I reported 240 of 244 turn-finishes truncated in wave bk and called it ~100%. That
count came from grepping lines containing 'finish=', which api_agent only prints when
a turn ends WITHOUT a tool call — so the denominator was not all turns, it was all
anomalous turns. I compared a subset against itself.
Counting every turn:
bk (8k / 420s): 240 truncated of 3,222 turns = 7.4%
bt (16k / 700s): 16 truncated of 1,210 turns = 1.3%
Still a ~6x improvement and the change stands on its own evidence, but it is a tax
reduction, not the collapse I described. Recorded alongside: a truncated turn is one
turn of 24, not a lost agent — the logs show the agent emitting its tool call on the
very next turn.
Both docs keep the wrong figure explicitly, with why it was wrong, so the next reader
does not re-derive it from the same grep.
SETUP gains rows for recover_rejects.py (free recovery of the 45% of drafts that never
reach the gate, 13% of which are a deterministic symbol rebase),
restart_main_lane_when_idle.sh, and a campaign-constants row recording MAXTOK 16000 /
HTTP_TIMEOUT 700 with the measurements behind them: reasoning_tokens=0 so the output
cap was the reasoning cap, 240 of 244 turn-finishes truncated at 8k, an uncapped hard
prompt wanting 8,067 tokens, ~30 tok/s, and the 1M-context / 131,072-max-completion
model ceiling that makes 16k our choice rather than a limit.
The runbook gains the same table plus the ordering rule (generation < HTTP_TIMEOUT <
stallguard's 1200s kill), the evidence that turn caps are NOT binding on the default
lane, one-lane-one-band with the size table that retired the 120-2000 slot, the
maintenance lane's new recovery job, and the main-lane restart helper.
Same problem as the drafter: an env/arg change (MAXTOK, HTTP_TIMEOUT) only reaches a
fresh shell, and the main lane is usually either drafting or gating. This waits for
the one safe window — no main-lane agents alive and no gate_main running, i.e.
between the gate and the next draw — then restarts. Mid-draft would discard drafted
work; mid-gate would abort a batch (safe, since gate_main reverts its own
substitution, but wasteful).
Probed ox-alpha directly on a real MIPS derivation:
no reasoning cap 265.2s finish=stop completion=8,067 reasoning=0 30 tok/s
reasoning cap 2000 22.3s finish=stop completion= 672 reasoning=0
reasoning cap 6000 41.4s finish=stop completion= 618 reasoning=0
Three findings. (1) ox reports reasoning_tokens=0 — its thinking is IN the content
stream, so the output cap was capping the reasoning; that is exactly why turns ended
in 'no tool call (finish=length)'. (2) The uncapped hard prompt wanted 8,067 tokens —
it was finishing precisely where the old 8k cap cut it off. (3) It generates at ~30
tok/s, not the ~54 I estimated from turn gaps, so a full 16k generation needs ~530s
and the 420s socket would have killed the very turns the bigger budget exists to
allow. A timeout wastes the whole turn; truncation at least leaves a partial.
HTTP_TIMEOUT=700 on both drafting lanes. The ordering that must hold is generation <
HTTP_TIMEOUT (700) < stallguard's wedged-agent kill (1200s). 420 was itself deliberate
— 1800 once parked a hung agent for thirty minutes — and 700 keeps a hang under 12
minutes without strangling legitimate deep reasoning.
Also recorded: a reasoning cap DOES work on ox, but it shortens the ANSWER too (618-672
total tokens), so it is a quality knob, not a fix for truncation.
THE OUTPUT CAP WAS EATING THE TURN BUDGET. Wave bk's shard logs: 240 of 244
turn-finishes were 'no tool call (finish=length) — NUDGE n/6'. The model was
exhausting its 8,000-token output budget BEFORE emitting a tool call, so the turn did
no work; an agent gets six nudges before giving up. That is why MATCHes average 2.8
oracle calls against a 24-turn budget — the turns are going to truncation, not
iteration. ox is free, so a bigger output budget costs latency and nothing else.
Measured alongside it, and worth recording because it redirects the obvious fix: turn
caps are NOT binding on the default lane. Across 1,166 agent completions, non-MATCH
runs used a median of 4 oracle calls and a p90 of 12, and exactly 1 of 194 reached 20
of the 24 available. Agents are not running out of turns; they are giving up early
after truncated turns. (The tells lane WAS cap-bound — 98 of 270 — which is why it
already has 40 turns.)
Plus tools/recover_rejects.py, wired into the maintenance lane: rebase the pre-gate
rejects whose body already matches and only the symbols are wrong (§171), stage them
for the lane's existing free gate. Zero model tokens; it only stages, so a bad
recovery can waste a build but never a bank.
Everything that reaches the GATE and fails gets a backlog row with closeness, class
and best draft. A draft the reloc pre-filter drops never reaches the gate, so it was
recorded nowhere and just sat on disk: 569 of 1,261 drafts across the last eight waves
— 45%.
They are not all garbage. 13% of the MISMATCH? rejects have a body that ALREADY
MATCHES and only the symbol names wrong, which is the deterministic aprop_symfix
stale-symbol class that banked 4 of 4 earlier this session. Roughly 6 recoverable
drafts per wave were being thrown away because no index existed to find them.
Now appended to .run/reloc_rejects.jsonl with the verdict, the shape (MATCH here means
right body, wrong symbols) and the first mismatches, so a recovery pass can work them
without re-drafting. Wrapped so telemetry can never break a gate.
The tells slot became redundant when build_wave_atlas started reserving 60 tell-lever
cards inside every ordinary wave: a dedicated tells wave draws 70-87 cards, a quarter
of a default wave, for a full 40-minute slot.
The 120-2000 slot is worse than redundant. Bank rate by size, measured: 57% under 50
instructions, 30% at 50-80, 22% at 80-120, 3% at 120-200, 6% above. Wave br drew 69
cards on that band — roughly 3 banks for a slot that a full-band wave turns into ~150.
Large functions are not abandoned: the full band contains them and the draw takes
mass-first within each gate group.
Takes effect at the next wave boundary via relaunch_drafter_shell.sh.
Drew's endgame deliverable is a workflow system another person can run solo on any
target, any compiler. We had three docs recording BFM's history (accelerators,
decision-log, automation-runbook) and none stating the SYSTEM. This is that document,
written to one rule: if it would still be true for a different console and a different
compiler, it belongs here.
Contents: the byte gate as the only arbiter and the oracle ladder around it (each
oracle must state its own blind spots); lanes and why the clock-limited one is never
stopped to ship a change; the CARD as fuel rather than a ticket, including the lever
lesson (a label a worker cannot look up is a dead end — 108 transcripts searched for a
word our knowledge base did not contain); draw-time refusal and the four measured
instances of the dominant defect class; free work before paid work; giving an excluded
population its own lane instead of an exclusion; model routing and per-lane budgets;
the flywheel with the one-wave lag and the inert-rider law (1 in 3 credited levers is
byte-inert, measured twice); the economics as measured; what transfers vs what does
not (the knowledge base is per-compiler, the machine that builds it is universal); and
a bootstrapping order for a new project.
Numbers are stated with their denominators so a new project calibrates rather than
copies.
corpus.stubs() misreports for a binary while a gate has draft bodies substituted into
its sources (R35) — but only for THAT binary. The blanket refusal cost far more than
it saved: the gater runs almost continuously, so nearly every fresh draw was refused
and the drafter fell back to PRE-DRAWN waves. Measured at 15:20 — wave br refused,
wave bj (drawn hours earlier) drafted instead.
That is worse than idle time: a pre-drawn wave carries the OLD draw-time defaults, so
every feature landed today — the tells quota, the jtbl quota, the -O0 filter, the
oversize filter — was silently not reaching the fleet, while the logs showed healthy
410-shard waves.
Which binaries are mid-gate is not a guess: gate_stage and gate_main hold
.run/auto/gate.<bin>.lock for exactly that window, so a non-blocking test-lock answers
it per binary. Those are added to EXCLUDE for that draw; the refusal survives only for
--only-bins draws where every requested binary is busy.
Verified live against a running gate: the draw that would have been refused now
returns 40 cards.
Uncommitted src/ changes found at gate entry. These are banked functions from a lane that gates with commit=False, not residue — preserved, not reverted.
One clean whole-EXE rebuild verified the batch (gate_main), and main re-checked
BYTE-IDENTICAL against config/check.us.sha before anything was credited.
func_8001D1C4
One clean whole-EXE rebuild verified the batch (gate_main), and main re-checked
BYTE-IDENTICAL against config/check.us.sha before anything was credited.
func_80014238
func_80017DC4
func_80029178
func_8002A790
func_8002AA00
func_8002D80C
func_8002D8A8
func_8002D8D4
func_8002E5BC
func_800342E8
func_800351E8
func_80036D24
func_8003A3D8
A bisect can run many levels; deferring the commit left byte-proven functions sitting
uncommitted in src/ for the whole descent — precisely the window in which any other
tool's blind revert destroys them (61 banked functions died that way once). The tree
is verified byte-identical on the line where the credit is granted; that is both when
it is safe to commit and when it must be.
The runbook was dated 2026-06-22 and described the reach-1 grinder pivot — it named
no lane that exists today, two months and an entire toolchain later. Rewritten around
what is actually running: the six lanes and their restart rules, the OpenRouter
drafting toolchain (cards, LEVER_CRIB, per-lane budgets, the draw's admit/refuse
census, quotas as floor AND ceiling), the banking toolchain by binary class
(sweep_parallel vs gate_main vs the gate-time jtbl carve vs -O0 objects), the main
lane, the distill lane and the flywheel's measured yield, the rate/credit numbers with
their denominators, and recovery.
Two ops laws are stated where they will be read rather than rediscovered: bash parses
a while-loop up front (so code, args and draw-defaults each take effect differently),
and never pkill -f a lane by a bare name because it matches the harness's own wrapper.
SETUP.md gains rows for main_lane, the distill lane and the three restart helpers.
Three defects found by running it, all of the same family — a check that is true about
the wrong thing:
1. FALSE BANKS. The first accounting asked corpus.stubs('main') whether each name was
still a stub; that returns {addr: Stub(symbol=...)} — a dict keyed by INT. Comparing
a NAME against a set of ints is always True, so the lane reported '12 banked of 12'
from a gate that banked nothing and committed nothing. Credit now requires BOTH the
INCLUDE_ASM line gone from the working tree AND main re-checked byte-identical.
2. INNOCENT DRAFTS DYING WITH A DECL CLASH. gate_main deliberately refuses to bisect a
COMPILE conflict (right for a human caller, wrong for an unattended lane): the first
live batch hit a conflict on a symbol that was in the TU and in NO draft, so there
was nothing to drop and 40 innocent drafts died with it. The lane now halves the
slate — a main rebuild measures ~15 s, so bisecting is cheaper than discarding.
3. THE DRAW GUARD REFUSED EVERYTHING. build_wave_atlas refused to draw whenever any
gate was in flight (R35: corpus.stubs misreports mid-gate) — but only for the
binaries being gated. Main's sources are touched by gate_main alone, so a main-only
draw now watches gate_main and every other draw keeps the blanket refusal.
Failed drafts are parked with a try count instead of discarded (a failed draft is
evidence), capped at 2 so an unbankable body cannot spin the lane.
Live: 13 main functions banked, main byte-identical at 143dbb89, stubs 1713 -> 1700.
main is excluded from every wave draw for a good reason — its gate is a clean
whole-EXE rebuild that bisects, and on the overlay critical path it cost three
measured stalls (39 min unfinished on 29 drafts, 25 on 8, 65+ on 8). The consequence
was that main sat outside the loop entirely: 1,713 open stubs, no lane, no cadence,
while the overlay lane ran at ~a quarter of the API ceiling because CARD SUPPLY, not
throughput, is its constraint. Two populations, one idle half of a rate limit.
draw (main only) -> draft -> reloc pre-filter -> ONE gate_main batch -> commit.
Never sweep_parallel or gate_stage (both build incrementally; main's extract rewrites
the linker script, so an incremental build yields a FALSE diff — that is what banked
0 of 105 main cards in wave ab). Batches because one clean rebuild verifies the whole
slate; the reloc pre-filter is what keeps a batch from bisecting. Commits the moment a
batch is green (R42) since gate_main deliberately does not.
Parked drafts first: 170 main drafts sit in .run/main_queue from before the exclusion —
already drafted, never gated, free.
TELLS QUOTA (Drew approved): a dedicated tells wave drew only 70-87 cards — a full
40-minute drafting slot at a quarter of a default wave — because the 5-80 size cap and
the tells pool cannot fill more. Tells now ride inside ordinary waves with a 60-card
quota, same as jtbl. The size cap moved into the draw itself: tell-lever members above
--tells-max-ins (80) are not drawn at all, because the measured bank rate is 27-40%
at 5-80, 10% at 81-120, 1% at 121-200 and 0% above — those 383 members / 51,941 ins
are idiom_serial's work, and the skip counter names it (R45).
A QUOTA IS A FLOOR UNLESS IT IS ALSO A CEILING. First test: putting the tell levers in
the default list let them win the ranked fill too, and a 300-card wave came back 122
tells (41%). The size cap held; the mix did not. Tells now enter through the quota or
not at all.
GATE JOBS 24. The quotas deliberately pull cards from binaries outside the ranked gate
groups, so a measured draw went from ~24 groups to 63 — 63 whole-binary rebuilds per
wave, five serial batches at 12 jobs. The box is 32 cores at ~6% (load 3.1) with 39 GB
free. Lands via restart_gater_when_idle.sh so no sweep is killed mid-flight.
Correction to the record: the live draw already passed --max-bins 24 (plus
--one-per-gid and --exclude-bins main). An earlier measurement of mine used the tool's
default of 12 without those flags and read as 'max-bins is the cap' — it is not;
--one-per-gid is, and deliberately: it defers same-skeleton siblings to the free
deterministic remap instead of paying an agent twice.
Balance $2.56 and falling ~$1.43/h over the last three waves ($4.56 at 11:54 ->
$2.56 at 13:18) — about 23 minutes from --credit-floor 2.0. That floor does NOT pause
the paid lane: it breaks the whole drafting loop, and the shell then restarts a python
that breaks again, so the clock-limited resource dies on a check about money.
ox-alpha is free for the rest of this window, so drafting continues on ox alone at zero
burn, and the floor drops to 0.25 because with a free model the balance stops being a
proxy for 'can we draft'. deepseek was 280 of 2,000 workers — its value was an
independent 429 ceiling, not throughput.
Takes effect at the next wave boundary via relaunch_drafter_shell.sh, so wave bp's
in-flight drafts are not lost. Restoring it after a top-up is two edits, named in the
script's header.
268 a register __asm__ pin on a call-clobbered register is honored EXACTLY when the
pinned range crosses no call — turning 257-2's 'pins are silently ignored' into a
rule with a precondition, and explaining both faces: a pin that does nothing
(range crosses a jal, gcc silently falls back) and a pin that fixes a REGALLOC
residual in a function that has calls (range sits between them). Three A/B'd cards.
269 ten addenda, plus the 266 solo-lever sweep table.
THE HEADLINE IS THE INERT-RIDER RATE. 19 strip-tests across 13 banked bodies: 6 of 19
credited levers are byte-inert (32%), against 4 of 8 last batch. One in three 'this is
what made it match' claims credits something that changes nothing — and one whole
proposed section dissolved under its own strip test. 67 of 82 candidates (81.7%) were
already covered, matching the previous batch's re-derivation rate.
Drew, 2026-08-24: distillation is judgement over an existing corpus (read harvested
notes, decide covered / addendum / new against 760+ sections), not a new wall class.
Fable is for the walls — an unsolved tooling problem, an adversarial design review, a
residual no documented lever reaches. I routed a distill batch to Fable; recorded here
so the next session reads the tier off the lane rather than guessing it.
A re-gated wave rewrites its candidate file with NEW rows under the SAME tag, so
"have I seen this tag" answers the wrong question. Two instances in one hour:
* wave `at` was re-gated hours after its first harvest, so an mtime-keyed seed
called it new and 52 mostly-re-derived rows went to a reviewer;
* my own hand-edit of the state folded "queued for review" into "reviewed", which
marked `ax` and `bm` — 82 candidates, gated minutes earlier — as mined by nobody.
Caught only because their files were newer than the edit.
The scan now compares COUNTS: a tag re-opens the moment its file grows past what was
mined from it. Extracted to tools/distill_scan.py so the logic is testable rather than
living inside a heredoc inside a lane loop (the heredoc-in-heredoc edit is also what
produced a syntax-broken lane script a minute earlier).
Verified: the lane now raises exactly the true pending batch — ax + bm, 82 novel.
Two discovery-gap defects the distill review measured, both costing drafters real
compiles:
1. LINE NUMBERS CITED AS SECTIONS. Index rows end with a <sub>L1234</sub> anchor = the
section's line in the cookbook. Drafters read it as a section id and cite it: this
batch alone carries §1907, §12479, §2965, §11383, §8892, §5583, §1832, §2429,
§1755, §2609 — line numbers, every one, and a grep for any of them returns nothing.
The number is real and the reading is wrong, which is the worst kind of dead end
because it looks like a citation. The index now publishes an L→§ table, and
answers it directly (verified: §12479 → §3-The,
§1907 → §21).
2. THE INDEX WAS NEVER NAMED AS THE ENTRY POINT. One drafter wrote 'no numbered
section I could find by grep' about a lever whose section title literally contains
the words it searched — it grepped the 25k-line cookbook, not the symptom-keyed
index. api_agent's SYS now says to start at the index, and how to resolve a
line-number citation.
265 the verbatim-asm bank lane — two in-tree precedents, the MASPSX decimal-immediate
rule, and a REVIEW-ADDED accounting caveat: an __asm__ body is not an INCLUDE_ASM
stub, so corpus.stubs() counts it as MATCHED. Bytes proven, function not
decompiled. Fine for hand-written asm; for an -O0 C function the right answer is
the -O0 object, and this lane is a temporary hold at best.
266 the inert-rider law — a lever is only citable when its solo removal breaks the
match. Measured 4 of 8 credited levers on this batch were byte-inert: a $2 pin
silently dropped, a volatile the scheduler already ordered, a named zero, and a
statement split. The banked artifact CONTAINS the rider precisely because it is
inert, which reads as proof. R40 applied to the flywheel itself.
267 eleven addenda to existing sections, six with fresh match_one A/Bs.
The batch's real headline: 145 of 165 candidates were ALREADY COVERED, and 8 claims
were refuted (4 by live A/B) — the harvest is mostly re-derivation, and an unchecked
wrong law is worse than no law.
The harness re-invokes the main loop when a background command exits, so a blocking
wait IS the self-reminder; a sleep-then-tail poll loop would just burn tokens for the
same information.
The gater already harvests every wave before the next draw (Drew's 2026-08-23 rule),
but that is EXTRACTION: it writes .run/idiom_candidates.<tag>.md and stops. What
changes the next wave's behaviour is the COOKBOOK, because that is what the drafting
agents grep — and distillation was batched per session, so the ore piled up: 165
novel candidates across 4 waves within three hours of the last cookbook update.
The lane does the zero-token half — watch, count novel rows, and raise a READY marker
naming the waves when a batch is worth a reviewer's turn (>=30 candidates or >=2
waves). It writes no cookbook, no src/, no config/: a bad harvest cannot pollute the
knowledge base on its own, and landing stays a reviewed step (us + a subagent).
It never blocks a draw. Wave N's ore is distilled while wave N+1 drafts, so wave N+2
is the first that can grep it — stopping the drafter to think cost 139 of 162 idle
minutes on 2026-08-23.
State seeded so it does not re-mine what S58 already landed as §233-§259: the "done"
list holds the 17 candidate files written before commit commit:2637.
Records the per-type answer to 'can the waves draw and bank this now', the four
commits that landed after the agents returned, three rule candidates for PhaseEnd
(a card may not name a lever the knowledge base lacks; draw-time bankability; a
budget is part of the harness), and the ranked open work from the agents' docs.
Adding the lever alone was inert: a jtbl card is one-per-binary by construction, so
jtbl cards are maximally UN-concentrated, and the gate-group ranking exists precisely
to pack many drafts behind one rebuild. Measured — a mixed draw offered 71 jtbl
candidates and selected ZERO. It would have done that every wave, forever, while
looking enabled.
--jtbl-quota (default 6) seeds the wave with the largest eligible jtbl cards before
the ranked fill, so the lane advances inside ordinary waves instead of needing a
dedicated one (a jtbl-only draw is ~12 cards and would idle a 2,000-agent fleet).
Cost is exactly 6 extra whole-binary rebuilds per wave.
Verified on a live-shaped draw: 6 jtbl-carve cards in a 200-card wave, 13,470 ins
across 7 gate groups (was 11,451 ins in 1 group), with the probe filter refusing what
the gate cannot reach — main 29, island-blocked 10, island-pads 6, one-per-binary 71.
Its entire code subseg is the -O0 run and the .c is stub-only, so this is the boot
precedent: a whole-object CC1FLAGS override, no splat change, no carve, and none of
the 18-P29 re-disassembly risk. Proven byte-neutral by a CLEAN per-binary rebuild —
build dirs deleted, re-extract, rebuild:
sha1 80731bac0ddd6b3e354f43b2c179582b12590752 == config/check.md_MAIN_011.sha
Landed with the coupling fix it requires, or the 21 would have stayed invisible.
Three tools decided -O0-ness from the subseg NAME ('_o0' in it, or 'boot'); this
object keeps its plain name, so match_one would have warned 'cannot bank' about
functions that now bank and the wave draw would have kept refusing to draw them. All
three now ask corpus.o0_subseg(), which derives the answer from the Makefile itself
(R33: a name is a convention, the Makefile is ground truth).
Verified end to end: match_one compiles md_MAIN_011 targets at -O0 with the
cannot-bank warning correctly gone, the wave draw emits cards for them, and
test_o0_detect still passes 167/167 coverage with 0 false positives.
Three measured harness defects, all fixed:
1. THE CARD NAMED A WORD THE COOKBOOK DOES NOT CONTAIN. api_agent stated the lever
as a bare label and nothing else; grep 'extend-tell' / 'swaprepeat' / 's16-div-tell'
over the 750-section cookbook returns ZERO. 108 failure transcripts grepped
extend-tell and 28 grepped swaprepeat against nothing while the knowledge sat at
172a/172b under different words. Fixed both ends: a LANE ALIASES grep-bait block at
172b, and LEVER_CRIB on the card — what the tell means, the section to grep, and
the byte-proven C spellings.
2. ONE GLOBAL AGENT BUDGET FOR CARDS OF VERY DIFFERENT SIZE. tells cards are 2.4x the
default lane's (median 89-95 ins vs 37-39) and stack 3-5 idioms; 98 of 270 final
attempts ended AT the 24-turn cap. LANE_BUDGET gives tells 40 turns / /bin/bash.40, and
logs the choice so it is auditable rather than invisible.
3. Two new SYS laws: grep the section your crib cites before drafting, and stop when
the residual class says [permuter]; plus 263 (an invented argument changes
scheduling — check arity before reaching for a fence the permuter cannot help with).
Cookbook 264 records the four recipes the tells agent drove to MATCH: the inline (s16)
in a call argument, the save-order/bb0 anti-dependence law (new), the opaque-bound
local assigned late (new), and 172b-1's multi-def mirror variable made concrete.
func_801F218C read as DELAY-SLOT/schedule: 83 vs 83, one mismatch, mine putting
'move a0,s0' in a jal delay slot the target leaves as nop. The 5a fence in both
placements, if/else inversion, an early-break restructuring and a 1200s permuter at
-j12 all failed. The cause was a declared parameter on a no-arg callee: passing it
makes the copy dominate the call, so the filler takes the slot. Deleting the argument
-> MATCH (83 ins).
Also records the tell that beats 195-A's 'the asm has no arity tell': an arg setup
sitting in a BRANCH delay slot, needed by only one successor, proves the call does
not use that register. And the standing waste warning — the permuter cannot change
call arity, so this class is guaranteed to defeat it.
The carve stays INSIDE the byte-gate (harvest_verify._jtbl_prep_one, the §61b-proven
order); everything new routes work to it:
* jtbl_carve: island_probe (read-only classifier: tail/covered/island-end/island-blocked/
island-pads/main-manual), --island-split (the one-line §260 insert, end-adjacent only),
and apply() now recognizes a completed island split as a no-op success instead of the
historical refusal.
* harvest_verify: _ISLAND_WALLS branch — on the §154-A refusal the gate isolates (body
still spliced), inserts the split line, re-extracts, re-carves. Snapshot-restore covers it.
* jtbl_lane.py (new): probe → draft (--draft-dir or api_agent) → gate via the exact
sweep_parallel worker call, HOLDING the campaign draw lock across gate+commit → commit
named per-binary paths. One jtbl target per gate invocation (§61c).
* build_wave_atlas: probe filter + one-jtbl-card-per-binary cap (inert unless
--levers jtbl-carve). idiom_serial: refuses the jtbl-carve lever (R43; its pre-carve ran
the refuted order — S58: 8 attempts, 0 banks).
Proven end to end with the live campaign running (banks committed separately):
commit:2661 ov_SC03_014/func_8017DCC0 tail: §8b adjacent merge + §8e pad recovery,
jr_8017AE2C.o .rodata 0x14→0x28 TIGHT, sha d84b01a2 green
commit:2663 md_SC03_076/func_801F218C covered: §260 STAGE 2 — sha 9a165e36 identical
with the table COMPILER-EMITTED; the first md_* jr bank ever
commit:2664 md_SC03_135/func_801E5358 island-end: the FULL split done BY THE GATE on a
virgin module (~1.1s, R40-checked), sha b901fda5, md.o 0x27c→0x268 + jr.o 0x14
Census (245/245 members probed, R32): 181 members / 26,445 ins reachable unattended;
main 47 parked (gate_main cadence), island-blocked 10 (stack order), island-pads 6
(needs §8e pads for modules.mk), no-jtbl 1 (atlas mislabel).
Design + failure semantics + campaign hook: docs/tool-designs/jtbl-automation-s59.md;
cookbook §260-A.