§H sold the reg_renumber-swap oracle as THE one-gdb-run discriminator between RC-6 (allocation) and
S3 (scheduling). It has two preconditions it never stated, and both failed silently on the first
real use after the audit:
1. reg_renumber maps PSEUDOS ONLY (index >= FIRST_PSEUDO_REGISTER = 68 on MIPS, mips.h:1179). A
contested register that is already HARD at .greg time — an incoming parameter reg, a pin, or a
local-alloc reuse — is structurally unreachable. Check the .greg RTL first: (reg/v:SI 6 a2) with
6 < 68 does not qualify; only (reg:SI 130)-style operands do.
2. The contest must be NARROW. The swap is global across reg_renumber, so if the pair serves many
pseudos it destroys the allocations that were already correct.
Byte-measured on func_80176734, baseline 13: control 1<->1 -> 13 (harness validated);
<-> moved 17 pseudos -> 345; <-> moved 31 -> 97. The .greg read then showed the
destination was (reg/v:SI 6 a2) — hard, a reused incoming parameter register — so the true class was
local-alloc TYING (K8/RC-4), not RC-6, and the lever is C-level lifetime shaping.
Harness + negative control preserved at tools/oracle/reg_renumber_swap.sh.
26 agents (5 derive + 21 adversarial refute), 1.73M subagent tokens. Two guards, because a false
REFUTED deletes a working lever and is worse than a stale line number:
- MECHANICAL FABRICATION CHECK (.run/verify_regalloc_findings.py, NEW): every claim had to carry a
verbatim source_quote + file + line; I re-opened each file at each line and compared. 184 checked,
**0 FABRICATED** (27 exact, 153 NEAR = quote real but line arithmetic off by +2..+19, 4 declared
unverifiable). Distinguishes NEAR from FABRICATED because the 2.8.1->2.7.2 drift (+300..+600 in
reload1.c) can land a lookup inside a DIFFERENT function and still read plausibly.
- ADVERSARIAL SECOND STAGE: every REFUTED claim went to an independent agent told to refute the
refutation, defaulting to upholding the map. **Of 21 REFUTED, 14 OVERTURNED, 7 stand.** The raw
audit output would have deleted 14 CORRECT levers (RC-6's verdict, the decoy-qty lever, the
<=3-qty creation-order rule, the keepalive-read lever).
FINAL: 119 CONFIRMED / 40 LINE-DRIFT / 7 REFUTED-upheld / 4 UNVERIFIABLE. The model is sound.
The 7, marked [A23] inline:
1. K4 flag_caller_saves is ON (toplev.c:3387-3394 at -O2), BYTE-PROVEN on the real cc1 — a
call-crossing value is not confined to $s0-$s7-or-spill. Added the missing diagnostic:
caller-save slots are 4-BYTE-PACKED vs reload spill slots 8-ROUNDED (misreading one as the other
sends you to RC-1 + decl reordering, the wrong lever entirely).
2. RC-7's premise false: a frame address is never CONSTANT_P (rtl.h:237-240 excludes PLUS), so it
gets a real slot + lw. THIS EXPLAINS T31's byte-tested failure today — cse_expr.md §2's remat
recipe could not dissolve func_80132F40's hoist (47->40, never 0) because the promised mechanism
does not apply to frame addresses. Independent audit and live byte-test converged.
3. The "init MOVED to just before its use" pass is 2.8.1-only; 2.7.2 deletes the init instead.
4. K2 refs are LOOP-DEPTH-WEIGHTED (reg_n_refs += loop_depth), not per-insn-mention.
5. K1 qty numbers come from BIRTH order, not regno order.
6. RC-15/K2: allocno_live_length is the DENOMINATOR — priority is a density.
7. Pins do NOT kill the S2 boost — independently reproducing yesterday's sched.md finding from a
different agent/section, plus the decisive detail that sched.c:423 DOES add the pseudo guard
where it wants one, so the omission at :2478 is deliberate.
NOT applied: the 40 LINE-DRIFT fixes wholesale — generic quotes match several places, so publishing
all 40 risks replacing 2.8.1 drift with fresh 2.7.2 drift. Header carries 12 hand-verified anchors +
an instruction to grep before citing. Struck text preserved, not deleted (H5).
Docs-only: no src/ or config/ touched, R22 not re-run and not claimed.
The flywheel step (R16/R30): turn the wave-1 + SIGABRT byte-proven findings into cookbook/codegen-map
knowledge, in the producing session. The distillation REWRITES wall verdicts, so accuracy is load-bearing.
- cookbook §42e-CORRECTION: the "pin-crash wall" (register-pin-heavy families "SIGABRT the sibling TU,
ov077-TU-context-specific, NOT ×134-recoverable") is REFUTED. The SIGABRT is real (sched.c:2725
create_reg_dead_note, a sched1 REG_DEAD-note conservation bug) but was TRIGGERED by extract_unit
dropping file-scope #define macros (the T5 bug) -> implicit-call GTE ops -> caller-saved pins in the
fatal shape. Only 1 of 4 families genuinely crashed; 3 were exit-33 plumbing folded into one crash
bucket. Fixed, all 4 stage 133/133 clean. Per-pin predicate recorded. P31's pin route is OPEN.
- cookbook §44-Lever-5: the 3 functions it cited as intrinsic (func_8014D820/8016CBC0/801670E4) are
each oracle-refuted (2 cracked roots + 1 RC-6-not-S3). Corrected the "NEVER ship pinned, it SIGABRTs"
claim per §42e-CORRECTION.
- gcc-2.7.2-map/regalloc.md §H: THE reg_renumber-swap oracle (discriminate RC-6 allocation from S3
scheduling in one gdb run — patch reg_renumber at reload entry, swap the contested regs; byte-exact =
pure allocation), RC-14 reused-load-temp serialization (the MERGE pole; pin-free, cheap-Opus), RC-15
the density dial across a floor_log2 boundary (subsumes "coalescing knife-edge"), and the local-vs-
global allocation tie as a precisely-named honest sub-class. Continues the §F/§G RC-6-downgrade series.
- decision-log.md R31: the 3 Phase-27 strategic findings (disc is bigger: 140 + 39 modules; a wall was
our tool again; a cheap win is dead) + the through-line — the roadmap's numbers were red-teamed, the
tools under them were not, until this phase.
func_80176734 (fresh-core wave-2 agent) still running; its findings fold in before the PhaseEnd.
Both concerns byte-verified from a fully-clean tree (ov_SC01_077 d19c9580, ov_SC07_009 2a6499b6
+ 133 overlays). Fleet is 135/136 — the 1 remaining failure is `main`, a SEPARATE pre-existing
Phase-21 breakage (62 dangling INCLUDE_ASM refs, tracked in CURRENT_PHASE, fix in progress),
NOT introduced by this commit.
[FIX (partial) — pre-existing Phase-21 latent breakage, found during T5b's fleet verify]
- A genuinely-clean `make check-all` failed 135/136 (overlays: `undefined reference to func_80058B40`;
main: dozens of `can't open asm/nonmatchings/800c3/func_*.s`). This commit fixes the OVERLAY side.
- Root cause: Phase-21 xdedup renamed func_80058B40 -> GetTPage in symbols.us.txt (one of the
+62 PsyQ names) but did NOT update the two shared engine_core.h macros that CALL it
(DEFINE_func_80139680, DEFINE_func_8012E28C — in all 134 overlays + ov_SC01_077_a). Since
Phase 21 a clean rebuild couldn't link; incremental builds reused stale .o's and masked it
(the R22 failure mode) — every "check-all 136/136" Phase 21->23 was incrementally-stale.
- Scope = exactly 1 symbol (static scan of all func_/D_ refs in the shared headers vs symbols).
- Fix: rename the 4 occurrences -> GetTPage (byte-neutral, same addr 0x80058b40 -> identical jal;
G6 curated-name). ov_SC07_009 link-fail -> byte-identical 2a6499b6.
- Lesson: a symbols.us.txt rename must be propagated to shared-macro bodies AND verified by a
genuinely clean (make clean + full re-extract) check-all, never incremental.
[FEAT — T5b: the S11 class crack, Fable5 spike]
- The S11 LUID(x)alloc "intrinsic" verdict was MAP-INCOMPLETENESS. func_8014E048 (143 ins,
reach-134; "not source-steerable" since the map wave; 28-off even after T5's directed permuter)
-> MATCH (143/143) -> whole-binary BANKED (ov_SC01_077 d19c9580). Derived by reading gcc-2.7.2
source + RTL dumps (12 experiments .run/gccmap/exp/e1a..e1k.c).
- NEW LEVERS (byte-proven): S12 reused-s32-temp fence (u16 temps DON'T work — combine folds the
unpromoted-HI zext temps away); S13 head-skip escape (body-local param copies conflict-steer the
scratch contest; volatile-asm dead-read wedge fence; multi-input dead-read K2 rebalance);
cse-opaque asm-copy; RC-4b pinned store-temp; RC-10 preference-cascade mechanics.
- Integration reconciles (both T6 classes): engine_core.h caller decl s16*->u16* (codegen-neutral)
+ canonical data decls w/ *(u16*) casts (D_801152A8 u8[] / D_801152AC s16). x134 lift blocked by
dedup_propagate self-containment (pins/asm) -> T6 target (joins func_80132784).
- Distilled (R30/R16): sched.md §6 (S12/S13) + regalloc.md §F (RC-10 + RC-6/S11 downgrade) +
cookbook §31 triage update; backlog re-logged (capped); memory updated.