- the 11-18 plateau had two mutually-exclusive halves under (A & 0xFF000000) | (B & 0xFFFFFF): preheader hoist order
of the two masks vs &otab[idx], and the $t3/$t4 pairing of the mask register and the slot pointer. store_field ->
store_fixed_bit_field expands the RHS bitfield extract BEFORE the destination read, which fixes loop.c's movable
order [&otab[idx]; 0xFFFFFF; 0xFF000000] AND the ior operand roles at once (operand swap alone = 35). Third witness
for §364's -O2 half (func_8001D3FC/func_80021284/func_80023570 in the same TU already use the idiom).
- kept from the S79 90->18 chain (re-measured): the §194-A fence in both arms, `code` split from its base with
compound accumulation, register u32 base __asm__("$3"), and exactly 13 zero-byte fences after pkt = D_800A5E60
(0->15, 8->13, 10/11/12->7, 13->MATCH). Dropped as now inert: the m24 $11 and e1 $4 pins.
- the S80 permuter waypoint (closeness 11) was semantically UNSOUND (m24 sunk into one arm) and was not used (R63).
- rtu_match MATCH 281/281 (coordinator-verified); gate_main --apply 1/1, main byte-identical
- the redundant D_80073140[i] re-read was spelled *(s32*)(base1 + i*4): a cast-wrapped PLUS is DENIED the /s
(MEM_IN_STRUCT_P) grant (expr.c:4570-4576, §30a#1), so true_dependence kept the edge to the fixed-address
D_800C7D20 store and pinned the re-read below it. ((s32*)base1)[i] makes the INDIRECT_REF operand a top-level
PLUS_EXPR -> /s granted -> the load hoists into the D_800C7D20 load-delay slot. Zero drift, first compile.
Load-bearing kept: $6/$7 pins on i/off (-23 without), the volatile launder on the D_80073140 base (-39 without).
- lesson for the router: "redundant re-read scheduled at point-of-use" -> §30 first, never the permuter (it cannot
reach an alias flag from C — why S80's ILS plateaued at 7 from a seed of 7). Harvest note in .run/P32/t3/.
- rtu_match MATCH 79/79 (coordinator-verified); gate_main --apply: 1/1 compatible, BANKED, main byte-identical
- the Opus drafter recovered the closeness-0 body the journals (attempts 1-3) pointed at (.run/S71b_1/fable/) — the
pack's inline 292-draft was the wrong one — and found the real blocker: the TU defines Struct80078E78 AFTER the
slot with a layout lacking bytes 0x36/0x37; only a BLOCK-scoped typedef under a distinct tag (Blk80078E78) + a
block-scoped extern compiles (decl-hoisting resolver variants recreate the S7x 'conflicting types'). Idioms:
§162k1 QImode (u8)(c-3)<2; explicit flag temp t=(u32)(r-0x64)<0x1E, s1=t^1; switch decision trees for both
currentLocationId dispatches. reloc_identity AGREE 50/50; rtu_match MATCH 344/344 (verified by the coordinator)
- jtbl_carve --func: jtbl_80113FA4 (5 words, the old tail2) joins the resident_jr_800D00E4 .rodata piece
(0x450e0..0x451c0, JTBL_PADS 0,0,0,0, tables +0x0/+0x3c/+0xb4/+0xcc); carve set 5 -> 4 pieces, --pre kept
- make extract + make build BINARY=resident -j8 rc 0; sha 8e17e02ff8954d07c979449198f7e1645046b353 == check;
pads_audit ok/ok; interleave_check ALIGNED n=4
- md_MAIN_007: func_800CF390 (8 — a 3-arg pass-through to func_800CF3B0, the shape of main's func_80014128, its
d=0 twin) + func_800CF0B8 (15 — RELOC-ONLY twin of resident:0x800cf4d4 with the index global read as lw, s32)
- md_SC03_054: func_801F0098 + func_801F0104 (12 each — NEAR-COUSINs of ov_SC03_006:0x80183744; constants
0x3C9 -> 0x11A, 1 -> 3, exactly as the real-TU diff named them)
- md_SC03_056: func_801CBBDC (11 — cousin of ov_SC03_001:0x8017ed8c, 2 -> 0xE)
- rtu_match MATCH each; make build -j8 rc 0: md_MAIN_007 2ff702b6 · md_SC03_054 06bd73df · md_SC03_056 bc768a6b
- md_SC03_056 (TEXT_LO 0x4, 4 stubs / 61 ins): 15/17 pointers cluster inside at 0x801CBB50; one outward call
(0x8018151C) hits a function only 3 overlays have, ov_SC03_002 among them; req_fit 9/9 for ov_SC03_002
- payload_base_evidence.py v2 (controls 7/7 throughout): (a) STRONG = internal jals + fn-ptr-table entries on the
module's own starts >= 2 (SC03/53 STRONG); (b) OUTWARD-EXPLAINED — a pure jal-vote base whose "internal" targets
are function starts of the fleet's overlays is downgraded: SC03/56's 0x80178C8C was two SHARED-engine functions
spaced like two of its five starts (and nobody's DESTPTR), a false STRONG; (c) the requester cross-check is
informational only — shared engine code makes every requester fit (an R39 control caught it scoring: 6/7)
- memory-map §S45 p7 amended: all five rows ONBOARDED + the two instrument findings (the first build is a NULL
oracle for FINE base errors — +8 builds byte-identical, +0x1000 fails the link; outward-explained vote bases);
SETUP row amended. The parked-for-L3 ledger is EMPTY pending `make audit-disc` (T2c).
- md_SC03_053 (TEXT_LO 0x4, 15 stubs / 372 ins) and md_SC03_054 (TEXT_LO 0xF0 — a 19-entry fn-ptr header, 7 stubs
/ 764 ins) share ov_SC03_001's DESTPTR slot 0x801EF468, the slot the S45 tracer watched other SC03 scripts load into
- BASE EVIDENCE (memory-map §S45 p7, static-derived STRONG at 0x801EF468 and nowhere else): SC03/53 — 52/75 absolute
pointers inside, 3 of them + its one internal jal exactly on its own function starts (0 at every rival); SC03/54 —
106/115 pointers inside, 5 header-table entries exactly on starts (0 at every rival); lui 0x801F ×18 / ×46
- first builds byte-identical (base-lenient, R34 — the base rests on the alignment; the first internal-call C bank
byte-proves it); the §S45 p6 "onboard at 0x801EF468, let the first build decide" step, finally run
- tools/new_binary.sh md_MAIN_009 extracted/retail/MAIN.CD.dir/FILE_009.dir/0.1 0x800CD348 0x3C -> first build
BYTE-IDENTICAL sha d270f695b793b5c03db159b7aabcc066daa87eda; 11 stubs (609 ins); window 0x800CD348..0x800CDD38
lies below the resident's symbol region, so the default symbol stack stands (no A4 edit)
- BASE EVIDENCE (memory-map §S45 p7, static-derived STRONG): 6/6 internal jals and 9/9 absolute pointers land
on the module's own function starts at exactly ONE base, 0x800CD348 — inside slot B's region (+0x82C from
0x800CCB1C), not a previously known slot; lui 0x800C/0x800D ×51. Same caveat as md_MAIN_007: the first build
is base-lenient (R34), the base rests on the alignment and will be byte-proven by the first internal-call C bank.
- tools/new_binary.sh md_MAIN_007 extracted/retail/MAIN.CD.dir/FILE_007 0x800CEDF8 0x34 -> first build
BYTE-IDENTICAL sha 2ff702b605ab5cfc18474c464c4c07e5f8ffd48c; A4 applied (symbols.resident.txt not stacked —
the window lies inside the resident's symbol region), re-extract + rebuild byte-identical; 19 stubs (802 ins)
- BASE EVIDENCE (memory-map §S45 p7, static-derived): STRONG — 9/9 internal jals and 14/16 absolute pointers
land on the module's own function starts at 0x800CEDF8 (the boot slot of md_MAIN_001/008/011); lui 0x800C/0x800D
- HONEST CAVEAT (R34, measured 2026-09-05): the all-INCLUDE_ASM first build is a NULL oracle for FINE base
errors — the same payload builds byte-identical at 0x800CEE00 (+8) — and catches only GROSS ones (at +0x1000
two internal jal targets leave the window: `undefined reference to func_800CEEA4/func_800CF3F4`, link fails).
The base therefore rests on the static alignment, and will be byte-proven by the first C bank that calls an
internal sibling. Controls: .run/P32/t2b/{control_full,control_fine}.log
- registered in modules.mk + the report/diff dicts (R36 citizenship asserted by tools-health at T2c)
- the instrument: module-id word, TEXT_LO estimate, absolute-pointer set, lui hi-half histogram, and a
jal->function-start VOTE (starts = prologues ∪ the word after every `jr $ra`+delay — leaf functions have no
prologue, the recall killer of S45's vote_base 4/12); scores a BOUNDED candidate list (5 §S44 slots ∪ 134
IDXTAB DESTPTRs ∪ vote bases): STRONG / CONSISTENT / INCONSISTENT / NO-EVIDENCE; AMBIGUOUS tie sets are
printed, never picked; a payload with no self-reference is REFUSED as base-independent (R43)
- R39 controls run before any emission: md_MAIN_008/011/013/042, md_SC03_073, md_SC02_009, md_SC07_004
re-derive their byte-proven bases top-ranked from their payloads alone (7/7); TEXT_LO estimates == yaml
(incl. the header-table modules 0x7C/0x14/0x158). The first draft of the scorer FAILED 5/7 (prologue-only
starts; a top-rank assertion on modules the bytes cannot discriminate) — fixed by the controls, not shipped
- the five (G5 static-derived, US): MAIN/7 STRONG 0x800CEDF8 (9/9 jals, 14/16 ptrs on starts); MAIN/9 STRONG
0x800CD348 (6/6, 9/9); SC03/53 + SC03/54 CONSISTENT with 0x801EF468 top of a 12-way tie; SC03/56 SPLIT
(jal vote 0x80178C8C vs pointers/lui ~0x801CBB50). T2b probes each with new_binary.sh — the byte gate decides
- SETUP row (R21); evidence rows .run/P32/t2a/evidence.json
- the census's best_draft (.run/wave_g0c/shard30, 174 ins, 7 pins) was a DIFFERENT, wrong body under the bare
name (R48); the journal (R38) named the real one — .run/O21/opus/func_800CB00C.c (88 lines, 7 BLOCK-scope
callee externs: gcc-2.7.2 demotes the later-definition type conflict to a warning at block scope). rtu_match
MATCH 123/123 in the real TU (the S75 redraft too); the S72 resolver had gated only the wrong file, 3x.
- raw splice into src/md_MAIN_034/md_MAIN_034.c; module island pads derived at build (§303); make build
BINARY=md_MAIN_034 -j8 rc 0, sha 46153c06bca859dec05aff59fb1a77d3add3d02b == check (R53); verbatim strict ok
- config/wave_exclude.txt regenerated (exclude_audit --write): the md_MAIN_034 WALL pin labelled a wrong draft,
not a wall — 8 -> 7 entries; docs/backlog.md re-rendered (matched rows drop)
- 0 drafting tokens; no Sonnet agent needed (plan T1c adjusted: no redraft)
- family_remap --addr 0x801810C8 --from ov_SC02_016 --to ov_SC02_017 --to-addr 0x80186C64 (23 per-overlay
symbols remapped); rtu_match then named four §376 TU spellings (func_8012A828 (s32, void *); D_801E0F44 s32
— address-only use; func_80131E00 (); func_80185F88 (s32) — calls already fn-ptr cast) + one TU-provided
typedef to strip (Prim_8016E7C8, §491 gap 2) -> MATCH 209/209 in the old TU and in the new region TU
- jtbl_carve --func: jtbl_801EE414 clamped to its `sltiu 6` (6 entries) into
[.rodata, ov_SC02_017_jr_80186C64] + tail19; JTBL_PADS 0,0; carve set 45 -> 46 pieces
- make extract + make build BINARY=ov_SC02_017 -j8 rc 0, sha c0253499eed71309d731862ffc76766d183d031e ==
check (R53); pads_audit all ok; interleave_check ALIGNED n=46; verbatim_check --strict no drift
- 0 drafting tokens (the journal's S69/S70 lever drafts carried the same body; R38)
- jr_isolate_all ov_SC02_017 --only func_80186C64 (CLEAN after the §497 carrier fix — no source rename);
2 region files; make extract + make build BINARY=ov_SC02_017 -j8 rc 0, sha
c0253499eed71309d731862ffc76766d183d031e == check (R53). Carve state only; the bank is the next commit.
- BANK: the stored S71 closeness-0 draft spliced into src/resident/resident_jr_800D128C.c; jtbl_carve --func
carved jtbl_80113FB8 (119 entries, 1 pad word trimmed) + jtbl_80114198 into [0x451c0, .rodata,
resident_jr_800D128C] + [0x453c4, data, tail3]; JTBL_PADS 0,4; make extract + make build BINARY=resident -j8
rc 0, sha 8e17e02ff8954d07c979449198f7e1645046b353 == check (R53). pads_audit ok/ok; interleave_check
ALIGNED n=5; verbatim_check --strict 5==5. Resident stubs 2 -> 1 (func_800D06E8 remains).
- WHY THE GATE SAID DIFF (parallel_gate banked 0/DIFF on an rtu_match MATCH): jtbl_carve.set_overlays_var
regenerated resident_JTBL_INTERLEAVE from the carve set and DROPPED the resident's `--pre hdr.rodata.o`
(§8f leading-rodata sandwich); make extract refused (ld_interleave: hdr.rodata.o would be parked with
.text), the build linked the STALE script (249,252 differing bytes from file offset 0x4), and
harvest_verify._jtbl_prep_one never read the post-carve extract's exit code (R49/R61).
- FIXES (R35/R40/R57): jtbl_carve._merge_pre carries an existing --pre forward (idempotent; overlays
unchanged, 4-shape unit control); harvest_verify refuses loudly on a failed post-carve extract and
restores the snapshot (CARVE refusal, NOT a draft verdict); interleave_check's anchor accepts a leading
--pre (was a false DRIFT n=0 on the resident; control ov_SC02_017 ALIGNED n=44 unchanged).
- cookbook §498 (+ the stale-asm-after-a-failed-extract sequencing law); SETUP rows for all three
- _type_names returned the TAG for `typedef struct Rec801806C8_s Rec801806C8;`, so the typedef block and the
tag's own packed struct definition collided under one key with different bodies and the R43 "CONFLICTING
bodies — a rename is needed" refusal fired on legal C. Now keyed by the alias (_TYPEDEF_TAG_ALIAS); the
`carried` set learns the alias; `typedef struct X X;` (alias == tag) keeps the old key so a second one
still dedupes/refuses. Unit control on 7 block shapes PASS; ov_SC02_017 --only func_80186C64 --dry-run:
2 region files, no carve repoints. cookbook §497; SETUP row.
- jr_isolate_all resident --only func_800D128C: [0x4 c resident] [0x12ec c resident_jr_800D00E4]
[0x2494 c resident_jr_800D128C]; the banked jr func_800D00E4's .rodata carve + JTBL_PADS + --order
repointed to resident_jr_800D00E4.o (config/overlays.mk resident block only, R60); make extract +
make build BINARY=resident -j8 rc 0, sha 8e17e02ff8954d07c979449198f7e1645046b353 == check (R53)
- TOOL FIX (R43/R33): the carried-type test consulted _engine_types() (engine_types.h + common.h) for
every TU, assuming each region includes engine_core.h; the resident includes only common.h, so its
file-local `typedef struct {...} CdFileLoc;` (a name engine_types.h also defines) was silently NOT
carried -> `parse error before cdFileLocTable` in both region TUs, build rc 2 while the stale binary
on disk read green. Now _provided_types(header) derives the set from the TU's own #include lines
(engine_core.h => engine_types.h + common.h, never engine_core's macro-internal typedefs; common.h
=> common.h) and _file_scope_decls(items, provided) uses it at both decision points. R39 controls:
overlay header == legacy set (1,197 names); resident set lacks CdFileLoc. cookbook §496; SETUP row
- rtu_match func_800D128C --split resident_jr_800D128C: MATCH (243 ins) on the stored S71 draft;
the gate is the next commit