-WRITE (P31 S58) <sub>L22663</sub>
|
||||
- **§30** — addendum (P31 S58) — the `/s` grant closes a SCHEDULING residual and a REGISTER residual with one edit <sub>L23162</sub>
|
||||
- **§165-40** — addendum (P31 S58) — the barrier goes at the COPY SITE, not inside the region it protects <sub>L23194</sub>
|
||||
- **§239** — TWO-STATEMENT INTEGER-SPACE MATERIALISATION REORDERS `la` vs `sll`; AND THE PLUS-TREE OPERAND ORDER (P31 S58b) <sub>L23506</sub>
|
||||
- **§243** — SPELL THE CSE BARRIER AS A REASSIGNED POINTER; AND THE `nop`-AFTER-EVERY-`lh` SIGNATURE (P31 S58b) <sub>L23626</sub>
|
||||
- **§245** — THE CALL'S ARGUMENT LIST IS A SCHEDULING SLOT (P31 S58b) <sub>L23691</sub>
|
||||
- **§211** — addendum (P31 S58b) — INIT PLACEMENT: FIVE MORE DIALS BEYOND THE GUARD HOIST <sub>L24221</sub>
|
||||
|
||||
### register allocation & pins (68)
|
||||
### register allocation & pins (81)
|
||||
|
||||
- **§10** — Closing the regalloc/scheduling hard tail by hand (LZSS, Phase 7 session F — the full close) <sub>L835</sub>
|
||||
- **Residual** — A — commutative `|`/`&`/`+` result lands in the wrong source-operand register <sub>L856</sub>
|
||||
@@ -167,8 +185,21 @@
|
||||
- **§199-A** — §189-A's asm→source inference is byte-FALSE: an interloper between a split constant's `lui`/`ori` is a SCHEDULE fact, not a source fact — and the separator is the BIRTHING BOOST, not a "priority floor" (§189-A's split-timing half survives; its "no statement order / no pin" absolute and the candidate's own forward-scheduler narrative both fall) <sub>L20681</sub>
|
||||
- **§199-B** — A permutation sweep that holds ANY statement fixed is not a sweep: the statement an agent pins as "obviously load-bearing" is the one carrying the signal, and the partial sweep returns a FLAT residual that reads as proof of order-invariance <sub>L20730</sub>
|
||||
- **§199-E** — §189-A BOUNDED AND CORRECTED — the discriminator is INSN_PRIORITY, not "is the interloper a constant": an insn between a `lui`/`ori` pair proves NOTHING about the source spelling unless it TIES the `ori` on priority, and on the pinned `-mcpu=3000` triple a dependent load never does <sub>L20883</sub>
|
||||
- **§205** — THE CHAINED ASSIGNMENT IS ITS OWN SCHEDULING DIAL: `*b = *a = v;` moves an argument copy that no local, no pin and no statement reorder will move (P31 S56) <sub>L22020</sub>
|
||||
- **§208** — TWO NAMED LOCALS FOR ONE RELOADED EXPRESSION BUY TWO ALLOCNOS — the naming granularity owns the REGISTER SPLIT, not just the load count (P31 S58) <sub>L22165</sub>
|
||||
- **§211** — HOIST THE LOOP INIT ABOVE THE DOMINATING GUARD: it fills the guard's delay slot AND flips the counter/pointer register pair (P31 S58) <sub>L22337</sub>
|
||||
- **§215** — PIN ECONOMY: the twin's pins are NOT part of the shape, and §17's "pin every call-crossing value" is over-broad (P31 S58) <sub>L22512</sub>
|
||||
- **§220** — THE PARAMETER ITSELF IS A REGALLOC DIAL: use it directly, prefer `s32` to `void*`, and place the save-copy AFTER the first call (P31 S58) <sub>L22690</sub>
|
||||
- **§221** — A CONSTANT SHARED BY TWO STORES DIES AT THE CALL WHOSE DELAY SLOT REFILLS ITS REGISTER **(single observation — not yet cross-confirmed)** (P31 S58) <sub>L22724</sub>
|
||||
- **§30** — addendum (P31 S58) — the `/s` grant closes a SCHEDULING residual and a REGISTER residual with one edit <sub>L23162</sub>
|
||||
- **§244** — `volatile` IS A COUNTING INSTRUMENT, A STORE-ORDER PIN, AND MUST SOMETIMES BE ASYMMETRIC (P31 S58b) <sub>L23656</sub>
|
||||
- **§248** — SPLIT THE LOAD FROM THE ARITHMETIC: A FUSED `g + K` DENIES THE CALLEE-SAVED REGISTER ITS DIRECT HOME (P31 S58b) <sub>L23812</sub>
|
||||
- **§253** — POSTFIX `++` vs `+= 1` PICKS A DIFFERENT SCRATCH REGISTER **(single observation — not yet cross-confirmed)** (P31 S58b) <sub>L23958</sub>
|
||||
- **§254** — THE DEAD PARAMETER IS A REGISTER-PLACEMENT TOOL **(single observation — not yet cross-confirmed)** (P31 S58b) <sub>L23972</sub>
|
||||
- **§215** — addendum (P31 S58b) — PIN ECONOMY, PART 2: NINE REFINEMENTS <sub>L24329</sub>
|
||||
- **§223** — addendum (P31 S58b) — FIVE MORE CONFIRMATIONS, AND THE CONSTANT-IN-`$v0` CASE <sub>L24441</sub>
|
||||
|
||||
### CSE / redundancy / rematerialization (17)
|
||||
### CSE / redundancy / rematerialization (20)
|
||||
|
||||
- **§46** — The `func_80178D40` crack (890 ins ×134, the heaviest core in the game): four LOOP-STRUCTURE levers cheap-Opus found by reading loop.c/jump.c/cse.c (Phase 26 session 8, 2026-07-13) <sub>L3313</sub>
|
||||
- **§83d** — CSE's quantity budget is WHOLE-FUNCTION, so a local rewrite cannot fix a local symptom <sub>L6452</sub>
|
||||
@@ -187,8 +218,11 @@
|
||||
- **§197-B** — A REPEATED COMPARE OF ONE VALUE AGAINST ONE CONSTANT IS DELETED BY cse's `qty_comparison_code` CHANNEL (the non-EQ complement of §165-03) — and a front-end-opaque mask on EITHER compare is a pure-C dial that keeps the target's second branch <sub>L20582</sub>
|
||||
- **§199-D** — A narrow UNSIGNED value compared in an ordered `if` emits `sltiu`/`sltu`; the only dial is the WIDTH of a real object, and a widening `(s32)` cast is inert — AMENDS §35 (whose stated "only CSE-reuse canonicalizes" mechanism is byte-wrong) and does NOT apply inside a `switch` <sub>L20823</sub>
|
||||
- **§201-E** — §194-J-2 — The `last_mem_set` deletion window is measured in SOURCE/expand order, not in the printed stream; a foreign store moved between the pair in C source is a real lever, and `volatile` is not always the better one <sub>L21331</sub>
|
||||
- **§204-D** — A LOOP-INVARIANT LOAD IS ADMITTED AS A MOVABLE ONLY IF ITS ADDRESS CANNOT TRAP: `local.field` PASSES, THE SAME READ THROUGH A POINTER LOCAL IS REFUSED <sub>L21726</sub>
|
||||
- **§243** — SPELL THE CSE BARRIER AS A REASSIGNED POINTER; AND THE `nop`-AFTER-EVERY-`lh` SIGNATURE (P31 S58b) <sub>L23626</sub>
|
||||
- **§244** — `volatile` IS A COUNTING INSTRUMENT, A STORE-ORDER PIN, AND MUST SOMETIMES BE ASYMMETRIC (P31 S58b) <sub>L23656</sub>
|
||||
|
||||
### loops & induction variables (14)
|
||||
### loops & induction variables (18)
|
||||
|
||||
- **§3-T1** — Loop pointer: top-of-body for `addu` induction, not constant-folded `addiu` <sub>L71</sub>
|
||||
- **§34** — The `func_80138ED0` giant crack: gcc-2.7.2's **3-qty sort bug** + the **zero-byte asm allocation toolkit** + the **giv-init fence** (Phase 24 T5; Opus→close=21, Fable5→MATCH ×134) <sub>L2454</sub>
|
||||
@@ -204,8 +238,12 @@
|
||||
- **§179-E** — A `>2*MAX_MOVE_BYTES` BLOCK COPY IS A **STRUCT ASSIGNMENT**, NOT A HAND LOOP <sub>L17483</sub>
|
||||
- **§179-F** — PINNING A LOOP-WALKED POINTER IS A TOTAL OFF-SWITCH FOR STRENGTH REDUCTION <sub>L17509</sub>
|
||||
- **§194-C** — A CALLER-SAVED loop counter proves its live range crosses ZERO calls — so it cannot share a pseudo with any value LIVE ACROSS a call (but it may freely share one with values that merely sit between calls) <sub>L19025</sub>
|
||||
- **§204-B** — A LOOP COUNT THAT ARRIVES ON THE STACK IS DECREMENTED IN PLACE: a fresh counter local can cost a real `move` AND permute the whole callee-saved file <sub>L21604</sub>
|
||||
- **§204-D** — A LOOP-INVARIANT LOAD IS ADMITTED AS A MOVABLE ONLY IF ITS ADDRESS CANNOT TRAP: `local.field` PASSES, THE SAME READ THROUGH A POINTER LOCAL IS REFUSED <sub>L21726</sub>
|
||||
- **§211** — HOIST THE LOOP INIT ABOVE THE DOMINATING GUARD: it fills the guard's delay slot AND flips the counter/pointer register pair (P31 S58) <sub>L22337</sub>
|
||||
- **§246** — THREE-LIVE-VALUE SCAN LOOPS WANT ADDRESS-FROM-INDEX; AND TWO SYMBOLS CAN SHARE ONE giv (P31 S58b) <sub>L23738</sub>
|
||||
|
||||
### structs, block moves & memcpy (51)
|
||||
### structs, block moves & memcpy (56)
|
||||
|
||||
- **§3-T2** — Source statement order drives instruction scheduling <sub>L78</sub>
|
||||
- **§5** — Known hard-residual classes (instruction-identical, one byte-exact blocker) <sub>L199</sub>
|
||||
@@ -258,8 +296,13 @@
|
||||
- **§195-K** — At -O2 the §18 array-of-struct lever is a FRAME lever, not a length lever — but only when the N reads carry DISTINCT index expressions; with a SHARED index §18's +2-instruction residual is still alive at -O2 (the submitted "memory-loaded narrow index" precondition and unconditional length-neutrality are both falsified) <sub>L20234</sub>
|
||||
- **§199-D** — A narrow UNSIGNED value compared in an ordered `if` emits `sltiu`/`sltu`; the only dial is the WIDTH of a real object, and a widening `(s32)` cast is inert — AMENDS §35 (whose stated "only CSE-reuse canonicalizes" mechanism is byte-wrong) and does NOT apply inside a `switch` <sub>L20823</sub>
|
||||
- **§199-F** — §164-36b — THE TARGET-HEAD FENCE IS A DELAY-SLOT THREAD SELECTOR, AND IT ONLY FIRES WHEN `mostly_true_jump > 0` (amendment to §164-36; its "−1 instruction" tell is falsified) <sub>L20942</sub>
|
||||
- **§204-D** — A LOOP-INVARIANT LOAD IS ADMITTED AS A MOVABLE ONLY IF ITS ADDRESS CANNOT TRAP: `local.field` PASSES, THE SAME READ THROUGH A POINTER LOCAL IS REFUSED <sub>L21726</sub>
|
||||
- **§225** — THREE CONTROL-FLOW SHAPES NO STRUCTURED SPELLING REACHES (P31 S58) <sub>L22880</sub>
|
||||
- **§30** — addendum (P31 S58) — the `/s` grant closes a SCHEDULING residual and a REGISTER residual with one edit <sub>L23162</sub>
|
||||
- **§249** — THE SELF-ASSIGN, THE DEAD RE-ASSIGN, AND THE `+ zr` COPY: THREE WAYS TO MAKE A DELETED INSTRUCTION REAL (P31 S58b) <sub>L23836</sub>
|
||||
- **§30** — addendum (P31 S58b) — THE ANONYMOUS STRUCT MEMBER REF GRANTS `/s`, AND THAT IS A TWO-FOR-ONE <sub>L24104</sub>
|
||||
|
||||
### types, signedness & load/store width (49)
|
||||
### types, signedness & load/store width (59)
|
||||
|
||||
- **§3-I1** — Unsigned range check: `(x - lo) < (hi-lo)` → `addiu`+`sltiu` <sub>L41</sub>
|
||||
- **§3-I2** — Byte mask forces `andi` even after `lbu` <sub>L47</sub>
|
||||
@@ -310,8 +353,18 @@
|
||||
- **§197-A** — A NARROW SIGNED MEMORY READ FEEDING A CONSTANT `>>` LOSES ITS `lh`, AND THE CURE IS AN ASM RE-TIE (attribution CONTESTED: cse vs combine) <sub>L20544</sub>
|
||||
- **§199-D** — A narrow UNSIGNED value compared in an ordered `if` emits `sltiu`/`sltu`; the only dial is the WIDTH of a real object, and a widening `(s32)` cast is inert — AMENDS §35 (whose stated "only CSE-reuse canonicalizes" mechanism is byte-wrong) and does NOT apply inside a `switch` <sub>L20823</sub>
|
||||
- **§201-D** — THE SIGNEDNESS OF A div/mod MAGIC IS DECIDED BY THE STATIC TYPE OF THE DIVIDEND TREE AFTER `get_narrower` STRIPS WIDENING CONVERSIONS — NEVER BY A PROVABLE RANGE. AN `& 0xFF` IS NOT A CONVERSION, SO IT NEVER FLIPS THE MAGIC; A DECLARED-UNSIGNED LOCAL *OR* A NARROWING CAST WRITTEN AT THE DIVIDE BOTH DO. <sub>L21284</sub>
|
||||
- **§203** — A DEDUPED TYPEDEF MUST PRECEDE EVERY SPLICE POINT, NOT JUST ITS OWN (P31 S56) <sub>L21449</sub>
|
||||
- **§204-E** — `decl_prior`'s `%hi/%lo` ARM HAS NEVER FIRED: the card's promised GLOBAL-TYPE row is 0 of 1,210 <sub>L21801</sub>
|
||||
- **§218** — A NARROW TYPE AT THE ABI BOUNDARY COSTS AN IN-PLACE `sll/sra` PAIR — on the RETURN as well as on the PARAMETER (P31 S58) <sub>L22634</sub>
|
||||
- **§220** — THE PARAMETER ITSELF IS A REGALLOC DIAL: use it directly, prefer `s32` to `void*`, and place the save-copy AFTER the first call (P31 S58) <sub>L22690</sub>
|
||||
- **§227** — TYPE THE SOURCE BY THE **LOAD** WIDTH, NOT BY THE STORE WIDTH (P31 S58) <sub>L22964</sub>
|
||||
- **§234** — CONSTANT MATERIALISATION: THE STORE LVALUE'S SIGNEDNESS PICKS `addiu` vs `li`/`ori` (P31 S58b) <sub>L23262</sub>
|
||||
- **§237** — THE CAST-AT-CALL-SITE DECISION TABLE: WHAT §17a-1 FIXES, WHAT IT CANNOT, AND THE FOUR ESCAPES (P31 S58b) <sub>L23411</sub>
|
||||
- **§242** — `*k` vs `<<n`, AND `/2^n` vs `>>n`: EXPRESSION SPELLING OWNS THE LOAD WIDTH AND THE ROUNDING CHAIN (P31 S58b) <sub>L23598</sub>
|
||||
- **§243** — SPELL THE CSE BARRIER AS A REASSIGNED POINTER; AND THE `nop`-AFTER-EVERY-`lh` SIGNATURE (P31 S58b) <sub>L23626</sub>
|
||||
- **§251** — IMMEDIATE-SPELLING TRIGGERS: `+= 0xFF`, FULL-WIDTH `~K`, AND THE TWO-OR SPLIT (P31 S58b) <sub>L23915</sub>
|
||||
|
||||
### declarations, prototypes & K&R (75)
|
||||
### declarations, prototypes & K&R (88)
|
||||
|
||||
- **§3-T4** — Branch polarity: invert the source condition to flip gcc's chosen branch <sub>L90</sub>
|
||||
- **§8c** — Splitting a TU means rebuilding its DECLARATION ENVIRONMENT, not moving text (Phase 26 session 6) <sub>L437</sub>
|
||||
@@ -388,8 +441,21 @@
|
||||
- **§200** — THE ALIAS IS THE UNIVERSAL DECLARATION ESCAPE: stop negotiating with the TU's spelling (P31 S55) <sub>L21062</sub>
|
||||
- **§201-A** — §150-B applies to `decl_prior`'s DEF row: for an overlay-window symbol the banked "definition" is usually another overlay's function, and the card ranks it ABOVE the destination TU <sub>L21121</sub>
|
||||
- **§201-D** — THE SIGNEDNESS OF A div/mod MAGIC IS DECIDED BY THE STATIC TYPE OF THE DIVIDEND TREE AFTER `get_narrower` STRIPS WIDENING CONVERSIONS — NEVER BY A PROVABLE RANGE. AN `& 0xFF` IS NOT A CONVERSION, SO IT NEVER FLIPS THE MAGIC; A DECLARED-UNSIGNED LOCAL *OR* A NARROWING CAST WRITTEN AT THE DIVIDE BOTH DO. <sub>L21284</sub>
|
||||
- **§202** — THE ALIAS CARRIES A DEFINITION, NOT JUST A DECLARATION: the DEF-SIDE-RETURN wall (P31 S56) <sub>L21412</sub>
|
||||
- **§204-C** — WHEN A LOCAL BUFFER'S ADDRESS IS PASSED TO A CALL, ITS SIZE IS A FACT ABOUT THE CALLEE'S BODY, NOT ABOUT THE CALL SITE: grep the callee's proven definition and count the stores through the pointer parameter before you declare the local <sub>L21668</sub>
|
||||
- **§204-E** — `decl_prior`'s `%hi/%lo` ARM HAS NEVER FIRED: the card's promised GLOBAL-TYPE row is 0 of 1,210 <sub>L21801</sub>
|
||||
- **§208** — TWO NAMED LOCALS FOR ONE RELOADED EXPRESSION BUY TWO ALLOCNOS — the naming granularity owns the REGISTER SPLIT, not just the load count (P31 S58) <sub>L22165</sub>
|
||||
- **§214** — THE BANKED TWIN MAY BE A MACRO, A DELETED `.s`, OR A SEMANTIC INVERSE — six ways a ≥0.9 similarity lies (P31 S58) <sub>L22466</sub>
|
||||
- **§216** — DISTINCT ADJACENT SCALARS vs ONE ARRAY: one `lui` per access is the tell, and the array decl is UNUSABLE (P31 S58) <sub>L22568</sub>
|
||||
- **§220** — THE PARAMETER ITSELF IS A REGALLOC DIAL: use it directly, prefer `s32` to `void*`, and place the save-copy AFTER the first call (P31 S58) <sub>L22690</sub>
|
||||
- **§224** — CROSS-JUMP: WRITE THE DUPLICATE, AND READ A SHARED DELAY SLOT AS THE MERGE SIGNATURE (P31 S58) <sub>L22844</sub>
|
||||
- **§236** — THE DECLARATION LAYER IS THE DOMINANT BANK-BLOCKER: NINE WAYS A BYTE-PERFECT BODY FAILS THE GATE (P31 S58b) <sub>L23332</sub>
|
||||
- **§243** — SPELL THE CSE BARRIER AS A REASSIGNED POINTER; AND THE `nop`-AFTER-EVERY-`lh` SIGNATURE (P31 S58b) <sub>L23626</sub>
|
||||
- **§250** — `%hi/%lo` vs `lw`: THE EXTERN'S ARRAY-vs-SCALAR SHAPE DECIDES ADDRESS MATERIALISATION (P31 S58b) <sub>L23878</sub>
|
||||
- **§214** — addendum (P31 S58b) — FOUR MORE WAYS A HIGH-SIMILARITY TWIN LIES <sub>L24293</sub>
|
||||
- **§226** — addendum (P31 S58b) — THE FRAME CATALOGUE: SEVEN MORE LEVERS, AND SLOT ORDER IS DECLARATION ORDER <sub>L24522</sub>
|
||||
|
||||
### jump tables & switches (31)
|
||||
### jump tables & switches (36)
|
||||
|
||||
- **§8** — rodata island (compiler jump tables) — the `.data→.rodata→.data` sandwich (Phase 7) <sub>L320</sub>
|
||||
- **§8a** — rodata island in a flat OVERLAY — the tail sandwich, per matched jr-function (Phase 26 — PoC PROVEN) <sub>L342</sub>
|
||||
@@ -422,8 +488,13 @@
|
||||
- **§188** — 🔴 THE `jr $ra` + `addiu $sp` TAIL IS AN **ASSEMBLER** ARTIFACT, NOT A FRAME SHAPE <sub>L18147</sub>
|
||||
- **§199-D** — A narrow UNSIGNED value compared in an ordered `if` emits `sltiu`/`sltu`; the only dial is the WIDTH of a real object, and a widening `(s32)` cast is inert — AMENDS §35 (whose stated "only CSE-reuse canonicalizes" mechanism is byte-wrong) and does NOT apply inside a `switch` <sub>L20823</sub>
|
||||
- **§199-G** — At TWO case nodes the switch-vs-if oracle is not blind — but the tell is ALL tests positive + a trailing `j default`, NOT the first test's polarity <sub>L20996</sub>
|
||||
- **§206** — THE JTBL-CARVE DRAFTING IDIOM: the bounds check is the entry count, and an EMPTY case owns a slot (P31 S56) <sub>L22075</sub>
|
||||
- **§222** — SWITCH vs IF-CHAIN, PART 3: source arm order IS emission order, a leading EMPTY case buys the median split, and a 2-way dispatch with a shared post-block is a `switch` (P31 S58) <sub>L22740</sub>
|
||||
- **§232** — WHEN THE `jr` DELAY SLOT'S STORE STORES THE RETURN VALUE, TIE THEM WITH ONE PSEUDO **(single observation — not yet cross-confirmed)** (P31 S58) <sub>L23126</sub>
|
||||
- **§256** — GOTOS IN THE TARGET'S BLOCK ORDER REPRODUCE SWITCH PLACEMENT WITHOUT SWITCH'S SIDE EFFECTS (P31 S58b) <sub>L24019</sub>
|
||||
- **§222** — addendum (P31 S58b) — IF-CHAIN vs SWITCH: THREE MORE DISCRIMINATORS <sub>L24423</sub>
|
||||
|
||||
### optimisation level (-O0/-O2) (13)
|
||||
### optimisation level (-O0/-O2) (14)
|
||||
|
||||
- **§6** — Per-module optimization mixing — the -O0 boot module (Phase 7) <sub>L246</sub>
|
||||
- **Detecting** — the opt level (do this first) <sub>L254</sub>
|
||||
@@ -438,8 +509,9 @@
|
||||
- **§127a** — §71 (sibling-first) is the strongest `-O0` lever, and it beats the index <sub>L8377</sub>
|
||||
- **§132** — The `JR-PAIR-IN-ONE-O0-OBJECT` "wall" was TWO instrument defects: a merged-double span the carve could not see, and a truncated object no rule deleted (P30 S29, `func_8013B83C` + `func_8013BD74`) <sub>L8570</sub>
|
||||
- **§195-K** — At -O2 the §18 array-of-struct lever is a FRAME lever, not a length lever — but only when the N reads carry DISTINCT index expressions; with a SHARED index §18's +2-instruction residual is still alive at -O2 (the submitted "memory-loaded narrow index" precondition and unconditional length-neutrality are both falsified) <sub>L20234</sub>
|
||||
- **§261** — THE -O0 ORACLE: DERIVE THE OPT LEVEL FROM THE TARGET, AND `$fp` IS NOT THE TELL (P31 S59) <sub>L24718</sub>
|
||||
|
||||
### family propagation & sweeps (91)
|
||||
### family propagation & sweeps (94)
|
||||
|
||||
- **§8d** — Templating a body INTO a TU must not CHANGE its declaration environment — demote the carried data externs (Phase 26 session 8, byte-proven on `func_8015AE2C` ×133) <sub>L483</sub>
|
||||
- **§11** — Cross-binary dedup & code-sharing (Phase 11 — "one match unlocks many") <sub>L908</sub>
|
||||
@@ -532,8 +604,11 @@
|
||||
- **§194-E** — The wave card's `exemplar` is the TARGET ITSELF on 42/73 wave-U and 36/71 wave-T cards — a construction consequence of `atlas.py:657` (exemplar = max-nins OPEN member) meeting `build_wave_atlas.py:166` (one card per gid); and the shipped §193-A `seed_ref` is same-binary on 0/51, so no card field can ever name a destination-TU sibling <sub>L19129</sub>
|
||||
- **§195-E** — A 0/1 materialised at a JOIN immediately before the controlling `beqz`/`bnez` proves the source NAMED the condition — a truth expression in an `if`'s controlling position reaches `do_jump`, which has no value path <sub>L19920</sub>
|
||||
- **§199-B** — A permutation sweep that holds ANY statement fixed is not a sweep: the statement an agent pins as "obviously load-bearing" is the one carrying the signal, and the partial sweep returns a FLAT residual that reads as proof of order-invariance <sub>L20730</sub>
|
||||
- **§203** — A DEDUPED TYPEDEF MUST PRECEDE EVERY SPLICE POINT, NOT JUST ITS OWN (P31 S56) <sub>L21449</sub>
|
||||
- **§225** — THREE CONTROL-FLOW SHAPES NO STRUCTURED SPELLING REACHES (P31 S58) <sub>L22880</sub>
|
||||
- **§30** — addendum (P31 S58b) — THE ANONYMOUS STRUCT MEMBER REF GRANTS `/s`, AND THAT IS A TWO-FOR-ONE <sub>L24104</sub>
|
||||
|
||||
### integration / TU plumbing (48)
|
||||
### integration / TU plumbing (50)
|
||||
|
||||
- **§8c** — Splitting a TU means rebuilding its DECLARATION ENVIRONMENT, not moving text (Phase 26 session 6) <sub>L437</sub>
|
||||
- **§8d** — Templating a body INTO a TU must not CHANGE its declaration environment — demote the carried data externs (Phase 26 session 8, byte-proven on `func_8015AE2C` ×133) <sub>L483</sub>
|
||||
@@ -583,8 +658,10 @@
|
||||
- **§199-D** — A narrow UNSIGNED value compared in an ordered `if` emits `sltiu`/`sltu`; the only dial is the WIDTH of a real object, and a widening `(s32)` cast is inert — AMENDS §35 (whose stated "only CSE-reuse canonicalizes" mechanism is byte-wrong) and does NOT apply inside a `switch` <sub>L20823</sub>
|
||||
- **§200** — THE ALIAS IS THE UNIVERSAL DECLARATION ESCAPE: stop negotiating with the TU's spelling (P31 S55) <sub>L21062</sub>
|
||||
- **§201-A** — §150-B applies to `decl_prior`'s DEF row: for an overlay-window symbol the banked "definition" is usually another overlay's function, and the card ranks it ABOVE the destination TU <sub>L21121</sub>
|
||||
- **§203** — A DEDUPED TYPEDEF MUST PRECEDE EVERY SPLICE POINT, NOT JUST ITS OWN (P31 S56) <sub>L21449</sub>
|
||||
- **§210** — THE SINGLE-BIT MASK IN A BOOLEAN TAIL: `andi K ; sltu $zero,v` vs `srl n ; andi 1` is a STATEMENT-SHAPE dial, not an operator choice (P31 S58) <sub>L22291</sub>
|
||||
|
||||
### build graph, splat & the harness (145)
|
||||
### build graph, splat & the harness (153)
|
||||
|
||||
- **§4** — Flag/toolchain gotchas <sub>L190</sub>
|
||||
- **Build** — mechanism — per-file opt override (splat resegmentation) <sub>L288</sub>
|
||||
@@ -731,8 +808,16 @@
|
||||
- **§199-D** — A narrow UNSIGNED value compared in an ordered `if` emits `sltiu`/`sltu`; the only dial is the WIDTH of a real object, and a widening `(s32)` cast is inert — AMENDS §35 (whose stated "only CSE-reuse canonicalizes" mechanism is byte-wrong) and does NOT apply inside a `switch` <sub>L20823</sub>
|
||||
- **§199-G** — At TWO case nodes the switch-vs-if oracle is not blind — but the tell is ALL tests positive + a trailing `j default`, NOT the first test's polarity <sub>L20996</sub>
|
||||
- **§201** — THE WAVE-Y HARVEST (P31 S55): 67 gap reports -> 5 laws, 8 rejected, 53 already-covered <sub>L21111</sub>
|
||||
- **§204** — THE WAVE-Z HARVEST (P31 S56): 82 gap reports -> 5 laws, 16 rejected, 30 already-covered <sub>L21510</sub>
|
||||
- **§207** — THE WAVE ab–ag HARVEST (P31 S58): 278 byte-banked notes → 25 laws, 103 self-reported no-gap <sub>L22144</sub>
|
||||
- **§233** — THE WAVE aa–bg HARVEST (P31 S58b): 1,101 byte-banked notes → 24 new laws, 21 addenda, ~700 already-covered <sub>L23218</sub>
|
||||
- **§236** — THE DECLARATION LAYER IS THE DOMINANT BANK-BLOCKER: NINE WAYS A BYTE-PERFECT BODY FAILS THE GATE (P31 S58b) <sub>L23332</sub>
|
||||
- **§247** — TWO BRANCHES TO **ONE** LABEL MEANS THE SOURCE CONDITION IS NEGATED (P31 S58b) <sub>L23778</sub>
|
||||
- **§254** — THE DEAD PARAMETER IS A REGISTER-PLACEMENT TOOL **(single observation — not yet cross-confirmed)** (P31 S58b) <sub>L23972</sub>
|
||||
- **§259** — THE DISCARD LEDGER FOR THE aa–bg HARVEST (P31 S58b): WHAT WAS MINED AND REJECTED, AND WHY <sub>L24629</sub>
|
||||
- **§261** — THE -O0 ORACLE: DERIVE THE OPT LEVEL FROM THE TARGET, AND `$fp` IS NOT THE TELL (P31 S59) <sub>L24718</sub>
|
||||
|
||||
### process, measurement & doctrine (89)
|
||||
### process, measurement & doctrine (92)
|
||||
|
||||
- **§8e** — The jtbl ALIGNMENT LAW + the pad-spec filter — multi-table .rodata spans (Phase 29, byte-proven; `.run/probe_jtbl/verdict.md`) <sub>L530</sub>
|
||||
- **§3-The** — mechanism: game-code dedup is SOURCE-LEVEL, not an object swap (R-D1, the key lesson) <sub>L926</sub>
|
||||
@@ -823,8 +908,11 @@
|
||||
- **§194-D** — Declared width of a computed-value local is a sched1 dial (count-neutral) — a replication + attribution correction of §165-17, NOT a new argument-register law <sub>L19088</sub>
|
||||
- **§195-J** — GTE / PsyQ op CALL-vs-INLINE is a PER-SITE SOURCE FACT, not a TU style — both forms coexist in one TU (measured in 2 TUs), and the tell is the target's own opcodes (`lwc2`/`sqr`/`swc2` vs `jal`), not the sibling. Costs -8 ins on func_8018505C. Corollary: the game's inline `sqr` macro emits TWO hazard nops, the SDK's `Square0` body emits ONE — so the inline form is provably not `Square0` inlined (a second instance of §187's SDK-vs-game GTE nop divergence). <sub>L20190</sub>
|
||||
- **§201-E** — §194-J-2 — The `last_mem_set` deletion window is measured in SOURCE/expand order, not in the printed stream; a foreign store moved between the pair in C source is a real lever, and `volatile` is not always the better one <sub>L21331</sub>
|
||||
- **§230** — THE ANCHOR PROBE: with `%hi`/`%lo` masked, the surviving `addiu` deltas tell you which assignment was written first **(single observation — not yet cross-confirmed)** (P31 S58) <sub>L23070</sub>
|
||||
- **§257** — THE DEAD-END LEDGER (P31 S58b): ELEVEN LEVERS THAT MEASURED NULL OR BACKFIRED <sub>L24056</sub>
|
||||
- **§194-B** — / §209 addendum (P31 S58b) — TWO MORE INSTANCES, AND THE BOUND IS NOW REFUTED FOUR WAYS <sub>L24125</sub>
|
||||
|
||||
### (unbucketed — title matched no symptom vocabulary) (198)
|
||||
### (unbucketed — title matched no symptom vocabulary) (233)
|
||||
|
||||
- **§3-How** — to use this <sub>L30</sub>
|
||||
- **§1** — Idiom catalog (asm pattern → C that produces it) <sub>L39</sub>
|
||||
@@ -1024,6 +1112,41 @@
|
||||
- **§199-REJECTED** — §199-REJECTED <sub>L21051</sub>
|
||||
- **§201-B** — In a narrowed PLUS/MINUS/AND/IOR/XOR expression the destination pointee is INERT — the sign of the materialized constant is decided by an OR over the UNWIDENED operands (convert.c trunc1), which bounds §1841 to direct constant stores <sub>L21153</sub>
|
||||
- **§201-REJECTED** — eight, the session's highest <sub>L21387</sub>
|
||||
- **§204-CONFIRMED** — 30 reports that the index already answered <sub>L21853</sub>
|
||||
- **§204-REJECTED** — sixteen, twice the previous record <sub>L21947</sub>
|
||||
- **§209** — THE NARROW LOCAL IS A DIAL IN TWO OPPOSITE DIRECTIONS, AND §194-B's "≥2 `sh` STORES" BOUND IS BYTE-WRONG (P31 S58) <sub>L22214</sub>
|
||||
- **§212** — THE WALKING CURSOR IS COUNTABLE: `*wp++` emits one `addiu` PER STORE, `wp[0..2]` emits one (P31 S58) <sub>L22385</sub>
|
||||
- **§213** — INDEPENDENT SAME-BASE STORES: THE EMISSION ORDER IS A PERMUTATION OF SOURCE ORDER, AND THE PERMUTATION IS NOT ALWAYS THE IDENTITY (P31 S58) <sub>L22430</sub>
|
||||
- **§217** — DECODING A CALL'S STACK ARGUMENT SLOTS: `sw` at `0x10`/`0x14`/`0x18` are params 5/6/7 **(single observation — not yet cross-confirmed)** (P31 S58) <sub>L22608</sub>
|
||||
- **§226** — FRAME PADS: FOUR WAYS §162i1/§2429's DEAD-LOCAL LEVER MISFIRES (P31 S58) <sub>L22923</sub>
|
||||
- **§228** — READING THE DIVIDE, PART N: the off-by-one compare is `% K == 1`, and three more discriminators (P31 S58) <sub>L22984</sub>
|
||||
- **§229** — THE ADDRESS IS A VALUE: NAMING IT MOVES THE `lui`/`addiu` PAIR — AND §L14410 SAYS THE OPPOSITE FOR A REASON (P31 S58) <sub>L23021</sub>
|
||||
- **§231** — TRANSCRIPTION AND SEMANTIC-READ HYGIENE: six ways the listing misleads (P31 S58) <sub>L23085</sub>
|
||||
- **§194-B** — addendum (P31 S58) — BOUND 2 is byte-wrong; see §209 Direction A <sub>L23182</sub>
|
||||
- **§176-B** — addendum (P31 S58) — the misdiagnosis direction <sub>L23188</sub>
|
||||
- **§164-63** — addendum (P31 S58) — the interposed asm works when the SECOND value is an ordinary assignment <sub>L23203</sub>
|
||||
- **§193-A** — / §194-E addendum (P31 S58) — where the twin's body actually lives <sub>L23212</sub>
|
||||
- **§235** — THE PHANTOM SYMBOL: A MASKED `MATCH` CAN CARRY A RELOCATION THAT DOES NOT EXIST (P31 S58b) <sub>L23303</sub>
|
||||
- **§238** — SAME NAME, DIFFERENT FUNCTION: THE OVERLAY-HOMONYM TRAP (P31 S58b) <sub>L23466</sub>
|
||||
- **§240** — `A + K + B`: WRITE THE CONSTANT **BETWEEN** THE TWO RUNTIME TERMS (P31 S58b) <sub>L23540</sub>
|
||||
- **§241** — THE FOLDED SIGN-EXTEND-AND-SCALE: `sll 16 ; sra (16 − log2 scale)` (P31 S58b) <sub>L23569</sub>
|
||||
- **§252** — THE GUARDED PRE-DECREMENT: `(x != 0) && (--x == 0)` (P31 S58b) <sub>L23937</sub>
|
||||
- **§255** — THE EMPTY CASE, PART 2: FOUR TREE SHAPES IT BUYS (P31 S58b) <sub>L23984</sub>
|
||||
- **§258** — ADDENDA TO EXISTING SECTIONS (P31 S58b) <sub>L24099</sub>
|
||||
- **§202** — addendum (P31 S58b) — THE DEF-SIDE ALIAS ALSO CLEARS A RETURN+PARAM DOUBLE CONFLICT <sub>L24148</sub>
|
||||
- **§205** — addendum (P31 S58b) — CHAINED ASSIGNMENT: N≥3 IS INNERMOST-FIRST, AND THE TEXT MIRRORS EMISSION <sub>L24159</sub>
|
||||
- **§208** — addendum (P31 S58b) — IT SCALES TO SIX SITES, AND IT HAS AN EXACT INVERSE <sub>L24176</sub>
|
||||
- **§210** — addendum (P31 S58b) — THREE CONFIRMED SPELLINGS OF THE BOOLEAN TAIL <sub>L24205</sub>
|
||||
- **§213** — addendum (P31 S58b) — THREE MORE PERMUTATION LAWS FOR INDEPENDENT SAME-BASE STORES <sub>L24264</sub>
|
||||
- **§217** — CROSS-CONFIRMED (P31 S58b) — AND THE INCOMING HOME SLOT IS THE MIRROR <sub>L24381</sub>
|
||||
- **§220** — addendum (P31 S58b) — THE PARAMETER, NOT A COPY (SEVEN CARDS) <sub>L24398</sub>
|
||||
- **§225** — addendum (P31 S58b) — THE GUARD-CLAUSE FINGERPRINT, AND THREE MORE SHAPES <sub>L24495</sub>
|
||||
- **§229** — addendum (P31 S58b) — NAME IT **INSIDE** THE ARM <sub>L24567</sub>
|
||||
- **§230** — CROSS-CONFIRMED (P31 S58b) <sub>L24578</sub>
|
||||
- **§231** — addendum (P31 S58b) — FOUR MORE WAYS THE LISTING MISLEADS <sub>L24587</sub>
|
||||
- **§232** — CROSS-CONFIRMED (P31 S58b) <sub>L24618</sub>
|
||||
- **§260** — THE §154-A LEADING-ISLAND SPLIT: ONE CONFIG LINE, AND THE ISLAND PEELS FROM THE END (P31 S59, byte-proven) <sub>L24668</sub>
|
||||
- **§262** — A LANE'S YIELD IS ONLY A LANE FACT IF IT IS SIZE-MATCHED (P31 S59) <sub>L24744</sub>
|
||||
|
||||
|
||||
## All sections, in order
|
||||
@@ -1679,3 +1802,98 @@
|
||||
- **§201-D** — THE SIGNEDNESS OF A div/mod MAGIC IS DECIDED BY THE STATIC TYPE OF THE DIVIDEND TREE AFTER `get_narrower` STRIPS WIDENING CONVERSIONS — NEVER BY A PROVABLE RANGE. AN `& 0xFF` IS NOT A CONVERSION, SO IT NEVER FLIPS THE MAGIC; A DECLARED-UNSIGNED LOCAL *OR* A NARROWING CAST WRITTEN AT THE DIVIDE BOTH DO. <sub>L21284</sub>
|
||||
- **§201-E** — §194-J-2 — The `last_mem_set` deletion window is measured in SOURCE/expand order, not in the printed stream; a foreign store moved between the pair in C source is a real lever, and `volatile` is not always the better one <sub>L21331</sub>
|
||||
- **§201-REJECTED** — eight, the session's highest <sub>L21387</sub>
|
||||
- **§202** — THE ALIAS CARRIES A DEFINITION, NOT JUST A DECLARATION: the DEF-SIDE-RETURN wall (P31 S56) <sub>L21412</sub>
|
||||
- **§203** — A DEDUPED TYPEDEF MUST PRECEDE EVERY SPLICE POINT, NOT JUST ITS OWN (P31 S56) <sub>L21449</sub>
|
||||
- **§204** — THE WAVE-Z HARVEST (P31 S56): 82 gap reports -> 5 laws, 16 rejected, 30 already-covered <sub>L21510</sub>
|
||||
- **§204-A** — A COMPARE THAT APPEARS BOTH IN A BRANCH'S DELAY SLOT AND AGAIN ON THE FALL-THROUGH IS A JOIN WITH TWO INCOMING EDGES: THE TWO GUARDS ARE SEQUENTIAL `if`s, NEVER `if/else if` <sub>L21529</sub>
|
||||
- **§204-B** — A LOOP COUNT THAT ARRIVES ON THE STACK IS DECREMENTED IN PLACE: a fresh counter local can cost a real `move` AND permute the whole callee-saved file <sub>L21604</sub>
|
||||
- **§204-C** — WHEN A LOCAL BUFFER'S ADDRESS IS PASSED TO A CALL, ITS SIZE IS A FACT ABOUT THE CALLEE'S BODY, NOT ABOUT THE CALL SITE: grep the callee's proven definition and count the stores through the pointer parameter before you declare the local <sub>L21668</sub>
|
||||
- **§204-D** — A LOOP-INVARIANT LOAD IS ADMITTED AS A MOVABLE ONLY IF ITS ADDRESS CANNOT TRAP: `local.field` PASSES, THE SAME READ THROUGH A POINTER LOCAL IS REFUSED <sub>L21726</sub>
|
||||
- **§204-E** — `decl_prior`'s `%hi/%lo` ARM HAS NEVER FIRED: the card's promised GLOBAL-TYPE row is 0 of 1,210 <sub>L21801</sub>
|
||||
- **§204-CONFIRMED** — 30 reports that the index already answered <sub>L21853</sub>
|
||||
- **§204-REJECTED** — sixteen, twice the previous record <sub>L21947</sub>
|
||||
- **§205** — THE CHAINED ASSIGNMENT IS ITS OWN SCHEDULING DIAL: `*b = *a = v;` moves an argument copy that no local, no pin and no statement reorder will move (P31 S56) <sub>L22020</sub>
|
||||
- **§206** — THE JTBL-CARVE DRAFTING IDIOM: the bounds check is the entry count, and an EMPTY case owns a slot (P31 S56) <sub>L22075</sub>
|
||||
- **§207** — THE WAVE ab–ag HARVEST (P31 S58): 278 byte-banked notes → 25 laws, 103 self-reported no-gap <sub>L22144</sub>
|
||||
- **§208** — TWO NAMED LOCALS FOR ONE RELOADED EXPRESSION BUY TWO ALLOCNOS — the naming granularity owns the REGISTER SPLIT, not just the load count (P31 S58) <sub>L22165</sub>
|
||||
- **§209** — THE NARROW LOCAL IS A DIAL IN TWO OPPOSITE DIRECTIONS, AND §194-B's "≥2 `sh` STORES" BOUND IS BYTE-WRONG (P31 S58) <sub>L22214</sub>
|
||||
- **§210** — THE SINGLE-BIT MASK IN A BOOLEAN TAIL: `andi K ; sltu $zero,v` vs `srl n ; andi 1` is a STATEMENT-SHAPE dial, not an operator choice (P31 S58) <sub>L22291</sub>
|
||||
- **§211** — HOIST THE LOOP INIT ABOVE THE DOMINATING GUARD: it fills the guard's delay slot AND flips the counter/pointer register pair (P31 S58) <sub>L22337</sub>
|
||||
- **§212** — THE WALKING CURSOR IS COUNTABLE: `*wp++` emits one `addiu` PER STORE, `wp[0..2]` emits one (P31 S58) <sub>L22385</sub>
|
||||
- **§213** — INDEPENDENT SAME-BASE STORES: THE EMISSION ORDER IS A PERMUTATION OF SOURCE ORDER, AND THE PERMUTATION IS NOT ALWAYS THE IDENTITY (P31 S58) <sub>L22430</sub>
|
||||
- **§214** — THE BANKED TWIN MAY BE A MACRO, A DELETED `.s`, OR A SEMANTIC INVERSE — six ways a ≥0.9 similarity lies (P31 S58) <sub>L22466</sub>
|
||||
- **§215** — PIN ECONOMY: the twin's pins are NOT part of the shape, and §17's "pin every call-crossing value" is over-broad (P31 S58) <sub>L22512</sub>
|
||||
- **§216** — DISTINCT ADJACENT SCALARS vs ONE ARRAY: one `lui` per access is the tell, and the array decl is UNUSABLE (P31 S58) <sub>L22568</sub>
|
||||
- **§217** — DECODING A CALL'S STACK ARGUMENT SLOTS: `sw` at `0x10`/`0x14`/`0x18` are params 5/6/7 **(single observation — not yet cross-confirmed)** (P31 S58) <sub>L22608</sub>
|
||||
- **§218** — A NARROW TYPE AT THE ABI BOUNDARY COSTS AN IN-PLACE `sll/sra` PAIR — on the RETURN as well as on the PARAMETER (P31 S58) <sub>L22634</sub>
|
||||
- **§219** — COMPOUND `+=`, FULL ASSIGNMENT, AND AN EXPLICIT TEMP ARE THREE DIFFERENT SCHEDULES OF ONE READ-MODIFY-WRITE (P31 S58) <sub>L22663</sub>
|
||||
- **§220** — THE PARAMETER ITSELF IS A REGALLOC DIAL: use it directly, prefer `s32` to `void*`, and place the save-copy AFTER the first call (P31 S58) <sub>L22690</sub>
|
||||
- **§221** — A CONSTANT SHARED BY TWO STORES DIES AT THE CALL WHOSE DELAY SLOT REFILLS ITS REGISTER **(single observation — not yet cross-confirmed)** (P31 S58) <sub>L22724</sub>
|
||||
- **§222** — SWITCH vs IF-CHAIN, PART 3: source arm order IS emission order, a leading EMPTY case buys the median split, and a 2-way dispatch with a shared post-block is a `switch` (P31 S58) <sub>L22740</sub>
|
||||
- **§223** — READING A `jal` DELAY SLOT: the value in it was produced BEFORE the call, so it is NEVER that call's return (P31 S58) <sub>L22782</sub>
|
||||
- **§224** — CROSS-JUMP: WRITE THE DUPLICATE, AND READ A SHARED DELAY SLOT AS THE MERGE SIGNATURE (P31 S58) <sub>L22844</sub>
|
||||
- **§225** — THREE CONTROL-FLOW SHAPES NO STRUCTURED SPELLING REACHES (P31 S58) <sub>L22880</sub>
|
||||
- **§226** — FRAME PADS: FOUR WAYS §162i1/§2429's DEAD-LOCAL LEVER MISFIRES (P31 S58) <sub>L22923</sub>
|
||||
- **§227** — TYPE THE SOURCE BY THE **LOAD** WIDTH, NOT BY THE STORE WIDTH (P31 S58) <sub>L22964</sub>
|
||||
- **§228** — READING THE DIVIDE, PART N: the off-by-one compare is `% K == 1`, and three more discriminators (P31 S58) <sub>L22984</sub>
|
||||
- **§229** — THE ADDRESS IS A VALUE: NAMING IT MOVES THE `lui`/`addiu` PAIR — AND §L14410 SAYS THE OPPOSITE FOR A REASON (P31 S58) <sub>L23021</sub>
|
||||
- **§230** — THE ANCHOR PROBE: with `%hi`/`%lo` masked, the surviving `addiu` deltas tell you which assignment was written first **(single observation — not yet cross-confirmed)** (P31 S58) <sub>L23070</sub>
|
||||
- **§231** — TRANSCRIPTION AND SEMANTIC-READ HYGIENE: six ways the listing misleads (P31 S58) <sub>L23085</sub>
|
||||
- **§232** — WHEN THE `jr` DELAY SLOT'S STORE STORES THE RETURN VALUE, TIE THEM WITH ONE PSEUDO **(single observation — not yet cross-confirmed)** (P31 S58) <sub>L23126</sub>
|
||||
- **§30** — addendum (P31 S58) — the `/s` grant closes a SCHEDULING residual and a REGISTER residual with one edit <sub>L23162</sub>
|
||||
- **§194-B** — addendum (P31 S58) — BOUND 2 is byte-wrong; see §209 Direction A <sub>L23182</sub>
|
||||
- **§176-B** — addendum (P31 S58) — the misdiagnosis direction <sub>L23188</sub>
|
||||
- **§165-40** — addendum (P31 S58) — the barrier goes at the COPY SITE, not inside the region it protects <sub>L23194</sub>
|
||||
- **§164-63** — addendum (P31 S58) — the interposed asm works when the SECOND value is an ordinary assignment <sub>L23203</sub>
|
||||
- **§193-A** — / §194-E addendum (P31 S58) — where the twin's body actually lives <sub>L23212</sub>
|
||||
- **§233** — THE WAVE aa–bg HARVEST (P31 S58b): 1,101 byte-banked notes → 24 new laws, 21 addenda, ~700 already-covered <sub>L23218</sub>
|
||||
- **§234** — CONSTANT MATERIALISATION: THE STORE LVALUE'S SIGNEDNESS PICKS `addiu` vs `li`/`ori` (P31 S58b) <sub>L23262</sub>
|
||||
- **§235** — THE PHANTOM SYMBOL: A MASKED `MATCH` CAN CARRY A RELOCATION THAT DOES NOT EXIST (P31 S58b) <sub>L23303</sub>
|
||||
- **§236** — THE DECLARATION LAYER IS THE DOMINANT BANK-BLOCKER: NINE WAYS A BYTE-PERFECT BODY FAILS THE GATE (P31 S58b) <sub>L23332</sub>
|
||||
- **§237** — THE CAST-AT-CALL-SITE DECISION TABLE: WHAT §17a-1 FIXES, WHAT IT CANNOT, AND THE FOUR ESCAPES (P31 S58b) <sub>L23411</sub>
|
||||
- **§238** — SAME NAME, DIFFERENT FUNCTION: THE OVERLAY-HOMONYM TRAP (P31 S58b) <sub>L23466</sub>
|
||||
- **§239** — TWO-STATEMENT INTEGER-SPACE MATERIALISATION REORDERS `la` vs `sll`; AND THE PLUS-TREE OPERAND ORDER (P31 S58b) <sub>L23506</sub>
|
||||
- **§240** — `A + K + B`: WRITE THE CONSTANT **BETWEEN** THE TWO RUNTIME TERMS (P31 S58b) <sub>L23540</sub>
|
||||
- **§241** — THE FOLDED SIGN-EXTEND-AND-SCALE: `sll 16 ; sra (16 − log2 scale)` (P31 S58b) <sub>L23569</sub>
|
||||
- **§242** — `*k` vs `<<n`, AND `/2^n` vs `>>n`: EXPRESSION SPELLING OWNS THE LOAD WIDTH AND THE ROUNDING CHAIN (P31 S58b) <sub>L23598</sub>
|
||||
- **§243** — SPELL THE CSE BARRIER AS A REASSIGNED POINTER; AND THE `nop`-AFTER-EVERY-`lh` SIGNATURE (P31 S58b) <sub>L23626</sub>
|
||||
- **§244** — `volatile` IS A COUNTING INSTRUMENT, A STORE-ORDER PIN, AND MUST SOMETIMES BE ASYMMETRIC (P31 S58b) <sub>L23656</sub>
|
||||
- **§245** — THE CALL'S ARGUMENT LIST IS A SCHEDULING SLOT (P31 S58b) <sub>L23691</sub>
|
||||
- **§246** — THREE-LIVE-VALUE SCAN LOOPS WANT ADDRESS-FROM-INDEX; AND TWO SYMBOLS CAN SHARE ONE giv (P31 S58b) <sub>L23738</sub>
|
||||
- **§247** — TWO BRANCHES TO **ONE** LABEL MEANS THE SOURCE CONDITION IS NEGATED (P31 S58b) <sub>L23778</sub>
|
||||
- **§248** — SPLIT THE LOAD FROM THE ARITHMETIC: A FUSED `g + K` DENIES THE CALLEE-SAVED REGISTER ITS DIRECT HOME (P31 S58b) <sub>L23812</sub>
|
||||
- **§249** — THE SELF-ASSIGN, THE DEAD RE-ASSIGN, AND THE `+ zr` COPY: THREE WAYS TO MAKE A DELETED INSTRUCTION REAL (P31 S58b) <sub>L23836</sub>
|
||||
- **§250** — `%hi/%lo` vs `lw`: THE EXTERN'S ARRAY-vs-SCALAR SHAPE DECIDES ADDRESS MATERIALISATION (P31 S58b) <sub>L23878</sub>
|
||||
- **§251** — IMMEDIATE-SPELLING TRIGGERS: `+= 0xFF`, FULL-WIDTH `~K`, AND THE TWO-OR SPLIT (P31 S58b) <sub>L23915</sub>
|
||||
- **§252** — THE GUARDED PRE-DECREMENT: `(x != 0) && (--x == 0)` (P31 S58b) <sub>L23937</sub>
|
||||
- **§253** — POSTFIX `++` vs `+= 1` PICKS A DIFFERENT SCRATCH REGISTER **(single observation — not yet cross-confirmed)** (P31 S58b) <sub>L23958</sub>
|
||||
- **§254** — THE DEAD PARAMETER IS A REGISTER-PLACEMENT TOOL **(single observation — not yet cross-confirmed)** (P31 S58b) <sub>L23972</sub>
|
||||
- **§255** — THE EMPTY CASE, PART 2: FOUR TREE SHAPES IT BUYS (P31 S58b) <sub>L23984</sub>
|
||||
- **§256** — GOTOS IN THE TARGET'S BLOCK ORDER REPRODUCE SWITCH PLACEMENT WITHOUT SWITCH'S SIDE EFFECTS (P31 S58b) <sub>L24019</sub>
|
||||
- **§257** — THE DEAD-END LEDGER (P31 S58b): ELEVEN LEVERS THAT MEASURED NULL OR BACKFIRED <sub>L24056</sub>
|
||||
- **§258** — ADDENDA TO EXISTING SECTIONS (P31 S58b) <sub>L24099</sub>
|
||||
- **§30** — addendum (P31 S58b) — THE ANONYMOUS STRUCT MEMBER REF GRANTS `/s`, AND THAT IS A TWO-FOR-ONE <sub>L24104</sub>
|
||||
- **§194-B** — / §209 addendum (P31 S58b) — TWO MORE INSTANCES, AND THE BOUND IS NOW REFUTED FOUR WAYS <sub>L24125</sub>
|
||||
- **§202** — addendum (P31 S58b) — THE DEF-SIDE ALIAS ALSO CLEARS A RETURN+PARAM DOUBLE CONFLICT <sub>L24148</sub>
|
||||
- **§205** — addendum (P31 S58b) — CHAINED ASSIGNMENT: N≥3 IS INNERMOST-FIRST, AND THE TEXT MIRRORS EMISSION <sub>L24159</sub>
|
||||
- **§208** — addendum (P31 S58b) — IT SCALES TO SIX SITES, AND IT HAS AN EXACT INVERSE <sub>L24176</sub>
|
||||
- **§210** — addendum (P31 S58b) — THREE CONFIRMED SPELLINGS OF THE BOOLEAN TAIL <sub>L24205</sub>
|
||||
- **§211** — addendum (P31 S58b) — INIT PLACEMENT: FIVE MORE DIALS BEYOND THE GUARD HOIST <sub>L24221</sub>
|
||||
- **§213** — addendum (P31 S58b) — THREE MORE PERMUTATION LAWS FOR INDEPENDENT SAME-BASE STORES <sub>L24264</sub>
|
||||
- **§214** — addendum (P31 S58b) — FOUR MORE WAYS A HIGH-SIMILARITY TWIN LIES <sub>L24293</sub>
|
||||
- **§215** — addendum (P31 S58b) — PIN ECONOMY, PART 2: NINE REFINEMENTS <sub>L24329</sub>
|
||||
- **§217** — CROSS-CONFIRMED (P31 S58b) — AND THE INCOMING HOME SLOT IS THE MIRROR <sub>L24381</sub>
|
||||
- **§220** — addendum (P31 S58b) — THE PARAMETER, NOT A COPY (SEVEN CARDS) <sub>L24398</sub>
|
||||
- **§222** — addendum (P31 S58b) — IF-CHAIN vs SWITCH: THREE MORE DISCRIMINATORS <sub>L24423</sub>
|
||||
- **§223** — addendum (P31 S58b) — FIVE MORE CONFIRMATIONS, AND THE CONSTANT-IN-`$v0` CASE <sub>L24441</sub>
|
||||
- **§224** — addendum (P31 S58b) — CROSS-JUMP MERGES *CALLS*, AND THE DELAY SLOT IS THE DISCRIMINATOR <sub>L24465</sub>
|
||||
- **§225** — addendum (P31 S58b) — THE GUARD-CLAUSE FINGERPRINT, AND THREE MORE SHAPES <sub>L24495</sub>
|
||||
- **§226** — addendum (P31 S58b) — THE FRAME CATALOGUE: SEVEN MORE LEVERS, AND SLOT ORDER IS DECLARATION ORDER <sub>L24522</sub>
|
||||
- **§229** — addendum (P31 S58b) — NAME IT **INSIDE** THE ARM <sub>L24567</sub>
|
||||
- **§230** — CROSS-CONFIRMED (P31 S58b) <sub>L24578</sub>
|
||||
- **§231** — addendum (P31 S58b) — FOUR MORE WAYS THE LISTING MISLEADS <sub>L24587</sub>
|
||||
- **§232** — CROSS-CONFIRMED (P31 S58b) <sub>L24618</sub>
|
||||
- **§259** — THE DISCARD LEDGER FOR THE aa–bg HARVEST (P31 S58b): WHAT WAS MINED AND REJECTED, AND WHY <sub>L24629</sub>
|
||||
- **§260** — THE §154-A LEADING-ISLAND SPLIT: ONE CONFIG LINE, AND THE ISLAND PEELS FROM THE END (P31 S59, byte-proven) <sub>L24668</sub>
|
||||
- **§261** — THE -O0 ORACLE: DERIVE THE OPT LEVEL FROM THE TARGET, AND `$fp` IS NOT THE TELL (P31 S59) <sub>L24718</sub>
|
||||
- **§262** — A LANE'S YIELD IS ONLY A LANE FACT IF IT IS SIZE-MATCHED (P31 S59) <sub>L24744</sub>
|
||||
|
||||
@@ -24664,3 +24664,109 @@ lever, and would be a false law if written up):
|
||||
(§246, `func_801AB5D4`). Nine drafts, all near-40.
|
||||
|
||||
Both are permuter jobs, not source-lever jobs. Do not spend a wave's budget re-deriving them.
|
||||
|
||||
## §260 — THE §154-A LEADING-ISLAND SPLIT: ONE CONFIG LINE, AND THE ISLAND PEELS FROM THE END (P31 S59, byte-proven)
|
||||
|
||||
An `md_*` module binds `.rodata` at offset 0 to the same subseg as its code, so the object's rodata
|
||||
order is the C file's include chain: the `INCLUDE_RODATA` blobs, then every `INCLUDE_ASM`'d
|
||||
function's still-migrated jump table, in source order. That island reproduces byte-exactly **while
|
||||
the functions are stubs**, and the moment one is matched its table leaves the chain and cc1 re-emits
|
||||
it at the end of the object's `.rodata` — the +8-and-everything-shifts failure P30 S48 measured.
|
||||
|
||||
**THE WHOLE FIX IS ONE INSERTED CONFIG LINE PLUS AN ISOLATION.** On `md_SC03_076` /
|
||||
`func_801F218C`:
|
||||
|
||||
```yaml
|
||||
- [0x0, .rodata, md_SC03_076] # leave the island piece ALONE
|
||||
- [0x268, .rodata, md_SC03_076_jr_801F218C] # the split: the function's own table
|
||||
- [0x27c, c, md_SC03_076]
|
||||
- [0x2d24, c, md_SC03_076_jr_801F218C] # jr_isolate_all.py --only
|
||||
```
|
||||
|
||||
Do **not** create a `_pre` piece (a dotted `.rodata` with no sibling `.c` points splat's ld at a
|
||||
never-built implied C file and unbinds the island from its module). Do **not** touch
|
||||
`ld_interleave` — the generated script is already rodata-first in yaml order. Use
|
||||
`jr_isolate_all.py --only`, not `jr_isolate.py` (its backend `sys.exit`s on a top-level extern
|
||||
block).
|
||||
|
||||
**THE CONTROL THAT SEPARATES "IT WORKED" FROM "IT DID NOTHING."** A green SHA proves nothing on its
|
||||
own here, because a split that silently failed to happen is also green. Pair it with the
|
||||
object-level size:
|
||||
|
||||
| | whole-binary sha1 | `md_SC03_076.o` `.rodata` | `md_SC03_076_jr_801F218C.o` `.rodata` |
|
||||
|---|---|---|---|
|
||||
| before | `9a165e36…` | 0x27c (the whole island) | — |
|
||||
| after | `9a165e36…` | **0x268** | **0x14** (the 5-entry table) |
|
||||
|
||||
**THE ISLAND IS A STACK.** Census of `md_SC03_076` (file offsets): `D_801EF468` 0x000, `D_801EF540`
|
||||
0x0D8, then `func_801EFBB4` 0x144 · `func_801F0210` 0x1B4 · `func_801F0734` 0x1EC ·
|
||||
`func_801F0A9C` 0x214 · `func_801F0F28` 0x23C · `func_801F218C` 0x268 → 0x27C, the island end. Only
|
||||
the **end-adjacent** table carves cheaply; each isolation makes the next one end-adjacent, so a
|
||||
module peels from the end, one function at a time. Picking a middle table first is what makes the
|
||||
job look like cascading isolation.
|
||||
|
||||
**TWO TOOL BLINDNESSES THIS EXPOSED, both md_*-only and both now fixed.** (1)
|
||||
`jtbl_carve.parse_config` took the FIRST `data/.rodata` piece in the file rather than the trailing
|
||||
run after the last `c` — identical on 171 configs, and on the 42 `md_*` it pointed at the island, so
|
||||
`apply()`'s splice DELETED the `c` line and wrote the yaml to disk before erroring for unrelated
|
||||
reasons. (2) `jr_isolate_all.jr_inventory` asserts every `.rodata` piece resolves to exactly one
|
||||
banked owner (R32) — true where jtbl_carve created every piece, false for the island, which has no
|
||||
owner; it aborted with `UNOWNED 0x801ef468` and md_* could not be isolated at all. The structural
|
||||
discriminator, verified over all 213 configs: a `.rodata` piece at offset 0 whose subseg is the
|
||||
binary's own alias exists in exactly the 42 `md_*` and in none of the others.
|
||||
|
||||
## §261 — THE -O0 ORACLE: DERIVE THE OPT LEVEL FROM THE TARGET, AND `$fp` IS NOT THE TELL (P31 S59)
|
||||
|
||||
`match_one --o0` existed for a year and **nothing ever passed it**. `api_draft.match_one()` — the
|
||||
oracle every wave agent iterates against — builds a fixed argv without it, so an agent handed an
|
||||
-O0 target was shown an **-O2 compile of its own C** and a mismatch on every instruction: feedback
|
||||
that cannot converge, for a reason that never appears in the diff. It hit even the functions already
|
||||
sitting in `_o0` objects, where a match was otherwise bankable today.
|
||||
|
||||
**DERIVE IT (R33), FROM TWO ORACLES (R34), BECAUSE NEITHER ALONE COVERS THE TREE:**
|
||||
* **the target's own prologue** — `sw $fp, N($sp)` + `addu $fp, $sp, $zero` (`21F0A003`) inside the
|
||||
function's first instructions. gcc-2.7.2 keeps a frame pointer at -O0 and omits it at -O2.
|
||||
* **the subseg's build flags** — `boot` and every `*_o0*` object are compiled -O0 by the Makefile.
|
||||
`boot/start.s` is -O0 with no ordinary prologue; only this oracle sees it.
|
||||
|
||||
**`$fp` MENTIONS ARE NOT THE POPULATION.** `$fp` is `$s8`, an ordinary allocatable callee-saved
|
||||
register at -O2. Over 14,400 `.s` files: **311 mention `$fp`, 167 carry the -O0 prologue.** Sizing a
|
||||
lane off the 311 over-counts by 1.9×. Anchor the prologue scan at `glabel`, not the top of the file
|
||||
— two `md_MAIN_011` targets open with a migrated jump table / `.asciz` blob, and a naive "first 8
|
||||
encoded lines" reads table words as the prologue and calls an -O0 function -O2.
|
||||
|
||||
**A MATCH IS NOT A BANK FOR THIS CLASS.** An -O0 function in an -O2 subseg cannot bank however
|
||||
perfect the body: the object's `CC1FLAGS` decide, and the Makefile's -O0 globs cover `boot`,
|
||||
`ov_SC01_077_o0`, `src/ov_*/ov_*_o0.c` and `src/ov_*/ov_*_o0?.c` — **nothing matches `src/md_*/`**.
|
||||
Of the 167, 51 are inside an -O0 object and **116 (14,148 ins) are stranded in -O2 subsegs**, so
|
||||
`match_one` now says so on sight rather than letting an agent chase a body that can never land.
|
||||
|
||||
## §262 — A LANE'S YIELD IS ONLY A LANE FACT IF IT IS SIZE-MATCHED (P31 S59)
|
||||
|
||||
The `tells` lane was removed from the drafting rotation on four waves that gated 3–6 of ~56 drafts.
|
||||
Two confounds, both measurable from artefacts the campaign already writes:
|
||||
|
||||
1. **The band.** All four cited waves ran at 120-2000. Pooled by band: tells @120-2000 = 228 drafts
|
||||
→ 18 banked (7.9%); tells @ full band = 655 → 161 (24.6%); default @ full band = 2,996 → 1,335
|
||||
(44.6%).
|
||||
2. **The size mix.** Join each wave's cards to the functions its own commit banked (the removed
|
||||
`INCLUDE_ASM` lines are the ground truth — no roster, no ledger):
|
||||
|
||||
| nins | default | tells |
|
||||
|---|---|---|
|
||||
| 0–50 | 303/528 **57%** | 27/67 **40%** |
|
||||
| 50–80 | 43/145 30% | 20/73 27% |
|
||||
| 80–120 | 9/41 22% | 10/100 10% |
|
||||
| 120–200 | 1/30 3% | 1/68 1% |
|
||||
| 200+ | 2/35 6% | 0/30 0% |
|
||||
|
||||
At equal size the lanes are close below 80 instructions and **both collapse above it**. What
|
||||
separated them was the pool: default's cards are median 37–39 ins, the tells pool median 89–95 —
|
||||
2.4× larger. "The lane is broken" was a statement about the population.
|
||||
|
||||
**THE CHEAP CHECK BEFORE YOU RETIRE A LANE:** compare bank rate *inside a size bucket*, and read the
|
||||
recorded pre-gate verdicts first (R38). Here the recorded `reloc_identity` rows also refuted the
|
||||
standing hypothesis (§235, the phantom symbol): among `MISMATCH?` rows the fraction whose
|
||||
instruction SHAPE already matched — the symbol-only class §235 describes — is 25/87, 16/79, 17/66,
|
||||
13/57 on default waves but 6/66, 4/81, 5/47 on tells. Tells drafts fail because the BODY is wrong,
|
||||
which is what a 2.4× larger median predicts, not because of symbols.
|
||||
|
||||
Reference in New Issue
Block a user