mirror of
https://github.com/Druthulu/BFM-decomp
synced 2026-09-28 06:49:47 -04:00
7e32da8f64ca7d65713a680f7a84d31afdf2b898
1205 Commits
| Author | SHA1 | Message | Date | |
|---|---|---|---|---|
|
|
7e32da8f64 |
feat(phase-29): T95/T96 — func_80142B2C 136/136 (§121); all 3 byte-identical stragglers closed
- The draft calls ((void(*)(void))func_80142C84)() but nothing declares that symbol above the splice: it is DEFINED by DEFINE_func_80142C84() in engine_core.h, so gather_externs has no extern line to harvest, and the member TU instantiates the macro BELOW our function. - The wrong guess was the useful step: a no-prototype `extern s32 func_80142C84();` turned `undeclared` into `conflicting types` — a DIFFERENT error, proving the diagnosis right and the type wrong. Synthesised from the macro's own definition head -> MATCH (34 ins) -> 136/136. - NEW macro_def_sig_map() (1,878 signatures): the complement of header_sig_map(), which reads the externs a macro emits FOR ITS CALLEES; this reads the signature a macro DEFINES. Cookbook §121. - ALL THREE byte-identical stragglers carried since SESSION-24 are now closed: func_80146750 137/137 (T84), func_801759D8 137/137 (T93), func_80142B2C 136/136 (T95) = 410 members, and not one was a compiler wall (a signedness-wrong header decl, a type-name collision, a missing extern). - Blast radius 0 (74 further families re-swept). FOUR data points now: only §117 (wrong LOGIC) generalised at 1,209 members; §118/§120/§121 are path-reachability gaps worth ~one family each. - GATES: R22 clean-fleet 140/140; dedup 1886/0; 0 NON_MATCHING (G4). - METRICS: fn-count 91.88 -> 91.96% (+273, exact) · instr 87.3 -> 87.4% (+12,296) · distinct +0 (both byte-identical families — §111 predicted exactly that). |
||
|
|
9a1507462f |
feat(phase-29): T93/T94 — func_801759D8 137/137 via type-uniquify (§120) + two T92 corrections
- CORRECTION 1 (R14/P9): T92's "strip-if-ambient" recipe was WRONG. Stripping the draft's duplicate
typedef breaks the extern that USES it (the TU's own copy sits below the spliced function), so the
"second stacked blocker" T92 recorded (D_800AF634 used prior to declaration) was my own fix
misfiring, not a real blocker. RENAME, don't remove: rtu_match CC1 FAIL -> MATCH (56 ins).
- CORRECTION 2: T91's wiring never RAN. family_sweep has THREE staging sites sharing the identical
two lines (edit-remap / hseq / plain h_norm); I patched by rindex twice, which lands on the PLAIN
site, so --hseq staged the draft unchanged and the lever looked ineffective. Re-anchored on the
hseq site's unique write (func_{to_addr:08X}.c) and the draft came out renamed. T91's revert was
right discipline on a false premise.
- RESULT: _uniquify_draft_types wired into the hseq path (byte-neutral — C type names never reach
codegen). func_801759D8, one of the three long-standing byte-identical stragglers: 0 -> 137/137,
0 failed. Blast radius 0 (74 further families re-swept, none moved) => TARGETED lever, like §118
and unlike §117.
- Cookbook §120, incl. the law: before concluding a lever does not work, prove it RAN — diff the
staged artifact for the change it is supposed to make.
- GATES: R22 clean-fleet 140/140; dedup 1886/0; 0 NON_MATCHING (G4).
- METRICS: fn-count 91.88 -> 91.92% (+137, exact) · instr 87.3 -> 87.4% (+7,672) · distinct +0
(byte-identical family — §111 predicted exactly that).
|
||
|
|
9f1f2e94b6 | docs(phase-29): SESSION-25 final checkpoint v6 — 3-step recipe for the stacked blocker | ||
|
|
2b76b73f73 |
docs(phase-29): T92 — typedef blocker confirmed by experiment; a SECOND blocker behind it
- Read the colliding decls out of the ASSEMBLED t.c (the step T91 named): the draft's file-scope typedef S_AF634 (line 2885) vs the TU's OWN file-scope S_AF634 (line 3016), character-identical, with the draft landing above. Stripping the draft's duplicate CLEARS the error — by experiment, not inference. - SECOND BLOCKER revealed behind it: "D_800AF634 used prior to declaration" — the draft's extern S_AF634 D_800AF634[] sits at BLOCK scope below its first use (the §8d demotion). So func_801759D8 is two STACKED blockers; a typedef-only fix will still gate-fail. Recorded so the strip is not billed as the family's answer. - tu_ambient DOES scan the whole file, so _uniquify_draft_types should have handled #1 and did not. Left unresolved rather than spend budget reconstructing a patch I had already reverted — but func_801759D8 is now a reproducible test case to gate any re-wiring against. - Ordered recipe recorded: strip ambient-duplicate typedefs -> fix the §8d demotion (hoist the data extern above first use) -> re-probe with rtu_match -> only then sweep. 137 members / ~130 distinct, and the auto-named S_* typedefs recur across the byte-identical stragglers. - No banks; tree clean; src/ untouched (the probe ran in .run/ and a scratch copy). |
||
|
|
f09c80e8a9 | docs(phase-29): SESSION-25 final checkpoint v5 — typedef-redefinition blocker named, §119 matrix exhausted | ||
|
|
dac90f0fa1 |
docs(phase-29): T91 — §119 matrix exhausted; still-zero blocker is a typedef redefinition
- Ran the last untested corner (--fix-def-sig only) over the 82 still-zero families: 0 banked. The 2x2 is now fully enumerated (both 0 / neither 9 / NSD-only 23+138 / fds-only 0), so §119 is SPENT on this population — a clean negative for one sweep's cost. - PROBE (func_801759D8, 137 members): rtu_match -> CC1 FAIL, conflicting types for 'S_AF634'. The TU already carries that typedef at file scope AND at block scope; the draft carries it too, and gcc-2.7.2 rejects a typedef redefinition even when character-identical. This class needs STRIP-IF-AMBIENT, not rename-if-colliding. - Wired canon_sig_reconcile._uniquify_draft_types into the hseq staging path (it lived only on --reconcile-raw — the 5th 'lever unreachable from this path' this phase), re-probed, and the error was UNCHANGED. REVERTED it: a default-ON change to the shared staging path that did not fix its own motivating case and that I cannot validate on remaining budget is the T80/§61 failure mode. The 3-line diff is trivial to redo once it can be gated. - Named next step: the error's line numbers are ASSEMBLED offsets, not source ones — read the preprocessed t.c to find which two decls actually collide, then make tu_ambient see file-scope typedefs (or drop the draft's when the TU declares the same name). 137 members / ~130 distinct. |
||
|
|
cc27701863 | docs(phase-29): SESSION-25 final checkpoint v4 — 2,302 banked, fleet 87.3% instr / 78.0% distinct | ||
|
|
f7c6d2eb2f |
feat(phase-29): T89/T90 — 0x80161c98 138/138 via the flag off-diagonal (§119) + a T84 correction
- CORRECTION (R14/P9): T84's '137 banked = all of 0x80161c98' is WRONG and committed wrong in commit:1193. The 137 were func_80146750 (a byte-identical straggler), banked 1-per-overlay in <ov>_after.c; 0x80161c98's members were still stubs. I assigned a count to the family I had been looking at without deriving it — third instance today of that error class. The --fix-def-sig-is-harmful finding itself stands (it unblocked func_80146750 x137). - THE REAL BLOCKER was a flag OFF-DIAGONAL, not a defect. 0x80161c98's byte truth is (int,u32) -> sltiu; engine_core.h says (s32,s32); and an in-TU decl disagrees with the def. The levers pull opposite ways: --fix-def-sig bends the DEFINITION to the header; --normalize-self-decls bends the DECLARATIONS to the definition. both-on -> slti DIFF (T79). both-off -> correct sltiu but 'conflicting types' (T84/T88). NSD-only -> 138/138 (T89). Three sweeps across three sessions tested only the diagonal of the 2x2. Cookbook §119. - T90 blast radius: 23 more (NSD-only) across the remaining still-zero families — targeted, not general; recorded so it is not over-projected. - GATES: R22 clean-fleet 140/140; dedup 1886/0; 0 NON_MATCHING (G4). - METRICS: fn-count 91.84 -> 91.88% (+161, exact) · distinct-code 69,593 -> 69,744 (+151). |
||
|
|
a9c7f09775 | docs(phase-29): SESSION-25 final checkpoint v3 — 2,141 banked, fleet 87.3% instr / 78.0% distinct | ||
|
|
bf71232d0b |
feat(phase-29): T87/T88 — ordinal immediate resolution (§118): 158 banked
- The T86 asm-ambiguous refusal was CORRECT (a by-value swap would corrupt the non-differing occurrence); the safety TEST was too strict. It compared the C literal's occurrences against EVERY asm use of that value, but gcc synthesises uses no C token names — e.g. D_80187044[*(u16 *)((s32)a0 + 0x2)]() has one C literal 0x2 and TWO asm uses of 2 (the per-member offset + a fixed sll ..,2 for the 4-byte stride). Unsatisfiable by construction. - FIX (_ordinal_edits, §118): pair C occurrences to asm positions IN ORDER, accepting either len(spans)==len(asm_pos) (every use named) or len(spans)==len(diff_pos) (extras are implicit). Rewrite only occurrences whose instruction is in diff_idx. Order is a heuristic, so the whole-binary byte-gate stays the sole arbiter — a wrong pairing is rejected, never banked. - T87: func_801599A4 0 -> 137 drafts, 137 banked; +12 singletons = 149 (family 0x80131eec). - T88 blast radius: only 9 of the other 144 immediate-refusals converted (refusals 67 -> 34). A TARGETED lever, not a second §117 — recorded so it is not over-projected. - GATES: R22 clean-fleet 140/140; dedup 1886/0; 0 NON_MATCHING (G4). - METRICS: fn-count 91.79 -> 91.84% (+158, exact) · distinct-code 69,450 -> 69,593 (+143). |
||
|
|
48a5bc358e | docs(phase-29): SESSION-25 final checkpoint v2 — 1,983 banked, fleet 87.3% instr / 77.9% distinct | ||
|
|
1175849d01 | docs(phase-29): T86 — items 3/5/6 resolved; item 6 was 8 eligible not 126 (my error) | ||
|
|
dcbeebaf49 |
feat(phase-29): T84/T85 — 0x80161c98 137/138 + func_801457A4 133/133 (+270 members)
- T84 (item 1): the top still-zero family's whole diff was ONE instruction — slti (signed) vs the target's sltiu. --fix-def-sig was conforming a byte-correct draft to engine_core.h's signedness-wrong decl (extern void func_80161D20(s32,s32)) while the exemplar's own def is (int, u32). Re-swept the 92 still-zero families WITHOUT the flag: 137 banked (all of 0x80161c98), other 91 unmoved => family-specific, NOT a second §117. Recorded as such. - T85 (item 2): rewrote tools/rollout_801457a4_o0.py as the two-file ATOMIC driver §116 called for (remapped body -> <ov>_o0b.c AND drop the INCLUDE_ASM from <ov>_after.c in one edit; build vs config/check.<ov>.sha; restore BOTH files on mismatch, §61). Validated on 3, then 130/130. No splat change — the Arm-A re-carve wall never touched. - Item 4 PRICED AND DROPPED: STRUCT residue = 34 families / 166 members / 0.02pp. - R14: my new_distinct estimator over-projects ~2x (priced 259, measured 125) — it counts classes unmatched at run time, so concurrent sweeps double-count. Ranks correctly, overstates absolutely. - GATES: R22 clean-fleet 140/140; dedup 1886/0; 0 NON_MATCHING (G4). - METRICS: fn-count 91.72 -> 91.79% (+270, exact) · instr 87.2 -> 87.3% (+16,946) · distinct-code 69,325 -> 69,450 (+125). |
||
|
|
3cb0e68fe4 | docs(phase-29): SESSION-25 final checkpoint — 1,713 banked, fleet 87.2% instr / 77.8% distinct | ||
|
|
9d0ce20015 |
feat(phase-29): T83 — the §117 blast radius: 821 members, 138 families zero -> complete
- Re-swept the 229 eligible non-jr families (2,575 candidate members) that had never seen a correct target spelling. 821 banked / 1,538 failed; 138 families went zero -> COMPLETE (732 members), 14 partial, 92 still zero. Top: 0x80172780 +135, 0x80128158 +31, 0x80187318 +28, 0x8016f540 +27, 0x8017bef8 +20. - Every one of those 138 families had been swept before and booked as a failure. None was a compiler problem — all were downstream of the one positional-map defect fixed in T82. - GATES: R22 clean-fleet 140/140; dedup 1886/0; 0 NON_MATCHING (G4). - METRICS: fn-count 91.48 -> 91.72% (+821, exact) · instr 86.9 -> 87.2% (+33,670) · distinct-code 69,024 -> 69,325 unique fns (+301). - The 92 still-zero families are the honest residue: swept with every lever this phase built (§114 callee, §115 named-symbol, §117 symbol-kind, def-sig, self-decl normalization), so no known harness defect applies to them. Correct starting population for the next diagnosis round. |
||
|
|
28dc3785f5 |
feat(phase-29): T82 — symbol-KIND fix in symbol_map: func_80174784 2/255 -> 251/251 (§117)
- CAUSE: family_remap.symbol_map zips exemplar/sibling reloc slots positionally and spelled the SIBLING's symbol from the EXEMPLAR's kind. Same-address families always agree, so it was invisible for 20+ phases; cross-address families need not agree — func_80174784's callback slot is the FUNCTION func_801747CC while member func_8017CFD4's same slot is the DATA symbol D_80182688. The map emitted func_80182688, the body materialized a name for an address that is not a function, and the fleet gate refused all 251 members. - FIX: spell the target by what the target address IS in the SIBLING's overlay (func_ iff in that overlay's sig set — the same boundary oracle nins_of trusts, R33; memoized). Phase 26-A had already established this rule and applied it only to the exemplar side. - WHY IT HID: rtu_match/match_one MASK HI16/LO16, so a wrong %hi/%lo symbol still reports a clean MATCH (measured: "MATCH (10 ins)" on a member the fleet gate rejected). masked-MATCH + whole-binary DIFF is the exact signature of a compiler wall. Cookbook §117 carries the law. - Also refuted en route (cheaply): --normalize-self-decls was NOT the cause — re-swept without it, still 0/251. - GATES: R22 clean-fleet 140/140; dedup 1886/0; 0 NON_MATCHING (G4). - METRICS: fn-count 91.41 -> 91.48% (+251, exact) · distinct-code 68,782 -> 69,024 unique fns (+242, projected 246) · instr +2,510. - BLAST RADIUS UNMEASURED: symbol_map serves every family sweep; 229 eligible non-jr families / 2,575 members have never been swept with a correct target spelling, incl. the byte-identical families T76 measured at 0/682 (same failure shape). |
||
|
|
90a644fb80 |
docs(phase-29): T80/T81 — two 0/N diagnoses + the SESSION-25 checkpoint
- T80: the §116 rollout prescription was WRONG and the build refuted it in 56s across 133 overlays. "Byte-neutral by construction" was a claim about the LINKER; splat keys asm/ generation to the SEGMENT, so deleting func_801457A4's INCLUDE_ASM from <ov>_after.c stops func_801457A4.s being emitted and <ov>_o0b.c cannot assemble. Reverted, nothing committed. Cookbook §116 corrected IN PLACE with the refutation + the corollary (build it before you call it neutral). Real route: a two-file atomic driver (body -> _o0b.c AND drop the stub from _after.c in one edit). 129 distinct still on the table, now costed. tools/rollout_801457a4_o0.py kept as the inventory pass ONLY — do not --apply. - T81: 0x80131eec 0/288, and the two halves have DIFFERENT blockers — func_80151944 (138) staged and gate-failed on the T71 decl conflict; func_801599A4 (137) + 13 singletons were REFUSED AT REMAP for unresolved immediates and never reached a compiler. My prediction that the correct-decl half would bank was the T76 error shape (reason from one property, ignore the disqualifying diff_class: IMM) — recorded, not buried. CORRECTION IT BUYS: T71's "the immediate engine is not the bottleneck" holds for T70's families and is FALSE here (150 of 288). T2a immediate resolution is now a named, sized lever. - Refuted from source before spending a probe: the reloc tracker DOES see a function address materialized as an argument (LO_OPS includes addiu), so 0x80174784's 2/255 is not that. - SESSION-25 checkpoint: fleet 86.9% instr / 77.4% distinct / 91.41% fn-count; 641 banked this session; ranked next-list with all six items measured. Nothing running, tree clean. |
||
|
|
774592c452 |
feat(phase-29): T79 — byte-VARIANT re-sweep: 641 banked; T70's "1 of 10" was a pre-lever measurement
- VALIDATED FIRST, then batched: 0x80143d28 (T66's #1, T76's ApplyMatrixSV callee diagnosis) banked 136/136 under the §114 callee axis + §115 named-symbol widening. Batch of 8 followed: 505/1039. Totals: 5 families outright + 1 partial of 9; 641 members ×N. - Attribution DERIVED (R33), not parsed from the sweep log: live stubs recomputed per family from corpus.stubs before/after. Reconciles exactly against the metric (fn-count +641). - §116 (NEW): optimization level is a property of the FILE, not the function. 0x801457a4 swept 0/137 because its exemplar lives in ov_SC01_077_o0b.c (-O0 via WHALE_O0B_OBJS) while all 137 members' stubs live in <ov>_after.c (-O2). The fix moves the STUB line, not the def: <ov>_o0b's .text ends exactly at 0x801457A4, so the relocation is byte-neutral by construction and needs no splat re-carve (which is the Arm-A +0x20 wall). 13th time a family-wide 0/N was the harness. - R14 CORRECTION to the handoff arithmetic: the tier is 123 families / 3,100 distinct on fresh sigs, but 1,287 of that distinct is the -O0 cluster behind the Arm-A splat wall. Honest addressable tier = 113 families / 85,360 ins / 1,813 distinct. Billing the walled 1,287 as sweep yield would have repeated the T76 error. - 0x80131eec (214 distinct, the biggest item left) diagnosed precisely: header macro decl + §20 call-site cast + a scripted §99 pass over 2,022 overlay-local decls; param is void*, so the T75 narrow-param refusal does not apply. - GATES: R22 clean-fleet 140/140 from make clean + extract-all + check-all; tools-health RC=0 (corpus 0 PHANTOM/0 TRUNCATED, cdecl, audit-binaries, dedup 1886/0, C1 239604/239604); report RC=0; 0 NON_MATCHING (G4). - METRICS: instr 86.7 -> 86.9% (+28,205 ins) · distinct-code 76.9 -> 77.4% (68,196 -> 68,782 unique fns) · fn-count 91.23 -> 91.41% (+641). The distinct-code move is the point of this tier. |
||
|
|
47d7137a30 |
docs(phase-29): SESSION-24 REVISED-3 checkpoint — 2,180 banked, fleet 86.7% instr
Supersedes all three earlier SESSION-24 blocks. Session total reconciled against the metric (fn-count 320524 -> 322704 = +2,180; instr +152,366; per-task recount agrees exactly), the lesson earned ~12 times with every cause enumerated, a ranked measured NEXT list led by the byte-VARIANT re-sweep (stale IN OUR FAVOUR — T70's 1/10 predates the §114 callee and §115 named-symbol levers, and 26 of 36 families were never swept), my errors, carried defects incl. the open §61 judgment call, and the 13 new cookbook entries. Fresh session safe from here: HEAD commit:1186, nothing running, tree clean but for the R23 db.*.gbf churn and a pre-existing .run/backlog.jsonl edit, R22 clean-fleet 140/140 (run 24x), tools-health OK, dedup 1886/0, 0 NON_MATCHING. |
||
|
|
611622c9e7 |
feat(phase-29): T78 — PsyQ-symbol widening: func_8012F40C 0/137 -> 137/137 (three places, not one)
I called this "a one-line predicate widening". It was THREE, and fixing the first two changed nothing
— the sweep still reported 0/547 (cookbook §115):
1. canonical_map : re.fullmatch(r'func_[0-9A-Fa-f]{8}') + keyed by parsed ADDRESS
2. DECL_LINE_RE : (func_[0-9A-Fa-f]+) as the name group
3. split_sig_string : \bfunc_[0-9A-Fa-f]+\s*\(
Each is a SILENT SKIP indistinguishable from "no conflict found". With 1+2 done the symbol reached 3
and died there; only tracing transform's internals (`callees cast: 0` while the canonical map plainly
held `s32 RotTransPers(s32, s32, s32*, s32*)`) located it. THE TRAP WORTH REMEMBERING: a partial fix
to a name-form assumption produces the exact symptom of no fix at all, so a correct hypothesis looks
refuted. Curated naming increases as RE quality improves, so any func_-only predicate is
rot-by-design — the same shape as stub_map's (Phase 26-A).
RESULT: func_8012F40C 0/137 -> 137/137. The other three families (801759D8, 80146750, 80142B2C) still
fail on different causes.
GATES: R22 clean-fleet 140 passed, 0 failed of 140; tools-health OK; dedup 1886/0; 0 NON_MATCHING.
METRICS: instr 86.7% (+4,932 ins); fn-count 91.19% -> 91.23% (+137); distinct +0 (byte-identical).
NEXT: the byte-VARIANT tier is worth re-sweeping — T70 banked 1/10 BEFORE the callee axis existed, and
26 families remain unswept by the two levers added since.
|
||
|
|
970559423d |
feat(phase-29): T77 — wire the callee-decl lever into family_sweep; func_80173A60 0/135 -> 135/135
Item 1. The T76 diagnosis was right and the fix was a lever we already owned. cast_call_sites
(§17a-1/§20) handles the callee-conflict class and lived ONLY in gate_stage, which the family sweep
deliberately does not use — the THIRD instance this session of a lever unreachable from the path that
needs it (T56 data-decl unreachable, T57 function-decl off-by-default, now T77 callee).
the 5 byte-identical families : 0/682 -> 135/682
func_80173A60 specifically : 0/135 -> 135/135
Wired after scope_data_fix (orthogonal axes: data vs callee), default ON with --no-cast-callees. Two
details that matter: the canonical map is built from the TARGET sibling's TU via cpp
(canonical_map(ov, src_file=tu) -> cdecl.tu_scope) so it sees MACRO-INJECTED declarations — a
raw-text scan returns nothing for exactly the callees that conflict (§51g LAW 7) — and it is read
AFTER any tu-scope edit is on disk.
THE OTHER FOUR STILL FAIL, different causes. And the next finding is already visible:
func_8012F40C's blocker is RotTransPers, a PsyQ LIBRARY symbol — a callee conflict the cast should
have handled. It did not, because cast_call_sites' canonical map keys on
re.fullmatch(r'func_[0-9A-Fa-f]{8}'), so NAMED PsyQ callees are structurally invisible to it. That is
a one-line predicate widening with ~270 members behind it (RotTransPers + ApplyMatrixSV families).
GATES: R22 clean-fleet 140 passed, 0 failed of 140; tools-health OK; dedup 1886/0; 0 NON_MATCHING.
METRICS: instr 86.6% -> 86.7% (+7,965 ins); fn-count 91.15% -> 91.19% (+135); distinct +0
(byte-identical — §111 predicted it).
cookbook §114 — the three decl axes, and "conflicting types for X: READ X".
|
||
|
|
d9f1ccad45 |
docs(phase-29): T76 — byte-identical families bank 0 of 682; my recommendation was wrong
I recommended this as "the only remaining item with YIELD rather than findings — pure instr yield, no
new tooling". It banked NOTHING. Recording the reasoning error plainly.
WHERE IT FAILED: "byte-identical families bank 137/137" was true of T63/T64/T65/T68/T72 — but every
one of those had a specific blocker cleared FIRST. Byte-identity predicts the template is EXACT IF IT
COMPILES; it says nothing about whether it compiles. The still-unswept families are precisely those
never unblocked, so the property selects FOR being blocked. I had written that caveat two turns
earlier ("only true after each family's blocker is cleared; T58 swept 6 and banked 1") and then
ignored it when recommending.
THE BATCH: the 13 had already been drawn down to 6 by today's work; swept 5 (skipping func_80147364,
proven the narrow-param wall in T75) -> 0 banked / 682 failed.
DIAGNOSED TWO — two different causes, NEITHER the family's own function:
func_80173A60 : conflicting types for func_80173B4C (a CALLEE)
func_8012F40C : conflicting types for RotTransPers (a PsyQ LIBRARY symbol)
Same shape as 0x80143d28's ApplyMatrixSV. That is a THIRD distinct decl axis (not the def's, not the
shared header's) and nothing in the pipeline reconciles it.
HONEST STATE OF THE FAMILY LEVER — every cheap variant now measured: h_exact cores xN (spent),
byte-identical (0/682), byte-variant (1/10), -O0 (~1/137). The mechanical family sweep is EXHAUSTED
at 86.6% instr unless the callee-decl axis is addressed.
NEXT: cast_call_sites (§17a-1/§20) is the existing lever for the callee axis and is NOT in
family_sweep's pipeline — the same "lever unreachable from this path" shape as T56, ~410 members
behind it.
|
||
|
|
862e31df10 |
fix(phase-29): T75 — reconcile_def_sig no-prototype regression; func_80147364 is the narrow-param wall
Item 3 closes with 0 banks and a real answer: both routes priced, both refused.
conform_decls (4,021 sites) : ⚠ SCALAR-NARROWING (s32->u16), NOT caller-neutral — argument
promotion changes at every call site (byte-proven on func_80175DA8).
Trades a plumbing failure for a byte failure.
§99 no-prototype (9 sites) : gated 140/140 byte-neutral, but the sweep fails with
`conflicting types ... An argument type that has a default promotion`
The second is the PHASE-15 DEAD-END reproduced: gcc-2.7.2 refuses to match a `()` no-prototype decl
against a definition with a default-promotion parameter (s8/s16/u8/u16/float). func_80147364 takes
(u16, u16). The remaining route is §43 — convert the DEFINITION to K&R so its params promote to int —
which is def-side and needs the exemplar re-matched, not a header edit.
A REGRESSION I CAUSED AND FIXED IN THE SAME TASK: the §99 header change broke reconcile_def_sig —
with the canonical now `void func_80147364()`, _merge_sig saw zero canonical params and returned the
canonical verbatim, DELETING the definition's parameters so the body referenced `param_1' undeclared
x137. A no-prototype decl constrains nothing, so it now REFUSES rather than conforms, distinguishing
`()` from `(void)` on the raw text. Verified the def keeps (u16 param_1, u16 param_2).
A §61 JUDGMENT CALL, FLAGGED: the func_80147364 header edit bought 0 banks and §61's undo law says an
edit that bought nothing gets undone. I KEPT it — `()` asserts no wrong type where `(u16, s32)` did,
it is gated byte-neutral, and it is a prerequisite for the §43 route; reverting costs another full
R22 gate for no functional gain. This is a judgment call against a documented law, Drew's to overrule.
|
||
|
|
14bc520c96 |
fix(phase-29): engine_core.h — §99 no-prototype for func_80147364 (sidesteps a 4,021-site conform)
Item 3, and the cheap route won. conform_decls' dry run priced the direct fix and warned it off:
byte-true def : void func_80147364(u16 param_1, u16 param_2)
4,021 decl sites: 2,030 (u16,s32) + 1,983 (u16 a0,s32 a1) + 4 byte-true + 4 (u16,u16)
⚠ SCALAR-NARROWING (s32 -> u16) — NOT caller-neutral; argument promotion changes at every call
site, so callers emit different code (byte-proven on func_80175DA8)
So conforming 4,021 sites would likely trade a PLUMBING failure for a BYTE failure. The §99
no-prototype form on the HEADER is compatible with both the byte-true definition and the existing
(u16, s32) prototypes, and touches 9 sites instead of 4,021:
extern void func_80147364(u16, s32); -> extern void func_80147364();
Verified: header change ALONE, no src change, R22 clean-fleet 140 passed, 0 failed of 140.
This is the T67 failure resolved — that batch failed 2/140 with because it corrected the header's TYPES while 272 TUs disagreed. Dropping the
prototype instead disagrees with nobody.
|
||
|
|
3e6c364cd8 |
feat(phase-29): T73 — items 1+2: ARITY class resolved, audit learns §113; DECLS is the last value
ITEM 1 (call-vs-address re-check). My first detector counted the DECLARATIONS as calls, so every function looked "called". Stripping `extern ...;` first gives the real split: func_80144B14 is ADDRESS-TAKEN only (full retype — done in T72, 137/137); func_8013BD34 / func_8014358C / func_8017D808 are genuinely CALLED and need §99. §99 applied to all three -> R22 clean-fleet 140 passed, 0 failed of 140, byte-neutral. SWEEP YIELD: ZERO, and recorded as such. func_8013BD34's family swept 0/136 — exactly as predicted when I switched T72's probe off it (its def lives in ov_SC07_010_o0.c and _o0 families sweep ~1/137). func_8014358C has no family as exemplar; func_8017D808's family is 1 member with an unbanked exemplar. The §99 fixes are correct and byte-neutral but unblock nothing today. ITEM 2: called_in_headers() strips declarations, treats `fn(` as a call and `&fn` as not; arity_ok is now "arity matches OR the macro never calls it" (§113). Verified against all four. THE AUDIT AFTER BOTH — 28 findings (from 61): DECLS 9 fns 141 stubbed binaries <- the only class with value left SAFE 13 fns 15 ARITY 3 fns 0 <- §99 cleared the stub-bearing ones §85 3 fns 0 func_80147364 is 137 of those 141, and is item 3. |
||
|
|
86c315ec08 |
fix(phase-29): engine_core.h — §99 no-prototype for the three CALLED ARITY functions
Item 1's payoff. §113's call-vs-address re-check found func_80144B14 was the ONLY address-taken one (already fully retyped, T72); func_8013BD34 / func_8014358C / func_8017D808 are genuinely CALLED, so their arity IS constrained by the macro's own call site and the full retype is unavailable. §99 no-prototype is the fix: `extern void func_X();` accepts the macro's fixed-arity call AND the definition's differing arity, and a no-prototype call passing the same arguments generates the same code. extern void func_8013BD34(void); -> extern void func_8013BD34(); (def takes s32 a0) extern void func_8014358C(void); -> extern void func_8014358C(); (def takes s32 param_1) extern void func_8017D808(s32, s32); -> extern void func_8017D808(); (def takes void *a0) Verified in one step per the T48 discipline: the header change ALONE, no src change, R22 clean-fleet 140 passed, 0 failed of 140. Batched three because the technique was the variable, not the targets — a bisect over three is cheap if it fails. |
||
|
|
ed95cad428 |
feat(phase-29): T72 — ARITY probe banks 137/137; most of the class was never an arity problem (§113)
Probe target switched from func_8013BD34 on measured evidence (its def is in ov_SC07_010_o0.c and
_o0 families sweep ~1/137 — a poor test of an unproven technique). func_80144B14: same class, 137
stubs, not -O0, real 34x137 family, tests both axes (void(void) -> int(int)).
THE PROBE FOUND THE PRECONDITION OVER-FIRING. The ARITY blocker exists because the macro's own CALL
SITE passes the header's arity. But DEFINE_func_* does not call func_80144B14 — it takes its ADDRESS:
*(s32 *)((s32)a0 + 0xDC) = (s32)&func_80144B14;
No call site => no arity constraint => the FULL correction is available, not the §99 no-prototype
workaround. Applied `extern int func_80144B14(int param_1);`.
RESULT: header change ALONE -> R22 clean-fleet 140 passed, 0 failed of 140 (byte-neutral); family
sweep -> 137/137, 0 failed.
METRICS: instr 86.6% (+4,658 ins); fn-count 91.12% -> 91.15% (+137); distinct-code +0 (byte-identical
family — §111 predicted it).
THE REFINEMENT (cookbook §113): the precondition must ask what the macro DOES with the symbol — a
call constrains arity, an address-taken or unused decl does not. Blocking on "both names appear"
over-fires, and it had 137 members behind it. The remaining ARITY findings should each be re-checked
for call-vs-address before assuming §99 is needed.
GATES: R22 140/140 twice; tools-health OK; dedup 1886/0; 0 NON_MATCHING (G4).
|
||
|
|
df86fcce50 |
fix(phase-29): engine_core.h — func_80144B14 declared int(int), not void(void)
The ARITY blocker did not apply: DEFINE_func_* does not CALL func_80144B14, it takes its ADDRESS (`*(s32 *)((s32)a0 + 0xDC) = (s32)&func_80144B14;`). There is no call site to break, so the FULL correction is available rather than the §99 no-prototype workaround. That is a refinement the audit needs: the ARITY precondition asks whether the macro's own call site would break, but an address-taken use has no call site. Over-fires on that shape. §85: 0 consumers, so the void->int return widening is byte-neutral. Verified in two steps (T48 discipline): header change ALONE, no src change, R22 clean-fleet 140 passed, 0 failed of 140. Fleet-shared (§61/§63), R22 mandatory. Probe target switched from func_8013BD34 on measured evidence: that one's definition lives in ov_SC07_010_o0.c, and _o0 families sweep ~1/137, making it a poor test of an unproven technique. func_80144B14 is the same class, 137 stubs, not -O0, with a real 34x137 family. |
||
|
|
3233ff3f81 |
docs(phase-29): T71 — the byte-variant stall is an AUDIT GAP, not an immediate-engine limit
The next-list item was "measure the T2a immediate-resolution rate". The log refutes that framing: of T70's 10 families only 152 members were refused at remap for unresolved immediates — 1,346 failed the GATE. The immediate engine is not the bottleneck. Diagnosed the largest failed family (0x80131eec, 15 ins x 289 members, class=IMM, cross-address): member ov_SC01_000 @ func_80151944, imm_map entries 0 (nothing to resolve), verdict PLUMBING — `conflicting types for func_80151944`, with the §85 guard correctly refusing to bend the draft. Same header-vs-byte-truth class as T63/T64/T68 — but audit_header_sigs.py never flagged it: func_80151944 definitions in src/ : 0 (a stub in all 138) declarations : 2,022 engine_core.h says : s32 func_80151944(void) byte truth (exemplar func_80131EEC): void func_80131EEC(void *a0) THE GAP: the audit compares a header decl against definitions OF THE SAME NAME and skips a function that has none. For a CROSS-ADDRESS family member the byte truth is the EXEMPLAR's definition, under a different name at a different address — so every such member is invisible to the audit while being blocked by exactly the defect the audit exists to find. That is why item 5 keeps hitting header conflicts the audit said were not there. THE EXTENSION: feed .run/family_hseq.json in, so an undefined member inherits its exemplar's signature as truth. This one would then class as ARITY ((void) vs (void *a0)) and need §99 treatment — the extension makes the blocker VISIBLE AND NAMED, not automatically fixable. No src/ or config/ change: no bank, no metric move. Tree clean. |
||
|
|
2962b01ec1 |
docs(phase-29): SESSION-24 REVISED-2 checkpoint — 1,771 banked, fleet 86.6% instr
Supersedes both earlier SESSION-24 blocks. Session total reconciled against the metric (fn-count 320524 -> 322295 = +1,771; instr +134,811), the lesson earned nine times, a ranked measured NEXT list led by the T2a immediate-rate measurement (which decides whether the 26 remaining byte-variant families are worth sweeping), my errors, carried defects. Fresh session safe from here: HEAD commit:1175, tree clean but for the R23 db.*.gbf churn, R22 clean-fleet 140/140 (run 17x), tools-health OK, dedup 1886/0, 0 NON_MATCHING. |
||
|
|
283937ed8e |
feat(phase-29): T70 — byte-variant families sweep 1 of 10 (138 banked, +130 distinct)
Item 5, first batch. Swept 10 byte-VARIANT non-jr non-O0 families (42,235 ins / 1,552 distinct projected): 138 BANKED / 1,346 failed — ONE family of ten (func_801627E8 137/137), plus 152 members skipped as "unresolved immediates (T2a)". THE FINDING: that is a ~10x worse rate than the byte-IDENTICAL families, which banked 137/137 apiece all session. It follows from what §111 established — a byte-variant member differs in more than relocations, so the template must adapt immediates too, and family_remap's T2a engine refuses what it cannot resolve. The distinct-code lever is real but it is NOT the same cheap sweep, and the projected "2,962 distinct across 36 families" should be discounted until the immediate-resolution rate is measured. That measurement is now item 1 of the next list, ahead of sweeping the other 26. §111 PASSED A SECOND PREDICTIVE TEST: projected +129 distinct for func_801627E8; observed +130 (the extra from an unrelated 2-member bank). GATES: R22 clean-fleet 140 passed, 0 failed of 140; tools-health OK; 0 NON_MATCHING (G4). METRICS: instr 86.5% -> 86.6% (+2,618 ins); fn-count 91.08% -> 91.12% (+138); distinct-code 68,066 -> 68,196 = +130 — the first real distinct-code movement of the session. |
||
|
|
a6e5abfd39 |
fix(phase-29): T69 — audit preconditions computed, not discovered; validated against known outcomes
Item 1. audit_header_sigs.py now COMPUTES the safe subset instead of leaving it to a failed gate,
and the two new preconditions took two wrong models to get right (cookbook §112).
PRECONDITION 1 — ARITY: correcting a `(void)` header decl for a 1-param definition breaks the macro's
OWN call site ("too few arguments"). Measured before the batch.
PRECONDITION 2 — VISIBLE COLLISION, and the two wrong models on the way:
(a) "any disagreeing decl in src/ blocks it" — compares type SPELLINGS, so s32-vs-int and
u32-vs-unsigned-int count as disagreements. Fixed by comparing type IDENTITY via
cdecl.compatible. Finding count 61 -> 32 once that noise is gone.
(b) "any INCOMPATIBLE decl in src/ blocks it" — STILL WRONG. It blocked ALL SIX corrections that
had just gated 140/140 and banked 685 members. func_80161774 has 1,063 TUs carrying the old
spelling and correcting it was byte-clean.
The right model: a macro-body decl is only visible where the MACRO IS INSTANTIATED, so a collision
needs a TU that BOTH instantiates the macro AND carries an incompatible decl. Measure the
INTERSECTION, not the population (macro_owners() + per-TU macro-use set).
VALIDATED AGAINST KNOWN OUTCOMES (the control this needed): the six that gated clean -> 0 colliding
TUs each; the one that failed the gate (func_80147364) -> 272. Perfect discrimination.
HONEST RESULT: 32 findings, 13 SAFE — but the safe subset is worth only 15 stubbed binaries. The
high-value targets (func_80147364 at 137, the arity trio at ~410) are all BLOCKED and need
conform_decls or §99 first. The cheap header lever is spent.
No src/ or config/ change: no bank, no metric move.
|
||
|
|
f59ae302b8 |
feat(phase-29): T68 — 6 header corrections sweep 685 members (+33,565 ins); fleet 86.5% instr
The audit was the right precondition: THREE of the six corrected functions were families already queued for the item-3 sweep, and each would have failed 0/137 exactly the way five families did earlier today. SWEEP: 6 corrected functions, all non-jr families with 137 live stubs -> 685 BANKED / 137 failed. Five families landed 137/137; func_80146750 failed on its own residual (undiagnosed). GATES: R22 clean-fleet 140 passed, 0 failed of 140 — after the header batch alone AND after the banks; tools-health OK (corpus 0 PHANTOM + 0 TRUNCATED, cdecl, audit-binaries, dedup 1886/0); 0 NON_MATCHING (G4). METRICS: instr 86.3% -> 86.5% (11338739 -> 11372304 = +33,565 ins); fn-count 90.88% -> 91.08% (321472 -> 322157 = +685); distinct-code 76.9% -> 76.9% (+0). §111 GOT ITS FIRST PREDICTIVE TEST AND PASSED: all six families have a single h_exact class, so the model predicted +0 distinct BEFORE the sweep ran, and +0 is what happened. The metric is modelled, not mysterious. |
||
|
|
0c5df25faf |
feat(phase-29): T67 — audit_header_sigs.py; 61 header decls contradict byte truth, 6 corrected
THE TOOL (tools/audit_header_sigs.py, cookbook §112). A DEFINE_func_*() macro forward-declares the
functions its body calls, and that decl is visible in EVERY overlay instantiating the macro — so when
it disagrees with the byte-true definition the whole family becomes untemplatable and the failure
wears a compiler wall's clothes. Three such were found ONE AT A TIME earlier this phase
(func_80156044, func_8016163C, func_8014D610), each worth ~137 members, each costing a
diagnose/fix/re-sweep cycle. This audits all of them in one pass: parse every `extern func_X(...)` in
src/shared/*.h, find every DEFINITION in src/**/*.c (via §110's _def_head_at, not "ends in ;"),
compare with cdecl, and report only where NO definition agrees — one overlay disagreeing is loose
typing (§16/T49), all of them disagreeing means the header is the outlier.
RESULT: 3,043 decls across 1,023 functions; 265 have definitions; 61 contradict every one. The top 10
are full-fleet families (137/136/134 live stubs, 1,366 total), all with an unambiguous byte truth.
APPLIED: 6 functions / 11 decl sites, R22 clean-fleet 140 passed, 0 failed of 140 —
func_80138DE0, func_80146750, func_80161374, func_80161774, func_80161888, func_801778A8.
TWO PRECONDITIONS THE AUDIT DOES NOT YET CHECK, both found by gating rather than by reasoning:
1. ARITY. func_80144B14 / func_8013BD34 / func_8014358C declare (void) but are DEFINED with one
parameter. Correcting the header would break the macro's OWN call site (too few arguments), so
they need the §99 no-prototype treatment instead. Excluded before the batch, by measurement.
2. OTHER IN-SCOPE DECLS. The first batch of 7 FAILED the gate 2/140 with `conflicting types for
func_80147364` — the overlays' own TUs declare it the old way (9 header sites rewritten, but
src/ov_*/…:347 disagrees). A header correction is only safe when no other in-scope declaration
disagrees; that one additionally needs a conform_decls pass. Excluded; the other 6 then gated
140/140 clean.
The gate caught the bad batch immediately and the culprit was found by reading one object's real cc1
output rather than by a 7-way bisect (7 fleet gates = ~2.5h; one serial compile = seconds).
|
||
|
|
a6f6ccf545 |
docs(phase-29): T66 — item 4: the distinct-code anomaly modelled and closed (it was never a bug)
Seven sweeps moved distinct-code by +125/+125/+129 and +0 four times; I had logged it four times as
"unexplained, still not guessed at". Modelled in one pass:
delta_distinct = (distinct h_exact classes in the family) - (classes already matched)
weighted_metrics counts distinct h_exact classes with >=1 matched instance. EXACT on all 7, no
residual: func_80135260 131-6=125; func_80133AB0 131-6=125; func_80156044 130-1=129; the four +0
families have EXACTLY 1 class across all 138 overlays (every member byte-identical), already matched
via the exemplar.
IT IS A REAL SIGNAL, NOT NOISE. A byte-IDENTICAL family is ONE piece of distinct code — the
exemplar's crack already reconstructed it, so the other 137 banks pay fleet/instr in full (each
binary now builds from source instead of pasted asm) but add NO new reverse-engineering. A
byte-VARIANT family is ~130 genuinely different functions and pays both. The two headline metrics
rank the same work differently, and both are now predictable BEFORE spending a sweep.
THE REMAINING FRONTIER, PRICED BOTH WAYS (49 eligible non-jr families):
byte-identical 13 families 80,085 ins 0 distinct
byte-variant 36 families 114,331 ins 2,962 distinct
total 49 194,416 ins (~1.48 pp instr)
MY OWN BUG, CAUGHT BY VERIFYING (R14): my first ranking reported ALL 49 families as byte-identical /
0 distinct yield. Defect in my probe — I wrote int(x,16) on the member address in one comprehension
and forgot it in the next, so every sig lookup missed and every family collapsed to one class. Caught
only by spot-checking two entries against a direct count (func_80143D28 is 130 classes, not 1). Had I
reported it, the conclusion "the entire remaining harvest is worthless for distinct-code" would have
been exactly backwards for 36 of 49 families.
cookbook §111, with §106 applied: the ranking is two lines over the sigs, so it is derivable on
demand and deliberately NOT committed as a table that rots.
No src/ or config/ change: no bank, no metric move.
|
||
|
|
350cc1c34c |
docs(phase-29): T63-T65 + SESSION-24 REVISED checkpoint — 948 banked, fleet 86.3% instr
Items 1-3 all landed 137/137 (func_8016163C, func_8014D610, func_80156044) for +30,962 ins; both
header flips byte-neutral and proven in two steps; §110 records the extract_unit definition-detection
law and the two traps in its assertion.
Full 🛑 checkpoint refreshed (the earlier SESSION-24 block predates T59-T65 and is superseded):
state, session total reconciled against the metric (fn-count 320524 -> 321472 = +948, +98,628 ins),
the one lesson earned seven times, a ranked measured NEXT list, my errors, carried defects.
Fresh session safe from here: HEAD commit:1169, tree clean but for the R23 db.*.gbf churn, R22
clean-fleet 140/140, tools-health OK, dedup 1886/0, 0 NON_MATCHING.
|
||
|
|
ec34c31b68 |
feat(phase-29): T65 — extract_unit definition-detection fixed; func_80156044 137/137 (+10,138 ins)
Item 3, and it banked the third family. extract_unit located a definition with "the line matches
<type> func_<addr>( and does not end in `;`" — wrong whenever ONE LINE holds both a declaration and a
definition, which the handwritten inline-asm wrappers do:
extern void func_80156044(int, int); int func_80155FF8(int, int) { __asm__ … }
The line does not end in `;`, so func_80156044 — appearing there only in the DECLARATION — was taken
as a definition head. extract_unit lifted the neighbouring WRAPPER instead of the real definition
seven lines below; every sibling already defines that wrapper via its shared DEFINE_ macro, so all
137 failed with `redefinition of func_80155FF8` and it read as a compiler wall.
FIX: ask what follows the PARAMETER LIST, not what ends the line (`_def_head_at`) — `;` is a
declaration, `{` or end-of-line is a definition. Plus the R32 assertion: a unit that defines a
function other than its target cannot template, so refuse LOUDLY (`_foreign_defs`).
TWO TRAPS HIT WHILE WRITING THAT ASSERTION, both caught by regression-checking against families known
to bank: (1) _def_head_at ALONE over-fires — a call whose args wrap has nothing after the `(` on its
line, which "end of line => definition" reads as a definition; it refused THREE families that had
just banked 137/137. (2) The type-prefix test ALONE under-fires — it is what missed the wrapper
originally. The predicate needs both: split the prefix on its last `;`, require the remainder to look
like a return type, then check what follows the parameter list. All five known-banking families
extract byte-identically before and after.
RESULT: func_80156044 0/137 -> 137/137, 0 failed.
GATES: R22 clean-fleet 140 passed, 0 failed of 140; tools-health OK (corpus 0 PHANTOM + 0 TRUNCATED,
cdecl, audit-binaries, dedup 1886/0); 0 NON_MATCHING (G4).
METRICS: instr 86.2% -> 86.3% (11328601 -> 11338739 = +10,138 ins); fn-count 90.84% -> 90.88%
(321335 -> 321472 = +137); distinct-code 76.7% -> 76.9% (67937 -> 68066 = +129).
cookbook §110.
|
||
|
|
60f9ac40f3 |
feat(phase-29): T64 — func_8014D610 swept 137/137 after the header correction (+10,138 ins)
Item 2, and the same story as item 1: the header correction WAS the fix. With engine_core.h declaring the byte truth, the family swept 137/137 with zero failures — no draft change. before (header wrong) 0/137 `conflicting types` / a param-retyped body that could not compile after (header right) 137/137, 0 failed GATES: R22 clean-fleet 140 passed, 0 failed of 140; tools-health OK (corpus 0 PHANTOM + 0 TRUNCATED, cdecl, audit-binaries, dedup 1886/0); 0 NON_MATCHING (G4). METRICS: instr 86.1% -> 86.2% (11318463 -> 11328601 = +10,138 ins); fn-count 90.81% -> 90.84% (321198 -> 321335 = +137); distinct-code 76.7% -> 76.7% (+0 — a SIXTH data point for the anomaly). |
||
|
|
3c380fec83 |
fix(phase-29): engine_core.h — func_8014D610 declared s32(s32,s32,u16*), not void(s32,void*,void*)
Same class as func_80156044 and func_8016163C: the shared header contradicted the byte truth. The
exemplar's banked definition is `s32 func_8014D610(s32 param_1, s32 param_2, u16 *param_3)`
(ov_SC07_006_jr_80140608.c:4576); DEFINE_func_8014D438 declared
`void func_8014D610(s32 a0, void *a1, void *a2)`.
That mismatch is what made --fix-def-sig retype param_3 to `void *` while the body does
`param_3[0]` -> `void value not ignored as it ought to be` (T61's param-use guard now refuses it,
naming the header as the real fix — this is that fix).
§85 sized first: 0 callers consume the return. The macro's call site passes `s16 buf1[4]`/`buf2`
into the s32/u16* params — same 4-byte values in $a1/$a2, so the retype is a warning, not a codegen
change.
Verified in two steps (T48 discipline): the header change ALONE, no src change, R22 clean-fleet ->
140 passed, 0 failed of 140. Fleet-shared (§61/§63), so R22 was mandatory.
NOTE: ov_SC07_006_jr_80140608.c:4529 records an earlier, DIFFERENT resolution of the same conflict —
a per-overlay de-macroized local decl ("do NOT re-macroize"). That remains correct and untouched;
this fixes the shared decl the other 137 overlays see.
|
||
|
|
a850255572 |
feat(phase-29): T63 — func_8016163C swept 137/137 after the header correction (+10,686 ins)
Item 1. The header flip (commit:1163's sibling, committed just before) was the whole blocker: with engine_core.h declaring the byte truth, the family swept 137/137 with ZERO failures — no draft change, no new lever. before (header wrong) 0/137 `conflicting types` / a --fix-def-sig-truncated draft after (header right) 137/137, 0 failed GATES: R22 clean-fleet 140 passed, 0 failed of 140; tools-health OK (corpus 0 PHANTOM + 0 TRUNCATED, cdecl, audit-binaries, dedup 1886/0); 0 NON_MATCHING (G4). METRICS: instr 86.0% -> 86.1% (11307777 -> 11318463 = +10,686 ins, exactly 137 x 78); fn-count 90.77% -> 90.81% (321061 -> 321198 = +137); distinct-code 76.7% -> 76.7% (+0). The distinct-code anomaly now has FIVE data points (T52 +125, T57 +125, T56 +0, T58 +0, T63 +0) and still no identified variable. Unchanged as the queued probe. |
||
|
|
2d91ed54fb |
fix(phase-29): engine_core.h — func_8016163C declared s32(s32,u32), not void(void*,s32)
The shared header contradicted the byte truth. The exemplar's banked definition is `s32 func_8016163C(s32 arg0, u32 arg1)`; both DEFINE_ macro decl sites said `void func_8016163C(void *a0, s32 a1)`. That mismatch is why the family could not template, and it is what made --fix-def-sig DEMOTE the return to void — gcc then deleted the computation feeding it and the draft compiled to 58 instructions against a 78-instruction target (T62's self-inflicted SIZE-MISMATCH). §85 sized first: conform_decls.consumers(func_8016163C) = 0 — both macro call sites discard the return (`func_8016163C(a0, func_801615C4(a0, 0));`), so the return-axis flip is byte-neutral. Verified in two steps (T48 discipline): the header change ALONE, no src change, R22 clean-fleet `make clean && extract-all && check-all` -> 140 passed, 0 failed of 140. Fleet-shared edit (engine_core.h reaches all 138 overlays), so R22 was mandatory (§61/§63). |
||
|
|
610a13c21c |
fix(phase-29): T61/T62 — items 1-4; all three families converge on one root cause (the shared header)
0 banked. Four tool fixes, one byte-neutral header correction (committed separately), and the three
families resolve to a SINGLE root problem — plus a defect I introduced and caught by measuring.
FOUR TOOL FIXES, each verified by a verdict MOVING rather than by assertion:
1. gather_externs prefers FILE-scope decls. Its contract says "file-scope extern decls" but
`^[ \t]*extern` also matches an INDENTED one — a block-scope decl inside some OTHER function, not
even in scope at the exemplar's own definition. Carried to file scope in the sibling,
`extern void func_80155FF8(void *, u8);` (ov_SC01_077 L1213) landed above that sibling's
DEFINE_func_80155FF8() macro and collided. ORDERED, not filtered — an indented decl stays the
fallback it always was, so a symbol declared only block-scope is unaffected.
2. reconcile_def_sig keeps the BODY's param names (the T60 fix, cookbook §109).
3. §85 return-axis precondition — refuses when callers consume the return (reuses
conform_decls.consumers, R33).
4. Param-use guard — refuses to retype a parameter the body indexes/dereferences (func_8014D610's
header says `void *a2` where the byte truth is `u16 *param_3` and the body does param_3[0]).
A DEFECT I INTRODUCED, CAUGHT BY MEASURING: func_8016163C read as a clean DIFF after T60 and I
reported it as "genuine codegen". It is not. match_one says SIZE-MISMATCH: draft 58 ins vs target 78
(delta -20, ratio 0.74, bucket redraft). Both overlays are 78 ins and extract_unit is fine —
--fix-def-sig demoted the return s32 -> void and gcc deleted the computation feeding it as dead. My
§85 check only asked whether CALLERS consume the return, never whether the BODY returns a value. The
tool manufactured a different-sized function and the verdict blamed the draft. Guard added. A "clean
DIFF" appearing right after a transform is a suspect, not a result.
THE CONVERGENCE: engine_core.h declares all three with types that contradict the byte truth —
func_80156044 int vs void (FIXED, byte-neutral, R22 140/140), func_8016163C void vs s32,
func_8014D610 void(s32,void*,void*) vs s32(s32,s32,u16*). Both remaining flips measure 0 §85
consumers. The fix is to correct the HEADER, not to bend the drafts.
AND ONE MORE LAYER: with its header fixed, func_80156044's verdict moved to `redefinition of
func_80155FF8` — extract_unit lifted a unit spanning TWO definitions and the sibling already defines
the wrapper via the shared macro. A unit-boundary defect, a fourth distinct cause. Three fixes peeled
three layers off one family.
|
||
|
|
51bac9f3e6 |
fix(phase-29): engine_core.h — DEFINE_func_80155FF8 declares func_80156044 void, not int
The exemplar's own @stuck note asked for this (ov_SC01_077_jr_80154C24.c L1349-1350): the handwritten func_80155FF8 wrapper calls func_80156044 via inline-asm `jal`, so nothing consumes the return, and ov_SC01_077 already declares it `void` inline — the MACRO was the outlier. §85 precondition measured before touching it: conform_decls.consumers(func_80156044) = 0 callers consume the return, so the return-axis flip is byte-neutral. Verified in two steps (T48 discipline): the header change ALONE, with no src change, R22 clean-fleet `make clean && extract-all && check-all` -> 140 passed, 0 failed of 140. Fleet-shared edit (engine_core.h reaches all 138 overlays), so R22 was mandatory (§61/§63). |
||
|
|
50a108b5a8 |
fix(phase-29): T60 — reconcile_def_sig name bug fixed (verdicts moved); 0 banked, three causes separated
Tool fix + a sharper diagnosis. NO BANKS — the three "header-conflict" families share a SYMPTOM, not
a cause.
THE FIX (cookbook §109): reconcile_def_sig now conforms the canonical TYPES and keeps the BODY's
parameter names, parsed with cdecl (base/params/pnames, R33 — not a regex). Two re-render traps
handled: `void*` + `a1` -> `void *a1` (cdecl glues stars to the type), and an EMPTY parameter list is
handed back verbatim because `(void)` and `()` both parse to params==[] and are DIFFERENT
declarations (§99 no-prototype). Unit-tested across 6 shapes incl. both void forms and an arity
mismatch; falls back to the wholesale canonical string for fn-ptr/array params.
THE FIX IS REAL, AND THE PROOF IS THAT THE VERDICTS MOVED:
func_8016163C `param_1 undeclared` -> DIFF (plumbing CLEARED; codegen left)
func_8014D610 `param_1 undeclared` -> `void value not ignored` (the HEADER is wrong)
func_80156044 unchanged -> `conflicting types for func_80155FF8` (WRONG LEVER — callee conflict)
TWO FINDINGS UNDER THAT:
1. The §85 return-axis precondition applies to reconcile_def_sig and NOTHING CHECKS IT. Conforming a
def's return to the canonical `void` is only safe when no caller consumes the return.
func_8014D610's callers do, so engine_core.h's `void` contradicts the byte truth and conforming
yields `void value not ignored`. The HEADER is the wrong artifact; correcting it is fleet-shared
blast radius (§61/§63), not a sweep-time fix.
2. func_80156044 was never the def-signature class — its conflict is on the CALLEE func_80155FF8
(decl 2 lines above the splice). That is cast_call_sites / canon_sig_reconcile territory.
HONEST ACCOUNTING: re-swept all three with the fix -> 0/411, tree clean throughout. The lever is now
correct (it no longer manufactures a false compile failure) but it was ONE of three causes, not the
cause. My T59 write-up grouped them as a single ~30,000-instruction block; that grouping was WRONG,
and what disproved it was re-reading each verdict after the fix rather than re-running the batch and
reporting the total.
No src/ or config/ change: no bank, no metric move.
|
||
|
|
28ef237c35 |
docs(phase-29): T59 — the five T58 zero families diagnosed: four causes, one wall
Deliverable is the diagnosis, not banks. Method: splice ONE member, `make -j1` the single object,
read the NON-warning cc1 lines (-j16 interleaves the real error away; the §58 memcpy / "type
mismatch" warnings dominate any naive tail; §93 pipefail names the wrong stage). Tree clean after
every probe.
CORRECTION TO MY OWN T58 REPORT (R14): I said "7 remaining families all have banked exemplars".
WRONG — there were 5. 0x80175820 (276 members) and 0x8016ec0c (138) have NO matched exemplar
anywhere: INCLUDE_ASM stubs in all 138 overlays. My batch-selection test picked the first TU
CONTAINING THE NAME (a declaration) and, seeing no stub in that file, called it banked. The family
map was right all along (kind='draft-ov077', matched_members=[]) and family_sweep correctly excluded
them ("6 matched-exemplar families" — a line I read past). Use corpus.stubs(ov), never a name-grep.
Their claimed 109,296 bytes were never real fuel.
THE FIVE VERDICTS:
0x8014d610 137 PLUMBING shared-header signature conflict
0x8016163c 137 PLUMBING shared-header signature conflict
0x80156044 137 PLUMBING shared-header signature conflict
0x80143d28 136 PLUMBING conflicting types for ApplyMatrixSV (a PsyQ library symbol)
0x801457a4 137 DIFF compiles clean, bytes differ — the ONLY genuine codegen wall
THE HEADER-CONFLICT CLASS (3 families / 411 members ~ 30,000 ins) + A THIRD OPT-IN LEVER. The
"previous declaration" line was the tell: for func_8014D610 it points at line 1727, which is NOT a
declaration — it is DEFINE_func_8014D438(), a shared-macro instantiation whose expansion
forward-declares the templated fn with the canonical engine_core.h signature. All four conflicting
fns are header-declared; the two non-header families are exactly the two with different verdicts.
--fix-def-sig is the lever (a THIRD opt-in one, after T56's unreachable and T57's off-by-default).
Tested: 0/411, and the verdict did NOT move to DIFF — it moved to a precise new compile error:
canonical : void func_8014D610(s32 a0, void *a1, void *a2)
draft body: ... param_1 ... -> `param_1' undeclared
reconcile_def_sig adopts the canonical signature WHOLESALE (types AND param names) while the body
keeps the exemplar's param_N names. Its docstring calls this a "rare name mismatch"; it is not rare —
an exemplar drafted with the param_N convention hits it every time. Fix: conform TYPES, keep BODY
names (both are in hand at the call site).
THE PATTERN, THREE TIMES IN ONE SESSION: T56 a lever unreachable from the sweep path, T57 a lever off
by default, T59 a lever subtly broken. Every family-wide 0/N so far has been a statement about the
HARNESS, not the code. cookbook §108 records the recipe + the four causes.
No src/ or config/ change: no bank, no metric move.
|
||
|
|
fa6d9c88e6 |
docs(phase-29): SESSION-24 final checkpoint — 537 functions banked, fleet 86.0% instr
Full 🛑 checkpoint block per the checkpoint-before-pause discipline: state, session total reconciled
against the metric (fn-count 320524 -> 321061 = +537, +67,666 ins), the three strategic changes, a
ranked measured NEXT list, my errors, and the carried defects (now incl. the Jul-21 autopsy corpus).
Fresh session is safe from here: HEAD commit:1159, tree clean but for the R23 db.*.gbf churn, R22
clean-fleet 140/140, tools-health OK, dedup 1886/0, 0 NON_MATCHING.
|
||
|
|
2d7694ba2d |
feat(phase-29): T58 — 8-family batch: 1 of 6 banked (func_8012A1BC 137/137, +10,686 ins)
Ran the batch with the T57 recipe (--band all --normalize-self-decls, live stubs derived from src/ not the stale map). 6 of 8 selected (two still filtered — selection line read this time). 821 candidate members across 6 families BANKED 137 — func_8012A1BC (78 ins) 137/137 failed 684 — the other FIVE families banked 0 each Attribution from git diff (137 x func_8012A1BC), not the per-group log lines whose split-name field my first aggregation mangled. THE SHAPE OF THE REMAINING FRONTIER — the finding. Across T56->T58 the per-family outcome is BINARY and near-total: a family banks ~137/137 or ~0/137, nothing in between. And each 0/N so far has had its OWN distinct cause — DATA decl scope (T56), FUNCTION decl scope (T57), jtbl table-count drift (func_8014032C), plus five more undiagnosed here. The mechanical lever is done pulling by itself: from here each family costs one diagnosis. A batch is now a DIAGNOSIS QUEUE, not a harvest, and the next phase of this work should be planned on that economics. GATES: R22 clean-fleet 140 passed, 0 failed of 140; tools-health OK (corpus 0 PHANTOM + 0 TRUNCATED, cdecl, audit-binaries, dedup 1886/0); 0 NON_MATCHING (G4). METRICS: instr 86.0% (11297091 -> 11307777 = +10,686 ins); fn-count 90.73% -> 90.77% (+137); distinct-code 76.7% -> 76.7% (+0). The distinct-code anomaly now has FOUR data points and still no explanation: T52 +125, T57 +125, T56 +0, T58 +0. All four families are PURE; the exemplar overlay does not separate them either (T56 and T57 both templated from ov_SC01_077 and disagree). Two behaviours, no identified variable. Still not guessed at — it stays the queued probe. |
||
|
|
cbc5665fd8 |
feat(phase-29): T57 — func_80133AB0 132/132 (+18,084 ins); a SECOND opt-in lever found; fleet 86.0% instr
First batch off the 64-family list. Fleet crosses 86.0% instr-weighted.
TWO OF MY OWN ERRORS, both caught by measuring:
1. Three of five targets never ran — --band defaults to `substantial` (nins>=80) and I picked three
at 79/78/78. The tool printed "2 matched-exemplar families" and I nearly read that as "5
attempted, 3 refused". Read the SELECTION line, not the intent.
2. Stale map: .run/family_hseq.json was regenerated in T55, BEFORE T56 banked func_80144090, so it
still listed 134 live stubs for a now-complete family. Membership is stable (h_seq over original
bytes); only the matched/unmatched split rots. Filter live stubs from src/, not from n_matched.
THE FIRST RUN WAS 0/268 — AND IT WAS A SECOND OPT-IN LEVER, NOT A WALL. Diagnosed one sibling past
the -j16 interleave and the §58 warning noise: `conflicting types for func_80133AB0` (spliced def at
2688 vs a decl at 2429) — the FUNCTION decl-conflict class, not the DATA one T56 fixed. That is
exactly what --normalize-self-decls exists for (the sibling's own caller declares the member in a
different C form than the exemplar's, which used a fn-ptr cast) — and it is OPT-IN, so it never ran.
Re-ran the identical two families with it: 0 -> 132 banked.
0x80133ab0 (137 ins, jr_8012ACE0) 132/132 BANKED
0x80143d28 (80 ins, jr_80140608) 0/136 — a different, undiagnosed blocker
THE PATTERN, TWICE IN A ROW: T56 the DATA decl lever was unreachable from the sweep path; T57 the
FUNCTION decl lever is reachable but OFF BY DEFAULT. Both present as a flat 0/N that reads exactly
like a compiler wall. A 0/N from a sweep is a statement about which levers were enabled, not about
the code.
GATES: R22 clean-fleet 140 passed, 0 failed of 140; tools-health OK (corpus 0 PHANTOM + 0 TRUNCATED,
cdecl, audit-binaries, dedup 1886/0); 0 NON_MATCHING (G4).
METRICS: instr 85.8% -> 86.0% (11279007 -> 11297091 = +18,084 ins); fn-count 90.69% -> 90.73% (+132);
distinct-code 76.4% -> 76.7% (67812 -> 67937 = +125).
SHARPENS the T56 anomaly rather than resolving it: 132 banked here moved distinct-code +125, and
T52's 132 also moved it +125 — but T56's 136 moved it +0. Three PURE families, two behave one way
and one the other. Still unexplained, still not guessed at.
|
||
|
|
56e2d808ab |
feat(phase-29): T56 — wire the tu-scope lever into family_sweep; func_80144090 0/136 -> 136/136
T55's two-part next step as one job. +20,944 instructions banked. 1. THE LEVER WAS UNREACHABLE FROM THE PATH MOST FAMILIES USE (cookbook §107) §103 was wired into jtbl_family_bank only (T53), and that tool runs for has_mid_jr families. Everything else sweeps through family_sweep, which gates via PLAIN harvest_verify by design — so the lever existed, was byte-proven, and most families could not reach it. The symptom was indistinguishable from a compiler wall: func_80144090 swept 0/136 with `conflicting types for D_800A651C`. Why it does not violate the plain-harvest_verify rule: that rule exists because gate_stage's transforms PERTURB A CORRECT DRAFT (§19/T3). The tu-scope never touches the draft — it moves a DECLARATION IN THE TARGET TU. The test is not "is it a transform" but "does it change the draft?" Reused the existing undo instead of inventing one: family_sweep already snapshots TUs it edits at staging time (--normalize-self-decls) and reverts on a final MISMATCH (not byte-neutral) AND on a zero-bank group (§61 undo law — no dead diff). The tu-scope shares that dict and inherits both backstops; renamed nsd_snapshots -> tu_snapshots. Default ON with --no-tu-scope to A/B it (the T24 --allow-pins precedent): byte-neutral by construction, a no-op when nothing collides, auto-reverted when it buys nothing. 2. THE DUPLICATE-DECL REFUSAL RELAXED — AND IT DID NOT MATTER scope_tu_externs refused N>1 file-scope decls as "ambiguous"; duplicate-IDENTICAL externs are legal C, so N identical decls are one decl written N times. Now compares whitespace-collapsed forms and refuses only on genuine disagreement. MEASURED, and my hypothesis was WRONG: D_800B9A02 is 3 decls in 2 DIFFERENT forms, so it was correctly refused all along — the family banked 136/136 without it. RESULT: func_80144090 0/136 -> 136/136, 0 failed, with NO change to any draft. GATES: R22 clean-fleet 140 passed, 0 failed of 140. tools-health OK (corpus 0 PHANTOM + 0 TRUNCATED, cdecl, audit-binaries, report/lint/dedup 1886/0). 0 NON_MATCHING (G4). METRICS (reconciled against make report): instr-weighted 85.7% -> 85.8% 11258063 -> 11279007 = +20,944 ins fn-count 90.65% -> 90.69% 320656 -> 320792 = +136 distinct-code 76.4% -> 76.4% +0 (67812 unique, UNCHANGED) FLAGGING the third row rather than explaining it away: 136 banked functions moved distinct-code by ZERO, where T52's 132 moved it by +125, and both families are classed PURE. I do not have a verified cause and will not invent one — either a real property of this family or a gap in the metric. Worth one probe before that number is quoted again. |
||
|
|
bcd44badc9 |
fix(phase-29): T55 — frontier re-mapped; 2 families swept, 0 banked, both blockers diagnosed to the line
Honest result: NO YIELD. What it produced is a re-measured frontier, a real fix to my own T53 work,
and both failures diagnosed rather than left as "0/N".
FRONTIER RE-MAPPED (T52's +132 moved it): family_hseq -> 2,647 target families, 513 substantial,
64 with a banked exemplar AND live stubs. Caveat recorded: the top two by byte-weight (0x8013c414
180KB, 0x8013c0f8 84KB) are -O0, and _o0 families are already measured at ~1/137 — do not be drawn
by their weight.
FAMILY 1 func_8014032C (183 ins x 136 ~ 25,000 ins): sample 0/8, last_err empty. Read one sibling's
real gate result (§53/§59) past the -j16 interleave and the §58 memcpy red herring — TWO causes:
(1) conflicting types for D_80115128 — the T48/T51 class, which tu-scoped should have caught;
(2) jtbl_rodata_pads "more rodata .align than pad specs — table-count drift vs the carve", a
DISTINCT class jtbl_family_bank's own comment documents as NOT isolate-fixable (§91 --like
role trap).
After fixing (1): still 0/8. Cause 2 is the live blocker — carve work, not decl work. NOT ground
further; it is a documented wall.
THE T53 DEFECT, FOUND AND FIXED: contested() scanned only the draft's BLOCK-scope externs, because
T51's motivating family had them hand-written in the body. But gather_externs carries decls in at
FILE scope, and those are exactly the ones scope_data_externs.fix DROPS when the TU already declares
the symbol — its give-up branch, the fatal case the lever exists for. Measured: scope_data_fix
dropped 3 symbols while contested() returned []. So the stage never fired on its own class. Now
scope-independent; regression-checked against T51's case using the pre-T51 TU from git (old ==
new, added []), and it now finds D_80115128 on the T55 target.
FAMILY 2 func_80144090 (154 ins x 136 ~ 21,000 ins), chosen because has_mid_jr=False avoids the
carve: 0/136. Diagnosed: conflicting types for D_800A651C (2210 vs 379) — the SAME class.
family_sweep gates via PLAIN harvest_verify by design, so it never sees the tu-scoped lever, which
lives only in jtbl_family_bank. Probed: the lever would move D_800A651C + D_800AF648 (deletion-only)
and REFUSES D_800B9A02 as "3 file-scope decls above (ambiguous)" — an over-conservative refusal,
since duplicate-IDENTICAL externs are legal C.
THE FINDING: the same decl-scope collision class gates the frontier's mechanical families — it cost
T52's family 133 of 137 siblings, and it blocks both families probed here. The lever exists and is
byte-proven; it is not reachable from the sweep path most families use.
No src/ or config/ change: no bank, no metric move. Tree verified clean after every probe.
|