mirror of
https://github.com/Druthulu/BFM-decomp
synced 2026-09-28 23:00:29 -04:00
45fb6affbb3737ede09cc754d753f4f2285155e2
658 Commits
| Author | SHA1 | Message | Date | |
|---|---|---|---|---|
|
|
45fb6affbb |
fix(phase-28 T7): worklist --assert-partition read the wrong manifest key (silent default)
- worklist.py:194 read manifest.get("source", "ov_SC01_077") but the manifest key is
`source_overlay` -> the ", ov_SC01_077" DEFAULT always fired, so the R32 partition assertion
checked a hardcoded binary regardless of the manifest, and would print "PARTITION OK" while
validating the wrong one. Now reads source_overlay and FAILS LOUD if the key is truly absent
(refuses to guess a default — R32/R35). Still passes: 223 live stubs, 223 rows -> PARTITION OK.
- worklist.py:100 n_overlays default 134 -> 138 (defensive; the manifest always provides 138 since
the P27 disc audit, so this default is never actually hit).
NOTE on the other "134" mentions (backlog.py:22, second-oracle.md:60, build_fuel_manifest docstrings,
worklist.py:13): those are descriptive ×134-LEVERAGE prose, not functional — the actual reach is
recomputed live from the 138 sigs everywhere (reach_histogram globs .run/sig.ov_*.jsonl). Left as-is
rather than burn a phase on cosmetic docstring edits that aren't wrong (the leverage concept holds).
|
||
|
|
6d9af19482 |
fix(phase-28 T7): disc_code_sweep was blind to COMPRESSED code — the type-4 row was vacuous
The disc-completeness oracle (R34) decoded only the RAW payload bytes, so LZSS-compressed type-4 overlay code read as noise: every type-4 row said "code 0" — a VACUOUS row for 138 known-code binaries. This is not cosmetic. The tool exists to answer "what code did nobody onboard", and it could NOT have found the 4 hidden SC07 overlays (their code is compressed like every type-4) — they were caught by hand-reconciling 138-vs-134. It found the 39 type-1 modules ONLY because those happen to be uncompressed. - FIX: code_signals now decodes BOTH layers — the raw bytes AND the lzss.decompress() output — and takes the stronger code signal, recording which layer (raw|dec) in the report. Uncompressed code (type-1 resident-class) lives in raw; compressed code (type-4 overlays) lives in the decompressed layer. Reuses the extractor's own game-semantics lzss decoder (R33), not a second one. - onboarded_payloads() now also keys by the .dec-stripped raw path: a type-4 _EXE is the .dec, but the sweep iterates raw payloads, so without this all 138 type-4 overlays — now correctly seen as code — would false-flag as HIDDEN. - RESULT: type-4 row 138 payloads / 138 code / 138 onboarded / 0 HIDDEN (was "code 0"). The 138 detections are all via the `dec` layer (verified: 100% valid, 3.39% jr). A 139th un-onboarded type-4 overlay would NOW flag HIDDEN — structurally impossible before. The 39 type-1 modules are unchanged and reconcile with the committed disc-completeness.md. - Coverage still asserted (R32): 1189/1189 classified. Tonight's separate exhaustive ad-hoc sweep independently confirmed no further hidden overlays; this makes that a REPRODUCIBLE tool, not a one-off script. Ranked list -> .run/disc_code_sweep.txt (the file disc-completeness.md references). |
||
|
|
758c4365b6 |
feat(phase-28 T7): make audit-binaries — the R36 citizenship gate (R32 enforcement)
R36: a newly-discovered binary is not real until every consumer knows it. Onboarding produces a
byte-CLEAN binary (check-all green) that is not yet a CITIZEN — the tools that enumerate binaries
can each be silently unaware of it, and the byte-gate is structurally blind to that (R34).
Not hypothetical: P27 onboarded 4 SC07 overlays byte-clean; P28 found FOUR consumers silently
ignoring them (family_remap.img_path, .run/family_hseq.json, config/dedup.us.yaml, and the overlays'
own .c), hiding ~6,400 already-matched bodies. Every failure was silent.
- tools/audit_binaries.py asserts, coverage-checked BOTH directions (R32), against the config the
BUILD reads (R33 — onboarded = main + resident + every config/splat.ov_*.yaml):
1. dup_report.BINARIES (what corpus/family_hseq/progress all derive from) EXACTLY equals the
onboarded set — a missing binary is invisible to every derived tool; a phantom is invented.
2. every onboarded binary has a byte-derived sig.
3. THE LOAD-BEARING SC07 CHECK: every onboarded OVERLAY's .c includes ../shared/engine_core.h,
or no shared body can ever reach it (main/resident have their own bodies, exempt).
4. every onboarded overlay is represented in the family map (warn — regenerable/may post-date).
INFO: dedup-group membership (0 = onboarded-but-un-harvested, a dedup_extend candidate).
- NEGATIVE CONTROL: stripping the shared include from ov_SC07_006.c makes the gate FAIL loudly and
exit 1 — it catches the exact bug that hid 6,400 bodies for a month. Restored clean.
- Wired into `make tools-health` (the pre-matching ritual) — cheap (config + text scans, no build),
so it sits in the fast lane. Passes today: 140 onboarded, all full citizens.
- Reads config/dedup.us.yaml as TEXT (never a YAML round-trip — the H5 lesson from T4).
|
||
|
|
064e762a00 |
docs(phase-28): checkpoint — 9/11 tasks done; resume point for T7 + T3b recorded
Fleet 67.0 -> 68.9% instr / 47.8 -> 49.5% distinct, 140/140 byte-identical, 0 NON_MATCHING. Gate items met (swing number measured; resident resolved 90.34% + dossier). T7 (expanded to the audit-binaries R32/R36 gate + the blind disc_code_sweep fix) and T3b (the legacy h_seq rate) are recorded in CURRENT_PHASE with full state; both benefit from a fresh session's context. R36 drafted for PhaseEnd ratification. |
||
|
|
1dbf5477d0 |
perf(phase-28 T6): harvest_verify --chunk 1 no longer double-builds every failing draft
The gate's hot path is --chunk 1 (the prescribed default — chunked failures mis-attribute innocent neighbours, cookbook:1568). With an atomic chunk the old code fell into the bisect loop and re-ran attempt([fn]) on the SAME single element against the SAME baseline: a byte-identical DUPLICATE build. classify_fail reads _last_sha/_last_err, which the failed attempt(chunk) ALREADY set, so the re-attempt bought nothing but a second cc1+maspsx+as+ld. - FIX: an `elif len(chunk) == 1:` branch classifies + reports directly, skipping the bisect. Per-draft failure build cost 2 -> 1 in the loop; ~26% fewer builds overall at the measured 65% bank rate (successes were always 1 build; only failures doubled). Every wave, one branch. - CORRECTNESS unchanged: verified a guaranteed-failing draft still classifies DIFF and is reported, not silently dropped. Measured make-build calls for one failing draft = 2 (attempt + the single final confirming build), the redundant re-attempt gone. - Gate tooling only — no src/config/build change, cannot alter any binary's bytes (a bug here can only fail-to-bank, never falsely bank; G3/P9). No R22 owed. Found by the explore agent's gate-substrate survey (Phase-28 planning); the shard-farm half of T6 is deferred (conditional on P29 volume — the distinct-binary farm already exists in bulk_harvest, and the same-binary axis is a directory-shard build, documented in CURRENT_PHASE). |
||
|
|
af05f6e412 |
docs(phase-28 T5b): the resident wall dossier — 14 remaining, classed and byte-grounded
The flag-plant did NOT reach 100% (21 -> 14). This records what is left and WHY, per function, so the next attempt starts from evidence instead of re-deriving it. - docs/resident-dossier.md: all 14 remaining stubs in 3 honest classes + the 5 deferred jtbl. Each entry is the agent's own byte-grounded analysis — the levers tried, the exact gcc pass that blocked it, why it stuck. That analysis cost ~2.4M tokens and IS the durable asset (R30); the 7 banks were the cheap part. Raw verdicts preserved at .run/resident_wave_verdicts.json (R20, force-added past the .run/ ignore since they are not regenerable). - 5 PLUMBING: reached match_one MATCH standalone, failed IN-TU on `conflicting types` (D_8010EDEC / D_80115110 / func_800D1984 / CdReadRequest / cdFileLocTable). The Phase-16 loose-typing wall: the C is byte-correct, the TU cannot hold both spellings. gate_stage's recovery banked 0/5 — this needs a resident-scoped §41 def-side lever, not more drafting. - 4 DIFF: genuine gcc-2.7.2 residuals, each with a NAMED mechanism (func_800D2650 close=4 and func_800CFAD0 close=5 are permuter-class seeds; func_800D0E30 and func_800D27DC carry intrinsic allocno-priority verdicts). - 5 jtbl DEFERRED: need the rodata-island carve (§53 + the Phase-7 workflow), which the resident has no split infra for. Deliberately NOT forced — sweeping a jr function without its carve is EXACTLY how the "≈0% structural families don't template" doctrine was manufactured (T1), and that mistake cost two phases of strategy. - The dossier records the two caveats a future reader needs: the wave ran on a broken match_one (shared scratch — fixed in commit:0652, verdicts may carry that noise, the GATE results do not), and the func_800CEDFC / func_800D33E0 sig_image boundary question (defined in resident.c, absent from the 2nd oracle, while audit-corpus reports 0 PHANTOM/TRUNCATED) -> T7 audit-binaries. |
||
|
|
876dc7f053 |
feat(phase-28 T5): resident 21 -> 14 stubs (7 banked, 90.34%) + fix match_one's fake isolation
Ultracode wave: 16 isolated drafters over the resident's non-jtbl stubs (the 5 jtbl deferred —
they need the rodata-island carve, §53). Drafts only; the whole-binary byte-gate arbitrated after.
- BANKED 7/16, byte-gated: func_800CEFD0(77) func_800D0D7C(45) func_800D1B80(22) func_800D1E28(37)
func_800D1FC8(62) func_800D29F8(172) func_800D2D10(39).
Resident REAL 122 -> 129, stubs 21 -> 14, byte-ident 124/145 (85.52%) -> 131/145 (90.34%).
FLEET instr 9017152 -> 9017606 (+454 ins). R22 make clean && extract-all && check-all ->
140 passed, 0 failed of 140 (the first R22 was killed by a terminal crash and RE-RUN, not assumed).
Ground truth on 14 agrees 3 ways: source grep, splat-emitted stub .s count, progress.py.
- §52b's LAW, MEASURED AGAIN INDEPENDENTLY: the agents self-reported 11 match_one MATCH; the
whole-binary gate banked 7 (64%). All 4 blocked MATCHes died on `conflicting types`
(D_8010EDEC / D_80115110 / func_800D1984 / cdFileLocTable) — the loose-typing def-side wall, NOT
codegen. gate_stage's recovery banked 0/5 on them. A match_one MATCH is a CANDIDATE (G3/P9).
- FIX — match_one's isolation was FAKE, and its own docstring was the false spec. It promises
"Fully isolated (own temp dir) so many run in PARALLEL with no shared build -- a real asm-differ
loop for an agent to iterate against", while `--work` defaulted to the SHARED '.run/match': every
concurrent caller compiled into the same t.c/t.o. FOUND BY AN AGENT MID-WAVE, the only way it can
be found — it read another agent's function out of its own scratch ("found another agent's
func_800D2650 in my t.c") and reported it. Every other agent steered by a loop that could hand it
someone else's compile: a CONFIDENT WRONG verdict, worse than a crash. Default is now a private
.run/match/<fn>.<pid>; the default IS the promise. (Some agents had already worked around it by
passing --work themselves.) The byte-gate was never at risk — it is the sole arbiter — but the
iteration loop the agents steer by absolutely was.
- The 14 remaining: 5 PLUMBING (loose-typing) + 4 DIFF (genuine codegen: func_800D2650 close=4,
func_800CFAD0 close=5, func_800D0E30 close=12, func_800D27DC close=48) + 5 jtbl deferred.
Dossier next (T5b) — the agents' per-function residual analyses are the durable asset (R30).
|
||
|
|
2c4e2344da |
fix(phase-28 T5): progress.py — #if 0 blindness + the len()-sum; resident 123/146 -> 122/145
R35: fix the instrument before planting a flag on its denominator.
- #if 0 BLINDNESS: classify() knew `#ifdef NON_MATCHING` (:425) but not `#if 0`, so a dead
analysis body was read as a live definition AND its real INCLUDE_ASM stub counted separately —
the SAME function in BOTH `real` and `stubs`. Live case: resident.c:868-925 wraps a full
void func_800D00E4(s32){...} in #if 0 (its jtbl dossier) and re-declares the stub at :926.
Now the block is skipped entirely: dead code is neither matched nor stubbed.
- THE len()-SUM (the dual defect): `placed` was a set union, so it caught a function in NO bucket
— but `matchable` SUMMED len()s, so a function in TWO buckets counted twice and nothing
complained. matchable/byteident are now SET unions, plus a new OVER-coverage assertion that
fails loudly if any fn lands in multiple buckets. R32 means both directions: nothing missing,
nothing double-counted.
- NEGATIVE CONTROL (the fix must change an answer the old tool gave):
resident REAL 123 -> 122 | matchable 146 -> 145 | 85.62% -> 85.52% | func_800D00E4 no longer
double-counted. FLEET instr 68.9% UNCHANGED (no #if 0 in the overlays) — the fix is scoped.
- FINDING (logged for T7's audit-binaries, does NOT block the flag-plant): the two INDEPENDENT
oracles now agree exactly at 144 — corpus (21 stubs + 123 matched, derived from the tree) and
sig_image (the 2nd oracle) — with EMPTY set difference both ways. progress.py still reports 145
because it counts func_800CEDFC and func_800D33E0, which are DEFINED in resident.c but absent
from sig_image. 0x800CEDFC is the resident's vram base +4 (the first function, code starts at
file offset 0x4 after the leading data word), yet make audit-corpus reports 0 PHANTOM +
0 TRUNCATED. Either sig_image has a boundary blind spot or those defs are not image functions.
progress.py's text-scanning classify() is exactly the re-parsing R33 says should be DERIVED from
corpus instead — a real refactor, logged not rushed.
The flag-plant claim is unaffected: it rests on corpus.stubs('resident') == 21 (tree-derived,
verified 5 ways), not on the contested denominator.
|
||
|
|
fda9eebb42 |
fix(phase-28 T4): wire all 4 SC07 overlays (6174/6457, 95.6%) + REPAIR the registry I destroyed
Completes T4 and corrects two defects I introduced, both landed in commit:0649. - WIRED: 006 1543/1614 · 007 1544/1615 · 010 1544/1614 · 011 1543/1614 = 6174/6457 = 95.6%, ~0 agent tokens. Stubs/overlay ~2400 -> 831/984/898/825. Fleet instr 67.0 -> 68.9%, fn-count 82.16 -> 83.94%. dedup-check 1840 validated / 0 failed; groups now read "138 members [138 binaries]" (was 134); C1 coverage 227211 -> 233385 = exactly +6174. R22 make clean && extract-all && check-all -> 140 passed, 0 failed of 140 at every stage. - FIX #1 — I DESTROYED THE REGISTRY'S DOCUMENTATION, AND EVERY GATE CALLED IT GREEN (H5). The first cut wrote config/dedup.us.yaml with yaml.safe_dump, round-tripping the whole file: 47 comment lines -> 0 (including the curated Phase-11 header explaining WHY the share is source-level) and 1832 `vram: 0x80162FF4` -> `vram: 2148937716` (PyYAML parses YAML-1.1 hex to int; dumps int as decimal). 25,948 lines rewritten. It passed dedup-check 1840/0 AND check-all 140/140 because _addr() accepts both forms: THE DATA WAS CORRECT AND THE DOCUMENT WAS RUINED. Fixed forward (R6, no history rewrite): restored from commit:0649~1 and re-applied the 6174 memberships via a surgical text edit (add_members_surgical). Verified: 1545 insertions / 1545 deletions, 0 non-`binaries:` lines changed, 47 comments + 1908 hex fields intact, and the rebuilt fleet is byte-identical to the destructive version (140/140). THE LESSON: every oracle this project owns measures BYTES, so a formatting-destructive write is invisible to all of them by construction. R34 says the byte-gate is a null COVERAGE oracle; this is the same hole one layer out — it is a null DOCUMENT oracle too. - FIX #2 — I MIS-REPORTED THE DIFFs, TWICE (R14). (a) commit:0649 claims ov_SC07_006's 71 non-banks were "ALL PLUMBING, ZERO DIFF". FALSE — I read head -6 of the classified file and generalized. It has the same 4 DIFFs as the others. (b) I then built the jr guard assuming those 4 were the §53 jr class BECAUSE ov_SC01_077 hosts them in _jr_8017A4AC.c / _jr_80182268.c. has_mid_jr is FALSE for all four (33-52 ins, no jump table): they merely live in a carved jr-REGION split, which sweeps in every function in its address range. HOSTING FILE != FUNCTION CLASS. The guard is KEPT (preventive, §53-correct, currently skips 0 — no jr fn is in the extendable set) with its docstring corrected to record what it is NOT. The 12 DIFFs (0.19%) are UNDIAGNOSED and logged, correctly left as stubs by the gate — not dressed in a story. - The 283 non-banks: 271 PLUMBING (the loose-typing conflict class + the whale, whose body lives in src/shared/func_80144B9C.h so no DEFINE macro exists to expand) + 12 DIFF. Existing tools cover the plumbing (cast_call_sites / canon_sig_reconcile / reconcile_tu). |
||
|
|
c0486fe5f8 |
feat(phase-28 T4): dedup_extend — wire newly-onboarded binaries in; ov_SC07_006 1543/1614 (95.6%)
The 4 SC07 overlays P27 onboarded were byte-clean but NOT citizens: their .c included only
common.h (never ../shared/engine_core.h), so no shared body could reach them, and they
appeared in ZERO dedup groups (1689 groups read "134 binaries", never 138). Each sat at ~80
matched / ~2400 stubs while its siblings were ~2150 matched.
- NEW tools/dedup_extend.py — the missing mode. dedup_propagate is built for CRACK -> AUTHOR
MACRO -> INSTANTIATE: --auto-from scans INLINE DEFS (planned only 11 here; the ~1600 shared
bodies are ALREADY DEFINE_func_* macros in engine_core.h) and --addr dies "no source overlay
has it matched" because no overlay holds an inline def. Extending an existing MACRO-BACKED
group to a newly-onboarded binary is a different operation and nothing implemented it.
- SAFETY (explicit — this feeds the byte-gate): h_exact is the SHA1 of RAW INSTRUCTION BYTES, so
two instances sharing one are identical INCLUDING their jal/lui/%lo reloc immediates — same
callees, same data addresses, same symbols. The body that compiles byte-identically at one
member does so at the other with NO remap. (Exactly why dup_report calls h_exact "guaranteed
byte-match" and h_norm "candidate-only".) A bug here can only FAIL TO BANK, never falsely bank.
- REUSE, DON'T REBUILD (R33): owns only the set computation + the registry edit. The splice and
the gate are harvest_verify verbatim (it already derives each stub's home TU from the corpus
oracle, chunks + bisects, reverts on failure). h_exact members are byte-identical by
construction -> the happy path is ~1 build per binary, not one per function.
- RESULT ov_SC07_006: 1543 / 1614 banked = 95.6%, ~0 agent tokens. Stubs 2374 -> 831.
The 71 non-banks are ALL PLUMBING, ZERO DIFF, in two named classes with existing tools:
* func_80144B9C "undefined reference" — the whale's body lives in src/shared/func_80144B9C.h
(the -O0 shared header), not engine_core.h, so no DEFINE macro exists to expand.
* "conflicting types for D_800A5E60 / func_8012C750 / func_8012C0EC" — the loose-typing
conflict class (cast_call_sites / canon_sig_reconcile / reconcile_tu already exist for it).
- GATES: R22 make clean && extract-all && check-all -> 140 passed, 0 failed of 140, 0 FAIL lines.
dedup-check 1840 validated / 0 failed; groups now read "135 members [135 binaries]" (was 134);
C1 coverage 227211 -> 228754 = exactly +1543. The second oracle accepts the extension.
- Mechanism had been proven by hand first (probe-before-investing): +include + ONE stub ->
DEFINE_func_80128158() -> ov_SC07_006 built 7ca772be BYTE-IDENTICAL, then reverted.
|
||
|
|
515d003dbe |
feat(phase-28 T3-A): ZERO DIFF — the SC07 pool is the EASY (h_exact) class and is simply UNWIRED
Stratum A of the swing-number probe, on the cleanest test available: the 4 highest-byte-weight
SC07-only families are the GIANTS (func_80144B9C 770 "the whale", func_80141CA4 476,
func_80132784 400 "irreducible for 22 phases", func_80133CD4 399 the §45 Fable5 crack).
Exemplars already byte-proven, members PURE, non-jr -> every confound removed.
- RESULT 4 banked / 8 failed / 4 skipped of 16, and the CLASSIFICATION is the finding:
* BANKED 4 = func_80133CD4, a 399-ins Fable5 giant, into 4/4 new overlays, free
* PLUMBING 8 = "parse error before ')'" (func_80144B9C, func_80132784) — never compiled
* skipped 4 = pinned-exemplar (§42e guard; P27 T5 dissolved the wall behind it)
* DIFF 0 <- NOT ONE failure is a byte mismatch
Of the members that reached the gate as valid C: 4/4 = 100%. This is exactly the
DIFF-vs-CC1-FAIL distinction Phase 26 never recorded, and why its 0% couldn't be trusted.
- ROOT CAUSE (byte-verified, far bigger than the parse error): the 4 new overlays were
onboarded byte-clean but NEVER WIRED INTO THE SHARED-BODY ECOSYSTEM.
established ov_SC01_001 : common.h + ../shared/engine_core.h ; DEFINE_func_*() ; ~2150 matched
the 4 new SC07 : common.h ONLY ; ~2400 raw stubs ; ~80 matched
refs in config/dedup.us.yaml: 0. 1689 registry groups say "134 binaries", never 138.
The parse error is a symptom: the drafts need types (P10/P14/P18/P1C/HDR/ENT) that live in
src/shared/func_80144B9C.h — a header the SC07 TU never includes.
- SCALE (measured vs the registry): 6,513 live stubs across the 4 new overlays are byte-identical
to an ALREADY-REGISTERED h_exact group (1625/1628/1627/1633). That is the h_exact class —
which calibration.md itself rates ~xN near-100% — NOT h_seq, and NOT a member_adapt problem.
- MECHANISM PROVEN BY HAND (probe-before-investing): +#include "../shared/engine_core.h" and ONE
stub -> DEFINE_func_80128158() in ov_SC07_006.c -> make build -> 7ca772be... BYTE-IDENTICAL.
Probe reverted; the tool should do it uniformly.
- THE TOOLING GAP -> T4: dedup_propagate --auto-from plans only 11 fns (it authors macros from
ov_SC01_077 INLINE DEFS; the ~1600 shared bodies are ALREADY DEFINE_func_* macros in
engine_core.h), and --addr errors "no source overlay has it matched" because no overlay holds
an inline def. There is NO mode for "extend an existing macro-backed group to a
newly-onboarded binary". T4 builds it (NOT member_adapt — the number says build nothing else).
- R22: make clean && extract-all && check-all -> 140 passed, 0 failed of 140.
- CARRIED -> T3b: strata B (legacy PURE non-jr, 95 fam / 7993 members) and C (legacy IMM, 36 fam
/ 6644) — the LEGACY h_seq rate is still genuinely unmeasured. The SC07 pool answered a
different, cheaper question than T3 set out to ask.
|
||
|
|
65e96e5d5a |
feat(phase-28 T2): purge the poisoned grinder blacklist — 8 of its 22 had MATCHED anyway
The blacklist recorded "permuter won, byte-gate rejected => plumbing-bound, never
re-permute" for 22 fns. It was manufactured by a gate that no longer exists.
- R14 ON THE PREMISE, TWICE (before touching anything):
* The roadmap's two named grinder bugs are ALREADY FIXED (commit:0327, commit:0200) — stale line.
* docs/tooling-audit.md:933-937 DOWNGRADED ITS OWN FINDING with three corrections: the
prescribed fix is a NO-OP (deleting the scanner banks zero fns — harvest_verify was
single-TU BY CONSTRUCTION, the defect was mislocalized to it); nothing is being discarded
now (grinder STOPPED since 2026-07-02 — confirmed via .run/auto/STOP); queue magnitude
inflated (1252, not 1298). T2's only real content was the persisted artifact.
- AND THE AUDIT'S SNAPSHOT IS ITSELF STALE (verified in code): harvest_verify is now fully
multi-TU — _stubs derives every stub across every TU from the corpus oracle (:122), render()
splices "each draft into the TU that actually holds its stub", _write() writes multiple
paths, un-stubbed drafts are REPORTED not silently dropped (R32). The gate that manufactured
the blacklist is gone. No harvest_verify change was needed or made.
- THE PROOF IT WAS MANUFACTURED, NOT OBSERVED: of the 22 entries, 8 have since MATCHED anyway
(func_80131D68/80149374/8014FE60/80150528/8016BBE0/80171C64/80174684/8017F290); the other 14
are still stubs and would have been skipped FOREVER on a dead gate's verdict. (16 of 22 were
split-hosted, so harvest_verify never compiled them — the permuter's byte-matches were
discarded UNBUILT. The audit predicted 5 matched-anyway; it is 8.)
- DONE: blacklist -> [] (poisoned copy preserved at grinder_blacklist.json.poisoned-pre-T2);
grinder.py now carries the RULE (R35): a blacklist entry is a verdict from a SPECIFIC GATE
and EXPIRES when that gate changes — purge and re-derive from the fixed gate, never inherit.
A persisted negative verdict is only as good as the instrument that produced it.
- No byte claim (analysis tooling + a scratch artifact only) -> no R22 cycle owed.
|
||
|
|
4db79a2060 |
feat(phase-28 T1b): the B2 family swept — 102/115 banked (88.7%), fleet 67.0 -> 67.7% instr
The family the roadmap recorded as 0/8 ("~0%, structural families do not template" — the
number that rewrote P29's arithmetic to "(cores cracked) x (reach)") banks at 88.7% when
swept with the carve its own exemplar required. ~0 agent tokens.
- SWEEP: jtbl_family_bank.py over the remaining 107 members ->
{'BANKED': 94, 'gate-fail': 7, 'remap-refuse': 6}. Family total 8 (T1) + 94 = 102/115.
R22: make clean && extract-all && check-all -> 140 passed, 0 failed of 140, 0 FAIL lines.
- FLEET (measured, make report): instr-weighted 67.0 -> 67.7% (+0.7pp, +97,104 ins);
distinct-code 47.8 -> 49.4% (+1.6pp); fn-count 82.16 -> 82.19%. 102 x 952 = 97,104 =
the exact measured instruction delta — the arithmetic reconciles to the byte.
- THE 13-MEMBER TAIL is the predicted shape, and both halves are data for T3:
* 6 remap-refuse = EXACTLY the family's 6 IMM members (cls_counts PURE 109 / IMM 6).
imm_map_tier1 REFUSED rather than guessed: "unresolved immediates: [(512,
'asm-ambiguous')]" — 512 also occurs at a non-differing position, so a blind swap could
corrupt it. This is the concrete shape of T3's IMM stratum.
* 7 gate-fail = genuine byte-DIFFs, correctly rejected. Verified to leave NO residue
(all 7: split_file=none, cfg_refs=0) — no false-bank risk.
- HYGIENE: the 7 "git checkout ... did not match any file" errors are benign (revert of a
never-tracked path). Verified 0 untracked splits belong to a non-banked member; 91 new
splits + 3 banked into existing splits = 94.
- SCOPE (P9, unchanged): still n=1 family, and jr is the rarest class (3/163 matched-exemplar
families). This demonstrates the mechanism at family scale; it does NOT give a rate for the
PURE/IMM mass (98% of the population). T3 measures the swing number.
|
||
|
|
a4640e3a51 |
feat(phase-28 T1): B2 LIVES — 8/8 banked; the "families don't template" doctrine was a missing carve
The roadmap's decisive P28/P29 input (h_seq families bank at ~0%) is byte-refuted. Same
family, same era, through the carve path its own exemplar required: 8 of 8 BANKED.
- THE PROBE: jtbl_family_bank.py func_8017BEBC ov_SC01_000 0x8017bebc --raw
.run/phase26-cracks/func_8017BEBC.c over 8 of 115 members (4 same-address + 4
CROSS-address, exercising to_addr) -> {'BANKED': 8}.
R22: make clean && extract-all && check-all -> 140 passed, 0 failed of 140.
- ROOT CAUSE of the P27 0/8, byte-verified: 0x8017BEBC is a jr/switch core. §47 banked its
exemplar as "lazy isolation -> carve (9-piece interleave) -> splice -> BYTE-IDENTICAL" and
called the fix "×N template-safe". family_sweep.hseq_sweep stages C and gates -- it has NO
CARVE STEP -- so gcc's generated jump table is never placed at the sibling's address. The
entire residual is TWO WORDS: classify_member -> PURE, ndiff=2 @ idx 343/345 =
lui/lw %hi/%lo(jtbl_801EC44C). overlays.mk:112 carves ov_SC01_000_jr_8017BEBC.o for the
exemplar; :134 has no such entry for the member. tools/jtbl_family_bank.py exists to do
exactly this per sibling and had NEVER been run on this family.
- THREE COMPOUNDING FAILURES made the doctrine: (1) wrong tool for the class; (2) n=1 on the
LEAST representative family -- has_mid_jr is 3 of 163 matched-exemplar families (120 of
13,232 members) -- generalized to the whole frontier; (3) its corroborating Phase-26 probes
(tiny-IMM 0/241, PURE 0/134, pinned 0/133) ALL predate _carry_macros (P27 T5, commit:0637).
P27's decision-log calls its own re-probe "a FOURTH phantom exhaustion proof" -- naming the
mechanism that would have faked the first three, and never re-running them. The ~0% doctrine
has NO surviving post-fix evidence.
- SCOPE HONESTY (P9): this refutes the EVIDENCE for ~0%; it does NOT establish a general rate.
n=1, and jr is the rarest class by construction. T3 measures the rate over the population
that actually exists: 1418 matched-exemplar families / 21,889 members (PURE 78% / IMM 20% /
STRUCT 1.8% -- note the roadmap sizes its swing number on STRUCT = 1.8% of the input).
- TWO SELF-CORRECTIONS (R14), both mine: (a) the approved plan's "add jtbl_ to symbol_map" was
a WRONG FIX FROM A TRUE DIAGNOSIS -- a compiler-generated switch table is never named in C,
so there is no token to substitute; the fix is PLACEMENT. No symbol_map change was made and
T1 became a run, not a code change. (b) func_8017BEBC.md's header still says "close=2 of 952"
(pre-§47-slider); the .c was updated, the .md was not -- templating from the header's premise
would have produced zeros indistinguishable from a wall.
- DISTILLED IN-SESSION (R30/R16): cookbook §53 (sweep a family with the tool its exemplar
needed: the carve law, the --raw rule, the symbol_map-jtbl trap, and the "before a 0%
retires a lever" three-question test); calibration.md's decisive table REWRITTEN (the ~0%
row marked an artifact, not a rate; the addressable pool tabulated); decision-log R31.
- Carried: the family's remaining 107 members (~101,864 ins, ~0 agent tokens) -> T1b.
|
||
|
|
76db32455c |
feat(phase-28 T0): fix img_path (derive, don't guess) — the SC07 pool was doubly hidden
R35 sequencing: fix the instrument before the probe that scopes the phase.
- family_remap.img_path: DERIVE the payload from config/splat.<bin>.yaml's target_path
(R33 — the file the BUILD reads, so it cannot drift from the bytes) instead of
reconstructing `.../FILE_{nnn}.dir/0.4.dec` from the alias. RAISES on a missing
payload (R32) — the silent None WAS the defect.
Negative control (the fix must change an answer the old tool gave):
ov_SC01_001 -> 0.4.dec UNCHANGED (no regression)
ov_SC07_006 -> None -> .../1.4.dec
resident -> (n/a) -> MAIN.CD.dir/FILE_010.dir/1.1 (free; feeds T5)
ov_SC99_999 -> None -> raises
Downstream: all 233 shared substantial fns between ov_SC07_006 and ov_SC01_001
classify PURE (reloc-only). Under the old tool every one returned LEN = "not
templatable" AND poisoned its family's diff_class to MIXED (family_hseq.py:141-143).
Same bug class as new_overlay.sh's hardcoded 0.4.dec glob (which hid these four
overlays for a month) — left uncorrected in a second tool. Fourth instance of the
project's dominant defect class, sitting directly under the number P28 must measure.
- .run/family_hseq.json regenerated: 134 -> 138 overlays (the 4 P27 SC07 overlays newly
visible); metrics re-baselined 68.9 -> 67.0% instr (now agreeing with the committed
progress.fleet.md); LEN across the whole frontier = 0 (a phantom-LEN from a missing
image is now structurally impossible). Proven consistent against the post-tools-health
sigs by a second run (byte-identical) rather than assuming sig_image is deterministic.
- FINDING — a large, doubly-hidden target pool: 1255 families / 6268 members / 230,612 ins
whose ONLY unmatched members are in the 4 new SC07 overlays (0 elsewhere — a clean
partition), each behind an ALREADY-MATCHED, byte-proven ov_SC01_077 exemplar. Classes
PURE 5575 (89%) / IMM 633 (10%) / STRUCT 60 (1%). Hidden twice: P27's disc audit created
it by onboarding the overlays but never regenerated the map — and had it, img_path would
have classified every member LEN. Corroborated independently by tools-health: the 4 new
overlays are ~97% unmatched (stubs ~2,400, matched ~80) vs ~85% matched for their
siblings. PREDICTION, not a bank — h_seq predicts, the whole-binary gate decides (G3/P9).
-> T3's headline stratum, and a better probe than planned: the exemplar is already
byte-proven, so a failure isolates the templating mechanism with no drafting variable.
- SELF-CORRECTION (R14): the approved plan's own population figures (163 families /
13,232 members) came from the STALE map — my numbers were an instance of the defect this
phase is about. Honest: 1418 matched-exemplar families / 21,889 unmatched members
(PURE 17,024 = 78% / IMM 4,473 = 20% / STRUCT 392 = 1.8% — the roadmap's "register-drift"
swing class stays ~2% of the input, so that framing is unchanged). Legacy pool unchanged
at 163 families (the fix + the 4 overlays are purely additive).
- T3 strata (honest): SC07-only 1255 fam / 6268 mem / 230,612 ins · legacy PURE non-jr
95 / 7993 / 478,379 · legacy IMM 36 / 6644 / 212,707 · legacy MIXED 30 / 968 / 10,462 ·
legacy PURE w/ jr 2 / 16 / 5,088. Total addressable 937,248 ins = 21.7% of all remaining
weight = 7.16pp of fleet instr if it all banked — the prize the roadmap declared dead.
- tools-health GREEN: sigs fresh; corpus(+resident) 0 PHANTOM + 0 TRUNCATED; cdecl;
report(lint + dedup 1840 validated / 0 failed, C1 coverage 227211/227211). No source or
build input touched (analysis tooling + regenerated digests only) -> no byte claim, no
R22 cycle owed. docs/duplicates.cross.md regenerated: overlays 134x -> 138x, h_exact
cross-binary 9366 -> 9484 groups; resident sig now the sig_image one (P27 T10 intent).
|
||
|
|
3b31508a24 |
feat(phase-27): the honest frontier — fix the instruments, audit the disc, dissolve a wall (v1.26.0)
- INSTRUMENTS FIXED: Makefile fail-closed (report's gates were swallowed); one cdecl typedef-strip primitive (was 6 regexes); scanners derived not hand-listed (difficulty/exemplar_miner); the second boundary oracle extended to resident. Each fix CHANGED an answer the old tool hid. - DISC AUDITED HONEST: 4 hidden SC07 overlays onboarded (136->140, code at PAC entry 1) + 39 un-onboarded type-1 code modules found (resident-class, load-address RE pending). The byte-gate is blind to un-onboarded code (R34); game-code TRUE 100% now spans 140 + ~39. Instr 68.9->67.0% (denominator correction, not regression). - PIN-CRASH WALL DISSOLVED: the §42e "cc1 SIGABRTs the sibling TU" wall is the extract_unit macro- drop (sched.c:2725), fixed (T5 _carry_macros); pinned families stage 133/133 clean -> P31 open. - HONEST FRONTIER: worklist --assert-partition (R32, caught 5 stale rows); ledger corruption fixed; calibration.md (the templatability swing: h_exact cores ~xN, h_seq families ~0% -> B2 refuted). - FABLE5 SPRINT: 4 cracks + the SIGABRT, 0 banks, but 3 wall reclassifications + the wall dissolved + ~9 pin-free levers distilled (cookbook §42e/§44 + regalloc/cse_expr §H + decision-log R31). - 140/140 byte-identical (R22), 0 NON_MATCHING (G4), audit gates green + fail-closed. No tools installed. rules R35 (fix the instrument before trusting its measurement). bumps 1.25.0 -> 1.26.0. |
||
|
|
d1ef983af0 |
docs(phase-27 T1 close): func_80176734 crack + distill — the CSE address-fold antidote
The last Fable5 pass of the sprint (Drew capped further waves at 86% context). func_80176734 (371 ins, fresh un-drafted core): NO bank (mine=370 vs 371, 5 permuter-shaped clusters — entry-schedule tie, caller-saved shuffles, a combine-merge missing insn, qty ties), pin-free, honestly handed off (P9; match_one confirms the DIFF). Draft -> decomp-permuter warm-start (P29). Idiom harvest (cookbook cse_expr §H): - THE CSE ADDRESS-FOLD ANTIDOTE (zero asm): find_best_addr's cost-ungated qty-const fold + from_plus re-association eat reg-based global accesses on every cse walk; a balanced if/else DIAMOND makes the merge label barrier-preceded -> fresh cse table -> both folds die with no #APP. Replaced two asm dials. - update_equiv_regs doubles live_length for single-set REG_EQUIV pseudos (local-alloc.c:1064) — a 2nd set forfeits the doubling, ~4x the allocno priority; explains a "my dial broke the $s-order" class. - record_jump_equiv fall-through delete (cse.c:7511) — a recognition tell for genuine dead source logic. T1 sprint COMPLETE: 4 cracks + the SIGABRT characterization, 0 direct banks, but 3 wall reclassifications + 2 cracked roots + the pin-crash wall dissolved + ~9 new pin-free levers. Fable5 DISCOVERS, cheap-Opus APPLIES — the ROI is idioms, not banks (docs/calibration.md). |
||
|
|
ce88baf365 |
feat(phase-27 T9): calibration — the templatability swing measured (structural families are NOT cheap)
docs/calibration.md — the byte-gate-grounded rates that size P28/P29 (roadmap §6 held yield projections until this). - VELOCITY: instr 68.9->67.0% (a T7 denominator re-baselining DOWN, not a regression) + ~0 matches banked (an infrastructure/findings phase). The honest flip-checkpoint read: denominator correction + unblocking findings, NOT 0 progress/session — velocity resumes at P29, re-measure there. - THE TEMPLATABILITY SWING (decisive for P28/P29): h_exact reach-N cores propagate ~xN near-100% (§52: 5 cores -> 670 instances) vs h_seq/h_norm structural families ~0% (0x8017BEBC: 106/112 stage but 0/8 bank, all genuine DIFF). So remaining yield = per-member cracking + mechanical xN for the h_exact cores, NOT "template x120 the 986 families" — B1/B2's cheap-harvest hope is byte-refuted. The 223-stub frontier: 101 reach-134 (xN-able if cracked) + 119 reach-1. - COST/TIER: Fable5 ~230k tok/fn, 0 banks / 5 — ROI is idioms + the pin-crash wall dissolved, not banks (the doctrine held). cheap-Opus is the banking tier; permuter tail exhausted; local-v3 $0/<=15. - HONEST GAP: the headline member-adapt close-rate on register-drift members needs P28's member_adapt tool (chicken-and-egg) -> P28 opens by measuring it on a byte-gated sample, per the risk register. - NEW un-projected fuel: ~20 PINS-class stubs now harvestable (pin-crash dissolved, T5). |
||
|
|
0f68a83cfa |
feat(phase-27 T8): worklist --assert-partition (R32) + honest re-scan + ledger corruption fixed
- worklist --assert-partition: the audit's literal R32 prescription (tooling-audit.md:1173) — enumerate live stubs from corpus.stubs (the invariant, R33), assert the fuel manifest partitions its source overlay's stubs, exactly one row each. Scoped honestly (worklist's universe is ONE overlay ~223 stubs, not the fleet's 53k — a fleet partition is a scope change, not a flag). PROVEN: it caught 5 stale rows (pin-free cores Phase-26 banked, manifest never re-derived) -> FAIL exit 1. - honest re-scan: build_fuel_manifest on the fixed tools + 140 binaries. Giants re-verified reach-138 (was 134 — the SC07 overlays now counted). Partition PASSES 223==223 after refresh. - ledger corruption fixed: func_80178004's 2 false `close=0 "MATCH"` records (a Phase-26-retracted myth — the seed's best was 5 pinned, and a real close=0 whole-binary match BANKS; it is still a stub) -> corrected to the honest close=91 regalloc wall. func_8012E364 already honest (close=23 — the "stale closeness" flag was itself stale). No real duplicate rows (load_best dedups by addr; the uniq hits were func names in where_stuck prose). docs/worklist.md + docs/backlog.md regenerated. - the 1,670-untriaged near-miss triage SCOPED TO P29 (P5d): Phase-21 automation leftovers whose class labels re-derive at harvest, and the pin-crash finding re-buckets the PINS class — an Ultracode fan-out buys low-durable labels; the gate's residue map is the partition + the class summary, done. |
||
|
|
54bdf96218 |
docs(phase-27 T1): distill the Fable5 wave — the pin-crash wall refuted + 3 RC-6 downgrades
The flywheel step (R16/R30): turn the wave-1 + SIGABRT byte-proven findings into cookbook/codegen-map knowledge, in the producing session. The distillation REWRITES wall verdicts, so accuracy is load-bearing. - cookbook §42e-CORRECTION: the "pin-crash wall" (register-pin-heavy families "SIGABRT the sibling TU, ov077-TU-context-specific, NOT ×134-recoverable") is REFUTED. The SIGABRT is real (sched.c:2725 create_reg_dead_note, a sched1 REG_DEAD-note conservation bug) but was TRIGGERED by extract_unit dropping file-scope #define macros (the T5 bug) -> implicit-call GTE ops -> caller-saved pins in the fatal shape. Only 1 of 4 families genuinely crashed; 3 were exit-33 plumbing folded into one crash bucket. Fixed, all 4 stage 133/133 clean. Per-pin predicate recorded. P31's pin route is OPEN. - cookbook §44-Lever-5: the 3 functions it cited as intrinsic (func_8014D820/8016CBC0/801670E4) are each oracle-refuted (2 cracked roots + 1 RC-6-not-S3). Corrected the "NEVER ship pinned, it SIGABRTs" claim per §42e-CORRECTION. - gcc-2.7.2-map/regalloc.md §H: THE reg_renumber-swap oracle (discriminate RC-6 allocation from S3 scheduling in one gdb run — patch reg_renumber at reload entry, swap the contested regs; byte-exact = pure allocation), RC-14 reused-load-temp serialization (the MERGE pole; pin-free, cheap-Opus), RC-15 the density dial across a floor_log2 boundary (subsumes "coalescing knife-edge"), and the local-vs- global allocation tie as a precisely-named honest sub-class. Continues the §F/§G RC-6-downgrade series. - decision-log.md R31: the 3 Phase-27 strategic findings (disc is bigger: 140 + 39 modules; a wall was our tool again; a cheap win is dead) + the through-line — the roadmap's numbers were red-teamed, the tools under them were not, until this phase. func_80176734 (fresh-core wave-2 agent) still running; its findings fold in before the PhaseEnd. |
||
|
|
2bcd1344e3 |
chore(phase-27): preserve the Fable5 wave-1/2 recon (R20) — 112K, not 260M
The Fable5 discovery sprint's irreplaceable output, banked before the distillation (that's the
pending Max task). Each is the product of a ~250k-token Fable5 pass; the bulk beside them (260M of
RTL dumps + bisection .s under pincrash/) is regenerable and stays ignored (R33).
- wave-1 crack recon: func_8014D820 (block-0 cracked pin-free 261->110, "reused-load-temp
serialization" lever), func_801670E4 (RC-6-not-S3 reclassification + the reg_renumber-swap oracle),
func_8016CBC0 (root-A cracked byte-zero, "coalescing knife-edge" refuted, density-dial lever) +
the workhorse variant.
- pin_crash_sigabrt.md + pincrash/{minimal_repro.c, *.gdb}: the §42e pin-crash wall CHARACTERIZED and
REFUTED as a compiler wall — it's the extract_unit macro-drop (fixed in T5); sched.c:2725
create_reg_dead_note abort; pinned families stage 133/133 clean once macros ride along.
All three wave-1 seeds produced oracle-proven reclassifications refuting cookbook §44-Lever-5 wall
names + new pin-free levers (Fable5 discovers, cheap-Opus applies). Distillation -> cookbook is next.
|
||
|
|
ee4b3a02e8 |
feat(phase-27 T5): extract_unit carries file-scope #define macros — honest 0x8017BEBC probe + the pin-crash wall dissolved
family_remap.extract_unit dropped the file-scope function-like #define macros a body references (the gte_* C inline-asm GTE-op macros live ABOVE the function; the backward preamble walk stopped at the first #define/continuation line). A staged sibling saw every GTE op as an implicit-declaration CALL. Two consequences in one bug: - staging failed: 0x8017BEBC's 112 members all CC1-FAIL'd -> a FAKE 0% probe that reads "mechanical harvest dead" when the tool was broken (a 4th phantom exhaustion proof, exactly the 26-A audit class). - the SIGABRT: with a caller-saved register PIN present, the phantom call pushes cc1's sched1 into create_reg_dead_note's abort (sched.c:2725) — the §42e "pin-crash wall". The wave-2 SIGABRT agent proved this IS the cause (.run/giants/pin_crash_sigabrt.md): pinned families stage 133/133 clean once their macros ride along. A propagation wall recorded as a compiler limit for phases = a staging-tool artefact. - _carry_macros: prepend the function-like #define macros the unit body references (file order), not already inside the unit. Safe by construction: feeds only the templating path (remap_hseq), never make_macro's engine_core.h lift (no #define embedded in a DEFINE_func_*() macro); gather_externs only scans func_/D_ so no bogus extern; regression-verified non-GTE exemplars carry 0 macros (a no-op where it should be). THE HONEST PROBE (R14): staging 0 -> 106/112 (6 skip = IMM tier-2). Bounded 8-member gate sample = 0 banked / 8, ALL genuine DIFF (T4 classifier: compiled, wrong bytes — NOT plumbing). 0x8017BEBC is BYTE-PROVEN NOT TEMPLATABLE: the roadmap's "largest cheap win left" (B2) is REFUTED. The h_seq match is necessary, not sufficient. This 0% MEANS something because the tool is fixed first. Carried to T8: harvest the now-unblocked pin families (verify the 133/133 claim + bank). |
||
|
|
427baba3bf |
feat(phase-27 T10): completion dashboard (main in the weighted metric) + the resident second oracle
The metrics contract (roadmap §1) wants all three metrics WITH main in the denominators, and the
second, independent boundary oracle (R34) extended beyond the overlays. Both had landmines.
10a — main into the weighted metric, safely:
- weighted_metrics off the func_-only src_stubs regex onto corpus.stubs (R33). THE LANDMINE IS
REAL: src_stubs("SLUS_007.26") globs src/SLUS_007.26/*.c -> 0 files -> every row "matched" ->
main 100% + fleet % silently inflates. Routing through corpus.stubs is a PROVEN 0.000pp no-op on
the existing fleet (overlays are all func_) and closes the curated-name leak.
- a SEPARATE "MAIN game-code weighted" line (0.7%): main's Ghidra sig excludes the LINKED PsyQ
objects (Ghidra never analysed them), which is exactly right for a game-code metric (LINKED is
complete, counted in fn-count). Reported un-folded and caveated (month-stale sig, PROVISIONAL) —
folding a stale/incomplete value into the decomp.dev headline would mislead the flip checkpoint.
10b — the resident second oracle:
- make sig-resident: sig_image on the resident flat blob (byte-derived, not Ghidra). corpus.
sig_is_independent now covers resident -> audit-corpus checks its boundaries too. Probed clean
BEFORE wiring (144 fns, all 21 stubs present, 0 phantom), verified 0 phantom + 0 truncated.
- sig-overlays now derives its payload list from config/overlays.mk, not a 0.4.dec glob that
silently dropped the 4 SC07 index-1 overlays (the audit's own silent-skip class). tools-health
regenerates sig-overlays + sig-resident first so the audit never crashes on an absent sig.
10c — main's second oracle: docs/second-oracle.md. sig_image can't sign the PS-X EXE yet (0x800
header offset, interleaved data/linked islands, one text range); seeding from splat would destroy
independence for the PHANTOM class specifically. Honest deferral + scoped design, not a fake oracle.
- docs/progress.fleet.md regenerated: 140 binaries · fn-count 82.16% · instr-weighted 67.0%
(the honest post-T7 drop from 68.9%) · distinct 47.8% · MAIN game-code 0.7% (separate).
- SETUP §6.3 updated (R21).
|
||
|
|
264fe6c115 |
feat(phase-27 T7): disc-completeness audit — onboard 4 hidden SC07 overlays (136->140) + the type sweep
The whole-binary byte-gate is structurally blind to code nobody onboarded (R34): check-all is
green over the onboarded set no matter what code sits unbuilt on the disc. This reconciles the
onboarded set against every code-bearing PAC payload.
- new_overlay.sh: optional [ENTRY] arg (default 0.4) reaches a non-0.4.dec payload. Onboarded
ov_SC07_{006,007,010,011} from 1.4.dec (they put graphics at PAC entry 0, the code overlay at
entry 1 — invisible to the 0.4 hardcode for a month). Each byte-identical (7ca772be / b3b95547 /
d7b5875d / 9885af74). FLEET 136 -> 140; check-all 140/140 (T2's pass==N re-baselined cleanly).
difficulty.py NOT in the insertion set anymore (it derives, T6) -> only 3 tool dicts touched.
- tools/disc_code_sweep.py: decode every payload (reusing sig_image.make_insn) and gate code on
BOTH valid>=0.90 AND jr_$ra density>=0.01. The jr_$ra gate is decisive: isValid() alone flags
389 false hits (type-0/2 structured data decodes ~100% valid but has ZERO returns); jr_$ra
separates code (~2.9-3.4%) from data (0.000%), validated on positive+negative controls.
- FINDING (docs/disc-completeness.md): type-4 location overlays are COMPLETE (138/138). All other
types are data EXCEPT type-1 = 40 code payloads, 1 onboarded (the resident), 39 HIDDEN
resident-class modules (mostly MAIN.CD/FILE_XXX/1.1). They load at UNKNOWN addresses (not the
shared overlay slot), so they are NOT mechanically onboardable — byte-verifying a build binary
needs its load address (P9), knowable only by runtime RE (the Phase-3 method). Deferred with
evidence, NOT force-onboarded at a guess.
- CONSEQUENCE: game-code TRUE 100% now spans 140 onboarded binaries PLUS ~39 type-1 modules
pending load-address RE. The roadmap assumed 136 — this is a real re-baselining (the +4 overlays
also add ~2.45 MB to the denominator; every family propagation is now x138). Flows to T10/T11.
- SETUP §6.3 tool inventory updated (R21).
|
||
|
|
8a1a1a0d79 |
feat(phase-27 T6): migrate difficulty + exemplar_miner off hand-lists/proxies (R33) — before T7
The 26-A audit named difficulty's 136-entry BINARIES dict as the exact root cause corpus.py:9 describes (a hand-maintained allowlist over a filesystem that already answers the question), and exemplar_miner's registered_addrs() as a ~60%-wrong proxy for "is this still work?". T7 onboards new overlays, so these are migrated FIRST or the new binaries silently miss make report. - exemplar_miner.py: "still a residual?" now = corpus.stubs(source) membership (the INCLUDE_ASM invariant, R33), not dp.registered_addrs() (config/dedup.us.yaml — a matched-but-unregistered fn, e.g. banked inline or matched-but-local, stayed wrongly in the residual pool). - difficulty.py: the 136-entry hand-dict -> cfg_for(alias), deriving the mechanical layout (src/<a> + asm/<a>/nonmatchings; main/resident the two specials). Validated against the tree (src/<a> must exist -> a typo is a clean error, R32), not a hand-list. A newly-onboarded overlay now needs zero difficulty registration. - new_overlay.sh: DROPPED difficulty from the sentinel-insertion set (T6 made it obsolete; leaving it would insert a dead dict entry into a file that no longer has a dict). The other 3 tools (diff_settings/progress/dup_report) keep their hand-lists — migrated one-at-a-time, byte-gated, per the audit's cadence; NOT dup_report.BINARIES, which corpus depends on as the binary list. VERIFIED: - difficulty derivation is BYTE-EXACT vs the old dict for all 136 aliases (0 mismatches), and old-tool vs new-tool output is byte-identical (.md AND .csv) on the same tree — the diff vs the committed docs was pure staleness (committed 2026-06-20, tree at 2026-07-15), NOT my change (R14). - unknown alias -> clean error, not silent-empty output. - exemplar_miner runs -> 223 residual stubs (corrected; it's a manual tool, not in make report). - new_overlay.sh: bash + embedded-python both parse; difficulty absent from the insertion set. |
||
|
|
e0a0becfaa |
feat(phase-27 T4): one cdecl typedef-strip primitive (was six regexes) + surface cc1 stderr
The plan named two defective regexes; the tree had SIX with complementary holes, each silently recording the resulting compile failure as "not a match" — a plumbing error wearing a compiler wall's clothes, the exact class the 26-A audit exists to end (R32). - cdecl.py: the canonical primitive — typedef_names(tu_path) + strip_provided_typedefs (draft, provided). Built on tu_statements (robust) NOT tu_scope (which coverage-asserts -> would crash the byte-gate on any unrelated unparseable file-scope statement). Splits multi-typedef lines (split_statements, depth-aware); covers scalar AND struct typedefs; keeps draft-local types. lru_cached. - harvest_verify.py: strips PER-TU (cdecl.typedef_names of the draft's real target TU) -> unblocks the 39 struct-typedef drafts the scalar-only _TD dropped. And SURFACES cc1 stderr: build() stashes it; a single-draft failure is classified DIFF / PLUMBING:… / CC1-FAIL / SKIP -> .run/harvest_failed.classified.txt. A `redefinition` is no longer recorded byte-identically to a codegen miss. - masked_diff.py: strip_scalar_typedefs() (common.h set derived from the header once, R33, cached) replaces SCALAR_TYPEDEF_RE.sub for the ISOLATED compile; wired into match_one + p16_permute. Fixes the multi-typedef-LINE skip that discarded 42 masked-MATCH drafts over whitespace. Unblocks B4's func_8015C32C (redefinition of 's16'). - canon_sig_reconcile / eval_lora / format_finetune keep their own copies — migrate per-bank, byte-gated (the audit-prescribed cadence, not a big-bang swap). VERIFIED: - HEADLINE known-answer: func_8015C030 -> MATCH (23 ins) UNEDITED via match_one (was CC1-FAIL; the multi-line typedef split alone fixes it — a live x134-family draft that was being discarded over whitespace). - unit: 7/7 scalars stripped; a local struct KEPT; a TU-provided Blk16 stripped. - classifier unit: DIFF / PLUMBING:… / CC1-FAIL / SKIP all label correctly. - all 5 edited tools import + AST-parse clean. - R22 clean-fleet: check-all 136/136; main clean-rebuild 143dbb89. (A mid-test c4546248 "mismatch" was a stale-incremental artifact from concurrent compiles, cleared by a clean rebuild — the R22 lesson; edits touch only tools/, src/ stayed git-clean.) - SAFETY: a strip bug can only fail-to-bank, never falsely bank (INCLUDE_ASM pastes the original asm; a wrong draft always changes bytes -> always fails SHA1). |
||
|
|
ebdef9012b |
feat(phase-27 T2): make the Makefile fail-closed — the enabling fix for every downstream gate
The roadmap §5 asserted `make report` is fail-closed. It was NOT: .ONESHELL sends each whole recipe to one `bash -c`, so with no -e only the LAST command's exit survives and every earlier failure is swallowed. `dedup-check` "gated" purely by being last; lint_symbol_refs / progress --audit / difficulty / dup_report were non-gates. That is the 26-A audit's own thesis (a loud failure nobody counts is as invisible as a silent one) biting the audit's infrastructure — and until it's fixed, any R32 assertion added to a report-invoked tool is swallowed on arrival. - .SHELLFLAGS := -ec (global fail-closed). ONE documented opt-out: check-env (set +e — its contract is accumulate-every-failure-and-report, which -e would truncate at the first missing tool). - check-all:610 grep -c landmine fixed (|| true): grep -c exits 1 on zero matches, which -e treats as fatal in a command substitution -> check-all would FAIL exactly when nothing did. - check-all / extract-all: assert COVERAGE (pass == N), not the absence of a failure marker. The old `fail == 0` / `! grep -q` form was a VACUOUS PASS on an empty pipeline (R32). - new `make tools-health` = audit-corpus + audit-cdecl + report, fail-closed — the deliberate pre-matching ritual the roadmap's standing invariant names, and the dependent the two derived oracles never had (nothing invoked them). NOT a report/build prereq — audit-cdecl cross-compiles every C decl through gcc (~minutes). SETUP §6.3 documents it (R21). VERIFIED: - NEGATIVE CONTROL (the proof): a broken lint_symbol_refs makes `make report` exit 0 under the old .SHELLFLAGS=-c and exit 2 under -ec. The swallow was real, not theoretical. - the grep -c landmine + the vacuous-pass both reproduced and fixed in isolation. - check-env still exits 0 (the opt-out works); recipe sweep found the Makefile already -e-aware (set -o pipefail, explicit || true) — line 610 was the only real hazard. - R22 clean-fleet: make check-all -> 136/136 byte-identical; a forced main re-extract+rebuild drove the full splat->cpp->cc1->maspsx->as->ld->objcopy->check pipeline under -e -> 143dbb89. - audit-corpus 7s / audit-cdecl green / tools-health wired. |
||
|
|
6e99157bcf |
chore(phase-27 T3 addendum): widen the .run/giants allowlist — cookbook §45 cited untracked files
Found while reading the seeds for T1: cookbook §45 names
.run/giants/func_80133CD4.fable.c as its worked example and .run/giants/fable_cd4/
as the flagship's gdb oracle — BOTH were untracked. The docs cite artifacts that
were not in the repo.
- .gitignore: widen by FILE TYPE, not directory — .run/giants/*.{c,md,sh} +
fable_cd4/*.{c,md,sh,gdb,txt}. +49 files / 460K.
- Now preserved: the flagship func_80133CD4 crack + its gdb oracle (§45's cited
worked example); the byte-verified pf*.c regression ladder (the seeds' own
Method/reproducibility section cites it: pf2 78, pf_c2 30, pf_d1 35, pf_h1 280);
the dump.sh/mon*.sh RTL harnesses; the banked giants' drafts (80135480, 80163EC8,
80166994).
- Still ignored (regenerable via dump.sh, R33): d_pf*.i.*, *.s, dumps_m*/, and the
ILS/permuter .log files. Negative control re-verified: all 5 probes IGNORED, no
db.*.gbf staged (R23).
Lesson (R31 candidate): a doc that cites a path is an untested claim about the repo.
The §45 citation and its file were 4 days out of sync; only reading the seed for an
unrelated reason caught it. Candidate lint: cookbook path citations must resolve to
tracked files.
|
||
|
|
2351c43e66 |
chore(phase-27 T3): preserve the irreplaceable .run/ recon (R20) — 2.2M, not 12.3M
Pulled ahead of T1: the Fable5 sprint's agents work inside .run/, and its Phase-25
seed recons were untracked — an agent overwriting .run/giants/*.opus.c would have
destroyed irreplaceable input. 5 minutes to remove that risk.
- .gitignore: /.run/ -> contents-exclude form (/.run/* + ! exceptions), following the
/tools/bin/*.sha256 precedent. Resolves R20 (commit irreplaceable RE work) vs R12
(.run/ is scratch) by splitting the directory on the real axis: what a rerun CANNOT
reproduce.
- PRESERVED (~2.2M / 31 files): the 6 Phase-25 *.opus.{c,md} giant seed recons (49K);
the func_80178004 gdb-on-cc1 harness + ORACLE_PROOF.md + the v00-v07 draft ladder +
the sched/combine .lst evidence (~110K — the distilled output of a 477k-token Fable5
pass, and the method §52 lever 6 depends on); backlog.jsonl (1.9M) + fuel_manifest.json.
- STILL IGNORED (regenerable, R33): dumps_v00..v07/ and d_pf*.i.* gcc RTL scratch —
12.3M reproducible via runorc.sh + the .gdb scripts; the MCP log; draft scratch.
The plan said "track the dirs"; the bytes said the dirs are 96% regenerable.
- VERIFIED both directions: git add --dry-run stages exactly the 30 intended files and
0 bulk; negative control — ghidra-mcp.log / dumps_v00 / d_pf.i.sched / d_pf.s all
still IGNORED. No db.*.gbf staged (R23 restart-noise).
|
||
|
|
002f6d7c7b |
chore(phase-27 T0): Phase Start — plan approved (gate 1) + the P27 verification corrections
- CURRENT_PHASE.md: the approved plan (11 tasks, effort-annotated per R7), the
Planning-verification section, blockers, and the Task-0 log entry
- harness task list built before work (R28); deps enforced T6->T7, T2->T8,
T2+T7->T10, T5->T9, all->T11
VERIFICATION (R14 at planning scale — the roadmap's own §0 mandate): 3 read-only
agents checked every P27 premise against the repo. ~28 specifics corrected. The
three that reshaped the plan:
- the 0x8017BEBC probe ("possibly the largest cheap win left") would fail 112/112
today on a TOOLING defect — extract_unit drops the 8 file-scope gte_* macros the
banked exemplar needs; 0 of 112 member TUs define them. It would have been logged
as a 4th 0% exhaustion probe: the 26-A audit's thesis, about to recur.
- `make report` is NOT fail-closed (roadmap §5 asserts it is): .ONESHELL + no -e in
.SHELLFLAGS => only the last command's exit survives; lint_symbol_refs/progress
--audit/difficulty/dup_report are swallowed. check-all/extract-all assert fail==0,
not pass==N => an empty pipeline is a vacuous pass.
- 4 code-bearing SC07 payloads (~2.45 MB, 98.0% plausible-opcode) are invisible to
every tool: they sit at PAC entry index 1 while new_overlay.sh hardcodes 0.4.dec.
Zero mentions in docs/ or config/.
DROPPED with reasons: 0x8013C414 (x134 contested by an explicit verified_reach:1;
already drafted) · func_801549F8 (from the SUPERSEDED megaplan; Phase 26 walled it
17/31 and wrote "do NOT hand-grind it"; inside the 0/958 re-gate) · func_8012E364
(the "stale closeness" label is itself stale — close=23) · jtbl_carve "fix first,
load-bearing for B5" (the audit measured it twice: 0 of 5043 jtbl ends differ).
B4 dissolves into T4 — its remedy already ran (A9b, 1/7) and the 1 is banked.
Owner decisions (Drew, 2026-07-15): curated .run/ preservation (R20 vs .gitignore —
every Fable5-sprint input is currently untracked) · full disc audit incl. the
type-sweep, accepting the denominator expansion · Fable5 in 2 waves, distill between.
|
||
|
|
6344a2c424 |
docs(roadmap): adopt the Road-to-100 endgame roadmap (Phase 27+) — supersedes the family-endgame megaplan
- docs/roadmap-to-100.md: the adopted P27-P32 roadmap to game-code TRUE 100% + public flip + Gen2 exit. Contract (Drew 2026-07-15): true 100% (walls re-attacked until they fall), PsyQ LINKED = complete (libs-from-source = far-future note), flip AT 100% (standing per-phase velocity checkpoint keeps the timing falsifiable), Fable5 window ~7/19 (P27 discovery sprint runs FIRST). Measured baseline from committed post-audit artifacts only; residue buckets B1-B12 incl. the never-probed 0x8017BEBC IMM family (~106k ins) and the main/resident second-oracle gap; foreseen-tooling table (member_adapt, gate farm, fleet Ghidra-C prefetch, diff_regions, cc1_probe, assert-partition); authority rules (docs-layer advisory; every PhaseEnd carries a 'Roadmap delta' line; constitution + latest PhaseEnd win) - docs/decision-log.md (R31): the adoption entry — Drew's four contract decisions, the flip-timing tension + checkpoint, the 16-defect red-team pass that purged numbers carried past their invalidation events (R14 at planning scale) - docs/family-endgame-megaplan.md: SUPERSEDED banner (content preserved; h_seq reframe survives, the templating thesis is byte-proven spent per PhaseEnd_Phase26) - memory: roadmap-to-100 pointer added; structural-family-mechanical-remap corrected with the Phase-26 probe results (outside the repo tree) - Phase 27 NOT started (fresh session, plan mode, per the constitution) |
||
|
|
1bbab78c65 |
feat(phase-26): close — family engine + the tooling-integrity audit + the §52 discovery-flywheel; mechanical harvest byte-proven exhausted; fleet 58.2->68.9% instr (v1.25.0)
- FAMILY ENGINE (Tasks 1-6): family_remap (extended reloc tracker + single-pass subst) + family_hseq (the h_seq reframe) + family_sweep (crack-one -> template-x134 -> byte-gate) + canon_sig_reconcile v3.2 + rtu_match. Sessions 6-8 cracked 13 cores (58.2->66.5% instr). - 26-A TOOLING-INTEGRITY AUDIT (inserted half-phase, A0-A11): the tools WERE several of the walls. Fixed ~15; DELETED decaying scanners (R33); built corpus.py + cdecl.py (derived, coverage-asserted oracles) + make audit-corpus (a SECOND, disagreeing oracle, R34); the listCdBuffer 193-slice corpus defect -> 0; masked_diff 150 closeness-lies -> 4; the stale- object false-pass closed. Payoff 66.5->68.6% instr. docs/tooling-audit.md AUDIT-CLOSE LEDGER. - 52 DISCOVERY-FLYWHEEL (Task 7): single Fable5 on func_80178004 = intrinsic 3-integer regalloc wall, BUT distilled the walker-family idiom (52); two cheap-Opus waves applied it -> 5 pin-free cores banked x134 = 670 instances (68.6->68.9%). 4 named wall classes; 52/52a/52b. pin-guard comment false-positive fixed; family_sweep --allow-pins. - FINDING (R14/P9, 3 probes 0%): the matched-sib mechanical harvest is EXHAUSTED; the manifest's ~13k "templatable" members are an h_seq prediction the byte-gate refuses. Phase-26's templating thesis is spent -> close, open Phase 27 with byte-gate-honest re-scans. - R22 clean-fleet 136/136 BYTE-IDENTICAL throughout; dedup 1840/0; 0 NON_MATCHING (G4). - rules R32 (coverage assertion) / R33 (derive, don't re-derive) / R34 (a second, disagreeing oracle). worklog -> phase-ends/logs/Phase26.md (R19). bumps 1.24.0 -> 1.25.0. |
||
|
|
d40711fe5f |
chore(phase-26 T7): family_sweep --allow-pins flag + honest matched-sib finding
- family_sweep: --allow-pins bypasses the §42e pinned-exemplar skip (template WITH pins, byte-gate arbitrates) — added to TEST the func_8017A4AC pinned-×134 precedent. - FINDING (3 probes, all 0% banked): the matched-sib harvest is TAPPED. tiny-IMM 0/241, PURE reach-134 0/134, pinned-PURE-with-pins 0/133. The manifest's ~13,075 'templatable' member-slots are an over-prediction the whole-binary byte-gate refuses (collision/drift/ pin-crash). A3h + the wave propagations already banked everything cleanly templatable. - regenerated family-hseq.md. |
||
|
|
ed09ee749f |
feat(phase-26 T7): §52 sibling wave 2 — 3 more cores banked ×134 (402 instances)
Second cheap-Opus §52 wave over the close=0 regalloc cluster (armed with §52a):
- BANKED ×134: func_801379FC (97), func_801497A8 (47), func_801495C4 (34) —
3 exemplars + 399 members = 402 function-instances, 0 gate failures.
- 2 whole-binary-near (func_8012E138, func_8012F40C — match_one MATCH, A10 gap),
1 new wall (func_8012B4B8 — symbol-address-base wins-low-needs-high, a 3rd class).
- §52b: new verified de-pin levers (per-loop pseudos for register role-swap; the
RC-7 second-set dial to defeat rematerialization; value-barriers dissolve the
CSE-stack-address-common wall) + the new wall class + the match_one→whole-binary
gap-at-scale finding.
- TOOL FIX: family_sweep §42e pin-guard was a FALSE POSITIVE — it matched
'__asm__("$N")' inside COMMENTS that document a REMOVED pin (recovered
func_801495C4's 133 members). Now strips comments before the pin check.
- R22 clean-fleet 136/136 BYTE-IDENTICAL; dedup 1840/0.
- Wave 1+2 combined: 5 pin-free cracks -> 670 instances, from the walled flagship's idiom.
|
||
|
|
06e43873e9 |
feat(phase-26 T7): §52 regalloc sibling wave — 2 cores banked ×134 (268 instances)
The Fable5 walker-family idiom (§52, from the func_80178004 wall) applied by a 6-agent cheap-Opus wave over the regalloc-order reach-134 cluster: - BANKED ×134: func_80171FFC (40 ins), func_801775E0 (67 ins) — 2 exemplars + 266 members = 268 function-instances, 0 gate failures (family_sweep byte-gate). - 4 precisely-characterized walls (P9), each yielding a byte-verified lever: func_80167714 (whole-binary near), func_80177AD4 (non-coalescing delay-slot copy), func_80169228 (NEW caller-saved priority-first-fit wall), func_80131A34 (save-order/ load-hoist tension; new const-unchanging-load lever). - §52a: the wave's new banking levers (pass-real-args/RC-10, store-base-both-arms, copy-chain-direction, pp-decl-schedule, const-unchanging-load/RC-3) + the two new intrinsic-wall classes. Fable5 DISCOVERS, cheap-Opus APPLIES. - fn-count 84.27→84.35% (+268), instr-weighted 68.6→68.7% (+14,338 ins), distinct +2. - R22 clean-fleet 136/136 BYTE-IDENTICAL; dedup 1840/0. |
||
|
|
8f3e4a12ba |
docs(phase-26): T7 re-baseline + §52 walker-family regalloc idiom (func_80178004 wall)
- re-baseline the target frontier from the fixed tools (R14): 228 ov077 stubs (broken manifest saw 30); worklist/family-hseq regenerated. 68.6% instr / 49.2% distinct. - R14 corrections to the audit handoff: the '~1,200 type-heavy' was already banked by A3h (+2,675); the real remaining lever is 128 matched-sib families (~2.64M templ ins), and register pins are NOT a banking blocker (func_8017A4AC banked ×134 with pins). - Task 7 is near-miss CLOSING (close 1-5 re-gate = 0/13 through the fixed pipeline), not fresh crack. - §52: single Fable5 on func_80178004 (regalloc-order class exemplar) = honest wall (P9), structure-exact 163/165, residual = 3 compiler-internal register-alloc integers, likely intrinsic; byte-verified 126/165. Correction: the 'pinned MATCH' was a myth (never matched). 6 byte-proven walker-family levers + the skeleton idiom transfer to the 11 regalloc-order siblings (Fable5 discovers, cheap-Opus applies). decision-log entry (R31). |
||
|
|
a33c6f85f5 |
docs(phase-26a): A11 — distill + close the tooling-integrity audit (26-A COMPLETE)
Closed the inserted half-phase. tooling-audit.md: DIAGNOSIS -> AUDIT-CLOSE LEDGER (A1-A10 outcomes + the payoff 66.5->68.6% instr + remaining/handoff); the "two rules" -> R32/R33/R34 crisp for P10 ratification at the Phase-26 PhaseEnd. decision-log: the A10 wall-re-test verdict (R31 -- the broken tools WERE the walls; the payoff was banked by the fixes; the closeness-0 residual is genuine; the real deliverable is the 3 rules + the derived-oracle pattern). SETUP: the A9d-A10 tool changes (R21). Cookbook §51 verified complete; LAW 3 tagged R34. Observables green: final R22 clean-fleet 136/136 BYTE-IDENTICAL; make report EXIT 0 (dedup 1840/0, C1 227211/227211 signed, lint_symbol_refs wired + passing); audit-corpus 0 slices; audit-cdecl green. Zero src/config changes this session. Phase 26 resumes at Task 7 (fresh session). |
||
|
|
e9038a04ea |
docs(phase-26a): A10 COMPLETE — wall re-test verdict on all 5 walls
The audit thesis is CONFIRMED: the tooling-walls were dissolved by the FIXES and the payoff banked there (A3f/g/h + A9a/b, 66.5->68.6% instr), while the re-tests confirm the residual walls are real. - fuel/closeness-0: CONFIRMED REAL (0/958 bank at fleet scale). - arity (Phase-15 dead-end): was tooling (A3c order-dependent rule); 13/18 banked. - def-side loose-typing: was partly tooling; A9b banked func_8017A4AC x134. - type-heavy: blocking tool build_engine_types was broken (A7 fixed it, now runs); the ~1,200-member family harvest is Task-8 integration, not a pure re-test. - 780 h_seq callee-oracle rejections: was tooling; A3h banked +2,675. A re-confirmed wall is as valuable as a dissolved one (P9). Next: A11 close. |
||
|
|
b1c58d7668 |
docs(phase-26a): A10 wave 1 — closeness-0 wall re-test CONFIRMED REAL (0/958 bank)
Re-gated all 958 closeness-0 open-stub backlog drafts through the FIXED gate across 135 binaries in parallel: banked=0, near=957, failed=71. The closeness-0 backlog is genuine whole-binary near-misses, NOT tooling misses -- match_one's isolated closeness==0 systematically overstates whole-binary bankability, and the repaired gate recovers none. P9: a re-confirmed wall is as valuable as a dissolved one. (The audit's tooling-walls were already banked by A3f/g/h + A9b, +2.1% instr.) backlog.py: env-gated BACKLOG_NO_RENDER so parallel workers skip the render race (append is atomic) -- backward-compatible parallel-safety. backlog.md refreshed with the re-test's whole-binary-informed scores. |
||
|
|
f2b2a9d778 |
docs(phase-26a): A10 Max-phase — wall re-test scoping + arity measurement (fan-out pending R27)
Scoped the 5 walls. The audit fixes already dissolved the easy wall (A3f/g/h + A9b, 66.5->68.6% instr). Remaining re-test pool = 2,218 open-stub backlog drafts (958 at closeness 0). #2 arity: 13/18 Phase-15 arity-conflict fns already banked (wall largely fell). Confirmed the remaining re-test is breadth (serial gate_stage timed out). R27 boundary reached: prompting Drew for /effort ultracode before the parallel re-gate fan-out. Tree clean (HEAD commit:0618 before this). |
||
|
|
ea20bdf9f3 |
fix(phase-26a): A9g — jr_inventory: retire the ephemeral roster, derive banked from the image (R33)
jr_inventory's `banked` set was filtered by an EPHEMERAL, gitignored .run/banked_func_*.json roster: a `rm -rf .run` / fresh clone would blind ALL banked jr at once, cross-address siblings (roster named after the exemplar) were structurally invisible, and non-leader banked jr were missed. "The purest R33 case in the group" (audit). FIX (the audit's exact prescription): delete the roster glob + `cand` filter; `banked` is DERIVED FROM THE IMAGE — a real-C def/define fn is a banked jr iff family_remap.reloc_targets shows it references a committed .rodata carve offset (config + image, both durable; cross-address- and non-leader-immune). R32 assertion: every committed carve must resolve to EXACTLY ONE owner or abort (a stranded/duplicated carve is the §8b func_801734BC incident, never silent). Also fixed the adjacent finding: the asm_jr scan's func_-fullmatch dropped the curated-name listCdBuffer jr; now resolved via oss.addr_of(). (The --only path's own fullmatch is left — it parses user input, not the corpus.) Perf: read the overlay image ONCE and pass it to reloc_targets(..., data=) — a new backward-compatible param on family_remap (regression: 0/80 mismatch vs the re-read path). Verified: data-param behavior-identical; the R33 win — ov_SC02_000 now finds the cross-address sibling func_8017FCB0 the roster missed; full-fleet parallel run = 134/134 OK, 0 false aborts, 1336 banked jr == 1336 carves -> 1:1 ownership holds fleet-wide. Byte-safe: jr_isolate_all is not in the make build/extract path (R22-neutral); the change makes future isolations strictly more correct. |
||
|
|
96e025a324 |
fix(phase-26a): A9f — overlay_src_split swallowed 2 real definitions; the selftest was blind
scan_construct's force_decl latched from the FIRST token and returned at the
first depth-0 `;`, so a definition sharing a physical line with leading externs
(`extern A; extern B; void f(){...}`) was never anchored — absorbed into the
next anchor's preamble. The parser jr_isolate_all rewrites source from was short
two functions in the exemplar overlay. The round-trip selftest is a SERIALISATION
check (a miss lands in a preamble -> round-trip still exact BY CONSTRUCTION), so
it was structurally incapable of seeing this.
FIX (byte-safe): force_decl no longer survives a same-line `;` with trailing
code — re-classify from the remainder and keep scanning so the def anchors (its
leading externs stay in its whole-line item text -> round-trip byte-identical).
Rejected the audit's "split into 3 constructs": round-trip joins whole-line
chunks with `\n`, so sub-line splitting would insert a newline where a space was.
def_name now names the LAST top-level header before `{` (the definition, not the
first same-line extern; byte-identical on every single-def construct).
R32: hidden_definitions() coverage oracle wired into selftest — an independent
detector of `func_XXXX(...){` bodies not anchored. The selftest is now a coverage
check, not just serialisation.
Verified: 2 swallowed -> 0; regression over 1738 overlay .c = 0 round-trip fails,
0 non-monotonic, 0 non-additive changes, +2 anchored defs. Byte-safe: tool not in
the build path (R22-neutral); ov_SC01_077 rebuilds d19c9580; neither def straddles
a committed subseg boundary. Audit ledger line refs were stale (src rewritten);
real cases are ov_SC01_077_after.c:2020 + ov_SC01_077_jr_8015444C.c:1495.
|
||
|
|
68d29ba8af |
fix(phase-26a): A9e — reconcile_tu already wired into bank_exemplar (A3d); document the ladder
NULL RESULT (P9/R14): the session-12 "wire reconcile_tu into bank_exemplar"
handoff item was stale — A3d (commit:0601) already wired reconcile_tu into
jtbl_family_bank.recover() ("on BOTH banking paths"), and bank_exemplar's
`recovered` stage delegates to fb.recover = cast_call_sites + reconcile_tu.
Proven working by A9b (func_8017A4AC banked at the recovered stage, reconcile_tu
resolving its struct + fn-ptr conflicts). No live tool references the RETIRED
reconcile_decls (only docstrings + the audit-cdecl differential harness).
No code change warranted. Byte-neutral hardening only: document the
raw/scoped/recovered/reconciled fallback-ladder composition inline in
bank_exemplar so a future session does not re-run this "is it wired?" trace.
|
||
|
|
40477281ce |
fix(phase-26a): A9d — retire the dead Phase-17 canonical-sig chain (R33)
DELETE tools/census_conflict_callees.py + tools/derive_canonical_sigs.py. - census_conflict_callees: audit-CONFIRMED marked-for-deletion (commit:0593; decision-log 836). It re-derives from C text the per-TU "defined/declared/ stubbed/external?" question that reconcile_tu (Phase 26) answers FROM THE BUILD — and does it WRONG in the unsafe direction (unknown -> conflict-free). - derive_canonical_sigs (census's ONLY consumer): genuinely dead — last touched Phase-17 (commit:0140), output .run/canonical_sigs.json read by nothing (no Makefile/workflow/import), no-ops on the 2-byte [] input, asm-arity heuristic 36% wrong vs byte-exact banked C. Its purpose was retired in A3d (fleet-majority oracle -> reconcile_tu's per-TU oracle). Deleting census orphans it, so the whole dead chain ceases to exist (R33: the best outcome is a DELETED SCANNER, not a fixed regex). Byte-neutral by construction (neither tool is in any build/report path): module-import smoke over the 13 importable harvest/bank/report/reconcile tools = all clean; bank_exemplar is a run-only script (indexes sys.argv at module scope), imports neither deleted module. No src/config change -> no byte moves. Doc-pointer hygiene: hand-matching-process.md 8a, matching-cookbook.md (canonical-sig-layer entry), tooling-audit.md (ledger row + derive entry) all annotated DELETED/historical so nothing points at a nonexistent tool. |
||
|
|
181191b6af | docs(phase-26a): log A9c (lint_symbol_refs green + wired into make report) | ||
|
|
d7d2613ae6 |
fix(phase-26a): A9c — lint_symbol_refs green + wired into make report
The ONLY detector for the R22 rename-drift failure mode (a symbols.us.txt rename leaves a func_<ADDR> ref dangling in committed src; a clean rebuild fails, an incremental build masks it with a stale .o — undetected Phase 21→23). It was RED (262 false positives) and UNWIRED. The audit's 3 blind spots, all fixed: #1 globbed src/**/*.c only -> now ALSO scans src/shared/*.h, where engine_core.h's 10k+ func_/D_ tokens live and one dangling ref breaks EVERY clean build at once (negative-control-proven: an injected bare ref in a shared header IS flagged). #2 read 2 of 138 symbol files -> now reads every REAL stacked file (config/symbols*.txt), and correctly EXCLUDES the R13 proto files (never stacked into a build; would invent phantoms). #3 no __asm__("label") model -> ALL 262 false positives were this class: engine_core.h binds func_8005C324 to memcpy via `... __asm__("memcpy")`, so the ref emits the LABEL and resolves at link regardless of the rename. asm_labeled_addrs() now recognizes it. VERIFIED: green on HEAD (exit 0); negative control (inject a bare func_800d1bd8 -> DsMix in a shared header) FLAGS it (exit 1) then clears on removal — detection intact, not trivially green. Wired as a fail-closed gate in `make report` (make -n confirms), beside dedup_integrate --check. No src/build change (report-time integrity gate) -> the byte-identical build is unaffected. |
||
|
|
49004f5b06 | docs(phase-26a): log A9a (canon_sig_reconcile fn-ptr fix) + A9b (func_8017A4AC ×134 wall re-test) | ||
|
|
3509acf4b7 |
feat(phase-26a): A9b — func_8017A4AC banked ×134 (536-ins giant, wall re-test payoff)
The A10 re-test payoff. func_8017A4AC (536 ins, reach-134) — "blocked on plumbing" since session 8 — banks now that the audit repaired the recover path (A3d reconcile_tu / A3e gate). jtbl_family_bank --raw swept all 133 siblings (per-sibling isolate → jtbl carve → remap_hseq + canon_sig_reconcile → whole-binary gate): 133/133 BANKED, 0 failed. 0 still-stub overlays. R22 CLEAN-FLEET (make clean + extract-all + check-all): 136 passed, 0 failed of 136. dedup-check 1840/0 (jtbl sweep banks are per-overlay src, not registry). DELTA: instr-weighted 68.1% -> 68.6% (+0.5%, ~71,824 shipped .text instructions) distinct-code 48.0% -> 49.2% (+1.2% — the siblings are per-location byte-variants) The audit thesis, demonstrated: a giant "wall" that stood for many phases was our TOOLING (the recover path could not resolve its struct/fn-ptr conflicts), not an intrinsic compiler residual. Once the oracle was fixed, the wall dissolved and banked ×134. |
||
|
|
97d86fae69 |
feat(phase-26a): A9b — bank func_8017A4AC exemplar ×1 (wall re-test payoff)
The 536-ins reach-134 giant listed "blocked on plumbing" since session 8. Re-tested through bank_exemplar after the audit's recover-path fixes (A3d reconcile_tu wiring / A3e gate): BANKED at the `recovered` stage (fb.recover / reconcile_tu resolves the D_80126B58 struct + D_801DA75C fn-ptr conflicts the raw/scoped stages hit). Lazy-isolated into its own jr subseg + jtbl carve. HONEST ATTRIBUTION (R14): this bank is the payoff of the A3 recover path, NOT A9a — it banked at `recovered`, before the `reconciled` (canon_sig_reconcile) stage was reached. A9a's fn-ptr classifier fix is a correctness fix that did NOT independently unblock a bank in the 7-candidate re-test (the reconciled stage failed on func_8015B950's func-conflicts; the rest hit K&R / scalar-typedef / non-ov077 / non-contiguous-carve blockers) — the same null-immediate-banking pattern as A3c/A3d/A3e; its value is protecting all future dispatch-table banking. R22 clean-fleet: 136 passed, 0 failed of 136. Exemplar ×1 (+536 ins); the ×134 family sweep follows. |
||
|
|
abbedcee8b |
fix(phase-26a): A9a — canon_sig_reconcile sees fn-ptr dispatch tables (cdecl supplement)
The def-side-wall recovery tool, live on the ×134 economic-engine paths (jtbl_family_bank,
family_sweep --reconcile-raw, bank_exemplar, t7_bank, scope_data_externs, family_remap). The
audit's two HIGH findings: its tu_ambient/visible_above classifier regexes and _reconcile_data's
_DATA_EXTERN_RE have a type class `[\w \*]` that cannot hold a `(`, so they are 100% blind to
fn-ptr DATA decls — `extern void (*D_x[])(void);`, the per-overlay jump-table DISPATCH arrays
jtbl_family_bank exists to bank. A fn-ptr symbol thus landed in NO bucket, fell out of `visible`,
and _reconcile_data block-moved the draft's extern into a guaranteed `conflicting types`.
FIX (R33-adjacent, but SUPPLEMENT not wholesale-replace — the proven regex stays byte-identical):
- tu_ambient / visible_above: keep the v3.2 regex classification UNCHANGED, then supplement from
cdecl.tu_scope with ONLY the fn-ptr symbols the regex drops (_fnptr_data). A full delegation was
tried and rejected — cdecl normalizes funcs formatting (void*→void *, param names, and a real
return-ptr hazard u8*→u8) which rippled 728k value-changes into the callee string-compare; the
audit flagged fn-ptr DATA, not funcs, so the blast radius is held to exactly that.
- _reconcile_data: a fn-ptr pre-pass (_FNPTR_DATA_RE) — visible ⇒ STRIP (ambient serves; a
call-through `D_x[i]()` is decl-INDEPENDENT indirect codegen, so NO access-cast: casting a
fn-ptr would mangle it into `((u8*)D_x)[i]()`, the dormant transform reconcile_tu documents);
not visible ⇒ block-move verbatim. Plus the F2 fix (bail on a `(` in the CODE, not a comment).
- R32 coverage assertion: a fn-ptr data extern may never survive the pass.
PROVEN ADDITIVE (regression baseline .run/audit/a9a_*):
- classifier snapshot over 1683 TUs: REGRESSIONS 0, ADDITIONS 69,798 (all data fn-ptr).
- reconcile() OLD-vs-NEW over 434 real drafts against home TUs: 0 regressions.
- src/ UNTOUCHED (a tool change moves no bytes); the whole-binary byte-gate (G3/P9) remains the
sole arbiter — a wrong reconcile fails to bank, never falsely banks.
|