92 Commits

Author SHA1 Message Date
Drew T 545092d376 phase-37: T3 ☑ — the tools: tools/struct_layout.py (the o32 layout engine + the canonical-type writer in the final style + the naming invariant), tools/restruct.py's full form (rungs S/S2/S+A/X/R/D/L, the ledger, inflight restore, selftest 48 + --real 53), delever_oracle's LINKED mode (the build's own ld on the candidate object; f3 known-true + negative; the snapshot guard that caught T2's contaminated build/ object), include/common.h's reinterpret macros (proven equal on cc1's assembly), tools/restruct_cycle.sh (detached); rung D banked on ov_SC04_011 (258 units: 242 canonical / 8 K&R marked / 16 kept with causes); SETUP §P37 S107, dictionary rows, kit corpus, decision log + accelerators P37 S107, cookbook §458 addendum, story §10 + retrospective §7 + timeline | R22 check-all: 218 passed, 0 failed of 218 (r22_t3c) | 🛑 T4 NEXT (the declaration layer; P6 rules check first) 2026-09-12 10:04:16 -06:00
Drew T ea75e0f231 phase-37: CHECKPOINT for a fresh session — T0–T2 ☑; the record banked: decision log P37 S106 (struct spelling moves bytes; the /s per-access dial), accelerators P37 S106 (→ DK-65 corrected in the kit), cookbook §458 (the func_801814AC byte-read), the handoff and wiki 'byte-neutral' claims date-stamped; the 🛑 block rewritten with T3's full design brief, the counters, the probe's findings and every command | 🛑 T3 NEXT (the tools, Max design) 2026-09-12 08:09:29 -06:00
Drew T cd39c79de6 phase-37: T2 ☑ — the probe: rung 1 (struct spelling) byte-neutral on 126/139 judged bodies (90.6 %, 716 sites moved), rung S2 closes 13/13 DIFFERS with 27 casts kept (139/139); the definition's signature free for 4,473/4,828 (TU, callee) pairs (92.6 %, 0 DIFFERS; 355 compile refusals = K&R sites + multi-spellings); the definition fold 12/20 TUs clean (opaque folds need member renames); the layout engine cc1-validated on 5,283 definitions / 29,248 fields (0 rejected; two engine gaps fixed: nested-paren attributes, per-field aligned(N); 27 dead-guarded standalone blocks blanked); the relocation control (object DIFFERS, binary identical) proves T3's linked mode; engine_types.h fan-out 3,975 objects in 35 s; tools/restruct.py (--try/--probe/--probe-decls/--probe-defs/--audit-layouts/--fanout-cost) + SETUP + dictionary | 🛑 T3 NEXT (the tools, Max design) 2026-09-12 01:27:45 -06:00
Drew T da26c05d67 phase-37: T1 ☑ — tools/type_census.py + the struct map: 7,261 struct definitions (525 layouts, 206 duplicate classes / 2,789 names, 39 VARIANT), 503,016 raw pointer-cast dereferences in four forms (coverage OK; + 18,912 address-of, 36,681 typed cast-member), 98,648 lying declarations / 1,609 callees, 18,760 evidence-clustered types explaining 99.2 % of sites, 24 parked P36 classes in parked.tsv, controls 4/4; lever_census controls re-keyed and --strict made literal (6,717 direct GTE statements in bodies); progress.py types block + README sentence + 2 corrections; the readability series read by column name with 16 census columns; docs/struct-map.md; SETUP §P37 S106; dictionary row; kit corpus | 🛑 T2 NEXT (the probe, Max) 2026-09-11 23:54:15 -06:00
Drew T 79b2f6f150 chore(phase-36): CLOSE — levers off to the measured floor: 53,234 → 4,010 register pins + asm statements (−92.5 %), every survivor marked with its pass and its instrument and named for the structs phase; the GTE idiom in one header; 16,759 lying call declarations repaired; the lever and readability series published; 218/218 at every step (v2.2.0) 2026-09-11 22:45:24 -06:00
Drew T 47bb0e88cd phase-36: T9 — kit corpus regenerated after the record edits 2026-09-11 21:30:52 -06:00
Drew T 0fcf000c5a phase-36: T8 — kit_lint leak fixed (the delever_regen dictionary row named generator families as bare R-tokens); kit corpus regenerated 2026-09-11 21:06:06 -06:00
Drew T 1feaff5390 phase-36: S105 FINAL — f8 landed 5/5 plain C, R22 218/218 at 36be9acef, census 4,046 / 0 unmarked (exit 0), nothing in flight; 42/42 drawn classes at 0 this session; cookbook §457, accelerators + decision log P36 S105, kit corpus; checkpoint final | 🛑 T7 RUNNING 2026-09-11 18:25:35 -06:00
Drew T 2dbe59b61e phase-36: decision log P36 S104 (Drew's four rulings via sotn, the sweep-before-agent rule, the TU-batch lane, six instrument findings); kit corpus regenerated (tool_census --check OK) 2026-09-11 05:49:47 -06:00
Drew T 16411105e2 phase-36: kit corpus regenerated for the delever_regen and lever_census changes (tool_census --check OK, 0 gaps) 2026-09-10 20:59:56 -06:00
Drew T 433aa07018 phase-36: c50 closes func_80136824 with zero levers body-only (off the types-phase list, 130 bodies); c49 func_8013F350 at two marked head levers (133 bodies); delever_regen survives stale sites (R22 218/218) 2026-09-10 18:38:42 -06:00
Drew T aada3bdc2b phase-36: the first minimum-lever bank (func_80177B5C: 1 marked launder instead of 23 levers, 133 bodies); c43/c44/c45/c37 closes with their cross-address copies (delever --port-scan); generator R26 alias_repeated_addresses (known-true: c45's close from its start text) (R22 218/218) 2026-09-10 18:32:46 -06:00
Drew T 8bc06a2cb8 phase-36: T7 agent c42 — func_80186A8C and func_80182058 closed through cross-jump readings (10 bodies); related.txt requires evidence before calling a same-name body a variant (R22 218/218) 2026-09-10 18:17:41 -06:00
Drew T 321b540e7f phase-36: propagate ignores body-local externs (re-propagation: 97 siblings banked of 145 candidates); R19 cast-arity regen 8 classes; c39 ports two variants; c41, c34, c32 closes; related.txt lists the same function lever-free elsewhere; cc1_dumps_tu.sh -dd (R22 218/218) 2026-09-10 18:07:41 -06:00
Drew T 7d5964b279 phase-36: T7 agents c36 + c35 — four tier classes closed (func_8014305C, func_80141874, func_8017DBE4, func_80185994; 39 bodies); R19 reads the arity a call's own cast asserts (known-true: c35's close from its start text) (R22 218/218) 2026-09-10 17:49:55 -06:00
Drew T 01f066923d phase-36: re-draw c21 — func_801397B0 closed (a do-while reference-weight wrapper, on the a4/c15 precedent), 125 bodies; c22's and c28's readings (func_8012E364 at 4, func_8013F350's head irreducible); --try parallel-safe per call with --keep (R22 218/218) 2026-09-10 17:14:30 -06:00
Drew T e984e5822f phase-36: re-draws c25 (func_80166F58, a narrowing copy) and c26 (func_80133CD4, split temps) closed, 254 bodies; tools/localalloc_sim.py (c26's local-alloc simulator, 0 mismatches over 150 blocks); propagate no longer trusts stale ledger hashes; R25 regen 3 classes; regen reports COMPILE-ERROR (14,xxx -> 13,083 sites, R22 218/218) 2026-09-10 16:58:01 -06:00
Drew T 96820256ce phase-36: re-draws c24 (func_8012956C: a phantom 4th argument + a switch) and c23 (func_80133784: the exit block inside a real loop, overturning b4's de-loop reading) closed, 252 bodies; R25 trim_arguments; argcheck reads K&R definitions (95 callees were invisible); the selftest asserts every dispatched family is registered (R22 218/218) 2026-09-10 16:45:14 -06:00
Drew T a620e1880f phase-36: generator R24 (the addPrim copy read as a whole word, c20's move) + its regen pass (2 classes, the func_80140D68 header on 140 objects); c13's reading of func_80140958 (43 -> 4, not closed) (R22 218/218) 2026-09-10 15:57:16 -06:00
Drew T 9f2b6b24aa phase-36: cc1_dumps_tu.sh takes a .c file and resolves ../shared includes (six agents had written their own dump.sh) 2026-09-10 15:43:03 -06:00
Drew T 164825b5d8 phase-36: delever_regen — R22+R23 re-run over the whole residue closes 17 classes / 22 bodies with no agent; --try learns header TUs (24 classes had never been scorable) (17,715 → 17,692 sites, R22 218/218)
- tools/delever_regen.py: read-only pass (both starting texts, only the named families, delever_search --try --body,
  one worker per class) + --bank (re-score on the current tree, apply_body_core, propagate); dictionary + SETUP rows
- pass 1: 1169 classes in 127 s, 14 MATCH; the 25 UNSCORED read before banking: 24 were header-TU classes whose
  includer's ../shared include never resolved in --try (fixed; controlled: unchanged body 0, lever-free 32, mutated 1),
  1 a body-local #define (R22/R23 now refuse preprocessor lines); pass 2 over header TUs: 104 judged, 3 MATCH
- banked: 14/14 + 3/3 (two shared headers IDENTICAL on 141 objects each); R23 12 classes, R22 5
- check-all 218 passed 0 failed; lever_census 17,692 marked 0 UNMARKED
2026-09-10 15:36:01 -06:00
Drew T a060705725 phase-36: T7 agents c14 + c16 — func_801670E4 (all seven levers; its refuted @stuck note replaced in 136 copies) and func_8013D178 (one pointer per if-group), 261 bodies; R23 widened to one open block and now closes func_8013D178 alone; c9's reading of func_8013CF68 (38 -> 10, not closed) (18,776 → 17,715 sites, R22 218/218) 2026-09-10 15:24:01 -06:00
Drew T 6252516263 phase-36: T7 agent c11 — func_80175AB8 closed (derived-pointer reads, one temp for both $a1 values, a cast-wrapped table read), 124 bodies; cc1_dumps_tu.sh dumps .cse2 and .jump2 (R22 218/218) 2026-09-10 15:15:34 -06:00
Drew T e6a8f35052 phase-36: T7 agents c12 + c10 — the func_80148E54/D44 twins (implicit handler argument) and func_80135A4C (cross-jump tails, parameters passed through), 395 bodies; delever_pack writes related.txt (20,206 → 19,276 sites, R22 218/218)
- c12: c3's reading held on both twins — the angle as the handler's first argument + tmp reused as the later operand;
  the stale 'jalr with no args' comment corrected in the 135 files whose body now passes it
- c10: jump2 cross-jump merged two walk tails (exits now fall to the single final return), the s16 SUBREG gate, and
  func_80135480 called at its real arity; its answer was func_80135888 in another file
- delever_pack related.txt: lever-free bodies in the overlay sharing a func_/D_ symbol, ranked (known-true: top hit for
  func_80135A4C is func_80135888); METHOD_S103 +6 emitter entries; SETUP rows
- apply-body IDENTICAL x3, propagate 131/131 x2 + 133/133; check-all 218 passed 0 failed; lever_census 19,276 marked 0 UNMARKED
2026-09-10 15:03:27 -06:00
Drew T 2e61220bde phase-36: T7 wave c — seven agent closes (c4 c6 c1 c7 c3 c5 c8) + func_8017EEC0's parameter, ~1,000 bodies; generator R23; CI's verbatim_check fixed and wired into tools-health (23,988 → 20,206 sites, R22 218/218)
- closes, each --try 0 then apply-body IDENTICAL + propagate N/N 0 refused: func_80133AB0 (u16 width moves), func_80130D48
  (one call per goto-tail site), func_80135168 (reused temps split + H16 member store), func_80134A74 (widths + join
  statement in both arms), func_80148AFC (implicit handler argument + later operand), func_8015D738 (jump threading:
  re-read + a do-while on precedent, the class raised with Drew), func_80135004 (temp split + argument from its global)
- func_8017EEC0: the uninitialised a0v T4 tus10 left is the parameter (8/8, IDENTICAL)
- CI red since cb2fb5e6d: verbatim_check --strict saw the DECOMPILE-NOW row func_8017EEC0 converted; row removed (one
  row), --update keeps order + UTF-8 (proven equal to the hand fix), verbatim_check --strict now in make tools-health
- delever.split_reused_locals = family R23 (selftest + two refusals; known-true: joint split = the agents' measured 12/26)
- check-all 218 passed 0 failed (twice); lever_census 20,206 marked 0 UNMARKED; Drew: at most five concurrent agents
2026-09-10 14:56:17 -06:00
Drew T 205331765f phase-36: T7 agent c2 — func_8013D8FC closed (the walked-pointer merge), 131 bodies; harvested as generator R22 (24,119 → 23,988 sites, R22 218/218)
- agent c2 (Opus): a second pointer q = p + 5 stepped in lockstep with p kept a second biv alive (loop.c strength
  reduction, -dL 'Cannot eliminate biv'); one pointer lets combine_givs fold every field read onto one base
- bank: apply-body IDENTICAL, propagate 130/130, check-all 218 passed 0 failed, lever_census 23,988 marked 0 UNMARKED
- delever.merge_walked_pointers = family R22 (selftest + two refusal controls; known-true: the agent's start text's
  candidate is its closing body, --try score 0); leads the COUNT class after R19 in delever_search; SETUP row
- S103 opening: the method addendum .run/P36/agents/METHOD_S103.md; wave c launched (six agents); Fable out of credits,
  c5/c6 relaunched on Opus
2026-09-10 14:30:30 -06:00
Drew T f96af3e487 phase-36: agent b9's reading of func_8013F350 (70 to 16, not closed) and two pack defects it found
Not banked, and the agent said so itself: it solved the whole tail — instructions 32 to 489 of 490 byte-identical in
plain C with the $4 pin gone — by hoisting one statement above two derived pointers, a COLOURING move rather than a
scheduling one (the scheduler's RTL order is identical in both candidates, so the tree's header note blaming it
describes the assembly, not the RTL). The head is a proven wall: find_best_addr (cse.c:2663-2665) folds the base to an
absolute address because its only set is a symbol_ref, and its known-true control keeps its base in plain C only because
both uses are at offset 0. It then labelled its two remaining improvements COMPENSATING ERRORS — a width change that
deletes the target's real andi to cancel an extra instruction — and wrote 'nothing here is bankable' instead of handing
back a 16 dressed as progress.

Two pack defects fixed from its report:
- neighbours.txt carried the @class/@stuck LINES but not the header comment they sit in, and that comment is an
  eight-point English explanation of every lever in the body, including the tail crack stated outright. The pack now
  ships the target's own header in full. A grep for tags is not a substitute for the paragraph it sits in.
- history.txt's line numbers are relative to the evolving text, so reconstructing a path by hand lands elsewhere (b9
  reached 51 where the engine reproduces 16 in one round). The pack now ships the best candidate's text as best_body.c.
2026-09-10 13:52:15 -06:00
Drew T d30ccc9a72 phase-36: T7 agent b8 — func_80135888, the largest class left, closed with all five levers gone (134 bodies; 24,789 → 24,119 sites, R22 218/218)
check-all: 218 passed, 0 failed of 218
  lever_census --check: 24,119 pin/asm sites, 24,119 marked !FAKE, 0 UNMARKED — OK

Three moves, each predicted from a dump before it was compiled:
- while -> a guarded do-while (29 to 22). Cross-jump (jump.c:1969 -> find_cross_jump :2371, from toplev.c:3142) had
  matched the load in front of the jump against the one in front of the bottom test and deleted three instructions; the
  guarded form makes the two tails differ.
- the duplicated pre-loop call block -> goto (22 to 6). This is an allocno_compare rank move (global.c:585-611): the
  priority is floor_log2(refs)*refs/live, reg_n_refs is loop-weighted (flow.c:2067), the in-loop copy of that call is
  worth two references, and deleting the out-of-loop copy takes exactly one off — 8 to 7 crosses a floor_log2 step and
  drops the pointer's priority from 3157.9 to 1891.9. The predicted allocation order matched the dump exactly. The
  rewrite is byte-neutral on its own: reorg steals the target's first insn into the delay slot and retargets.
- the two-arm mask temp inlined (6 to 0): set in two arms it has two deaths, fails local-alloc.c:472, and combine_regs
  bails at :1774, so it went to global allocation and took its copy preference.

Harvested as R21 second_consumer, from agents b2 and b6 together: give a computed value a second consumer before its
copy, either by chaining (v = slot = E) or by hoisting the store above it. cse deletes such a copy only when the
producer sits immediately before it (cse.c:7440-7501, guard :7454-7460), and flow links only the FIRST following use
(flow.c:2076-2091), so a store in between defeats both. R9 can never produce it — the two statements share the
identifier, so its independence guard refuses the swap. Known-true: the joint form scores 0 on b6's pre-bank text, and
the single-site forms do not, which is the third measured case this session of a joint edit no hill-climb can reach.

Also recorded from b8, worth a pre-check later: declaration-order moves are PROVABLY DEAD on a register residual whose
allocnos have distinct priorities, because global.c:604-610 compares priority first and only ties by allocno number —
4,811 compiles of those candidates sat flat because of it.
2026-09-10 13:31:47 -06:00
Drew T 9d78fc4085 phase-36: T7 agent b3 — func_8016CBC0 closed from a residual of 55 (128 bodies), and its move toolified as R20
- the move: narrow every local in the counter's def-use chain together — the counter, its +/-1 temp and the copy-back —
  and do it for BOTH chains at once. Four instructions were MISSING, not miscoloured, three of them the moves the $0 pin
  was faking. insert_regs (cse.c:1029-1032, early bail :1018-1020) puts two pseudos in one equivalence class only when
  their MODES match, so an all-int copy-back is collapsed and swept, while the narrowed one is a truncation: no
  equivalence, the wide temp stays live and reaches reload as the move the target has. The fourth instruction is
  strength_reduce minting a shift giv from a wide counter whose every use is a cast; a HImode pseudo cannot be that giv.
  delever --propagate: 127 of 127 sibling(s) banked, 0 refused. 26,202 -> the census below.

- R20 narrow_chains: the agent PROVED the joint form is necessary, and the generator reproduces it. Single declarations
  scored 45/72/51/24, each chain alone 43, both chains together 0 — every intermediate worse than the search's own best
  of 11, so a beam over R12's one-declaration width moves cannot reach the answer from either side. Seven runs and 4,811
  compiles stalled at 11; R20 offers six candidates and the right one is a single compile.
- known-true check: run on b3's pre-bank text, R20's joint signed candidate scores 0 (MATCH) and its single-chain
  candidates score 43 and 51 — the agent's own hand-measured numbers, reproduced by the tool.
- chains are built conservatively from the body's text (two locals linked when one is assigned from the other, through a
  cast or a +/- constant), and only whole components are offered, so the partial narrowings the measurement showed are
  always worse are never generated. Selftest: the chain is found whole, an unlinked local is not pulled in, and a body
  with no linked pair offers nothing.
2026-09-10 12:57:06 -06:00
Drew T acba5c59df phase-36: T7 agent b1 — func_801651B8 closed on its FIRST try (127 bodies), and its lesson made part of every pack
- the move: delete the hand-walked pointer's self-increment and recompute p = &tbl[i] from the loop counter each
  iteration. The lever-free body had TWO induction variables — the loop dump says 'Cannot eliminate biv 73: biv used in
  insn 50' (loop.c:5976) because the pointer is itself a call argument — and combine_givs (loop.c:5494/:5527) then
  merged the three +12 field addresses into one giv whose benefit clears the not-worth-while gate at loop.c:3822-3828,
  reducing it to a THIRD walking register and forcing a fourth callee-saved one: the +4 instructions and the whole
  recolouring. Indexing instead leaves one biv, the +12 rides as an immediate, and the body is byte-identical.
  delever --propagate: 126 of 126 sibling(s) banked, 0 refused. 26,456 -> 26,202 sites.

- THE HEADLINE IS THE METHOD, not the crack: the answer was written in English thirty lines above, in the // @class:
  header of an already-matched sibling in the same file, which spells out 'recompute p = &D[i] each iteration (NOT p++)
  so gcc reduces base+i*0x10 into a SINGLE pointer IV'. The pack sent agents to the cookbook and to the compiler source
  and never to the target's own neighbours. This project has been leaving itself notes for months and nobody was reading
  them.
- delever_pack.py now writes PACK/neighbours.txt — the comment headers of the three matched functions either side of the
  target, plus every @class/@stuck/@crack note in the translation unit — and the brief makes reading it step 0.
2026-09-10 12:49:36 -06:00
Drew T dd744df53e phase-36: track readability_progress.py (the census's second oracle caught it untracked, R34)
tool_census's two enumerations disagreed on one file: the new tool was written but never added, so the dictionary row
existed for a path git did not carry. That is exactly the disagreement the second oracle is there to find.
2026-09-10 12:12:18 -06:00
Drew T f3de70fce5 phase-36: R19 — the argument-restore generator: call signatures become engine work, not agent work
Six T7 agents independently reached score 0 by restoring an argument the decompiled source had dropped, and no generator
could reach the class because every other family rewrites statements that exist while this changes a call's ARITY. R19
closes that gap without cracking anything: it finds every call whose in-scope declaration is narrower than the callee's
real definition, then offers one candidate per value already in scope (each parameter, each local declared before the
call) and lets the byte oracle pick. The missing argument is never inferred.

- known-true check: run on the pre-bank text of func_8017A3D8, which agent a12 solved by hand, R19 emits that agent's
  exact fix and --try scores it 0 (OTHER; mine 53 ins, target 53) — MATCH.
- two spellings were wrong before that passed. It took the return type from the DEFINITION and produced
  ((void (*)(s32))f)(a) != 0, which cannot compile because the defining TU says void where this one says int — it now
  repairs the arity only and keeps the TU's declared return type. And it required a simple statement, so it found
  nothing on the very body it was written from: these calls live in  and  far more often
  than in a plain statement.
- it also sees the cast-wrapped form ((s32 (*)(void))f)(), which is how m2c usually spells a dropped argument, and
  replaces the whole wrapper rather than nesting a second cast.
- ranked FIRST in every residual class: it emits candidates only for calls whose declaration provably disagrees with the
  definition, so it costs nothing when it does not apply. The engine selftest's ordering invariant is updated to say so
  rather than being widened again.
- argcheck now carries each definition's return type, which the cast route needs.
- selftest: two positive assertions and two controls (the declared return type is kept; the definition's is refused; a
  call inside a return statement is seen; a matching declaration offers nothing).
2026-09-10 11:13:34 -06:00
Drew T e76cb1c89e phase-36: fix the instrument four agents asked for — alloc_table now covers every pseudo and asserts its own coverage
tools/alloc_table.py had only ever printed pseudos that landed in $s0-$s7/$fp, and it depended on 'Register N in M.'
lines the dumps often do not emit — so two agents in the burst were handed an EMPTY or one-row table and read it as an
answer. That is the silently-narrowed-scope defect class: a true number about a scope far narrower than the reader
believes.

- it now prints every pseudo with refs, live length, block, conflicts, copy preferences and allocno_compare's priority,
  takes the hard register from either dump, and ASSERTS ITS COVERAGE against the .greg order line (R32) — a named gap and
  a non-zero exit instead of a confident subset. A missing dump section is refused loudly rather than printed as an
  empty table.
- documented honestly: .greg carries the INPUTS to global allocation (order, conflicts, preferences), not the final
  assignment, so a global allocno's hard register prints as '-'. That is the dump's shape, not a gap.
- verified on a real dump from an agent's pack: 4 pseudos, the order line, preferences and conflicts all parsed,
  coverage OK. The old tool would have printed nothing for it — none of the four is callee-saved.
- tools/cc1_dumps_tu.sh: add -I<the TU's own directory> (an agent found it silently preprocessing to 44 lines and
  exiting 0 on any TU with relative includes), add -dR for the post-reload schedule, and REFUSE a preprocess under 200
  lines instead of producing empty dumps.
- the agent brief now says to read the allocation table first for any register residual, that the .greg assignment is
  absent by design, and that the residual text cannot distinguish a missing instruction from wrong registers — one agent
  chased a register lever for hours when the defect was a cse store-to-load forward that had deleted a load.
2026-09-10 11:05:21 -06:00
Drew T fc7d8c4019 phase-36: T7 burst — a22 banked (126 bodies), a14 refused as an invented zero term, and the struct question answered on the record
- a22: func_8017B238 closed by giving the if-arm's pointer and the else arm's first table address one function-scope
  local. Three decisions turn on that edit, all dump-proven: make_regs_eqv's head rule (cse.c:840-857), set_preference
  stripping one RTX level so an arithmetic set inherits its operand's register (global.c:1535), and combine_regs with
  birthing_insn_p's reg_n_sets == 1 (local-alloc.c:1765-1788, sched.c:2469) — which is why the merge must be with the
  else arm's non-call-crossing temp. 26,714 -> 26,462 sites.
- a14 reaches score 0 on func_80139BE0 but only by an INVENTED identically-zero term whose sole purpose is to keep a
  value live. NOT BANKED: an invented no-op expression is a compiler-forcing construct in C clothing, and worse than the
  marked launder it replaces because the launder is counted and this would be silent. The phase's own rule is ban the
  silence, not the lever. Parked for the structs/types phase with its reading; the tree comment above it ('no pure-C
  spelling survives that fold') is refuted.
- a6 corrects cookbook 455: cse1 (cse.c:7439-7502) rewrites the producer's destination to the copy's whenever the
  producer is the immediately preceding insn; combine only finishes the job once that adjacency is broken. It enumerated
  the three lever-free blockers can_combine_p admits and showed the body can pay for none, then scanned all 4,284 built
  objects for the shape — 101 hits, every lever-free precedent paying with a genuine second use, a narrow local with two
  consumers, or a join label.
- a24's residual was one absent load: cse forwards a just-stored halfword so no lh is emitted, and seven branch
  displacement mismatches were downstream of it. Its method gap is the instrument to fix next — three agents have now
  asked for local-alloc's quantity table in the pack, and alloc_table.py prints an empty or one-row table because it
  keys on dump lines that are often absent.
- Drew's struct question answered on the record: structs are not in the binary (types are erased; no metadata in a
  retail build), what is there is base + offset + width + stride, so a struct is an inference across every function
  touching a base — which makes per-function struct invention the wrong unit and is the failure P35 already recorded.
  Recommendation: keep pins as the main lane, build a zero-token struct evidence census beside it, park stuck pins with
  their evidence, and fix call signatures first because they are the bigger and cheaper blocker (471 narrow call sites
  in 323 pinned bodies). Measured: 372,224 raw cast dereferences against 92,624 struct member accesses.
2026-09-10 11:02:14 -06:00
Drew T 449acd8cb3 phase-36: T7 sweep s4 and the OUT-OF-BODY defect fixed at its cause (R14 refuses what the body-only bank cannot take)
search: 0 of 139 exemplars matched lever-free in 0.54 h (0 of 7,077 bodies behind them; 52,566 compiles) — NO-MATCH 136 · BANK-REFUSED 3

- the three refusals are the three fleet copies of func_80136824, each a real score 0 (R15 sink + R12 width + R14
  param-width) blocked by a contract rather than by a bad body: the engine verifies the whole candidate text but hands
  apply_body_core only the definition, and --propagate remaps that body to siblings, so a generator that edits lines
  outside the definition can never bank. R14 is the only such generator.
- my first diagnosis was wrong and was discarded rather than shipped: I guessed the conflicting declaration was in a
  shared header and built a 2,431-name index to refuse on, and the index said the function is not in it. Reading cmd_run
  gave the real answer.
- two fixes: param_widths refuses outright when the TU declares the function anywhere but at its definition
  (protos_outside_definition; the earlier R14 banks had no such prototype, so nothing that worked is lost), and the engine
  names the condition itself with a new OUT-OF-BODY verdict instead of letting the bank die on a compiler error that reads
  like a bad body. Controls both ways in the selftest.
- the steering measurement (R41): across s1-s4 the head's 57 classes have absorbed ~128,000 compiles for 6 closes, all of
  them R15's and all in the first sweep. The head is resistant to every mechanical generator at this width; sweeps pay on
  the tail and on targeted families, and the head is what agents are for.
- open by name for the types phase: func_80136824 (133 copies) has a real crack that needs its prototype widened with its
  definition — the second measured case where a declaration, not codegen, stands between us and the bytes.
2026-09-10 05:00:01 -06:00
Drew T d71836107c phase-36: T7 agent a3 — func_801397B0 not closed (best 2), its reading toolified as R18 the bystander move
The third agent produced no bank and a precise refutation plus a generator, which is the deliverable the brief asks for.

- it refuted the a2 hypothesis on its own body: git grep returns 1,770 declarations in two forms, both (s32 a0), no (void)
  anywhere, and the pin is on a local rather than the parameter. Three lever-free spellings reach the target's complete
  register assignment, so the class is reachable from plain C.
- its best is score 2, class ORDER, 89/89 instructions, every register correct, one displaced bystander store. The target's
  sw sits inside the lbu->addiu window and that position is forced: anti_dependence and true_dependence (sched.c:817/845)
  both hold, so the store can neither hoist nor sink. Post-sched1 stream and reg_live_length then match ours, leaving
  reg_n_refs — computed by flow on the pre-combine RTL — as the only remaining input.
- R18 moves one simple statement to each other position in its own block, up to six away. R9's adjacent swap is the special
  case; the distance is the point. It costs no instruction where R7's LOOP notes are a full sched1 barrier and always cost
  one displaced insn, so R18 is ranked ahead of R7 in every class.
- two wrong spellings before the known-true check passed: identifier-disjointness as a requirement offered three candidates
  and none of them the agent's (it is only an ordering preference now — byte-identical output is the same program, so the
  oracle is the whole correctness proof, which is R9's own footing), and a blank line counted as an obstacle, so the
  generator never offered the very move it was written from. It now reproduces that body exactly: bystander @21->17.
- delever_pack.py now writes each trace candidate's residual class beside its score, from the agent's method note: a bare
  number hid that a move had already turned this body's residual from REG into ORDER.
- delever --selftest OK (3 new controls incl. the nested-block refusal); delever_search --selftest OK; tool_census OK.
2026-09-10 04:26:00 -06:00
Drew T 975850ff84 phase-36: T7 toolify a2 — generators R16 (constant holder inlined) and R17 (constant-run split), the directed form of a move R9 reached only by luck
- R16 writes a local whose only assignment is one integer literal at every use and deletes it. R6 stops at a temp read
  exactly once, so a holder read four times was invisible to the search and its whole family with it. Deleting it is
  byte-neutral alone but removes a quantity from the block, which is what lets the next move reach the allocator.
- R17 splits a run of consecutive same-literal assignments by moving the nearest differently-valued one into it, at each
  interior split point. find_free_reg's live-range scan (local-alloc.c:2109-2110): while the two constants' ranges are
  disjoint they share a caller-saved register; splitting makes the first live across the second and it takes another colour.
- known-true check: on the seed that keeps func_80168828's semantically-forced $4 pin, R16 then R17 reaches
  score 0 (OTHER; mine 108 ins, target 108) — MATCH at three of the six offered split points, in ten compiles where the
  blind search needed 2,271.
- the engine selftest's caller-saved assertion is now the ordering invariant (every targeted lever before every blind
  family) rather than a fixed window widened once per new generator.
- delever --selftest OK (4 new controls); delever_search --selftest OK; tool_census --check OK; SETUP row (R21).
2026-09-10 01:27:20 -06:00
Drew T 861dd0651c phase-36: T7 toolify a1 — generator R15, the sink (agent a1's crack made mechanical; reproduces it from the pre-bank text at score 0)
The harvest half of the one-at-a-time loop (R16): agent a1's reading of func_80156044 is now a move the engine can make
on any body, so the remaining head classes get it for free.

- R15 sinks the statement AFTER an if/else chain into every arm and deletes the variables it consumed:
  `if (c) { v = e1; } else { v = e2; } w = f(v);` -> `if (c) { w = f(e1); } else { w = f(e2); }`.
- it is a REGISTER move, not a scheduling one. A value set in every arm and read after the merge is a cross-block pseudo
  local-alloc never gives a quantity (local-alloc.c:472, next_qty reset at :517), so the arm holds two quantities and
  takes block_alloc's unrolled case 2 (:1499-1502, qty_compare :1578-1596). Sinking makes it a third block-local
  quantity, and case 3 (:1491-1496) falls through into case 2 and applies that comparison a second time, undoing its own
  exchange — the two caller-saved colours swap. It also takes the value out of global.c, where set_preference
  (global.c:1535+) had given it a copy preference through the merge result's argument copy.
- applicability is checked, never assumed: each consumed variable must be assigned exactly once in every arm by a simple
  statement, appear in the merge statement, and occur nowhere else in the function.
- if_chains() counts a line's CLOSING braces before its opening ones. On a `} else if (...) {` line the two net to zero
  and the first version's depth counter never closed the arm — the generator found 0 candidates on the very body it was
  written from. Caught by running it on that known-true case before believing it.
- ranked third in REG-caller / REG-mixed / COUNT; the engine selftest's "R5 in the first three" assertion widened to
  "R5 and R15 in the first four" rather than de-ranking the new move.
- verified: delever --selftest OK (3 new controls: a variable read after the merge, a variable one arm does not set, the
  brace walk's three arms); delever_search --selftest OK; and the known-true check — R15 run on func_80156044's
  pre-bank text emits the agent's crack and `--try` scores it
  `score 0 (OTHER; mine 74 ins, target 74) — MATCH`.
- SETUP row rewritten (R21), kit corpus regenerated, tool_census --check OK (371 copies + 30 pointers, 0 gaps).
- no src/ change in this commit; the sweep of the other 56 head classes follows.
2026-09-10 00:45:15 -06:00
Drew T 7b2200edad phase-36: the tail pass g6 + g6b (47 + 63 of 400 small classes; 186/191 siblings propagated), R22 218/218; 30,806 → 30,358 sites; --try (a candidate scored without a tree write), delever_pack.py (the 57 T7 packs + PROMPT.md), --restore refuses an empty snapshot; the checkpoint: T7 as one agent at a time, approved, starts in the fresh session 2026-09-09 23:32:57 -06:00
Drew T 2f3ce92a15 phase-36: rung G run g5 — the head re-drawn wide: 5 of 70 (small classes, 62 bodies), R22 218/218; 30,892 → 30,806 sites; the wide-search lever is spent on the big classes (112,216 compiles); R14 rewrites prototypes, R8 names repeated operands/groups, R12 splits multi-declarator lines; C/D-only bodies are done and not drawn, the seed keeps class C/D sites 2026-09-09 22:07:17 -06:00
Drew T 623e553408 phase-36: rung G — tools/delever_search.py, the guided search (the score is the oracle's own object read as an edit distance, the residual classified to pick the move families, a beam composing 2–3 moves; positive controls 1–2 PASS, 3 FAIL on a missing inverse); R8/R9 + the unwrap in delever's generator registry; the 301-row ledger hash defect fixed at its cause and repaired; lane B's residual→move map banked 2026-09-09 18:11:16 -06:00
Drew T aef1159488 phase-36: T6 CLOSE — both yield lines measured (permuter 5 of 16 exemplars / 665 of 2,131 bodies; recipes 134 of 134 in 6.0 min), 664 sites gone (34,091 -> 33,427), R22 218/218 at every step; the S99 checkpoint written for T7 (which starts only on Drew's direct approval) with the parallelised rung-R sweep as the drawable work meanwhile 2026-09-09 13:02:51 -06:00
Drew T 22a31bc025 phase-36: T6 — the kit corpus and the tool index regenerated for delever_permute.py (tool_census --check: 0 gaps) 2026-09-09 10:23:35 -06:00
Drew T d025e67e71 phase-36: T5 CLOSE — the GTE consolidation and the dead-macro sweep: include/gte_inline.h (50 canonical macros for 9,102 definitions), 8,951 per-TU definitions deleted, 629 clobber variants freed byte-identical and 70 kept as marked levers, 575 direct statements → Sony-named calls, 274 dead launder macros swept; the census learns cross-file macro names (10 launders surfaced in two shared headers, 6 removed); per-TU asm macro definitions 9,540 → 314 with 0 canonical duplicates; THE NUMBER 34,091 sites (incl. 462 GTE levers) in 12,712 bodies, all marked, 0 orphans — lever_census --check OK; R22 218/218; SETUP rows; kit corpus; the 🛑 block for T6 2026-09-09 07:12:06 -06:00
Drew T 3b2c5178b6 phase-36: T5 — the scrub of 3 markers orphaned by the rejudge (R22 218/218, r22_sweep1.log); delever --scrub --dirty-ok; the sweep's dead-macro test skips a name's sibling definitions (SHB is defined twice per unit, so nothing was ever dead); kit corpus 2026-09-09 06:38:42 -06:00
Drew T 5b6e1a2fe7 phase-36: T5 — the consolidation applied (644 files: 8,951 per-TU GTE definitions gone, 629 clobber variants byte-identical without the clobber, 70 kept as marked levers, 575 direct statements → canonical calls, 85 header-bound homonyms kept) + the marker repair (scrub 344 misplaced, re-mark 349); four instrument fixes: scoped renames, header-bound homonyms kept, object-like macros, the canonical table stable (the header's definitions in the inventory) and the census cache keyed on the tables; R22 218/218; the number 34,090 (33,625 + 465 GTE levers) all marked, 0 orphans, --check OK; kit corpus; log entry 2026-09-09 06:29:00 -06:00
Drew T 0bd784c64e phase-36: T5 (header step) — the GTE consolidation: tools/gte_consolidate.py (signatures by the build's own maspsx→as tail: bytes + operand counts + clobbers; one canonical text per signature under Sony's names, Sony's clobbers canonical even when every definition carries the steer; lever variants <name>_m tried as canonical first; direct statements → canonical calls; --sweep), include/gte_inline.h (50 macros for 9,102 definitions) included from common.h — R22 218/218; the census's gte-lever class + per-TU definition count + strict gate; the cycle's MODE=gte; dictionary + SETUP rows; kit corpus; log entry 2026-09-09 05:28:50 -06:00
Drew T 917c68afd9 phase-36: T4 CLOSE — the mechanical campaign over the whole population: 16,334 bodies judged in 13 gated batches (3,341 lever-free = 20.5 %; 21,063 of 56,445 sites removed or rewritten = 37.3 %; 8,239 replays, 1 disagreement; 49,487 compiles); the file-scope asm statements judged too (batch tus11: 6 barriers NEEDED, 7 .section blocks refused as asm-data and marked); THE NUMBER 53,234 → 33,625 sites (−36.8 %) in 12,501 bodies (1,728 distinct), 33,625 marked, 0 UNMARKED, 0 orphans — lever_census --check OK; the residue 12,967 bodies in 1,803 distinct classes (pins-only 6,018 · pins+asm 4,310 · asm-only 2,141 · C/D-only 498); published by make report (README line 30, progress.json counts.levers, the timeline); kit corpus; the 🛑 block rewritten for T5 2026-09-09 05:05:33 -06:00
Drew T fa008b8629 phase-36: T4 — the census's known-true controls keyed on their bodies' T1 text hashes (N-A once the campaign edits a control body: tus7 removed func_80184034's three bare-name pins and the census refused a correct tree); the cycle's FINISH=<label> mode completes a batch from its green logs (tus7 finished so: 34f03003d); kit corpus; log entry 2026-09-09 04:04:14 -06:00
Drew T 77a1298cb7 phase-36: T4 — batch tus3 killed mid-apply by the harness's low-memory guard (22 GB free): recovered by dropping its 641 ledger rows (backup) and --restore (50 files, src clean); --restore now drops the in-flight label's rows itself (inflight.json carries the label); the cycle's usage: run it DETACHED (setsid nohup) with a tiny waiter; SETUP row; kit corpus; log entry 2026-09-09 03:35:35 -06:00