One clean whole-EXE rebuild verified the batch (gate_main), and main re-checked
BYTE-IDENTICAL against config/check.us.sha before anything was credited.
func_80027058
A marker is a CLAIM on work, not a record of it. axbm.json sat in .run/distill_ready
for 10.5 hours AFTER its waves were distilled into cookbook §269 — the reviewer landed
the sections, updated the mined state, and never removed the marker — and distill_scan's
one-pending-marker-at-a-time rule (correct, it stopped eight overlapping batches) then
refused to raise anything while 18 waves / 315 novel candidates accumulated behind it.
The marker's own waves are checkable against the mined state, so check them: a marker
whose every wave is already mined clears itself and says so. Negative control (R39): a
marker naming any still-unmined wave survives untouched.
Same family as R47 — a stage that consumes work must also consume the token that
represents it.
.run/maintenance.sh (what runs) and tools/lanes/maintenance.sh (a pre-S59 copy) had
diverged. The 150->50 threshold tune landed on the stale copy and was then copied over
the live one, silently reverting five S59 fixes:
* the R47 shape filter (staging fell back to status=='AGREE' alone — the exact defect
that staged 82 hopeless drafts every 45 minutes)
* the R48 (binary, fn) keying (bare-fn keys collide across overlays)
* reloc --fix MISMATCH auto-repair (measured 4/4 repaired to AGREE)
* rtu_second_chance (re-judges standalone COMPILE-FAILs against the real TU)
* fix_tu_ret_decls (the return-type half of the stale-decl wall)
Rebuilt from the S59 lineage with the 150->50 threshold and the periodic fleet R22
re-applied, both paths now byte-identical, `bash -n` clean, and the two-path hazard
documented in the header so the next edit cannot repeat it.
Also: relaunch_drafter_shell.sh 30s -> 5s ready-marker poll; regenerated backlog and
fleet progress artifacts.
1,342 banked, 140 commits, open stubs 6,575 (main 1,493 / overlay-md 5,082).
The session's one lesson, measured six times: every lane that looked like the models
underperforming was a harness defect — an -O0 oracle nothing ever passed, a lane
retired on a card-size verdict, carve machinery nothing fed, a poisoned main baseline
that made 737 drafts read as bad, a soft 429 killing 44-72% of shards at turn 1, and a
stager consuming one bit of one verdict.
Records what landed (jtbl island split + gate automation, the -O0 census and unlock,
the new main and distill lanes, two RED binaries fixed, the throughput settings with
their probe evidence, the portable-workflow doc), seven rule candidates for PhaseEnd
approval, the ranked open threads with the A-prop residual named and sized, and a
resume procedure that starts from campaign_status.py and verifies from the process
rather than the file.
150 was tuned for a lane that only re-swept an unchanged sibling pool and banked
nothing. The lane now consumes every verdict layer in the A-prop pipeline, carries the
free pre-gate reject recovery, and runs the periodic fleet R22 — a pass is worth
running on a much smaller refill.
One clean whole-EXE rebuild verified the batch (gate_main), and main re-checked
BYTE-IDENTICAL against config/check.us.sha before anything was credited.
SYS_OBJ_11C
SYS_OBJ_19A4
SYS_OBJ_222C
SYS_OBJ_2CC4
SYS_OBJ_640
SetDrawOffset
VM_NOWON_OBJ_230
VM_NOWON_OBJ_2C8
func_80028488
func_80041354
One clean whole-EXE rebuild verified the batch (gate_main), and main re-checked
BYTE-IDENTICAL against config/check.us.sha before anything was credited.
func_8002EB10
func_8005EA88
One clean whole-EXE rebuild verified the batch (gate_main), and main re-checked
BYTE-IDENTICAL against config/check.us.sha before anything was credited.
func_800525DC
Two binaries sat RED for hours today and nothing noticed: ov_SC07_010 from a
maintenance commit whose final tree state was provably never built, and ov_SC07_002
from a stale 2-table jtbl pad spec written at wave bp. Every lane only ever checks the
binary it is currently touching, so a byte-gate — a correctness oracle — was silent
about everything it did not build. They were found by accident, by an agent's scoped
R22 sweeping 141 binaries.
Every 4th maintenance pass (~3h), skipped while any gate is in flight (check-all
rebuilds stale objects and must not race a gate), it runs the fleet check and writes
any REDs to .run/fleet_red.txt with a loud log line. It FIXES NOTHING: a wrong repair
to a pad spec or a config is exactly how a silent byte shift gets committed, and the
two we fixed today each needed a different, evidence-led remedy.
The binary has been RED since wave bp (commit:2687), where the gate-time jtbl carve
wrote 'JTBL_PADS := 0,0 # tables=+0x0,+0x20' for ov_SC07_002_jr_8017C8D0.o. The
object emits ONE rodata .align, so jtbl_rodata_pads refused every build:
consumed 1 rodata .align(s) but 2 pad spec(s) given — table-count drift vs the carve
make: *** [build/src/ov_SC07_002/ov_SC07_002_jr_8017C8D0.o] Error 1
The carve itself is legitimate — jr_isolate_all's jr_inventory resolves every
committed .rodata carve in this binary to exactly one banked owner (R32/R33), so this
was never an orphaned carve. Only the pad SPEC was wrong, and §8e's own rule is that a
single-table span gets no line at all (its pipeline stays byte-identical to pre-§8e).
Removing the line restores it:
sha1 fad71342019704d1dd6ec25f2f3934c97e322624 == config/check.ov_SC07_002.sha
Found by the A-prop agent's scoped R22 (141 binaries affected, 96 SHA-checked), which
also fixed ov_SC07_010 — a binary whose committed tree state had provably never been
built. Two RED binaries had been sitting in the fleet while every lane gated against
them; neither was noticed because no lane checks a binary it is not currently touching.
One clean whole-EXE rebuild verified the batch (gate_main), and main re-checked
BYTE-IDENTICAL against config/check.us.sha before anything was credited.
SYS_OBJ_16C
SYS_OBJ_1A70
SYS_OBJ_FD8
SetPriority
SetRGBfifo
SetRii
SquareRoot12
func_80010BB4
func_80028304
func_8002EA10
func_80047D3C
func_8005AB00
func_8005B75C
gfx2D_BG0_OBJ_1B4
gfx2D_BG0_OBJ_4A0
gteMIMefunc
OpenRouter returns a provider throttle as HTTP 200 whose body has no 'choices' and an
error of {"message": "Provider returned error", "code": 429}. That never reached the
429 handler, which keys on HTTPError, so it fell through to the 'no choices' raise and
ended the agent at turn 1 with no draft, no submit, $0.00 spent.
Measured, and it is not marginal:
wave cb: 169 of 260 shards hit a soft 429
wave cc: 115 of 260
wave cd: 187 of 260 <- 260 shards 'finished cleanly', 72 drafts produced
wave ce: 119 of 258
That is the draft-completion collapse. I had attributed 28-60% completion (against
84-89% before) to the straggler grace and raised it to 700s; the grace was never the
cause. The shard logs said 'finished cleanly' because the agent DID exit normally —
after being killed by an unretried rate limit on its first API call.
Now treated like every other transient: back off, retry, and log it as SOFT-BODY so
the rate telemetry stops under-counting 429s. Takes effect on the next wave's shards —
api_agent is spawned fresh per shard, so no lane restart is needed.
R40 again: the fleet looked like it was giving up, and the harness was hanging up on it.
One clean whole-EXE rebuild verified the batch (gate_main), and main re-checked
BYTE-IDENTICAL against config/check.us.sha before anything was credited.
DrawSyncCallback
SetSZfifo3
_drs
func_80059888
func_80059D68
One clean whole-EXE rebuild verified the batch (gate_main), and main re-checked
BYTE-IDENTICAL against config/check.us.sha before anything was credited.
func_8002E818
func_8005EAA8
docs/tool-designs/aprop-lane-s59.md: baseline (117 staged / 0 banked = 82
shape-DIFF + 19 standalone-fail + 16 near-0, none invisible), the defect
classes with byte-proofs, the fixed pipeline's end-to-end numbers (64+ banked,
zero tokens), the near-miss taxonomy (11 IMM tier-2, 8 wrong-family), the
ceiling with every refusal named and sized, and the two pre-existing RED
binaries the scoped R22 surfaced (SC07_010 fixed green; SC07_002 named for the
jtbl owner).
Cookbook: §270 the four-verdict law (instructions/symbols/TU/whole-binary —
stage on fewer and burn a build per missing layer forever), §271 ordinal
candidate pairing, §272 K&R the definition, §273 the wrong-oracle law.
maintenance.sh now runs the full recovered pipeline unattended: shape-gated
(binary,fn)-keyed staging, reloc --fix repair+recheck, rtu second chance,
fix_tu_ret_decls on fresh near-0 rejects.
One clean whole-EXE rebuild verified the batch (gate_main), and main re-checked
BYTE-IDENTICAL against config/check.us.sha before anything was credited.
func_80011DA0
func_80011E84
func_800273F4
func_8002D4C8
Measured 23:20: the maintenance lane held .run/auto/draw.lock for a multi-minute
sweep, the pre-draw buffer happened to be empty, and the drafting fleet — the one
clock-limited resource — sat at 13 agents and 3 req/min printing 'gate holds the draw
lock and nothing is pre-drawn — waiting 30s' every thirty seconds.
That wait dates from when drawing during a gate was genuinely unsafe: corpus.stubs()
misreports for a binary whose sources carry a substituted draft (R35), so the draw
refused outright. Since 15:23 build_wave_atlas excludes exactly the binaries whose
per-binary gate lock is held and draws from the rest, so the hazard is handled at the
right granularity and the blanket wait now protects nothing.
Same lesson as the draw's own refusal earlier today: a guard scoped more broadly than
the hazard gets routed around or, worse, quietly starves the thing it sits in front of.
1. decl_for searched the DESTINATION for the SEED's name: a RENAMED symbol's
destination spelling can only exist under the MEMBER's name, so the
destination preference silently never applied to renamed data symbols
(D_801B9DF8 adopted the seed's 'short' against the TU's file-scope 's32').
dest/fleet tiers now search target_sym; seed tiers keep the seed name.
2. dest_scope is FILE-SCOPE-ONLY (brace-masked): the TUs are full of
block-scope externs inside banked bodies, and a flat regex adopted one of
those as 'the destination spelling' over the DEFINE macro's true file-scope
decl.
3. A body-embedded block extern that diverges from the destination file scope
is rewritten to the destination spelling when every use is ADDRESS-ONLY
(type is codegen-irrelevant for &sym); valued uses keep the seed spelling.
+ fix_tu_ret_decls.draft_ret now parses K&R definitions (its first run SKIPped
30 of 32 because the param decls sit between ')' and '{').
tools/fix_tu_ret_decls.py: sweep-1's dominant residual (32 fresh near-0 rejects
— byte-correct bodies, TU-refused) is the RETURN-TYPE half of the stale-decl
wall: the TU forward-declares 'extern void f(void);' while the byte-true
definition returns s32; the gate's arity pre-pass relaxes the PARENS but not
the return. Retyping the TU's own decls to 'extern s32 f();' (byte-neutral:
every declared-void caller ignores $v0 — fix_header_decl's proven argument,
TU-scoped) banked 14 byte-identical, journaled edits kept only where the gate
paid. 12 SKIPs are void-returning defs (a different conflict, suspected
freshly-spliced (void) preambles), 4 retyped-but-refused.
The S59 scoped R22 sweep (96 binaries whose TUs instantiate the DEFINE macros
my engine_core edit touched) found ov_SC07_010 RED at HEAD: the 14:57
maintenance commit (commit:2694) banked func_8017F2BC's (s16*) definition into a
TU that still carries an earlier draft-preamble decl 'extern void
func_8017F2BC(void);' at line 4932 — conflicting types, TU uncompilable, though
the TU is byte-identical to its committed state (how that pass reported green
is an open question for the lane's arity/splice ordering). Provenance checked:
my commits touch only func_80162CCC decls; the pinned cc1 accepts the
no-proto+definition pair in isolation. Fix: the arity pass's own byte-neutral
no-proto form; whole-binary SHA re-checked green. ov_SC07_002 remains RED on a
jtbl_rodata_pads carve drift (also pre-existing, also from earlier passes) —
named in docs/tool-designs/aprop-lane-s59.md, not papered over.
Two new recovery mechanisms, both byte-proven this sweep:
6/7 rtu-second-chance: standalone COMPILE-FAILs re-judged in their REAL TU
(rtu_match) — 6 banked whole-binary; the standalone verdict was the
wrong oracle for a TU-destined draft
6/15 reloc UNRESOLVED/shape-MATCH: identity unverifiable locally, but the
whole-binary gate is the arbiter — staging them is free banks
Not banked: 5 MISMATCH?-advisory, 4 reloc-repaired (symbols now right, bytes
still differ), 2 old K&R conversions, 9 UNRESOLVED, 1 rtu (all reverted by the
gate; drafts retained in backlog).
Uncommitted src/ changes found at gate entry. These are banked functions from a lane that gates with commit=False, not residue — preserved, not reverted. Top-level src/*.c (main TUs) are excluded by construction (S59).
The population that banked 0/117 on three consecutive passes banks 38/80 with
the S59 fixes, attributed against the 21:04 baseline classes:
29 the closeness-2 ordinal cluster (value/offset swap -> candidate pairing
adjudicated by match_one at draft time)
4 the near-0 TU-integration class (K&R definitions + the arity pre-pass;
func_80162CCC x3 overlays among them — 42 engine_core.h caller decls
kept no-proto for the banked set, byte-neutral for empty calls)
5 drafts the old pipeline refused or mis-staged
Every bank is whole-binary SHA-verified by gate_stage/harvest_verify (G3/P9).
reloc_identity --fix's rowmap keyed rows by fn alone, so three same-named
func_8013BCDC rows across binaries all received ONE binary's draft — 2 of 4
'no textual occurrence' refusals were the tool editing the wrong file. Keyed
by (binary, fn): 4/4 repaired to AGREE/MATCH (byte-checked by re-run).
maintenance.sh: stage on status in {AGREE,UNRESOLVED} AND shape==MATCH keyed
(binary,fn); run reloc --fix on MISMATCH rows and re-check so repairs stage the
same pass; add rtu_second_chance for standalone COMPILE-FAILs (7/27 measured
TU-byte-MATCH, previously dropped unjudged).
aprop_autodraft decl_for gains the BORROW tier: when both home TU and seed are
silent, adopt a sibling TU's extern spelling under the same body-compatibility
guards — 'which TU may conflict' (home only) and 'where a guess may come from'
(anywhere) are different questions; refusing outright left 125 members undrafted.
Baseline measured on the 21:04 pass (117 staged, 0 banked): 82 near real-diff /
19 standalone compile-fail / 16 near-0 TU-integration; zero drafts invisible to
the gate (the 'drafts: 0' probe was the triage harness racing itself — a shared
per-fn probe dir rm -rf'd by a concurrent triage run, not lane plumbing).
1. K&R definitions (aprop_autodraft.kr_definition): the near-0 class is the TU's
own '(void)' decls + empty K&R call sites rejecting the draft's ANSI def
('too few arguments' after the arity pre-pass relaxes the decls). K&R the def
when every param is promotion-safe; byte-proven MATCH on func_80162CCC's real
TU (rtu_match) where the ANSI form CC1-failed.
2. decl_for scope: the destination is the HOME TU ONLY, macro-expanded
(dest_scope) — the whole-binary concat adopted spellings the home TU never
declares; and a dest spelling is adopted only when the seed body can compile
against it (void-return-value guard + call-arity guard; measured 42 and 15
fresh drafts died on each before the guards).
3. Ordinal IMM pairing is now a CANDIDATE SET (family_remap._ordinal_candidates):
the single-guess form paired the first spelling's occurrences only and shipped
35 of 117 drafts with value/offset swapped ('*(p+3)=2' for '*(p+2)=3',
closeness-2 forever); candidates are adjudicated with match_one at draft time.
4. Staging filter (maintenance.sh): stage only AGREE + shape==MATCH, keyed by
(binary, fn) — status-only staging burned 82 whole-binary builds per pass on
drafts match_one had already refuted, every 45 minutes.
+ tools/rtu_second_chance.py: standalone COMPILE-FAIL is the wrong oracle for a
TU-destined draft; re-judge those against the real TU (rtu_match) and stage
the MATCHes.
One clean whole-EXE rebuild verified the batch (gate_main), and main re-checked
BYTE-IDENTICAL against config/check.us.sha before anything was credited.
ClearImage2
GsSortBg
SYS_OBJ_1578
SYS_OBJ_1790
SetGraphReverse
func_800167F0
func_8005C1C0
func_8005D8A0
func_8005E804
func_8005EA54
One clean whole-EXE rebuild verified the batch (gate_main), and main re-checked
BYTE-IDENTICAL against config/check.us.sha before anything was credited.
StartRCnt
func_800145EC
func_8005E79C
func_8005EAC8
One clean whole-EXE rebuild verified the batch (gate_main), and main re-checked
BYTE-IDENTICAL against config/check.us.sha before anything was credited.
VectorNormal
func_80018714
func_8001A0FC
func_80029240
One clean whole-EXE rebuild verified the batch (gate_main), and main re-checked
BYTE-IDENTICAL against config/check.us.sha before anything was credited.
SYS_OBJ_19D8
func_8001751C
func_8005B684
MY BUG, SAME DAY, SAME CLASS. recover_rejects staged by the binary field of
aprop_symfix's output slate — and aprop_symfix tags its REBASE VARIANTS into that
field (ov_MAIN_012-cn, -cn-cast, -cn-cast-rc, -s2in, -s2in-uni). Staged verbatim,
each variant became its own directory and sweep_parallel was handed 273 directories
naming binaries THAT DO NOT EXIST: 553 drafts that could never be gated against
anything, while the sweep reported 'over 331 binaries'. It now resolves the variant
tag back to a real binary, keeps ONE variant per target, and COUNTS what it cannot
resolve (R43). The 290 bogus staging dirs are cleaned; 118 real drafts remain.
aprop_autodraft, per Drew:
* decl_for prefers the DESTINATION TU's own spelling and falls back to the seed's
only when the destination is silent (wave law 2 — the destination is
authoritative; 45 of 188 staged drafts declared a conflicting type).
* it REFUSES a seed whose body is a verbatim __asm__ block. Those transcribe
instructions rather than decompiling them, trivially 'MATCH' the local oracle
because they ARE the target's bytes, and would count as matched functions in every
progress number while nothing was decompiled. 26 of 188 were this shape. §265 is a
deliberate human escape hatch for hand-written asm, not something an unattended
lane propagates across a family.
Measured before changing the drafting prompt instead: model waves bw/bx/by/bz produced
ZERO whole-body asm across 530 drafts, so this is a tool behaviour, not a model one. A
blanket 'no asm' rule on every card would have cost us the sanctioned one-line levers
(§5a fences, §17 register pins) that appear in 32-47 drafts per wave.
One clean whole-EXE rebuild verified the batch (gate_main), and main re-checked
BYTE-IDENTICAL against config/check.us.sha before anything was credited.
GetRCnt
StopRCnt
func_8005BED8
func_8005D6A0
func_8005D980
func_8005E9D4
func_8005F228
func_8005F728
One clean whole-EXE rebuild verified the batch (gate_main), and main re-checked
BYTE-IDENTICAL against config/check.us.sha before anything was credited.
func_80014094
func_8001599C
func_80015A2C
func_80016A7C
func_80017758
func_8001BFD0
func_8002AED0
One clean whole-EXE rebuild verified the batch (gate_main), and main re-checked
BYTE-IDENTICAL against config/check.us.sha before anything was credited.
func_80015978
func_800290E0
One clean whole-EXE rebuild verified the batch (gate_main), and main re-checked
BYTE-IDENTICAL against config/check.us.sha before anything was credited.
SYS_OBJ_11C0
SYS_OBJ_210
func_80016224
func_8005C29C
Uncommitted src/ changes found at gate entry. These are banked functions from a lane that gates with commit=False, not residue — preserved, not reverted. Top-level src/*.c (main TUs) are excluded by construction (S59).
One clean whole-EXE rebuild verified the batch (gate_main), and main re-checked
BYTE-IDENTICAL against config/check.us.sha before anything was credited.
GetODE
SYS_OBJ_1AA4
SYS_OBJ_604
SYS_OBJ_F00
SYS_OBJ_F24
_getctl
_status
func_80018C64
func_8001C0C8
func_80037FC4
func_8005ADB8
func_8005B710
func_8005D4B8
func_8005E1A4
func_8005EAE8
func_8005F6CC