Commit Graph

203 Commits

Author SHA1 Message Date
Drew T 768676ac0d feat(phase-29 giants): func_8013C0F8 ×1 in ov_SC01_077 (jtbl_801D82FC carve)
-O0 core, single jump table jtbl_801D82FC carved into the o0 object's .rodata via
jtbl_carve (fit contiguously with the existing o0 carve). ov_SC01_077 byte-identical (R22 d19c9580).
2026-07-19 00:09:18 -06:00
Drew T af6e70afe8 feat(phase-29 crack-wave): func_8016D1D8 + func_8016D688 family sweep +274 (137/137 each)
These reference a per-overlay tail work-buffer whose base address DIFFERS per
overlay (h_seq relocated data). remap_hseq keyed the byte-OFFSET addresses
(D_801D9C21..) not the base symbol D_801D9C20/D_801D9C60 the exemplar C uses, so
it left them unresolved -> 0/137. Per overlay: base = symbol_map[D_801D9C21]-1;
declare dlabel D_<base> in config/symbols.<ov>.txt (byte-neutral, re-extract emits
the linker def), remap D_801D9C20->D_<base1> / D_801D9C60->D_<base2>. 3 SC07 stragglers
needed the carried ApplyMatrixSV/RotMatrixYXZ externs dropped (TU already declares
them with a different sig -> conflicting types). Each gated whole-overlay byte-identical.
2026-07-19 00:05:52 -06:00
Drew T 2605f206d3 feat(phase-29 crack-wave): func_80150170 ×138 dedup-propagate (+137, 138/138)
The hexR=138 dedup core (banked ×1 in commit:0716) -> dedup_propagate --addr
0x80150170 --source-overlay ov_SC01_077 --recover: 138 overlays rebuilt
byte-identical, 1 new group registered in config/dedup.us.yaml (0 stubs left).
~+13k ins (95 ins × 137 new members). (First attempt SIGTERM'd mid-gate at the
2-min timeout -> reverted the half-gated state, re-ran clean fail-closed.)
2026-07-18 23:15:06 -06:00
Drew T c9e12a079b feat(phase-29 crack-wave): +6 cores banked ×1 in ov_SC01_077 (R22 140/140)
Ultracode 11-core crack-wave over the freshly-regenerated draftable structural
frontier (R35: the Jul-14 manifest still listed already-banked families). 9
match_one MATCH / 2 near; 6 of 9 banked whole-binary byte-identical.

Banked (ov_SC01_077, ×1 — ×138 sweep deferred, Drew paused after the bank):
- func_80150170 (95, hexR=138 dedup core) — engine_core void->s32 narrow
- func_8016D1D8 (148) — data-label + typedef-scope
- func_8016D688 (60)  — data-label (D_801D9C20)
- func_80165240 (63)  — normalize_self_decls (caller-decl -> void(void*x3))
- func_80164E40 (25)  — engine_core void->s32 narrow
- func_801457A4 (79)  — -O0 (relocated into _o0b object)

- engine_core.h: 3 decls narrowed void->s32 (byte-neutral fleet-wide; callers
  ignore the return) — R22 clean-fleet 140/140 confirms neutrality.
- config/symbols.ov_SC01_077.txt: D_801D9C20/60 u8 data-label mirror so a
  re-extract re-emits the labels the D1D8/D688 banks reference (R22 corollary;
  fixed a type:data->type:u8 splat-format bug that broke ov_SC01_077 extract).
- 3 NOT banked (801549F8, 8013BD74, 8013C0F8): all match standalone, blocked
  ONLY by the §8 jtbl-rodata carve (NOT codegen; C0F8 was NOT a real DIFF).
- .run/giants: 2 near (8014D820 close-11 intrinsic-sched, 8012E364 close-22)
  + the 3 jtbl-blocked drafts preserved (R20).

R22 clean-fleet: 140/140 byte-identical; tools-health OK (dedup 1846/0,
C1 234205/234205); 0 NON_MATCHING linked (G4). Fleet 75.2/60.6/87.04 (flat —
×1 banks; the ×138 sweep is the deferred fleet-mover).

cookbook §58 (R30): match_one MATCH != bank — it compiles standalone so it is
blind to (a) Ghidra symbol names, (b) def-sig conflicts vs the fleet, (c)
callee-decl conflicts, (d) -O0-vs-O2; crack-wave drafts need a reconcile pass.
2026-07-18 22:58:15 -06:00
Drew T ece9c6ee8d feat(phase-29 §8e): sweep func_8013F350 x37 (chunk 3/3) — family COMPLETE 138/138, 0 failed
The hardest family (490 ins, 4-table [0,0,4,0] span, --like structure transfer, §30#2 x267
widen) swept PERFECT incl. all 4 SC07 tail overlays.
2026-07-18 04:15:54 -06:00
Drew T abc658b590 feat(phase-29 §8e): sweep func_8013F350 (chunk 2/3) — 50/50 BANKED 2026-07-18 04:06:15 -06:00
Drew T 232698dcfb feat(phase-29 §8e): sweep func_8013F350 x50 (chunk 1/3) — 50/50 BANKED (--like 4-table span transfer proven x50) 2026-07-18 03:53:21 -06:00
Drew T 698a3d58e2 feat(phase-29 §8e): sweep func_80159C84 remainder r3 — 29/33 BANKED (family 133/137) 2026-07-18 03:37:06 -06:00
Drew T 85fc2a1a7c feat(phase-29 §8e): sweep func_80159C84 remainder r2 — 51/50 BANKED 2026-07-18 03:28:10 -06:00
Drew T 44f70fbb8f feat(phase-29 §8e): sweep func_80159C84 remainder r1 — 50/50 BANKED (clean canonical-decl draft) 2026-07-18 03:15:21 -06:00
Drew T c9499fbef8 feat(phase-29 §8e): func_80159C84 diagnostic — clean (canonical-decl) draft banks the gate-fail class (ov_SC01_004 BANKED) 2026-07-18 03:01:01 -06:00
Drew T a11e4d9d85 feat(phase-29 §8e): sweep func_80159C84 partial — 3 BANKED (SC01_000/001/005) before diagnostic stop
Chunk stopped at 8/50 (3 BANKED / 5 gate-fail) to read the real per-sibling error instead of
churning the ladder (§55b). Mid-flight ov_SC01_080 reverted clean.
2026-07-18 03:00:32 -06:00
Drew T c3afadc878 feat(phase-29 §8e): bank giant func_8013C414 (329, -O0) x1 — all 4 jtbl giants banked x1
Single-table carve jtbl_801D836C (27e, 4-mod-8 first-table = placement-only) into the _o0
subseg; draft spliced clean, no reconciles needed (its only blocker was the missing carve).
Whole-binary gate [ OK ] sha1 d19c9580 == check.
2026-07-18 02:56:25 -06:00
Drew T 1cb018bc00 feat(phase-29 §8e): bank giant func_8013F350 (490) x1 — the 4-table [0,0,4,0] span + tables= persistence
- jtbl_carve §8e hardening (the F350 lesson): a pre-§8e Phase-26 merged-double span had NO
  recoverable structure — spec derivation now uses the payload ZERO-WORD rule over persisted
  table starts (tables= comment on the JTBL_PADS line), with source priority
  {untouched+line=reuse verbatim | untouched+no-line=skip | touched=union of .s refs,
  line tables=, --span-tables override, --like exemplar role-transfer}; spec_from_starts
  replaces interval-carry; None-tolerant legacy comments; --like/--span-tables CLI.
- F350 carve: tables 8860(8e)+8880(5e,trimmed) fused BEFORE the existing 8898/88B8 double via
  the zero-checked 4-gap -> ov_SC01_077.o JTBL_PADS := 0,0,4,0 (tables= persisted).
- splice reconciles (§56, byte-neutral): §30#2 def-side widen void->s32 (TU extern +
  engine_core discarding-caller macro extern); D_80115158/D_8011515C macro-canonical redecls
  + §18 width-preserving store casts (sh under u8[]/u8); func_801416D4 canonical (s16) redecl
  + §17a-1 fn-ptr (s32) call cast; D_80187BD0 block-scalar decl dropped (file array covers).
- whole-binary gate [ OK ] sha1 d19c9580 == check. 3 of 4 giants now banked x1.
2026-07-18 02:55:34 -06:00
Drew T db2daf47e4 feat(phase-29 §8e): bank giant func_80159C84 (337) x1 — isolate + the FIRST pad=4 spec
- NON-CONTIGUOUS -> jr_isolate_all --only (new jr_80159C84 subseg, 2 region files);
  jtbl_carve func_jtbls: stale-location .s CONTENT fallback (ownership stays config-derived) —
  needed once a spliced fn is re-extracted (no fresh .s anywhere).
- carve: jtbl_801D8AFC (7e, trimmed) + pad word + jtbl_801D8B1C (5e, trimmed) ->
  JTBL_PADS := 0,4 — the first reproduced ORIGINAL interior pad (the §8a 'handle then' address).
- splice reconciles (§8d carried-layer-wins, all byte-neutral): draft scalar typedefs stripped;
  3 draft decls dropped for carried (D_801891B8 void*, D_8018911C u8 addr-only, func_80149FB0 s32);
  3 call-site casts + the §17a-1 fn-ptr cast for canonical-(void) func_80161208.
- whole-binary gate [ OK ] sha1 d19c9580 == check.
2026-07-18 02:41:16 -06:00
Drew T 9b463f2f97 feat(phase-29 §8e): sweep func_80131340 x37 (chunk 3/3) — 137/137 siblings BANKED, family COMPLETE
The full 138-overlay family (424 ins) is now banked: exemplar + 137 siblings, 0 failures across
all 3 chunks — the first jtbl giant family completed through the §8e pad-spec mechanism.
Logs .run/sweep_80131340_c{1,2,3}.log.
2026-07-18 02:29:43 -06:00
Drew T 224bf44ca2 feat(phase-29 §8e): sweep func_80131340 x50 (chunk 2/3) — 50/50 BANKED, 0 failed
Per-sibling §8e carve+pad-spec, every sibling whole-binary byte-identical.
Log .run/sweep_80131340_c2.log.
2026-07-18 02:20:38 -06:00
Drew T 387e224ead feat(phase-29 §8e): sweep func_80131340 x50 (chunk 1/3) — 50/50 BANKED, 0 failed
jtbl_family_bank --raw, per-sibling §8e carve+pad-spec auto-derived; every sibling whole-binary
byte-identical ([ OK ] per member). Log .run/sweep_80131340_c1.log.
2026-07-18 02:13:51 -06:00
Drew T 15c38fd953 feat(phase-29 §8e): bank giant func_80131340 (424) x1 — first 4-mod-8 non-first jtbl bank
- draft (.run/giants/p29t3_func_80131340.c, match_one 424/424 twice-verified) spliced at the
  ov_SC01_077_jr_8012ACE0.c stub slot; block-scope V8 + func_80131CF4(int,int) fixes carried.
- jtbl_carve: merged .rodata span 0xaff20..0xb0000 (jtbl_801D8078 51e + jtbl_801D8144 5e) +
  JTBL_PADS := 0,0 (the first §8e spec in the fleet; the +4 align pad suppressed).
- whole-binary gate [ OK ]: sha1 d19c9580 == config/check.ov_SC01_077.sha. Object proof:
  .rodata 0xE0 / Al=4 / table 2 tight at 0xCC in the production pipeline.
2026-07-18 02:05:11 -06:00
Drew T d6db1343b8 feat(phase-29 T4): type-lift + propagate 2 local-type cores x138 (func_8014E284, func_80137DD4)
The 2 Task-3 cores banked x1 but skipped by dedup_propagate ("not self-contained: local types").
Lifted EntSC01077 (func_8014E284) + P_TAG_80137DD4 (func_80137DD4) into src/shared/engine_types.h
(fleet-included via engine_core.h), and inlined func_80137DD4's file-local `#define OTE` into the body
(byte-neutral macro expansion, re-evaluated per use to preserve codegen). Both now self-contained ->
dedup_propagate --recover = 138 overlays byte-identical, 0 stragglers, 2 new dedup groups.

~+32.7k ins (108+129 x138). R22 clean-fleet 140/140 byte-identical; tools-health OK; dedup 1846->1852;
C1 coverage 234205. §55c local-type propagation cap lifted for these 2.

SESSION-2 close: this session banked ~94k ins across 4 fns x~137 overlays (2 non-jtbl giants fully
propagated + this 2-core type-lift); fleet 71.4->72.1% instr (+0.7pp), 140/140 throughout. The 4 jtbl
giants remain deferred on the byte-proven 8-align jtbl-carve gap (root cause half-pinned: cc1+maspsx
both emit .align 2, so the +4B pad is a downstream as/ld_interleave artifact) -> teed up as the next task.
2026-07-17 18:37:00 -06:00
Drew T c7fedced10 feat(phase-29 T4): propagate giant func_8014F4C0 (141) x134 + bank x1
Task-4 giant-bank #2. func_8014F4C0 (141 ins) banked x1 in ov_SC01_077_after.c (its earlier
"gate reject" was pure §55b propagate-damage — gated clean on the healthy tree, no fleet change).
h_exact family -> dedup_propagate --addr 0x8014F4C0 --recover: ov_SC01_000 was a cross-overlay
straggler (all-or-nothing h_exact), --recover reconciled the conflicting caller externs and kept
it -> 134 overlays byte-identical after propagation, +1 dedup group in config/dedup.us.yaml.

R22 clean-fleet 140/140 byte-identical; tools-health OK; ~+19k ins.

GIANT TAXONOMY (session finding, cookbook §56 + CURRENT_PHASE): the 12 preserved giants split into
- NON-jtbl (func_8013FAF8, func_8014F4C0): bank clean on a healthy tree, propagate x137 via macro/h_seq.
- jtbl (func_80131340/func_80159C84/func_8013C414/func_8013F350): each needs a per-overlay jtbl carve
  x137 AND hits an 8-align gap -> func_80131340 DEFERRED (byte-proven: gcc emits a non-first jump
  table .align 3 while the original packs it 4-aligned -> +4B padding shifts the whole data island,
  +5B/3077-diff image-wide %lo breakage). A jtbl_carve 8-align/isolation fix unlocks ~4 giants x137.
2026-07-17 17:40:54 -06:00
Drew T fd564a2cf7 feat(phase-29 T3): propagate the 3 self-contained cores ×137 (+410 instances; fleet 71.0->71.4% instr)
- targeted dedup_propagate --addr per core (NOT --auto-from), --recover for stragglers:
    0x8014ADE0 -> 138 overlays byte-identical
    0x801325B8 -> 134 (ov_SC07_011 byte-diverges -> auto-excluded, kept x1 — what --recover is for)
    0x801387B8 -> 138 overlays byte-identical
  = ~410 member-instances; 3 new dedup groups (1840 -> 1843), C1 coverage 233795/233795.
- 2 of the 5 banked cores (func_8014E284, func_80137DD4) stay ×1: "not self-contained (local types)"
  -> blocked on the build_engine_types type-lift (the §19/§20 propagation cap). Carried.
- R22 clean-fleet 140/140 BYTE-IDENTICAL; audit-binaries OK; dedup 1843/0; 0 NON_MATCHING (G4).
  Fleet instr 71.0 -> 71.4% / fn-count 86.30 -> 86.42% / distinct-code 53.3%.

- SELF-CORRECTION (R14/R35), now fixed in cookbook §55c + CURRENT_PHASE: my earlier claim that this
  propagate "needs ~2h+" was WRONG. That timing was taken while the tree still carried the partial
  damage of a killed --auto-from (90/140 overlays broken), so every member-gate was failing/retrying.
  On a HEALTHY tree a targeted --addr propagate is ~233s/core (all 3 = ~27 min) — ~20x faster. Only
  --auto-from is genuinely fleet-slow. A timing taken on a broken tree measures the breakage, not the
  tool — recover the tree FIRST, then measure.
- cookbook §55: the wave's new byte-proven levers (§49-variant birthing-boost suppression via
  reg_n_sets 1->2; sched1 birthing/LUID + "cc1 -dL" movable introspection; switch-tree vs jtbl
  CASE_VALUES_THRESHOLD=5; block-scope-extern beats *(T*)&sym) + the GATE-ORCHESTRATION law
  (--no-propagate per group then ONE targeted --addr; commit banks BEFORE propagating; a reverted src
  needs a re-extract; gate_stage's default harvest_verified.txt accumulates -> phantom banks).
2026-07-17 02:04:38 -06:00
Drew T f6f89781ff feat(phase-29 T2 Arm A): swing verdict = BANKED FACT (9/9 -O0 members on ov_SC07_010); fleet -O0 rollout deferred at the splat wall
- tools/rollout_o0_cluster.py (new) + Makefile O0_CLUSTER_OBJS -O0 wildcard: the -O0-cluster
  carve (0x13410..0x14834), adapting rollout_whale_o0.py to a 3-way <ov>/<ov>_o0/<ov>_o2b split
- ov_SC07_010: carve byte-neutral -> family_sweep --hseq banked 9/9 -O0 exemplar-family members
  whole-binary (R22 clean-fleet 140/140). The Task-1 masked-MATCH swing verdict is now a BANKED
  FACT: -O0 cluster members DO bank at -O0 (§52b). Phase-20 'func_8013B7AC overlay-local' refuted.
- THE WALL (byte-proven, TOOLING not compiler): the same carve on 006/007/011 byte-shifts the whole
  image (+0x20 %lo data-symbol shift, 34% diff) from a CLEAN build; boundaries verified as real
  fn-starts. Root cause = splat re-disassembly of a 3-way-split subseg that still holds INCLUDE_ASM
  stubs (the whale's stub-free _o0b shape avoids it). The Phase-20 '-O0 split infra' wall, root-caused.
- DEFERRED (ROI): full -O0 fleet rollout (~1,233 / ~0.6pp) — 3/4 sampled walled + 134 jr-embedded +
  bigger levers (Task 3 core-cracks, Task 6 tiny-IMM ~5,566). decision-log R31 + cookbook §18-P29.
- 140/140 byte-identical; dedup 1840/0; 0 NON_MATCHING (G4); main 143dbb89. Task 2 substantively done.
2026-07-16 17:05:52 -06:00
Drew T fda9eebb42 fix(phase-28 T4): wire all 4 SC07 overlays (6174/6457, 95.6%) + REPAIR the registry I destroyed
Completes T4 and corrects two defects I introduced, both landed in commit:0649.

- WIRED: 006 1543/1614 · 007 1544/1615 · 010 1544/1614 · 011 1543/1614 = 6174/6457 = 95.6%,
  ~0 agent tokens. Stubs/overlay ~2400 -> 831/984/898/825. Fleet instr 67.0 -> 68.9%,
  fn-count 82.16 -> 83.94%. dedup-check 1840 validated / 0 failed; groups now read
  "138 members [138 binaries]" (was 134); C1 coverage 227211 -> 233385 = exactly +6174.
  R22 make clean && extract-all && check-all -> 140 passed, 0 failed of 140 at every stage.

- FIX #1 — I DESTROYED THE REGISTRY'S DOCUMENTATION, AND EVERY GATE CALLED IT GREEN (H5).
  The first cut wrote config/dedup.us.yaml with yaml.safe_dump, round-tripping the whole file:
  47 comment lines -> 0 (including the curated Phase-11 header explaining WHY the share is
  source-level) and 1832 `vram: 0x80162FF4` -> `vram: 2148937716` (PyYAML parses YAML-1.1 hex to
  int; dumps int as decimal). 25,948 lines rewritten. It passed dedup-check 1840/0 AND check-all
  140/140 because _addr() accepts both forms: THE DATA WAS CORRECT AND THE DOCUMENT WAS RUINED.
  Fixed forward (R6, no history rewrite): restored from commit:0649~1 and re-applied the 6174
  memberships via a surgical text edit (add_members_surgical). Verified: 1545 insertions / 1545
  deletions, 0 non-`binaries:` lines changed, 47 comments + 1908 hex fields intact, and the
  rebuilt fleet is byte-identical to the destructive version (140/140).
  THE LESSON: every oracle this project owns measures BYTES, so a formatting-destructive write is
  invisible to all of them by construction. R34 says the byte-gate is a null COVERAGE oracle; this
  is the same hole one layer out — it is a null DOCUMENT oracle too.

- FIX #2 — I MIS-REPORTED THE DIFFs, TWICE (R14).
  (a) commit:0649 claims ov_SC07_006's 71 non-banks were "ALL PLUMBING, ZERO DIFF". FALSE — I read
      head -6 of the classified file and generalized. It has the same 4 DIFFs as the others.
  (b) I then built the jr guard assuming those 4 were the §53 jr class BECAUSE ov_SC01_077 hosts
      them in _jr_8017A4AC.c / _jr_80182268.c. has_mid_jr is FALSE for all four (33-52 ins, no
      jump table): they merely live in a carved jr-REGION split, which sweeps in every function in
      its address range. HOSTING FILE != FUNCTION CLASS.
  The guard is KEPT (preventive, §53-correct, currently skips 0 — no jr fn is in the extendable
  set) with its docstring corrected to record what it is NOT. The 12 DIFFs (0.19%) are UNDIAGNOSED
  and logged, correctly left as stubs by the gate — not dressed in a story.

- The 283 non-banks: 271 PLUMBING (the loose-typing conflict class + the whale, whose body lives
  in src/shared/func_80144B9C.h so no DEFINE macro exists to expand) + 12 DIFF. Existing tools
  cover the plumbing (cast_call_sites / canon_sig_reconcile / reconcile_tu).
2026-07-16 00:10:12 -06:00
Drew T c0486fe5f8 feat(phase-28 T4): dedup_extend — wire newly-onboarded binaries in; ov_SC07_006 1543/1614 (95.6%)
The 4 SC07 overlays P27 onboarded were byte-clean but NOT citizens: their .c included only
common.h (never ../shared/engine_core.h), so no shared body could reach them, and they
appeared in ZERO dedup groups (1689 groups read "134 binaries", never 138). Each sat at ~80
matched / ~2400 stubs while its siblings were ~2150 matched.

- NEW tools/dedup_extend.py — the missing mode. dedup_propagate is built for CRACK -> AUTHOR
  MACRO -> INSTANTIATE: --auto-from scans INLINE DEFS (planned only 11 here; the ~1600 shared
  bodies are ALREADY DEFINE_func_* macros in engine_core.h) and --addr dies "no source overlay
  has it matched" because no overlay holds an inline def. Extending an existing MACRO-BACKED
  group to a newly-onboarded binary is a different operation and nothing implemented it.

- SAFETY (explicit — this feeds the byte-gate): h_exact is the SHA1 of RAW INSTRUCTION BYTES, so
  two instances sharing one are identical INCLUDING their jal/lui/%lo reloc immediates — same
  callees, same data addresses, same symbols. The body that compiles byte-identically at one
  member does so at the other with NO remap. (Exactly why dup_report calls h_exact "guaranteed
  byte-match" and h_norm "candidate-only".) A bug here can only FAIL TO BANK, never falsely bank.

- REUSE, DON'T REBUILD (R33): owns only the set computation + the registry edit. The splice and
  the gate are harvest_verify verbatim (it already derives each stub's home TU from the corpus
  oracle, chunks + bisects, reverts on failure). h_exact members are byte-identical by
  construction -> the happy path is ~1 build per binary, not one per function.

- RESULT ov_SC07_006: 1543 / 1614 banked = 95.6%, ~0 agent tokens. Stubs 2374 -> 831.
  The 71 non-banks are ALL PLUMBING, ZERO DIFF, in two named classes with existing tools:
    * func_80144B9C "undefined reference" — the whale's body lives in src/shared/func_80144B9C.h
      (the -O0 shared header), not engine_core.h, so no DEFINE macro exists to expand.
    * "conflicting types for D_800A5E60 / func_8012C750 / func_8012C0EC" — the loose-typing
      conflict class (cast_call_sites / canon_sig_reconcile / reconcile_tu already exist for it).

- GATES: R22 make clean && extract-all && check-all -> 140 passed, 0 failed of 140, 0 FAIL lines.
  dedup-check 1840 validated / 0 failed; groups now read "135 members [135 binaries]" (was 134);
  C1 coverage 227211 -> 228754 = exactly +1543. The second oracle accepts the extension.

- Mechanism had been proven by hand first (probe-before-investing): +include + ONE stub ->
  DEFINE_func_80128158() -> ov_SC07_006 built 7ca772be BYTE-IDENTICAL, then reverted.
2026-07-15 23:14:19 -06:00
Drew T 4db79a2060 feat(phase-28 T1b): the B2 family swept — 102/115 banked (88.7%), fleet 67.0 -> 67.7% instr
The family the roadmap recorded as 0/8 ("~0%, structural families do not template" — the
number that rewrote P29's arithmetic to "(cores cracked) x (reach)") banks at 88.7% when
swept with the carve its own exemplar required. ~0 agent tokens.

- SWEEP: jtbl_family_bank.py over the remaining 107 members ->
  {'BANKED': 94, 'gate-fail': 7, 'remap-refuse': 6}. Family total 8 (T1) + 94 = 102/115.
  R22: make clean && extract-all && check-all -> 140 passed, 0 failed of 140, 0 FAIL lines.

- FLEET (measured, make report): instr-weighted 67.0 -> 67.7% (+0.7pp, +97,104 ins);
  distinct-code 47.8 -> 49.4% (+1.6pp); fn-count 82.16 -> 82.19%. 102 x 952 = 97,104 =
  the exact measured instruction delta — the arithmetic reconciles to the byte.

- THE 13-MEMBER TAIL is the predicted shape, and both halves are data for T3:
  * 6 remap-refuse = EXACTLY the family's 6 IMM members (cls_counts PURE 109 / IMM 6).
    imm_map_tier1 REFUSED rather than guessed: "unresolved immediates: [(512,
    'asm-ambiguous')]" — 512 also occurs at a non-differing position, so a blind swap could
    corrupt it. This is the concrete shape of T3's IMM stratum.
  * 7 gate-fail = genuine byte-DIFFs, correctly rejected. Verified to leave NO residue
    (all 7: split_file=none, cfg_refs=0) — no false-bank risk.

- HYGIENE: the 7 "git checkout ... did not match any file" errors are benign (revert of a
  never-tracked path). Verified 0 untracked splits belong to a non-banked member; 91 new
  splits + 3 banked into existing splits = 94.

- SCOPE (P9, unchanged): still n=1 family, and jr is the rarest class (3/163 matched-exemplar
  families). This demonstrates the mechanism at family scale; it does NOT give a rate for the
  PURE/IMM mass (98% of the population). T3 measures the swing number.
2026-07-15 22:34:45 -06:00
Drew T a4640e3a51 feat(phase-28 T1): B2 LIVES — 8/8 banked; the "families don't template" doctrine was a missing carve
The roadmap's decisive P28/P29 input (h_seq families bank at ~0%) is byte-refuted. Same
family, same era, through the carve path its own exemplar required: 8 of 8 BANKED.

- THE PROBE: jtbl_family_bank.py func_8017BEBC ov_SC01_000 0x8017bebc --raw
  .run/phase26-cracks/func_8017BEBC.c over 8 of 115 members (4 same-address + 4
  CROSS-address, exercising to_addr) -> {'BANKED': 8}.
  R22: make clean && extract-all && check-all -> 140 passed, 0 failed of 140.

- ROOT CAUSE of the P27 0/8, byte-verified: 0x8017BEBC is a jr/switch core. §47 banked its
  exemplar as "lazy isolation -> carve (9-piece interleave) -> splice -> BYTE-IDENTICAL" and
  called the fix "×N template-safe". family_sweep.hseq_sweep stages C and gates -- it has NO
  CARVE STEP -- so gcc's generated jump table is never placed at the sibling's address. The
  entire residual is TWO WORDS: classify_member -> PURE, ndiff=2 @ idx 343/345 =
  lui/lw %hi/%lo(jtbl_801EC44C). overlays.mk:112 carves ov_SC01_000_jr_8017BEBC.o for the
  exemplar; :134 has no such entry for the member. tools/jtbl_family_bank.py exists to do
  exactly this per sibling and had NEVER been run on this family.

- THREE COMPOUNDING FAILURES made the doctrine: (1) wrong tool for the class; (2) n=1 on the
  LEAST representative family -- has_mid_jr is 3 of 163 matched-exemplar families (120 of
  13,232 members) -- generalized to the whole frontier; (3) its corroborating Phase-26 probes
  (tiny-IMM 0/241, PURE 0/134, pinned 0/133) ALL predate _carry_macros (P27 T5, commit:0637).
  P27's decision-log calls its own re-probe "a FOURTH phantom exhaustion proof" -- naming the
  mechanism that would have faked the first three, and never re-running them. The ~0% doctrine
  has NO surviving post-fix evidence.

- SCOPE HONESTY (P9): this refutes the EVIDENCE for ~0%; it does NOT establish a general rate.
  n=1, and jr is the rarest class by construction. T3 measures the rate over the population
  that actually exists: 1418 matched-exemplar families / 21,889 members (PURE 78% / IMM 20% /
  STRUCT 1.8% -- note the roadmap sizes its swing number on STRUCT = 1.8% of the input).

- TWO SELF-CORRECTIONS (R14), both mine: (a) the approved plan's "add jtbl_ to symbol_map" was
  a WRONG FIX FROM A TRUE DIAGNOSIS -- a compiler-generated switch table is never named in C,
  so there is no token to substitute; the fix is PLACEMENT. No symbol_map change was made and
  T1 became a run, not a code change. (b) func_8017BEBC.md's header still says "close=2 of 952"
  (pre-§47-slider); the .c was updated, the .md was not -- templating from the header's premise
  would have produced zeros indistinguishable from a wall.

- DISTILLED IN-SESSION (R30/R16): cookbook §53 (sweep a family with the tool its exemplar
  needed: the carve law, the --raw rule, the symbol_map-jtbl trap, and the "before a 0%
  retires a lever" three-question test); calibration.md's decisive table REWRITTEN (the ~0%
  row marked an artifact, not a rate; the addressable pool tabulated); decision-log R31.

- Carried: the family's remaining 107 members (~101,864 ins, ~0 agent tokens) -> T1b.
2026-07-15 21:56:28 -06:00
Drew T 264fe6c115 feat(phase-27 T7): disc-completeness audit — onboard 4 hidden SC07 overlays (136->140) + the type sweep
The whole-binary byte-gate is structurally blind to code nobody onboarded (R34): check-all is
green over the onboarded set no matter what code sits unbuilt on the disc. This reconciles the
onboarded set against every code-bearing PAC payload.

- new_overlay.sh: optional [ENTRY] arg (default 0.4) reaches a non-0.4.dec payload. Onboarded
  ov_SC07_{006,007,010,011} from 1.4.dec (they put graphics at PAC entry 0, the code overlay at
  entry 1 — invisible to the 0.4 hardcode for a month). Each byte-identical (7ca772be / b3b95547 /
  d7b5875d / 9885af74). FLEET 136 -> 140; check-all 140/140 (T2's pass==N re-baselined cleanly).
  difficulty.py NOT in the insertion set anymore (it derives, T6) -> only 3 tool dicts touched.
- tools/disc_code_sweep.py: decode every payload (reusing sig_image.make_insn) and gate code on
  BOTH valid>=0.90 AND jr_$ra density>=0.01. The jr_$ra gate is decisive: isValid() alone flags
  389 false hits (type-0/2 structured data decodes ~100% valid but has ZERO returns); jr_$ra
  separates code (~2.9-3.4%) from data (0.000%), validated on positive+negative controls.
- FINDING (docs/disc-completeness.md): type-4 location overlays are COMPLETE (138/138). All other
  types are data EXCEPT type-1 = 40 code payloads, 1 onboarded (the resident), 39 HIDDEN
  resident-class modules (mostly MAIN.CD/FILE_XXX/1.1). They load at UNKNOWN addresses (not the
  shared overlay slot), so they are NOT mechanically onboardable — byte-verifying a build binary
  needs its load address (P9), knowable only by runtime RE (the Phase-3 method). Deferred with
  evidence, NOT force-onboarded at a guess.
- CONSEQUENCE: game-code TRUE 100% now spans 140 onboarded binaries PLUS ~39 type-1 modules
  pending load-address RE. The roadmap assumed 136 — this is a real re-baselining (the +4 overlays
  also add ~2.45 MB to the denominator; every family propagation is now x138). Flows to T10/T11.
- SETUP §6.3 tool inventory updated (R21).
2026-07-15 18:33:37 -06:00
Drew T 3509acf4b7 feat(phase-26a): A9b — func_8017A4AC banked ×134 (536-ins giant, wall re-test payoff)
The A10 re-test payoff. func_8017A4AC (536 ins, reach-134) — "blocked on plumbing" since
session 8 — banks now that the audit repaired the recover path (A3d reconcile_tu / A3e gate).
jtbl_family_bank --raw swept all 133 siblings (per-sibling isolate → jtbl carve → remap_hseq +
canon_sig_reconcile → whole-binary gate): 133/133 BANKED, 0 failed. 0 still-stub overlays.

R22 CLEAN-FLEET (make clean + extract-all + check-all): 136 passed, 0 failed of 136.
dedup-check 1840/0 (jtbl sweep banks are per-overlay src, not registry).

DELTA:
  instr-weighted  68.1% -> 68.6%  (+0.5%, ~71,824 shipped .text instructions)
  distinct-code   48.0% -> 49.2%  (+1.2% — the siblings are per-location byte-variants)

The audit thesis, demonstrated: a giant "wall" that stood for many phases was our TOOLING (the
recover path could not resolve its struct/fn-ptr conflicts), not an intrinsic compiler residual.
Once the oracle was fixed, the wall dissolved and banked ×134.
2026-07-14 20:38:10 -06:00
Drew T 97d86fae69 feat(phase-26a): A9b — bank func_8017A4AC exemplar ×1 (wall re-test payoff)
The 536-ins reach-134 giant listed "blocked on plumbing" since session 8. Re-tested through
bank_exemplar after the audit's recover-path fixes (A3d reconcile_tu wiring / A3e gate): BANKED
at the `recovered` stage (fb.recover / reconcile_tu resolves the D_80126B58 struct + D_801DA75C
fn-ptr conflicts the raw/scoped stages hit). Lazy-isolated into its own jr subseg + jtbl carve.

HONEST ATTRIBUTION (R14): this bank is the payoff of the A3 recover path, NOT A9a — it banked at
`recovered`, before the `reconciled` (canon_sig_reconcile) stage was reached. A9a's fn-ptr
classifier fix is a correctness fix that did NOT independently unblock a bank in the 7-candidate
re-test (the reconciled stage failed on func_8015B950's func-conflicts; the rest hit K&R /
scalar-typedef / non-ov077 / non-contiguous-carve blockers) — the same null-immediate-banking
pattern as A3c/A3d/A3e; its value is protecting all future dispatch-table banking.

R22 clean-fleet: 136 passed, 0 failed of 136. Exemplar ×1 (+536 ins); the ×134 family sweep follows.
2026-07-14 20:09:22 -06:00
Drew T 2f38e31e76 feat(phase-26a): A3h — propagate 14 fleet-wide byte-exact stubs ×134 (Bucket P)
The standing-lead harvest (A3f/A3g continuation), measured precisely first (R14). Of the
~1,060 still-open byte-exact functions in the backlog:

  - Bucket G (67 open in ov_SC01_077): re-gated through the A3e-fixed gate_stage
    --no-propagate -> 0 banked. HONEST: A3f already took the bankable 33; the residual is
    the known hard classes (jtbl-rodata / register-pins / struct-collision) + stale backlog
    rows whose LATEST state is a WAVE mismatch. Correct G3/P9 rejection.

  - Bucket P (88 matched in ov077, open in siblings): the clean lead. dedup_propagate --addr
    (A3g primitive) skipped 70 as h_exact reach<2 (per-location byte VARIANTS -> family_sweep
    territory, not plain propagation) and propagated the 14 genuine PURE fleet families:
      5 top (func_80129C40/8012A6D0/80130A18/80131D68/80136DFC) + 9 more; 2 stragglers
      dropped all-or-nothing (0x80173A60, 0x8014C568 -> --recover candidates).

Each propagated x~133 (dedup_propagate internal gate: 134 overlays byte-identical).
R22 CLEAN-FLEET (make clean + extract-all + check-all): 136 passed, 0 failed of 136.
dedup-check: 1826 -> 1840 validated, 0 failed | C1 227211/227211.

DELTA:
  instr-weighted  66.8% -> 67.4%  (+~1,862 member instantiations shipped from C)
  distinct-code   46.8% -> 46.8%  (flat: propagation adds MEMBERS, not new distinct code)
  673 files (671 overlay .c instantiations + engine_core.h) + dedup.us.yaml + progress.fleet.md

Remaining standing lead: the ~72 variant Bucket-P + ~905 Bucket-X (absent from ov077) fns,
all latest-row closeness==0 -> route through family_sweep --hseq (per-sibling remap), next.
2026-07-14 17:41:24 -06:00
Drew T 60e26e07f8 feat(phase-26a): A3g — propagate the 3 fleet-wide banks ×134 (bounded, gated, R22-clean)
The 3 of A3f's 33 banks that are shared fleet-wide, stamped across all 134 overlays. Done the way
the earlier run should have been: TARGETED (--addr, not --auto-from), dry-run-sized first
(3 functions × 134 members = ~400 gates, not an unbounded fleet sweep), on a clean tree at HEAD.

  func_80130650 (31 ins) · func_80149450 (13 ins) · func_80174684 (9 ins) — each ×134.

  dedup_propagate internal gate : 134 overlays byte-identical, 3 groups registered
  R22 CLEAN-FLEET (the real proof, not the tool's incremental check that lied during the crash):
      make clean + extract-all + check-all -> 136 passed, 0 failed of 136
  dedup-check: 1823 -> 1826 validated, 0 failed | C1 coverage 225335/225335

DELTA (reconciles exactly):
    functions byte-identical  284,559 -> 284,958   (+399 = 3 fns × 133 other overlays)
    instr-weighted            66.7% -> 66.8%   (+13,167 shipped .text instructions)
    distinct-code             46.8% -> 46.8%   (flat: propagation adds MEMBERS, not new distinct
                                                code — the 3 bodies were counted at A3f)
    403 src files (3 ×134 instantiations + engine_core.h) + config/dedup.us.yaml

The other 30 of A3f's 33 are overlay-unique (×1) and need no propagation. The larger prize remains
the ~310 byte-exact stubs in the OTHER overlays (A3e), not yet attempted.
2026-07-14 16:47:42 -06:00
Drew T 82d79e7a32 fix(phase-26a): A6/A7 — the family engine could not see half its corpus; 17 fns banked x134 free
R22: check-all 136 PASSED / 0 FAILED. dedup-check 1823 validated / 0 failed (C1 coverage 224,933/224,933).
Fleet instr-weighted 66.5% -> 66.7%.

=== dedup_propagate: it was blind to HALF the corpus ===
overlay_files() used a hardcoded suffix allowlist ("_a","_o0","_o0b","_after") that predated the
Phase-26 jr carves -> 404 of the fleet's 811 overlay .c. The 407-file gap held 36,135 INCLUDE_ASM stubs
and ~32,000 inline defs, and overlay_files gates ALL of dedup_propagate (source_text / find_site /
apply_plan / struct_check / reconcile_caller_extern). Now a GLOB — never an allowlist, because the NEXT
split family would re-open it. The asm_subdir is always the file stem, an invariant the old four entries
already satisfied.

find_site's def-detector required the signature line to END in ')' and the next non-blank line to START
with '{'. It therefore silently dropped THREE shapes: K&R definitions (`s32 f(arg0)` / `s32 arg0;` / `{`),
multi-line signatures, and single-line bodies. K&R is the project's house style for exactly the biggest,
highest-reach functions — func_8015AE2C (562 ins), func_80166994, func_80133CD4, func_8015A3C8 — and they
live in the _jr_* files overlay_files could not even open. Fixing either alone would have been useless:
the glob exposes the files, and find_site would still drop their biggest prizes. Both fixed together.
  * The signature's closing paren is now found by a real paren-walk, not line.count() or split(')')[-1]:
    a single-line body containing a call (`void f(int a){ g(a); }`) has balanced parens of its own, so
    both shortcuts land on the WRONG paren and then misread the body's ';' as a prototype terminator.
  * AGREEMENT ASSERTION (the audit's): find_site vs family_remap.extract_unit -> 701 agree / 0 disagree.
    Negative controls hold (a prototype+call is rejected; a 1-line body with a call is a def).

=== THE HARVEST (free work, byte-gated) ===
--auto-from ov_SC01_077 now nominates what it could never see: 20 planned, 17 propagated x134, 3 dropped
as cross-overlay stragglers. 134 overlays rebuilt BYTE-IDENTICAL; 17 new dedup groups.
Includes ALL FOUR functions A1 caught the registry lying about (func_80128ED8 / 8012C098 / 8012C0EC /
8012C750): 0 stubs remaining, real shared macros. THE LOOP CLOSES — A1 found the lie, and THIS is the
bug that had made it true (3 of the 4 are defined in ov_SC01_077_jr_8012ACE0.c, which the allowlist could
not open, so the propagation never ran and dedup_integrate greenlit the result).

=== family_remap: 96 PHANTOM exemplars -> 0 ===
extract_unit globbed only src/<ov>/<ov>*.c, so a function matched via a SHARED body had no source form
and read as NOT MATCHED. 93-96 of 218 h_seq "matched" exemplars were phantom, carrying 2,157 candidate
members of which 1,834 are still-stubbed, PURE/IMM-clean, symbol_map-clean and unpinned — staged and
gated today, dropped before the first build then. It is now TOTAL over BOTH shared-body mechanisms:
  (1) the DEFINE_func_<ADDR>() macro — reconstructed as the exact INVERSE of dedup_propagate.make_macro
      (derived from the generator, not re-guessed from the text);
  (2) a DIRECT definition in a shared header, #included per overlay — the whale (func_80144B9C, 770 ins,
      -O0), which the registry explicitly records as "NOT a DEFINE_ macro".
  CENSUS: 216 matched exemplars, 216 real, 0 PHANTOM.

symbol_map named the symbol by HOW IT WAS LOADED, not by WHAT IT IS: reloc_targets labels every lui/%lo
pair "data", and a FUNCTION's address taken via lui/%lo (an address-taken callback) is exactly that shape
(splat's own .s: %lo(func_8017E1D4), 7 occurrences). The map got a D_<ADDR> key while the C writes
func_<ADDR>, so the word-bounded substitution matched NOTHING and silently no-op'd — the sibling kept the
EXEMPLAR's function pointer and the loss was booked as a BYTE failure, indistinguishable from a compiler
wall. Now emits both keys (addresses are unique; the pass is simultaneous, so the extra key is free).

gather_externs was line-oriented, so a WRAPPED comma extern was invisible in both directions (the first
line has no ';', the continuation has no `extern`). ov_SC01_077.c:271-272 declares NINE symbols that way,
and the exemplar referencing them (func_8013D178) is a 133-member family — every sibling was staged with
NO declaration, failed to compile, and bisect-stormed its whole gate group. Now statement-oriented, and
an unresolved symbol is REPORTED, never silently dropped.

=== family_sweep.stub_map / build_engine_types ===
stub_map: func_-only -> a curated-name stub read as "already matched" -> phantom exemplar. Now corpus-derived.
build_engine_types hard-exited on 1,070 of 1,470 type-bearing overlay .c (73%; the audit measured 573/709
= 81% on its narrower set) because 1,929 TAGGED-struct typedefs tripped a guard whose own comment asserts
"our source has only ANONYMOUS-struct typedefs" — true in Phase 20, false since the harvest agents started
writing tagged structs. inject_capped_externs routes every type-bearing body HERE as the type-heavy tail's
ONLY sanctioned unblocker, so the tail's unblocker could not run on the corpus the tail lives in.
A contained def (the typedef's span encloses the body) is liftable — it just must not be counted twice;
only a PARTIAL overlap is malformed. Verified on a file that used to hard-exit: 5 tagged typedefs folded +
forward-declared, 46 types written, exit 0.

  ** AND THE SHARPEST LESSON IN THE AUDIT: this one was never silent. It printed "[overlap] ... handle
     manually" every single time. But the message reads like a rare edge case rather than a four-fifths
     coverage failure, so nobody ever COUNTED it. A loud failure that nobody counts is exactly as
     invisible as a silent one. R32 must be "assert your coverage", not merely "fail loud". **

R14 self-catches, recorded because I hit both while fixing them: my first shared-header scan read a macro
body's `extern void f(void); \` as a DEFINITION (the trailing continuation means the line does not end in
';', so the decl guard never fired) — the exact bug fixed at commit:0552, reintroduced by me and caught only
because the whale resolved from the WRONG file. Column-0 anchoring fixes it by construction. And my
phantom census returned 0/0 twice because I guessed the manifest schema instead of reading it.
2026-07-14 10:34:06 -06:00
Drew T af2f40d153 fix(phase-26a): A4/A5 — 193 unmatchable slices dissolved; the closeness oracle stops lying
R22 CLEAN-FLEET: make clean -> extract 136 -> build 136 -> check-all = 136 PASSED, 0 FAILED.
make audit-corpus: 0 PHANTOM + 0 TRUNCATED (was 193).

=== A4: a CORPUS defect the byte-gate could never have caught ===
config/symbols.us.txt:981 declared `listCdBuffer = 0x80180000` — a correct Phase-3 name for MAIN's
LIST.CD RAM buffer. But that address is OUTSIDE main's image and INSIDE the overlay slot, and every
overlay's splat config stacks symbols.us.txt. High RAM is REUSED: an address that is a buffer to main
is live CODE to an overlay. So splat saw a symbol boundary mid-code and, across 97 of 134 overlays:
  * CUT 97 REAL FUNCTIONS IN HALF (a head ending on a `lui`, no return), and
  * INVENTED 96 PHANTOM ONES      (a tail beginning by reading the assembler temp $at).
193 slices NOBODY COULD EVER MATCH — not "hard", not "a compiler wall": unmatchable by construction.
They sat in the harvest queue as ordinary work, so agents would burn on them forever and the failures
would be filed as intrinsic compiler residuals.

The phantom listCdBuffer.s in ov_SC01_005 literally begins:
    lw $ra, 0x10($sp) / addiu $sp, $sp, 0x18 / jr $ra
splat cut a function immediately before its EPILOGUE and called the epilogue a function.

AND IT HAD ALREADY CONTAMINATED REAL WORK: in ov_SC03_031 the cut landed where the epilogue was
exactly `jr $ra; nop`, so the Phase-26 x134 sweep innocently BANKED the phantom as
`void listCdBuffer(void) {}` — byte-correct, gate-green, entirely fictitious — while leaving
func_8017FFC4 permanently unmatchable. Removed.

WHY NO GATE CAUGHT IT, AND WHY THAT IS THE POINT: INCLUDE_ASM pastes the two .s halves back VERBATIM
in original order, so the image is byte-identical either way. The byte-gate was green the whole time
and always would have been. It is a perfect CORRECTNESS oracle and a NULL COVERAGE oracle. No
assertion added INSIDE it could ever have found this. What found it was a SECOND, INDEPENDENT oracle:
tools/sig_image.py derives boundaries from the ORIGINAL bytes without splat, and DISAGREED with the
corpus (58,524/58,621 agreement with spimdisasm; correct on all 97 disagreements).
  => When one oracle is structurally blind to a class of error, the answer is not a better assertion
     inside it. It is a SECOND ORACLE THAT CAN DISAGREE WITH IT.  (`make audit-corpus` is now that.)

THE RULE (the mirror of R13/R15, never written down): a symbol whose address falls inside ANOTHER
binary's vram window must never enter that binary's symbol stack.
FIX: config/symbols.us.ram.txt — main-scoped symbols outside main's image — stacked ONLY by
config/splat.us.exe.yaml. Main keeps the name it needs (10 %hi / 11 %lo refs; 143dbb89 byte-identical);
the overlays never see it. Exactly one symbol was in scope fleet-wide; the resident window was clean.

AND A REAL FUNCTION THE ACCIDENT WAS HIDING: in ov_SC01_084 / ov_SC02_041 / ov_SC03_094 / ov_SC06_008
there IS a genuine function at 0x80180000 (111 / 35 / 28 / 74 ins), reachable ONLY via a fn-pointer
table (.word func_80180000) and never by `jal` — so splat cannot find it and needs the boundary
DECLARED. listCdBuffer had been supplying it by luck. Now declared honestly, per-overlay, in
config/symbols.<ov>.txt — exactly where R13/R15 says an overlay-scoped symbol belongs.

=== A5: the closeness oracle every crack agent trusts was lying on 155 functions ===
masked_diff._reloc_kind() knew 26/HI16/LO16. An over-approximating sweep of every reloc objdump emits
across all 3,367 build objects found FOUR: R_MIPS_26, HI16, LO16 — and R_MIPS_PC16 (211). PC16 fell
through to a FULL-WORD compare, but the object holds an UNRESOLVED PLACEHOLDER in the branch
displacement, so that compare can NEVER succeed.
DECISIVE TEST (derived from the invariant, not from reading the regex): INCLUDE_ASM pastes the
ORIGINAL asm, so for every stub diff_object_s() MUST be 0. Measured, coverage-asserted:
    2,741 functions scored — old mask: 150 LIES;  PC16 masked: 4 LIES.
(The 4 survivors are the separate length-delta defect.) A phantom non-zero sends an agent to grind at
a wall that is not there, and the wasted attempt is then booked as a MATCHING failure, feeding
reserved_walls() and PERMANENTLY BLACKLISTING a function that was never broken.

=== NEW FINDING (found by cutting the R22 corner): a STALE OBJECT CAN PRODUCE A FALSE PASS ===
`.o <- .s` is not a dependency make can see: assembly arrives via INCLUDE_ASM, expanded to a `.include`
consumed by maspsx/as AFTER cpp, while -MMD tracks headers only. Re-extract, build incrementally, and
make links a STALE object. This is not merely slow — INCLUDE_ASM pastes the ORIGINAL bytes, so a stale
object still yields the original image: SHA1 GOES GREEN while the split just changed is never exercised.
A broken config change can be "verified" by an incremental build. Live proof: 8 of 136 binaries linked
stale objects here; they failed LOUDLY ONLY BY LUCK (the dead symbol was an undefined reference) — a
merely-different-but-valid split would have gone green on all 136.
R22/H3 already legislate this, and I broke them. But a rule that needs a human to remember it is not a
gate. FIX: `extract` now invalidates the objects that include what it just rewrote (main's are top-level,
so -maxdepth 1 — verified it cannot clobber the other 1,605 objects). Structural, not advisory.

R14 self-catch, recorded: my first A5 test passed `fn=` to diff_object_s(), which takes two args; the
TypeError was swallowed by my own `except Exception: continue` and it reported 0 scored / 0 lies. I
wrote the exact bug I was auditing, inside the test for it. Caught only because 0 looked wrong. The
test now asserts its own coverage.
2026-07-14 10:12:19 -06:00
Drew T bb65d36341 fix(phase-26a): A1 — dedup_integrate was a gate that could print a FALSE GREEN
The audit's priority #1: a fail-closed byte-honesty validator whose silent skips nothing
downstream can catch. Three false-green paths, all measured, all now fail-closed with
negative controls.

R33 FIRST (derive, don't re-derive). The registry makes two claims; the tool only ever
checked one, and mis-described that one:
  C1 EQUIVALENCE ("these vrams hold the same code in the ORIGINAL") — checked against the
     sigs, which sign the ORIGINAL bytes. KEPT. But the docstring claimed it also caught
     SOURCE drift: it cannot. A sig is a property of the ROM, immutable w.r.t. src/. Source
     drift is caught by the BUILD. Docstring corrected (P9).
  C2 BANK ("matched once in the source header, instantiated at every member") — NEVER
     CHECKED. Now DERIVED from the build invariant: INCLUDE_ASM pastes the ORIGINAL asm, so
     a member NOT wrapped in it is byte-exact, and one that IS wrapped is not banked —
     whatever the registry says. C2a: the group's macro token must occur in its source file.
     C2b: no member may still be an INCLUDE_ASM stub.

THE THREE FALSE GREENS
 1. 1808 groups claimed a DEFINE_func_* macro; only 1801 exist. The 7 ghosts printed [ OK ] —
    hiding 532 member-instances / 22,344 instructions of REAL, UNBANKED work (4 fns matched in
    ov_SC01_077, still INCLUDE_ASM in the other 133 overlays).
 2. An absent .run/sig.<bin>.jsonl degraded to "0 validated, 0 failed" and EXIT 0. On a fresh
    clone the gate validated NOTHING and passed. Now fails; --allow-unsigned is the escape.
 3. The bank claim was never checked at all.

THE CAUSAL CHAIN (the audit's thesis in one example). 3 of the 4 hidden fns are defined in
ov_SC01_077_jr_8012ACE0.c — a _jr_* split file. dedup_propagate.overlay_files allowlists only
("_a","_o0","_o0b","_after"), so the propagator could not SEE them; the group was registered
anyway; dedup_integrate greenlit the lie. TWO silent-skip bugs compounding: one created the
hole, the other hid it. Harvest fuel -> .run/audit/a1_harvest_fuel.json, banked in A5.

BLAST RADIUS, MEASURED NOT PREDICTED (R14). Headline metrics UNCHANGED to the decimal
(instr-weighted 66.5%, distinct-code 46.8%) — weighted_metrics() derives from the invariant and
was structurally immune to the lying registry. FLEET REAL substantive unchanged (282,466):
progress.py had already been taught to distrust it (commit:0574). Only dedup_integrate still
believed it. A null result that CONFIRMS R33: the tool that refused to re-derive was the one
that was right.

- registry repaired: 1813 -> 1806 groups (7 ghosts removed; instances 223,725 -> 222,787)
- make report GREEN end-to-end: 1806 validated, 0 failed | C1 coverage 222,787/222,787 signed
- negative controls: stubbed member -> exit 1; missing sig -> exit 1; --allow-unsigned -> exit 0
- report-only tool: no compiled artifact depends on it, so no R22 clean-fleet is owed here
2026-07-14 02:50:28 -06:00
Drew T cc7ee23d03 feat(phase-26): func_801380E0 swept ×134 siblings — R22 136/136 byte-identical 2026-07-14 02:18:46 -06:00
Drew T c12c497e10 feat(phase-26): func_801380E0 banked ×1 (crack wave) — whole-binary gate, R22 136/136 2026-07-14 01:52:02 -06:00
Drew T 8a3f227ac1 feat(phase-26): func_8015444C swept ×134 siblings — R22 136/136 byte-identical 2026-07-14 01:50:19 -06:00
Drew T 9caea60142 feat(phase-26): func_8015444C banked ×1 (crack wave) — whole-binary gate, R22 136/136 2026-07-14 01:29:48 -06:00
Drew T cffbdbe88e feat(phase-26): func_8016AB6C swept ×134 siblings — R22 136/136 byte-identical 2026-07-14 01:28:41 -06:00
Drew T f5f3c44693 feat(phase-26): func_8016AB6C banked ×1 (crack wave) — whole-binary gate, R22 136/136 2026-07-14 01:00:51 -06:00
Drew T 55a63fae95 fix(phase-26): remove the duplicate code-subseg line from ov_SC01_077's committed config
Residue of the same isolation-revert bug fixed for ov_SC01_000 in commit:0558: a failed bank left its
isolation's config in place, the retry re-isolated on top, and a duplicate
  - [0x4b364, c, ov_SC01_077_jr_801734BC]
line rode into a commit. It is HARMLESS to splat (a zero-length subseg), so R22 stayed green and the
correctness gate never saw it — but it BLOCKED every subsequent isolation, which is what failed 5 of
the 9 crack-wave banks. Caught only by the fail-loud validation added in commit:0558 (a tool that refuses
to proceed on input it does not understand), never by the byte-gate. Fleet audit: ov_SC01_077 was the
ONLY affected config of 137. ov_SC01_077 rebuilds d19c9580 BYTE-IDENTICAL.
2026-07-14 00:59:13 -06:00
Drew T ffcd914ed5 feat(phase-26): func_8013FFD8 swept ×128 siblings — R22 136/136 byte-identical 2026-07-14 00:58:33 -06:00
Drew T b813432b1b feat(phase-26): func_8013FFD8 banked ×1 (crack wave) — whole-binary gate, R22 136/136 2026-07-14 00:31:58 -06:00
Drew T 7a5657e83c feat(phase-26): func_8015A3C8 swept x132 siblings — R22 136/136 2026-07-14 00:30:06 -06:00
Drew T 6f3441d261 fix(phase-26): 10% of the canonical-callee oracle was silently missing (own-line-brace DEFINE macros)
- BUG: gen_harvest_targets.SIG_IN_BODY_RE required `)\s*{` between a DEFINE_func_* macro's signature
  and its opening brace. When the brace sits on its OWN continuation line there is a line-continuation
  BACKSLASH between them:
        s32 func_80148824(void *arg0) \
        { \
  and `\s` does not match `\`. So the regex silently dropped every own-line-brace macro.

- BLAST RADIUS (measured): 186 of 1801 engine_core.h shared signatures — 10% of the oracle — were
  MISSING from the canonical-callee map that cast_call_sites / sig_unify / gen_harvest_targets resolve
  against. A draft calling one of them kept its own guessed signature, hit `conflicting types` against
  the TU's real definition, and the recovery pass reported nothing to fix — the failure looked like a
  hard wall. This is why the crack wave's byte-exact cores would not bank.

- FIX: `[\s\\]*` instead of `\s*`. Oracle 2122 -> 2308 entries.

- PROOF: func_8015A3C8 (493 ins, MATCH standalone) went from "28 conflicting types, unbankable" to
  BANKED ×1 BYTE-IDENTICAL at the `recovered` stage, with zero hand edits. R22 clean-fleet 136/136.

- This is the phase's SIXTH silent-skip bug and the THIRD of the same brace-placement class (§19
  find_site; scope_data_externs' own-line brace; now this). Cookbook §40's standing lesson applies:
  a tool that silently no-ops on input it cannot parse is indistinguishable from one that had nothing
  to do — prefer fail-loud on unparsed input.
2026-07-14 00:08:59 -06:00
Drew T cc08601ae7 feat(phase-26): func_80178D40 swept ×134 — the heaviest core in the game, fleet-wide
- 132/132 siblings banked (0 failures) via jtbl_family_bank --raw + the lazy-isolation chain.
  Each sibling: isolate -> jtbl carve -> remap from the raw crack -> stage ladder
  (raw -> scoped §8d -> recovered -> reconciled) -> WHOLE-BINARY byte-gate.
- R22 clean-fleet 136/136 BYTE-IDENTICAL from `make clean`; 0 NON_MATCHING (G4).
- METRICS: instr-weighted 63.8 -> 64.7%; distinct-code 40.7 -> 42.8% (+2.1 points from ONE core —
  890 ins x 133 overlays = ~118K instructions of unique engine code); fn-count 82.43%.
- tools/bank_exemplar.py promoted from scratch: bank a cracked EXEMPLAR ×1 through the same stage
  ladder jtbl_family_bank uses for siblings (carve/lazy-isolate -> raw/scoped/recovered/reconciled
  -> whole-binary gate). The exemplar path was previously hand-run each time.
2026-07-14 00:02:26 -06:00
Drew T 07ebb5658d fix(phase-26): jr_isolate_all empty-region0 skip — cutting an already-isolated region's non-leader works
Cutting func_80178D40 out of ov_SC01_000_jr_801734BC adds the region's banked LEADER (0x801734BC)
as a cut too (the one-carve-per-object rule), making region 0 EMPTY (the object's first item IS the
first cut) — and region 1's derived name equals the object name, so emitting region 0 duplicated the
line exactly -> splat "segments out of order". Skip an empty region 0; region 1 rightly claims the
object's offset and name. First sibling then banks through the full chain (isolation validation
green -> carve -> --raw remap -> stage ladder -> whole-binary gate): ov_SC01_000 BANKED, included
here. The remaining 132 siblings sweep next.
2026-07-13 22:14:57 -06:00
Drew T 7e4165676d fix(phase-26): isolation-residue corruption chain — config cleanup + revert() restores config + fail-loud validation + --raw sweep mode
Three-layer fix for the func_80178D40 ×133 sweep failures:

- LAYER 1 (the residue): jtbl_family_bank.revert() restored carve pieces + src/ but NOT the
  isolation's CODE-subseg lines in the splat config. A failed bank attempt (BEBC's first try)
  left its isolation config in place; the successful retry re-isolated on top and a DUPLICATE
  `- [0x4b364, c, ov_SC01_000_jr_801734BC]` line rode into the commit (harmless to splat —
  zero-length — so R22 stayed green). revert() now also restores config/splat.<ov>.yaml.
  The committed duplicate is removed (ov_SC01_000 rebuilt BYTE-IDENTICAL 9052dc0e).

- LAYER 2 (the detonation): jr_isolate_all walked the duplicated object TWICE -> two
  replacements -> a reversed duplicate block -> splat "segments out of order". It now VALIDATES
  the generated config (code subsegs strictly ascending, names unique) and refuses to write on
  violation, naming the likely cause — a corrupt input dies at the tool, not three tools later.

- LAYER 3 (the sweep template): jtbl_family_bank gains --raw <crack.c> — template from the RAW
  crack via remap_hseq_body instead of the exemplar's banked source unit. REQUIRED when the
  exemplar banked at the `reconciled` stage: a reconciled body is TU-SPECIFIC (§41c — uniquified
  type names, TU-targeted casts), so extract_unit hands the sweep a polluted template and every
  sibling gate-fails (byte-proven: 178D40 banked reconciled -> sweep 0/4; 8015AE2C banked raw ->
  sweep 133/133). Same law as family_sweep --reconcile-raw.
2026-07-13 22:13:11 -06:00
Drew T 660aa9f215 feat(phase-26): func_80178D40 (890 ins, ×134 — the heaviest core) banked ×1 in ov_SC01_077
The §46 crack (MATCH 890/890, pin-free) banked through the whole-binary gate: lazy isolation ->
new region ov_SC01_077_jr_80178D40 + jtbl carve -> the FULL stage ladder (raw 36 conflicts ->
scoped -> recovered 5 -> RECONCILED banked; canon_sig_reconcile's type-name uniquification resolved
the SV3/Obj20/Blk typedef collisions) -> BYTE-IDENTICAL d19c9580. R22 clean-fleet 136/136.
The ×133 sibling sweep (PURE per-location, members staged) runs next.
2026-07-13 22:05:53 -06:00