Probe-12 wave (workflow wf_45e34026-aed, 21 agents, 3.36M tok, 70 min):
12 top-weight zero-crack sibling families cracked against match_one, every
claimed MATCH re-gated by an independent adversarial verifier.
crack-agent MATCH 9/12 (75%) adversarially refuted 0
whole-binary gate 8/12 (67%) NEAR 3, FAIL 0
Banked (exemplars, 1,941 ins; ~10k templatable ins across 42 member slots):
ov_SC06_018 func_80186270 x6 func_80185F58 x6 func_80187AEC x6
ov_MAIN_012 func_8017D730 x5 func_8017D2A4 x5 func_8017CF3C x5
func_8017CBC8 x5
ov_SC04_018 func_80188E1C x5
NOT banked, ledgered:
func_8017F2D4 (ov_SC01_005) — match_one MATCH, verifier confirmed, and the
WHOLE-BINARY gate still classifies DIFF. The §52b gap made concrete: the
per-function gate is a candidate filter, the binary gate is the arbiter.
func_8017C294 (x16, the largest single item on the board) NEAR 18 ins
func_8017C3BC NEAR 17 ins · func_80189540 NEAR +2 ins / 4 sites
R22 clean-fleet after banking: 213 passed / 0 failed of 213.
The 0b blocker was not "the pads line is left behind" alone — it fails two
different ways, and the second one is silent:
* bare isolate + `make build`: the stale line arms the pads filter on the
RESIDUAL object, which emits no jump table ->
`jtbl_rodata_pads: consumed 0 rodata .align(s) but 4 pad spec(s) given` (S47).
* isolate -> jtbl_carve (the jtbl_family_bank path): `set_pads_vars`
regenerates the block keyed by the CURRENT subseg names, finds no prior spec
under the new `_jr_<addr>` name, and DROPS the line. cc1's natural `.align 3`
then pads the span's non-8-aligned interior tables and the image shifts —
reported only as `built, bytes differ`.
- jr_isolate_all.repoint_overlays_mk: repoint the `build/src/<ov>/<sub>.o:
JTBL_PADS` target with the `--order` leaf whenever a carve moves; refuse
loud if the old object still hosts a .rodata piece (R32).
- jtbl_carve.set_pads_vars: second, disagreeing oracle (R34) — refuse when a
spec would vanish for a subseg no longer in the carve set (rename/merge
drift), instead of silently emitting a padless object.
R37 probe: func_801789AC -> ov_SC02_037 went `built, bytes differ` -> BANKED
on the whole-binary byte gate. ov_SC02_037's spec is 0,0,0,0 over tables
+0x0,+0x14,+0x34,+0x4c — load-bearing (span start is 4 mod 8).
W1b — the 3 targets whose agents died on API rate limiting, retried with cookbook §160 in the
prompt: func_801EFBF4 (reach 12), func_801EFDC8 (12), func_8018CC40 (10, jr). 3/3 confirmed by an
independent verifier, all banked, R22 clean-fleet 213 passed / 0 failed of 213.
func_8018CC40 failed the first gate with `too many arguments to function func_80178970` — which its
own crack agent had PREDICTED in its report, naming the §17a-1 remedy. Dropped the draft's
empty-paren externs and cast 6 call sites instead; banked. Read the agent's integration notes
before diagnosing a gate failure — it has already seen the TU.
Cookbook §161a-c (index 469 sections):
§161a case 0: break; is LOAD-BEARING when a jump table is indexed from zero. The natural
case 1..5 makes gcc-2.7.2 pick minval=1, emit `addiu $v1,-1`, and shift every table index —
58 of 77 mismatched on a byte-perfect body. Tell: the table's FIRST entry points at the
function's own end address. Family-wide (10 members).
§161b aliasing a parameter into a local can force a SECOND callee-saved register (+8 frame,
+3 ins) even when uses are mutually exclusive. Suspect it before reaching for register pins.
§161c loose-prototype engine helpers: don't fight the TU's (void) decl, cast at the call site.
G2 — THE MAIN EXPERIMENT. family_hseq excludes main as "structurally barren — zero h_exact
overlap". True and irrelevant: an h_exact claim guarding an h_seq tool. There is not even a
sig-main target — main had never been signed for this pipeline. Signed it (2,002 fns, seeded from
splat boundaries via corpus.stubs rather than --bootstrap, which glues functions around jtbl
dispatch and would have corrupted the hashes under test).
Result: main is ~85% singleton work, not 100%.
internal h_seq families (>=2): 207 families / 748 fns / 11,537 ins (13.7%)
shapes shared with the fleet: 161 fns / 1,346 ins (1.6%)
genuine x1 remainder: ~71,034 ins (84.6%)
IMMEDIATELY ACTIONABLE: 44 classes / 151 main functions / 1,239 ins already have a matched exemplar
in the fleet — free propagation, invisible only because main is not in the map.
Long-term: 748 of main's 2,002 functions (37%) are templatable once one exemplar per family is
cracked, which refutes "2,002 independent cracks" as the planning assumption for the 79k-ins tail.
OPEN, deliberately not done unilaterally: adding a sig-main target and dropping main's exclusion
from family_hseq.load() changes a fleet-shared oracle every targeting tool reads. Needs Drew's call.
The reach-10 jr exemplar cracked in the reach-15 wave; its 9 siblings needed the §53 path rather
than family_sweep (the sweep's interlock refuses has_mid_jr families by design). Per sibling:
jtbl_carve -> make extract -> remap_hseq -> make build, keep iff byte-identical.
Result: 9/9 BANKED. R22 clean-fleet: check-all 213 passed / 0 failed of 213.
WHY 100% HERE VS 56/182 THIS MORNING — the difference was never the code or the tool. This
exemplar banked RAW (so its unit is the raw crack, not an ov077-TU-specific reconciled body, which
is the trap the tool's docstring documents and which historically sent func_80178D40 to 0/4), and
every target binary was already carved. Given those two conditions the §53 path is deterministic.
This morning's 126 failures were 112 isolate-fails in three UNCARVED binaries plus 10 gate-fails
and 4 carve-fails.
Consequence for planning: the 122 jr member-slots still blocked behind the JTBL_PADS repointing in
ov_SC02_037 / ov_SC03_107 / ov_MAIN_012 are not a speculative number — they convert at the rate
just demonstrated once those binaries are carveable. Those are the same three binaries that
absorbed 1,102 of today's propagation banks, so unblocking them pays across every lane.
First wave of the reach-ordered campaign: the 15 highest-reach zero-crack sibling families.
15 agents (size-routed Haiku<=30 / Sonnet 30-120 / Opus>=120), every MATCH claim re-verified by an
independent skeptic that re-ran match_one itself. 22 of 25 agents completed; 3 were rate-limited by
the API and never attempted their targets.
BANKED 10 exemplars (reach in parens), all gate-verified, R22 213 passed / 0 failed of 213:
func_801EDC80 (28) func_801ED99C (28) func_801EDDAC (28) md_SC05_023
func_801EDED4 (24) md_SC05_023 func_800CB8B4 (24) md_MAIN_036
func_801E8254 (14) func_801E7C04 (13) md_SC04_025
func_80181070 (12) ov_SC03_024 func_8017E384 (10) ov_SC01_005
func_80185D70 (10, jr) ov_SC04_018 — gate auto-carved it into its own subseg (§53 machinery)
NEAR, not banked: func_801EDC18 (reach 57 — the single largest multiplier on the board) at
closeness 6, and func_8017C294 (reach 16) at closeness 2. Both are grinder/permuter candidates
rather than redraft work.
NOT ATTEMPTED (rate-limited): func_801EFBF4 (12), func_801EFDC8 (12), func_8018CC40 (10) — a clean
retry, since they never ran.
COUNTING (§55b, and the second time today this trap fired): git diff showed 12 INCLUDE_ASM removals
but only 10 are banks. func_80186460 and func_8018651C were RELOCATED into the untracked carve file
ov_SC04_018_jr_80185D70.c, not banked — verified by grepping the new file, where both still carry
INCLUDE_ASM. Any count taken across a carve must come from the stub oracle, never from git diff.
TREE SAFETY: zero agent writes to src/ or config/, despite 5 agents running while the safety
classifier was unavailable. The "drafts live in .run/ only" rule held under exactly the conditions
where it mattered.
gate_stage's --verified-out came back populated for all 6 binaries — this morning's truncation fix
(S47-C) confirmed on live traffic, not just controls.
Idioms harvested for the cookbook: the ASYMMETRIC INDEX RELOAD (a just-stored narrow field read
twice emits reuse-then-reload; the C is deliberately asymmetric — local for use #1, memory re-read
for #2), a stack-layout scheduling rule now byte-proven on a SECOND independent function
(func_8017D364 + func_801EDED4, promoting it from coincidence to rule), and a process finding:
sibling-search keyed on the CALLEE SET should be step 0 of every wave prompt — one grep turned a
126-instruction crack into a copy-edit.
Exemplar ov_SC01_077 @0x80180b64 (matched-ov077), 2 members. Per-sibling whole-binary byte-gate (G3/P9) is the
arbiter: jtbl_carve -> make extract -> remap_hseq -> make build, keep iff byte-identical else
revert. Tally: === func_80180B64: {'BANKED': 2} ===
Committed per family because jtbl_family_bank's per-sibling revert restores from HEAD — an
uncommitted prior family would be lost. Campaign-end R22 verifies the fleet.
Exemplar ov_SC01_077 @0x80183bac (matched-ov077), 5 members. Per-sibling whole-binary byte-gate (G3/P9) is the
arbiter: jtbl_carve -> make extract -> remap_hseq -> make build, keep iff byte-identical else
revert. Tally: === func_80183BAC: {'BANKED': 5} ===
Committed per family because jtbl_family_bank's per-sibling revert restores from HEAD — an
uncommitted prior family would be lost. Campaign-end R22 verifies the fleet.
Exemplar ov_SC01_077 @0x801789ac (matched-ov077), 3 members. Per-sibling whole-binary byte-gate (G3/P9) is the
arbiter: jtbl_carve -> make extract -> remap_hseq -> make build, keep iff byte-identical else
revert. Tally: === func_801789AC: {'BANKED': 2, 'isolate-fail': 1} ===
Committed per family because jtbl_family_bank's per-sibling revert restores from HEAD — an
uncommitted prior family would be lost. Campaign-end R22 verifies the fleet.
Exemplar ov_SC02_026 @0x8017fee0 (matched), 1 members. Per-sibling whole-binary byte-gate (G3/P9) is the
arbiter: jtbl_carve -> make extract -> remap_hseq -> make build, keep iff byte-identical else
revert. Tally: === func_8017FEE0: {'BANKED': 1} ===
Committed per family because jtbl_family_bank's per-sibling revert restores from HEAD — an
uncommitted prior family would be lost. Campaign-end R22 verifies the fleet.
Exemplar ov_SC01_077 @0x80179b74 (matched-ov077), 3 members. Per-sibling whole-binary byte-gate (G3/P9) is the
arbiter: jtbl_carve -> make extract -> remap_hseq -> make build, keep iff byte-identical else
revert. Tally: === func_80179B74: {'BANKED': 2, 'isolate-fail': 1} ===
Committed per family because jtbl_family_bank's per-sibling revert restores from HEAD — an
uncommitted prior family would be lost. Campaign-end R22 verifies the fleet.