The test was `^\s*typedef\b[^\n]*\bNAME\b` — the name must sit on the SAME LINE
as the keyword. True of `typedef unsigned char u8;`, never true of the
multi-line form the preamble backscan actually carries:
typedef struct Foo { … } Foo;
so every multi-line typedef already in the unit was carried a SECOND time and
the unit reached the gate with two definitions of one tag. canon_sig_reconcile
uniquifies draft tags, so the duplicate is exact: `redefinition of struct
Foo_8013C0F8`.
- Extract the block capture as `_typedef_blocks(lines)` and derive the
already-carried set from it (R33: one parser, two callers), so the
multi-line form is recognised exactly as the single-line form always was.
Measured on the 0b population: func_8013C0F8 (3 slots) carried Foo+Bar twice;
func_8013B83C dropped a redundant file-scope copy of a typedef its body
declares at block scope. 6 other families byte-identical output.
`_proto_from_lines` starts `_strip` with in_block=False, but item boundaries
are `;`-terminated — so a declaration whose TRAILING comment wraps hands the
comment's continuation to the NEXT item, and the implied prototype came out as
extern * a prototyped (s32) decl is `conflicting types` … */ void func_80151664(void);
It compiled only because the hoist emits the opening `/*` line immediately
above it, so the garbage lands back inside a comment — but `_file_scope_decls`
then meets a col-0 `extern …;` whose base type is `extern` and REFUSES (R32).
That is the isolate-fail class: 23 of the 111 open 0b member-slots.
- overlay_src_split._proto_from_lines: apply family_remap's D1 backstop — a
`*/` with no `/*` before it means the chunk opened inside a comment; drop
that residue before parsing the header.
- Repaired the 16 already-emitted region files (the garbage line's live
payload was a redundant `extern void func_80151664(void);`).
Byte-gate after the repair: ov_MAIN_012 / ov_SC02_037 / ov_SC03_107 all
BYTE-IDENTICAL.
The 0b blocker was not "the pads line is left behind" alone — it fails two
different ways, and the second one is silent:
* bare isolate + `make build`: the stale line arms the pads filter on the
RESIDUAL object, which emits no jump table ->
`jtbl_rodata_pads: consumed 0 rodata .align(s) but 4 pad spec(s) given` (S47).
* isolate -> jtbl_carve (the jtbl_family_bank path): `set_pads_vars`
regenerates the block keyed by the CURRENT subseg names, finds no prior spec
under the new `_jr_<addr>` name, and DROPS the line. cc1's natural `.align 3`
then pads the span's non-8-aligned interior tables and the image shifts —
reported only as `built, bytes differ`.
- jr_isolate_all.repoint_overlays_mk: repoint the `build/src/<ov>/<sub>.o:
JTBL_PADS` target with the `--order` leaf whenever a carve moves; refuse
loud if the old object still hosts a .rodata piece (R32).
- jtbl_carve.set_pads_vars: second, disagreeing oracle (R34) — refuse when a
spec would vanish for a subseg no longer in the carve set (rename/merge
drift), instead of silently emitting a padless object.
R37 probe: func_801789AC -> ov_SC02_037 went `built, bytes differ` -> BANKED
on the whole-binary byte gate. ov_SC02_037's spec is 0,0,0,0 over tables
+0x0,+0x14,+0x34,+0x4c — load-bearing (span start is 4 mod 8).
2,197 instances banked, derived from the STUB ORACLE (15,542 -> 13,345), not from summing
per-batch reports (my running total said ~2,307 — summing drifts, the oracle does not).
35 commits, R22 213/213 after every batch, fleet 94.4% instr / 88.3% distinct / 96.33% fn-count.
THE STRATEGIC FINDING: the sweep residue started the session ~5:1 PLUMBING:DIFF and ends at DIFF
170 of 575 (30%), larger than the next four classes combined. The declaration-axis vein is spent;
from here the mover is volume with multipliers, not more plumbing. The Fable frontier analysis
predicted this and the residue confirmed it rather than my framing.
Landed: ~1,900 functions from plumbing at ~0 agent tokens (8 declaration axes, the symbol-KIND fix
at 205, cdFileLocTable, memcpy, the cpp-derived type map, the alias-drop fix) plus 163 from the
reach-15 agent wave at a 15x effective multiplier (reach-ordering, not the 3.55 mean, produced
that). Seven instruments repaired, cookbook to 469 sections.
Error ledger: 8, all caught. The pattern in most of them is that I proposed a mechanism before
reading evidence that was already written down — four were in files I had open.
Resume at Stage 0b (JTBL_PADS, 122 slots at ~100% measured conversion), then Stage 1's
reach-ordered sibling campaign. Stage 0a is done enough; what remains of it is bounded, not
compounding. tools-health was launched at close — confirm it before banking.
The new head plumbing class after the symbol-kind fix: `conflicting types for func_80175414` (27
member-rows). Byte-true DEF is `void func_80175414(s32 _arg0)` (its DEFINE_ macro). The fleet
declared it 1,845 times in four spellings, of which three are the SAME TYPE (parameter names do not
participate) — the outlier was 28 sites declaring `(void)`.
conform_decls REFUSED the naive conform and was right to: 29 ZERO-ARG CALL SITES exist across 28
files, so conforming the declaration alone turns each into `too few arguments` — a fleet-wide
COMPILE break the per-binary gate cannot see (the tool cites 138/140 binaries, measured). It named
the count, the consequence, why the cheap check misses it, and the flag that repairs it, then
forced the two-step: --cast-zero-arg-calls (29 sites cast to the 0-arg fn-ptr shape, §17a-1 — gcc
folds the cast of a known symbol to a direct jal, so it is codegen-neutral), then the conform.
Result: 1,845 declaration sites rewritten across 1,061 files, 0 non-canonical remaining (axis
complete, R32). R22 clean-fleet: check-all 213 passed / 0 failed of 213.
WORTH RECORDING AS A TOOLCHAIN STANDARD: this is the instrument that has not wasted a cycle today.
Every other one reported SUCCESS over a defect — a classifier that discarded every gcc-2.7.2 hard
error (no `error:` prefix), a diff that miscounted 116 data-bundled .s files, a --verified-out
truncated to zero bytes over 62 real banks, a --band default that reported "0 families" on a real
135-member family, and a scope stamp describing the filesystem instead of the run. conform_decls
reports FAILURE with a repair path. A guard must state its COVERAGE, not just its verdict; the
in-repo exemplars are this tool and the §53 jr interlock.
Stage 0a's first defect, and the largest single zero-token bank of the session.
family_remap's kind test asked ONE question — is this address a function in the SIBLING'S OWN sig?
— and defaulted to `D_` on "no". But a body calls outside its image constantly: an overlay calls
resident helpers, an md_* module calls the overlay-range engine. Those addresses are absent from
the sibling's sig, so the test fell through and emitted a DATA NAME FOR A FUNCTION —
`D_800183E0`, `D_800D1EBC`, `D_80171A1C`. None exist anywhere in src/ or config/symbols.us.txt,
while `func_80171A1C` alone has 1,061 references. Measured: 611 member-rows across 45 symbols,
the largest named residue class. "Not in MY sig" means "not mine", not "is data".
Fix — three oracles, strongest first, never a blanket fallback:
1. the sibling's own sig (authoritative for its image; this is what preserves the Phase-29 T82
case where a slot is a function in the exemplar and DATA in the member — unioning every sig
would have re-broken the 251 members T82 fixed),
2. the always-linked images via extern_fn_addrs() — resident + main, 2,146 addresses whose ranges
cannot collide with an overlay's,
3. the exemplar reached it by `jal` — a call target is a function BY DEFINITION, which covers an
external address neither sig claims (0x80171A1C from an md_* module, 112 rows).
Only a non-call reloc no oracle claims still falls to `D_`.
Result: BANKED 205 member-matches, failures 670 -> 575, derived net = report = 205.
R22 clean-fleet 213 passed / 0 failed of 213.
Fleet 94.4% instr / 88.3% distinct / 96.27 -> 96.33% fn-count; stubs 13,563 -> 13,345.
THE RESIDUE HAS CROSSED OVER: DIFF is now the LARGEST class at 143 of 575 — real byte divergence
outranks plumbing for the first time this session (undefined-ref 611 -> ~8, PLUMBING-other
231 -> 81). The ~5:1 plumbing:DIFF ratio that justified "tooling beats volume" has inverted in this
queue, exactly as the frontier analysis predicted: the declaration-axis vein was one-time.
The new head class is `conflicting types for func_80175414` (27) — the same addresses this fix
started naming correctly, now surfacing the NEXT layer (the symbol resolves; its declared signature
disagrees). That is the conform axis, not the remap axis.
Note for anyone auditing this class: rtu_match MASKS HI16/LO16, so a wrong %hi/%lo symbol still
reports MATCH (the T82 comment records `MATCH (10 ins)` on a member the fleet gate refused). This
defect is invisible to the per-function tool by construction — only the whole-binary gate sees it.
The targeting oracle stamped its scope as "the N OVERLAYS only (no main, no resident)" while
load() has scanned the md_* modules and the resident since S44. Measured at this HEAD: 141 location
overlays + 70 md_* modules + the resident = 212 binaries. That is the §159 coverage law broken by
the file that documents coverage, on the repo's most load-bearing targeting instrument — and it is
how "main is structurally barren" survived two phases unexamined.
The COUNT beside it was already derived, with a comment saying "report the scope we ACTUALLY
scanned, never a hardcoded count". The PROSE describing what the count meant was hardcoded and
rotted. Both are derived now.
Caught while fixing it: my first cut read glob(".run/sig.main.jsonl") and stamped "main INCLUDED"
the moment that file existed — while load() still did not glob it. Same defect one layer down: a
stamp describing the filesystem instead of the run. Now derived from the loaded instances.
Also added a glossary line: "zero-crack" means n_matched == 0 (needs its FIRST crack) in this map,
and the OPPOSITE (a matched exemplar awaiting propagation) in roadmap §3 T3 — a ~30x mis-scope risk
for any session reading one against the other.
NOT DONE — main inclusion (0c) is still blocked on settling the attribution. Confirmed the
mechanism: main has 49 LINKED PsyQ subsegs, corpus.stubs('main') returns 2,002 INCLUDING them,
progress.py correctly excludes them and reports 1,034 game-code stubs. progress.linked_subsegs'
own docstring records this exact trap ("an importer then classifies ~1,300 already-byte-identical
LINKED library stubs as outstanding game-code work") — and my sig-main seeded from corpus.stubs,
so it inherited the LINKED rows, which is why G2's 207-family finding was inflated.
My partition probe is NOT trustworthy: 954 of 2,002 stubs returned no asm path from
corpus.asm_path, so 199 LINKED / 849 game / 954 unresolved does not reconcile with 1,034. Fix the
probe before trusting any main-scope number.
Independent frontier analysis re-derived every headline number from family_hseq.json (all reproduce
exactly) and corrected four claims, one of them mine from this session.
THE SEQUENCE: Stage 0 tooling (0a the DATA SIDE of the template engine — the 207 undefined-refs,
54/56 parse errors, 116 data-bundled .s and the F2 collisions are ONE mechanism, and unlike the
JTBL_PADS fix it COMPOUNDS across ~7,500 future member banks; 0b JTBL_PADS; 0c sig-main, recommended
yes, needs Drew; 0d a free-CPU permuter probe with a kill rule). Then Stage 1, the reach-ordered
sibling campaign to ~97.5%. Then Stage 2 singletons. Special projects LAST.
CORRECTIONS: (1) my G2 main finding was inflated — 968 of sig.main's 2,002 rows are SDK-region
stubs that fall to LINKED conversion, so the real main templating pool is ~123 families / ~303 fns
/ ~9k ins, not 207/748/11,537. (2) docs/family-hseq.md stamps its own scope as '212 OVERLAYS only
(no main, no resident)' while the map contains resident and 70 md_* modules — the §159 coverage law
violated by the file that documents coverage. (3) the close-1-4 backlog is 103, not 157, and its
reach column is TOTAL sharers not LIVE. (4) 'zero-crack' means opposite things in the roadmap and
the current map — a 30x mis-scope risk.
FRAMING: my cost-per-crack thesis holds for the singleton half only. True singleton pool is
~5,200-5,600 cracks / ~345k ins (45%); the other 55% rides on ~2,100 exemplar cracks where ORDER and
LEAK-RATE decide the calendar. Do not cross-price the two economies: 5:1 plumbing:DIFF is a property
of the residue queue, while W1's fresh wave converted 81%.
Also recorded: the 15-step reach-ordered sibling loop, with the three steps whose omission destroys
the multiplier called out (regen before targeting, regen after cracking, --band all).
W1b — the 3 targets whose agents died on API rate limiting, retried with cookbook §160 in the
prompt: func_801EFBF4 (reach 12), func_801EFDC8 (12), func_8018CC40 (10, jr). 3/3 confirmed by an
independent verifier, all banked, R22 clean-fleet 213 passed / 0 failed of 213.
func_8018CC40 failed the first gate with `too many arguments to function func_80178970` — which its
own crack agent had PREDICTED in its report, naming the §17a-1 remedy. Dropped the draft's
empty-paren externs and cast 6 call sites instead; banked. Read the agent's integration notes
before diagnosing a gate failure — it has already seen the TU.
Cookbook §161a-c (index 469 sections):
§161a case 0: break; is LOAD-BEARING when a jump table is indexed from zero. The natural
case 1..5 makes gcc-2.7.2 pick minval=1, emit `addiu $v1,-1`, and shift every table index —
58 of 77 mismatched on a byte-perfect body. Tell: the table's FIRST entry points at the
function's own end address. Family-wide (10 members).
§161b aliasing a parameter into a local can force a SECOND callee-saved register (+8 frame,
+3 ins) even when uses are mutually exclusive. Suspect it before reaching for register pins.
§161c loose-prototype engine helpers: don't fight the TU's (void) decl, cast at the call site.
G2 — THE MAIN EXPERIMENT. family_hseq excludes main as "structurally barren — zero h_exact
overlap". True and irrelevant: an h_exact claim guarding an h_seq tool. There is not even a
sig-main target — main had never been signed for this pipeline. Signed it (2,002 fns, seeded from
splat boundaries via corpus.stubs rather than --bootstrap, which glues functions around jtbl
dispatch and would have corrupted the hashes under test).
Result: main is ~85% singleton work, not 100%.
internal h_seq families (>=2): 207 families / 748 fns / 11,537 ins (13.7%)
shapes shared with the fleet: 161 fns / 1,346 ins (1.6%)
genuine x1 remainder: ~71,034 ins (84.6%)
IMMEDIATELY ACTIONABLE: 44 classes / 151 main functions / 1,239 ins already have a matched exemplar
in the fleet — free propagation, invisible only because main is not in the map.
Long-term: 748 of main's 2,002 functions (37%) are templatable once one exemplar per family is
cracked, which refutes "2,002 independent cracks" as the planning assumption for the 79k-ins tail.
OPEN, deliberately not done unilaterally: adding a sig-main target and dropping main's exclusion
from family_hseq.load() changes a fleet-shared oracle every targeting tool reads. Needs Drew's call.
The reach-10 jr exemplar cracked in the reach-15 wave; its 9 siblings needed the §53 path rather
than family_sweep (the sweep's interlock refuses has_mid_jr families by design). Per sibling:
jtbl_carve -> make extract -> remap_hseq -> make build, keep iff byte-identical.
Result: 9/9 BANKED. R22 clean-fleet: check-all 213 passed / 0 failed of 213.
WHY 100% HERE VS 56/182 THIS MORNING — the difference was never the code or the tool. This
exemplar banked RAW (so its unit is the raw crack, not an ov077-TU-specific reconciled body, which
is the trap the tool's docstring documents and which historically sent func_80178D40 to 0/4), and
every target binary was already carved. Given those two conditions the §53 path is deterministic.
This morning's 126 failures were 112 isolate-fails in three UNCARVED binaries plus 10 gate-fails
and 4 carve-fails.
Consequence for planning: the 122 jr member-slots still blocked behind the JTBL_PADS repointing in
ov_SC02_037 / ov_SC03_107 / ov_MAIN_012 are not a speculative number — they convert at the rate
just demonstrated once those binaries are carveable. Those are the same three binaries that
absorbed 1,102 of today's propagation banks, so unblocking them pays across every lane.
The reach-57 exemplar func_801EDC18 is banked and R22-green, but its family sweep returned 0/56.
54 of 56 failed 'parse error before buffer': the remapped sibling carries neither the draft's own
Blk8 typedef nor any declaration of the per-member data symbol.
Two gaps. (1) family_remap does not gather draft typedefs — the T7-S1 class, named a phase ago and
still unbuilt; cdecl.strip_provided_typedefs is NOT the culprit, it correctly keeps a typedef the
target lacks, so the loss is in unit extraction. (2) NEW: this family's data is PER-MEMBER — each
sibling's .s carries its own rodata bytes, so a symbol remap cannot produce it; the bytes must be
decoded per member and emitted as that member's definition. No existing tool does this.
Bounded: 116 of 12,583 .s files are data-bundled. The md_* module TUs cannot fall back on the
shared Blk8 (engine_types.h:497) because they include only common.h — tu_scope is 53 entries there
versus 4,190 for an overlay.
func_801EDC18 (md_SC05_023) is the largest multiplier remaining — 57 members. The wave agent
abandoned it at "closeness 6" with class SIZE-MISMATCH [redraft]. It was two lines from correct.
THE CODE (cookbook §160a): the target copies 8 bytes with lwl/lwr + swl/swr — gcc-2.7.2's
emit_block_move for a type with ALIGNMENT 1. The draft used a u32 copy (aligned lw/sw), which is
wrong by construction. `typedef struct { char c[8]; } Blk8; buffer = D_801ED98C;` reproduces it.
Six spellings were tried in parallel; two independent agents converged on the same one.
THE INSTRUMENT (§160b) — this is the part worth more than the function. The target .s bundles a
leading `.section .rodata` block (D_801ED98C as two .word) ahead of .text. Those lines carry the
same `/* off vaddr HEX */` shape as instructions, so masked_diff.insns_from_s counted them as TARGET
instructions, while insns_from_object (objdump -j .text) can never emit them. A byte-perfect draft
therefore read `mine=26, target=28, 26 mismatched` — every position shifted by a constant +2 — and
got classified as needing a redraft. 116 of 12,583 .s files in the corpus have this shape, one at
-29 instructions. Every one of them would report a false wall to any agent that tried it.
Fixed: insns_from_s tracks .section and counts only .text. Full-corpus control: 12,467 unchanged,
116 corrected, 0 regressions. Same artifact class as §129a (post-carve jtbl inflation).
THE OWNERSHIP LAW (§160c) — my own error, corrected by the gate. Four sites declare
`extern short D_801ED98C;` and nothing in src/ defines it, so I shipped an extern-only draft. The
gate refuted it: `undefined reference`. The .s block the draft REPLACED was the definition. The
variant emitting `const Blk8 D_801ED98C = {{...}}` banks clean. Never infer ownership from externs.
R22 clean-fleet: check-all 213 passed / 0 failed of 213.
ALSO BANKED — the wave's idiom harvest, which had been sitting unwritten in workflow transcripts
(R16/R30 debt): §160d the ASYMMETRIC INDEX RELOAD (a just-stored narrow field read twice emits
reuse-then-reload; the C is deliberately asymmetric), §160e a stack-layout scheduling rule now
byte-proven on a SECOND independent function (promoting it from coincidence to rule), §160f the
address-only global store via array decl, §160g sibling-search keyed on the CALLEE SET as step 0 of
every wave prompt (one grep turned a 126-instruction crack into a copy-edit).
Cookbook index regenerated: 468 sections.