- run 5 under BRIEF-run5.md (the D6 guardrails restated): ProjectArchitect 2.0 §1–§9 then the kit Steps 0–10, unattended from
answers.md; 4 trailer-free commits; stopped_at null; manifest 57 == 57 (docs/inherited-record.md included); G 67; seeds 34/34;
check-ignore 9/9 + 5/5; placeholder audit clean; the audit exits 0 in the throwaway; PhaseEnd_Phase0.5 + the archived log; tree
clean; settings/statusline/memory/ghidra/dumps/~/.claude guardrails unchanged
- the agent's notes, acted on: the installer named pa-overlays.md without its templates/ folder at Steps 6 and 8 → `$KIT/templates/…`;
its own write-scope slip (two staging files under /tmp, deleted) recorded; the manifest rule's silence on a file the installer
creates and deletes itself noted
- the judge: my run-5 BEFORE snapshot stripped the first porcelain line's status space and so failed to exclude a deletion under the
dry-run's own directory (the false flag of the first judge pass — re-filtered, not re-snapshotted); the judge's reader crashed on an
empty dirty set (a one-token line) → tolerated; run-4 evidence kept under the .run4 suffix
- wiki page (five dry-runs, the run-5 row), Home/Tools/README/SETUP rows: five runs
- 21 read-only Opus slices over the 26 worklogs (30,540 lines read; the three giants by line range), briefed by
.run/P33.5/log-mining/BRIEF.md with the "already banked?" grep protocol: 777 candidates, 634 already banked, 143 NEW;
every cited log line verified to exist by harvest.py and read; 142 banked + 1 dropped (the miner's own low-value verdict)
- decomp-kernels.md: twelve kernels DK-69–DK-80 (instrument blind spots; verdict staleness + the health suite; what earns
belief; denominators/units/labels; leverage vs tractability + campaign scoping; models and prompts; the unattended run;
agents and the tree; edits that keep proofs; the search harness + the compiler as evidence; maintaining the knowledge base;
hosts and services), each provenance line generated from the slices' cited worklog lines (bank.py); section 8 retitled;
Coverage "In all: DK-1 … DK-80"; every count mention → 80 (kit README, methodology, SETUP row, wiki page)
- docs/accelerators.md "P33.5 S92" (two accelerators: a distillation ships with a coverage check; the end-of-project worklog
pass recovers the fixed-but-never-generalised lessons — 1 in 5 here) → cited by the twelve kernels (kit_coverage: 59 entries,
42 cited + 15 dispositioned, 0 UNCOVERED; the matcher now requires an un-numbered entry's FULL group text);
docs/decision-log.md "P33.5 S92" (R31: the question, the measurement, the pivot, the 82%/18% why, the hindsight path)
- evidence tracked under .run/P33.5/log-mining/ (BRIEF, 21 slice reports, HARVEST.md, HARVEST_TABLE.md, harvest.py, bank.py;
a dated .gitignore block); expected-manifest +1 (docs/inherited-record.md); make kit-corpus regenerated the record copies
- verify: tool_census --check OK (358 copies); kit_coverage OK; kit_lint OK (0 leaks over 436 files); doc_links --strict OK;
wiki_render --selftest 32/0; audit_public OK on the new files; 80 DK ids cited, 0 dangling
- decomp-architect/corpus/record/: the how-to (13), decision-log, accelerators, retrospective, story, wave-playbook, effort-map,
gen3-standards, gen3-handoff, DIGEST and every PhaseEnd (34) verbatim behind an authored front page (what each is, how to
read it, what is NOT there — the phase logs, R19 — and that the mining pass is their distillation); tool_census: RECORD_SOURCES
+ record_dest + the third corpus in plan/write/check (358 copies + 28 pointers, --check OK); kit_lint exempts corpus/record;
SETUP Step 6 gains 2c docs/inherited-record.md (+ the verify line; expected-manifest +1); ops-setup/README/tree/methodology/
wiki page/Home/Tools page/README bullet/SETUP row: "two dictionaries" → three
- tools/kit_coverage.py (+ config/kit_coverage_map.tsv): derives R1..R83 from DIGEST §3 (asserted contiguous) and the 58
accelerator entries (headings + numbered items), asserts each is cited by a provenance line of the registry seed / the
kernels or dispositioned (G / DK / FOLDED:G / ENV / PA / SEED: / KIT: / RECORD / COOKBOOK / NOT-PORTABLE; unknown ids
refused); first run: 26 uncited rules + 21 uncited entries → DK-66 (a ledger's tie-break, a checker's widening and a blanket
commit are part of the instrument — R70/R80/R52), DK-67 (the ignore file's directory-form wall — S91 (1)), DK-68 (a
summarised signal is a claim, not ground truth — R14/R66) in a new kernels section 8 (the museum is 9; "In all" 68) + 41
dispositions (15 PA, 3 ENV, folds into G6/G18/G38/G66/DK-12/19/20/22/25/26/31/35/44/45/46/57/61, 1 KIT template, 1 COOKBOOK);
now 0 UNCOVERED on both populations; wired into tools-health after tool_census --check; SETUP row + dictionary row
- verify: tool_census --check OK; kit_coverage OK (rules 57 cited + 26 dispositioned / 83; accelerators 41 + 15 / 58);
kit_lint OK; doc_links --strict OK; wiki_render --selftest 32 pages / 0 unlisted
- kit: DK-65 "types are a banking lever and a width lever, not a byte lever" (kernel, when, cost, calibration fence, provenance;
the kernels file now states its own total "In all: DK-1 … DK-65" and SETUP Step 6 compares grep -c against it instead of a typed
64); intake row 6's milestone gains the canonical type layer (one definition per shape, widths proven by the bytes at bank time,
a bank refused for a duplicate definition or a raw address cast) + the type tools moved forward + G62/DK-65 in its columns; row 10
reads "short if Part C and Phase 6's type layer held"; G62 extended with the bank-time clause (G1–G67 kept); tool_dictionary:
lift_types + canon_sig_reconcile P10 → P6 and the five type tools' need-keys name the type layer at Phase 6 (the phase column is
one token — the corpus dir derives from it); the cookbook front page's type-verdict sentence (a NAME never moves a byte, a WIDTH
or SIGNEDNESS is the one place a type does, the permuter cannot reach it); the methodology's "Types — the two-sided verdict"
paragraph; the kit README's table + tree now name the two dictionaries and layout-contract.md; make kit-corpus regenerated the
tool index, the MANIFEST and the corpora (302 copies + 28 pointers)
- wiki: docs/wiki/Start-a-new-decomp-project.md — the three steps, what it installs / does not (the two dictionaries), the ladder
(11 rows), the five AI-use rules, the six inversions (raw casts → declared symbols; DK-65), the compiler question, the accelerators
one line each (58 rows), the four dry-runs, how it is kept honest; sidebar + Home rows; Tools-from-this-project rows for the kit
and the tool index; README bullets for both; SETUP row for decomp-architect/ (R21); Where-the-project-goes-next links the page and
records the probe PASS (2026-09-07); phase34-seed: task 0 PASSED, the kit carried whole through the flip and split later
- verify: wiki_render --selftest 12/12 + reachability 32 pages / 0 unlisted; doc_links --strict 58 documents / 451 links / 0 pending /
0 broken / coverage 65 of 65 (one BROKEN on the first draft — a foreign project's docs/ path cited in backticks — reworded);
kit_lint OK (leak 0 / placeholders 22 == 22 / syntax 0 / gitignore 75 identical); tool_census --check OK; 65 DK ids cited, 0
dangling; audit_public OK on the touched files; no build input changed
- log + checkpoint (NEXT = task 15, Max, Tier 1 — prompt Drew and wait for gate 2)
- docs/commit-map.tsv: 4,032 rows (ordinal of the ORIGINAL main -> rewritten hash, author/committer dates, subject);
1 pruned row of zeros (ordinal 1712, "session archive update"); 0 old hashes asserted; ordinal 1 unchanged by the
rewrite (byte-identical)
- resolve_tokens: 1,238 commit:NNNN tokens -> shortest-unique new hashes in 98 files (docs, phase-ends, logs, tool
docstrings, 2 C comments, the A5 evidence logs); residue left as tokens: commit:1712 x4 (the pruned commit),
commit:orphan-24 x2, commit:orphan-26, commit:orphan-35 (cited commits that exist in no lineage)
- the rewrite (C4): filter-repo 2.47.0 on a bare clone of the C2 tip, 311 s, exactly 1 pruned, main 4,032 -> 4,031;
the pre-rewrite history is mirrored in the private archive repo and in the local bundle
- the proof (C5): verify_rewrite 4,031 pairs / 0 failures; absent_scan 0 offenders; gate_scan 0 offenders on the clone
- adoption (C6): 100 text files differ at the tip, 0 purge paths, 0 added/deleted; leftover refs dropped; no gc yet
- resolver skips tools/public_rewrite/ (its self-test fixtures are the token grammar, not citations); repo-local
identity is the GitHub noreply address from here on; CURRENT_PHASE: C4–C7 logged, checkpoint -> NEXT = C8
- hash_dict (4,420 commit objects -> commit:NNNN / twin / orphan; 150,280 prefixes; 0 ambiguous; 0 collisions with 1,480
cited content hashes; scratch mailmap), scrub (12/12 self-test; HEAD sample 731 distinct tokens == git's own lookup),
gate_scan (+ expected_offenders.txt fixture: the R39 negative control, PASS over 16.8 GB in 2 m 25 s; rom_blob_ids =
content/signature hits U purge-path blobs not shared with any other path), run_filter (module API; --force only for the
deleted tag), verify_rewrite (pairwise proof + no purge path survives + pruned set == derived purge-only set),
build_commit_map (0 old hashes asserted; unchanged commits exempted), resolve_tokens, absent_scan (positive control on the
current repo: FAIL 82,362), probe_github.sh (skips unchanged commits)
- trial #1 found two defects the plan had not foreseen: the EMPTY blob in the strip list (--strip-blobs-with-ids then
undid every "file emptied" change in history and pruned a restore commit) and the byte-identical Initial commit keeping
its hash; both fixed with controls
- trial #2: filter 269 s, exactly 1 pruned, verify 4,029 pairs / 0 failures, map 4,030 rows, absent_scan + gate PASS on
the clone, 1,231 tokens resolved at a trial tip (residue 7: the pruned commit x3, orphans x4), aggressive repack 500 -> 80 MB
- SETUP P33 C1 section + rows (R21); runbook §3/§5/§6/§10 measured; requirements-python.txt; CURRENT_PHASE -> NEXT = C2
- pre-checks: census (nothing project-authored under a purged dir), ignore coverage with `git check-ignore --no-index`
on every path, and the control that the public build needs none of it (main 143dbb89 byte-identical with tools/psyq
+ .run/obj40 + .run/obj42 moved aside; WITH state restored)
- after: git ls-files on every purge path = 0; no untracked purge path; tools/audit_public.py OK — 0 offenders among
6,566 tracked paths (255 before; the no-rom `audits` CI job goes green from here); make check-env 0
- docs/public-flip-runbook.md (NEW): Block C operational — decisions, actor table, C3..C11 with commands/checks, the
Support-ticket text, the probe, the fallback, the risk register, rollback; the mailmap is scratch, no personal
address in any tracked file
- SETUP §2.3/§2.4: the zips' sha256 + sizes (download-only now); verification.md: a --cached removal changes no
tracked-content byte, A5 holds for this tip; CLAUDE.md fail-safe: never `git clean -x` (ignored-but-present RE data);
decision-log R31 entry (why the purge leaves the index before the rewrite); CURRENT_PHASE -> NEXT = C1
- audit_public: purge paths from purge_set.txt (the C1 rewrite's own input) + a DERIVED ROM-hash set (1,801 manifest
rows + 218 check.*.sha + redump Track 1) + 50 MiB cap; controls: the current tree FAILS naming exactly the purge set
(255 rows), a clean subset OK, a renamed EXE copy caught by content; zero-length files exempt (the empty-file SHA1 is
also the zero-length SC04/SC05 FILE_029/1.6 payloads')
- compile_only: Makefile flags parsed at run time; TUs from <alias>_SRC_DIR with nested-binary pruning; skips derived
(70 LINKED tiles, 47 INCLUDE_ASM TUs), -O0 TUs compiled at -O0; PR scope 54/54 in 1.6 s; fleet 4,170/4,170 in 123 s
at -j32, failed 0; unknown alias refused (R43)
- no-rom.yml: audits (8 commands, each re-run under the system python without the venv -> rc 0) + compile-only (apt
binutils-mipsel + cpp-mipsel-linux-gnu, cc1 from the sha256-checked tarball, maspsx submodule; PR scope on push/PR,
--all weekly + dispatch); the audits job is RED until C3 by design
- SETUP P33 B7 section + 4 inventory rows (R21); CURRENT_PHASE log + checkpoint -> NEXT = B8
- ImportAnnotations.java: the S86 OSGi-bundle blocker was 3 javac errors (Long->int unboxing x2, a nonexistent
LocalVariableImpl ctor -> VariableStorage); "/undefined" resolves to DataType.DEFAULT (it lives in neither type
manager — main's first proof passed the cmp with failed=13 because the plate-comment rows had set the same function
comments); ghidra_rebuild.sh now dies unless the import printed failed=0 (R49), writes .proof markers
- ghidra_annotations_delta.py: analysis drift measured and encoded as three counted classes — Error/Analysis bookmarks;
auto-named DEFAULT functions the rebuild did not create (29 in main's LINKED regions); auto-named rows lagging the curated
symbol file (10 sep8 + 5 aug31, R15). Result: main 38 hand-authored rows (13 annotated fns incl. 3 the ELF does not
define, 22 comments, 3 labels); resident/overlays/protos container rows only; the DB holds no hand-authored types
- controls (R39): mutated block row -> PROOF FAIL; synthetic comment/bookmark/label/signature round-trip -> PROOF PASS
twice (idempotent); the filter keeps the synthetic rows and a hand-renamed name-only diff; fake failed=2 refused,
resident re-proven; roster --check controls both ways
- proofs, all PASS failed=0: resident 65s, ov_SC01_077 169s, ov_SC06_018 173s, SLUS_007.26 210s, sep8 202s, aug31 206s
- tools/ghidra_roster.py -> config/ghidra/ROSTER.md (--check in tools-health, ignores the per-machine proof column)
- .claude/settings.json hooks $CLAUDE_PROJECT_DIR-relative; ghidra_mcp_start.sh is a silent exit 0 without Ghidra or
the project (both controlled); SETUP P33 B5 section + 5 inventory rows + §2.8 (R21); CURRENT_PHASE log + checkpoint