WAVE 3 (48 agents / 8 binaries, dealt across binaries so BANKING fans out): 48/48 match_one MATCH,
48/48 banked through 8 PARALLEL per-binary gates. WAVE 2: 15/19. BEHEMOTHS: 4 non-jr confirmed
(func_8017E120 884ins x14, func_8017FA5C 728, func_8017CAD4 755, func_8017E35C 719).
Tier-routed propagation (§123): family_sweep --hseq banked 911 members across 137 overlays.
fn-count 92.32 -> 92.59% | instr 87.9 -> 88.2% | distinct 78.3 -> 78.7% (70,506 unique fns)
R22 clean-fleet 140 passed / 0 failed, under one campaign lock (treelock.sh).
CORRECTION (R14): the 'per-binary bank-rate cliff' I reported from the pre-incident gate run
(SC03_014 1/6, SC04_018 1/6, SC06_018 2/6) was an ARTIFACT — those gates ran against a tree
propagation was concurrently rewriting. Re-gated clean: 6/6 everywhere. A measurement taken during
corruption is not a measurement; I should not have theorised a cause before re-running it.
I gated 8 binaries in parallel while wave-2's propagation loop was still running, then ran
'make clean' on top. check-all 77/140; the corpus denominator moved, so the apparent 91.4% instr
was a half-written tree, not a gain. Reverted to commit:1245 (last R22-verified) — 140/140 restored,
all 58 drafts survived because agents only ever write .run/.
ROOT CAUSE, and it was structural not unlucky: my guard was
while pgrep -f dedup_propagate; do sleep; done
A CAMPAIGN is a LOOP of short-lived processes (15 sequential invocations), so it has gaps where no
process matches. The poll sampled a gap and started. Presence-of-a-process cannot express 'a
campaign owns the tree'.
treelock.sh holds one flock for the WHOLE campaign, released by the kernel on exit OR kill, with
--status; both drivers refuse to run unlocked. LAW: guard the CAMPAIGN, not the process.
Corollary (twice today): a killed process performs no undo — a fleet-tier write needs a lock ABOVE
it, not cleanup inside it.
run_gate() always took per-worker result paths; the CLI never exposed them, so every CLI gate used
the shared .run/harvest_{verified,failed}.txt. Concurrent per-binary gates — safe on every other
axis, since the byte-gate IS per-binary — would have read each other's results and mis-attributed
banks (the §55b trap-4 shared-scratch defect that bit match_one in P28, one level up). Default is
now .run/harvest_verified.<binary>.txt: safe by construction, not by remembering a flag.
WAVE-2 MEASURED THE INDEX: 15/19 index hits and the bank rate went 57% (wave 1, no index) -> 79%
(wave 2, index-first) on the same gate. Agents also NAMED its gaps, which is the flywheel working.
Two real defects found and fixed:
1. COVERAGE. The parser required a '§' prefix, so 111 h2-h4 headers were invisible — including
'### T4 — Branch polarity', the fix match_one names by class (BRANCH-POLARITY) and which two
agents re-derived by hand, and the §1/§2 idiom-catalog entries (I1-I4, T1-T4).
2. THE ASSERTION ITSELF. My R32 check compared §-headers-parsed against §-header-CANDIDATES — a
tautology over a set I had already narrowed. R32 says the candidate set must OVER-approximate;
it now counts EVERY header and accounts for each as indexed-or-explicitly-skipped. The tool
written to stop silent skips had the silent-skip defect.
3. Keyword matching over titles cannot surface an idiom whose title omits the symptom, so the
index now opens with a hand-curated SYMPTOM -> section list, seeded from what agents actually
hit (branch polarity, (void)-canon conflicting types, asm-label alias, one-base-register reuse,
folded andi, slti/sltiu, sibling-first, delay-slot theft, void->s32).
Verified against code rather than the ledger: the split-blind lookup globs */ correctly, and the
churn was fixed by T5's input-signature gating. Both struck. asm_subdir_for was still a parallel
oracle (silent g[0] on multi-match) -> now corpus.asm_path. --fix-def-sig defaults off correctly
but advertised 'Byte-neutral; gate arbitrates' — the claim T84 refuted (signedness-wrong header
decl over a byte-correct draft; 137 members held at 0 until the flag was dropped).
A defect ledger nobody re-verifies decays into busywork — verify before scheduling.
Wave-1 measured the tax: three agents each reported a 'NEW idiom' that was ALREADY documented —
the asm-label alias (line ~2516, same 'address-of perturbs regalloc' mechanism) and the void->s32
non-neutrality (§41d, Phase 26; the agents cited the very entry §41d corrects). They consulted the
cookbook as instructed and could not FIND them. 716 KB / 226 sections with no index = a
discoverability failure, and every wave re-paying for prior waves' findings is the inverse of R16.
docs/cookbook-index.md maps SYMPTOM (what you see in the diff) -> sections, 14 buckets, a section
listed under every symptom it addresses. Derived by tools/cookbook_index.py (R33 — cannot drift),
--check wired into tools-health.
R32 on my own tool: the first regex required an em-dash separator and silently dropped 50 sections
— including §1 (idiom catalog), §2, §5a (cross-jump, cited by an agent today). An index missing its
most-cited entries turns 'I could not find it' into 'it is not there'. Now asserts extracted ==
candidate '§' headers and hard-exits on a gap.
The 4 cores dedup_propagate refused (h_exact tier) templated cleanly via family_sweep --hseq once
the family map was regenerated post-bank (a bank invalidates the map: sig-overlays + family_hseq
must run BEFORE the sweep — the standing wave-loop order). 548/686 banked, 138 failed (one
consistent per-overlay slice, diagnose next). Wave-1 total: 8 cores -> 1,121 instances.
instr 87.5 -> 87.9%, distinct 69,828 -> 70,094 unique fns.
Ultracode wave of 14 agents over fresh reach-138 cores: 14/14 match_one MATCH, 8 accepted by the
whole-binary gate (the §52b law reproduced exactly). Propagated per-function (the incident fix):
0x8012E014, 0x80151C54, 0x8012F49C, 0x80151B98 -> +573 instances. R22 clean-fleet 140/140;
instr 87.5 -> 87.7%, fn-count 92.00 -> 92.16%, distinct 69,828 -> 69,836.
The other 4 banked cores are h_seq (PURE/IMM) families: dedup_propagate is h_exact-only, so its
'reach<2' / 'not self-contained' refusals were statements about the TOOL's tier, not the functions
-> cookbook §123 (the §53 carve-law generalized to the propagation-tier axis) + a routing table.
They bank via family_sweep --hseq next.
A killed process performs no undo, so a fixed timeout on a fleet-tier write is a tree-corruption
mechanism, not just a delay. Now: timeout = min(6h, 1800+1800*banks); on expiry the driver reports
TREE DIRTY, REVERT REQUIRED and returns cleanly. Standing practice for multi-bank waves: re-gate
--no-propagate, then propagate PER FUNCTION (dedup_propagate --addr) — bounded and resumable.
Wave-1 result recorded: 14/14 match_one MATCH -> 8/14 banked (the §52b law); 3 new idioms owed.
39% prior did not generalize (S16 measured FRESH wave drafts; this is A10's stored-backlog class,
0/958 by plain re-gate) — the driver lifted ~16% over that 0%. Residue routed to T3 redraft lanes.
§61 orphan-carve residue reverted; two T3 pre-work gaps recorded (gate_stage commit add-scope for
new carve files; no tracked writes during tree-writing campaigns). Ledger pruned: 1,350 -> 1,332.
o0b-bearing != o0b-adjacent: T85's 0x801457A4 banked by append only because it abuts the o0b
object's END; the 0x8013Bxxx-0x8013Cxxx families mis-place by construction (probe 1/1 gate-reject)
and per-fn isolation IS the Arm-A re-carve. Frontier report corrected; T2 pivots to the Arm-A
+0x20 defect itself (symbol-pin hypothesis first). Driver stands as the post-fix sweep harness.
Probe: main +476/477, fresh-import ov_SC03_001 +238/238, ov_SC02_011 +227/228. Raw-blob
auto-analysis finds only the reachable subset (Phase-10 finding, now automated per program).
One representative per remaining h_seq distinct class + all main/resident stubs -> .run/ghidra_c/.
Resumable (skips cached); serial on the exclusive project lock; auto-stops a serving MCP (R23);
imports missing overlay programs on demand via ghidra_import_raw.sh (blob derived via
family_remap.img_path, vram from the splat yaml — R33, never guessed); R32 per-program outcome
report, continues past failures. Dry-run: 126 programs / 7,966 uncached representatives.
- Filter + prune existed since 07-24; jsonl already compacted (the tree's uncommitted edit was
S25's un-committed prune output; prune today 1350->1350/0 dropped). Stale rows were worklist.md's.
- Oracle agreement: 0 divergence across 131 ledger binaries (my first probe compared names vs int
addrs — R35 on my own instrument). Hex-case canonicalized in the membership test (R32).
- Parity proven post-change: load_best 1350 == 1350. §83 doctrinal caveat stands.
The SESSION-25 recipe (grep -v warnings from --stderr-out) applied in-tool across all 4 stages;
gcc-2.7.2 hard errors have no 'error:' prefix so the old tail-truncation drowned them (cost 3
probes). Raw-tail fallback if the filter empties. Verified on a real deliberate CC1 failure.
- STAGE 0: gate the RAW drafts before any transform (GATE_NO_STAGE0 escape) — the carried
'ladder destroys good drafts' defect (SESSION-22 reproduction: _o0 pair + func_80138C60,
ladder-FAILED/bare-VERIFIED) is impossible by construction; ladder+arity now touch only
stage-0 failures. TU-blind-transform root-cause hypothesis recorded in-code, open.
- fix_arity_callers --journal/--undo-journal --keep: exact per-edit undo in the WRITER,
shared by ladder AND bare workflows (the 17-TU residue class); replaces the two-special-case
file snapshot; undo moved after stage 2 (closes the stage-2 arity parity gap); stale-journal
guard. Negative-control: apply->undo byte-identical; --keep exact.
- Flow test .run/t0a_flowtest/driver.py 7/7 PASS. Cookbook §122. CURRENT_PHASE T0(a) logged.
- Re-ranked after T97: 80 families / 960 members / 173 new distinct, top family worth 20.
- Probed the top (0x8017d840): stages 0 drafts, skipped {'member class STRUCT': 21} — every member
is register-drift class, refused by remap_hseq for a REAL structural reason. First still-zero
family this session whose blocker is not our own tooling.
- Clean split measured: 29 all-STRUCT families (86 members, refused by design, per-member drafting
only) vs 51 no-STRUCT families (874 members, ~150 distinct, stage fine but fail the gate) — no
mixed families at all.
- HONEST ROI: the 51 are ~51 independent diagnoses at ~3 distinct each, and the last THREE blast
sweeps over them returned 0 with every lever this phase built applied. Residue total is 173
distinct vs 2,713 members banked today. The mechanical family engine is SPENT — this is the ROI
conversation SESSION-24 deferred, now supported by data (Drew's gate-2 call).
- No banks; tree clean; src/ untouched.
- The last big NAMED blocker, costed across four checkpoints as §112 header + §20 call-site cast +
a scripted §99 pass over 2,022 overlay-local decls. Probing first showed two of the three were
unnecessary: the conflict is entirely between DEFINE_func_80151924()'s own forward-decl
(extern s32 func_80151944(void)) and the byte-true definition (void f(void *a0)), four lines
apart in the assembled TU. The 2,022 decls live in OTHER TUs and never entered it.
- ONE 4-line edit in engine_core.h: decl -> byte-true, call site -> ((s32 (*)(void))f)() so the
caller's codegen is unchanged. rtu_match: conflicting types -> MATCH (15 ins). Sweep 138/138.
- Family 0x80131eec fully closed: 149 (T87) + 138 (T97) + 1 immediate-refusal = all 288 members.
- SHARED-HEADER RISK VERIFIED, NOT ARGUED: engine_core.h is included by all 138 overlays, so §20
cast-folding is a hypothesis. Per-binary gates 138/138 are necessary but not sufficient; the
fleet check is the one that counts. R22 clean-fleet 140/140 + tools-health RC=0 (corpus 0
PHANTOM/0 TRUNCATED, cdecl, audit-binaries, dedup 1886/0, C1 239604/239604).
- METRICS: fn-count 91.96 -> 92.00% (+138, exact) · instr 87.4 -> 87.5% (+2,070) · distinct +72.
- COSTING LESSON: the estimate came from reading the symptom (2,022 decls of this name exist)
instead of probing the failure (which decl actually conflicts). Probe before COSTING, not just
before scaling.