From f3dc5b6f28e27a539b0c717faa53bc5c2a4ae3e2 Mon Sep 17 00:00:00 2001 From: Drew T <50529377+Druthulu@users.noreply.github.com> Date: Fri, 11 Sep 2026 03:14:30 -0600 Subject: [PATCH] phase-36: S104 e27 packs (md_SC07_004 + main func_800377D8) --- .run/P36/agents/ORDER.tsv | 9 +- .../md_SC07_004__func_801AC9CC/body_free.c | 30 +++ .../md_SC07_004__func_801AC9CC/body_tree.c | 31 +++ .../md_SC07_004__func_801AC9CC/history.txt | 14 ++ .../md_SC07_004__func_801AC9CC/neighbours.txt | 3 + .../md_SC07_004__func_801AC9CC/related.txt | 87 +++++++++ .../md_SC07_004__func_801AC9CC/residual.txt | 18 ++ .../md_SC07_004__func_801AC9CC/sites.txt | 1 + .../agents/md_SC07_004__func_801AC9CC/tu.txt | 2 + .../md_SC07_004__func_801AD068/body_free.c | 50 +++++ .../md_SC07_004__func_801AD068/body_tree.c | 50 +++++ .../md_SC07_004__func_801AD068/history.txt | 14 ++ .../md_SC07_004__func_801AD068/neighbours.txt | 3 + .../md_SC07_004__func_801AD068/related.txt | 176 ++++++++++++++++++ .../md_SC07_004__func_801AD068/residual.txt | 12 ++ .../md_SC07_004__func_801AD068/sites.txt | 1 + .../agents/md_SC07_004__func_801AD068/tu.txt | 2 + .../md_SC07_004__func_801AE82C/body_free.c | 29 +++ .../md_SC07_004__func_801AE82C/body_tree.c | 30 +++ .../md_SC07_004__func_801AE82C/history.txt | 14 ++ .../md_SC07_004__func_801AE82C/neighbours.txt | 3 + .../md_SC07_004__func_801AE82C/related.txt | 11 ++ .../md_SC07_004__func_801AE82C/residual.txt | 16 ++ .../md_SC07_004__func_801AE82C/sites.txt | 1 + .../agents/md_SC07_004__func_801AE82C/tu.txt | 2 + 25 files changed, 603 insertions(+), 6 deletions(-) create mode 100644 .run/P36/agents/md_SC07_004__func_801AC9CC/body_free.c create mode 100644 .run/P36/agents/md_SC07_004__func_801AC9CC/body_tree.c create mode 100644 .run/P36/agents/md_SC07_004__func_801AC9CC/history.txt create mode 100644 .run/P36/agents/md_SC07_004__func_801AC9CC/neighbours.txt create mode 100644 .run/P36/agents/md_SC07_004__func_801AC9CC/related.txt create mode 100644 .run/P36/agents/md_SC07_004__func_801AC9CC/residual.txt create mode 100644 .run/P36/agents/md_SC07_004__func_801AC9CC/sites.txt create mode 100644 .run/P36/agents/md_SC07_004__func_801AC9CC/tu.txt create mode 100644 .run/P36/agents/md_SC07_004__func_801AD068/body_free.c create mode 100644 .run/P36/agents/md_SC07_004__func_801AD068/body_tree.c create mode 100644 .run/P36/agents/md_SC07_004__func_801AD068/history.txt create mode 100644 .run/P36/agents/md_SC07_004__func_801AD068/neighbours.txt create mode 100644 .run/P36/agents/md_SC07_004__func_801AD068/related.txt create mode 100644 .run/P36/agents/md_SC07_004__func_801AD068/residual.txt create mode 100644 .run/P36/agents/md_SC07_004__func_801AD068/sites.txt create mode 100644 .run/P36/agents/md_SC07_004__func_801AD068/tu.txt create mode 100644 .run/P36/agents/md_SC07_004__func_801AE82C/body_free.c create mode 100644 .run/P36/agents/md_SC07_004__func_801AE82C/body_tree.c create mode 100644 .run/P36/agents/md_SC07_004__func_801AE82C/history.txt create mode 100644 .run/P36/agents/md_SC07_004__func_801AE82C/neighbours.txt create mode 100644 .run/P36/agents/md_SC07_004__func_801AE82C/related.txt create mode 100644 .run/P36/agents/md_SC07_004__func_801AE82C/residual.txt create mode 100644 .run/P36/agents/md_SC07_004__func_801AE82C/sites.txt create mode 100644 .run/P36/agents/md_SC07_004__func_801AE82C/tu.txt diff --git a/.run/P36/agents/ORDER.tsv b/.run/P36/agents/ORDER.tsv index 2b61e1d06..35c1f62e7 100644 --- a/.run/P36/agents/ORDER.tsv +++ b/.run/P36/agents/ORDER.tsv @@ -1,7 +1,4 @@ rank fn alias copies best needed kinds regs tu -60 func_8017F024 ov_SC06_010 1 5 2 launder,pin $2 src/ov_SC06_010/ov_SC06_010_jr_8017A4AC.c -58 func_8017E764 ov_SC06_010 1 6 2 cast,pin $3 src/ov_SC06_010/ov_SC06_010_jr_8017A4AC.c -64 func_8017F438 ov_SC06_010 1 18 4 barrier,pin $2 src/ov_SC06_010/ov_SC06_010_jr_8017A4AC.c -65 func_8017F600 ov_SC06_010 1 18 4 barrier,pin $2 src/ov_SC06_010/ov_SC06_010_jr_8017A4AC.c -27 func_800377D8 main 1 19 4 barrier,pin $2 src/800_c.c -6 func_800383A4 main 1 None 1 pin $2 src/800_c.c +254 func_801AC9CC md_SC07_004 1 2 1 barrier src/md_SC07_004/md_SC07_004.c +264 func_801AD068 md_SC07_004 1 5 1 pin $3 src/md_SC07_004/md_SC07_004.c +298 func_801AE82C md_SC07_004 1 5 1 pin $0 src/md_SC07_004/md_SC07_004.c diff --git a/.run/P36/agents/md_SC07_004__func_801AC9CC/body_free.c b/.run/P36/agents/md_SC07_004__func_801AC9CC/body_free.c new file mode 100644 index 000000000..fe2ea8b22 --- /dev/null +++ b/.run/P36/agents/md_SC07_004__func_801AC9CC/body_free.c @@ -0,0 +1,30 @@ +void func_801AC9CC(void *arg0) { + void *temp_a0; + s16 sp10[8]; + s32 v0; + s32 v1; + u16 a3; + + temp_a0 = *(void **)((u8 *)arg0 + 0x20); + if (temp_a0 != NULL) { + func_80016714(temp_a0, 0x38); + *(void **)((u8 *)arg0 + 0x20) = NULL; + } + sp10[0] = *(u16 *)((u8 *)arg0 + 0x6); + sp10[1] = *(u16 *)((u8 *)arg0 + 0xA); + sp10[2] = *(u16 *)((u8 *)arg0 + 0xE); + v0 = *(s16 *)((u8 *)arg0 + 0x30); + a3 = *(u16 *)((u8 *)arg0 + 0x30); + if (v0 == 0) { + a3 = 6; + } + v0 = func_8017D7D4(sp10, NULL, (u8 *)arg0 + 0x34, (s8)a3); + v1 = *(s16 *)((u8 *)arg0 + 0x32); + *(s32 *)((u8 *)arg0 + 0x2C) = v0; + if (v1 == 0) { + *(s32 *)((u8 *)arg0 + 0x1C) = 0x10; + } else { + *(s32 *)((u8 *)arg0 + 0x1C) = v1; + } + *(u16 *)((u8 *)arg0 + 0x2) = *(u16 *)((u8 *)arg0 + 0x2) + 1; +} diff --git a/.run/P36/agents/md_SC07_004__func_801AC9CC/body_tree.c b/.run/P36/agents/md_SC07_004__func_801AC9CC/body_tree.c new file mode 100644 index 000000000..bac65a71a --- /dev/null +++ b/.run/P36/agents/md_SC07_004__func_801AC9CC/body_tree.c @@ -0,0 +1,31 @@ +void func_801AC9CC(void *arg0) { + void *temp_a0; + s16 sp10[8]; + s32 v0; + s32 v1; + u16 a3; + + temp_a0 = *(void **)((u8 *)arg0 + 0x20); + if (temp_a0 != NULL) { + func_80016714(temp_a0, 0x38); + *(void **)((u8 *)arg0 + 0x20) = NULL; + } + sp10[0] = *(u16 *)((u8 *)arg0 + 0x6); + sp10[1] = *(u16 *)((u8 *)arg0 + 0xA); + sp10[2] = *(u16 *)((u8 *)arg0 + 0xE); + v0 = *(s16 *)((u8 *)arg0 + 0x30); + __asm__ __volatile__("" ::: "memory"); // !FAKE: barrier memory — NEEDED DIFFERS (P36 rung B tus9) + a3 = *(u16 *)((u8 *)arg0 + 0x30); + if (v0 == 0) { + a3 = 6; + } + v0 = func_8017D7D4(sp10, NULL, (u8 *)arg0 + 0x34, (s8)a3); + v1 = *(s16 *)((u8 *)arg0 + 0x32); + *(s32 *)((u8 *)arg0 + 0x2C) = v0; + if (v1 == 0) { + *(s32 *)((u8 *)arg0 + 0x1C) = 0x10; + } else { + *(s32 *)((u8 *)arg0 + 0x1C) = v1; + } + *(u16 *)((u8 *)arg0 + 0x2) = *(u16 *)((u8 *)arg0 + 0x2) + 1; +} diff --git a/.run/P36/agents/md_SC07_004__func_801AC9CC/history.txt b/.run/P36/agents/md_SC07_004__func_801AC9CC/history.txt new file mode 100644 index 000000000..ca08db96c --- /dev/null +++ b/.run/P36/agents/md_SC07_004__func_801AC9CC/history.txt @@ -0,0 +1,14 @@ +s5: verdict NO-MATCH start 10 best 2 compiles 176 path R18 bystander @8750->8746 +best-scoring single candidates of the last trace (move -> score [residual class]): + R18 bystander @8750->8746 -> 2 [ORDER] (from 10) + R18 bystander @8750->8747 -> 2 [ORDER] (from 10) + R18 bystander @8750->8748 -> 2 [ORDER] (from 10) + R7 block @8747 -> 2 [ORDER] (from 2) + R8 temp tmp0 @8747 -> 2 [ORDER] (from 2) + R12 width a3 u16->s32 @8739 -> 2 [ORDER] (from 2) + R10 param-copy arg0 @8740 -> 2 [ORDER] (from 2) + R6 inline v0 @8750 -> 2 [ORDER] (from 2) + R8 base tmp0 @8747 -> 2 [ORDER] (from 2) + R12 width a3 u16->s16 @8739 -> 2 [ORDER] (from 2) + R7 block @8741 -> 2 [ORDER] (from 2) + R8 temp tmp0 @8741 -> 2 [ORDER] (from 2) diff --git a/.run/P36/agents/md_SC07_004__func_801AC9CC/neighbours.txt b/.run/P36/agents/md_SC07_004__func_801AC9CC/neighbours.txt new file mode 100644 index 000000000..02091e67b --- /dev/null +++ b/.run/P36/agents/md_SC07_004__func_801AC9CC/neighbours.txt @@ -0,0 +1,3 @@ +--- every @class/@stuck/@crack note in this translation unit --- +// @class: loose-typing +// @stuck: none — MATCH (99 ins). short* for param_2/param_3: gcc emits lh where sign is live (<<1 for signed div), lhu where truncated to short (arith result / direct copy) diff --git a/.run/P36/agents/md_SC07_004__func_801AC9CC/related.txt b/.run/P36/agents/md_SC07_004__func_801AC9CC/related.txt new file mode 100644 index 000000000..732a8cc08 --- /dev/null +++ b/.run/P36/agents/md_SC07_004__func_801AC9CC/related.txt @@ -0,0 +1,87 @@ +=== lever-free bodies in md_SC07_004 sharing a callee or global with func_801AC9CC (9 found; top 6 by shared symbols) — read them for the SHAPE === +--- func_801AEAE4 (src/md_SC07_004/md_SC07_004.c:10300) shares 1: func_80016714 --- +void func_801AEAE4(void *a0) { + func_80016714(a0, 0x24); +} + +--- func_801A63A8 (src/md_SC07_004/md_SC07_004.c:4195) shares 1: func_80016714 --- +void func_801A63A8(void *arg0) { + void *temp_a0; + + temp_a0 = *(void **)((char *)arg0 + 0xCC); + if (temp_a0 != NULL) { + func_80016714(temp_a0, 0x38); + } + func_8012C218(arg0); +} + +--- func_801A9954 (src/md_SC07_004/md_SC07_004.c:6537) shares 1: func_80016714 --- +void func_801A9954(void *arg0) { + void *temp_a0; + + temp_a0 = *(void **)((char *)arg0 + 0xD0); + if (temp_a0 != NULL) { + func_801439C0(temp_a0); + } + temp_a0 = *(void **)((char *)arg0 + 0xCC); + func_80016714(temp_a0, 0x38); + func_8012C218(arg0); +} + +--- func_801A9EB0 (src/md_SC07_004/md_SC07_004.c:6769) shares 1: func_8017D7D4 --- +void func_801A9EB0(void *arg0) { + void *s2; + s8 sp10[0x20]; + s8 sp30[0x18]; + + func_801AA004(arg0, sp10); + func_8012AD80((s32)arg0); + func_8012AD80((s32)arg0); + func_801AA210(arg0, sp10, sp30); + s2 = &D_801B077C; + *(s32 *)((u8 *)arg0 + 0xCC) = func_8017D7D4(sp30, sp30 + 8, s2, 12); + *(s32 *)((u8 *)arg0 + 0xD0) = func_8017D7D4(sp30, sp30 + 0x10, s2, 12); + *(s32 *)((u8 *)arg0 + 0x1C) = 0x30; + func_8012AD44((s32 *)arg0, 1); +} + +--- func_801AC0D4 (src/md_SC07_004/md_SC07_004.c:8331) shares 1: func_80016714 --- +void func_801AC0D4(void *arg0) { + void *s0; + s16 val; + + s0 = *(void **)((char *)arg0 + 0xCC); + func_80128ED8((s32)s0, (s32 *)((char *)arg0 + 0xF0)); + + val = *(s16 *)((char *)s0 + 0x1A); + if (val >= 0x1801) { + *(s16 *)((char *)s0 + 0x1A) = val - 0x400; + } + + if (func_8012BEE8((s32)arg0) != 0) { + func_80016714(*(void **)((char *)arg0 + 0xCC), 0x38); + func_8012C218(arg0); + } +} + +--- func_801A6FD4 (src/md_SC07_004/md_SC07_004.c:4757) shares 1: func_8017D7D4 --- +void func_801A6FD4(void *arg0) { + void *s1; + s32 v0; + + s1 = *(void **)((u8 *)arg0 + 0xCC); + func_801A5C44(); + func_801A5B5C(arg0); + + if ((D_8019FF8A & 4) && *(s16 *)((u8 *)arg0 + 0xFE) == 0xB) { + func_801A5AC0(arg0); + func_801A5D68(arg0); + func_801A5CE8(arg0); + D_801F8747[0] = 1; + v0 = func_8017D7D4(D_801F88A8, D_801F88B0, D_801F8747 - 3, 6); + *(s32 *)((u8 *)arg0 + 0xD0) = v0; + } else if ((D_8019FF8A & 0x10) && *(s32 *)((u8 *)s1 + 4) >= 0 && (D_800B99DA & 1)) { + func_801A6428(arg0); + } +} + diff --git a/.run/P36/agents/md_SC07_004__func_801AC9CC/residual.txt b/.run/P36/agents/md_SC07_004__func_801AC9CC/residual.txt new file mode 100644 index 000000000..53be3f4c5 --- /dev/null +++ b/.run/P36/agents/md_SC07_004__func_801AC9CC/residual.txt @@ -0,0 +1,18 @@ +src/md_SC07_004/md_SC07_004.c:func_801AC9CC: score 10 (COUNT; mine 48 ins, target 47) — not yet + replace mine[0:2] target[0:2] + 0 addiu sp,sp,-48 | addiu sp,sp,-40 + 1 sw s0,40(sp) | sw s0,32(sp) + replace mine[3:4] target[3:4] + 3 sw ra,44(sp) | sw ra,36(sp) + replace mine[21:22] target[21:22] + 21 nop | lhu a3,48(s0) + replace mine[23:24] target[23:24] + 23 move a3,v0 | addiu a0,sp,16 + delete mine[25:26] target[25:25] + 25 addiu a0,sp,16 | -- + replace mine[36:37] target[35:36] + 36 j c838 | j c834 + replace mine[43:46] target[42:45] + 43 lw ra,44(sp) | lw ra,36(sp) + 44 lw s0,40(sp) | lw s0,32(sp) + 45 addiu sp,sp,48 | addiu sp,sp,40 diff --git a/.run/P36/agents/md_SC07_004__func_801AC9CC/sites.txt b/.run/P36/agents/md_SC07_004__func_801AC9CC/sites.txt new file mode 100644 index 000000000..3e1fe1205 --- /dev/null +++ b/.run/P36/agents/md_SC07_004__func_801AC9CC/sites.txt @@ -0,0 +1 @@ +NEEDED barrier memory line 8771 diff --git a/.run/P36/agents/md_SC07_004__func_801AC9CC/tu.txt b/.run/P36/agents/md_SC07_004__func_801AC9CC/tu.txt new file mode 100644 index 000000000..2a1b72edf --- /dev/null +++ b/.run/P36/agents/md_SC07_004__func_801AC9CC/tu.txt @@ -0,0 +1,2 @@ +src/md_SC07_004/md_SC07_004.c +func_801AC9CC diff --git a/.run/P36/agents/md_SC07_004__func_801AD068/body_free.c b/.run/P36/agents/md_SC07_004__func_801AD068/body_free.c new file mode 100644 index 000000000..5e513769b --- /dev/null +++ b/.run/P36/agents/md_SC07_004__func_801AD068/body_free.c @@ -0,0 +1,50 @@ +void func_801AD068(void *arg0) { + if (func_8012BEE8((s32)arg0) != 0) { + func_80016714(*(void **)((u8 *)arg0 + 0xCC), 0x38); + func_80016714(*(void **)((u8 *)arg0 + 0xD0), 0x38); + func_8012C218(arg0); + } else { + /* target keeps this guard value in $v1; unpinned it lands in $a0 (5 mismatches) */ + s32 v1 = *(s32 *)((u8 *)arg0 + 0x1C); + s32 t; /* address-taken => lives in 0x10($sp); every assignment is a real store */ + s32 *p; + + if (v1 < 15) { + s32 v0; + + /* arms textually swapped vs. the natural reading so gcc emits the real + `j .L801AD0D8` + delay slot instead of a delay-slot-fused shortcut */ + if (v1 >= 12) { + v0 = 0xF - v1; + v0 = v0 << 5; + } else { + v0 = v1 << 3; + } + func_80016450(v0 & 0xF8, 1); + } + + *(u16 *)((u8 *)*(void **)((u8 *)arg0 + 0x20) + 0x18) += 0x1C0; + *(u16 *)((u8 *)*(void **)((u8 *)arg0 + 0x20) + 0x1C) = + *(u16 *)((u8 *)*(void **)((u8 *)arg0 + 0x20) + 0x18); + *(u16 *)((u8 *)*(void **)((u8 *)arg0 + 0x20) + 0x1A) += 0x80; + *(u16 *)((u8 *)*(void **)((u8 *)arg0 + 0x20) + 0x12) += 0x100; + + func_801ADE1C(D_801B07F0, (u16 *)D_801F8A98, (s8 *)D_801F8AB8, (u8 *)D_801F8AE8); + + /* the two write-backs are ASYMMETRIC IN THE TARGET and the asymmetry is spelled here: + D_801F8D18 is reached through a NAMED POINTER LOCAL, so its address is materialised + (lui+addiu $a0) before the read and the read folds onto it (`lw 0($a0)`), sharing one + base with the swl/swr. D_801F8D58 is named bare, so the read %lo-folds + (`lw %lo(D_801F8D58)($v0)`) and the store re-materialises its own base ($a1). */ + p = &D_801F8D18; + t = *p; + t -= ((Obj_801AD068 *)arg0)->dE0; + *(Align1W_801AD068 *)p = *(Align1W_801AD068 *)&t; + func_801AD220(arg0, *(void **)((u8 *)arg0 + 0xCC)); + + t = D_801F8D58; + t -= ((Obj_801AD068 *)arg0)->dE4; + *(Align1W_801AD068 *)&D_801F8D58 = *(Align1W_801AD068 *)&t; + func_801AD220(arg0, *(void **)((u8 *)arg0 + 0xD0)); + } +} diff --git a/.run/P36/agents/md_SC07_004__func_801AD068/body_tree.c b/.run/P36/agents/md_SC07_004__func_801AD068/body_tree.c new file mode 100644 index 000000000..2de10ece4 --- /dev/null +++ b/.run/P36/agents/md_SC07_004__func_801AD068/body_tree.c @@ -0,0 +1,50 @@ +void func_801AD068(void *arg0) { + if (func_8012BEE8((s32)arg0) != 0) { + func_80016714(*(void **)((u8 *)arg0 + 0xCC), 0x38); + func_80016714(*(void **)((u8 *)arg0 + 0xD0), 0x38); + func_8012C218(arg0); + } else { + /* target keeps this guard value in $v1; unpinned it lands in $a0 (5 mismatches) */ + register s32 v1 __asm__("$3") = *(s32 *)((u8 *)arg0 + 0x1C); // !FAKE: pin $3 — NEEDED DIFFERS (P36 rung B tus9) + s32 t; /* address-taken => lives in 0x10($sp); every assignment is a real store */ + s32 *p; + + if (v1 < 15) { + s32 v0; + + /* arms textually swapped vs. the natural reading so gcc emits the real + `j .L801AD0D8` + delay slot instead of a delay-slot-fused shortcut */ + if (v1 >= 12) { + v0 = 0xF - v1; + v0 = v0 << 5; + } else { + v0 = v1 << 3; + } + func_80016450(v0 & 0xF8, 1); + } + + *(u16 *)((u8 *)*(void **)((u8 *)arg0 + 0x20) + 0x18) += 0x1C0; + *(u16 *)((u8 *)*(void **)((u8 *)arg0 + 0x20) + 0x1C) = + *(u16 *)((u8 *)*(void **)((u8 *)arg0 + 0x20) + 0x18); + *(u16 *)((u8 *)*(void **)((u8 *)arg0 + 0x20) + 0x1A) += 0x80; + *(u16 *)((u8 *)*(void **)((u8 *)arg0 + 0x20) + 0x12) += 0x100; + + func_801ADE1C(D_801B07F0, (u16 *)D_801F8A98, (s8 *)D_801F8AB8, (u8 *)D_801F8AE8); + + /* the two write-backs are ASYMMETRIC IN THE TARGET and the asymmetry is spelled here: + D_801F8D18 is reached through a NAMED POINTER LOCAL, so its address is materialised + (lui+addiu $a0) before the read and the read folds onto it (`lw 0($a0)`), sharing one + base with the swl/swr. D_801F8D58 is named bare, so the read %lo-folds + (`lw %lo(D_801F8D58)($v0)`) and the store re-materialises its own base ($a1). */ + p = &D_801F8D18; + t = *p; + t -= ((Obj_801AD068 *)arg0)->dE0; + *(Align1W_801AD068 *)p = *(Align1W_801AD068 *)&t; + func_801AD220(arg0, *(void **)((u8 *)arg0 + 0xCC)); + + t = D_801F8D58; + t -= ((Obj_801AD068 *)arg0)->dE4; + *(Align1W_801AD068 *)&D_801F8D58 = *(Align1W_801AD068 *)&t; + func_801AD220(arg0, *(void **)((u8 *)arg0 + 0xD0)); + } +} diff --git a/.run/P36/agents/md_SC07_004__func_801AD068/history.txt b/.run/P36/agents/md_SC07_004__func_801AD068/history.txt new file mode 100644 index 000000000..d9319a6cc --- /dev/null +++ b/.run/P36/agents/md_SC07_004__func_801AD068/history.txt @@ -0,0 +1,14 @@ +s5: verdict NO-MATCH start 5 best 5 compiles 190 path +best-scoring single candidates of the last trace (move -> score [residual class]): + R8 temp tmp0 @9081 -> 5 [REG] (from 5) + R18 bystander @9120->9122 -> 5 [REG] (from 5) + R10 param-copy arg0 @9079 -> 5 [REG] (from 5) + R7 block @9095 -> 5 [REG] (from 5) + R8 base tmp0 @9081 -> 5 [REG] (from 5) + R7 do-while @9095 -> 5 [REG] (from 5) + R7 block @9096 -> 5 [REG] (from 5) + R8 temp tmp0 @9080 -> 5 [REG] (from 5) + R7 do-while @9096 -> 5 [REG] (from 5) + R8 base tmp0 @9080 -> 5 [REG] (from 5) + R7 block @9082 -> 5 [REG] (from 5) + R7 do-while @9082 -> 5 [REG] (from 5) diff --git a/.run/P36/agents/md_SC07_004__func_801AD068/neighbours.txt b/.run/P36/agents/md_SC07_004__func_801AD068/neighbours.txt new file mode 100644 index 000000000..02091e67b --- /dev/null +++ b/.run/P36/agents/md_SC07_004__func_801AD068/neighbours.txt @@ -0,0 +1,3 @@ +--- every @class/@stuck/@crack note in this translation unit --- +// @class: loose-typing +// @stuck: none — MATCH (99 ins). short* for param_2/param_3: gcc emits lh where sign is live (<<1 for signed div), lhu where truncated to short (arith result / direct copy) diff --git a/.run/P36/agents/md_SC07_004__func_801AD068/related.txt b/.run/P36/agents/md_SC07_004__func_801AD068/related.txt new file mode 100644 index 000000000..13f2687ad --- /dev/null +++ b/.run/P36/agents/md_SC07_004__func_801AD068/related.txt @@ -0,0 +1,176 @@ +=== lever-free bodies in md_SC07_004 sharing a callee or global with func_801AD068 (31 found; top 6 by shared symbols) — read them for the SHAPE === +--- func_801ACE5C (src/md_SC07_004/md_SC07_004.c:8942) shares 4: D_801F8AB8 D_801F8AE8 D_801F8D18 D_801F8D58 --- +void func_801ACE5C(void *a0) { + /* §160a / §48-C2: align-1 4-byte block copy => lwl/lwr + swl/swr */ + typedef struct { char c[4]; } Blk4; + extern s32 D_801A0218; + extern s32 D_801A021C; + extern s32 D_801A0220; + + s32 v0; + s32 v1; + s32 s1; + s32 t; + void *p; + + v0 = func_8012C1B8(); + *(s32 *)((s32)a0 + 0x20) = v0; + if (v0 == 0) { + func_8012CAE4(a0); + return; + } + func_8001C214(v0, (s32)D_801F0C90); + + *(u16 *)(*(s32 *)((s32)a0 + 0x20) + 0x2C) |= 0x10; + *(s32 *)(*(s32 *)((s32)a0 + 0x20) + 0x4) |= 0x40; + + v1 = *(s32 *)((s32)a0 + 0x20); + *(s16 *)(v1 + 0x1C) = 0x200; + *(s16 *)(v1 + 0x18) = 0x200; + + *(s16 *)(*(s32 *)((s32)a0 + 0x20) + 0x1A) = 0x300; + + t = *(u16 *)(*(s32 *)((s32)a0 + 0x64) + 0xA); + *(u16 *)((s32)a0 + 0xE) += 0x20; + *(s16 *)((s32)a0 + 0x52) = -0x200 - t; + func_801ADD98(D_801F8A78, D_801F8AB8, D_801F8AE8); + + s1 = func_8001D074(0x7E, 0x100); + *(s32 *)((s32)a0 + 0xCC) = s1; + if (s1 != 0) { + p = (void *)&D_801F8D18; + func_800233CC(p, 0x80); + *(Blk4 *)p = *(Blk4 *)&D_801A0218; + *(s32 *)((s32)a0 + 0xE0) = 0x20C; + *(Blk4 *)&D_801F8D1C = *(Blk4 *)&D_801A021C; + func_8001CD9C(s1, (s32)p); + *(u16 *)(s1 + 0x2C) = 0xC100; + *(s32 *)(s1 + 0x4) = 0x50000000; + } + + s1 = func_8001D074(0x7E, 0x100); + *(s32 *)((s32)a0 + 0xD0) = s1; + if (s1 != 0) { + p = (void *)&D_801F8D58; + func_800233CC(p, 0x60); + *(Blk4 *)p = *(Blk4 *)&D_801A0220; + *(s32 *)((s32)a0 + 0xE4) = 0xC02; + *(Blk4 *)&D_801F8D5C = *(Blk4 *)&D_801A021C; + func_8001CD9C(s1, (s32)p); + *(u16 *)(s1 + 0x2C) = 0xC100; + *(s32 *)(s1 + 0x4) = 0x50000000; + } + + *(s32 *)((s32)a0 + 0x1C) = 0x10; + func_8012AD50(a0); +} + +--- func_801AC0D4 (src/md_SC07_004/md_SC07_004.c:8331) shares 3: func_80016714 func_8012BEE8 func_8012C218 --- +void func_801AC0D4(void *arg0) { + void *s0; + s16 val; + + s0 = *(void **)((char *)arg0 + 0xCC); + func_80128ED8((s32)s0, (s32 *)((char *)arg0 + 0xF0)); + + val = *(s16 *)((char *)s0 + 0x1A); + if (val >= 0x1801) { + *(s16 *)((char *)s0 + 0x1A) = val - 0x400; + } + + if (func_8012BEE8((s32)arg0) != 0) { + func_80016714(*(void **)((char *)arg0 + 0xCC), 0x38); + func_8012C218(arg0); + } +} + +--- func_801ABFF8 (src/md_SC07_004/md_SC07_004.c:8296) shares 3: func_80016714 func_8012BEE8 func_8012C218 --- +void func_801ABFF8(void *arg0) { + s32 s1; + s16 val; + + s1 = *(s32 *)((char *)arg0 + 0xCC); + func_80128ED8(s1, (s32 *)((char *)arg0 + 0xF0)); + + val = *(s16 *)((char *)s1 + 0x1A); + if (val >= 0x1801) { + *(s16 *)((char *)s1 + 0x1A) = val - 0x400; + } + + if (func_8012BEE8((s32)arg0) != 0) { + ((void (*)(s32, s32))func_801A9454)((s32)arg0, 0x10); + func_80016714(*(void **)((char *)arg0 + 0xCC), 0x38); + func_8012C218(arg0); + if (--D_801F8E98 == 0) { + func_8002D4C8(4, 0xABD); + } + } else { + if ((*(s32 *)((char *)arg0 + 0x1C) & 7) == 0) { + ((void (*)(s32, s32))func_801A9454)((s32)arg0, 0); + } + func_801A9378(arg0); + } +} + +--- func_801A7604 (src/md_SC07_004/md_SC07_004.c:4992) shares 3: func_80016714 func_8012BEE8 func_8012C218 --- +void func_801A7604(void *arg0) { + s16 idx; + + switch (*(u16 *)((u8 *)arg0 + 0x34)) { + case 0: + idx = *(s16 *)((u8 *)arg0 + 0x70); + *(u16 *)((u8 *)arg0 + 0xFE) += *(u16 *)(D_801B0368 + idx * 8); + idx = *(s16 *)((u8 *)arg0 + 0x70); + *(u16 *)((u8 *)arg0 + 0x100) += *(u16 *)(D_801B036A + idx * 8); + idx = *(s16 *)((u8 *)arg0 + 0x70); + *(u16 *)((u8 *)arg0 + 0x102) += *(u16 *)(D_801B036C + idx * 8); + func_801AB21C(1, *(u8 *)((u8 *)arg0 + 0xFF), *(u8 *)((u8 *)arg0 + 0x101), *(u8 *)((u8 *)arg0 + 0x103)); + if (func_8012BEE8((s32)arg0) != 0) { + *(s32 *)((u8 *)arg0 + 0x1C) = 8; + *(u16 *)((u8 *)arg0 + 0x34) = *(u16 *)((u8 *)arg0 + 0x34) + 1; + } + break; + case 1: + idx = *(s16 *)((u8 *)arg0 + 0x70); + *(u16 *)((u8 *)arg0 + 0xFE) -= (s16)(*(u16 *)(D_801B0368 + idx * 8)) >> 1; + idx = *(s16 *)((u8 *)arg0 + 0x70); + *(u16 *)((u8 *)arg0 + 0x100) -= (s16)(*(u16 *)(D_801B036A + idx * 8)) >> 1; + idx = *(s16 *)((u8 *)arg0 + 0x70); + *(u16 *)((u8 *)arg0 + 0x102) -= (s16)(*(u16 *)(D_801B036C + idx * 8)) >> 1; + func_801AB21C(1, *(u8 *)((u8 *)arg0 + 0xFF), *(u8 *)((u8 *)arg0 + 0x101), *(u8 *)((u8 *)arg0 + 0x103)); + if (func_8012BEE8((s32)arg0) != 0) { + if (*(void **)((u8 *)arg0 + 0xCC) != NULL) { + func_80016714(*(void **)((u8 *)arg0 + 0xCC), 0x38); + } + if (*(void **)((u8 *)arg0 + 0xD0) != NULL) { + func_80016714(*(void **)((u8 *)arg0 + 0xD0), 0x38); + } + if (*(void **)((u8 *)arg0 + 0xD4) != NULL) { + func_80016714(*(void **)((u8 *)arg0 + 0xD4), 0x38); + } + func_8012C218(arg0); + } + break; + } +} + +--- func_801AC54C (src/md_SC07_004/md_SC07_004.c:8522) shares 2: func_8012BEE8 func_8012C218 --- +void func_801AC54C(s32 param_1) { + if (func_8012BEE8(param_1) != 0) { + func_8012C218((void *)param_1); + } else { + func_801A9B80(&D_801F8A58, 0x160, 0x157); + } +} + +--- func_801A63A8 (src/md_SC07_004/md_SC07_004.c:4195) shares 2: func_80016714 func_8012C218 --- +void func_801A63A8(void *arg0) { + void *temp_a0; + + temp_a0 = *(void **)((char *)arg0 + 0xCC); + if (temp_a0 != NULL) { + func_80016714(temp_a0, 0x38); + } + func_8012C218(arg0); +} + diff --git a/.run/P36/agents/md_SC07_004__func_801AD068/residual.txt b/.run/P36/agents/md_SC07_004__func_801AD068/residual.txt new file mode 100644 index 000000000..434e85896 --- /dev/null +++ b/.run/P36/agents/md_SC07_004__func_801AD068/residual.txt @@ -0,0 +1,12 @@ +src/md_SC07_004/md_SC07_004.c:func_801AD068: score 5 (REG-caller; mine 95 ins, target 95) — not yet + register pairs (mine -> target, count): a0->v1 x5 + replace mine[17:18] target[17:18] + 17 lw a0,28(s0) | lw v1,28(s0) + replace mine[19:20] target[19:20] + 19 slti v0,a0,15 | slti v0,v1,15 + replace mine[21:22] target[21:22] + 21 slti v0,a0,12 | slti v0,v1,12 + replace mine[24:25] target[24:25] + 24 subu v0,v0,a0 | subu v0,v0,v1 + replace mine[27:28] target[27:28] + 27 sll v0,a0,0x3 | sll v0,v1,0x3 diff --git a/.run/P36/agents/md_SC07_004__func_801AD068/sites.txt b/.run/P36/agents/md_SC07_004__func_801AD068/sites.txt new file mode 100644 index 000000000..b1338fc9e --- /dev/null +++ b/.run/P36/agents/md_SC07_004__func_801AD068/sites.txt @@ -0,0 +1 @@ +NEEDED pin $3 line 9106 diff --git a/.run/P36/agents/md_SC07_004__func_801AD068/tu.txt b/.run/P36/agents/md_SC07_004__func_801AD068/tu.txt new file mode 100644 index 000000000..0dc626e58 --- /dev/null +++ b/.run/P36/agents/md_SC07_004__func_801AD068/tu.txt @@ -0,0 +1,2 @@ +src/md_SC07_004/md_SC07_004.c +func_801AD068 diff --git a/.run/P36/agents/md_SC07_004__func_801AE82C/body_free.c b/.run/P36/agents/md_SC07_004__func_801AE82C/body_free.c new file mode 100644 index 000000000..2ad0b4613 --- /dev/null +++ b/.run/P36/agents/md_SC07_004__func_801AE82C/body_free.c @@ -0,0 +1,29 @@ +void func_801AE82C(s32 a0) { + s32 cnt; + s32 v1; + s32 t; + s32 w; + s32 frame_pad[1]; + + (void)&frame_pad; + + cnt = *(s32 *)((s32)a0 + 0x1C); + v1 = *(s32 *)((s32)a0 + 0x34); + if (cnt != 0) { + *(s32 *)((s32)a0 + 0x1C) = cnt - 1; + } else { + t = *(s16 *)(v1 + 0xC); + w = t + 0; + if (t < 0x1000) { + t = w + 0x400; + *(s16 *)(v1 + 0xC) = t; + *(s16 *)(v1 + 0x10) = t; + } else { + *(u16 *)((s32)a0 + 2) += 1; + *(s32 *)((s32)a0 + 0x1C) = 0x48; + } + } + if (*(s32 *)((s32)a0 + 0x1C) & 1) { + func_801ADA10(a0); + } +} diff --git a/.run/P36/agents/md_SC07_004__func_801AE82C/body_tree.c b/.run/P36/agents/md_SC07_004__func_801AE82C/body_tree.c new file mode 100644 index 000000000..bfe962e54 --- /dev/null +++ b/.run/P36/agents/md_SC07_004__func_801AE82C/body_tree.c @@ -0,0 +1,30 @@ +void func_801AE82C(s32 a0) { + register u32 zr __asm__("$0"); // !FAKE: pin $0 — NEEDED DIFFERS (P36 rung B tus9) + s32 cnt; + s32 v1; + s32 t; + s32 w; + s32 frame_pad[1]; + + (void)&frame_pad; + + cnt = *(s32 *)((s32)a0 + 0x1C); + v1 = *(s32 *)((s32)a0 + 0x34); + if (cnt != 0) { + *(s32 *)((s32)a0 + 0x1C) = cnt - 1; + } else { + t = *(s16 *)(v1 + 0xC); + w = t + zr; + if (t < 0x1000) { + t = w + 0x400; + *(s16 *)(v1 + 0xC) = t; + *(s16 *)(v1 + 0x10) = t; + } else { + *(u16 *)((s32)a0 + 2) += 1; + *(s32 *)((s32)a0 + 0x1C) = 0x48; + } + } + if (*(s32 *)((s32)a0 + 0x1C) & 1) { + func_801ADA10(a0); + } +} diff --git a/.run/P36/agents/md_SC07_004__func_801AE82C/history.txt b/.run/P36/agents/md_SC07_004__func_801AE82C/history.txt new file mode 100644 index 000000000..4f4186e34 --- /dev/null +++ b/.run/P36/agents/md_SC07_004__func_801AE82C/history.txt @@ -0,0 +1,14 @@ +s5: verdict NO-MATCH start 9 best 5 compiles 181 path R12 width t s32->u16 @10192 +best-scoring single candidates of the last trace (move -> score [residual class]): + R12 width t s32->u16 @10192 -> 5 [COUNT] (from 9) + R12 width t s32->s16 @10192 -> 5 [COUNT] (from 9) + R12 width w s32->u16 @10193 -> 5 [COUNT] (from 9) + R12 width w s32->u8 @10193 -> 5 [COUNT] (from 9) + R8 temp tmp0 @10198 -> 5 [COUNT] (from 5) + R18 bystander @10196->10198 -> 5 [COUNT] (from 5) + R7 block @10196 -> 5 [COUNT] (from 5) + R9 swap-stmts @10198 -> 5 [COUNT] (from 5) + R10 param-copy a0 @10195 -> 5 [COUNT] (from 5) + R8 base tmp0 @10198 -> 5 [COUNT] (from 5) + R18 bystander @10196->10199 -> 5 [COUNT] (from 5) + R7 do-while @10196 -> 5 [COUNT] (from 5) diff --git a/.run/P36/agents/md_SC07_004__func_801AE82C/neighbours.txt b/.run/P36/agents/md_SC07_004__func_801AE82C/neighbours.txt new file mode 100644 index 000000000..02091e67b --- /dev/null +++ b/.run/P36/agents/md_SC07_004__func_801AE82C/neighbours.txt @@ -0,0 +1,3 @@ +--- every @class/@stuck/@crack note in this translation unit --- +// @class: loose-typing +// @stuck: none — MATCH (99 ins). short* for param_2/param_3: gcc emits lh where sign is live (<<1 for signed div), lhu where truncated to short (arith result / direct copy) diff --git a/.run/P36/agents/md_SC07_004__func_801AE82C/related.txt b/.run/P36/agents/md_SC07_004__func_801AE82C/related.txt new file mode 100644 index 000000000..f22d4cb1f --- /dev/null +++ b/.run/P36/agents/md_SC07_004__func_801AE82C/related.txt @@ -0,0 +1,11 @@ +=== lever-free bodies in md_SC07_004 sharing a callee or global with func_801AE82C (1 found; top 6 by shared symbols) — read them for the SHAPE === +--- func_801AE8B0 (src/md_SC07_004/md_SC07_004.c:10194) shares 1: func_801ADA10 --- +void func_801AE8B0(s32 a0) { + if (--*(s32 *)(a0 + 0x1C) == 0) { + *(u16 *)(a0 + 2) += 1; + } + if (*(s32 *)(a0 + 0x1C) & 1) { + func_801ADA10(a0); + } +} + diff --git a/.run/P36/agents/md_SC07_004__func_801AE82C/residual.txt b/.run/P36/agents/md_SC07_004__func_801AE82C/residual.txt new file mode 100644 index 000000000..46eab1550 --- /dev/null +++ b/.run/P36/agents/md_SC07_004__func_801AE82C/residual.txt @@ -0,0 +1,16 @@ +src/md_SC07_004/md_SC07_004.c:func_801AE82C: score 9 (COUNT; mine 32 ins, target 33) — not yet + register pairs (mine -> target, count): a1->v1 x4, v1->v0 x4, v1->a1 x1 + replace mine[3:4] target[3:4] + 3 lw a1,52(a0) | lw v1,52(a0) + replace mine[6:7] target[6:7] + 6 j e650 | j e654 + replace mine[8:9] target[8:9] + 8 lh v1,12(a1) | lh v0,12(v1) + replace mine[10:11] target[10:12] + 10 slti v0,v1,4096 | move a1,v0 + 11 -- | slti v0,v0,4096 + replace mine[12:16] target[13:17] + 12 addiu v1,v1,1024 | addiu v0,a1,1024 + 13 sh v1,12(a1) | sh v0,12(v1) + 14 j e650 | j e654 + 15 sh v1,16(a1) | sh v0,16(v1) diff --git a/.run/P36/agents/md_SC07_004__func_801AE82C/sites.txt b/.run/P36/agents/md_SC07_004__func_801AE82C/sites.txt new file mode 100644 index 000000000..54ea2b8da --- /dev/null +++ b/.run/P36/agents/md_SC07_004__func_801AE82C/sites.txt @@ -0,0 +1 @@ +NEEDED pin $0 line 10222 diff --git a/.run/P36/agents/md_SC07_004__func_801AE82C/tu.txt b/.run/P36/agents/md_SC07_004__func_801AE82C/tu.txt new file mode 100644 index 000000000..5cc8a478f --- /dev/null +++ b/.run/P36/agents/md_SC07_004__func_801AE82C/tu.txt @@ -0,0 +1,2 @@ +src/md_SC07_004/md_SC07_004.c +func_801AE82C