Commit Graph

270 Commits

Author SHA1 Message Date
Drew T 3a67dd609f feat(phase-26): func_8017BEBC (952 ins, ×113) CLOSED + banked ×1 — the §47 live-length slider
The largest unmatched core in the game, walled at close=2 for the permuter (25 min, no close) and
queued for a gdb-on-cc1 read. Closed WITHOUT gdb — the RTL dumps were the oracle:

- THE TIE, byte-measured (.lreg): &g.sz1 pseudo 228 refs 13 / live_length 783; &g.sz2 pseudo 230
  refs 13 / 782 -> pri = int(390000/L) = 498 == 498, an exact int-truncation tie in global.c:594
  allocno_compare. Tie-break = creation order -> allocation follows emission; the target needs them
  to DIFFER (allocation sz2-first, emission sz1-first). The shipped operand-permutation workaround
  could only pick one (close=2 vs close=10).
- THE FIX (§47): restore NATURAL operand order (emission correct) + ONE zero-byte
  `__asm__ volatile ("")` placed BETWEEN two existing GTE volatile asms (no new cse/sched barrier —
  one is already there) -> +1 static insn at global-alloc time -> L 784/783 -> pri 497 vs 498 ->
  the tie SPLITS toward the shorter-lived (later-created) pseudo, which is ALWAYS the direction
  "allocation != creation" requires. All 10 grants cascade; MATCH 952/952 first try; the slider
  emits only #APP/#NO_APP (zero bytes). PIN-FREE, ×113 template-safe.
- BANKED ×1 in ov_SC01_000 through the WHOLE-BINARY gate (jr fn — match_one is not the arbiter,
  §8a): lazy isolation -> new region ov_SC01_000_jr_8017BEBC + 9-piece jtbl interleave -> splice ->
  BYTE-IDENTICAL. One TU-visible decl reconcile en route (D_800B9A02: declare the TU's `short`,
  force the unsigned halfword at use `(*(u16*)&D_800B9A02)` — §8d sub-class (b)).
- R22 clean-fleet 136/136 BYTE-IDENTICAL; 0 NON_MATCHING (G4). The ×113 sibling sweep is IMM-class
  (scattered addresses) -> Task-8 mechanical work via the imm engine.
- cookbook §47 (the slider method + the placement rule + the direction law); decision-log (R31).
2026-07-13 22:02:46 -06:00
Drew T b8a525bb98 feat(phase-26): h_seq substantial-band re-sweep — 266 free member-matches (~0 agent tokens)
The extract_unit fix (commit:0552) revealed 82 families with a genuinely-matched exemplar and UNSWEPT
siblings (~2.03M templatable bytes) — mostly exemplars cracked AFTER the session-2/3 mechanical band
sweeps ran (the giant campaign + recent cores), so the sweep had simply never seen them.

- re-ran `family_sweep --hseq --band substantial` on a regenerated manifest: 29 matched-exemplar
  families, 1046 member drafts staged, 1643 correctly skipped as pinned-exemplar.
- BANKED 266 member-matches / 780 gate-rejected. The whole-binary byte-gate (G3/P9) arbitrated every
  one; R22 clean-fleet 136/136 BYTE-IDENTICAL from `make clean`.
- metrics: instr-weighted 63.6 -> 63.8%; distinct-code 40.5 -> 40.7%; fn-count 82.39%.

The 780 gate-rejections are the next lever: family_sweep's h_seq path does NOT yet carry the §8d
`scoped` stage (it prepends carried data externs at FILE scope, the exact class that blocked the jr
sweeps), so a large share are expected to be the same decl-environment conflict. Investigated next.
2026-07-13 21:29:45 -06:00
Drew T 7b970653ff docs(phase-26): cookbook §46 — func_80178D40 MATCH (890 ins ×134): four loop-structure levers
The heaviest core in the game (890 ins, reach 134 = 477 KB) closed from close=39 to MATCH 890/890,
PIN-FREE, by cheap-Opus reading loop.c/jump.c/cse.c. All 39 residuals were in ONE case body and every
one was STRUCTURAL — the permuter could not have reached any of them. Four new general levers:

- L1 PEEL: a loop's `break` must not land on the loop's own fall-through label — that leaves
  NOTE_INSN_LOOP_BEG + an unconditional jump, firing duplicate_loop_exit_test (jump.c:2131), which
  rotates the loop and peels iteration 1 (const-folding `i++` and dragging an extra address
  re-materialization block). Write `goto <label>;` — same destination, different construct.
- L2 SURVIVING COPY: a source-level `fp = q;` ALWAYS dies (cse canon_reg + qty_first_reg, then flow).
  To make it survive, split def and uses across extended basic blocks — cse resets its hash table at a
  label with >1 predecessor. Test the memory, assign inside the guard branch.
- L3 MERGED STORE: write the store INSIDE the branch that reaches the shared tail, so jump2 tail-merges
  it and reorg steals the `li` into the delay slot. An unconditional store before the `if` blocks it.
- L4 UN-COALESCED LOOP COPY = a non-replaceable giv, needing all three of: an index giv `&A[i]`; a use
  OUTSIDE the loop (record_giv, loop.c:4437 -> emit_insn_after at loop.c:3945); and the biv increment
  LAST, so the reduced giv's addiu lands in the loop-back delay slot (i++ at the top costs +1 insn).
- L5 KEEP TAILS APART: two structurally identical loops must differ in a REGISTER or cross_jump merges
  their tails — give each its own pointer pseudo. (§8's cross-jump lever, inverted.)

Confirms the tier doctrine: cheap-Opus applying the documented §31 map cracked the game's heaviest core;
Fable5 was not needed. R17 held — "wrong BYTES" -> read the real gcc-2.7.2 passes.
2026-07-13 21:16:36 -06:00
Drew T cc6220eba4 fix(phase-26): extract_unit mistook m2c declarations for definitions (15 phantom exemplars)
- BUG: the guard `not ln.rstrip().endswith(";")` misses m2c's declaration form
  `M2C_UNK func_80178D40(s32, s32);   /* extern */` — the raw line ends in `*/`, not `;`, so a
  DECLARATION was accepted as a DEFINITION and the forward brace-scan swallowed the NEXT
  function's body, handing remap_hseq a garbage unit.

- BLAST RADIUS (measured): 15 of 35 substantial-family exemplars were phantom "matches" — all
  still INCLUDE_ASM stubs (incl. func_80178D40 and the carried-queue func_801670E4); 3 more
  anchored on the Phase-17 canonical-sig layer's `extern … /* match-first, arity N */` decls and
  templated garbage, leaving those families SILENTLY UNBANKABLE. The whole-binary byte-gate
  rejected every one — no wrong match was ever banked (G3/P9 held) — but the engine burned a
  build per sibling and every extract_unit-based readiness analysis was wrong.

- FIX: strip trailing comments before the `;` test.

- REGRESSION-GATED over the whole corpus (6,286 family exemplars, .run/_eu_before.json):
  15 phantom exemplars now correctly refused; 3 garbage units corrected to the REAL definition
  (found in the right region file); 0 real definitions lost; 0 unit contents otherwise changed.
  src/ and config/ untouched, so the committed build is unaffected.

- cookbook §40: the trap + the general lesson — this is the phase's FOURTH silent-skip bug
  (find_site braces, overlay_files splits, reconcile_decls fn-ptr regex, now this). A tool that
  silently no-ops on input it cannot parse is indistinguishable from one that had nothing to do.
2026-07-13 20:53:23 -06:00
Drew T 1ab9905368 feat(phase-26): §8d scope_data_externs — the ×133 sweep blocker fixed; func_8015AE2C banked ×134
- ROOT CAUSE (R14 — the session-7 diagnosis was half right): the isolated region builds [ OK ]
  WITHOUT the body, so §8b isolation was never implicated. `family_remap.gather_externs` prepends
  carried decls at FILE scope; D_801812A4 is a fn-ptr dispatch table the sibling declares FOUR
  incompatible ways at BLOCK scope inside its own later functions, so the carried file-scope decl
  ESTABLISHES A GLOBAL THE TU NEVER HAD and every later block-scope extern must now agree with it.
  Byte-proven asymmetry: BLOCK(int)->BLOCK(struct*)->FILE(void*) builds; FILE(void*)->BLOCK(int)
  errors. It was the ONLY hard error in the build — all 27 carried function externs were fine raw.

- THE FIX (demote, don't reconcile): tools/scope_data_externs.py emits a carried D_ extern at BLOCK
  scope inside the function body when the TU has no file-scope decl of it above the insertion point.
  Byte-neutral (an extern emits no code; type + access opcodes unchanged) and never worse than raw,
  so it needs no oracle, no type comparator, no fn-ptr parser. Restores fidelity — the original
  declares these symbols at block scope in exactly this way. Wired into jtbl_family_bank as the
  `scoped` stage: raw -> scoped -> recovered -> reconciled (scoped is the base for the later stages).

- reconcile_decls is the WRONG instrument for this class, twice: its oracle answers "what does the
  FLEET call this symbol" when the question is "what can THIS TU see", and its DATA_DECL_LINE_RE
  cannot parse `extern void (*D_x[])(void *);` — silently skipping the very symbols that were
  failing (the phase's third silent-skip bug, after find_site braces + overlay_files splits).

- R17 TRIAGE RULE, first real test, held: `conflicting types` = the compiler REFUSED TO COMPILE =
  a C front-end diagnostic = our Python. Reading cse.c/global.c would have taught nothing.

- RESULT: func_8015AE2C (562 ins, reach 134) swept 133/133 siblings, 0 failures. R22 clean-fleet
  136/136 BYTE-IDENTICAL (534 changed src files); dedup-check 1813 validated / 0 failed; 0
  NON_MATCHING (G4). instr-weighted 63.0 -> 63.6%; distinct-code 39.1 -> 40.5% (+256 unique fns /
  +79,957 ins) — one core, ~0 agent tokens.

- knowledge captured during the producing session (R30/R31/R21): cookbook §8d, decision-log
  2026-07-13 session 8, SETUP tool-inventory row; CURRENT_PHASE session-8 checkpoint.
2026-07-13 20:45:15 -06:00
Drew T 12631df74a docs(phase-26): R17 triage rule — 'wrong bytes' -> read gcc; 'won't compile' -> read our Python
Drew asked whether the x133 sweep blocker warrants a gcc-2.7.2 source read. It does not,
and the distinction is worth pinning down because it routes every future residual:

- The sweep blocker is a C FRONT-END diagnostic (conflicting types: two incompatible
  file-scope decls of one identifier in one TU). gcc is correctly rejecting plain C89.
  The bug is in reconcile_decls (fleet-majority oracle vs the TU's visible decl).
  Reading cse.c/loop.c/global.c would tell you nothing.
- func_8017BEBC (close=2) is the opposite: it compiles fine and emits the wrong bytes, and
  the cause is localized to global.c's allocno-priority tie. THAT is the R17/§45-B target
  (gdb-on-cc1 read of allocno_live_length) — 2 instructions from a 107K-ins bank.

Rule: 'wrong BYTES' -> read the compiler (R17). 'won't COMPILE' -> read our Python.
cookbook §31-triage + the CURRENT_PHASE NEXT block annotated with the routing.
2026-07-13 19:50:51 -06:00
Drew T 754ac3428f fix(phase-26): permuter silently no-op'd on every GTE draft (+ --asm-subdir)
Second silent no-op of the §G class, found while permuting func_8017BEBC (close=2):

- hide_asm() is built for __asm__ STATEMENTS and `register __asm__("$sN")` pins inside a
  function body (it scans back to the previous ;{} and forward to the next top-level ;).
  A draft whose GTE ops are #defines CONTAINING __asm__ (the PsyQ inline_c.h convention,
  i.e. most renderer code) therefore had its macro DEFINITIONS chewed up, swallowing the
  function itself -> pycparser 'Function <fn> not found in base.c' -> decomp-permuter
  no-op'd in 0s. base.c contained ZERO occurrences of the target function.
  FIX: cpp_expand_macros() pre-expands with `cpp -P` so each GTE op becomes an inline
  __asm__ statement hide_asm can carry via the b64 pragma. Applied ONLY when a
  '#define ... __asm__' is present -> macro-free drafts byte-untouched.
- p16_permute was hardcoded to OV=ov_SC01_077's MAIN object, so no core in another overlay
  or split object could be permuted at all. Added --asm-subdir (threaded explicitly: a
  def-time default arg cannot see a mutated global).

LESSON (cookbook): permuter 'no match (0s)' is a TOOLING failure signature, never a real
search result. Verify workers actually ran.

Verified: base.c now holds the function; 16 workers searching on func_8017BEBC.
2026-07-13 16:50:38 -06:00
Drew T b0691f4bd9 fix(phase-26): jtbl_carve trims trailing .align pad words (§8a-pad)
A trailing `.word 0x00000000` under a jtbl dlabel is the ORIGINAL TU's intra-rdata
.align 3 padding, NOT a table entry (0x00000000 is not a jump target). The true entry
count is the fn's `sltiu <n>` bound: func_8015AE2C has sltiu 0x7 = 7 entries yet its
raw dlabel spans 8 words.

maspsx drops all .align, so a C-emitted jump table can never reproduce the pad. Carving
to the next dlabel would reserve 8 words while the compiled object supplies 7 ->
.rodata under-fills by 4 B -> every later symbol shifts +4 (the same image-corruption
class as §41d). jtbl_range now trims trailing zero words, leaving the pad in the raw
post-carve data piece.

Retroactively explains the §8a func_80159C84 '5 words vs the real 6' false-MATCH.
Existing carves are parsed from CONFIG, not re-derived, so committed banks are
unaffected (verified: the 3 carved jtbls are absent from the raw data asm). The build
never invokes jtbl_carve, so the fleet is inert to this change until the next bank.

Found by the Fable5 crack of func_8015AE2C (562 ins x134, MATCH, pin-free).
2026-07-13 15:23:59 -06:00
Drew T e79d030499 feat(phase-26): func_80182268 banked via the LAZY isolation path + the void->s32 gate-cap fix
End-to-end proof of the §8b lazy bank composition on a real cracked jr core:
lazy isolate -> jtbl_carve into the isolated subseg -> C body -> whole-binary gate
-> d19c9580 BYTE-IDENTICAL; R22 clean-fleet 136/136.

- func_80182268 (31-ins jr, ov_SC01_077_after) MATCHED first try: shared-tail
  fallthrough (jtbl cases 3+7 enter case 4's tail) + the u16-shift sign-extend idiom
  ((s8)(*(u16*)(p+0x70) >> 8) -> lhu/sll16/sra24). Carve collided with the committed
  func_801734BC carve -> lazy isolation fired exactly as designed.
- R14 FINDING (cookbook §41d): the Phase-17 canonical convention "void->s32 return is
  byte-neutral (§3a-1)" is FALSE for a void body with no `return` — it costs ONE extra
  instruction. canon_sig_reconcile applies it unconditionally, so it turned a perfect
  31-ins MATCH into 32 ins. That extra word made the isolated object's .text 4 B long,
  shifting EVERY data symbol +4 -> ~271k differing bytes, image +5 B. match_one said
  MATCH; only the whole-binary gate caught it (G3/P9).
- FIX (generalizes the §19 sig_unify lesson): every recovery pass is a FALLBACK, never
  unconditional. jtbl_family_bank now gates RAW first, reconciled only on failure.
- 136/136 byte-identical from a clean tree (R22); 0 NON_MATCHING (G4).
2026-07-13 14:34:04 -06:00
Drew T 38ac5659aa feat(phase-26): §8b scoping wall BROKEN — decl-environment reconstruction + lazy per-core isolation
The full 54-jr isolate-all on ov_SC01_077 now builds d19c9580 BYTE-IDENTICAL
(R22 clean-fleet 136/136) — the configuration session 5 could not build. The
heavy-jr harvest (191 cores / 5.53M templatable ins) is unblocked.

- R14 CORRECTION: session-5's "gcc-2.7.2 block-scope-extern TU-persistence" root
  cause was WRONG. There is no gcc quirk — DEFINE_func_* macros expand at FILE
  scope, so their leading externs are genuine file-scope decls that merely live in
  engine_core.h, invisible to any col-0 .c scan (1377 macros / 3929 lines / 1462 syms).
- REJECTED the approved "global symbol->type map + shadow set" design: the engine is
  loosely typed (func_80173544 is DEFINED `s32 f(void*)` yet declared `extern void
  f(void);` inside func_801734BC's body), so declaring every USED symbol hoists that
  block-scope shadow to file scope and CREATES the conflict a shadow-set then dodges.
  Instead reconstruct the original TU's file-scope decl environment and carry it
  strictly FORWARD — conflict-free by construction (every carried decl already
  coexisted with every definition in the one original TU; compatibility is
  order-symmetric; shadows stay in bodies and travel with their item).
- The byte-gate found two MORE lost decl sources, not predicted: (a) a definition is
  itself a declaration for everything below it in its TU (func_8012B2CC undeclared);
  (b) file-local typedefs used by a carried prototype (parse error, Vec3s). K&R defs
  must render `extern T f();` (unprototyped), never f(void).
- LAZY per-core isolation wired into jtbl_family_bank (Drew's call — upfront-x134 =
  ~7,200 region files): jtbl_carve NON-CONTIGUOUS fail-loud -> jr_isolate_all --only
  <core> -> re-extract -> re-carve. Proven on func_80178D40 (890x134, heaviest core):
  carve blocked -> isolated (byte-neutral d19c9580) -> carve in its own subseg.
- TWO LATENT BUGS fixed (both would have corrupted the heavy sweeps):
  * jtbl_carve.func_subseg derived the owning subseg from the ASM TREE, which `make
    extract` never prunes -> after an isolation it returned the STALE owner and
    silently re-created the very collision the isolation removed. Now config-derived.
  * jtbl_family_bank/jtbl_carve revert() DELETED the shared overlays.mk carve var
    unconditionally -> would destroy a COMMITTED carve (all 134 overlays have one) on
    any failed sibling. Now restored to its committed value; only region files created
    by this attempt are removed; dirty-tree preflight refuses to start a sweep.
- docs: cookbook §8b RESOLVED + new §8c "splitting a TU means rebuilding its
  DECLARATION ENVIRONMENT, not moving text"; decision-log 2026-07-13 (R30/R31).
- parser selftest 404/404; R22 clean-fleet 136/136; 0 NON_MATCHING (G4).
2026-07-13 13:25:39 -06:00
Drew T 234788dfc4 feat(phase-26): §8b overlay-src parser (404/404) + jr isolation tool + the gcc-scoping wall finding
- tools/overlay_src_split.py: overlay-.c-aware partition (header = includes + Phase-17
  canonical-sig layer; per-address items = preamble + body; robust def/decl/K&R/DEFINE_func/
  SETTER/RETCONST classification). Fleet-validated 404/404 overlay .c, 341,902 items —
  round-trip exact / 0 unresolved / 0 non-monotonic. The Stage-2 isolation unblock.
- tools/jr_isolate_all.py: multi-cut jr resegment (config split at jr boundaries, source
  repartition + INCLUDE_ASM path repoint, banked-jr carve repoint, -O0 skip, ambient decl
  carry). SINGLE-cut isolation byte-identical (func_8013FFD8 -> d19c9580, R22).
- FINDING (decision-log 2026-07-13): full 54-jr isolation of the dense _after object hits
  gcc-2.7.2 block-scope-extern TU-persistence (func_801734BC/D_80126B3E declared only in
  engine_core.h DEFINE_func macros); mechanical TU-split breaks it. Fix = declaration-
  completion from a global symbol->type map (Drew-approved next step; lazy per-core).
- baseline intact (ov_SC01_077 rebuilds d19c9580); no config/src/binary change committed.
  CURRENT_PHASE session-5 checkpoint + decision-log R31. db.*.gbf = R23 noise, not staged.
2026-07-13 12:00:26 -06:00
Drew T d1dd29d815 feat(phase-26): §8b multi-jtbl same-subseg — contiguous MERGE (built) + isolation scaffold
Session-4 same-subseg handling (the de-risk preamble's harder half; byte-proof of
the merged build + isolation deferred to Stage 2 with concrete cores):

- jtbl_carve.py: MERGE adjacent same-subseg carves into one spanning .rodata piece
  (a code object emits its jtbls contiguous, so two matched jr-fns in one subseg are
  byte-correct iff their jtbls abut). BOUND-FIX: a new jtbl's end is bounded by the
  next raw dlabel OR the next existing carve start (an already-carved adjacent jtbl
  is gone from the data asm -> raw dlabels over-extend it -> false "non-contiguous").
  Config-proven (func_80171B4C 801D8C48 merges with func_801734BC 801D8C68). NO-OP
  for family-1/cross-subseg (single carve per subseg) -> committed configs unaffected.
- jr_isolate.py (scaffold, NOT yet functional): the non-contiguous case — split a fn
  into its own code subseg (whale _o0b precedent) so its jtbl carves independently.
  BLOCKED on split_src_region, which can't partition the overlay .c (global canonical-
  sig extern layer + per-fn callee-externs + DEFINE_func macros + @class annotations,
  ~922 non-address items). Stage-2 build item (overlay-.c-aware source split).
- cookbook §8b (the --order sandwich + the two same-subseg cases + the blocker);
  CURRENT_PHASE session-4 checkpoint updated with the Stage-2 unblock decision.
2026-07-12 22:06:17 -06:00
Drew T 79ca6b4975 docs(phase-26): refine session-3 checkpoint — small-jr-first as de-risk preamble, then heavy 191
- Drew's sequencing (agreed): do the 45 small jr families FIRST — not for byte-weight (~+1% instr,
  129K ins) but to de-risk + harden the §8 x134 pipeline before the heavy Fable5 cores bet on it.
- decisive technical reason: jtbl_carve only built the single-jtbl carve; func_8012ACE0 is now
  matched in all 133 siblings, so family #2 forces the multi-jtbl address-ordered `ld_interleave
  --order` carve -> build & prove it on cheap 30-ins targets first. Also needs no Fable5.
- guardrail kept explicit: small tier = MEANS (harden pipeline + build multi-jtbl), NOT the
  objective; the 191 heavy jr families (5.53M ins) remain THE byte-weight target -> pivot after.
- CURRENT_PHASE.md SESSION-3 checkpoint updated to Stage 1 (small + build multi-jtbl) -> Stage 2
  (heavy 191, Fable5 un-paused). decision-log addendum with the forcing-function wiki lesson.
2026-07-12 20:24:21 -06:00
Drew T 4e17a7e77b docs(phase-26): session-3 checkpoint — heavy-byte-weight reframe (§8 unlocked the switch cores)
- decision-log (R31): §8 unblocked the SINGLE heaviest byte-weight chunk of the game — 9 of
  the 10 heaviest unmatched family cores are switch (jr) functions (func_80178D40 890x134 =
  477K ins alone); jr substantial = 191 fams / 5.53M templatable ins. My "45 small jr families"
  recommendation (129K ins) was a light-tail trap — Drew caught it against the endgame plan
  (heaviest-byte-weight-first). Corrected next play: Fable5 crack the heavy jr cores -> §8 x134
  bank -> parallel R22 verify; needs Task 7 (Fable5) un-paused (§8 makes that worth it now).
- CURRENT_PHASE.md: SESSION-3 checkpoint as the fresh-session resume point (4 commits this
  session: tiny-band commit:0531, §8 PoC commit:0532, §8 x134 commit:0533, R22 parallel commit:0534;
  distinct-code 30.3->39.1%, instr-weighted 58.2->63.0%, R22 now ~50s)
2026-07-12 19:20:58 -06:00
Drew T 5a08180617 feat(phase-26): §8 ×134 automation — func_8012ACE0 banked fleet-wide (133/133, R22 136/136)
- the jr-function ×134 harvest pipeline, proven end-to-end: per family sibling,
  jtbl_carve (per-sibling jtbl-rodata carve, computed from THAT sibling's own jtbl
  address — the fn is at the same vram across overlays but its jtbl floats) -> make
  extract (auto ld_interleave) -> remap_hseq + canon_sig_reconcile -> whole-binary gate
- tools/jtbl_carve.py: per-overlay §8 carve generator (config data-tail split +
  <ov>_JTBL_INTERLEAVE var)
- tools/jtbl_family_bank.py: the sibling sweep driver (idempotent, revert-on-fail, byte-gated)
- tools/family_remap.py: extract_unit now carries single-line typedefs (jr-function bodies
  define local `typedef struct{} Foo_<addr>;` that must template with the body — the
  propagation cap for these; additive, byte-gate-protected)
- func_8012ACE0 family: 133/133 siblings BANKED, 0 failures; R22 clean-fleet 136/136
  byte-identical; 0 NON_MATCHING (G4)
- metrics: distinct-code 39.1% (50,698 unique fns), instr-weighted 63.0%
- opportunity (has_mid_jr families): 237 total (5,805 members) = 46 small mid/tiny
  (771 members, same mechanical pipeline) + 191 substantial (the Fable5 cores, Task 7 paused)
- NEXT: R22 profiling/parallelization; then the other 45 small jr families
2026-07-12 19:02:25 -06:00
Drew T 095a611e75 feat(phase-26): §8 jtbl-rodata tooling — overlay PoC proven (func_8012ACE0, R22 136/136)
- overlay jr-functions can now bank as C: gcc switch jump tables form a .rodata island at
  the overlay TAIL; carve a matched fn's jtbl into a dotted [.rodata, <code-subseg>] subseg
  + ld_interleave (data->rodata->data sandwich) places it byte-exact. cookbook §8a + SETUP.
- tools/ld_interleave.py: --section .<binary> param (derives the <binary>_TEXT/DATA/RODATA/
  DATA2/BSS symbol prefix); default .main = the EXE, byte-identical (backward-compat proven)
- Makefile + config/overlays.mk: <bin>_JTBL_INTERLEAVE hook + a $(strip)-guarded extract
  branch (gotcha caught: a trailing #comment on the := left whitespace -> non-empty -> the
  branch misfired on resident with the EXE defaults)
- PoC: func_8012ACE0 (25-ins jr-fn in ov_SC01_077) reconciled (canon_sig_reconcile) + banked
  BYTE-IDENTICAL d19c9580 -- the first overlay jr-function matched through the C pipeline
- R22 FULL-FLEET clean rebuild: 136 passed, 0 failed (main 143dbb89 unaffected by the
  ld_interleave change); 0 NON_MATCHING in any default build (G4)
- P9 findings: func_80159C84/func_8015444C (the 2 carried Fable5 jr bodies) are rtu_match
  FALSE-matches (incomplete jtbls: 52B vs 56B -> never bank); the maspsx "hang" scare was a
  truncated experimental-file artifact (real pipeline builds in ~1s)
- metrics: distinct-code 39.1% (50,572 unique fns), instr-weighted 62.9%
- NEXT: the ×134 automation (generate the per-overlay carve + template the reconciled body)
2026-07-12 16:37:37 -06:00
Drew T 025cc03f69 feat(phase-26): tiny-band mechanical harvest — 17,975 member-matches, R22 136/136
- family_sweep --hseq --band tiny: 180 tiny matched-exemplar families ->
  17,975 member-matches BANKED / 5,617 gate-rejected (h_seq-collision
  false-templates — the whole-binary byte-gate refused every one; G3/P9),
  266 overlay .c files touched (~76% bank rate)
- R22 clean-fleet (make clean + extract-all-136 + check-all) -> 136/136,
  0 failed; dedup-check 1813 validated / 0 failed; 0 NON_MATCHING in any
  default build (G4)
- metrics: distinct-code 35.2 -> 39.1% (50,571/84,996 unique fns),
  instr-weighted 60.9 -> 62.9%. mechanical size-bands (substantial/mid/tiny)
  now harvested; remaining levers = the two harvest gaps (§8 jtbl-rodata,
  reconcile fn-ptr-extern)
- regen docs/family-hseq.md + docs/progress.fleet.md; CURRENT_PHASE.md log
2026-07-12 15:38:40 -06:00
Drew T 3074ceb485 feat(phase-26): mid-band clean harvest — 6853 member-matches (320 distinct fns), R22 136/136
- plain --hseq --band mid: 6,853 whole-binary member-matches banked = 320 distinct engine functions
  templated across the overlays (matched-exemplar families, plain templating; the ×N leverage of the
  h_seq per-location reframe). 3,098 type-heavy tail + 1,743 pinned + 873 no-ov077-body skipped/failed
  (expected — the reconcile/§8/pin tail, not machinery failures).
- R22 clean-fleet: make clean + extract-all-136 + check-all = 136 passed, 0 failed. 0 NON_MATCHING.
- METRICS: distinct-code 31.1->35.2% (+6,437 byte-distinct classes), instr-weighted 58.9->60.9%.
  Phase-26 total: distinct 30.3->35.2%, instr 58.2->60.9%.
- session-2 checkpoint (CURRENT_PHASE 'SESSION-2 CHECKPOINT') current: next = tiny band, then the §8
  jtbl tooling (Drew-approved) + reconcile fn-ptr fix. Fable5 held until re-approval.
2026-07-12 11:28:48 -06:00
Drew T b94e417edf docs(phase-26): session-2 checkpoint — full resume context (mid-harvest in flight, §8 approved, 2 gaps)
Comprehensive CURRENT_PHASE handoff for a fresh session: committed baseline commit:0528 (729 banks, R22
136/136); the h_seq engine + reconcile-raw tooling map; the mid-band harvest in flight (~2477+ banked,
uncommitted -> R22 + commit next); the two harvest gaps (§8 jtbl-rodata [Drew-approved] + reconcile
fn-ptr-extern); the Fable5 rtu_match-vs-whole-binary finding (no more Fable5 until re-approval); and the
mechanical next-steps priority order. R30 knowledge capture before context handoff.
2026-07-12 10:22:31 -06:00
Drew T 62f9533024 feat(phase-26): +266 reconcile-class banks (2 no-jtbl cracks x133) + Fable5 batch-1 whole-binary findings
- +266 member-matches: func_8015CD20/func_8015C128 templated x133 via --reconcile-raw (each SHA-gated
  per-overlay vs config/check.<ov>.sha = byte-identical, G3). Full R22 deferred until func_80176218
  releases asm/ (established per-overlay-gate + deferred-R22 pattern, as the committed 463 which R22'd 136/136).
- family_sweep: --reconcile-raw now also covers draft-ov077 (unbanked) cracks (template from the RAW seed).
- P9 CORRECTION + decision-log 2026-07-12: the 2 Fable5 cracks rtu_match-MATCH but FAIL the whole-binary
  gate (both jr-functions; rtu_match masks relocs + excludes neutralized INCLUDE_ASM rodata, so it never
  verifies the §8 jtbl rodata). TWO harvest gaps: §8 jtbl-rodata (blocks all jr cracks) + reconcile
  data-extern (D_801891B8-class, blocks ~15/21 no-jtbl triage cracks). 6 no-jtbl reconcile-clean cracks
  bank whole-binary (729 members). rtu_match is NOT a sufficient arbiter for jr-functions.
2026-07-12 01:38:49 -06:00
Drew T 7ccf48f2f4 feat(phase-26): Task-8 reconcile wiring (§41c h_seq) + 463 reconcile-class banks
- BUILT the per-sibling reconcile: family_remap.remap_hseq_body (h_seq-remap a RAW crack draft: symbol +
  immediate + cross-address self-rename) + family_sweep.reconcile_remap_hseq + --reconcile-raw. Per sibling,
  remap the RAW crack then canon_sig_reconcile against that sibling's own TU (the h_seq port of the h_norm
  M2 path) — because a reconciled body is TU-specific and can't template plainly (validation: 0/4).
- HARVEST: the 4 triage isolation-cracks (func_80155800/80167540/801506A4/8016A73C) templated 463/0 x~133
  via --reconcile-raw (0 failures). Metrics: instr 58.5->58.9%, distinct 30.9->31.1%.
- each overlay SHA-gated by harvest_verify vs config/check.<ov>.sha (byte-identical = the match def, G3).
  FULL R22 clean-fleet DEFERRED until the concurrent Fable5 crack agents release asm/ (their m2c needs it);
  R22 fleet-confirm to follow post-window.
- cookbook §40c (the h_seq per-sibling reconcile technique, R30).
2026-07-12 00:03:47 -06:00
Drew T 8dbde10752 feat(phase-26): Task-8 validation slice — reconcile→bank proven (4 cracks into ov077, R22 136/136)
- pre-Fable5-window de-risk (Drew): validate reconcile→gate→template on the triage cracks before the window.
- reconcile→bank WORKS: raw 0/23 (§41 def-side wall) -> canon_sig_reconcile v3.2 -> 4/15 banked into ov077
  (func_801506A4/8016A73C/80167540/80155800), byte-identical, R22 clean-fleet 136/136.
- templating a RECONCILED body x133 FAILS 0/4: reconciled bodies are ov077-TU-specific (canonical-sig casts
  + collision-renames) -> need per-sibling re-reconcile (§41c). Task-8 prerequisite: port the h_norm
  --reconcile M2 path into hseq_sweep so the type-using families (triage cracks + the 61 Fable5 cores) can
  template x134. PURE families already template plainly (Task 5: 399 banked).
- decision-log 2026-07-11: the slice paid for itself — found the templating gap BEFORE spending the window.
  Paused before building the wiring per Drew.
2026-07-11 23:40:01 -06:00
Drew T 5f07d099e6 docs(phase-26): finalize Task-6 triage (119 agents) + banking caveat; pause before Task 8
- full triage complete: cheap 29 (23 closeness-0 isolation-MATCH) / permuter 29 / fable5 61 (1.71M ins).
- attempted to bank the 23 cracked wins into ov077 -> 0/23: the match_one isolation-MATCHes are genuine
  function matches but carry standalone struct/scalar typedefs + Ghidra-typed sigs that conflict with the
  real ov077 TU (redefinition of struct Obj / conflicting types) = the §41 def-side wall. Banking needs
  the Task-8 --reconcile / canon_sig_reconcile pass (not run — paused before Task 8 per Drew).
- docs/phase26-triage.md carries the crack curriculum + the caveat; seeds in .run/phase26-seeds/.
- src pristine, ov077 byte-identical.
2026-07-11 23:12:53 -06:00
Drew T 80536efbea feat(phase-26): task 6 — Ultracode triage of 119 draftable substantial families
- .run/wf_triage*.js Workflow: per-family m2c draft (+§8 jtbl handling) -> match_one reloc-masked
  closeness -> classify cheap/permuter/fable5 + §31/§45 lever + seed to .run/phase26-seeds/.
- 119 families triaged (2.38M templatable ins): cheap 22 (324k ins, 20 already isolation-MATCH) /
  permuter 23 (340k) / fable5 74 (1.72M). The cheap-Opus triage flywheel cracked 20 families to
  closeness-0 as a side effect (each templates x134) -> Task-8 gate+template candidates.
- docs/phase26-triage.md = the crack curriculum (already-cracked seeds + top-30 Fable5 targets +
  permuter band). Seeds in .run/phase26-seeds/. match_one closeness is an INDICATOR; the whole-binary
  byte-gate (Task 8) is the sole arbiter (G3/P9).
2026-07-11 23:00:26 -06:00
Drew T d05203b9a0 feat(phase-26): task 5 — h_seq zero-crack GO/NO-GO = GO; 532 members banked (R22 136/136)
- remap_hseq.gather_externs: carry file-scope externs for body-referenced symbols (extract_unit only
  grabbed adjacent ones) — the decl class that blocked per-location bodies indexing a global. func_8015F118
  gate-fail -> BYTE-IDENTICAL; the 3 tracker-miss PURE families then bank 133/133 each.
- ran the real whole-binary byte-gate on the 29 substantial matched-exemplar families:
  532 members BANKED (byte-gated). Per-family: 3 tracker-miss PURE (0x8015d5e8/0x8015f118/0x801407f4)
  bank 100% x133 = 399 byte-perfect (the tracker-fix free win); 1 cross-addr family 50%; 9 zero-bank
  families are type-using (Work8016/Prim/...) -> the existing --reconcile/type-lift follow-on (Task 8);
  16 families pinned -> Task 7 pin-free re-crack.
- VERDICT: the h_seq machinery (tracker + imm + cross-address + extern-carry) is byte-proven 100% correct
  on clean families. GO to scale.
- R22 clean-fleet: make clean + extract-all-136 + check-all = 136 passed, 0 failed. 0 NON_MATCHING (G4).
  Metrics: distinct-code 30.3->30.9% (+375 fns), instr-weighted 58.2->58.5%.
- decision-log 2026-07-11 (R31: stratify a mechanical-harvest rate by family/class before judging it).
2026-07-11 22:15:30 -06:00
Drew T 462734edb2 feat(phase-26): task 3 — T2a immediate engine (Tier 1) + T2b cross-address, 0-DIFF verified
- family_remap: imm_value (signed/unsigned field-aware) + imm_map_tier1 (diff-driven literal swap:
  asm-side ambiguity guard defers values that also appear at a non-differing position; C-literal
  swap preserves sign + hex-case) + remap_hseq (symbol remap + imm subst + cross-address self-rename
  in one pass; refuses STRUCT/unresolved members -> caller skips, byte-gate would reject anyway).
- Tier 2 (targeted probe) intentionally DEFERRED — build-if-needed per Task-5 measurement; only ~8
  low-weight IMM families, and the whole-binary byte-gate arbitrates (plan: simpler where gate arbitrates).
- VERIFIED (.run/v3_imm.py, match_one reloc-masked so immediates are checked exactly): 0 DIFF on every
  compilable derived draft — 3 IMM + 2 PURE cross-address MATCH; 4 remap-fails were correctly-deferred
  asm-ambiguous values (not wrong output); 45 compile-fail are match_one isolation limits -> whole-TU
  gate in Task 5. Cookbook §40b imm-engine forward-ref fixed.
2026-07-11 21:14:09 -06:00
Drew T faedd103e4 feat(phase-26): task 2 — tools/family_hseq.py full-frontier survey + shared word-diff classifier
- family_remap.py: shared classifier (stream_words / reloc_indices / reg_fields / classify_member)
  — per-instruction diff class RELOC/IMM/IMM_SA/STRUCT, register-drift aware (h_seq ignores registers,
  so regalloc-drift members are STRUCT-excluded, not templatable). Reused by T1/T2a/T3.
- tools/family_hseq.py: cluster ALL unmatched overlay instances by h_seq; per family classify every
  member vs exemplar (PURE/IMM/MIXED), tag per-location/cross-address/scattered, matched-sibling count,
  has_mid_jr (§8), exemplar pick (matched-ov077 > matched > draft-ov077 > modal), size band.
  -> .run/family_hseq.json + docs/family-hseq.md (committed digest).
- VERIFIED: fleet 74.8/58.2/30.3 (= PhaseEnd_25 + progress.py exact); tail cross-check 663 families /
  186 substantial / 1.847M ins (exact); classification vs Plan-agent PURE-same 62 & IMM 8 exact;
  890x134/562x134 PURE per-location + 952x113 #addr21 IMM confirmed. Full frontier: 581 substantial
  families / 3.22M templatable ins; 345 matched-sibling PURE/IMM families / 1.14M ins = V2/V3 corpus.
2026-07-11 21:05:29 -06:00
Drew T 5b7e366648 feat(phase-26): task 1 — extended reloc tracker (addu-hi) + single-pass remap; V0/V1 green
- reloc_targets: propagate lui-hi through add/addu index arithmetic (gcc-2.7.2 indexed-global
  idiom lui;addu $idx;lw %lo($at)). The pre-26 tracker dropped it -> D[i] functions mis-normalized
  per overlay (inflated the 'h_norm reach-1 tail') AND lost their indexed D_ symbols in remap.
  norm_stream/h_norm deliberately UNTOUCHED (fleet metrics + proven sweep depend on it).
- remap/symbol_map: backward-compatible to_addr=None (cross-address T2b sibling + self-rename) +
  imm_map hook (T2a); sequential re.sub -> single-pass simultaneous substitution (fixes latent
  chained-rename/value-permutation corruption). All 5 family_sweep call sites unchanged.
- V0 (.run/v0_reloc.py): func_80141100 22/22 NEW==OLD (zero regression); func_801407F4 15/15 vs
  splat .s (pre-fix 10), recovers indexed D_80187B88/90/B0; cross-addr symbol_map clean.
- V1 (.run/v1_regression.py): 160 real h_norm sibling pairs, 96 SAME, 0 lost — differences are
  strict indexed-reloc improvements only.
- docs: cookbook §40b (the technique, R30) + decision-log 2026-07-11 (the strategic why, R31).
2026-07-11 20:57:28 -06:00
Drew T b438ee1846 docs(phase-25): family-endgame megaplan + checkpoint — the 'unique tail' is ~986 templatable h_seq families
- FINDING (byte-verified): the '36k unique / 87% distinct-code tail' is a strict-h_norm artifact. Re-clustered
  by h_seq (mnemonic skeleton) it collapses 90% into ~754 families (986 substantial nins>=80 / 1.88M ins, top-20
  = 52%), all per-location-shaped; templatability CONFIRMED (identical nbytes/ncalls/calls across ~120 members;
  e.g. 0x80178d40 890ins x121, 0x8015ae2c 562 x121). Endgame = crack ~986 exemplars -> template x120, NOT 36k
  hand-decomps. (Drew's insight; makes 'finish this weekend' credible.)
- docs/family-endgame-megaplan.md: self-contained plan-mode/Fable5 input — Step A cheap map+triage -> Step B
  Fable5 hard family cores -> Step C family_remap immediate-substitution + mechanical x120 harvest -> Step D
  unique residue. Fable5 doctrine (family cores + 2 walls + 3 walled giants, NOT the unique behemoths; parallel-
  isolated, distill-between). Carried context: §45 flagship idiom, flywheel seeds, permuter-batch-walled.
- CURRENT_PHASE checkpoint: megaplan pivot; Fable5 batch #2 + F-band deferred into the megaplan; permuter batch
  ran this session + all walled (masked 22/31/2, 0 banks).
2026-07-11 16:52:46 -06:00
Drew T 8270e7692e feat(phase-25): task A giant #2 — flagship func_80133CD4 (399 ins) cracked ×134 via Fable5 §45; 3 flywheel giants Fable5-seeded
- FLAGSHIP func_80133CD4 (399 ins) CRACKED ×134 (Fable5 gdb-on-cc1 §34): whole-binary byte-gate
  BYTE-IDENTICAL (d19c9580); family_sweep 133/133 siblings, 0 failed; PIN-FREE (×134-clean).
  Retires the ~22-phase 'unsteerable whole-function register permutation'. Fleet instr-weighted
  57.7->58.2%, distinct-code 29.3->30.3% (+1.0% distinct from one giant).
- cookbook §45: merged-accumulator-variables permutation-breaker (K8 no-coalescing -> one reused
  C var) + 1-death local-alloc in-out-asm (flow.c:2511) + offset-0 /s + goto-shared-return.
- FLYWHEEL (3 cheap-Opus, §45 + the map): all 3 walled -> Fable5, each a pin-free ×134-safe seed
  + gdb-oracle spec (func_8014D820 LCS226, func_8016CBC0 c=153, func_801670E4 c=23). Downgraded
  §44-Lever-5 'i=0/p-hoist' (42->0, R14); merge-lever mirror split-law + input-anchor dial.
- R22 clean-fleet 136/136 byte-identical; 0 NON_MATCHING (G4).
2026-07-11 15:09:40 -06:00
Drew T 89162fd6b8 feat(phase-25): task A giant batch 1 — 2 more giants ×134 (func_80135480, func_80163EC8) + §44 levers; 4 Fable5 seeds
- cheap-Opus batch over the 6 frontier giants: 3 banked ×134 this session (func_80166994 §43
  committed earlier; + func_80135480 258-ins block-scoped-pointer-split; func_80163EC8 234-ins
  cross-jump-duplicated-tail, 1 benign $v0 pin). 266 siblings byte-identical, 0 failed
- R22 clean-fleet 136/136; instr-weighted 57.2->57.7%, distinct-code 28.2->29.3%, dedup 1813/0
- cookbook §44 — 5 reusable levers: §43-extension (K&R s16 also covers callee-stash sign-extend),
  pointer-var-decl (avoid &sym CSE-hoist), block-scoped-pointer-split, cross-jump-duplicated-tail
  (cracks a §31-D1/D2-"permuter-only" class), + the intrinsic-wall taxonomy (what cheap-Opus can't)
- R14: §43 does NOT universally transfer (only 1 of 6 giants was K&R-s16; each is its own class);
  giant #1's prior "MATCH" note was stale/false (verify vs bytes)
- 4 giants -> pin-free/structural Fable5+permuter SEEDS (func_80133CD4 flagship §37 allocno-tie,
  func_8014D820 RC-6 pin-free, func_801670E4 scheduling, func_8016CBC0 coalescing); escalation
  = permuter-first then Fable5 §34, queued in the CURRENT_PHASE resume block
- SESSION CHECKPOINT: phase 25 OPEN; fresh session resumes the giant-seed escalation round
2026-07-11 02:27:23 -06:00
Drew T c62fe7f7ea feat(phase-25): task A giant #1 — func_80166994 (369 ins) cracked ×134 via Fable5 + the K&R s16-param idiom (§43)
- Fable5 subagent cracked func_80166994 (trail/afterimage ring recorder, 369 ins) — FULLY
  STRUCTURAL, zero register pins -> swept ×134 CLEAN (exemplar + 133 siblings byte-identical).
  R22 clean-fleet 136/136; instr-weighted 56.8% -> 57.2%; distinct-code 27.3% -> 28.2%
- NEW IDIOM cookbook §43: a K&R s16-param DEFINITION dissolves the §17/§29 "narrow-param wall".
  On MIPS K&R promotes s16->int (ABI-identical to the canon-sig s32), body keeps the in-place
  sll aN,16 narrow/extend the (s16)cast form can't reproduce. void->s32 return-flip pair:
  split //@EDIT (self-fn, ov077-specific) + engine_core.h ec_edit ×5 (byte-neutral, callers discard)
- family_sweep --edit-remap: split-edits now OPTIONAL (apply where present, never skip; the
  whole-binary byte-gate is the sole arbiter, G3/P9) — a sibling lacking the ov077 canon-sig decl
  still banks via ec_edit + body. edit-absent tracked, not skipped
- R14: the prior wave's "@stuck: none — MATCH" note on func_80166994 was STALE/FALSE (re-ran DIFF
  366/369). Verify a MATCH claim vs the bytes, never a stale note
- structural cracks are the ×134-SAFE ones (contrast §42e pin-heavy families that cc1-SIGABRT in
  sibling TUs). Other 6 giants -> cheap-Opus applying §43+§31, Fable5 only on new-class evidence
2026-07-11 01:03:09 -06:00
Drew T c0379f0738 feat(phase-25): progress.py --weighted — byte/instruction-weighted metrics (the honest headline numbers)
- weighted_metrics() from .run/sig.*.jsonl + src stubs (executable code only, resident + 134
  overlays; main EXE excluded). Two framings: fleet instr-weighted (per-overlay, the decomp.dev
  -display number) + dedup distinct-code (each unique h_exact once, the distinct-RE number)
- --fleet now emits THREE labeled metrics into docs/progress.fleet.md: fn-count 74.48% (×134-
  inflated), instr-weighted 56.8% (shipped .text), distinct-code 27.3% (of 84,996 unique fns)
- --weighted prints the two weighted numbers standalone; degrades gracefully if sigs absent
- corrects the stale "~30-35% byte-weighted" estimate: the giant campaign since Phase 19 raised
  the fleet instr-weighted number to 56.8%; the distinct-code 27.3% is the unique-monster-tail truth
- SETUP §tooling row updated (R21)
2026-07-11 00:42:22 -06:00
Drew T 5fcb040dc3 feat(phase-25): task B — family_sweep --edit-remap; 2 array-decay families ×134 (+266 fns), 4 cc1-crash-walled
- family_sweep.py: new --edit-remap MANIFEST mode (§42e) — per family, symbol-remap the
  split-scope //@EDIT old||new per sibling + apply once-global engine_core.h ec_edits
  (byte-neutral), stage the family_remap body, gate via harvest_verify (the sole arbiter)
- BANKED 266/266 (0 failed): func_80136824 + func_80136334 (array-decay ptr-flip) ×133
  siblings each — full ×134. R22 clean-fleet 136/136, fleet 74.40% -> 74.48%, dedup 1813/0
- R14 FINDING (cookbook §42e addendum + decision-log): the other 4 byte-drift families
  (func_80133AB0 zero-reg pin, func_8016DF5C/8013D9B0 GTE-pin, func_80156044 trampoline)
  cc1-SIGABRT (Error 134) in the SIBLING TU — hand pins are ov077-TU-context-specific,
  NOT mechanically ×134-recoverable; backlogged as ×1/permuter fuel. rtu_match/match_one
  are blind here (neutralized/isolation compiles crash too); only make build is truth
- 0 NON_MATCHING in any default build (G4)
2026-07-11 00:03:39 -06:00
Drew T 0241772225 fix(phase-25): canon_sig_reconcile def-finder (\n -> (?:^|\n)) unblocks crack propagation; recover func_8014FE60 x134; fleet 74.36->74.40%, R22 136/136
- R14 CORRECTION of the prior "family_remap limitation" call: it was a MISDIAGNOSIS. family_remap
  succeeds on all droppers; the "remap-fail" family_sweep reports was a mislabeled canon_sig_reconcile
  throw ("no definition of func_X found in draft") — the def-finder regex required a leading \n, so a
  //@EDIT-stripped raw draft with the fn definition on line 1 was not found.
- FIX: def-finder regex \n -> (?:^|\n) (also match a def at draft start; strictly additive, low-risk).
- Recovered func_8014FE60 fully: 133/133 siblings banked (fix + engine_core.h DEFINE_func_8014FDF4
  extern void->s32 global flip, byte-neutral fleet-wide; caller discards return).
- Residual (the genuine, small --edit-remap): func_8016DF5C/80136334/8013D9B0/80156044 reconcile but
  byte-drift per sibling (out-of-body fixes: pointer //@EDIT, no-proto, return-flip not carried per sibling).
- cookbook §42e (the two-layer diagnosis + the forward ×134-leverage-realism rule); decision-log corrected.
- R22 clean-fleet 136/136 BYTE-IDENTICAL from a fully clean tree; NON_MATCHING 7 (0 in default build, G4).
2026-07-10 21:05:25 -06:00
Drew T 56a2be10bf docs(phase-25): decision-log — task-b propagation recovery is a family_remap limitation, not an --edit-remap gap (backlogged) 2026-07-10 20:00:04 -06:00
Drew T 6c0887b097 feat(phase-25): crack fan-out over the frontier map — wave 4, 24/26 MATCH + 1330 swept; fleet 73.97->74.36% (+1350 fns), R22 136/136
- Frontier map (docs/phase25-frontier-map.md, committed commit:0506): rtu_match-measured all 42 draftable
  families -> 37 crack targets; endgame = 42 draftable + 235 matched-free + 2481 absent.
- Crack fan-out wf_b54b5d98-380 (26 tractable-band exemplars): 24/26 MATCH -> 20 banked byte-identical,
  incl. func_8014FBC0 (22 ins x1996 inline-asm trampoline), func_80132144 (27 x539), func_8016CF04
  (engine_core.h void->short flip). Swept x134: 1330 siblings / 931 failed (//@EDIT/trampoline/engine_core
  families -> --edit-remap backlog). Batch = 20 exemplars + 1330 = 1350 fns.
- 5 durable levers -> cookbook §42d: return-type flip BOTH ways (void<->s32/short); address-recompute-vs-cache
  (the unifying read-global rule); the full-inline-asm trampoline idiom + family_remap-inside-asm; memcpy->
  struct-assign at scale; phantom-frame induction.
- Deferred (backlog, map tiers): func_8016D1D8/80165240 (M-linkwall), func_80164E40 (sig-reconcile),
  func_801457A4 (-O0), func_8012E364/801549F8 (permuter).
- R22 clean-fleet 136/136 BYTE-IDENTICAL from a fully clean tree; NON_MATCHING 7 (0 in default build, G4).
2026-07-10 19:49:39 -06:00
Drew T b099169430 docs(phase-25): frontier map — rtu_match-measured classification of the 42 draftable + 235 matched-free families
Systematic map of ALL remaining endgame work (replaces the stale-object-tainted wave-2 list).
- 42 draftable (crack): 37 fan-out targets (24 reconcile-first + 7 DIFF-crack + 6 near, leverage-ranked)
  + 4 F-jumptable + 1 M-linkwall (rtu-blind specialized tiers). Giants 200+ = likely Fable5 short-list.
- 235 matched-free (propagate): earlier-sweep-failure walls -> propagation enhancements (--edit-remap, split-TU).
- 2481 absent: last.
docs/phase25-frontier-map.md + .run/frontier_{draftable,measured,crack_targets}.json.
2026-07-10 17:54:01 -06:00
Drew T 8fa29f2dda feat(phase-25): T7 F-band wave 3 part 2 — corrected rtu_match fan-out, 7/9 cracked + 266 swept; fleet 73.89->73.97%, R22 136/136
- NEW tools/rtu_match.py: real-TU-faithful, PARALLEL-SAFE per-fn match check. Compiles the WHOLE
  split TU (candidate spliced, INCLUDE_ASM neutralized via -DINCLUDE_ASM(a,b)= + -Isrc/<source>)
  in a per-fn temp dir -> no asm/, no shared overlay build. Closes match_one's isolation blind
  spot (in-TU decl/global-type/memcpy-builtin drift) so a MATCH HOLDS at the whole-binary gate.
- Corrected Ultracode fan-out (wf_80762f2c-822, 9 xHigh workers): 7/9 real-TU MATCH -> all 7
  banked byte-identical (individual + combined d19c9580), ZERO drift (vs wave-2's ~50% attrition).
  Banked: func_8012FCC4 func_80133AB0 func_80134A74 func_80136824 func_8014DD8C func_80168828
  func_8016C188. func_8012FCC4's "irreducible" delay-slot was a wrong-callee-arity bug.
- Swept x134: 266 siblings banked / 266 failed (the 2 //@EDIT families func_80133AB0/80136824
  can't per-sibling-reconcile via family_sweep -> backlog: a --edit-remap enhancement). Batch =
  7 exemplars + 266 = 273 fns.
- func_8014DD8C: engine_core.h DEFINE_func_8014D790 extern void->s32 flip (byte-neutral fleet-wide,
  caller discards return) -- R22-confirmed neutral across all 136.
- 7 durable levers -> cookbook §42c (callee-arity delay-slot, pointer-global *(T**)&, array-decay
  CSE, §17 zero-reg copy, void->s32, register-arg capture, free-floating load hoist). rtu_match -> SETUP §6.
- 2 DIFF -> permuter (func_801670E4 70->48, func_80185BA4 c=65), seeds .run/crack3/wave3/.
- R22 clean-fleet 136/136 BYTE-IDENTICAL from a fully clean tree; NON_MATCHING 7 (0 in default build, G4).
2026-07-10 17:23:20 -06:00
Drew T 69d1d37262 feat(phase-25): T7 F-band wave 3 — func_80164930 cracked + swept ×134 (read-global fix); fleet 73.85->73.89%, R22 136/136
- func_80164930 (81 ins) CRACKED + swept x134 = 134 fns (133/0 siblings, family_sweep --reconcile).
  The crack = the read-global fix: flip the file-scope decl s16->u16 (byte-neutral to the store-only
  caller func_801647A4) + reference the global directly, so the read lowers to direct-addressed `lhu`.
- TWO DURABLE FINDINGS (cookbook §42b):
  (1) THE STALE-OBJECT GATE TRAP: a piped `make build >/dev/null` that FAILS leaves a stale .o, and
      `asm-differ -o` then reports a phantom score-0. This invalidated wave-2's "iso-drift" labels --
      a rigorous re-check (rm .o + build exit-code + real whole-binary SHA) shows all 4 remaining
      iso-drift drafts NOCOMPILE (unreconciled callee externs vs the TU canonical-sig layer). Every
      gate MUST rm the split .o + check the exit code (compounds the §42a --out gotcha).
  (2) canon_sig_reconcile `*(T*)&D_sym` READ-global drift: &sym forces the address into a held register
      (kills direct %hi/%lo -> schedule drift); write-only globals unaffected. Fix = file-scope exact-type
      decl + direct ref (a block-scoped `extern u16` vs ambient s16 is a hard cc1 conflicting-types error).
- Frontier reassessed: the 9 remaining wave-3 targets each need real-TU reconcile-cracking (NOT gating the
  broken wave-2 drafts); each cracks -> ~134 fns (all x134 families). ~1,200 fleet potential.
- R22 clean-fleet 136/136 BYTE-IDENTICAL from a fully clean tree; NON_MATCHING 7 (0 in default build, G4).
2026-07-10 14:58:19 -06:00
Drew T b936dec411 docs(phase-25): T7 F-band wave 2 — 4 banked + 399 swept ×134 (fleet 73.73→73.85%, R22 136/136)
- Ultracode 14-worker wave 2 (§42 playbook): 9/14 iso-MATCH -> 4 banked, 5 real-TU drift, 5 near
- Banked: func_80133784 (203-ins 29-100 win), func_8017B614 (memcpy-fix held), func_8017EF50, func_80145CEC
- Swept ×134: 399 member-matches / 0 failed (auto-committed commit:0502)
- cookbook §42a: real-TU-verify rule (iso-MATCH != real-TU bank; 5/9 drifted), memcpy->struct-assign fix, 5 levers
- Session total: fleet 73.66% -> 73.85% (~673 fns across 2 waves); dedup 1813; NON_MATCHING 7 (0 in default build)
2026-07-10 12:52:20 -06:00
Drew T 67a8fe670d docs(phase-25): T7 F-band ≤28 regalloc crack wave — 4 banked + 266 swept ×134
- Ultracode 9-worker wave (register-pin/§31-density levers) cracked 7/9 to byte-0 in isolation
- Gated: 4 banked byte-identical (func_80134C20/801345F8/80141A60/80180F10); 3 real-TU drift; 2 near
- Swept ×134: func_80134C20 + func_801345F8 = 266 siblings (func_80141A60 frame-pad = exemplar-only)
- Fleet 73.66% -> 73.73%; R22 clean-fleet 136/136; dedup 1813; NON_MATCHING 7 (0 in default build)
- cookbook §42: density-lever catalog + 3 tooling gotchas (harvest_verify --out, reconcile fn-ptr, R22 extract-all)
- src banks already committed commit:0500 (family_sweep --commit)
2026-07-10 04:22:52 -06:00
Drew T ee957d11c6 docs(phase-25): T7-M4 verdict — NOT mechanical (0/8), re-tiered to F-band; checkpoint for fresh session
- M4's 8 fns byte-correct in ISOLATION but drift 8-69 in-TU (codegen scheduling/volatile-loss, not
  data-type casts; 4 have no data conflict) -> reconcile_decls banks 0/8. R14 correction: the T6
  'mechanical M4' projection was a 3rd object-probe over-count (after jumptable + linkwall). The 8
  re-tier to F-band (permuter/§31). cookbook §41b-addendum + decision-log R31 entry.
- T7 truly-mechanical tier EXHAUSTED: M1 37 + M3-clean 2 = 39 exemplars swept ×134 = ~4,694 fleet fns,
  fleet 72.29 -> 73.66%, R22 136/136 (committed commit:0495/commit:0496/commit:0497). CHECKPOINT for a fresh
  session; phase OPEN; NEXT = the F-band frontier (~39 fns) + jumptable/linkwall specialist workflows
2026-07-10 01:52:24 -06:00
Drew T 1ea7c2925d feat(phase-25): T7-M3 — 2 no-proto exemplars banked + swept ×134 (engine_core.h fleet-neutral)
- 4 clean M3 fns: rewrote their engine_core.h macro-internal externs to no-proto (10 decl edits,
  byte-neutral — every caller passes matching args): func_80131B14/8015D01C/8012D664/8016F0AC
- banked 2 in ov077 via canon_sig_reconcile v3.2 (now sees the no-proto canonical): func_8012D664
  (44), func_8015D01C (58); swept ×134 -> 266/266 members banked (100%)
- 4 M3 residue deferred (func_80131B14/8016F0AC arity, func_8013D9B0 TU-internal, func_80182988
  loose-typing macro)
- R22 clean-fleet 136/136 byte-identical (the fleet-wide EC no-proto change verified neutral);
  dedup-check 1813/0; 0 NON_MATCHING (G4)
2026-07-10 01:43:05 -06:00
Drew T c908c3913a feat(phase-25): T7-M2 — 4,389 def-side-wall members swept ×134 (fleet 72.29→73.58%)
- tools/family_sweep.py --reconcile <rawdir>: the Q5-proven per-sibling path — symbol-remap the RAW
  exemplar draft (family_remap.symbol_map) then RE-RUN canon_sig_reconcile v3.2 against EACH sibling's
  own TU (block-scope-vs-ambient decisions depend on the sibling's decompile state), then the plain
  whole-binary byte-gate. Plain remap of the ov077-reconciled body banks 0; per-sibling reconcile banks 94%
- swept the 35 M1 exemplars across 133 overlays: 4,389 / 4,655 member-remaps banked (266 per-sibling
  loose-typing-wall misses -> backlog); 266 overlay source files gained real C defs
- fleet 72.29% -> 73.58% (+1.29%), REAL 251,804; R22 clean-fleet 136/136 byte-identical (make clean +
  extract-all-136 + check-all); dedup-check 1813 validated / 0 failed; 0 NON_MATCHING (G4)
- cookbook §41c (the ×134 def-side-wall sweep). ~0 agent tokens (local cpp+build only)
2026-07-10 01:20:38 -06:00
Drew T 5b94a8247b feat(phase-25): T7-M1 — 37 exemplars banked ×1 via canon_sig_reconcile v3.2 (giants incl. func_8016A290/284)
- tools/t7_bank.py: the M1 driver (reconcile-at-bank-time against the CURRENT TU + harvest_verify
  whole-binary gate; chunk-bet + per-round re-reconcile for cross-fn ambient mutation; giants first)
- canon_sig_reconcile v3.2: uniquify ALL draft-defined type names AND struct/union TAGS to <name>_<addr>
  (byte-neutral) -> collision-proof when many exemplars bank into one TU (the 'redefinition of struct Fr'
  class); banked func_8016A290 (284-ins giant) + fixed the inter-draft collisions
- 37/40 non-jumptable M1 exemplars banked BYTE-IDENTICAL (ov_SC01_077 d19c9580, clean rebuild); each is
  currently ×1 (M2 sweeps them ×134 next)
- R14 CORRECTION (cookbook §41b): the T6 object-only probe OVER-counted BANKABLE by 7 -- it is blind to
  rodata + link. (a) 4 jump-table fns (3 _o0 giants + func_8012ACE0): .text byte-perfect but a switch
  jump table in rodata diverges -> REFUTES the T6 'Q3 -O0 REFUTED' claim; F-band jump-table workflow.
  (b) 3 last-referencer link-walls (func_8016D688/D1D8/165240): C-ifying the only asm referencer of a
  scratch data symbol drops splat's auto-symbol -> ld undefined reference; M-linkwall tier, deferred
- ov_SC01_077 REAL 32 stub-exemplars -> 37 more defined; whole binary byte-identical throughout (G3/P9)
2026-07-10 00:02:55 -06:00
Drew T f12bff04c0 feat(phase-25): T6 — Fable5 crack curriculum: def-side wall ~71% tool-shaped; 44/62 probe-BANKABLE via canon_sig_reconcile v3.1; x134 sweep law proven
- R14 re-verified ALL 95 draftable-exemplar stubs (match_one, best-of every drafts dir):
  62 genuine isolation-MATCH (incl. all 11 batch-2 'walls' + the 3 _o0 giants), 31 verified
  nears (closeness reproduces exactly), 2 no-draft tinies
- 6-iteration probe program (reconcile -> splice into the REAL TU -> full cpp|cc1|maspsx|as ->
  relocation-masked in-TU byte-compare): canon_sig_reconcile v1 itself was the wall for most.
  v3.1 fixes 5 measured defects (scalar-typedef strip; preprocessed-TU canonical incl. the
  self-decl class; block-scope-move-not-strip [draft extern types are LOAD-BEARING]; colliding-
  typedef RENAME [SVEC/Vec3/ApplyMatrixSV walls = rename, never layout]; decl-lines-never-cast
  + comment-masked def anchor) -> BANKABLE 10 -> 20 -> 37 -> 44 (4,254 ins, 13 giants >=145)
- swing answers: Q1 44 mechanical (not ~19); Q2 resident-callee moot (real class = arity-vs-
  visible-prototype -> M3 engine_core no-proto rewrite, 6 fns); Q3 -O0 reconcile REFUTED (all
  3 _o0 giants bank under v3.1 as-is); Q4 type collisions = rename; Q5 x134 sweep = remap +
  PER-SIBLING re-reconcile, 6/6 proven (S41 sweep-fragility dissolved)
- gate-validated end-to-end: func_8013DD68 (187-ins wall giant) banks BYTE-IDENTICAL through
  make build (d19c9580 == check file); tree restored (no T7 execution in T6)
- deliverables: docs/phase25-t6-curriculum.md (tiers M1-M4/F + per-fn worklists + commands +
  projections: mechanical tiers ~ +2.2% fleet for ~0 agent tokens), .run/t6_worklist.json +
  .run/t6_recon6/ (44 staged drafts), cookbook S41a, decision-log R31 entry, CURRENT_PHASE T7 handoff
- cost: ~0 agent tokens (local deterministic compute; no Workflow/Agent fan-out)
2026-07-09 23:39:14 -06:00
Drew T d572cc4d2b chore(phase-25): T5b batch-3 (_o0 measured) + T6 Fable5 brief + match_one --o0 (fleet 72.29%, handoff)
- batch-3: the 3 _o0 giants 3/3 isolation-MATCH at -O0 (new tools/match_one.py --o0 flag);
  0 banked — an -O0 in-context byte-diff (canon_sig_reconcile's void->s32 is NOT byte-neutral
  at -O0) -> deferred to T7. Frontier 125/127 draftable exemplars measured.
- R14 correction: the mechanical reconcile-sweep is NOT the clean 51-target x134 win first
  hoped. The frontier "match" status carried un-verified agent claims (5-sample spot-check
  = 3/5 genuine); ~19/51 have clean engine_core.h canonicals (the reliable canon_sig_reconcile
  tier), the rest hit VARIED walls (callee-sig conflicts, non-identical types Vec3/SVEC,
  macro-local data) -> this is the genuine Fable5/T6 residual, not a mechanical sweep.
- docs/phase25-t6-fable-brief.md: the grounded Step-B input package for the fresh Fable5Max
  session to author the crack curriculum (95-stub worklist by wall-class + tools + 5 swing
  questions). CURRENT_PHASE: T6 hand-off (fresh session, Fable5Max, read the brief). Phase OPEN.
2026-07-09 22:45:56 -06:00
Drew T 20747321c4 feat(phase-25): T5b batch-2 — def-side wall cracked mechanically (canon_sig_reconcile); +5 giants, 3x134 (fleet 72.18->72.29%)
- 29 giants drafted (Opus-xHigh wave), 16 R14-isolation-MATCH but 0 auto-banked: ALL
  blocked by the DEF-SIDE canonical-sig wall (Ghidra-typed draft sigs conflict with the
  engine_core.h canonical, which lives inside DEFINE_ macros so sig_unify can't reach it).
- NEW tools/canon_sig_reconcile.py: strip ambient-dup typedefs/externs -> rewrite def to
  the canonical sig -> cast changed params AT USE (never intermediate locals: a local adds
  a pseudo -> regalloc shift -> byte-diff, measured 70ff4748 != d19c9580). Byte-neutral.
- BANKED 5 giants mechanically: func_8013B274 func_80130D48 func_80167DBC (family_sweep
  x134) + func_8016DC20 func_8018514C (exemplar-only). ~404 new fn-defs.
- R22 clean-fleet 136/136 BYTE-IDENTICAL (from make clean + extract-all + check-all),
  dedup 1813/0, 0 NON_MATCHING (G4).
- 11 walls backlogged (non-identical ambient types SVEC/ApplyMatrixSV, macro-local data
  symbols D_*, u8 redef, byte-diff) + 13 nears (permuter-ILS/Fable5 fuel). Frontier +29.
- Cookbook §41 (the reconcile recipe + the at-use-cast-not-locals regalloc proof) +
  decision-log R31 (the "giant tier was plumbing not matching" pivot). R30/R31.
2026-07-09 20:56:35 -06:00
Drew T 808ec6ff7e feat(phase-25): T5b batch-1 COMPLETE — continuation +541 fns (fleet 72.02->72.18%)
- batch-1 cheap tier (83) now 100% drafted: the 29-continuation recovered via
  resumeFromRunId (9 session-cap failures re-run, 20 cached-replay, 0 errors).
- 22/29 -O2 match_one-MATCH; gate banked 8 clean (main 3, _a 2, _after 3) +
  family_sweep +533 siblings across 133 overlays (5 exemplars, ~0 tokens).
- R22 clean-fleet 136/136; dedup-check 1813/0; 0 NON_MATCHING (G4).
- backlog: func_801457A4 (MATCH but -O0-only -> batch-3), func_80135004/8013AD38
  (need the T7 caller-decl reconcile), func_80168828 (close=8, permuter fuel).
- frontier map now 93 exemplars measured (.run/t5_frontier.jsonl).
- docs/gen3-parking-lot.md: captured the Gen3 native-port recomp architecture
  (PsyQ-SDK HLE boundary on Vulkan; recomp-front-end + decomp-incrementally hybrid).
- session totals: fleet 71.36 -> 72.18% (+2820 fns). Cheap tier done; giants next (hold).
2026-07-09 15:47:30 -06:00