mirror of
https://github.com/Druthulu/BFM-decomp
synced 2026-09-27 22:45:39 -04:00
85fb289db582d842fc41dc059fa187bb992e76ea
305 Commits
| Author | SHA1 | Message | Date | |
|---|---|---|---|---|
|
|
2f7e06564b |
feat(phase-30 S50): the stale seed symbol — A-prop's 57% was ours, not the lane's (§171)
- REFUTES §170's open hypothesis (batched cards concentrate members into one TU ⇒ §169
collision): 5-draft groups banked 5/5; 11 of 35 unbanked drafts were already one-per-TU;
and the two "concentrated" groups banked 12/12 and 10/10 once the real defect was fixed.
- The cause: a per-location data symbol carried out of the seed body unrebased. match_one
compares instruction ENCODINGS and is blind to a relocation's target NAME, so it scores
MATCH standalone and dies at link in the host TU. 24 of 24 concentrated failures, all 1:1
rewritable at one constant vram delta (0x4128).
- tools/aprop_symfix.py: audit + --fix, emits a gate_lane-shaped slate; deterministic and
build-free, so it runs BEFORE the gate. The R34 second oracle for the class match_one
cannot see.
- family_cousins.py --aprop-cards: members now carry sym_map, the explicit {seed -> member}
renames, read from the seed's C BODY (a matched seed has no .s of its own) vs the member's
.s. Two case-mismatch defects fixed while wiring it (sig lowercase vs splat uppercase).
- 23/24 banked. Stubs 12,468 -> 12,445. Fleet 95.2% instr / 89.9% distinct / 96.57% fn.
R22 clean rebuild: check-all 213 passed, 0 failed of 213. dedup 2,043/0.
- A-prop's true conversion is 87% (79/91); the 320 batched members are unblocked.
- Cookbook §171 + §170 struck in place; SETUP row; decision-log (R31).
|
||
|
|
bcc3130eb4 |
feat(phase-30 S49): the A-prop word-diff card + aprop_wave — 56 banked from the >=16 head (§170)
- NEW family_cousins.py --aprop-cards + tools/wave/aprop_wave.js: lane A (1,700 open fns / 76,419 ins) had NO card type — cousin diffs are empty for h_seq-identical members, so the card is a positional WORD diff vs the matched sibling, grouped BY FAMILY (one agent, N drafts). Head cards: 13 families / 433 members, median TWO differing words each. - calibration 9 batches / 108 members: 98 agent-MATCH (91%, best of any wave) -> 56 BANKED (57%), ~80k tok/banked fn vs 157k (cousin card) vs 400k+ (crack wave). R22 213/213 BYTE-IDENTICAL. - HONEST GAP (R14): 91% agent -> 57% gate is the worst conversion measured; 14 groups banked 0. Hypothesis TESTABLE not proven — family batching concentrates members per destination TU, the §169 collision. Re-gate unbanked ONE PER TU before scaling the remaining 320. - >=16 head diagnosed: 3 of 4 blockers are plumbing — the --band substantial default hid 5 of 13 families from every prior sweep; one missing file-scope extern (D_801ED98C) gates 56 PURE members; dedup_extend is macro-only. Only func_8017C294 is a genuine crack. - fleet 96.56% fn / 95.2% instr / 89.9% distinct; stubs 12,535 -> 12,468; dedup 2,043/0. - cookbook §170. |
||
|
|
79b7ff2cbf |
chore(phase-30 S49): wave 7b — adapt lane scaled, 44 banked (92% MATCH->bank); the TU-spread law
- thresholds relaxed to <=6 blocks/<=16 tokens UNION edit-fraction <=0.20: cards 518 -> 721, MIXED 310 -> 50 skeletons; the 753-ins func_8017BEBC (0.987 sim) became reachable. - 59 cards -> 48 agent-MATCH (81%) -> 44 BANKED (92% MATCH->bank, 75% end-to-end), 6.9M tok. - FINDING (the actionable one): 7b's bank rate crushed 7a's because it SPREAD 48 drafts over 35 destination TUs; 7a's failures were per-TU declaration collisions between sibling drafts. Cookbook §169 updated with the spread law. - R22 213/213 BYTE-IDENTICAL from clean; fleet 96.55% fn / 95.2% instr / 89.9% distinct; stubs 12,584 -> 12,535; dedup 2,035/0. - incidents 3 & 4 recorded: an agent wrote a TRACKED header (guard caught it, prose is not enforcement); my own gate_lane filtered on the wrong key and printed 'gating 0 drafts' as a result (R32 silent skip) — fixed with a coverage assertion that refuses to report 0. |
||
|
|
44b49ed715 |
chore(phase-30 S49): wave 7a checkpoint — micro-adapt lane measured (83% MATCH / 64% bank), §169
- pilot 30 cards -> 25 agent-MATCH (0 refuted) -> 16 banked; 29 instances banked tonight (89 incl. propagation); 2.7M tokens haiku-tier ~= 30k/banked instance vs a crack wave's ~75k. - R22 213/213 BYTE-IDENTICAL from clean; fleet 96.53% fn / 95.1% instr / 89.8% distinct; stubs 12,613 -> 12,584; dedup 2,029/0. - R14 CORRECTION: a banked cousin usually does NOT propagate (2 of 8; cousins are byte-variant). The card 'reach' column is cousin fuel, not dedup copies — priced wrong in my earlier framing. - FINDING: the 9 gate failures are per-TU INTEGRATION (standalone-MATCH, host-TU-rejected), clustered 5+2 in two binaries — the reconcile-ladder class, not codegen. - TWO INCIDENTS (mine): an outer timeout tighter than gate_stage's own scaled timeout killed a healthy 5-bank group mid-write AND orphaned its dedup_propagate child, which kept rewriting src/ through a git checkout. Killed, inspected, reverted; the same 5 drafts banked 5/5 untimed. Law: never wrap a self-timing tool in a tighter cap; kill process GROUPS, not pids. - cookbook §169 (the lane + the three laws + the threshold sizing table). |
||
|
|
b3713cc3ca |
feat(phase-30 S49): the cousin tier — family_cousins.py similarity map + seeded wave-7 slate (§168)
- FINDING (Drew's smell, byte-verified): the '4,513 unique singletons' picture is substantially an h_seq exact-hash artifact — 86/120 near-pairs in the 0.85-0.99 band differ by PURE insertion/deletion (li-expansion tell in 25). Specimen: ov_SC06_010:0x8017bebc (753 ins, 'singleton') is 0.987-similar to a MATCHED fn in the same binary. - NEW tools/family_cousins.py: distinct open skeletons -> shingle index -> >=0.85 union-find -> matched-seed attachment -> .run/family_cousins.json + docs/family-cousins.md. R32 BOTH ways (independent stub recount fails loud on a stale map — negative-control-proven; partition assert). Reproduced the probe within +-1%; totals EXACT (11,627 inst / 584,448 ins). - Unit table: A-prop 197u/68,729ins · seeded 418u/50,422 · cousin-multi 1,552u/249,799 · cold 3,240u/215,498 — the genuinely-unique tail is 37% of the remainder, not 90%. Main's 'structurally barren' HOLDS at the similarity tier (94% mass <0.70). - --targets wave slate: .run/wave7_targets.json = 40 targets / 33,304 unit ins (+33% vs family-ranked), 9 resolved seed C paths, size-routed 2 haiku/20 sonnet/18 opus. - LAWS (§168): a cousin is a SEEDED CRACK never a remap; rank waves by UNIT weight; discount short-fn similarity. Byte-gate stays the sole arbiter (G3/P9). - docs/family-hseq.md: this session's frontier regen (post-S48 propagations) rides along. - cookbook §168 + SETUP inventory row (R16/R21/R30); CURRENT_PHASE S49 entry. |
||
|
|
57ff04c1ac |
docs(phase-30 S48): §167 — wave-5/6 harvest, and the saturation signal
27 note-sets, 197 claims, one skeptic each, against a cookbook already holding §162-§166 from this campaign: NEW 5 · SHARPENS 43 · COVERED 126 · UNSOUND 23 byte-probed 92 · single-instance 75 · asserted 30 COVERED+UNSOUND: 57% (§164) -> 64% (§165) -> 76% (here). The duplicate rate rises monotonically as the base grows. FIVE genuinely new laws out of 197 claims is the signal that the idiom well for this class of function is approaching dry — future waves should spend tokens on cracks, not on mining notes for idioms, and harvest only what a skeptic grades byte-probed. The skeptics ran their own A/Bs this round. Best example: a crack agent claimed "the source STATEMENT BOUNDARY decides whether the scheduler hoists a far-consumed load". The vetter built that spelling and got .text BYTE-IDENTICAL to the inline form, then swept eight POSITIONS and got five distinct objects — showing the lever is statement position (the already-banked INSN_LUID tie-break), not the boundary. Plausible mechanism, refuted by measurement, true lever named in its place. 46 entries banked as §167-01..46; §167z records the 23 refutations. cookbook_index.py: 508 sections. |
||
|
|
0fc297184c |
fix(phase-30 S48): §166a — strike the causal claim I did not verify (R14)
I banked the crack agent's story that a wrong-TU citation CAUSED func_8017F2D4's seven gate refusals, and relayed it to Drew, without checking it. corpus.stubs() derives each stub's TU from the actual INCLUDE_ASM site and gate_stage splices via corpus — the harness was always editing the right file. Only the PROSE was wrong. Measured: func_8017F2D4 is still a stub, still classifies DIFF, and is a has_mid_jr function referencing jtbl_801CC504 — so it carries a jump table the standalone gate cannot see. The real residual is CAUSE NOT DETERMINED. The ORACLE stands on its own evidence (the asm subdir's third component IS the TU stem, by construction from the split config). The causal story does not, and is now marked as such. This entry was written to stop a tool printing an unmeasured cause and its first draft printed one. |
||
|
|
80f3ee7397 |
fix(phase-30 S48): §166 — the destination-TU oracle, and stop printing a guess as a finding
gate_stage labelled every "standalone MATCH / whole-binary DIFF" with "(declaration/TU plumbing)". The tool never checked for a declaration conflict — that was a GUESS printed as a diagnosis, and func_8017F2D4 carried it through SEVEN attempts across five waves while every agent hunted codegen. The body was byte-correct from the first attempt; the notes had simply named the wrong destination TU (a file holding only a caller + prototype), and splicing there is a no-op that leaves the INCLUDE_ASM bytes in place. - gate_stage now says only what is true (the two oracles disagree) and hands over the check that resolves it, instead of naming a cause it did not measure. - §166a banks the oracle: asm/<ov>/nonmatchings/<TU_stem>/<fn>.s => the INCLUDE_ASM is in src/<ov>/<TU_stem>.c. The third path component IS the TU stem, derived from the split config, and it beats any prose citation — a grep for the function name also hits callers and prototypes in OTHER TUs and reads exactly like a destination hit. - Plus the two probe gotchas that cost wave-5/6 agents real time: the wrong --aspsx-version fakes ~32 ori-vs-addiu mismatches, and a collateral-drift check must filter to sized symbols (nm -S) or the zero-size .NON_MATCHING aliases all report false drift. cookbook_index.py: 506 sections. |
||
|
|
a2362e6711 |
docs(phase-30 S48): §165 — wave-4 harvest banked the same day the wave landed
19 note-sets, 131 claims, one skeptic each, vetted against a cookbook that already held §162/§163/§164 from this same campaign: NEW 8 · SHARPENS 39 · COVERED 64 · UNSOUND 20 byte-probed 61 · single-instance 43 · asserted 27 COVERED+UNSOUND is 64%, up from §164's 57% — the duplicate rate RISES as the knowledge base grows. That is the argument for harvesting after EVERY wave: a wave launched before its predecessor's harvest lands re-derives laws already on disk. This one was banked while wave-4 propagation was still committing. THE PASS CORRECTED ITS OWN PREDECESSOR. §165-01 BOUNDS §163a, banked hours earlier today. §163a says "block scope is a conflict SOLVENT" — byte-proven, but on a DATA symbol. It does NOT reach an ARITY conflict: there the two decls are COMPATIBLE (cc1 emits no `conflicting types` for scope to downgrade) and the failure is call-vs-composite in convert_arguments (c-typeck.c:1623), which a `()` declaration cannot defuse at ANY scope. The diagnostic word picks the lever: `conflicting types` -> §163a's solvent; `too many arguments` -> cast the call site (§17a-1/§161c) or replace the host prototype. §165z records the 20 refuted claims. cookbook_index.py: 505 sections. |
||
|
|
137a8540b5 |
docs(phase-30 S48): §164 — 190 claims vetted by 34 skeptics, 82 banked, 28 refuted
The §163z catalogue was 34 crack-agent note-sets claiming 190 distinct laws. One independent skeptic per function, each required to read the full notes, grep the whole cookbook, classify, and GRADE THE EVIDENCE: NEW 20 · SHARPENS 62 · COVERED 80 · UNSOUND 28 byte-probed 114 · single-instance 51 · asserted 25 57% of what the crack agents flagged as novel was already in the cookbook or does not survive scrutiny. That ratio is the lesson: a crack agent is the right instrument for FINDING a lever and the wrong one for judging its novelty — it has just spent hours in one function and has not read the other 497 sections. Never bank a wave's flags directly. Banked as §164-01..82, each carrying its verdict, what it sharpens, and its evidence grade (70 byte-probed, 12 single-instance). Several skeptics CORRECTED the mechanism the crack agent proposed while confirming its effect — e.g. the "fold distributes the constant out of an index" claim, where the skeptic traced the real site to expand_expr's MULT_EXPR EXPAND_SUM case (expr.c:5359-5375) after showing pointer_int_sum's distributive law cannot fire on that tree. §164z records the 28 REFUTED claims with the reason, so no future wave spends tokens rediscovering them. cookbook_index.py: 501 sections. |
||
|
|
57cef6325a |
docs(phase-30 S48): §163 — the five vetted laws from waves 2-3
The waves flagged ~40 candidate laws. Five were byte-probed, generalizable and actionable enough to bank; they were deduped by hand against the file (no skeptic-agent pass this time, so each says what it sharpens and why that section is insufficient): - §163a decl-conflict severity is SCOPE-DEPENDENT — hard error if either decl is at file scope, warning only if BOTH are at block scope. §8d proves the phenomenon on D_801812A4 but never states the rule or its LEVER half: block scope is a deliberate conflict SOLVENT, so a struct-typed draft can be banked into a scalar-typed TU by moving the typedef AND the extern into the block. - §163b the switch-index parameter-WIDTH oracle: sll/sra straddling the minval subtract is a 2-insn signature of a short parameter. Read the extension, not just the bound. - §163c case_values_threshold is 5 — an empty `case k:` glued to default can be the only thing that emits a table at all; jtbl[k]==default label is the tell. - §163d cse deletes a reg-reg copy by rewriting the PREVIOUS insn's SET_DEST (cse.c:7440-7477). This is §162j's symptom in a DIFFERENT PASS and needs a different lever; the residual it explains had been declared "unsteerable, 30 variants all >=17" and fell to source-shape edits alone, no pins. - §163e the frame is a PSEUDO-NUMBER oracle (reload1.c:658 alter_reg in NUMBER order); dead-local slot order is not declaration order, and a BLKmode local is 8-aligned while a scalar s32 is not. Sharpens §162i, which gets the pad's SIZE right and its PLACEMENT wrong. §163z catalogues the ~35 unvetted claims by function so a future harvest can go straight to them, explicitly marked "one agent's reconstruction until re-measured" (R14). cookbook_index.py: 497 sections. |
||
|
|
0c5d6fa909 |
docs(phase-30 S48): §162 — the wave-1 idiom harvest, deduped by a skeptic pass
17 candidates from the 12 crack agents, each audited against the whole
cookbook by an independent agent before being written: NEW 3, SHARPENS 13,
COVERED 0 (one agent died mid-response — its entry, §162c, is written by the
orchestrator and labelled as the least-audited one).
The three genuinely new laws:
- §162e LICM: uniform loop-variable indexing is what makes a symbol address a
MOVABLE at all (a literal index leaves a constant, no base pseudo, no
hoist), and preheader order is body order.
- §162g cross-jump DIRECTION is a source-shape oracle: do_cross_jump always
keeps the LATER copy, so a BACKWARD jump into an earlier block can
never be cross-jumping — it is a source `goto`.
- §162n a conditionally-assigned alias pointer kills a spurious giv
(loop.c cant_derive).
Two in-place CORRECTIONS, because a reader who lands there first must not be
taught the superseded rule:
- §161a's "diagnostic tell (family-wide)" reads as a complete test on entry[0]
and actively teaches skipping the upper edge. Amended: check BOTH edges.
The maxval symptom is the OPPOSITE of the minval one — it shifts nothing and
costs two bytes, so it is functionally invisible.
- §25's triage rule prescribes pins for a symptom whose sibling mechanism
(local-alloc optimize_reg_copy_1) pins provably cannot reach, because
SMALL_REGISTER_CLASSES is never defined in config/mips/mips.h. Amended to
point at §162j.
The skeptic pass also caught two errors in MY submitted evidence: I had copied
§161a's minval symptom onto the maxval case, and I described func_8017F2D4 as
a verified MATCH when the whole-binary gate had refused it (it is still
INCLUDE_ASM). Both corrected in the entries.
cookbook_index.py: 495 sections, 14 symptom buckets.
|
||
|
|
d3f3d8ba22 |
feat(phase-30 S47-W1b/G2): 3 retries banked, 2 new rules; main signed for the first time
W1b — the 3 targets whose agents died on API rate limiting, retried with cookbook §160 in the prompt: func_801EFBF4 (reach 12), func_801EFDC8 (12), func_8018CC40 (10, jr). 3/3 confirmed by an independent verifier, all banked, R22 clean-fleet 213 passed / 0 failed of 213. func_8018CC40 failed the first gate with `too many arguments to function func_80178970` — which its own crack agent had PREDICTED in its report, naming the §17a-1 remedy. Dropped the draft's empty-paren externs and cast 6 call sites instead; banked. Read the agent's integration notes before diagnosing a gate failure — it has already seen the TU. Cookbook §161a-c (index 469 sections): §161a case 0: break; is LOAD-BEARING when a jump table is indexed from zero. The natural case 1..5 makes gcc-2.7.2 pick minval=1, emit `addiu $v1,-1`, and shift every table index — 58 of 77 mismatched on a byte-perfect body. Tell: the table's FIRST entry points at the function's own end address. Family-wide (10 members). §161b aliasing a parameter into a local can force a SECOND callee-saved register (+8 frame, +3 ins) even when uses are mutually exclusive. Suspect it before reaching for register pins. §161c loose-prototype engine helpers: don't fight the TU's (void) decl, cast at the call site. G2 — THE MAIN EXPERIMENT. family_hseq excludes main as "structurally barren — zero h_exact overlap". True and irrelevant: an h_exact claim guarding an h_seq tool. There is not even a sig-main target — main had never been signed for this pipeline. Signed it (2,002 fns, seeded from splat boundaries via corpus.stubs rather than --bootstrap, which glues functions around jtbl dispatch and would have corrupted the hashes under test). Result: main is ~85% singleton work, not 100%. internal h_seq families (>=2): 207 families / 748 fns / 11,537 ins (13.7%) shapes shared with the fleet: 161 fns / 1,346 ins (1.6%) genuine x1 remainder: ~71,034 ins (84.6%) IMMEDIATELY ACTIONABLE: 44 classes / 151 main functions / 1,239 ins already have a matched exemplar in the fleet — free propagation, invisible only because main is not in the map. Long-term: 748 of main's 2,002 functions (37%) are templatable once one exemplar per family is cracked, which refutes "2,002 independent cracks" as the planning assumption for the 79k-ins tail. OPEN, deliberately not done unilaterally: adding a sig-main target and dropping main's exclusion from family_hseq.load() changes a fleet-shared oracle every targeting tool reads. Needs Drew's call. |
||
|
|
d806766eef |
feat(phase-30 S47-W1c): crack the reach-57 exemplar; fix the instrument that called it a wall
func_801EDC18 (md_SC05_023) is the largest multiplier remaining — 57 members. The wave agent
abandoned it at "closeness 6" with class SIZE-MISMATCH [redraft]. It was two lines from correct.
THE CODE (cookbook §160a): the target copies 8 bytes with lwl/lwr + swl/swr — gcc-2.7.2's
emit_block_move for a type with ALIGNMENT 1. The draft used a u32 copy (aligned lw/sw), which is
wrong by construction. `typedef struct { char c[8]; } Blk8; buffer = D_801ED98C;` reproduces it.
Six spellings were tried in parallel; two independent agents converged on the same one.
THE INSTRUMENT (§160b) — this is the part worth more than the function. The target .s bundles a
leading `.section .rodata` block (D_801ED98C as two .word) ahead of .text. Those lines carry the
same `/* off vaddr HEX */` shape as instructions, so masked_diff.insns_from_s counted them as TARGET
instructions, while insns_from_object (objdump -j .text) can never emit them. A byte-perfect draft
therefore read `mine=26, target=28, 26 mismatched` — every position shifted by a constant +2 — and
got classified as needing a redraft. 116 of 12,583 .s files in the corpus have this shape, one at
-29 instructions. Every one of them would report a false wall to any agent that tried it.
Fixed: insns_from_s tracks .section and counts only .text. Full-corpus control: 12,467 unchanged,
116 corrected, 0 regressions. Same artifact class as §129a (post-carve jtbl inflation).
THE OWNERSHIP LAW (§160c) — my own error, corrected by the gate. Four sites declare
`extern short D_801ED98C;` and nothing in src/ defines it, so I shipped an extern-only draft. The
gate refuted it: `undefined reference`. The .s block the draft REPLACED was the definition. The
variant emitting `const Blk8 D_801ED98C = {{...}}` banks clean. Never infer ownership from externs.
R22 clean-fleet: check-all 213 passed / 0 failed of 213.
ALSO BANKED — the wave's idiom harvest, which had been sitting unwritten in workflow transcripts
(R16/R30 debt): §160d the ASYMMETRIC INDEX RELOAD (a just-stored narrow field read twice emits
reuse-then-reload; the C is deliberately asymmetric), §160e a stack-layout scheduling rule now
byte-proven on a SECOND independent function (promoting it from coincidence to rule), §160f the
address-only global store via array decl, §160g sibling-search keyed on the CALLEE SET as step 0 of
every wave prompt (one grep turned a 126-instruction crack into a copy-edit).
Cookbook index regenerated: 468 sections.
|
||
|
|
9ab9120e04 |
feat(phase-30 S47-B): conform 8 declaration axes (~10,930 sites); 3 guard defects fixed; 213/213
Task B, re-scoped from evidence. The 129 dedup_extend failures are 106 conflicting-types / 21 CC1-FAIL / 4 undefined-ref / 3 DIFF — real byte divergence is 2%, and memcpy is 17 of 106, not the story. Direction reversed too: the byte-true DEF of func_80128ED8 is what the target .c files already declare; engine_core.h's macro-local extern was the stub-era guess. Conformed 8 axes to byte-truth (func_8012F14C 2843, func_8012E5CC 2052, func_8012F038 2214, func_8014C568 1816, func_80128ED8 1524, func_8012C750 406, func_8012C0EC 50, func_80144A04 25). R22 clean-fleet: check-all 213 passed / 0 failed of 213. Zero functions banked by design. Tooling (R33/R35) — three guards that asserted completeness over a narrowed population: - NEW tools/macro_draft.py: a deduped fn has no definition in any .c (body lives in a DEFINE_ macro), so conform_decls had been refusing the largest class it was built for. - conform_decls skipped engine_core.h wholesale as "a defining TU": 10 stale externs survived while 1,514 fleet sites moved, and it still printed "axis complete". Skip now scoped to the defining macro's span. - Return-axis compare was literal: typedef int/s32 and a missing `extern` faked a return change. Now compares normalized types. - §85 consumer scan under-reported (the dangerous direction): a cast between `=` and the call hid `s0 = (s32 *)func_80144A04(...)`. Now classified by position, validated both ways. Corrections to my own predictions (R14): the documented scalar-narrowing hazard was benign across 2,052 sites; the breaks were arity (6 call sites, fixed with §17a-1 fn-ptr casts) and the consumer-guard gap. A header-only first probe broke ov_SC01_000 — §85 is literal. Not done, named: memcpy (builtin codegen), ApplyMatrixSV (no DEF), gte_SetRotMatrix (link bug), func_80147364 (unparseable macro), D_800AE620/D_80126CC4 (data axis). Cookbook §159. |
||
|
|
b0c1e14fda |
feat(phase-30 S46-final): 400+ cascade banked (11) + waste-prevention gate; B re-scoped, C blocked
- BANKED: 11 functions at 400-952 ins from the cascade (func_8017D898 952, func_8017CE58 733,
func_801902EC 673, func_8018C2D8 673, func_8018A8D4, func_8017C6F4, func_800CBB38,
func_800CF3A4, +3). check-all 213/213 from a clean tree. 6 near = jr/switch (§53 separate
banking step), 1 failed. The cascade agents wrote 6 new cookbook sections incl. §158.
⚠️ tools-health UNVERIFIED at commit (stale cookbook index fixed, confirming re-run
interrupted) — run it first next session. check-all is the byte oracle and it is green.
- WASTE PREVENTION (Drew: "prevent this from ever happening again, however you need to"):
* tools/validate_targets.py (NEW) — names 5 defect classes (NO-ASM / MID-BODY /
OUT-OF-RANGE / ALREADY-DONE / NO-BOUNDARY), exits non-zero.
* WIRED INTO wave_snapshot so it fails closed — every wave passes through there for its .s
files, so no path from target list to spawned agents bypasses validation. Negative-control:
a 3-target bad list is refused with the exact mid-body offset (+72 bytes of 100).
* The cascade `done()` predicate now short-circuits on SKIPPED as well as MATCH. It tested
only MATCH, so a non-existent target fell Sonnet -> Opus -> Fable and three agents each
proved the same phantom absent: ~29 invalid targets x 3 tiers = 87 of 119 agents, ~9.7M
tokens. A tier that cannot act must END the pipeline, not escalate emptiness.
* docs/accelerators.md A9, including that wave_snapshot's own R32 assertion REFUSED that list
(24 of 57 found) and was routed around — the one instrument warning that was right and ignored.
- B RE-SCOPED (S46-10) and deliberately NOT done: the extend blocker is INTRA-HEADER, not
target-side. engine_core.h declares memcpy FOUR incompatible ways across its DEFINE_ macros;
two in one TU collide. NOT a safe cleanup — the in-tree note at ov_MAIN_012.c:14333 records
that `extern memcpy` disables gcc's builtin and turns an inlined block-move into a CALL, so the
declaration CHANGES CODEGEN. Probe one macro in one binary and byte-gate before any sweep.
- C (dedup_extend over the 129) stays blocked on B. Full context for both in the checkpoint.
|
||
|
|
9351b17f48 |
feat(phase-30 S46-2): the master IDXTAB/DESTPTR load map — and the tracker blind spot that hid it
Drew's S45 idea, delivered fleet-wide + wired into the permanent references.
- THE BLOCKER WAS OUR INSTRUMENT (R35, the 3rd time): the S45 plan ("require a
register-verified reference to the run's address") returns ZERO for both byte-proved
tables. They are read by gcc's indexed global-array form —
lui $at,0x8019 ; addu $at,$at,$a0 ; lh $v0,-0x2844($at) -> 0x8018D7BC
— where the address exists only as (lui imm, LOAD offset) with the index add between.
find_addr_refs killed the lui register at the addu, so the halves never rejoined and
the tables looked unreachable. Now it carries the hi half through the index add (still
strictly register-tracked, never window-paired) and labels those hits `-indexed`.
- tools/idxtab_map.py (NEW): fleet-wide payload -> owning binary -> load address.
Controls-gated (refuses to emit unless ov_SC01_000 0x8017EEC8/37 + *0x801A3234, and
ov_SC03_001 0x8018D7BC/5 + *0x801EBC68 reproduce from the images alone). Index space
DERIVED from the extracted tree (reproduces §S44's table independently). Process-pooled.
Rejects all-zero and majority-zero runs (132 of the first pass's 452 "tables" were that).
- RESULT: 213 binaries -> 143 with a referenced table (294), 141 with a DESTPTR (141/141
resolved from the binary's OWN image), 61 payloads. The two dominant tables are
fleet-wide CONSTANTS (5-entry and 37-entry, identical in all 141 overlays); the
per-binary variable is the destination (134 distinct).
- CORRECTION 1 (R14): §S45 p6's "the SC03 trio are owned by ov_SC03_001" is refuted —
that 5-entry table is identical in ALL 141 overlays. The byte-observed parts stand.
- CORRECTION 2 (P9): this route CANNOT settle MAIN/7+9. They are absent from all 294
tables — but so are MAIN/13/20/34/42/44, which are byte-proved to load. Absence here
means "not on this route", nothing more. Recorded so it is not re-derived as a finding.
- Confidence is stated per-claim in docs/idxtab-map.md: proven (controls) / high (283
fleet-wide-class tables) / low (3 named rare rows) / UNMEASURED (recall — no oracle
for "all tables" exists beyond the 2 controls).
- Wired in permanently: docs/idxtab-map.md (the how/when/limits), memory-map.md §S46,
cookbook §155c (the generalizable law: "no code references X" is a claim about your
DECODER until it is shown to recognise the forms the compiler emits), SETUP.md
tooling inventory (R21).
|
||
|
|
a0236b2220 |
docs(phase-30 S45p7): correct the F1 misattribution — the cause was an orphaned reconcile
R14 correction to cookbook 156 + checkpoint p7. I blamed gate_stage's arity pre-pass (F1) for the 141/213 breakage. That was wrong: no arity journal from the session mentions func_80146A6C (74/26/4 entries checked) and the arity undo reported success in every log. The real cause was dedup_propagate --recover leaving an orphaned caller-extern reconcile (now fixed + proven, commit:1521 / commit:1522). F1 remains real, unguarded, and part of the remaining Stage-1 work -- it simply did not cause this incident. Generalizable law added to 156: a tool that deliberately leaves an edit on disk pending an outcome owes a LEDGER for it. 'Keep it if this succeeds' is half a transaction; the other half is undoing it on every path that can later invalidate the success, exit paths included. commit:1519's commit message keeps the wrong attribution (history not rewritten, corrected forward). |
||
|
|
0d05d91293 |
docs(phase-30 S45 p7): F1 confirmed live (cookbook 156) + the cheap-tier size cliff (157) + wave_snapshot
- cookbook 156: a FAILED draft can poison the fleet. gate_stage's arity pre-pass writes the shared engine_core.h before the gate; a rejected draft's caller-signature edit survived and broke 141/213 binaries. Byte-gate held (fail-closed). The trap: a broken tree makes every later gate report 'near' -- two batches of verdicts were void, not evidence. Standing practice: GATE_NO_ARITY=1, assert 'git status --porcelain src/shared config' empty after every batch, recover by revert+replay (deterministic). - cookbook 157: the cheap-tier size cliff, measured over two controlled waves. Haiku 4-27 ins 86% (~44k tok/match); >=50 ins 20% (~177k, 4x worse). The documented '<=50' band was optimistic. Agent honesty 63/63 claims true across 100 drafters. - tools/wave_snapshot.py: immutable sha1-manifested per-wave .s copy, so a running wave can no longer block R22's 'make clean'. Coverage-asserting (exit 2 on a missing target), negative-control proven. - docs/concurrency-design.md (Fable5): the lane contract, the false-bank correctness argument, and the finding that a worktree verify certifies the COMMIT -- strictly stronger than our main-tree R22, which also compiles untracked strays. - checkpoint p7. |
||
|
|
0f409249ba |
chore(phase-30 S45 p6): wave-1 banked 0 — the frontier DEFINITION was the bug; cookbook 155b
HONESTY LEDGER (the wave cost 2.5M tokens and banked nothing; root cause mine): - I FABRICATED the workflow args: after generating the real target list to args_light.json I hand-typed the array instead of reading it, inventing names and a descending nins run. ~40 of 50 agents got nonexistent targets. The agents refused to fabricate and returned accurate diagnoses -- the prompt's honesty rules held perfectly under a bad input. - I then misdiagnosed it twice with a broken check: corpus.stubs() is keyed by INTEGER ADDRESS and I compared string names (always False), producing two confident wrong claims. Pool was in fact 160/160 + 166/166 valid. -> cookbook 155b: check the TYPE your oracle returns; an exactly-0/N result is more often a type error than a discovery. R32/R35 assert coverage+correctness of a tool, but neither catches an INTERFACE mismatch at the call site. SOLID: 9 drafts independently re-verified MATCH by re-running match_one myself (not agent claims); all 9 are genuine INCLUDE_ASM stubs; kept at .run/s45p5/gate1. They did not bank (0/8 near/1 failed) -- but see the open instrument question. OPEN (do first): harvest_verify reports 619 live stubs where the single source .c holds 626 INCLUDE_ASM, and skipped a valid stub. Until explained, the 0-banked verdict is not evidence about the drafts (R35). CORRECTED FRONTIER: reach-141 identifies the most-DONE work (shared core, already DEFINE_ macros ~1,614/binary), not the most valuable. Derive targets from the build invariant (R33): INCLUDE_ASM in committed source. Big-3 = 1,799 draftable, 1,168 already seeded -- the real II.5 fuel. Tree restored: gate_stage left 659 files dirty; git checkout -- src/ config/ verified clean. |
||
|
|
a3976d73e5 |
docs(phase-30 S45 p5): the resourceIdMap branch is REFUTED for all 5 parked payloads
- resourceIdMap @0x80063138 decoded from the EXE using the index math in our OWN matched C (ResourceGetCdLoc is byte-exact): exactly 162 6-byte records, 2 negative non-CD sentinels, streamIds >=0x100 -- self-consistent with the C in every field. - FINDING: its 98 distinct global indices include NONE of gi 7/9/231/232/234, so the five parked payloads cannot reach ResourceGetCdLoc/StreamLoadStateMachine/D_80068B60. The S44 'descriptor path' branch of the parked-dest disjunction is refuted; only the per-overlay IDXTAB/DESTPTR route survives. - R34 corroboration: loadDestPtrTable's 5 u32s re-derived independently and reproduce the S44 table exactly (0x800CEDF8/0x80128158/0x800CAE08/0x800CCB1C/0x800C7F08). - R14 CORRECTION to S44: 'IDXTAB ... same list fleet-wide' is wrong. The 37-entry list at 0x8017EEC8 is real for ov_SC01_000 only; 140 of 141 overlays hold unrelated bytes there. IDXTAB is per-overlay data at a per-overlay address; only the mechanism is shared. - NEGATIVE TOOLING RESULT (cookbook 155a): a shape-only IDXTAB scan passes its R32 coverage assertion and is still non-discriminating (664 'tables'; hits are (offset,count) pair data). Coverage != discrimination -- two different oracles (R34). Recorded so it is not repeated; next instrument is a register-tracked decode of func_80128CFC (155). |
||
|
|
7e9394f691 |
fix(phase-30 S45 p4): R14 correction — the MAIN/7/SC03-trio 'loader fn' leads were scanner phantoms
- the quick hi/lo sweep paired lui/lo16 WITHOUT tracking base registers -> phantom refs
(0x800AE868 read where the true target was 0x8018E868); register-tracked rescan: the ONLY
literal loc-table ref fleet-wide is SC02/9's (solved)
- standing truth: MAIN/7, MAIN/9, SC03/53/54/56 all load via table-INDEXED paths; homework
respecified (descriptor-data hunt + ResourceGetCdLoc/StreamLoad index math)
- fn 0x80161E08's real gate: currentLocationId vs {0x3012,0x3054,0x3079,0x3096} — the
'variable 0x800C3054' never existed; cookbook §155 (track the register)
|
||
|
|
c697746462 |
docs(phase-30 S44 I.0): the static loader routing table + the full tool audit — knowledge captured
Plan-approved campaign (Fable5Max, ~/.claude/plans/optimized-squishing-engelbart.md). I.0 = capture
while hot (R30/R31), before any code:
- memory-map.md §"Phase 30 S44": the COMPLETE loader routing table, static-derived (G5) — the EXE's
loadDestPtrTable (0x80072C70: resident/overlay/slotA/slotB/type-7), the boot k-set {1,3,8,10,11},
the RESIDENT's index tables D_800D3764 (29x8, MAIN/13-41 -> 0x800CAE08) and D_800D384C (6x8,
MAIN/42-47 -> 0x800CCB1C), resident.c:641 (MAIN/12 -> 0x80128158), the SC07 pair's header-derived
0x801A00D8, gbase arithmetic (LIST.CD carries LBA+len ONLY), the slot-adjacency proof, the
module-id-word law (word0, dense 0x13..0x73, resident=0x36; MAIN/9-vs-39 duplicate flagged), and
"PAC type 1 = uncompressed overlay, type 4 = LZSS". SUPERSEDES P3-T5's "entries [1]+ are
runtime-indexed (no static xref)".
- disc-completeness.md: the "only knowable by runtime RE" doctrine REFUTED in place (H5, original
kept) — 46 of 78 addresses are static; the runtime-only remainder is 28 script modules + 4
stragglers, parked for L3 with evidence. Byte-sum correction (rows 3,406,325 B vs bucket
3,564,021 incl. PAC headers), MAIN/7 raw-path exception, MAIN/0≡1.
- tooling-audit.md §S44: EVERY tool classified with file:line — 8 must-change (family_remap VRAM
const, Makefile+modules.mk, sig-target generalization, audit_binaries de-ov_, family_hseq/
progress:647/audit_frontier globs, corpus.sig_is_independent), 7 one-line registrations, 5
retirements (disc_code_sweep superseded by disc_audit; reconcile_decls; 3 rollout one-shots;
ImportOverlay/VerifyOverlay.java), rest auto-OK/N-A. new_overlay.sh -> new_binary.sh design.
- decision-log (R31): the pivot entry — the emulator dependency dissolves; the "modules" mostly
dissolve into overlays (~75-77% h_exact-known; 802 novel fns); why the doctrine was missable for
30 phases (a confident negative doctrine is a claim like any other — date it, cite it, re-measure).
- cookbook §154 + index regen (454 sections): module-id word / dual base-voting (h_exact ~500:1 +
jal-alignment, must AGREE; thin votes => park, P9) / diff a mystery payload's head against classes
you already own before inventing a new one.
|
||
|
|
37c60a5ff3 |
feat(phase-30 S43): R22 CONFIRMS ALL 18 BANKS 140/140 — fleet 94.99% instr; §147 refuted by the bytes
- ✅ R22 CLEAN-FLEET: make clean && extract-all && check-all -> 140 passed, 0 failed of 140.
Discharges the [R22 PENDING] caveats on commit:1486 (the 0xECC family x12) and commit:1487
(func_8018D98C). All 18 of today's banks are confirmed, not incremental artifacts (§130).
- FLEET: 96.63% fn-count / 94.99% instr-weighted (12,501,204/13,160,961) / 89.4% distinct-code.
Session +16,831 instructions, 18 functions. P30's 95% instr bar is 1,708 instructions away
(18,539 at session open). NOTE the report line rounds to "95.0%" — the bar is NOT yet met.
- THE 5th WAVE AGENT: func_8017CE58 is TWO bodies at one address (246 in SC02_000/003, 734 in
SC03_092). The 246 body is byte-identical to func_8017C294 — THE FUNCTION §147 WAS WRITTEN FROM —
so one draft covers 4 instances, and it went 12 (with a recorded "stop searching" verdict) -> 2.
- §147 CORRECTED IN PLACE (H5: original text preserved, correction appended):
* A "stratum 3, unreachable from C" is REFUTED — there is NO stratum 3. The frame is declared
locals then reload spill slots in pseudo-regno order; the mystery 0x108 slot is an ordinary
spill on a loop.c-created pseudo, reachable by writing the loop as an INDEX loop (a pointer
walk puts it at the bottom). Prior drafts faked it with volatile pEnd + dead[7]. (121 -> 54)
* B the unreferenced slots are combine-orphaned sign-extension intermediates (combine.c:10839),
not "?: on memory" frame cost.
* E the qty_compare tie IS breakable — §148-C's zero-emission ref slider. (30 -> 25)
* D applied properly (drop volatile out + the $24 pin, let a1 spill) remains: 54 -> 30.
- CONSEQUENCE: func_8017C294's 15 siblings were parked "until stratum 3 is explained" — that hold
is VOID. Both near-misses logged to the ledger with their measured closeness, not forced (P9).
- PROCESS LESSON in §147: a confident NEGATIVE verdict is a claim like any other — date it, name
its evidence, and re-measure it before letting it park work (same shape as §146).
|
||
|
|
dee33412db |
feat(phase-30 S43): func_8018D98C banked (710 ins) + §153 the address-rematerialisation launder [R22 PENDING]
- func_8018D98C (ov_SC06_033, 710 ins): MATCH, gated, carved into its own split
(src/ov_SC06_033/ov_SC06_033_jr_8018D98C.c); image matches its locked SHA; stub gone.
NOT a family — `find asm -name func_8018D98C.s` returns exactly one file, so this banks 1x710.
The prompt's "renderer sibling" premise was wrong: it is a 12-state entity state machine over
jtbl_801CF234; func_8017C6F4's C shares nothing with it. Structurally exact on the first draft.
- §153 THE ADDRESS-REMATERIALISATION LAUNDER (third zero-emission asm lever, after §148-C's allocno
numerator and §151's blocked scheduler tick): an `&SYM` used as an argument >=2x in ONE cse basic
block gets its pseudos unified (4 refs), so local-alloc.c:1080's remat path (needs reg_n_refs==2)
never fires and global.c:388 hands it a CALLEE-SAVED register, cascading a rename. 14 probes prove
no respelling reaches it (do/while splits cse1; cse2 puts it back). Cure, zero bytes, one per site
in its own block: `{ s32 _m = (s32)&SYM; __asm__ __volatile__("" : "=r"(_m) : "0"(_m)); f(x,_m,y); }`
— the volatile asm is never entered in cse's table AND sets _m, emptying the equivalence class.
Placement is load-bearing (#APP is a scheduling barrier); with two address args, launder BOTH.
- INTEGRATION CAUTION: the agent's TU-CONFORMED variant gated DIFF while the PLAIN one banked.
rtu_match MATCHing does not promise a decl-rewritten variant survives the real build — gate the
plain variant first.
- R22 clean-fleet still owed (one agent remains on asm/); this and the 12 family banks are
incremental-gated (§130) until it runs.
|
||
|
|
f5498c3c66 |
feat(phase-30 S43): the 0xECC family — ONE crack banks 12 overlays / 11,364 ins [R22 PENDING]
⚠️ R22 CLEAN-FLEET OWED (two agents still reading asm/, so `make clean` is unsafe). Each of the 12
was gated whole-binary AND independently re-checked against its own config/check.<bin>.sha (12/12),
stubs confirmed replaced — but incremental (§130). Treat as UNCONFIRMED until the clean run.
- THREE isolated cheap-Opus agents, briefed with §150/§151 + the mandatory all-drafts scan,
CONVERGED INDEPENDENTLY: func_8017C6F4's 947-ins body exists in 12 OVERLAYS under 5 DIFFERENT
NAMES at 6 DIFFERENT ADDRESSES, each differing by exactly TWO per-overlay symbols (screen-rect
helper + 64x64 cell table). Gated 12/12, 0 failed. 11,364 ins from this morning's single crack.
- WHY IT HID ~30 PHASES (cookbook §152): name-keyed grouping scattered it across 5 names,
address-keyed across 6 addresses (and the address collides with an unrelated 15-ins body in 3
other overlays), and h_seq-keyed scattered it too — which is why the Phase-26 sweeps missed it.
THE KEY IS BYTE SIZE: `grep -rl 'nonmatching .*, 0xECC' asm/*/nonmatchings/*/` returns exactly
the 12, reads the asm (cannot go stale like family_hseq.json), no false positives. Refines the
Phase-26 "h_seq is spent" finding: h_seq is worth exactly ONE size-keyed sweep behind each FRESH
core crack — here it paid 11:1.
- TWO CAUTIONS THAT TRAVEL WITH IT: (1) a MASKED tool cannot validate a remap — match_one and
rtu_match both mask jal/%hi/%lo, exactly the fields a remap edits, so a wrong symbol map still
reports MATCH; gate remaps by the whole-binary SHA only. (2) a stale residual is NOT evidence two
functions differ — I briefed "func_8017C59C scores 340, different body"; refuted in one command
(that 340 came from a pre-§150-fix draft, which scores nonzero against its own target too).
- OPEN TOOL DEFECT (R32): family_remap's unit backscan halts at the first #define, so it carried
16/16 gte macros and 0/10 typedefs, silently — the §146 gap from the other side.
- MY ERROR, RETRACTED IN THE LOG (S43-9): I reported the 263x5 cluster as "5 byte-identical, 1,315
ins". FALSE — the drafts had been reverted, so I measured the INCLUDE_ASM STUB BASELINE, which is
byte-identical by construction. R34's trap, self-inflicted by hand-building instead of using
harvest_verify. Nothing was banked there; the cluster is UNRESOLVED. ("41 behemoth drafts" was
likewise a file count — 79 files, 20 distinct functions.)
|
||
|
|
01d7d3276c |
feat(phase-30 S43): FABLE5 CRACKS func_8017EF68 (the 2-of-969 wedge); R22 CONFIRMS ALL FIVE BANKS 140/140
- func_8017EF68 MATCH 969/969, re-verified by me, gated: ov_SC06_000 byte-identical at da4a26ff.
- MECHANISM (from cc1's own -dR trace, not inferred): the r3000 machine description gives the
memory unit load-ready-cost 2 / store 1, so blockage(load,store)=2 — a LOAD CAN NEVER BE PICKED
IN THE TICK IMMEDIATELY AFTER A STORE PICK. sched2 therefore always wedges one ready ALU insn
between the lw and the sh, and the target's zero-wedge order is UNREACHABLE BY ANY STATEMENT
ORDER. That is why ~20 documented hand variants AND the repaired permuter both floored at 2.
The draft's own §49 sched1-LUID story was incomplete — real but secondary.
- THE LEVER (cookbook §151, "the ghost wedge"): a zero-emission tied in/out asm
`__asm__("" : "=r"(v) : "0"(v), "r"(rival));` — 0 bytes, but a schedulable insn that absorbs the
blocked tick, and it sets reg_n_sets(v)=2 which also kills sched1's birthing boost (one
instrument, both passes). Two measured fallouts: rival-read in the same asm (22->12), then a
second re-tie on a HIGH-REF host to restore allocno live-length parity (each in-loop insn is +1
live length for every loop-spanning allocno; a trio of invariant addresses sat exactly on
allocno_compare's integer-floor boundary). Host choice empirical: pkt=MATCH, ot=705, double=10.
- ✅ R22 CLEAN-FLEET: make clean && extract-all && check-all -> 140 passed, 0 failed of 140.
This DISCHARGES the [R22 PENDING] caveat on commit:1484 — all five banks are confirmed, not
incremental-build artifacts (§130).
- FLEET: 96.63% fn-count / 94.9% instr-weighted (12,489,130/13,160,961) / 89.2% distinct-code;
0 NON_MATCHING (G4); dedup 1919 groups. Session +4,757 ins from 2 cracks x 5 binaries.
Distance to P30's 95% instr bar: 13,782 ins (was 18,539 at session start).
|
||
|
|
25402b2eb4 |
feat(phase-30 S43): FABLE5 CRACKS func_8017C6F4 pin-free — banked ×4 (~3,788 ins) [R22 PENDING]
⚠️ R22 CLEAN-FLEET VERIFY IS OWED, NOT DONE. All four gates below were INCREMENTAL builds
(§130: an incremental build can report BYTE-IDENTICAL for a change a clean build cannot link).
Committed now only to protect the work — a second Fable5 agent is reading asm/, so `make clean`
would destroy its inputs mid-run. The clean-fleet run follows the moment that agent finishes;
treat these four banks as UNCONFIRMED until then.
- THE CRACK (Drew approved the Fable5 escalation, R27): byte-exact, PIN-FREE, 947 ins. My §147-E
"qty_compare tie, unreachable from source" diagnosis was WRONG. The residual was VARIABLE
IDENTITY: (1) the X-pass and Y-pass min/max intermediates are DIFFERENT variables (8, not 4
reused); (2) mnc/mxc do not exist — the cell clamps reuse the prim-loop mn/mx (X) and mny/my (Y).
Ablations: split-only 63, reuse-only 624, conjunction MATCH. That is also why S42's "separate
X vs Y variables" probe was filed as a failure (it was half the fix), and why every allocator
lever was inert — pins, §148-C sliders, declaration order and 14 permuter restarts cannot reach
a draft with the wrong NUMBER OF PSEUDOS.
- VERIFIED INDEPENDENTLY BEFORE BELIEVING IT (R14): I re-ran match_one -> MATCH (947 ins), then
the whole-binary gate per binary.
- BANKED ×4 (every 948-ins sibling of this body), each byte-identical:
ov_SC03_126 c48a8bb8 · ov_SC03_003 898bf52a · ov_SC04_021 33614234 · ov_SC05_019 3f5b4f13.
family_remap produced all three siblings cleanly.
- §146 SEEN AGAIN: all three siblings first failed with `PLUMBING: parse error before 'MTX_C6F4'`
— _carry_macros carries #defines but NOT typedefs; prepending the 9 typedef lines fixed all
three. That label is legible ONLY because of this session's classifier fix; before it, it read
"CC1-FAIL: make: *** Error N" and cost a manual splice-and-rebuild each.
- cookbook §150 (decode register ownership from the MATCHING diff regions before touching the
allocator; per-instance register asymmetry ⇒ per-instance variables; the deleted-self-move tell
and the global.c:719-vs-:729 death-before-store exemption behind it). §147-E corrected: it named
the wrong allocator — these are global.c allocnos, not local qty_compare quantities.
|
||
|
|
b20b397a5d |
docs(phase-30 S43): the "26 unpropagated members = cheapest fuel" is REFUTED — 0 of 31 templatable
- RE-DERIVED from the tree (R35): the S40 propagation banked 59 families; 22 still have open
members = 31 instances, not the carried 26.
- SCANNED all 31 (not sampled, S4's lesson): mechanical family_remap from EVERY binary where the
same fn is already matched (up to 4 sources each) fails 31/31 with gross reloc-count mismatches
(2!=15, 12!=2, 11!=20, 2!=0). Script + JSON: .run/s43/probe_leftovers.{py,json}.
- WHAT THEY ARE: structurally DISTINCT bodies sharing an address and a name — the func_8017C6F4
15-vs-948 collision one level down. family_hseq independently agrees (R34): these cluster into
families with matched=0, several n_members=1. No matched sibling => nothing to template from =>
the failures were NEVER plumbing. They are per-member drafting work, not deterministic fuel.
- SCOPE STATED (P9): what is refuted is mechanical remap from a matched sibling (0/31). An
h_seq-staged draft + recovery ladder is formally untested — but that path produced the original
CC1-FAILs, its labels were content-free until this session, and --hseq --only now stages 0
families for these addrs. Cost the next wave as agent work.
- cookbook §149: the four instrument defects of this session as ONE pattern (silent fallback =
"found nothing"; same addr != same body, ledger side; make's wrapper is not a diagnosis; carried
cheap fuel nobody probed) + the rules each one yields.
|
||
|
|
63d029b563 |
fix(phase-30 S43): the §148 "GTE macro wall" is a SILENT CPP FALLBACK — permuter lane was dead on 63 drafts
- ROOT CAUSE (reproduced): make_base_c ran cpp_expand_macros BEFORE #include lines were dropped, so `cpp -P -nostdinc -` died on `#include "common.h"` (rc=1, empty stdout) and the `return c` fallback handed back the UNEXPANDED draft. hide_asm then ate the gte_* #define block + the function itself -> "Function not found in base.c" -> decomp-permuter no-opped in 0s, indistinguishable at the call site from "searched, found nothing". - FIX: strip #include inside cpp_expand_macros (byte-neutral) + RAISE on cpp failure (R32/R35, no silent fallback); NEW defines_fn() assertion in setup() guards the OUTPUT so it catches every swallow cause (this, the §G comment class, future macro shapes); main() catches per-fn so a bad draft is loud+counted but cannot abort a batch. - VERIFIED: func_8017C6F4 base.c keeps the def, 0 gte_ macros left, 35 asm b64-carriers; proxy validated over 388 stored drafts = 0 false alarms, 0 cpp raises (macro-free untouched); permuter now loads at base score 65 and iterates (was a 0s no-op). - BLAST RADIUS (14,899 drafts scanned): 63 carry `#define … __asm__` + `#include`, incl. the behemoth renderer drafts — the permuter was silently dead on the highest-byte-weight targets. - CONSEQUENCE (R14): §147/§148's ~40-probe floors were measured with the permuter UNAVAILABLE; "the permuter also plateaus" was never actually tested on those functions. §148 note corrected. |
||
|
|
de141dc221 | docs(phase-30 S42): cookbook §148 — the loop.c hoisting threshold arithmetic, the MIN_EXPR clamp fold, the allocno-priority slider; and the x16 claim corrected | ||
|
|
bcdf6750bd | docs(phase-30 S42): cookbook §147 — the three-stratum frame law + four stop-searching verdicts (from the serial func_8017C294 run) | ||
|
|
4aa7dbdfa4 | docs(phase-30 S6): cookbook §146 — re-measure a wall before respecting it; both giants fell to stored drafts | ||
|
|
443a3e3afe |
feat(phase-30 S40): waves 1+2 bank 24/24 after recovery — ZERO codegen walls; +5,479 ins
Two ultracode waves over the open-only h_norm clusters (the pool nobody had ever aimed a wave at),
pool VERIFIED from the sigs first (R14).
wave 1 8 targets 8/8 match_one 5/8 gate first pass -> 8/8 after recovery
wave 2 16 targets 16/16 match_one 14/16 gate first pass -> 16/16 after recovery
THE HEADLINE IS NOT 24/24 -- IT IS THAT NOT ONE FAILURE WAS CODEGEN. All six first-pass gate
failures were TU-integration plumbing, each with an already-documented lever:
func_801802EC redefinition of morph_lerp strip the §77 PROBE LAYER (the draft carries types +
a static inline so match_one can compile standalone;
the real TU already defines them -- scaffolding is
not part of the bank)
func_8018B238 conflicting types D_80115158 recover_giant: draft declared it file-scope as a
struct array, TU declares u8[] BLOCK-scope inside
other functions -> block-scope the draft's externs
func_8017EF54 conflicting types (SELF) §37/§124 def-side asm-label alias (TU declares
void f(void) for no-arg callers; byte-true def takes
s32 in $a0; no-proto escape illegal once a param
promotes)
func_80183D78 conflicting types (callee) recover_giant
func_8017F278 conflicting types func_80146C3C §17a-1: the fleet canonical is the NO-PROTOTYPE
form + the intended signature applied AT THE CALL
SITE; a concrete prototype collides with it
(wave-2's 14 first-pass banks needed nothing -- the wave-1 lessons were folded into the prompt)
=> the gate number measures INTEGRATION, not matching. Run the recovery ladder before recording a
wave's yield or the metrics under-report the drafters and send the next wave hunting walls that are
not there. docs/wave-metrics.md S40-1.
POOL VERIFICATION (R14, and it cut both ways): the frontier report's cluster pool MEASURED
1,677 clusters / 5,795 fns / 319,755 ins at a 3.68x multiplier vs its claimed 1,689 / 5,956 /
326,261 at 2.7x -- within 2-4%, and the multiplier is BETTER than claimed. The SAME document's whale
claim was 3/4 wrong. Verify each claim separately; do not accept or reject a source wholesale.
ALSO: 24/24 members propagated from wave 1's 5 banked exemplars (0 failed) -- the same machinery
that returned 0/39 before this session's cast_call_sites fix.
NEW IDIOMS, distilled in-session (R16/R30):
§144 the LITERAL'S SPELLING picks the immediate encoding (`cnt + 0xff` vs `cnt - 1`: mod-256
identical, both one addiu, but gcc emits 0x00FF vs 0xFFFF from the source text)
§145a combine_givs ANCHOR RULE -- the address-giv group anchors on the LAST address-giv in SOURCE
order (record_giv prepends, combine_givs takes the head); store order decides the base and a
wrong choice spawns a third induction register
§145b a bare `p = r;` is a COMBINE BARRIER (can_combine_p/use_crosses_set_p) -- it preserves a
pointer-bump addiu that combine would otherwise fold into every MEM offset
§145c chained assignment `a=b=c=0` emits stores RIGHT-TO-LEFT
VERIFIED: make clean && make extract-all && make check-all -> 140 passed, 0 failed of 140.
Fleet 12420375 -> 12425854 instr (+5,479); distinct +5,479 / +43 uniq; fn-count +43.
audit-digest OK. 0 NON_MATCHING (G4). Cost: 3.73M subagent tokens across 24 agents, 0 errors.
|
||
|
|
84d1193f21 | docs(phase-30 S40): cookbook §144 (literal spelling = immediate encoding) + wave-metrics S40-1 (8/8 after recovery, 0 codegen walls) | ||
|
|
6e0b1605c6 |
fix(phase-30 S40): cast_call_sites read a RETURN as a prototype and deleted it — 0/39 sweep becomes 18/39
THE BUG. tools/cast_call_sites.py classifies a declaration line with
^([ \t]*)(extern\s+)?([A-Za-z_][\w \t\*]*?)\b([A-Za-z_]\w*)\s*\(([^;{]*)\)\s*;
Feed it a return statement and `return` is a perfectly good identifier where a type is expected:
return func_8012CB64((s32)out, -0xC0, 0x40, -0x60, 0);
^^^^^^ captured as the return TYPE, func_8012CB64 as the DECLARED NAME
so the "rewrite this decl to canonical" path REPLACED the statement with
`extern s32 func_8012CB64(s32,s32,s32,s32,s32);`, DELETING the return. In C89 a declaration after a
statement is a parse error, so the damage surfaced as a bare syntax error in the DRAFT -- reading as
the draft's fault, not the tool's. 9 of 9 staged members of family 0x801848dc lost their return.
fix: a keyword guard (a declaration's type-specifier can never begin with a statement keyword)
family_sweep --hseq --band all over 5 families: 0/39 -> 18/39 banked (only the guard changed)
⚠️ AND THE TRAP INSIDE THE FIX: the obvious R33 move is "route it through cdecl". CHECKED, and it is
WRONG -- cdecl.parse() is a DECLARATOR-GRAMMAR parser that assumes it was handed a declaration; it
reports `return func_X(...);` as declaring func_X and `if (f(a));` as declaring `if`.
Statement-vs-declaration is a question cdecl does not answer. Routing there would have been a silent
non-fix that looked principled. §134's law still holds for line-SHAPE masking; this is a different
question.
BLAST RADIUS (measured, not assumed -- R14): cast_call_sites is in gate_stage's DEFAULT pipeline
(canon_resident_calls -> cast_call_sites -> sig_unify -> harvest_verify) and has been since Phase 20.
Of 44,833 stored drafts, 318 (0.7%) carry a `return f(...);` line this mis-reads, across 67 callees
(func_8014F468 x41, func_8014F6F4 x37, func_8014F74C x32, ratan2 x25). Every one, every time it
passed the gate pipeline, lost its return and failed as PLUMBING. Part of the historical plumbing
tail is this bug.
ALSO IN THIS COMMIT
- S5 CALIBRATION WAVE (8 agents, ultracode, 1.31M tokens). Pool VERIFIED FIRST (R14 -- Fable's whale
claim was 3/4 wrong): measured 1,677 clusters / 5,795 fns / 319,755 ins at a 3.68x multiplier vs
its claimed 1,689 / 5,956 / 326,261 at 2.7x -- its numbers hold, and the multiplier is BETTER.
Result: 8/8 match_one MATCH (close=0), and 5/8 banked whole-binary -- the §52b/§61 gap is
integration, not codegen. Banked: func_801822E0 func_8017EC98 func_801851A8 func_80189A34
func_80188E10 (693 ins x1 before propagation). Not banked: func_8018B238 (FAILED),
func_8017EF54 + func_801802EC (NEAR) -- drafts kept in .run/wave-s40/ for recovery.
- 18 member-banks from the re-run sweep (the cross-address free-h_exact pool: h_exact-identical at
DIFFERENT addresses, which dedup_propagate correctly refuses since it assumes position-locking --
family_sweep is the right lane).
- cookbook §143 (this bug + the cdecl trap + the blast radius); index regenerated.
VERIFIED: make clean && make extract-all && make check-all -> 140 passed, 0 failed of 140.
Fleet 12419169 -> 12420375 instr; distinct +1,526 / +5 uniq; fn-count +23. audit-digest OK.
0 NON_MATCHING (G4).
NEW IDIOM FROM THE WAVE, not yet folded into §31 (agent was told to write only its draft): a byte
counter must be spelled `cnt + 0xff`, NOT `cnt - 1`. Both are mod-256 identical and both compile to
one addiu, but gcc-2.7.2 picks the immediate encoding from the SOURCE SPELLING (0xFFFF vs 0x00FF).
Also flagged: .run/ghidra_c/func_8017EF54.c is a stale decompile of the WRONG function.
|
||
|
|
6d684ac650 | docs(phase-30 S39): cookbook §142 — the free h_exact pool; propagate the matched body, don't gate a draft | ||
|
|
e9c66a6720 |
fix(phase-30 S39): close the §134 class — the last two line-shape scanners route through cdecl._mask
§134 had been patched individually in six tools; the standing note said the fix is ONE masking
oracle, not a seventh regex (R33). The last two holdouts are migrated.
progress.py.strip_comments — a private 2-line regex, NOT string-aware, feeding three line-shape
decisions in classify(): the {-vs-; definition/declaration scan, the count('{')-count('}') body
walk, and the empty-vs-real body test. A brace inside a string literal therefore mis-buckets a
function in the FN-COUNT metric. Negative control:
void f(void) { puts("}"); x = 1; }
old regex -> body-depth -1 (the string's brace was counted)
cdecl._mask -> body-depth 0 (correct)
Metrics IDENTICAL before/after on today's corpus (341365/353717; REAL 339510, empty 896, stubs
12345) -- a latent defect, harmless until someone banks a function containing "{".
lint_symbol_refs.strip_comments_strings — correct, but a SECOND implementation of the same
masking. Deleted in favour of cdecl._mask. The one behavioural difference (_mask blanks the quote
DELIMITERS, the private scanner kept them) was CHECKED not assumed: irrelevant because every token
the linter hunts lives outside the quotes. Gated on the linter's OUTPUT being byte-identical across
the change (it is), not on the two masks being byte-identical -- the right gate is the tool's
answer, not its internals.
cookbook §141 + index regenerated. No src/ or config/ change; no bytes touched.
|
||
|
|
1576570271 |
fix(phase-30 S1e): the distinct-code "regression" was a STALE DIGEST — alias lever ungated
The S38 checkpoint gated the phase's best lever ("do NOT scale the alias lever") on
distinct-code falling 89.3 -> 89.2. It never fell.
PROOF (each commit's metric recomputed from its OWN committed tree, 0 unresolved):
commit:1426 TRUE : instr 12394533 distinct 5022306 (77895 uniq)
commit:1426 COMMITTED: instr 12402412 distinct 5029324 (78025 uniq) <- stale
HEAD TRUE == COMMITTED: instr 12405402 distinct 5025082 (77952 uniq)
=> true delta 843->HEAD: instr +10869, distinct +2776 ins / +57 uniq. ALL ROSE.
The 843 digest was generated from a working tree still holding work REVERTED before the
commit landed (+7,879 ins / +130 uniq overstated) and never regenerated, so the next
HONEST digest read as a fall. => THE ALIAS LEVER IS UNGATED (scale it, §61 small batches).
Both recorded leads were wrong (R14): progress.py:423's SIG regex feeds fn-count ONLY
(neither weighted metric sees a C identifier — both derive matched = sig - corpus.stubs),
and "the harvest reverted functions to INCLUDE_ASM" died on one grep (483 removed, 0 added).
The 3-grep proof: identical sigs + unchanged tools/ + zero +INCLUDE_ASM => HEAD's stub set
is a strict subset => both numerators are FORBIDDEN to fall.
THREE INSTRUMENT DEFECTS, all one class (a bare except around a fail-CLOSED oracle):
- progress.py stub_addrs wrapped corpus.stubs in `except Exception: return set()`. An empty
stub set means "could not answer", not "no stubs", so matched = sig - stubs credited EVERY
function. Byte-witnessed: instr 100.00% / distinct 100.00% in a tree with no asm/. Now
propagates.
- cast_call_sites.tu_for + reconcile_tu.tu_for had the identical swallow, falling back to the
default <ov>.c instead of the jr/-O0 split TU — silently reinstating the exact bug
cast_call_sites' own docstring says it exists to fix. A wrong-TU reconcile fails the gate,
and this phase's base rate is ~24k PLUMBING vs 4,917 DIFF, so it presents as a codegen wall.
Now propagate CorpusError; ValueError fallback for curated names preserved; derived-TU path
re-verified (a _jr_ split stub resolves correctly, both tools agree).
NEW GATE (R34 — the byte-gate is a null oracle for DOCUMENTS; check-all stays 140/140 over a
stale digest forever): tools/audit_digest.py + `make audit-digest`, wired into tools-health
after report. Recomputes the three headline metrics from the current tree and fails if the
committed digest disagrees. Compares INTEGERS, not percentages — the +7,879-instruction
staleness printed as "94.4%" on both sides. Negative-control-proven against the stale 843
digest (fails, exit 1) and green on HEAD.
Verified: make report exit 0 (dedup-check 1910 validated / 0 failed, C1 coverage
241216/241216); audit-digest OK; cookbook-index OK (398 sections); metrics unchanged by the
fix (94.40% / 89.18%). No src/ or config/ edits — no bytes touched, nothing banked.
cookbook §140 · decision-log 2026-08-04 · SETUP.md inventory (R21) · R14/R32/R34/R35.
|
||
|
|
e977205bb8 |
docs(cookbook): §139 — a gate that greps for verdicts must assert 1:1 accounting
The wave-6 gate printed BANKED 5 / FAILED 1 over SIXTEEN drafts and nothing said so. Captured with
the three corollaries that outlive the bug (R30 — written in the session that produced them):
(a) the byte-gate is a perfect CORRECTNESS oracle and a NULL COVERAGE oracle (R34 again), so every
wave-level tally is a coverage claim and needs its own assertion;
(b) a pipeline's exit status is the LAST command's — "family_sweep ... | tail" hid a non-zero exit
in this same session; use pipefail/PIPESTATUS or the tail IS the error handler;
(c) a reverted CONFIG needs a re-extract before the next measurement means anything (the Phase-20
R22 corollary; skipping it made three genuinely-banked functions read as failures).
Plus the inverse-lookup trap: a just-banked head LEAVES its family's members list and becomes
exemplar.kind='matched', so a member-list lookup reports "no family" for exactly the heads you just
banked. Distinct from §138 rule 4, which governs target SELECTION.
Index regenerated: 393 sections, 3 new symptom keys.
|
||
|
|
7a4abddbfa |
feat(phase-30 S34): wave 2 — 10 heads + 18 members; the search order had a cross-overlay hole
Fleet 96.24% fn-count / 93.9 -> 94.0% instr / 88.4% distinct. R22 clean-fleet: 140 passed, 0 failed of 140. dedup 1910/0. WAVE 2: 13 targets / 37,943 templatable ins. 19 agents, 4.5M tokens. Claimed 11 MATCH; the whole-binary gate banked 9, +1 on reconcile (func_8017E5D0 via the §37/§124 DEFINITION-side alias — the TU declares it `(void)`, the byte-true def takes a pointer). Reconcile lane now 19/20 lifetime. 18 members swept. THE FINDING (an agent caught a hole in our own procedure). §136c's search order — engine_core.h near-twin -> same-TU banked sibling -> the .s — is entirely SAME-TU or SHARED-HEADER scoped, so no step can reach a banked twin in a DIFFERENT overlay's TU. But the large template classes live cross-overlay by construction. func_80188C04 (328 ins) turned out byte-identical to an already-banked func_801833F0 in ov_SC02_028, and ONE command found it: `grep -rn "E100000A" src/` — a magic word lifted from the target .s. The body was then reused verbatim, only file-local suffixes renamed. Promoted to STEP 0 of §136c, ahead of engine_core.h. That compounds with the manifest finding this session: the family map's `exemplar` is an IN-FAMILY pointer, so a family whose twin is banked elsewhere looks un-cracked — and the pointer can itself name an ALREADY-BANKED instance, hiding the family from any ranking built on it. Derive open sites from corpus.stubs over the member list instead. Measured on this wave: ranking off the map's exemplar gave 16,696 templatable ins; deriving from corpus.stubs gave 41,023, including a 55-ins family open in 138 overlays and a 46-ins one in 133. HONEST ON THE SWEEP: those two big families templated 18/165. That is the known h_seq refusal ceiling, not a new wall. One agent reported "all 10 members distance 0" — that is NORMALIZED distance, not h_exact, which is why dedup_propagate correctly answered reach<2. Do not read a normalized-distance claim as an h_exact guarantee. LEDGERED (real residual, not paperwork): func_8017F7B4 — needed its sibling's type names AND a data asm-label alias for a u8-shaped symbol, and still refuses. Plus func_8017C294 (DIFF close=12: 4 register/schedule permutations + a frame where I can get the 0x138 size OR pEnd's slot at 0x108, not both) and func_801898E4. |
||
|
|
138e21c7d4 |
feat(phase-30 S33e): both gate-refused drafts reconciled — the lane is 18/18 lifetime
Fleet 96.23 -> 96.24% fn-count / 93.9% instr / 88.3 -> 88.4% distinct. R22 clean-fleet: 140 passed, 0 failed of 140. dedup 1910/0. func_8017D318 (184 ins) + func_80181EE0 (198 ins) both banked, + 6 members swept (6 per-overlay variants failed — ledger material, not a lever). THE RECONCILE DIRECTION DEPENDS ON WHERE THE TU'S DECL IS, and picking wrong CREATES the next error (-> cookbook §138): - decl ABOVE the splice point -> DELETE the draft's duplicate (§100). func_8017D318: the TU defines MATRIX_/SVECTOR_8017C290, D_801EA8C0 AND a `struct PW8017C290` tag above it; I missed the tag on the first pass, so it took two rounds. - decl BELOW the splice point -> KEEP a decl in the TU's EXACT shape and cast at the use (§17a-1 D2). func_80181EE0: I removed its decl assuming the TU provided one; the TU's `extern int func_80143C74(short *, int);` is at L5082, ~180 lines BELOW the splice at 4901, so the identifier went undeclared. Grep the TU for the symbol and compare line numbers with the stub line first. MY OWN §136a VIOLATION, recorded: the blocker-capture filtered the build log for `error|conflicting|undefined reference` and reported "NO COMPILE ERROR" on a build that was failing with `redefinition of struct PW8017C290` and `'func_80143C74' undeclared` — neither phrase matched. A narrow keyword filter is exactly how a real error goes unseen, which is the thing §136a exists to say. Widened to keep any line naming a source position. |
||
|
|
b497ee1649 |
feat(phase-30 S33c): PROPAGATE head COMPLETE — func_801466F0 x137 took three fixes + a type-lift
Fleet 96.17 -> 96.21% fn-count / 93.8% instr / 88.0% distinct; dedup 1909 -> 1910
groups, 0 failed, C1 241216/241216. R22 clean-fleet: 140 passed, 0 failed of 140.
The head is now 5/5 classes, 18,545 templatable ins, all banked this session from
a standing start of 0.
func_801466F0 had sat since S6b behind THREE separate blockers, each of which
looked sufficient on its own to explain the failure:
1. Its definition is under a §37/§73 ASM-LABEL ALIAS (`aF801466F0` in C, bound to
the real symbol by `__asm__`), and dedup_propagate.find_site anchored its head
regex on the literal `func_<ADDR>` — structurally blind to the form, returning
None, which every caller reads as "not matched". Now reuses
family_remap._alias_decl_for rather than growing a second matcher (R33).
2. That matcher was itself blind to the WRAPPED (multi-line) declaration — the
§134 shape, third tool. Fixed by matching over the joined text and mapping the
offset back to the decl's FIRST line (extract_unit carries from there).
Regression control: the single-line form still resolves. Fleet census after:
2,768 of 2,768 alias sites resolve, 0 missed.
3. Its record type was a draft-local typedef, so the body failed
compiles_standalone. Lifted Rec801466F0 to src/shared/engine_types.h INSIDE
the include guard (the SESSION-19 double-include note) and switched both the
macro and the exemplar to it — byte-neutral, gate-proven.
Probed on ONE member before the fleet run: byte-identical 9052dc0e first try.
MEASURED, NOT INHERITED (R37): the S6b note frames the alias-regex gap as a CLASS
of missed work. It is ONE function — 91 distinct alias decls fleet-wide, the
per-line matcher resolved 90. Recording it so a future session does not scope a
phase against a class that does not exist.
cookbook §138 extended with the alias-form tool boundary and the three-blocker
story; index regenerated.
|
||
|
|
4f6b0e8de1 |
feat(phase-30 S33b): PROPAGATE head 82% banked — 15,257 of 18,545 ins, four levers
Fleet 96.10 -> 96.17% fn-count / 93.7 -> 93.8% instr / 88.0% distinct.
dedup 1908 -> 1909 groups, 0 failed, C1 241078/241078.
R22 clean-fleet: 140 passed, 0 failed of 140.
func_80147364 4,110 x137 definition-side asm-label alias
func_8016BA68 3,886 x134 dedup_extend + the MIRROR decl relax
func_8012F274 3,973 x136 hand-authored macro, source overlay excluded
func_8012A598 3,288 x138 cdecl._mask backscan fix + shared-type switch
func_801466F0 3,288 OPEN the wrapped-alias regex — measured as ONE function
THREE DISTINCT CARRY VARIANTS were hiding in one "CARRY-FIXABLE" bucket, and
only one is a tool bug (-> cookbook §138):
- a MULTI-LINE comment halts the preamble backscan -> fix the tool (cdecl._mask)
- a draft-local `struct Tag {…}` -> switch the exemplar to the SHARED type
- a file-scope `static inline` helper -> hand-author, EXCLUDE the source overlay
The third is the sneakiest: gcc-2.7.2 accepts implicit function declarations, so
the extracted body PASSED compiles_standalone with the helper undeclared and the
miss surfaced only as a whole-binary byte DIFF 137 gates later. Instantiating
that macro in the SOURCE overlay is a duplicate definition (its file-scope helper
is still there), so the shape is `--source-overlay X --binaries <all-but-X>`;
`--binaries` alone removes the source from the scan pool and errors.
TOOL BOUNDARY: once a group's members are DEFINE_func_*() sites, dedup_propagate
cannot extend it (find_site never returns a `def`). dedup_extend is the tool for
an already-macro-ized group — and `dedup_extend --check-only` across ordinary
overlays is a cheap fleet-wide wiring census (measured: exactly 1 group per
overlay, so no hidden backlog).
MEASURED, NOT INHERITED (R37): the S6b note frames _alias_decl_for's single-line
regex as a CLASS of missed work. It is not — 91 asm-label alias decls exist
fleet-wide, the regex matches 90, and the single miss is func_801466F0. Worth
3,288 ins, but a one-function fix. Correcting the expectation so a future session
does not scope against it.
|
||
|
|
356373efab |
fix(phase-30 S33b): the PAIR rule — my 42-decl relax did NOT unblock the lane; the mirror form did
HONEST CORRECTION to commit:1382. That commit's message implies the 42 `(void)` relaxes unblocked the PROPAGATE remainder. They did NOT: the re-run banked 0/1 in all 134 overlays with the same error, because DEFINE_func_8016BA68 declares func_80146C3C `(u8*)` — the MIRROR of the EXTEND-lane pair — and my relax only touched the `(void)` direction. Root cause is the R37 shape a third time: I bucketed by SYMBOL and stopped. The lever is set by the (macro-shape, TU-shape) PAIR, and the same symbol conflicts in BOTH directions across this fleet. One awk over the macro I was ACTUALLY fixing — which I ran for the EXTEND macros and not for this one — shows the pair before a 134-build run. §138 amended with the PAIR rule; correction logged in CURRENT_PHASE.md rather than rewritten out of history. The 42-decl relax still stands: byte-neutral, R22 140/140, removes a real conflict class. It just did not do what I predicted. THIS commit relaxes the 2 remaining `(u8*)` decls (uses are cast; `()` is compatible with the (void)/()/(u8*) forms the fleet carries and no decl of this symbol has a default-promotion param). R22 clean-fleet: 140 passed, 0 failed. ALSO: tools/overlay_src_split.py `_split_macro_body` — the §134 sweep's one real target, fixed. It carried the identical single-line-only comment test, and it decides where a macro body's file-scope externs END, so a multi-line comment truncated the extern set. SIZED FIRST: 38 live lines in engine_core.h macro bodies hit it today. Now decides on cdecl._mask (one oracle, R33) with the length-preservation invariant asserted (R32). Proven both directions by a control: pre-fix it stopped at `/* multi` carrying 1 of 2 externs and treated the comment as the definition head; post-fix both externs carry and the def head is correct. Not in the gate path (only o0_subsplit + jr_isolate_all import it). |
||
|
|
3daa647bb3 |
docs(phase-30 S11): cookbook §138 + SESSION-33 checkpoint
§138 — "the propagation lanes: a gate refusal is a DECLARATION, and which lever you owe depends on blast radius". The durable content of this session: - the 4-lever triage table ranked by blast radius, and the rule to grep the fleet's decl shapes BEFORE relaxing to `()` (illegal only against a default-promotion param — 4,020 decls measured, 8 of 36 banked for one token) - `volatile` in the host TU is a SCHEDULING BARRIER that masquerades as a codegen wall; the tell is a positional shift with a `nop` at a delay slot, and the h_exact contract is confirmed/refuted in ONE command with no build - the DEFINITION-side asm-label alias as the only zero-radius escape when the fleet canon disagrees on a promoting param (1,725 in-tree precedents) - rank a lane by measured concentration, not class count (5 of 45 classes carried 89%), and `--recover` is not a retry (16/16 on drafts, 4/138 on a propagation) - §134 multi-line blindness recurring in a second tool; decide on `cdecl._mask` - the waiter rule CORRECTED: `pgrep -x make` is wrong for a campaign of sequential makes, `pgrep -f` self-matches, `nohup … &` signals the wrapper Checkpoint refreshed and placed below the task checklist (fresh-session safe): fleet 96.10 / 93.7 / 88.0, dedup 1908/0, R22 140/140 four times this session, nothing running, lock free. Three named next items, none yet diagnosed against a build — the PROPAGATE head remainder (11,147 ins), the 41-class tail (2,316), and EXTEND's last 5 (the whale needs the §38 -O0 route; dedup_extend should refuse-and-name that class per R32). |
||
|
|
a4bc49a23d |
feat(phase-30 S8): the x10-99 band closes 23/23; §137 makes REGALLOC-PERM arithmetic, not a permuter job
- S8-3 (23 fresh x10-99 families, 121-328 ins — the hardest band this session): draft 16/23 ->
capture (1 PLUMBING / 6 DIFF) -> reconcile 1/1 -> redraft 6/6 => **23/23 (100%)**.
Propagated 206 + 81 = 287 member-matches across 80+54 overlays. R22 clean-fleet 140/140.
FLEET 95.97% fn / 93.4% instr / 87.5% distinct (77,404 uniq); dedup 1905/0; 0 NON_MATCHING.
- §136b CLOSES AT 15/15 — no function ledgered "genuine byte-DIFF" survived a redraft, all session.
- §137 (NEW, the session's most reusable result): REGALLOC-PERM — a clean 2-register swap — is a
TWO-COMPILE ARITHMETIC PROBLEM. global.c:allocno_compare ranks by floor_log2(R)*R/L*1e4*size;
read R and L out of `cc1 -dl -dg` for BOTH contenders AND their ranked neighbours to get the
admissible priority WINDOW, then place a zero-byte `__asm__ __volatile__("" ::"r"(v))` so L lands
inside it. func_801833F0: contenders ONE unit apart (1297 vs 1296), window (1228,1296), five
placements probed, only L=219 -> pri 1232 worked. R and L are FORCED BY THE EMITTED CODE (L is
recomputed post-sched1), which is exactly why source-reordering is a dead end for this class.
Converts a class the permuter banked 0 from all session into a deterministic calculation.
Companion: floor_log2 makes ref-count a STEP function (5/6/7 refs are worthless, you must reach 8)
— func_8017EFA8 closed 30 register-name mismatches by taking a pseudo 4 refs -> 8 with a dead read.
- §136j — the failure MIX FLIPS WITH SIZE: <=120 ins fails ~70% on declarations; 121-328 ins fails
86% on genuine codegen. Budget reconcile for the small band, redraft for the big one — and do NOT
read 70% on a big-function wave as a broken pipeline; that is the expected shape.
- §137a — a gate verdict has a TIMESTAMP. Two "DIFF" ledger entries were STALE (draft rewritten 28
min after the gate ran, never re-gated); both were already byte-perfect. Compare verdict time to
draft mtime before redrafting. Plus two offline oracles an agent built: a FULL RELOCATION RESOLVE
(catches wrong jal/%hi/%lo targets that match_one's mask hides) and a COLLATERAL CHECK (whole-TU
objdump with/without splice). Together they discriminate all three causes of "match_one says MATCH
but the overlay SHA differs" without running make.
- §136f addendum — the collider is often an already-banked SIBLING BELOW the splice; locate it by
arithmetic (draft grows the file N lines, so TU line L reports at L+N).
- cookbook-index 380 -> 382 sections.
|
||
|
|
18fc50d0f8 |
docs(phase-30): §136i — insert SONNET between Haiku and Opus in the drafter ladder (Drew 2026-08-03)
- MEASURED BASIS (P30 S7, 144-target campaign): the two-tier rule from the 2026-06-29 A/B left the ~50-120-ins band unassigned, and every wave since defaulted it to Haiku-with-Opus-escalation. Haiku-direct banked 3/8 on that band while Opus-escalation-after-a-Haiku-miss banked 10/11 — i.e. Haiku was acting as EXPENSIVE TRIAGE (a wasted draft + a full Opus redraft), not a cheap drafter. The original A/B only proved parity <=52 ins; everything above that was extrapolation. - LADDER: haiku <=~50 ins · SONNET ~50-120 · opus >=~120 or escalation · fable5 for a genuinely NEW wall class only. Never haiku->opus directly; never default a whole wave to opus because the band "looks hard" (the same extrapolation in the other direction). - WIRED, not just documented: s7_manifest.py routes by the new thresholds; s7_wave4b.js escalates haiku->sonnet->opus instead of haiku->opus, and its meta/prose say so. - Boundaries (~50/~120) are current best estimates — re-measure per-tier from the journal + the gate, never from the workflow's by_tier (it counts claims, not banks — §136). - Byte-gate remains the sole arbiter, so a weaker drafter is a throughput risk, never a correctness risk (G3/P9). cookbook-index 378 -> 379. |
||
|
|
e8a57b13fa | docs(phase-30 S8): CORRECTION §136h — the zero-crack pool is residue, not a lever (1 bank / 1,781); my R37 violation | ||
|
|
1b8f26113c |
feat(phase-30 S7): close the B-shape queue — 144/144 drafts banked; §136b closes 9/9
- FINAL LANES: reconcile ×5 (5/5) + redraft ×1 (1/1) -> gate BANKED 6/6 -> propagated 50 members across 28 overlays. **ALL 144 DRAFTED TARGETS BANKED (100%); zero stubs remain in the queue.** R22 clean-fleet 140/140 (seventh time this session). FLEET 95.88% fn / 92.9% instr / 86.5% distinct (77,106 unique fns); dedup 1905/0; 0 NON_MATCHING. - LANE RECORDS: reconcile 15/15 lifetime · redraft 9/9 · §136b closes at 9 FOR 9 (every function ever ledgered "genuine byte-DIFF" banked on redraft). - THE CAPTURE CLASSIFIER, third and final defect (§136a): it decided PLUMBING by matching a regex against cc1's PROSE, and cc1's vocabulary is open-ended — `too many arguments to function` matched nothing, so a trivially reconcilable function sat UNKNOWN through two gate rounds. Now DERIVES the class from the closed invariant (did the compile produce an object: `make ... Error N` + `Deleting file`). Re-running it moved 5 PLUMBING / 1 UNKNOWN -> 5 PLUMBING / 1 DIFF, and BOTH reclassified functions then banked. Three defects in one small tool in one session — an unreachable exit-status branch, a missed phrasing, and the prose-matching design behind both — each SILENTLY MIS-ROUTING REAL WORK. R33 in one line: if an invariant answers it, never re-parse. - §136f — two declaration sub-cases: (1) a symbol you call may be DEFINED, not just declared, BELOW your splice point (func_8017D540 is defined 275 lines below as int(int); the draft guessed void(s32) from a bare jal); (2) an ARITY clash on the symbol you are DEFINING cannot be fixed by a cast — use the §37/§124 asm-label alias (func_801848DC; in-TU precedent at :8872). - §136g — TWO INDEX ROUTINGS BYTE-REFUTED (func_801863B4). The index sends BRANCH-POLARITY to §3-T4 (invert) and §34 (zero-byte fence); the agent tested BOTH at zero, read the gcc-2.7.2 source, and found jump.c:1806 `if (foo) bar; else break` range-swap — which runs long BEFORE reorg, so a fence CANNOT block it. Real lever: put a label between the if-join and the return label (wrap the loop in the guard). Also: same-address lh+lhu is MIPS LOAD_EXTEND_OP==ZERO_EXTEND (mips.h:1163), and combine collapses the pair unless the HImode pseudo has two reaching defs. REFUTED ROUTINGS ARE RECORDED NEXT TO THE CORRECT ONE — otherwise the next agent re-runs them. - cookbook-index 375 -> 377 sections (§136 .. §136g earned this session). |