- THE TOUR (Drew driving the retail debug menu; mode-7 hammer over the Redux web API):
all 28 script modules captured live at four byte-verified per-chapter slots
(SC03/73-79 @0x801EF468 ch2-period, SC03/132-138 @0x801E25E8 ch3, SC04/24-30
@0x801E7B28, SC05/23-29 @0x801ED988); the routing law: debug-menu AREA selects the
chapter, each CITY interior streams its own module (member k <-> interior k).
md_MAIN_011/DISELECT byte-proven 24,236/24,240 in RAM; slots A/B/boot R34-verified live.
- MAIN/3 DISCOVERED: the main-menu module (id 0x39, 121,884 B), mis-bucketed as data by
BOTH audit oracles; live byte-proven @0x800CEDF8 (42,632-B exact prefix); onboarded.
- 29 onboardings BYTE-IDENTICAL on first build -> fleet 212; R22 212/212 after three
md_MAIN_003 catches: the A4 DsMix leak; an extract-order-sensitive splat boundary
(bytes: a 1-word data sentinel in .text + fn at +4 -> pinned in symbols file);
corpus.stubs now treats D_*/jtbl_* INCLUDE_ASM as blob includes (mirrors progress.py)
- module-id census (offline, disc-wide): 77 id-law code payloads, 0 further misses;
SC03/55 = confirmed DATA. audit-disc: UNCLAIMED 34 -> 6, residue 0 — the 6 carry
byte-checked negative evidence; next tier = the CD-read tracer
- docs: memory-map §S45 (slots + routing + debug-menu ops), disc-completeness S45
addendum, decision-log R31 entry, docs/debug-menu-list.txt (Drew's transcription)
- .run/s45 evidence allowlisted (tour logs/scripts/rosters); 104 ram dumps LOCAL-ONLY
- new baseline: 93.8% instr / 95.68% fn / 87.2% distinct over 212
- func_8017C6F4 FINAL for this session: hand 63 -> ILS 42 (pin-free seed, masked 44, flat over 8
warm restarts) -> ILS 41 (pin-t5 seed, masked 43, flat over 5). Best draft
.run/s43/func_8017C6F4.ils43-pin.c (closeness 41), logged + allowlisted. Both basins are now
MEASURED FLAT — do not re-run the ILS on these seeds; next levers are §148-C by hand, then Fable5.
- .gitignore: allowlist .run/s43/*.py + *.json so the refutation evidence (probe_leftovers.py,
leftover_probe.json) is preserved, not one `git clean` from gone (R20, the S42 lesson).
- S43 checkpoint block refreshed at the top of the file: the four instrument defects as one table,
the one number that moved, the resume list (with "26 unpropagated members" struck as refuted),
the harvest_verify import hazard, and my four process errors.
- THE FLOOR MOVED: permuter_ils on the S42 draft -> masked 65->44 (cycle 1, flat over 5 warm
restarts); re-measured in match_one terms 63 -> 42 mismatched, 947/947 ins. First movement
after ~40 hand probes, and it came from repairing an instrument (S43-1), not from new C.
Draft preserved + allowlisted: .run/s43/func_8017C6F4.ils44.c; logged at closeness 42.
- THE S42 "rumour" CLAIM WAS WRONG (R14): the 2026-07-01 row HAS an artifact, it IS on disk,
and it reproduces exactly (14 mismatched of 15 target ins, SIZE-MISMATCH/redraft). It is a
near-worthless draft on a DIFFERENT BODY: 0x8017C6F4 is 15 ins in ov_SC03_010/011/013 and
948 ins in ov_SC03_126/003 + ov_SC04_021 + ov_SC05_019 (§148-E, ledger side).
- THREE ledger defects fixed: (1) load_best keyed on ADDRESS ALONE -> the two bodies merged and
the lower ABSOLUTE closeness won, so 14-of-15-wrong (7% correct) masked 63-of-947 (93%);
now sub-keyed by known nins, legacy rows unchanged. (2) binary=null defaulted to ov_SC01_077,
where the fn does not exist AT ALL, and "not an open stub" was read as "banked" -> today's
result was invisible to render/grinder/target-selection (absent != done, R32/R34); now derive
binary from the draft path + only drop when closed everywhere it exists. (3) `log` had NO
--binary flag -- the root cause of every null; added + derived in append_record.
- IMPACT DERIVED, NOT ASSERTED (R37): replaying the pre-fix selection = 836 -> 837, 1 appeared
(func_8017C6F4 nins=947), 0 vanished. One row today; the mechanism would eat every future one.
- PROBED AND NOT BUILT: relative-closeness ranking (only 24/836 rows carry closeness+nins, and
the two orderings agree 14/15 on those). Documented in the log instead.
Answering "did you bank the results": the two serial functions did NOT match, so there was nothing
to bank (G3 -- NEAR is not a match). Everything that DID match this session is already banked and
committed (7 from the S4 redo, 24 wave exemplars + propagations, both giants x138).
But the drafts were about to be LOST, which is worse than not banking them:
.run/s42/ov_SC01_077/func_8017C294.c NEAR(12) of 246 ~245k subagent tokens
.run/s42/ov_SC03_126/func_8017C6F4.c NEAR(63) of 947 ~434k subagent tokens
.run/s42/ov_SC03_126/func_8017C6F4.pin-t5.c NEAR(47), pinned variant
All three were gitignored -- one `git clean` from gone (R20: commit irreplaceable work). Added a
curated /.run/s42/ allowlist and committed them. They are the best base any future attempt has:
func_8017C6F4 has frame 0x120 + vars=232 EXACT with only a register rotation left, and its permuter
has never been aimed at it (make_base_c fails on the gte_ macro block -- demacroize first).
Both logged to the backlog with today's MEASURED values, class, reach and draft path.
⚠️ LEDGER INTEGRITY, flagged not silently fixed: the backlog already held
`func_8017C6F4 closeness=14` (2026-07-01, ov_SC03_010, source=bulk-harvest) -- BETTER than today's
63, but with **draft: None, klass: None, nins: None, reach: None**. There is no artifact behind it
and no draft of it survives on disk (today's agent scanned every stored draft and found two, both
junk). `load_best` takes the LOWEST closeness per address, so this unverifiable row will out-rank
today's real, reproducible 63 in every future target selection.
This is the Phase-28 defect class (`func_80178004` recorded close=0 when it was 91). It is left in
place rather than deleted because deciding between "a lost good draft" and "a bad number" needs
evidence I do not have. **Whoever picks this up: treat the 14 as UNVERIFIED, start from the
committed 63/47 drafts, and if the 14 cannot be reproduced, purge the row.**
The general rule this argues for: a backlog row with no draft artifact is a rumour, not a result --
`backlog.py log` should require a draft path (or mark the row unverifiable) so an artifact-less
number cannot outrank a reproducible one.
NOTHING BANKED — no draft reached closeness 0. Recorded as such (P9). No src/ or config/ change,
so the fleet is untouched at HEAD's verified 140/140; R22 deliberately NOT re-run and NOT claimed.
- VERIFIED the checkpoint's six closeness numbers against the bytes (R14/R35): 217/10/11/6/7/9 all
reproduce EXACTLY through match_one --json, with asm_subdir/-O0 DERIVED from wave22_targets.json
rather than guessed. All six are reach-138 cores = ~135,516 templated ins (~1.04pp) if cracked.
Reproducer .run/near6_measure.py.
- PERMUTER (only 2 of 6 are §60a-admissible): func_80177B5C 11->7, func_80140958 10->6, both
re-measured with match_one — an oracle INDEPENDENT of the permuter's scorer (R34) — agreeing
exactly. Both plateaued after cycle 1. Seeds preserved + allowlisted.
- THE FINDING: residual_class routes ADDRESSING -> permuter, but gcc-2.7.2-map/cse_expr.md §2
documents that exact class (hoist-vs-remat) as STEERABLE by a byte-proven C recipe. The tool
spends CPU searching for what the map says has a deterministic fix, and both ADDRESSING targets
plateaued exactly as that predicts. R35-shaped instrument defect, not a compiler wall.
- NEGATIVE RESULT, byte-tested on func_80132F40 (6 variants): the §83d CSE fork is REAL (s32 fixes
the min-block opcodes but hoists &v[0] into a 5th callee-saved reg, 47 mism), and the §2 kill
moves it (47->40) but does NOT dissolve it in 3 placements. §2 has an unstated boundary: proven
where the address's only uses are call arguments; a STRUCT-COPY source address survives the kill.
close=6 (s16) remains the best known state — the wave agent's verdict, independently re-earned.
- NEW DIAGNOSIS: func_80140958's post-permuter residual is not scheduling — my draft CONSTANT-FOLDED
a loop value the target keeps live (li v0,3 / li a3,3 / li t3,12 vs addu/sll from $v1). Untried.
- NOT SPENT, deliberately: func_80176734 (already a no-bank Fable5 pass, §H), func_80140D68 (~200
compiles already), func_8012E364 (~2500 variants already).
- tools-health exit 0 (green, fail-closed) at preflight.
CAUGHT BY VERIFYING THE CHECKPOINT INSTEAD OF ASSERTING IT. `.run/wave22/` was covered by the blanket
`/.run/*` ignore, so the 13 UNBANKED drafts — 6 NEAR with precise residual diagnoses and 7 that
reached match_one MATCH but did not bank whole-binary — existed only on disk. My own checkpoint's
"START HERE" list names them as next-session fuel, and they cost ~2.59M subagent tokens to produce.
One `git clean -fdx` would have destroyed them: exactly the exposure the .run/giants Fable5 cracks
had before Phase 27 curated them (R20).
Now allowlisted: .run/wave22/*.c + .run/wave22_targets.json (the per-target canonical callee/data
declarations resolved from the real TU scope — the §17a-1 lever the wave was built on).
Also commits docs/family-hseq.md, regenerated by this session's family_hseq runs.
First attempt on the game's largest unmatched function. No match (never the goal); the deliverable
is the map, and every claim is byte-verified against the target .s.
- STRUCTURE: an actor state machine, not a straight-line giant. 21-case switch via jtbl_801F4CE4
(sltiu 0x15); 359 jals to only 37 DISTINCT callees (verified); 48-ins preamble + 19-ins shared tail.
- THE FINDING: it decomposes into repeated templates, not 5122 unique instructions —
35 instances of one "spawn-effect" packet (~1400 ins, crack one -> 34 free),
7 "wait/countdown" (already reproduced at 0 skeleton diffs), 12 "HUD/text",
plus twin cases (0≈3, 1≈4). Only 3 cross-jump edges couple anything.
- TWO GENERAL LAWS FOR GIANTS, measured: (1) register pressure is GLOBAL, so a partial draft gets
10 callee-saved regs instead of 8 and a matching PREFIX is structurally unavailable — write all
cases coarsely first, then refine; (2) match_one's global number is meaningless on a partial giant
(666 vs 5122) — measure REGION-ALIGNED instead.
- NEW REUSABLE TOOL: .run/giants/s18_regions_comparator.py (region-aligned skeleton comparator, works
on any giant). Caveat travels with it: masks register numbers + jal targets, so it proves STRUCTURE,
never closeness; finish on the whole-binary gate (G3/P9).
- 2 idioms cracked in passing (the D_x[t+K] constant-fold needing a separate index statement; the
(s16)*(u16*)p + /455 magic-0x90090091 form).
- VERDICT: tractable but a ~2000-line WRITE, not a hard puzzle — no scheduler wall, no unsteerable
regalloc. Recipe for the next attempt recorded.
- artifacts preserved under the tracked .run/giants/ path (.gitignore now allowlists *.py there).
- ROOT CAUSE PINNED (the session-2 half-pin was INVERTED; both probes were vacuous, R35):
cc1 emits .align 3 before EVERY jump table; maspsx passes it VERBATIM (the :435 'drop' is
an inventory-only pass); as bakes the pad SECTION-RELATIVE; link placement was never guilty
(SUBALIGN(2) + ALIGN(.,4) place 4-mod-8 carve starts tight). Merging originally-separate
TUs fires an intra-TU align where the original packed tight -> +4 at rodata 0xCC ->
image-wide %lo shift. Honest probes persisted: .run/probe_jtbl/ (verdict.md + objdumps).
- NEW tools/jtbl_rodata_pads.py: post-maspsx filter replaces each rodata .align 3 with the
ORIGINAL's exact pad bytes per a JTBL_PADS spec; fail-loud on table-count drift /
non-align-3 / non-jtbl rodata content. Byte-proven: verbatim 0xE4 pad-at-0xCC ->
filtered 0xE0 tight (= the merged carve span).
- jtbl_carve.py: spec-aware same-subseg merge (gap 0 or 4-with-zero-payload-word; else
NON-CONTIGUOUS -> isolate), interval-arithmetic pad specs (committed values CARRIED,
never re-derived), JTBL_PADS target-var emission into overlays.mk + revert() restore +
stale-.o invalidation; the false 'maspsx drops .align' docstring corrected (H5).
- Makefile: $(if $(JTBL_PADS),| jtbl_rodata_pads.py ...) stage in build/src/%.o + file-scope
empty default (env-shield). jtbl_family_bank.stub_file: duplicate-stub fail-loud (the
earlier 'ladder failure' was a wrong-TU splice into a stale _a.c stub, byte-witnessed).
- R22 clean-fleet WITH the fix wired: 140/140 byte-identical, tools-health green
(dedup 1846/0, C1 234205/234205), ZERO new banks -- fleet-neutral by construction.
- cookbook §8e (the jtbl alignment law) + §8a/§8a-pad corrections; decision-log R31 entry;
SETUP.md tool row; .gitignore allowlist for the probe verdict artifacts.
The Fable5 discovery sprint's irreplaceable output, banked before the distillation (that's the
pending Max task). Each is the product of a ~250k-token Fable5 pass; the bulk beside them (260M of
RTL dumps + bisection .s under pincrash/) is regenerable and stays ignored (R33).
- wave-1 crack recon: func_8014D820 (block-0 cracked pin-free 261->110, "reused-load-temp
serialization" lever), func_801670E4 (RC-6-not-S3 reclassification + the reg_renumber-swap oracle),
func_8016CBC0 (root-A cracked byte-zero, "coalescing knife-edge" refuted, density-dial lever) +
the workhorse variant.
- pin_crash_sigabrt.md + pincrash/{minimal_repro.c, *.gdb}: the §42e pin-crash wall CHARACTERIZED and
REFUTED as a compiler wall — it's the extract_unit macro-drop (fixed in T5); sched.c:2725
create_reg_dead_note abort; pinned families stage 133/133 clean once macros ride along.
All three wave-1 seeds produced oracle-proven reclassifications refuting cookbook §44-Lever-5 wall
names + new pin-free levers (Fable5 discovers, cheap-Opus applies). Distillation -> cookbook is next.
Found while reading the seeds for T1: cookbook §45 names
.run/giants/func_80133CD4.fable.c as its worked example and .run/giants/fable_cd4/
as the flagship's gdb oracle — BOTH were untracked. The docs cite artifacts that
were not in the repo.
- .gitignore: widen by FILE TYPE, not directory — .run/giants/*.{c,md,sh} +
fable_cd4/*.{c,md,sh,gdb,txt}. +49 files / 460K.
- Now preserved: the flagship func_80133CD4 crack + its gdb oracle (§45's cited
worked example); the byte-verified pf*.c regression ladder (the seeds' own
Method/reproducibility section cites it: pf2 78, pf_c2 30, pf_d1 35, pf_h1 280);
the dump.sh/mon*.sh RTL harnesses; the banked giants' drafts (80135480, 80163EC8,
80166994).
- Still ignored (regenerable via dump.sh, R33): d_pf*.i.*, *.s, dumps_m*/, and the
ILS/permuter .log files. Negative control re-verified: all 5 probes IGNORED, no
db.*.gbf staged (R23).
Lesson (R31 candidate): a doc that cites a path is an untested claim about the repo.
The §45 citation and its file were 4 days out of sync; only reading the seed for an
unrelated reason caught it. Candidate lint: cookbook path citations must resolve to
tracked files.
Pulled ahead of T1: the Fable5 sprint's agents work inside .run/, and its Phase-25
seed recons were untracked — an agent overwriting .run/giants/*.opus.c would have
destroyed irreplaceable input. 5 minutes to remove that risk.
- .gitignore: /.run/ -> contents-exclude form (/.run/* + ! exceptions), following the
/tools/bin/*.sha256 precedent. Resolves R20 (commit irreplaceable RE work) vs R12
(.run/ is scratch) by splitting the directory on the real axis: what a rerun CANNOT
reproduce.
- PRESERVED (~2.2M / 31 files): the 6 Phase-25 *.opus.{c,md} giant seed recons (49K);
the func_80178004 gdb-on-cc1 harness + ORACLE_PROOF.md + the v00-v07 draft ladder +
the sched/combine .lst evidence (~110K — the distilled output of a 477k-token Fable5
pass, and the method §52 lever 6 depends on); backlog.jsonl (1.9M) + fuel_manifest.json.
- STILL IGNORED (regenerable, R33): dumps_v00..v07/ and d_pf*.i.* gcc RTL scratch —
12.3M reproducible via runorc.sh + the .gdb scripts; the MCP log; draft scratch.
The plan said "track the dirs"; the bytes said the dirs are 96% regenerable.
- VERIFIED both directions: git add --dry-run stages exactly the 30 intended files and
0 bulk; negative control — ghidra-mcp.log / dumps_v00 / d_pf.i.sched / d_pf.s all
still IGNORED. No db.*.gbf staged (R23 restart-noise).
The 500-fn calibration banked 0/222 across the binary rotation. Root-caused (R14, by
reading the code + the run's own backlog — resolving a flat contradiction between two
scout agents) to TWO independent bugs in lora_grind's use of gate_stage.run_gate, NOT
model quality:
- Bug A: good_sha() passed the sha1sum line "<sha> <name>" vs harvest_verify's bare
sha1() -> 0 banks for EVERY binary incl. 077 (so the "0/12" was a bug artifact, not
an exhausted tail)
- Bug B: the gate call left src/asm/out at the hardcoded ov_SC01_077 defaults -> non-077
drafts dropped at the 077 stub-filter, silently (and the asm mis-resolution contaminated
the backlog near-miss classification)
Fix (tools/gate_stage.py): run_gate resolves src/asm/out/good_sha from `binary` when unset
(binary-agnostic, no silent ov_SC01_077 default an overlay inherits; good_sha bare-hash
normalized) + a loud negative-control guard (0-overlap binary/src mismatch warns, so a 0
can never again masquerade as 'nothing matched'). tools/lora_grind.good_sha fixed at source.
Byte-neutral: make check-all 136/136.
Proof: ov_SC01_000 spot-run banked 7/15 (47%) byte-identical (@commit:0322); reach-2
func_8017CE24 propagated x2. ROI finding: 6/7 banks are reach-1 (overlay-unique) -> broad
rotation is high bank-RATE / low fleet-% ROI; the fleet lever is reach>=2 targeting (T9) +
corpus-v3 (T8). Backlog now correctly classified (4x close=1 = grinder fuel).
- docs/gen2-mips-matching-model.md: T7 RESULT section
- phase-ends/CURRENT_PHASE.md: T7 done; next = T8 corpus-v3 / T9 reach>=2 selection
docs/gen2-mips-matching-model.md: the BFM/gcc-2.7.2 matching-specialist idea (LoRA on our own
gate-verified pairs — the corpus off-the-shelf RE LLMs lack). export_pairs.py mines 1307 banked
(asm<->C) pairs from build objects (asm/ is gitignored, so disasm the ROM-identical build, splat-like
format) + src defs -> datasets/match_pairs/{pairs,train,test}.jsonl (gitignored, 1174/133 split).
api_draft.py: TEMP env-tunable. .gitignore: datasets/ models/ weights.
- PhaseEnd_Phase9.md written; CURRENT_PHASE.md archived -> phase-ends/logs/Phase9.md (R19)
- MILESTONE (gate-2 confirmed): the toolchain is binary-agnostic — EXE rebuilds
143dbb89 through the parameterized path WITH and WITHOUT SDK objects; make report
52/959/7/50.24%; every binary-specific value a required param (no EXE default);
wrong --vram-base -> cae22f7e (negative control). Landed as 11 per-tool checkpoints.
- R23: stop the Ghidra MCP + commit the DB at phase-end/RE-checkpoint (lock won't
release until MCP closes; SessionEnd is too late for a mid-session commit). This
commit reconciles the Ghidra program DB (db.12 -> db.15, 99% identical: Phase 9 did
zero RE writes) after a clean ghidra_mcp_stop.sh save.
- .gitignore: ignore /ghidra/**/*.lock~ (the lock-backup that churned every session)
- bumps project version 1.8.0 -> 1.9.0
- docs/gen2-roadmap.md: approved Gen2 plan (phases 8-15; finish-EXE-first,
two-repo LATE public flip, substantial exit) + Backup & disaster-recovery policy
- back up irreplaceable / hard-to-re-source artifacts to the private remote (R20):
- track ghidra/ (the RE database; *.lock/tmp*.ps transients excluded)
- tools/psyq/ working libs/tools (minus the two >100MB raw source archives)
- tools/bin/*.tar.gz (old-gcc cc1 compiler sources; extracted binaries stay regenerable)
- tools/ghidra-ext/ (GhidrAssistMCP 2.8.0 + ghidra_psx_ldr 2026.06.04 installer zips)
- .claude/settings.json: SessionStart + SessionEnd hooks (auto-start / clean-save the
headless Ghidra MCP); moved out of the gitignored settings.local.json so they are backed up
- docs/SETUP.md: document the MCP server lifecycle + persistence model + session hooks (§2.8),
a tooling inventory, .run/ runtime scratch (§1a), and the backup posture (§ Backup) — R21
- .gitmodules: ignore=dirty on the 4 submodules (maspsx/asm-differ/m2c/decomp-permuter) —
silences the phantom "modified" state from generated pycache + cross-filesystem filemode;
gitlinks unchanged (still at the pinned commits)
- rules R20 (back up irreplaceable work + gathered tooling; loosens R8) and R21 (keep
SETUP.md current) recorded in memory; to be formalized at the next PhaseEnd