- A: frontier regen at HEAD (sigs + family_hseq) before pricing anything (R35). Also the reason
it was needed: .run/hseq_verified.*.txt has accumulated 22,841 files across every sweep ever
run, so any per-family analysis globbing them over-counts; the regenerated map derives state
from sigs + corpus.stubs (R33), which is the authority.
- B / THE FINDING (third §133-class miss in a row): the S29 checkpoint's structural signal
"after S2 the x138 era ENDS — those are the last two crackable fleet-wide families" — the stated
TRIGGER for the phase close — is wrong. Two fresh-crack families with >=126 members were open:
0x8017cdd8 ov_SC02_039 17 ins x 142 members PURE
0x8017ce7c ov_SC03_114 16 ins x 126 members IMM
Both kind=modal (NO member matched anywhere, so no sweep could reach them) and neither exemplar
in ov_SC01_077 — invisible to exactly the two habits this phase already corrected.
- Both hand-drafted off the .s, match_one MATCH on the FIRST try, ~0 agent tokens. First gate
attempt failed PLUMBING (not DIFF): the draft declared `extern void func_8017CFCC(s32 a0)` while
the TU DEFINES `void func_8017CFCC(void)` — the target passes $a0 only because the caller's
incoming argument still sits in the register (loose typing). Byte-true C calls it with no
argument; re-verified MATCH, gated byte-identical, propagated 266 members / 0 failed / 118 overlays.
- R14 on the seed: the cached Ghidra-C for func_8017CE7C decompiled an entirely DIFFERENT body
(three calls absent from the asm). Reading the .s is what made it one-shot.
- R22 clean-fleet 140/140. Fleet 94.88->94.96% fn-count, 91.9% instr, 84.6->84.7% distinct.
- D6: hseq_sweep took the tu_snapshots snapshot UNCONDITIONALLY, one line before the `if nfix:`
that decides whether to edit. A TU that normalize_self_decls merely INSPECTED was therefore
registered, and the phase-2 MISMATCH backstop attributed ANY group failure to a "self-decl edit"
that was never made -> revert + `0/N banked`. Measured: 909 of 909 groups took that branch while
NSD actually fires on ~25% of members (3 of 12 probed). The §103 tu-scope path below has always
snapshotted inside `if _rep["moved"]:`; NSD now matches it.
- After the fix: NON-NEUTRAL 909 -> 303 (consistent with the fire rate) and STILL 0 banked — the 606
groups that now take the normal path bank nothing, so the lever's verdict is REAL, not an artifact:
this residue is not self-decl-conflict-bound. Lever measured, closed, zero.
- R14 on my own conclusion: I byte-measured a firing case instead of trusting the backstop —
func_80162CCC/ov_SC01_000 builds to 9052dc0e... WITH and WITHOUT the NSD edit (byte-NEUTRAL), so
the surviving 303 verdicts are wrong too (likely accumulated multi-member edits in one TU).
Logged as a named open item, not chased: the lever yields 0 either way.
- The tell, twice in one session (§134): a 100% rate is a property of the mechanism, not of 1,622
different functions. Three earlier sweeps over the same population reported 0 NON-NEUTRAL.
- ONE root cause, four faces (cookbook §134): extract_unit's preamble scanner reads C
one line at a time, so every construct that WRAPS was misread.
D1 the {-guard fired on a documentation comment mentioning a brace -> carry truncated
mid-comment -> `parse error before 'the'`.
D2 _def_head_at's "param list continues -> ANSI definition" fallback accepted a WRAPPED
DECLARATION as a definition head -> a 16-line fragment with no body, closed by a brace
pair inside a comment -> a silent 0/137 that reads exactly like a compiler wall.
D5 the backscan met a multi-line typedef's CLOSING line `} T;` first and stopped -> the
type never travelled -> `T undeclared` across 17 families / 24,332 templatable ins.
(The code comment claimed they "route through the engine_types.h lift"; measured, they
routed nowhere.)
D4 wrapped __asm__("func_...") alias invisible to a single-line regex — MEASURED (1 exemplar,
3,288 ins, second blocker behind it) and deliberately NOT fixed; it now returns None so the
sweep reports a VISIBLE skip instead of 137 silent failures (R32).
- Fixes: _def_head_at(ln, idx, more=()) lookahead (no-lookahead keeps the historical answer);
{-guard exempts comment-only lines + an R32 dangling-comment backstop; forward brace scan
counts over cdecl._mask (R33, one masking oracle); _typedef_block_start carries whole blocks.
- BLAST RADIUS (R14): extract_unit diffed vs the pre-fix tool over all 181 zero-crack exemplars
-> 157 byte-IDENTICAL, 24 changed, all in the intended direction.
- PAYOFF: D1+D2 +323 members from families that banked ZERO; D5 +417 incl. func_8012B77C 139/139
(8,062 ins) and func_80128C98 137/275. S6 total 1,582 members (pre-fix tool scored 842).
- R22 clean-fleet 140/140. Fleet 94.43->94.88% fn-count, 91.4->91.9% instr, 84.0->84.6% distinct.
- TELL worth keeping (§134): bimodal bank rates (57 all / 52 zero / 8 partial) are a TOOLING
signature, not codegen. Probe one member and read one compiler error before writing a family off.
- family_sweep --hseq --band all (no --source override), 117 pre-classified families:
staged 2735 drafts / 1239 groups / 0 skips -> BANKED 842, R22 clean-fleet 140/140.
Fleet 94.43->94.67% fn-count, 91.4->91.6% instr, 84.0->84.5% distinct.
- R37 setup: the 190 zero-crack families decomposed with ZERO builds — 117 sweepable /
17 §94-§100 multi-line-typedef-blocked (24,332 ins incl. the 275-member 0x80128c98) /
9 jr (§53 carve path) / 47 remap-REFUSED.
- R14 PREMISE CORRECTION: the "every sweep passed --source ov_SC01_077" mechanism in the
post-wave checkpoint is wrong (that IS the default and overrides nothing). The real gate
was --band substantial: only 13 of 181 non-jr families are substantial. --band all is it.
- FINDING: the residue is bimodal — 57 families ALL-banked, 52 ZERO, 8 partial — the shape
of a per-family blocker, not per-member codegen. 8 probed via the new generic
.run/s6_diag.py (one build per family, not 137): 7 of 8 are declaration/carry plumbing.
Two proven family_remap defects located at source (D1 comment-line {-guard truncating the
preamble carry; D2 _def_head_at accepting a wrapped multi-line DECLARATION as a def head).
Frontier at HEAD after the 2,192-member propagation: overlays 94.7% fn / 91.8% instr / 85.0%
distinct; 13,658 distinct classes remain.
- S4 PINS RETIRED WITHOUT EXECUTION: planned at 44,279 ins from worklist.md (h_exact-priced,
x138/fn); family-map priced after the waves it is 24 fns / 101 ins. The same mis-pricing that
under-valued the frontier head by 138x over-valued this by ~440x.
- S6 ADDED, highest ROI: 190 zero-crack families / 129,997 ins, ~0 agent tokens. 106 of them have
exemplars OUTSIDE ov_SC01_077, and every sweep this project has run passed --source ov_SC01_077 —
structurally unreachable, not walled. Probe-confirmed on func_8012B77C (defined in ov_SC07_006,
still a stub in ov_SC01_000).
- S5 re-derived as the x10-99 band: 243 families / 239,058 ins.
The reconcile lane's second pass. Every one match_one-verified by me before gating, then
whole-binary byte-gated: 11 verified / 0 failed.
Escapes used (no header edit anywhere): the §37/§124 ASM-LABEL ALIAS for return/arity conflicts on
the function itself (7 of 11), and conform-the-decl + cast-at-use for conflicts on OTHER symbols —
func_80142A80, RotTransSV, func_80146C3C (4 of 11). Agents also proved each fix WITHOUT the gate by
compiling the real TU with the body spliced on a .run/ copy.
R14 on my own capture: the ':5201/:5219/:5223/:5228 note:' lines I fed the agents were pre-existing
SHB macro-redefinition NOISE, not the conflict — my blocker filter let 'note:' lines through and I
mislabelled one target as a redefinition on that basis. The agents caught it and said so.
Banked: func_80170CF0 func_801708B0 + the six gate-blocked wave-1 survivors (func_80151664
func_801376E8 func_80176144 func_8012EFB8 func_80146AFC func_8014E5B4). Every one match_one-verified
by me before gating (19/19), then whole-binary byte-gated.
The reconcile lane's whole premise held: agents cannot run the gate, so I captured each blocker with
a splice-build-revert first and embedded the exact compiler error in the brief. Three of the six
conflicts were on a DIFFERENT symbol than the function (D_800AF634, D_8011D030, func_80153C18) —
invisible in the summary, decisive in the brief. All six cleared WITHOUT a header edit, via the
§37/§124 asm-label alias (aF<ADDR> __asm__("func_<ADDR>")) or conform-the-decl + cast-at-use.
- 9 banked heads propagated: 1,096 non-jr member-matches (family_sweep --hseq --band all, 0 failed)
+ 137 (func_80159A20, jr) + 137 (func_801549F8, jr)
- func_80176734 (371 ins, the largest single item in the frontier) banked + propagated
- FLEET 93.81% fn / 90.9% instr / 83.9% distinct; dedup 1905/0; 0 NON_MATCHING (G4)
- cookbook §132b (--span-rel: the already-matched owner that is ITSELF multi-switch) and §133
(the DEFAULT-FILTER class — three times in one session a tool silently answered a narrower
question than the one asked: my own >=80-ins cut, worklist's h_exact pricing, --band substantial)
Structure-first crack (agent, 371/371 byte-exact, independently re-verified by match_one before
gating). Levers were type- and placement-driven rather than pins: u8 locals produce the andi masks
(a QImode result sends the arithmetic arms through force_to_mode while the comparison keeps its
zero_extend); cross-BB placement defeats combine (LOG_LINKS are per-BB); a DUPLICATED store keeps
the following re-read in a fresh EBB so it stays a real lbu; and a deliberately-unused u8 dum[8]
because the target's .frame says vars=8 with no spill in the body — the original had a dead local.
Only non-call-spanning pins used, so the body is x137-safe (§44).
Family: 371 ins x 138 = 51,198 templatable ins — the single largest item on the board.
func_8016706C func_80131A34 func_80161A90 func_801549F8 func_8014C4AC — each match_one-verified
by me before gating (R14), then whole-binary byte-gated. func_8014C4AC is the standout: the agent
resolved its 'conflicting types' with the §37/§124 ASM-LABEL ALIAS (s32 aF8014C4AC(...) __asm__
("func_8014C4AC")) instead of a header edit — exactly the alternative to the fleet-sed that failed
earlier today. 9 remain blocked on declaration conflicts.
Chartered as a diagnostic ('classify; build a fix only if >=3 share a class'). Result: no cheap
shared class, so nothing was scaled — the correct outcome for the charter.
- 30 x138 family heads carry a stored draft = 182,850 templatable ins (plan estimated ~12 drafts)
- only 7 of 30 still verify; 23 have DECAYED (LENGTH-DRIFT/SIZE-MISMATCH/WIDTH/ADDRESSING)
=> a stored draft's recorded closeness is NOT a current fact (extends A10/T1a)
- of the 7: 1 banked clean (func_801754A8, 37 ins x138); 6 hit "conflicting types", and
gate_stage's ladder recovered 0/6 -> 1 is the §30#2 return-widen class, 5 are PARAMETER
conflicts (the Phase-16 def-side loose-typing wall)
- the §30#2 attempt REVERTED (R14): the draft's note claimed no split .c carries its own decl —
the gate named two that do; a sed over all of them touched 2,046 files and still was not green.
That is the 'bulk header edits BREAK builds' pattern; a fleet-wide decl reconcile needs a gated
TOOL, not a sed. Exemplar re-verified d19c9580 after revert.
The stored backlog draft was 2 mismatches from perfect (88/88, DELAY-SLOT) for one reason its own
notes had already recorded: the definition must return VOID, not the canonical s32. An s32 return
keeps $v0 live-out at the epilogue, so dbr refuses to steal the loop-top addiu $v0,$zero,0x1858
into the loop-back bne delay slot -> nop + a branch target one insn early. void -> steal -> MATCH.
This is the one place §3a-1's 'void->s32 is byte-neutral' claim is FALSE (S27 finding, now banked).
Applied with the draft's own //@EDIT directive: 5 in-TU 'extern s32 func_8016EC0C' decls flipped
to void (every call site already casts the fn pointer, so no caller changes). ov_SC01_077
d19c9580 BYTE-IDENTICAL. Family: 88 ins × 138 = 12,144 templatable ins; sweep next.
- head func_8014032C 137/137 (25,071 ins, --span-rel §132b) + jr tier 46 members incl.
func_8017BEBC 13/13 (12,376), func_8015A3C8 6/6, func_8015AE2C 4/4, func_8017A4AC 4/4,
func_8013FFD8 9/10 + non-jr pass 3.
- MY ROUTING ERROR (recorded): pass 1 ran all 28 families through jtbl_family_bank; 13 are NOT
jr functions, so they carve-failed by construction — §123's own law ('propagate a family with
the tool its TIER needs'), which I had quoted in the task description. Re-routed via
family_sweep --hseq: 3 banked / 38 failed => that residue is the genuine stage-but-DIFF class.
- MEASURED: 13 of 29 zero-crack families have remaining members ONLY in the 4 P27-onboarded SC07
overlays (18,856 ins) — not a stub-count gap; they simply missed every sweep that predates them.
- R22 clean-fleet 140/140. Fleet 93.38% fn / 90.0% instr / 82.4% distinct; dedup 1905/0.
Phase arc: +1.38pp fn / +2.5pp instr / +4.4pp distinct.
S1's head family (0x8014032C, 183 ins ×137 = 25,071 templatable ins) gate-failed on its probe
sibling. Diagnosis (the §132 ladder, one build): the object emits FOUR tables — BOTH functions in
it are multi-switch (8+5 entries each) — while the carve derived THREE starts.
The missing start belongs to the ALREADY-MATCHED owner func_8013FFD8, and neither oracle can see
it: its stub .s is pruned by extract, and its second table abuts its first with NO pad (8 entries
= 32 B = 0 mod 8, so `.align 3` emits nothing) — precisely the honest limit §132's payload
zero-word recovery documents. Note the true pads [0,0,4,0] are exactly what natural alignment
produces; the build breaks only because a SHORT spec gets written.
Fix: thread the documented `--span-tables` escape through the sweep as `--span-rel` — offsets
relative to the FIRST NEW table, which func_jtbls reads from the sibling's own .s. Byte-verified
family-invariant before use (identical relative offsets on 3 sampled siblings; same code, same
entry counts, only the base moves). Empty by default => every other family untouched.
Also clears my own §132a guard of suspicion (R14): the --like transfer was inert here regardless
(exemplar subseg `ov_SC01_077` vs sibling `_jr_8013FFD8` — roles never matched).
Drew's call (2026-08-01, P5d in-phase re-plan): gate 2 was reached and deliberately NOT taken —
closing now would strand roadmap-v2 bucket W3 (the overlay family mass) with no owner phase
(P31 = scope-complete/main/resident, P32 = walls/behemoths).
Order derived from the S29 frontier regen, ranked by TEMPLATABLE weight:
S1 zero-crack propagation (29 families / 67,470 ins, ~0 agent tokens)
S2 the LAST two reach-138 fresh cracks (func_80176734 51,198 + func_8016EC0C 12,144)
S3 close=0 stored drafts as a DIAGNOSTIC pass (not a blind re-sweep)
S4 PINS bounded wave (14 fns / 44,279 ins)
S5 the x10-133 mid-multiplicity families (142,527 ins)
Excluded: the 2 GIANT walls (P32), the x2-9 mass, the x1 singleton residue.
THE PRICING FINDING (R14/R35): worklist.md ranks by h_exact reach, so a per-location PURE family
is priced x1 — under-pricing the frontier head by up to 138x. Byte-proof: S29's pair was priced
272 and 198 ins and delivered 37,536 + 27,324. func_80176734 (the single largest item on the
board) sits at rank ~50 in worklist.md. Rank family work by .run/family_hseq.json.
THE STRUCTURAL SIGNAL: after S2 the x138 era ENDS (last two crackable fleet-wide families);
everything after is <=133 members and mostly <=9. That cost-per-point rise, not a session count,
is P30's honest ROI floor and T5's trigger.
- tools-health OK: sigs regenerated post-bank; corpus(+resident) 0 PHANTOM/0 TRUNCATED; cdecl;
audit-binaries 140/140 citizens (R36); report(lint+dedup) 1905/0; cookbook-index 357 sections.
- Fresh overlay frontier at HEAD: 93.6% fn / 90.1% instr / 82.5% distinct; unmatched 22,550
instances / 1,298,980 ins / 15,029 distinct classes -> 2,414 families + 3,767 singletons
(472 substantial / 543,901 templatable ins; 29 zero-crack).
- T1 ticked with its honest scope: delivered as T1a (+18 banked, 16% vs the S16 39% prior which did
NOT generalize); the ~90 integration-decayed drafts route to T3 redraft lanes (A10).
- T3 ticked with a PER-LANE verdict: Lane B (top-mass) pays and is not exhausted; Lane C (x2-reach
cached tail) is at the floor (1.33M tokens -> 12 banks -> +0.00pp). The ROI floor is a lane
property, not a phase property.
- 2 × 138 = 276 function-instances banked (exemplar + 137 siblings each); the -O0 cluster is now
COMPLETE fleet-wide (these were the last open stubs in every overlay's _o0* region)
- §132a: --like matches by subseg ROLE NAME; ov_SC07_010 shares the exemplar's _o0 role (the only
other overlay so named — the other 136 are _o0c, whose role never matched, which is the only
reason the sweep worked at all). Six derived starts for three emitted tables; guard shipped.
- R22 clean-fleet 140/140. Fleet 93.33% fn-count / 89.6% instr / 81.6% distinct (+260 unique fns);
dedup 1905/0; 0 NON_MATCHING (G4). Phase arc: 92.00->93.33 / 87.5->89.6 / 78.0->81.6.
The one sibling both sweeps failed on. `--like <exemplar>` transfers the exemplar span's table
STRUCTURE, and jtbl_carve matches donor to recipient by the subseg's ROLE NAME. ov_SC07_010's
-O0 region is named `_o0` — the same role as ov_SC01_077's, and the ONLY other overlay so named
(the other 136 are `_o0c`, whose role never matched, which is the only reason the sweep worked).
The exemplar had just banked 2 more owners than the sibling has, so the transfer unioned its
rebased 4 offsets with the sibling's real 2 + the new table: SIX starts for THREE emitted tables
-> jtbl_rodata_pads refused ("consumed 3 rodata .align(s) but 6 pad spec(s)").
Guard (tools/jtbl_family_bank.py like_arg): suppress --like when the sibling already carries a
committed `tables=` for the target subseg — its own record is authoritative, and jtbl_carve's new
payload zero-word recovery covers the incomplete-record case that --like used to paper over.
Derived via jtbl_carve.func_subseg, the same derivation the carve itself uses (R33); never blocks
a bank (any failure falls back to the old behaviour). Inert for all 136 siblings already banked;
fixes exactly the broken one. Both fns now bank on ov_SC07_010 => 137/137 siblings each.