Commit Graph

171 Commits

Author SHA1 Message Date
Drew T a8457663fc src(phase-35): T4 finalize — engine_core.h, ov_setters.h and clearTbl40.h deleted; the legacy sites converted (clearTbl40 as the SHARED_FN parameterized control in src/800_c.c; the three SC01_005 accessors as headers), the whale header moved under ov/ with every -O0 includer rewritten, 7 alias-form bodies given their own __asm__ binding, the registry's source/func lines text-edited by id, three non-shared headers rewritten; --verify OK (0 macro sites, no macro header); R22 clean fleet check-all: 218 passed, 0 failed of 218 in 145 s; dedup-check 2220/0; audit-binaries OK; the census 362,389/362,389 with 0 macro sites; SETUP + dictionary rows; kit corpus 2026-09-08 18:06:04 -06:00
Drew T b47bc2ea0b feat(phase-32): T4b (5) — main: func_80020DA4 (100 ins) BANKED byte-identical 143dbb89 via gate_main — a pinned WALL falls: the $6 pin on e0 FORBADE $a2 at reload's retry_global_alloc (regs_ever_live seeds bad_spill_regs), so the product took $t0; unpinned + two zero-byte launders steer local-alloc's qty_compare to the target's allocation (Fable agent)
- pinned since S79 as "mflo destination $t0 vs $a2 (REGALLOC-PERM), pinning regresses to 79"; 5 attempts 51->20->14->8->2 +
  permuter_ils null (S80); T4 re-probed DIFF 2; the S83 hand pass measured the variable-reuse form at 80
- mechanism (dumps + source): the mult results are GLOBAL allocnos (mulsi3_internal '=l', mips.md:848; 'pref LO_REG');
  global.c parks m3/m8/m13 in LO, reload spills LO ("Spilling reg 65") and retries via retry_global_alloc (reload1.c:3497)
  with losers = forbidden_regs, seeded from bad_spill_regs = regs_explicitly_used = regs_ever_live at reload entry
  (reload1.c:486, 3651-3660, 709) — the S76 `register s32 e0 __asm__("$6")` made $a2 ever-live, so m13's retry could not
  take it and first-fit gave $t0 ("Register 102 now in 8")
- fix: unpin e0; `__asm__("" : "=r"(e1) : "0"(e1))` immediately before `dst[6] = -e1` (e1's qty 6666 -> 8750, allocated
  before e0's 7894, holds $v1, e0's first fit drops to $a2) + `__asm__("" : "=r"(p1) : "0"(p1))` between p1's andi and sll
  (undoes the global-allocno tie the first launder created; the $t6/$t7/$t8 rotation). Ladder 2 (pinned) -> 37 (unpinned)
  -> 15 -> 6 -> MATCH; a byte-identical alternate launders addr1 after its addu
- draft .run/P32/t5x/fable/func_80020DA4.c; report .run/P32/t5x/reports/func_80020DA4.md; coordinator rtu_match MATCH
  100/100 in src/800.c; gate_main slate_20DA4: BANKED, 143dbb89 BYTE-IDENTICAL
- main open 4 -> 3 (2 pinned walls + func_80039308 NEAR)
2026-09-05 18:16:01 -06:00
Drew T 836181a6c2 feat(phase-32): T3 (38) — main: func_8001BC6C (69 ins) BANKED byte-identical 143dbb89 via gate_main — permuter_ils found the two levers, the coordinator dropped its wrong-width mutation (R63) and re-spelled them well-defined
- seed: the Opus NEAR-6 draft (.run/P32/t3/opus/func_8001BC6C.c; §500-C REGALLOC-PERM $v0<->$v1 across the six OT-chain insns,
  local-alloc qty_compare one span unit). permuter_ils 8x150s -j3 --klass REGALLOC: cycles 6/7/8 = 6, 5, 1 (output-1-1)
- R63 read of the "1": three mutations — (a) `idx` computed AFTER `color`, (b) an early dead `tag = (a1 << 8) | k;` before
  k's assignment, (c) `(D_800B9A02 & 0xFFu) << 14` — and (c) turns the target's `lhu` into an `lbu` (semantically WRONG:
  the masked score rewards it; second witness after S80). (a)+(b) alone = leaf MATCH 69/69; (a) alone 8, (b) alone 21
- well-defined re-spelling: `k = 0; tag = (a1 << 8) | k;` at the top (I1) MATCHES; k-initialised-first (15), tag=a1<<8 (19),
  tag=a1 (8), tag=(a1<<8)|K (20), tag=0 (8), tag-then-k (8) all regress — the lever is the early BIRTH of the tag/k pseudos
  (§47 live-length: qty_compare = floor_log2(n_refs)·n_refs·size/(death−birth)), documented in the source comment
- rtu_match MATCH 69/69 in src/800.c; gate_main slate_main3: "slate 1 -> 1 compatible … BANKED 1 of 1 … 143dbb89 BYTE-IDENTICAL",
  EXIT 0 (.run/P32/t3s3/gate/gate_main3.log); main open 7 -> 6 (5 pinned walls + func_80039308 NEAR 17)
- func_800CD674's ILS plateaued at the SAME $a3<->$t1 pair (output-2-1 = 2 rows, no drift) — ledgered with its cost (R41)
- variants kept under .run/P32/t3s3/p1bc6c/ (the 11 spellings measured)
2026-09-05 11:35:41 -06:00
Drew T e2aee8e274 feat(phase-32): T3 (12)+(13) — main: func_80015B6C (120 ins) + func_8002FDE8 (73 ins) BANKED byte-identical 143dbb89 via gate_main
- gate_main .run/P32/t3s3/gate/slate_main2.json --apply: "slate 2 -> 2 compatible, 0 dropped"; clean EXE rebuild
  (extract + build) -> "BANKED 2 main functions -- 143dbb89f34491258bbc27810d0a12ec8b43a8dd BYTE-IDENTICAL", EXIT 0
  (.run/P32/t3s3/gate/gate_main2.log)
- func_80015B6C (src/800.c, Opus .run/P32/t3/opus/func_80015B6C.c): both journal walls fell — the "$v0/$v1 swap" was an
  artefact of the s32 wh[3] frame-slot hack; the corner-copy wall is cse.c canon_reg (make_regs_eqv keeps the FIRST
  register canonical) -> a barrier on the SOURCE variable `__asm__("" : "=r"(x) : "0"(x))`; four empty volatile fences
  partition block 2 into five phases at zero cost; the 0xE1000200 trailer lui hoist = reuse the $6-pinned tag variable
- func_8002FDE8 (src/800_b_2.c, Opus .run/P32/t3/opus/func_8002FDE8.c): the "regalloc-priority wall" at 35 was the ARRAY
  spelling of D_800A46D2 — the block-scope SCALAR `extern s16 D_800A46D2;` (as same-TU func_8002FF0C/func_800301C8) gives
  35 -> 3; third `return 1` inside the == -1 arm; the §47 live-length slider COMPUTED from -dl -dg (one fence where the
  constant is live and `data` dead); `one = 1;` and `i4 = idx * 4;` as separate statements
- both rtu_match MATCH in the real TU (S82 re-verification); cookbook §500-B carries the closers
- main: 12 -> 7 open (5 pinned walls + 2 NEAR)
2026-09-05 10:34:35 -06:00
Drew T 0276aaec68 feat(phase-32): T3 (8) — main: func_80023BF0 (281 ins) BANKED byte-identical 143dbb89 via gate_main — the OT link is libgpu's P_TAG 24-bit BITFIELD store (§364), not a hand-written mask/or
- the 11-18 plateau had two mutually-exclusive halves under (A & 0xFF000000) | (B & 0xFFFFFF): preheader hoist order
  of the two masks vs &otab[idx], and the $t3/$t4 pairing of the mask register and the slot pointer. store_field ->
  store_fixed_bit_field expands the RHS bitfield extract BEFORE the destination read, which fixes loop.c's movable
  order [&otab[idx]; 0xFFFFFF; 0xFF000000] AND the ior operand roles at once (operand swap alone = 35). Third witness
  for §364's -O2 half (func_8001D3FC/func_80021284/func_80023570 in the same TU already use the idiom).
- kept from the S79 90->18 chain (re-measured): the §194-A fence in both arms, `code` split from its base with
  compound accumulation, register u32 base __asm__("$3"), and exactly 13 zero-byte fences after pkt = D_800A5E60
  (0->15, 8->13, 10/11/12->7, 13->MATCH). Dropped as now inert: the m24 $11 and e1 $4 pins.
- the S80 permuter waypoint (closeness 11) was semantically UNSOUND (m24 sunk into one arm) and was not used (R63).
- rtu_match MATCH 281/281 (coordinator-verified); gate_main --apply 1/1, main byte-identical
2026-09-05 01:06:17 -06:00
Drew T d04fe31882 feat(phase-31): S79 #9 (9) — main: func_8001EFE0 (468 ins, the largest G-UNKNOWN main body) banked from an Opus agent's draft: recovered the prior closeness-14 body from .run/match and closed all three [permuter]-filed clusters by reading the matched same-TU siblings func_8001DA34/func_8001EA14 — the addPrim tail's ot split so the sll lands between the two pinned luis, one zero-byte fence between the tpage sh and the q[7] RMW, a §419 density asm on (vh,vv2,vw) for the two-SVECTOR fill, and the shift split from its mask; rtu_match --tu src/800.c MATCH, gate_main --apply clean rebuild BYTE-IDENTICAL 143dbb89 2026-09-04 20:47:51 -06:00
Drew T 1961a7bfb1 feat(phase-31): S79 #9 (5) — main: func_8002AC98 (114 ins) banked: the generic arm's val = r + b routed through a fresh s32 temp ({ s32 xt = r + b; val = xt; }, with b widened to s32) so expand_binop's target==op1 swap does not fire — the same lever as func_80015608; gate_main BYTE-IDENTICAL 143dbb89 2026-09-04 19:05:29 -06:00
Drew T ec786e0a46 feat(phase-31): S79 #9 (2) — main: func_80015608 (86 ins) banked: a Sonnet agent closed the permuter's last instruction by routing the accumulator add through a fresh temp ({ s32 xt = blockSize + x0; x0 = xt; } — expand_binop's target==op1 swap does not fire on a new pseudo); gate_main BYTE-IDENTICAL 143dbb89 2026-09-04 19:00:03 -06:00
Drew T 06ee3c1234 feat(phase-31): S79 #8 (1) — main: func_80015760 (106 ins) banked from a permuter ILS score-0 winner (cycle 1) + plumbing: TU data spelling (u8 *D_800A5E60), the callee's TU prototype with a (u16) call-site cast for the target's andi, the permuter's typedef preamble stripped; gate_main BYTE-IDENTICAL 143dbb89 — the S76 journal had filed it as a 'genuine sched1 artifact' 2026-09-04 18:42:41 -06:00
Drew T 7129b6cac8 chore(phase-31): S79 #8 plumbing — main src/800.c: func_80015760's forward decl no-protoed + its 2 call sites cast (cast_self_callers --sync-decls); byte-neutral (143dbb89) 2026-09-04 18:39:40 -06:00
Drew T a85733a487 feat(phase-31): S78 #3 — 13 "game code" subsegs were PsyQ objects: wired LINKED (libgte 70/30, libgs 33/7, snd 62/11); main's game-code metric corrected to 91.8%
- exact tiles, 0 tokens: libgte23-26 (MSC01/02/05/09, SMP_00, FGO_01-06, PATCHGTE), libgte9 re-derived
  as SMP_05 NormalClip (SMP_06 NormalClipS = nested sub-pattern; psyq_integrate now drops nested
  placements), libgte27-30 (the libgs-gap MTX_05/07/11, REG03+REG11), libgs7 (2D_BG0+2D_BG1), snd10
  (VM_NO1), snd11 (VM_NOWON carved off sgap_8). LINKED 959->1040, REAL 912->886 (SDK inline-asm wrappers
  re-provenanced), VERBATIM 146->85, 13 TUs deleted; splat re-emits the stub records.
- main 143dbb89 WITH and WITHOUT the SDK objects. The no-SDK fallback had been red since S7x
  (CdReadyCallback called by its SDK name while the libcd stub carried func_800435B4) — curated
  CdReadyCallback = 0x800435B4, refs unified. R22 clean fleet 213/213; tools-health OK.
- METRIC CORRECTION (R35): progress.py's "MAIN game-code weighted" sig never excluded the LINKED
  objects (its comment said it did) — ~31k linked-SDK ins sat in the denominator as unmatched game
  code. Exclusion now derived LIVE from the Makefile stub lists + yaml ranges: 91.8% (44,562/48,537),
  not 59.8%; the 3,975-ins remainder equals the open-stub sum exactly.
- VM_F.o probed SPLITTABLE at .bss 0x50c (SYS.o's class -> task #4). cookbook §488; worklist S78 #3;
  decision-log + accelerators; SETUP rows.
2026-09-04 16:26:12 -06:00
Drew T a7394f44dc feat(phase-31): S78 #12 — the 800c3 "wall" band is LIBPAD 4.2.1 + LIBAPI 4.2: 46 names applied; integrate wired by subseg range; renames via ApplySymbols
- provenance: the psx loader's per-version PsyQ signature sets place PADENTRY/PADCMD/PADPORTD/
  PADSEQD (4.2), WAITRC2 (4.3), COUNTER/C114/FIRST/PAD/PATCH/CHCLRPAD (libapi 4.2) byte-exact in
  0x8005CE48-0x8005FC68 / 800c2 -> 12 of main's 29 stubs incl. all four §332 walls are Sony's
  DualShock library in reorder mode. 46 names -> symbols.us.txt (count 1081), band TUs, verbatim
  manifest, wave_exclude; firstfile/firstfile2 (4.2 naming); CdGetToc @0x800430B8 (was the Phase-21
  xdedup mislabel DecDCToutCallback). SETUP §5.1 corrected; psyq-worklist S78; cookbook §487;
  decision-log + accelerators S78; CHECKSUMS +Psy-Q_46.zip +PSYQ_SDevTC_v4.5.zip.
- psyq_integrate: --yaml maps stub<->objects by SUBSEG RANGE with an exact-tiling check and PRINTS
  the located-but-unwired residue (libgte: 13 objs / 1,264 ins) — main's LINKED build had been RED
  at HEAD since the S77 psyq_identify fix (22 libgte blocks merged to 3; gate worktrees take the
  stub fallback so it never showed); a library object's exported symbol whose recovered address the
  curated file names differently is --redefine-sym'd (R15; A66 firstfile->firstfile2).
- Ghidra: 47 MCP renames did NOT persist through the sentinel stop (R9 caught it) -> NEW
  tools/ghidra_scripts/ApplySymbols.java + tools/ghidra_apply_symbols.sh mirror the curated file
  headless with a real save: 73 renamed, R9-verified x4. SETUP inventory rows (R21).
- lint_symbol_refs: scans verbatim __asm__ bodies (`.ent\tfunc_X` is invisible to \b and to the
  string-masked scan); negative-controlled (red on the pre-fix TUs, green on the passing tree).
- R22: clean extract-all 212/212 + check-all green on the final config; main rebuilt byte-identical
  143dbb89 after the last src-only fix -> 213/213; tools-health OK.
2026-09-04 15:57:06 -06:00
Drew T 335e1d677d feat(decomp): bank main:func_8001EA14 (371 ins) from close=89
Five new levers, all in the draft header. The headline one (L5): STATEMENT
ORDER IS THE ALIAS ORDER — a mem/s local matrix store can never be hoisted over
by a mem/s varying p-> load, because true_dependence's exemption needs one side
non-struct AND non-varying. Writing the matrix init in NATURAL OFFSET ORDER
closed the whole 45-instruction init block, and the same law one scope down
removed the +1 length drift.

Also: an inline-asm "r" operand that is a bare symbol_ref has NO pseudo and is
allocated by reload ($t0); assigning it to a local first makes it a pseudo and
local-alloc gives $v0 — worth 10 instructions.

A scripted 858-candidate sweep PROVED mode/rot/shift placement inert, which is
what redirected the hunt from LUID to DAG/allocation.

gate_main: BANKED 1, 143dbb89f34491258bbc27810d0a12ec8b43a8dd BYTE-IDENTICAL.
2026-09-03 20:43:01 -06:00
Drew T 1f2ae12b5d feat(decomp): bank main:func_8001FC08 (400 ins) and func_8002FF0C (166 ins)
Both bodies were already solved in S76 and had never banked. Neither needed a
codegen change — they needed the gate to stop applying a rule cc1 does not
(§481 / the _depth0 fix): func_8001FC08 renames its struct to MTX_8001FC08 and
declares D_80074818/D_80075018 at block scope, and func_8002FF0C shadows
D_800A46D2 with a block-scope scalar because the array spelling forces la and
costs 12 mismatches.

gate_main: BANKED, 143dbb89f34491258bbc27810d0a12ec8b43a8dd BYTE-IDENTICAL.
2026-09-03 20:21:22 -06:00
Drew T 337a040047 feat(decomp): bank main:func_80024054 via permuter ILS (DELAY-SLOT/2, 4 of 91)
Score 0 on cycle 1. gate_main: BANKED 1, 143dbb89f34491258bbc27810d0a12ec8b43a8dd BYTE-IDENTICAL.
2026-09-03 19:39:54 -06:00
Drew T 94b528b54e feat(decomp): bank main:func_80021174 via permuter ILS (SCHEDULE-REORDER/2)
The residual was a two-instruction adjacent swap in the target's favour:

    idx 49  MINE lh   $a1, 0($sp)      TARGET sra $a2, $v1, 16
    idx 50  MINE sra  $a2, $v1, 16     TARGET lh  $a1, 0($sp)

Hand lever tried first and REFUTED by bytes: hoisting `a0 = a0 >> 16` above
the load is semantics-preserving (a0 is untouched in between) but scores
23 mismatched at 67/68 ins — it lets gcc fold an instruction away entirely.

permuter_ils --klass SCHEDULE reached score 0 on cycle 1. Its winning edit is
a clean C-level one: drop the `a1 = *(s16 *)sp;` temporary and inline the load
into both comparisons, which is what moves the sign-extend ahead of it.

gate_main: BANKED 1, 143dbb89f34491258bbc27810d0a12ec8b43a8dd BYTE-IDENTICAL.
2026-09-03 19:28:06 -06:00
Drew T ef0cb64c14 plumb(main): undo-journal the plumbing for the 3 drafts that did not bank
`cast_self_callers --undo-journal .run/S77_selfcast.json --keep
func_80013154,func_8005EAC8,func_8005E3AC,func_8005E79C` — reverted 6 edits
across 2 files, kept the 4 that banked.

The three reverted are func_80015608, func_80015760 and func_80039DEC, all
proven NEARs (closeness 3, closeness 9, and 8 differing bytes at 0x80039ded
respectively) — body residuals for the DIFF lane, not plumbing. Their §378
chain is one command to regenerate when a corrected body arrives.

main rebuilds 143dbb89f34491258bbc27810d0a12ec8b43a8dd after the revert.
2026-09-03 18:58:06 -06:00
Drew T a9980bdd8c feat(decomp): bank func_80013154 and func_8005EAC8 in main (§378 self-decl chain)
The first two banks off the `self_decl_tu` class: the TU declared the very
function the draft defines, with a different signature, so the draft could not
compile no matter how correct its body was.

  func_80013154  src/800.c    tu s32 (s32,s32,s32)  | def s32 (s16,s16,s16)
  func_8005EAC8  src/800c3.c  tu void (void)        | def void (void*)

func_80013154 was a §265 VERBATIM-ASM bank — it is now real decompiled C.

gate_main: 3-draft slate, bisected in 5 rebuilds, 2 banked,
143dbb89f34491258bbc27810d0a12ec8b43a8dd BYTE-IDENTICAL.

progress.py main: REAL 895 -> 897, INCLUDE_ASM stubs 46 -> 44.

Rejected by the byte gate, correctly, and handed to the DIFF lane:
  func_80039DEC  8 differing bytes at 0x80039ded  (a NEAR, not a plumbing miss)
  func_80015608  sync_tu_decls refused up front: NEAR at closeness 3
2026-09-03 18:53:15 -06:00
Drew T cb1b6fc9fb plumb(main): §378 self-caller casts + decl sync for 7 self_decl_tu drafts
`blocker_probe --binary main` over the 36 stranded S76 drafts classifies 7
whose blocker is `self_decl_tu` — the TU declares the very function the draft
defines, with a different signature:

    func_80013154 src/800.c    tu s32 (s32,s32,s32)   | def s32 (s16,s16,s16)
    func_80015608 src/800.c    tu void (s32,s32)      | def void (void*,u32*)
    func_80015760 src/800.c    tu void (s32,s32)      | def void (Obj*,s32*)
    func_80039DEC src/800_c.c  tu void (void*,s16,u8) | def void (void*,s16,s16)
    func_8005E3AC src/800c3.c  tu void ()             | def s32 (Ctx*,s32)
    func_8005E79C src/800c3.c  tu void ()             | def s32 (void*,void*)
    func_8005EAC8 src/800c3.c  tu void (void)         | def void (void*)

14 edits: each call site cast to a no-proto function pointer (§20 — gcc-2.7.2
folds the cast of a known function symbol back to a direct `jal`, so the
caller's bytes do not move), then the forward declaration synced.

Verified byte-neutral BEFORE any draft is substituted: main builds
143dbb89f34491258bbc27810d0a12ec8b43a8dd with these edits alone.

Committed ahead of the gate because gate_main `git checkout`s main's TUs
before substituting and would otherwise destroy these edits. Journal at
.run/S77_selfcast.json — `--undo-journal --keep <banked>` follows the gate.
2026-09-03 18:49:56 -06:00
Drew T 1b648fcc5b Revert "plumb(main): §378 self-caller casts + decl sync for 7 self_decl_tu drafts"
This reverts commit commit:3801.
2026-09-03 18:48:28 -06:00
Drew T 54717c4b62 plumb(main): §378 self-caller casts + decl sync for 7 self_decl_tu drafts
`blocker_probe --binary main` over the 36 stranded S76 drafts classifies 7
whose blocker is `self_decl_tu` — the TU declares the very function the draft
defines, with a different signature:

    func_80013154 src/800.c    tu s32 (s32,s32,s32)  | def s32 (s16,s16,s16)
    func_80015608 src/800.c    tu void (s32,s32)     | def void (void*,u32*)
    func_80015760 src/800.c    tu void (s32,s32)     | def void (Obj*,s32*)
    func_80039DEC src/800_c.c  tu void (void*,s16,u8)| def void (void*,s16,s16)
    func_8005E3AC src/800c3.c  tu void ()            | def s32 (Ctx*,s32)
    func_8005E79C src/800c3.c  tu void ()            | def s32 (void*,void*)
    func_8005EAC8 src/800c3.c  tu void (void)        | def void (void*)

14 edits: each call site cast to a no-proto function pointer (§20 — gcc-2.7.2
folds the cast of a known function symbol back to a direct `jal`, so the
caller's bytes do not move), then the forward declaration synced to the
draft's own spelling, which emits no code once the sites are cast.

Committed ahead of the gate because gate_main `git checkout`s main's TUs
before substituting and would otherwise destroy these edits. Journal at
.run/S77_selfcast.json — `--undo-journal --keep <banked>` follows the gate.
2026-09-03 18:45:52 -06:00
Drew T fc644dddb4 feat(decomp): bank 9 main functions, including main itself and the 670-ins giant
BANKED 9 of 28 after bisection, 143dbb89 BYTE-IDENTICAL. Verified from the
SOURCE (every stub gone), not from the gate's own count.

  main            509 ins  the game's entry point
  func_800226C0   670 ins  the largest function in the project
  func_800215F4   465
  func_800623A4    36 · func_80062434 36 · func_8005D410 42
  func_8005D4B8    14 · func_8005D4F0 18 · StopRCnt 13

Reached by iterating the gate and dropping the compile-conflict culprit it
named each round: func_8005E79C, func_8005E3AC, func_8005EAE8, func_8001FC08.
Each of those is a §376/§378 declaration conflict, not a bad body — they go to
the recovery chain, not the bin.

Several were only reachable because of this session's oracle fixes: the 800c3
functions had been recorded as §182/§188 epilogue walls by an oracle modelling
maspsx + as -O1 for a TU the Makefile builds through reorder_passthrough +
as -O2. func_800226C0 came from the §476 finding that a hard-register pin
strips nonzero_bits and reg_n_sets==1.
2026-09-03 17:05:47 -06:00
Drew T d7a9f471b4 refactor(fleet): convert 26 DECOMPILE-NOW verbatim bodies to stubs
Every remaining DECOMPILE-NOW row in config/verbatim_manifest.json that was
still a §265 verbatim __asm__ body: main 13 (incl. `main` itself, 509 ins,
in src/boot.c), md_MAIN_003 11, md_MAIN_020 1, ov_SC06_010 1. They were
byte-identical by construction and completely undecompiled, and no gate or
draw could see them — draw_waves reported only 26 drawable stubs fleet-wide
while 27 more sat locked in this form.

Byte-neutral, verified per binary: main 143dbb89, md_MAIN_003 dd1b32ec,
md_MAIN_020 0990e041, ov_SC06_010 05c2d8c4.

SKIPPED ov_SC03_107:func_8017D878. The manifest marks it DECOMPILE-NOW but
the cookbook's §265 addendum documents it as a DELIBERATE verbatim bank: its
only use in the TU is address-taken, forcing a `void f(void)` declaration
the real body contradicts, and no C spelling reconciles them. Two sources
disagree; the one with the byte evidence wins.

md_MAIN_020 and ov_SC06_010 needed --asm-subdir: both are single-TU overlays
with zero INCLUDE_ASM lines left, so there is no prefix in the binary to
derive from. Spelling confirmed against a sibling overlay's own stubs.
2026-09-03 14:02:09 -06:00
Drew T e1631eaacb feat(main): CdReadSectorReadyCB (424) + func_80035C4C (248) banked byte-identical
Both needed the §376 recovery in the DRAFT — adopt the TU's spelling for a symbol the
draft also declares:
  * CdReadSectorReadyCB dropped its own 'extern void func_800599B8(void *rect, ...)';
    the TU declares it (SpadRect_800184F0 *) at src/800.c:5480, above the insertion point.
  * func_80035C4C adopted 'extern void func_8003D650(int,int,int)' — no caller anywhere
    uses the return value, so the s32-vs-void difference was free to give up.

Also corrects src/800.c's dead-branch 'extern void func_80018714(void);' to '(void *)'.
That declaration lives inside #ifdef NON_MATCHING and is never compiled, but gate_main's
DECL scan has no notion of preprocessor guards and read it as a live conflict. The live
K&R definition at :5576 takes void *, so the correction makes the dead copy agree with
reality as well as clearing the false conflict.
2026-09-02 16:24:23 -06:00
Drew T 383ff02d93 fix(main): align 12 forward declarations with their definitions (§376), byte-neutral
Prepares the S73 wave's 9 byte-verified drafts for gating. Five definitions have
promotion-safe params so the declaration becomes K&R no-prototype — which also keeps
func_8003388C's 'Ent388C *' typedef out of scope at the declaration site, where it is not
yet defined. CdReadSectorReadyCB's u8 is NARROW so no-proto is unsafe (§17-stop); it gets
the exact prototype, safe because that symbol is only ever passed BY ADDRESS.

Verified BYTE-IDENTICAL with no draft substituted, via a DIRECT extract+build with the
binary deleted first — NOT via gate_main --assert-baseline, whose first action is
'git checkout -- src/*.c'. I used that first and it silently reverted these very edits,
then reported GREEN for a tree that no longer contained them: a verification of the
wrong thing. Same hazard as the two banks lost this morning, from the other direction.

Six of the twelve were found by checking every draft systematically rather than trusting
the agents' notes; two were never reported.
2026-09-02 16:21:49 -06:00
Drew T 7df4895e7b feat(main): split src/800.c at the jtbl-span TU boundaries — spans B and C now carve
BYTE-IDENTICAL with NO function banked (gate_main --assert-baseline, clean rebuild),
which is the whole point: the structure lands first and proves neutral, then drafts bank
against it.

One code object contributes exactly ONE contiguous .rodata run, and 800.o's is span A,
so spans B and C each needed their own object:

  800    vram 0x800123F0-0x8002B0B4  -> .rodata span A (0x80072A38-0x80072C70)
  800_b  vram 0x8002B0B4-0x80035270  -> .rodata span B (0x80072E44-0x80073140)
  800_c  vram 0x80035270-0x8003A444  -> .rodata span C (0x800732A0-0x8007344C)

The span owners' address ranges are disjoint and ordered — tables pack tight WITHIN a
TU and are separated by other data ACROSS TUs — so these are (at least some of) the
original translation-unit boundaries. Splitting here is both the fix and the minimum;
any extra split would be speculation.

main's island is now a 7-piece data->rodata sandwich, so ld_interleave moves from
--front/--tail to --order.

THE SPLIT WAS CHEAP, AND MY FIRST ESTIMATE WAS WRONG. I costed it at '2,318 scattered
extern lines' — that is the TOTAL; what matters is how many CROSS a boundary, and that
is 57 of 1,247 declared names (4.6%), of which 19 are typedefs with exactly one
definition each and zero shape conflicts. Zero file-local statics. src/800_shared.h
carries exactly those, derived from the COMPILER's own errors rather than a regex model
of C (R33), and each typedef was MOVED, never copied.

Unlocks 17 functions / 4,471 instructions = 39% of what is left in main, incl.
SaveLoadRoutine (1139) and func_8003388C (663).
2026-09-02 13:27:29 -06:00
Drew T 8c40fa3ebd feat(main): 4 more span-A switch functions banked byte-identical (wave S72m_1)
CdReadStateMachine (385 ins) · func_80024448 (362) · func_80026D64 (189) ·
func_8001B0D4 (86). One clean rebuild, 10.8 s, 4 of 4 accepted.

Wave shape: 5 targets, one agent per workflow, 5 concurrent. 4 MATCH / 1 NEAR.
Every agent verified its jump table and reloc stream past match_one's .text-only blind
spot (§405-A) because the packs carried the §426 carve note.

Three new laws banked from their notes: §428 (zero-byte cross-jump barrier), §429
(every held pointer needs its own local), §428a (two residuals moving in opposite
directions share one starved resource — which refuted my own prediction).

func_80024448 was recovered from disk after its Fable agent was killed by a rate limit
and the workflow reported NO-DRAFT; match_one on that file: closeness 0 (playbook §5b).
2026-09-02 12:52:39 -06:00
Drew T cbf5bae043 feat(main): unblock main's switch functions — the rodata span carve + derived jtbl pads
main's gate could only ever say "got X want Y". S71 read 7 such verdicts as body
rejects and recorded 11 functions as "PROVEN gate-rejects, §376 in its purest form".
They are not: all 11 are switch functions, and the blocker is that main has had
exactly ONE rodata carve since Phase 7 (LZSS's jtbl_80072A38). Every other main jump
table stayed raw in the tail data, so a drafted switch DOUBLE-EMITTED its table, the
image grew (+28/+52/+76/+84 measured), and all 238 symbols above 0x80072A4C shifted.

* tools/main_diff_locate.py (NEW) — turns a red image into a named list of divergent
  symbols via the linker map; per-byte attribution, self-test flips a byte at a known
  address and asserts the containing symbol (plus the identical-pair direction).
* gate_main.py — PRESERVES the red image + map before the R40 baseline control
  rebuilds over it, and auto-localizes: BODY REJECT vs PLUMBING REJECT vs MIXED. Also
  -j on the build (was single-threaded) and the §376 drop list written to
  .run/gate_main_dropped.json with the reconciliation chain.
* splat.us.exe.yaml — the .rodata carve extends from the LZSS table alone to the whole
  contiguous game-jtbl span 0x80072A38-0x80072C70 (12 tables, one 800.o run).
  Byte-neutral with no drafts substituted (probed first).
* jtbl_rodata_pads.py — --derive now works for main: one file-0-vram expression makes
  both address->bytes and yaml-piece->address correct for the EXE's 0x800 header and
  leaves flat overlays unchanged. Makefile arms it for BINARY=main.

Banked byte-identical: func_8001A114, func_8001AAD0, func_8001AF34 — three of the
eleven. 25 of main's 59 frontier functions (6,215 of 12,912 instructions) are in this
class; the remaining spans need src/800.c split at the TU boundaries the spans reveal.
2026-09-02 11:56:35 -06:00
Drew T e167c9c3cc feat(decomp): main +5 via gate_main - four §265 verbatim-asm walls and one ordinary body
The main lane, run the ONLY way main can be gated (§414): substitute the whole slate ->
make extract -> make build -> compare SHA1, with a bisect when the batch fails.
Baseline asserted green first (143dbb89...), batch of 6 failed, bisect isolated
func_8002C410 in 7 rebuilds, and the remaining 5 banked BYTE-IDENTICAL.

Four of the five are §265 verbatim-asm bodies for functions on the §332/§188 toolchain
wall list - the accepted route for a function the pinned triple cannot emit from C, the
same way func_800D0B1C banked overnight. Candidates came from scoring every stored draft
for main's 53 non-rejected open functions with match_one: 6 of 53 at closeness 0.
2026-09-02 10:05:39 -06:00
Drew T 6fbdfdb361 revert(main): commit:3586's 11 banks — main did not build from clean, and was not byte-identical
The R22 clean-fleet verify came back 212/213. The failure is main, and `git log -L` puts
all four conflicting declaration lines in commit:3586 — this session's own main re-gate:

  src/800.c:24519  extern int  func_8004355C(s32, void *);   vs :24396 (s32, u8 *)
  src/800.c:26395  extern void func_80038FFC();              vs the s32 definition below

Reconciling both declarations (byte-neutral, §376) made main COMPILE, and it was then
still not byte-identical — so the commit was wrong on both counts, not merely unbuildable.
The gate reported "11 banked" against a tree that cannot compile from clean.

src/800.c restored to commit:3586^; `make extract BINARY=main && make build BINARY=main`
now gives sha1 143dbb89f34491258bbc27810d0a12ec8b43a8dd BYTE-IDENTICAL. The 11 bodies are
kept at .run/S71_main_suspect/800.c.banked11 for a per-function re-gate — this revert is
about restoring a green fleet, not a verdict on every one of them.
2026-09-02 01:41:34 -06:00
Drew T 588208d50f feat(decomp): parallel gate — 11 fns across 1 binaries (1 workers)
main           func_8001A114 func_8001AAD0 func_8001AF34 func_8002EED8 func_8002F248 func_800316F8 func_80031988 func_8003602C func_80036260 func_80038FFC func_80039C70
2026-09-02 00:27:07 -06:00
Drew T cafaa7ac30 feat(decomp): §332b reorder island — +3 main fns (func_8005D244, func_8005DBD8, func_80061FA8) 2026-09-01 20:36:02 -06:00
Drew T 55c263d591 feat(decomp): S70 main — +1 fn (func_8002B0B4) from the standalone-match sweep 2026-09-01 17:11:59 -06:00
Drew T ebb0d3a2e3 feat(decomp): main in-tree gate — 3 fn(s)
main  func_80020598
  main  func_80030F80
  main  func_80038A58
2026-09-01 11:10:12 -06:00
Drew T 6a96a62f27 feat(decomp): main in-tree gate — 2 fn(s)
main  func_8001DA34
  main  func_80021D38
2026-09-01 04:53:15 -06:00
Drew T c794091725 feat(decomp): main in-tree gate — 8 fn(s)
main  func_80020A28
  main  func_80021284
  main  func_800221A8
  main  func_8002374C
  main  func_80026514
  main  func_8002D904
  main  func_800377D8
  main  func_8003DC90
2026-09-01 04:51:47 -06:00
Drew T c6f6f668ba feat(decomp): main/func_80036D58 — the narrow-param decl-sync completes the §378 chain
A no-proto decl is ILLEGAL against a definition whose parameter is affected by
the default argument promotions (s16 here): C89 requires the parameter types be
promotion-stable when one declaration has no prototype. So fix_arity_callers'
--any-proto cannot reach this case (it skips it as 'narrow-param').

With the call sites already cast (§378) the decls emit no code, so syncing them
to the draft's exact signature is byte-neutral: 3 decls in src/800.c rewritten to
extern void func_80036D58(s16). Byte-identical, main.
2026-08-31 23:51:19 -06:00
Drew T 72d3f61dcd chore(integration): self-caller casts for the 27 remaining §376 candidates (pre-gate) 2026-08-31 23:36:59 -06:00
Drew T da32350873 feat(decomp): main in-tree gate — 1 fn(s)
main  func_80013B64
2026-08-31 22:18:35 -06:00
Drew T 0dacc7b3f9 feat(decomp): main in-tree gate — 0 fn(s) 2026-08-31 18:50:44 -06:00
Drew T 86918184da feat(decomp): main in-tree gate — 0 fn(s) 2026-08-31 18:47:29 -06:00
Drew T f7fee7fcde feat(decomp): main banks again — 3 fns (func_80012B58, func_800241C0, func_800242D0)
The first main banks since the two harness defects were fixed. All three were
proven byte-perfect in the real link by the Fable investigation BEFORE any fix,
and reported {banked:0, near:3} purely because:
  * gate_stage compared main against ov_SC01_077's SHA (build/main/main never
    exists, config/check.main.sha never exists, DEF_SHA took over), and
  * psyq_integrate dropped 'firstfile = 0x80061FA8;' on every incremental relink,
    so main's BASELINE was already 2 bytes red before a draft was spliced.

func_800242D0 additionally needed one reconcile: it declared 'extern u16
D_80063870' while the just-banked func_800241C0 declares 'extern s16
D_80063870[]' at file scope. gcc-2.7.2 rejects the conflicting redeclaration at
file scope AND at block scope (the block-scope shadow was tried and also
rejected), so the draft now matches the banked spelling and takes the address by
array decay. Only the address is used (t4 is a 'register s16 *'), so the element
type never reaches codegen -- and the whole-binary SHA proves it.

harvest_verify in the main tree: verified 3 / failed 0, final SHA
143dbb89f34491258bbc27810d0a12ec8b43a8dd BYTE-IDENTICAL. main 1048 -> 1045 stubs.

NOTE for the next session: parallel_gate's WORKTREE still cannot gate main (its
generated-input staging covers the 3 Makefile-named files but main's link needs
more). main is one binary, so gate it in the main tree with harvest_verify --
there is no parallelism to lose.
2026-08-31 17:08:32 -06:00
Drew T 21a2212ae3 feat(decomp): S67 main r2 — 1 banked (main 89 -> 88) + §332/§332a toolchain-wall findings
Wave s67m2_1: 7 sonnet agents, 1 MATCH banked, 6 NEAR — but 4 of the 7 are NOT drafting failures:
* func_8005FA94 / func_8005D244 — oracle_reorder.py bypass gives 0/55 and 0/62 diffs: the C is
  byte-correct, the pinned as -O1 cannot emit the §188 epilogue. func_8005D244 is additionally
  libpad pdent3.o, an SDK object owned by psyq_integrate.py — it should never have been drawn.
* func_80062144 / func_8005DBD8 — §332, traced to the compiler sources: gcc-2.7.2 emits a symbolic
  la as ONE atomic length-2 insn (no HIGH/LO_SUM split in this backend), eligible_for_delay requires
  length==1, so it can never fill a jump delay slot; the retail split is ASPSX macro-hopping that
  maspsx does not replicate. Byte-verified by running maspsx over cc1's raw -dS output.
  6 such functions fleet-wide, NONE banked.

§332a records the draw-policy consequence: main's cheap population is spent and the residual is
ENRICHED in toolchain walls, so main's apparent match rate is contamination, not a model signal.
Wall ledger at .run/S67_walls.txt for the --exclude mechanism.
2026-08-31 13:21:01 -06:00
Drew T 9673373d97 feat(decomp): S67 main wave — 5 of 7 banked (main 94 -> 89), byte-identical 143dbb89
Wave s67m1: 7 sonnet agents, 0 errors. 5 MATCH banked after bisection in 9 rebuilds;
the 2 NEAR drafts rejected exactly as their agents predicted (func_80013154 close=12,
func_8005ECC0 close=6).

One draft's declaration refused the whole batch first: func_8002A088 declared
`extern s32 func_8002A108(void);` while src/800.c DEFINES it as (s32) at line 15270.
Fixed with the no-proto half of cookbook §324 (`extern s32 func_8002A108();`) — a
no-prototype decl is compatible with a promotion-safe definition and leaves the 0-arg
call unchecked, byte-neutral for the emitted jal. Argues for wiring §324 into the ladder
rather than hand-applying it; it cost a full main gate cycle.

NOTE for the ledger: func_8005E8E8 and func_8005EC00 are verbatim file-scope __asm__
transcriptions, not decompiled C — both hit the §188 wall (2 callee-saved regs with
jr $ra + addiu $sp in the delay slot, unreachable from cc1 under the pinned as -O1),
and both follow established in-TU precedent (func_8005E79C, func_8005EB28).

WALL LEDGER candidates: func_8005ECC0's epilogue tail is proven unreachable via
oracle_reorder.py; only idx24-26 (a beq delay-slot steal) remains open there, and it has
now resisted 8 prior wave attempts plus 3 today.
2026-08-31 10:20:25 -06:00
Drew T f8d790c51e feat(decomp): main batch-gate batch 0 — 143dbb89 byte-identical 2026-08-30 22:50:31 -06:00
Drew T dfaec94e51 fix(main): declare the 3 return-type-flip fns s32, not void — byte-neutral, unblocks their drafts
src/800.c declares func_8002A544/func_8002A2D4/func_8002A7B4 as `extern void f(s32)`, but each
body genuinely materializes a value in $v0 on both exits (asm-proven). Under a true void signature
gcc-2.7.2 dead-codes exactly those materializations, so the byte-correct s32 body can never compile
in this TU — cookbook §43's 'return-type flip pair', which §183 records as TU-edit-required.

All three call sites discard the result (`func_8002A544(0x32);` as a bare statement), so widening
the declaration cannot change a caller. NEGATIVE CONTROL, run twice: with the edit applied and NO
draft substituted, main still builds 143dbb89f34491258bbc27810d0a12ec8b43a8dd, identical to
config/check.us.sha. The edit is byte-neutral by measurement, not by argument.

Committing it SEPARATELY because gate_main snapshots and restores the TU between passes: an
uncommitted edit is reverted before the gate ever sees it (measured — the first attempt banked 4 of
7 and left all three of these as stubs).

Note for the record: the S66 overlay reconcile lane proved this class also has DRAFT-ONLY escapes
that need no TU edit at all — §202's asm-label alias (`s32 aF800CCBC0(void) __asm__("func_800CCBC0")`,
used byte-proven on func_800CCBC0 and func_800D30D0) and a new register-$2 + input-barrier + shared
goto-exit lever (func_800D2A24). Those are the smaller blast radius and should be preferred where
the TU is shared; this edit is kept because it is proven neutral and these three drafts already
exist in s32 form.
2026-08-30 22:49:42 -06:00
Drew T ce4c7eaae1 feat(decomp): main batch-gate batch 0 — 143dbb89 byte-identical 2026-08-30 22:47:31 -06:00
Drew T c9029b18fd feat(decomp): main batch-gate batch 1 — 143dbb89 byte-identical 2026-08-30 21:27:06 -06:00
Drew T 9184ab9c8d feat(decomp): main batch-gate batch 0 — 143dbb89 byte-identical 2026-08-30 21:26:52 -06:00
Drew T 481cb5dff1 feat(decomp): main batch-gate batch 0 — 143dbb89 byte-identical 2026-08-30 20:14:04 -06:00