Commit Graph

773 Commits

Author SHA1 Message Date
Drew T 85b526cddd feat(phase-30 S45 II.1a): all 38 MAIN modules onboarded byte-identical at the §S44 static addresses
- slot A 29/29 (md_MAIN_013..041 @ 0x800CAE08), slot B 6/6 (md_MAIN_042..047 @ 0x800CCB1C),
  boot trio 3/3 (md_MAIN_001 [=MAIN/0 twin], md_MAIN_008, md_MAIN_011 @ 0x800CEDF8) — every one
  BYTE-IDENTICAL on its FIRST build (byte-corroborating the §S44 loader table for slots A/B/boot)
- TLO roster derived from the §154 id-word law (.run/s45/derive_tlo.py): 0x4 default;
  011=0x7C, 025=0xC, 034=0x80, 039=0xC (first-prologue scan)
- new_binary.sh: module hdr carve is now a dot-typed .rodata PAIRED with the c segment —
  a header can hold a function's jump table (md_MAIN_034), and standalone rodata emits
  .L locals that don't cross objects; bin links in the data block (both refuted by bytes)
- A4 law: symbols.resident.txt dropped from the boot trio's stacks (windows inside the
  resident region; DsMix @0x800D1BD8 had minted a phantom fn boundary in md_MAIN_011) —
  re-extracted clean, all three byte-identical, phantom gone
2026-08-06 12:36:49 -06:00
Drew T 41ff2ba127 docs(phase-30 S44 I.3): checkpoint — Part I complete; fresh session resumes at Part II
- R22 clean-fleet 143/143; fleet 96.13% fn / 94.4% instr (honest grown denominator; pre-expansion
  line 95.00% on 140 kept for continuity) / 88.3% distinct. audit-binaries OK over 143.
- make audit-disc: UNCLAIMED 78 -> 75 payloads (3,564,021 -> 2,038,104 B), residue 0 — the three
  claims flipped automatically via check.sha, exactly as the ledger was designed.
- S44 session total: 5,126 member-functions banked into the 3 new overlays; the ~2,051 remaining
  stubs are the new frontier, visible to every tool via citizenship (no separate ledger rows —
  recorded as a deviation from plan I.2e, redundant by construction).
- Part II handoff live in the plan file + the S44 checkpoint block.
2026-08-06 12:10:25 -06:00
Drew T c697746462 docs(phase-30 S44 I.0): the static loader routing table + the full tool audit — knowledge captured
Plan-approved campaign (Fable5Max, ~/.claude/plans/optimized-squishing-engelbart.md). I.0 = capture
while hot (R30/R31), before any code:

- memory-map.md §"Phase 30 S44": the COMPLETE loader routing table, static-derived (G5) — the EXE's
  loadDestPtrTable (0x80072C70: resident/overlay/slotA/slotB/type-7), the boot k-set {1,3,8,10,11},
  the RESIDENT's index tables D_800D3764 (29x8, MAIN/13-41 -> 0x800CAE08) and D_800D384C (6x8,
  MAIN/42-47 -> 0x800CCB1C), resident.c:641 (MAIN/12 -> 0x80128158), the SC07 pair's header-derived
  0x801A00D8, gbase arithmetic (LIST.CD carries LBA+len ONLY), the slot-adjacency proof, the
  module-id-word law (word0, dense 0x13..0x73, resident=0x36; MAIN/9-vs-39 duplicate flagged), and
  "PAC type 1 = uncompressed overlay, type 4 = LZSS". SUPERSEDES P3-T5's "entries [1]+ are
  runtime-indexed (no static xref)".
- disc-completeness.md: the "only knowable by runtime RE" doctrine REFUTED in place (H5, original
  kept) — 46 of 78 addresses are static; the runtime-only remainder is 28 script modules + 4
  stragglers, parked for L3 with evidence. Byte-sum correction (rows 3,406,325 B vs bucket
  3,564,021 incl. PAC headers), MAIN/7 raw-path exception, MAIN/0≡1.
- tooling-audit.md §S44: EVERY tool classified with file:line — 8 must-change (family_remap VRAM
  const, Makefile+modules.mk, sig-target generalization, audit_binaries de-ov_, family_hseq/
  progress:647/audit_frontier globs, corpus.sig_is_independent), 7 one-line registrations, 5
  retirements (disc_code_sweep superseded by disc_audit; reconcile_decls; 3 rollout one-shots;
  ImportOverlay/VerifyOverlay.java), rest auto-OK/N-A. new_overlay.sh -> new_binary.sh design.
- decision-log (R31): the pivot entry — the emulator dependency dissolves; the "modules" mostly
  dissolve into overlays (~75-77% h_exact-known; 802 novel fns); why the doctrine was missable for
  30 phases (a confident negative doctrine is a claim like any other — date it, cite it, re-measure).
- cookbook §154 + index regen (454 sections): module-id word / dual base-voting (h_exact ~500:1 +
  jal-alignment, must AGREE; thin votes => park, P9) / diff a mystery payload's head against classes
  you already own before inventing a new one.
2026-08-06 10:52:07 -06:00
Drew T 964afdba4e feat(phase-30 S43): L2 second oracle — it found TWO L1 defects; unclaimed code 1.70 -> 3.56 MB
L2 (R34) is sig_image boundary carving: walk the payload cutting each function at the first `jr $ra`
at/after every forward branch target. Structurally different question from L1's statistical test
(valid>=0.90 AND jr>=0.01), so the two can ARGUE — and they did, 80 times, all one shape.

- L1 DEFECT 1 — A CLAIM OUTRANKED BY A HEURISTIC. A payload whose SHA1 equals a committed
  config/check.<bin>.sha IS that onboarded binary (the build gates on that hash daily), but I let the
  statistical verdict file it as classified-data. Onboarded bucket understated by 14.5 MB.
- L1 DEFECT 2 — WHOLE-PAYLOAD AVERAGING DILUTES CODE. A real location overlay is code followed by a
  large data tail, so its whole-payload valid-ratio is ~0.87, under the 0.90 gate — while L2 carves
  real functions from its head. The "classify the whole payload" fix for the old 4,096-word window had
  traded a head-only bias for an averaging bias. 80 disagreements, every one this shape.
- RESOLUTION (bucket_of): a claim wins outright; otherwise take the UNION of both oracles. Union is
  the conservative direction for this audit's question — over-reporting code yields a review queue,
  under-reporting HIDES code, the exact failure that produced three "more code all along" surprises.
- RESULT: partition still holds, residue 0 over 416,021,760 B / 1,291 payloads.
    onboarded-code 47,066,812 · UNCLAIMED-CODE 3,564,021 (34 payloads) · classified-data 134,265,572
    · audio-video 184,338,000 · filesystem-metadata 46,787,355
  Largest unclaimed: MAIN.CD sub-file 12 entry 1 type 1, 383,783 B; the rest small type-1, mostly MAIN.CD.
- The ledger now carries an explicit L2 REVIEW QUEUE section; L1=data/L2=code is flagged as the
  DANGEROUS direction (missed code).
2026-08-06 09:48:16 -06:00
Drew T 41a3de342d fix(phase-30 S43): family_remap now carries TYPEDEFS (transitive, brace-aware) — the §146/§152 gap closed
- ROOT CAUSE PINNED, and my first hypothesis was WRONG (R14, corrected in the log): I wrote that a
  gate transform ate a `/*` opener and turned comment prose into code. REFUTED — cast_call_sites,
  sig_unify and reconcile_tu each run with the gate's real --src-file all preserve it. The real
  cause is family_remap's preamble backscan, whose accept-set (blank/extern/comment/typedef) HALTS
  AT THE FIRST `#define` and never reaches typedefs above the macro block. `_carry_macros` then
  re-attaches the macros, which HIDES the truncation — the unit looks complete and is not.
  "parse error before 'unsigned'" was that failure surfacing at the next token (the following
  `extern unsigned char` line): a misleading label, not a second defect.
- FIX: _carry_typedefs() — additive, TRANSITIVE (a carried typedef may name another; measured:
  carrying Vec8_80182FD4 alone then failed on SVECTOR_8016E7C8), and BRACE-AWARE (a `;`-terminated
  scan stops INSIDE the struct at its first member line, emitting a truncated unclosed typedef).
  Emits dependency-first for C89. Only types the unit actually names and does not already carry.
- VERIFIED: the 0x80182FD4 unit now carries its Prim_8016E7C8 block complete; the 0xECC family's
  remaps now carry the four typedefs I had prepended BY HAND before gating them — i.e. the fix
  automates the exact workaround that banked those three siblings. Residual isolated-compile failure
  on SVECTOR_8016E7C8 is a match_one artifact: that type lives in src/shared/engine_types.h, which
  the real TU includes — the typedef gap is fatal ONLY when the target TU lacks the type, which is
  why this class failed loudly for some families and silently succeeded for others.
2026-08-05 23:50:40 -06:00
Drew T 5c84ad5ada feat(phase-30 S43): the 263x5 cluster BANKED 5/5 (+1,315 ins) — the SWEEP was corrupting correct drafts
- R22 CLEAN-FLEET: 140 passed, 0 failed of 140. Fleet 12,502,519/13,160,961 = 94.997% instr
  (+18,146 instructions this session, 23 functions). 393 instructions from the 95.000% bar.
- REDO of the S43-9 retraction, done correctly through harvest_verify (splice/build/keep-iff-
  byte-identical/revert) instead of hand-building. 5/5 banked, each re-verified three ways:
  image SHA == locked SHA, stub gone, real definition present.
  ov_SC03_101/func_801814F8 · ov_SC03_104/func_80184934 · ov_SC04_003/func_8017E4F4 ·
  ov_SC04_005/func_80181054 · ov_SC04_007/func_8017FF08
- THE DEFECT THIS PROVES: family_sweep --hseq reported this family 0/5 with
  "PLUMBING: parse error before 'unsigned'" — but the remapped drafts are byte-CORRECT. The only
  `unsigned` in the draft is INSIDE A COMMENT, so a gate-pipeline transform is eating a `/*` opener
  and turning comment text into code. Per-transform runs on the draft alone all preserve it, so it
  needs the gate's real invocation (--src-file) to reproduce. NOT YET PINNED — and it is silently
  costing banks in every sweep it touches. Next: run the three transforms with --src-file and diff.
- Workaround that banked them: carry the exemplar's typedefs by hand (the family_remap _carry_macros
  gap, §146/§152) and gate directly, bypassing the sweep's recovery ladder.
- Also killed a self-inflicted infinite poll: an `until ! pgrep -f "permuter_ils.py <fn>"` loop whose
  pattern matched its OWN bash command line, so the condition could never go false (spun 2h30m).
  Same family as the day's other defects: a check that cannot return the answer that ends it.
2026-08-05 21:15:06 -06:00
Drew T 37c60a5ff3 feat(phase-30 S43): R22 CONFIRMS ALL 18 BANKS 140/140 — fleet 94.99% instr; §147 refuted by the bytes
- ✅ R22 CLEAN-FLEET: make clean && extract-all && check-all -> 140 passed, 0 failed of 140.
  Discharges the [R22 PENDING] caveats on commit:1486 (the 0xECC family x12) and commit:1487
  (func_8018D98C). All 18 of today's banks are confirmed, not incremental artifacts (§130).
- FLEET: 96.63% fn-count / 94.99% instr-weighted (12,501,204/13,160,961) / 89.4% distinct-code.
  Session +16,831 instructions, 18 functions. P30's 95% instr bar is 1,708 instructions away
  (18,539 at session open). NOTE the report line rounds to "95.0%" — the bar is NOT yet met.
- THE 5th WAVE AGENT: func_8017CE58 is TWO bodies at one address (246 in SC02_000/003, 734 in
  SC03_092). The 246 body is byte-identical to func_8017C294 — THE FUNCTION §147 WAS WRITTEN FROM —
  so one draft covers 4 instances, and it went 12 (with a recorded "stop searching" verdict) -> 2.
- §147 CORRECTED IN PLACE (H5: original text preserved, correction appended):
  * A "stratum 3, unreachable from C" is REFUTED — there is NO stratum 3. The frame is declared
    locals then reload spill slots in pseudo-regno order; the mystery 0x108 slot is an ordinary
    spill on a loop.c-created pseudo, reachable by writing the loop as an INDEX loop (a pointer
    walk puts it at the bottom). Prior drafts faked it with volatile pEnd + dead[7]. (121 -> 54)
  * B the unreferenced slots are combine-orphaned sign-extension intermediates (combine.c:10839),
    not "?: on memory" frame cost.
  * E the qty_compare tie IS breakable — §148-C's zero-emission ref slider. (30 -> 25)
  * D applied properly (drop volatile out + the $24 pin, let a1 spill) remains: 54 -> 30.
- CONSEQUENCE: func_8017C294's 15 siblings were parked "until stratum 3 is explained" — that hold
  is VOID. Both near-misses logged to the ledger with their measured closeness, not forced (P9).
- PROCESS LESSON in §147: a confident NEGATIVE verdict is a claim like any other — date it, name
  its evidence, and re-measure it before letting it park work (same shape as §146).
2026-08-05 18:54:07 -06:00
Drew T f5498c3c66 feat(phase-30 S43): the 0xECC family — ONE crack banks 12 overlays / 11,364 ins [R22 PENDING]
⚠️ R22 CLEAN-FLEET OWED (two agents still reading asm/, so `make clean` is unsafe). Each of the 12
was gated whole-binary AND independently re-checked against its own config/check.<bin>.sha (12/12),
stubs confirmed replaced — but incremental (§130). Treat as UNCONFIRMED until the clean run.

- THREE isolated cheap-Opus agents, briefed with §150/§151 + the mandatory all-drafts scan,
  CONVERGED INDEPENDENTLY: func_8017C6F4's 947-ins body exists in 12 OVERLAYS under 5 DIFFERENT
  NAMES at 6 DIFFERENT ADDRESSES, each differing by exactly TWO per-overlay symbols (screen-rect
  helper + 64x64 cell table). Gated 12/12, 0 failed. 11,364 ins from this morning's single crack.
- WHY IT HID ~30 PHASES (cookbook §152): name-keyed grouping scattered it across 5 names,
  address-keyed across 6 addresses (and the address collides with an unrelated 15-ins body in 3
  other overlays), and h_seq-keyed scattered it too — which is why the Phase-26 sweeps missed it.
  THE KEY IS BYTE SIZE: `grep -rl 'nonmatching .*, 0xECC' asm/*/nonmatchings/*/` returns exactly
  the 12, reads the asm (cannot go stale like family_hseq.json), no false positives. Refines the
  Phase-26 "h_seq is spent" finding: h_seq is worth exactly ONE size-keyed sweep behind each FRESH
  core crack — here it paid 11:1.
- TWO CAUTIONS THAT TRAVEL WITH IT: (1) a MASKED tool cannot validate a remap — match_one and
  rtu_match both mask jal/%hi/%lo, exactly the fields a remap edits, so a wrong symbol map still
  reports MATCH; gate remaps by the whole-binary SHA only. (2) a stale residual is NOT evidence two
  functions differ — I briefed "func_8017C59C scores 340, different body"; refuted in one command
  (that 340 came from a pre-§150-fix draft, which scores nonzero against its own target too).
- OPEN TOOL DEFECT (R32): family_remap's unit backscan halts at the first #define, so it carried
  16/16 gte macros and 0/10 typedefs, silently — the §146 gap from the other side.
- MY ERROR, RETRACTED IN THE LOG (S43-9): I reported the 263x5 cluster as "5 byte-identical, 1,315
  ins". FALSE — the drafts had been reverted, so I measured the INCLUDE_ASM STUB BASELINE, which is
  byte-identical by construction. R34's trap, self-inflicted by hand-building instead of using
  harvest_verify. Nothing was banked there; the cluster is UNRESOLVED. ("41 behemoth drafts" was
  likewise a file count — 79 files, 20 distinct functions.)
2026-08-05 17:40:27 -06:00
Drew T 01d7d3276c feat(phase-30 S43): FABLE5 CRACKS func_8017EF68 (the 2-of-969 wedge); R22 CONFIRMS ALL FIVE BANKS 140/140
- func_8017EF68 MATCH 969/969, re-verified by me, gated: ov_SC06_000 byte-identical at da4a26ff.
- MECHANISM (from cc1's own -dR trace, not inferred): the r3000 machine description gives the
  memory unit load-ready-cost 2 / store 1, so blockage(load,store)=2 — a LOAD CAN NEVER BE PICKED
  IN THE TICK IMMEDIATELY AFTER A STORE PICK. sched2 therefore always wedges one ready ALU insn
  between the lw and the sh, and the target's zero-wedge order is UNREACHABLE BY ANY STATEMENT
  ORDER. That is why ~20 documented hand variants AND the repaired permuter both floored at 2.
  The draft's own §49 sched1-LUID story was incomplete — real but secondary.
- THE LEVER (cookbook §151, "the ghost wedge"): a zero-emission tied in/out asm
  `__asm__("" : "=r"(v) : "0"(v), "r"(rival));` — 0 bytes, but a schedulable insn that absorbs the
  blocked tick, and it sets reg_n_sets(v)=2 which also kills sched1's birthing boost (one
  instrument, both passes). Two measured fallouts: rival-read in the same asm (22->12), then a
  second re-tie on a HIGH-REF host to restore allocno live-length parity (each in-loop insn is +1
  live length for every loop-spanning allocno; a trio of invariant addresses sat exactly on
  allocno_compare's integer-floor boundary). Host choice empirical: pkt=MATCH, ot=705, double=10.
- ✅ R22 CLEAN-FLEET: make clean && extract-all && check-all -> 140 passed, 0 failed of 140.
  This DISCHARGES the [R22 PENDING] caveat on commit:1484 — all five banks are confirmed, not
  incremental-build artifacts (§130).
- FLEET: 96.63% fn-count / 94.9% instr-weighted (12,489,130/13,160,961) / 89.2% distinct-code;
  0 NON_MATCHING (G4); dedup 1919 groups. Session +4,757 ins from 2 cracks x 5 binaries.
  Distance to P30's 95% instr bar: 13,782 ins (was 18,539 at session start).
2026-08-05 17:21:47 -06:00
Drew T 25402b2eb4 feat(phase-30 S43): FABLE5 CRACKS func_8017C6F4 pin-free — banked ×4 (~3,788 ins) [R22 PENDING]
⚠️ R22 CLEAN-FLEET VERIFY IS OWED, NOT DONE. All four gates below were INCREMENTAL builds
(§130: an incremental build can report BYTE-IDENTICAL for a change a clean build cannot link).
Committed now only to protect the work — a second Fable5 agent is reading asm/, so `make clean`
would destroy its inputs mid-run. The clean-fleet run follows the moment that agent finishes;
treat these four banks as UNCONFIRMED until then.

- THE CRACK (Drew approved the Fable5 escalation, R27): byte-exact, PIN-FREE, 947 ins. My §147-E
  "qty_compare tie, unreachable from source" diagnosis was WRONG. The residual was VARIABLE
  IDENTITY: (1) the X-pass and Y-pass min/max intermediates are DIFFERENT variables (8, not 4
  reused); (2) mnc/mxc do not exist — the cell clamps reuse the prim-loop mn/mx (X) and mny/my (Y).
  Ablations: split-only 63, reuse-only 624, conjunction MATCH. That is also why S42's "separate
  X vs Y variables" probe was filed as a failure (it was half the fix), and why every allocator
  lever was inert — pins, §148-C sliders, declaration order and 14 permuter restarts cannot reach
  a draft with the wrong NUMBER OF PSEUDOS.
- VERIFIED INDEPENDENTLY BEFORE BELIEVING IT (R14): I re-ran match_one -> MATCH (947 ins), then
  the whole-binary gate per binary.
- BANKED ×4 (every 948-ins sibling of this body), each byte-identical:
  ov_SC03_126 c48a8bb8 · ov_SC03_003 898bf52a · ov_SC04_021 33614234 · ov_SC05_019 3f5b4f13.
  family_remap produced all three siblings cleanly.
- §146 SEEN AGAIN: all three siblings first failed with `PLUMBING: parse error before 'MTX_C6F4'`
  — _carry_macros carries #defines but NOT typedefs; prepending the 9 typedef lines fixed all
  three. That label is legible ONLY because of this session's classifier fix; before it, it read
  "CC1-FAIL: make: *** Error N" and cost a manual splice-and-rebuild each.
- cookbook §150 (decode register ownership from the MATCHING diff regions before touching the
  allocator; per-instance register asymmetry ⇒ per-instance variables; the deleted-self-move tell
  and the global.c:719-vs-:729 death-before-store exemption behind it). §147-E corrected: it named
  the wrong allocator — these are global.c allocnos, not local qty_compare quantities.
2026-08-05 17:07:41 -06:00
Drew T f5ea22b4f5 feat(phase-30 S43): serial queue — func_8017EF68 is at 2 of 969, and was scanned against the WRONG BODY
- THE ALL-DRAFTS SCAN PAID (S4's law): .run/drafts-p30beh/func_8017EF68.c is a 969-ins draft that
  scores "969 mismatched" against ov_SC03_007's 12-ins body — which is what every name+home scan
  keyed on. Against its OWN body (ov_SC06_000, 970 ins): DIFF 969/969, **2 mismatched**,
  SCHEDULE-REORDER/2, everything else — registers, frame, spill map — already byte-exact.
- THIRD instance of today's address collision: 0x8017EF68 = 12 ins (SC03_007) AND 970 (SC06_000);
  0x8017CE58 = 246 (SC02_000/003) AND 734 (SC03_092). The serial queue's own size annotations
  ("func_8017EF68 (969)", "func_8017CE58 (733x3)") are therefore unreliable — re-derive from bytes.
- THE VINDICATION: the draft's header ends "NEXT STEP: this is the permuter's exact profile", and
  drafts-p30beh is one of the 63 GTE dirs S43-1 unblocked — this function sat ONE working permuter
  run from a bank, with the note naming the permuter, for as long as the silent fallback existed.
- The residual is a 2-ins adjacent transposition (lw $v0,0($s3) <-> srl $a2,$a1,16), root-caused in
  the draft to a sched2 INSN_LUID tie (§49) with ~20 hand variants recorded DO-NOT-RE-BUY.
  Repaired-permuter ILS (schedule profile, 6x240s) reaches 2 and holds flat; a free 12x600s run is
  queued. Logged to the backlog at closeness 2 with the correct binary.
- Queue triage: func_8017C974's 22 stored drafts are all far (best 812/947); func_8017CE58 has only
  a CC1-FAILing Ghidra-C draft. Neither is a near-miss.
2026-08-05 16:39:37 -06:00
Drew T e75ed7adcc docs(phase-30 S43): checkpoint — the permuter takes 63->41 and plateaus; evidence preserved
- func_8017C6F4 FINAL for this session: hand 63 -> ILS 42 (pin-free seed, masked 44, flat over 8
  warm restarts) -> ILS 41 (pin-t5 seed, masked 43, flat over 5). Best draft
  .run/s43/func_8017C6F4.ils43-pin.c (closeness 41), logged + allowlisted. Both basins are now
  MEASURED FLAT — do not re-run the ILS on these seeds; next levers are §148-C by hand, then Fable5.
- .gitignore: allowlist .run/s43/*.py + *.json so the refutation evidence (probe_leftovers.py,
  leftover_probe.json) is preserved, not one `git clean` from gone (R20, the S42 lesson).
- S43 checkpoint block refreshed at the top of the file: the four instrument defects as one table,
  the one number that moved, the resume list (with "26 unpropagated members" struck as refuted),
  the harvest_verify import hazard, and my four process errors.
2026-08-05 16:18:12 -06:00
Drew T b20b397a5d docs(phase-30 S43): the "26 unpropagated members = cheapest fuel" is REFUTED — 0 of 31 templatable
- RE-DERIVED from the tree (R35): the S40 propagation banked 59 families; 22 still have open
  members = 31 instances, not the carried 26.
- SCANNED all 31 (not sampled, S4's lesson): mechanical family_remap from EVERY binary where the
  same fn is already matched (up to 4 sources each) fails 31/31 with gross reloc-count mismatches
  (2!=15, 12!=2, 11!=20, 2!=0). Script + JSON: .run/s43/probe_leftovers.{py,json}.
- WHAT THEY ARE: structurally DISTINCT bodies sharing an address and a name — the func_8017C6F4
  15-vs-948 collision one level down. family_hseq independently agrees (R34): these cluster into
  families with matched=0, several n_members=1. No matched sibling => nothing to template from =>
  the failures were NEVER plumbing. They are per-member drafting work, not deterministic fuel.
- SCOPE STATED (P9): what is refuted is mechanical remap from a matched sibling (0/31). An
  h_seq-staged draft + recovery ladder is formally untested — but that path produced the original
  CC1-FAILs, its labels were content-free until this session, and --hseq --only now stages 0
  families for these addrs. Cost the next wave as agent work.
- cookbook §149: the four instrument defects of this session as ONE pattern (silent fallback =
  "found nothing"; same addr != same body, ledger side; make's wrapper is not a diagnosis; carried
  cheap fuel nobody probed) + the rules each one yields.
2026-08-05 16:16:37 -06:00
Drew T 50c6f61056 fix(phase-30 S43): the CC1-FAIL label named MAKE, not the compiler (~3,000 content-free labels)
- ROOT CAUSE: classify_fail took errs[-1], and make prints its own summary
  `make: *** [Makefile:N: build/src/<ov>/<tu>.o] Error N` LAST, always — so the wrapper won
  every time and the label carried only the TU name the record already stores. Each CC1-FAIL
  therefore cost a manual splice-and-rebuild to learn what cc1 actually said (3x in S42 alone).
- MEASURED (R37, over the committed .classified.txt corpus): ~3,000 of ~4,000 CC1-FAIL labels
  are that wrapper; a further 1,019 are bare CC1-FAIL with no message at all.
- FIX: _MAKE_WRAP guard excludes make's summary lines; the FIRST real diagnostic wins (cc1
  cascades — error #1 is the root cause); nothing-but-wrapper is now labelled
  CC1-FAIL(no-diagnostic) rather than disguised (R32). Same family as the §58 warning
  red-herring guard directly above it: a label identical for every input carries no information.
- VERIFIED on the exact branch (exec'd the real source, see hazard below):
  "CC1-FAIL: make: *** [...] Error 33" -> "CC1-FAIL: src/…/tu.c:2240: error: too few arguments
  to function `gte_ldv3'". DIFF/SKIP/PLUMBING paths unchanged.
- HAZARD DOCUMENTED (mine): harvest_verify.py has NO `if __name__ == '__main__'` guard — the
  whole gate is module-level, so `import harvest_verify` PARSES argv, RUNS A BUILD and overwrites
  .run/harvest_*.txt. Tripped it unit-testing classify_fail (resident stayed 8e17e02f, 0 banked,
  tree clean, no damage). Nothing imports it today, so it is flagged in the file header rather
  than fixed by a risky 500-line refactor of our most load-bearing gate.
2026-08-05 16:09:52 -06:00
Drew T fa122cf62f fix(phase-30 S43): permuter takes func_8017C6F4 63->42; the "rumour row" was an ADDRESS COLLISION
- THE FLOOR MOVED: permuter_ils on the S42 draft -> masked 65->44 (cycle 1, flat over 5 warm
  restarts); re-measured in match_one terms 63 -> 42 mismatched, 947/947 ins. First movement
  after ~40 hand probes, and it came from repairing an instrument (S43-1), not from new C.
  Draft preserved + allowlisted: .run/s43/func_8017C6F4.ils44.c; logged at closeness 42.
- THE S42 "rumour" CLAIM WAS WRONG (R14): the 2026-07-01 row HAS an artifact, it IS on disk,
  and it reproduces exactly (14 mismatched of 15 target ins, SIZE-MISMATCH/redraft). It is a
  near-worthless draft on a DIFFERENT BODY: 0x8017C6F4 is 15 ins in ov_SC03_010/011/013 and
  948 ins in ov_SC03_126/003 + ov_SC04_021 + ov_SC05_019 (§148-E, ledger side).
- THREE ledger defects fixed: (1) load_best keyed on ADDRESS ALONE -> the two bodies merged and
  the lower ABSOLUTE closeness won, so 14-of-15-wrong (7% correct) masked 63-of-947 (93%);
  now sub-keyed by known nins, legacy rows unchanged. (2) binary=null defaulted to ov_SC01_077,
  where the fn does not exist AT ALL, and "not an open stub" was read as "banked" -> today's
  result was invisible to render/grinder/target-selection (absent != done, R32/R34); now derive
  binary from the draft path + only drop when closed everywhere it exists. (3) `log` had NO
  --binary flag -- the root cause of every null; added + derived in append_record.
- IMPACT DERIVED, NOT ASSERTED (R37): replaying the pre-fix selection = 836 -> 837, 1 appeared
  (func_8017C6F4 nins=947), 0 vanished. One row today; the mechanism would eat every future one.
- PROBED AND NOT BUILT: relative-closeness ranking (only 24/836 rows carry closeness+nins, and
  the two orderings agree 14/15 on those). Documented in the log instead.
2026-08-05 16:06:16 -06:00
Drew T 63d029b563 fix(phase-30 S43): the §148 "GTE macro wall" is a SILENT CPP FALLBACK — permuter lane was dead on 63 drafts
- ROOT CAUSE (reproduced): make_base_c ran cpp_expand_macros BEFORE #include lines were
  dropped, so `cpp -P -nostdinc -` died on `#include "common.h"` (rc=1, empty stdout) and the
  `return c` fallback handed back the UNEXPANDED draft. hide_asm then ate the gte_* #define
  block + the function itself -> "Function not found in base.c" -> decomp-permuter no-opped
  in 0s, indistinguishable at the call site from "searched, found nothing".
- FIX: strip #include inside cpp_expand_macros (byte-neutral) + RAISE on cpp failure (R32/R35,
  no silent fallback); NEW defines_fn() assertion in setup() guards the OUTPUT so it catches
  every swallow cause (this, the §G comment class, future macro shapes); main() catches per-fn
  so a bad draft is loud+counted but cannot abort a batch.
- VERIFIED: func_8017C6F4 base.c keeps the def, 0 gte_ macros left, 35 asm b64-carriers;
  proxy validated over 388 stored drafts = 0 false alarms, 0 cpp raises (macro-free untouched);
  permuter now loads at base score 65 and iterates (was a 0s no-op).
- BLAST RADIUS (14,899 drafts scanned): 63 carry `#define … __asm__` + `#include`, incl. the
  behemoth renderer drafts — the permuter was silently dead on the highest-byte-weight targets.
- CONSEQUENCE (R14): §147/§148's ~40-probe floors were measured with the permuter UNAVAILABLE;
  "the permuter also plateaus" was never actually tested on those functions. §148 note corrected.
2026-08-05 15:59:27 -06:00
Drew T aacc681ac1 docs(phase-30 S42): checkpoint — serial drafts preserved + allowlisted; flag the artifact-less backlog row that outranks them 2026-08-05 14:58:44 -06:00
Drew T b155c7f789 docs(phase-30 S42): checkpoint — serial #2 result NEAR(63), the x16 claim corrected, demacroize-for-permuter as next move 2026-08-05 14:48:42 -06:00
Drew T 427f4615d8 docs(phase-30 S39-S42): full fresh-session checkpoint — the agreed disc-audit plan, both giants, the cast_call_sites bug, serial queue state 2026-08-05 14:08:51 -06:00
Drew T 461979449e docs(phase-30 S6): checkpoint — both giant walls cracked ×138 (+50,094 ins); roadmap 'permanent walls' line retired 2026-08-05 12:52:07 -06:00
Drew T 350423d1df docs(phase-30 S40): checkpoint — the cast_call_sites bug, 24/24 waves with zero codegen walls, §144/§145, next-session fuel 2026-08-05 11:53:41 -06:00
Drew T 64ad8a1c7a docs(phase-30 S40): checkpoint — the cast_call_sites bug, wave 1 (5/8 banked + 24/24 propagated), pool verified 2026-08-05 11:08:26 -06:00
Drew T 4f6e82ba13 docs(phase-30 S39): checkpoint v3 — overnight deliverables, grinder caveat, morning actions 2026-08-05 00:50:48 -06:00
Drew T c8bf4a1e92 docs(phase-30 S39): checkpoint v2 — +13,767 ins, the free-h_exact finding, honest denominator, grinder running 2026-08-05 00:44:42 -06:00
Drew T 9e5ff203e7 docs(phase-30 S39): refresh checkpoint — final fleet numbers, re-gate rates, the reconciliation-gate item 2026-08-04 22:44:07 -06:00
Drew T 7b5eda0424 feat(phase-30 S39/S4): re-gate probe — A10 broadly stands; 4 banked from the reverted overlays (+146 ins)
Tested whether decision-log A10 ("stored drafts re-gate at 0/958", measured in T1) survives
S38's tool repairs. Three populations, plain re-gate, no draft edits:

  fresh wave-6 drafts (diagnosed "blocked on a class")   4/6
  stored pool, unbiased sample (every 96th of 1,155)     1/12   <- hit was in a REVERTED overlay
  the two REVERTED overlays, targeted                    3/17

A10 BROADLY STANDS. ~8% on the general stored pool is not a harvest, and a 1,155-wide sweep
(= 1,155 whole-binary builds) is not justified by it. Do NOT generalise the fresh-draft rate
(4/6) onto the stored pool -- different populations. The honest rule is narrower and cheaper:

  after a tool repair, re-gate the drafts THAT DEFECT plausibly touched, targeted by its
  blast radius -- not the whole ledger. (R35 applied to the backlog, not just to metrics.)

BANKED (+146 ins): ov_SC06_030 func_80161208 + func_80162CCC; ov_SC07_010 func_801506A4 +
func_8016F0AC. R22 clean-fleet 140 passed, 0 failed of 140 -- which also proves byte-neutral a
fleet-shared engine_core.h edit the bank required (extern s32 func_801506A4(s32,s32) -> the
no-prototype form), reaching all 138 overlays (T2 blast radius).

Fleet 12410129 -> 12410275 instr; distinct +95 / +1 uniq; fn-count +4. audit-digest OK.

Also documents the LEDGER MECHANICS in calibration.md (Drew asked): .run/backlog.jsonl is
append-only and nothing is deleted on bank -- open-ness is DERIVED from corpus.stubs at every
read (load_best drops now-banked rows per-binary, P9) and `make report` runs `backlog.py prune`.
Membership is therefore self-maintaining and currently clean: 863 rows, 0 already-banked, 14
duplicate-addr (was 6,867 rows / 98% banked before Phase-29 compaction). What pruning does NOT
re-validate is the VERDICT on surviving rows -- closeness + residual class are as old as the
tooling that wrote them (Phase 28 found a corrupt one: func_80178004 close=0 -> 91). That is
the staleness that matters, and it is exactly what this probe measured.
2026-08-04 22:42:54 -06:00
Drew T 819a4c5317 docs(phase-30 S39): session checkpoint — stale-digest finding, 4 instrument fixes, +4,727 ins, fresh-session safe 2026-08-04 22:17:31 -06:00
Drew T a2a50635b3 feat(phase-30 S39/S4): func_801878E8 family 4/4 siblings banked ×N (+2,052 ins, ~0 agent tokens)
Propagation behind the crack banked this session. jtbl_family_bank.py over the 4 open
h_seq siblings of func_801878E8 (513 ins each):

  ov_SC03_001  BANKED    ov_SC03_124  BANKED
  ov_SC04_019  BANKED    ov_SC05_017  BANKED

ROUTE NOTE (§53, worth keeping): family_sweep --hseq REFUSED this family by design --
has_mid_jr => it needs the jtbl carve, not the remap sweep, and the interlock says plainly
that "a 0% from this path would be a TOOL artifact, not a wall". Taking the refusal at face
value and using the named tool banked 4/4 first try. This is the same lesson as the rest of
the session from the other side: the instrument told the truth about its own limits.

jtbl_family_bank also enforces a CLEAN tree (it reverts from HEAD per sibling, so an
uncommitted prior bank would be destroyed) -- which is why the ×1 banks committed first (H4).

VERIFIED: make clean && make extract-all && make check-all -> 140 passed, 0 failed of 140
(each sibling carves its own jtbl => config changed => fleet blast radius). Fleet
instr-weighted 12408077 -> 12410129 = +2,052, exactly 4 x 513; distinct +1,539 / +3 unique
fns (the 4th sibling shares an h_exact class already matched); fn-count +4. audit-digest OK.
0 NON_MATCHING (G4).

Session running total: +4,727 instructions (whale 770 + 4 drafts 1,905 + family 2,052),
12405402 -> 12410129, every step R22 clean-fleet 140/140.
2026-08-04 22:16:33 -06:00
Drew T f2696653ef feat(phase-30 S39/S4): 4 wave-6 drafts bank UNCHANGED — the block was our tooling, not the code (+1,905 ins)
The 6 still-open wave-6 drafts were triaged against S38's own diagnosis table; 4 banked,
R22 clean-fleet 140/140.

  func_801919A0  ov_SC06_032  710 ins   (was: undefined ref func_8018B878 -- "alias class")
  func_80189030  ov_SC03_001  557 ins   (was: undefined ref func_80186F88 -- "alias class")
  func_801878E8  ov_SC04_018  513 ins   (was: undefined ref func_801848DC -- "alias class")
  func_8018A564  ov_SC02_027  125 ins   (was: CC1-FAIL Error 33)

THE FINDING: all four banked with NO change to the drafts. S38 recorded them blocked on a
class that needed cracking ("cracking this one class frees 6 drafts at once"); they had
ALREADY been freed by S38's own tool repairs -- the jr_isolate_all/overlay_src_split
alias-DEFINITION-deletion blindness and harvest_verify._reload_corpus. The drafts were
correct all along; the instruments were failing them. That is the FIFTH recorded "wall"
this phase to resolve to our own tooling.

  => RE-GATE STORED DRAFTS AFTER ANY TOOL REPAIR before treating a stored verdict as a
     fact about the code. A verdict is only as current as the instrument that produced it
     (R35 applied to the backlog, not just to metrics).

Each bank also performed a jtbl carve, so config/ changed => fleet blast radius => full R22
(clean + extract-all + check-all) = 140 passed, 0 failed of 140.

Metrics move exactly as the model predicts: instr 12406172 -> 12408077 = +1,905, the exact
sum of the four (710+557+513+125); distinct +1,905 / +4 unique fns; fn-count +4.
audit-digest OK. 0 NON_MATCHING (G4).

LEFT ON THE BACKLOG as genuine codegen residuals, not forced (P9):
  func_8017C974 (ov_SC01_077, 947 ins, close=47, REGALLOC-PERM, 12 permuter variants inert)
  func_80188C68 (ov_SC03_124, 551 ins, close=370, the only target with no twin anywhere)

NEXT: the func_801878E8 family (4 open siblings x 513 ~= +2,052). family_sweep --hseq
correctly REFUSED it via the §53 interlock (has_mid_jr => jtbl carve route; "a 0% from this
path would be a TOOL artifact, not a wall"), and jtbl_family_bank.py requires a clean tree
because it reverts from HEAD per sibling -- which is why this commit lands first.
2026-08-04 22:10:49 -06:00
Drew T 3c0f60861d feat(phase-30 S39): the whale is 138/138 — ov_SC07_010 carved + banked (+770 ins, R22 140/140)
Closes the first of S38's two reverted R22 failures. ov_SC07_010 was the lone overlay
still shipping func_80144B9C (770 ins) as INCLUDE_ASM while the other 137 banked it.

Its _jr_80140608 object ran 0x184b0..0x2c2f4 straight through the whale; the sibling
ov_SC07_006 carves the same span into _o0d (0x1ca44) + _jr_801457A4 (0x1d64c). Note
0x1ca44 + 0x80128158 = 0x80144B9C exactly.

  tools/o0_subsplit.py ov_SC07_010 --lo 0x80144B9C --hi 0x801457A4
    -> 1 unmatched stub, 0 ALREADY-MATCHED in range (so no §126 island; K=0 => 3 regions)
    -> split BYTE-NEUTRAL first (d7b5875d), then banked via ../shared/func_80144B9C.h

The S38 cause ("its -O0 split reused an EXISTING _o0c instead of a fresh _o0d") did NOT
recur: o0_subsplit.free_letters derives the unused suffix (_o0c is free in THIS overlay).

Two decl conflicts on the way, enumerated with `cdecl` in ONE pass (R33) rather than one
build at a time — of the whale header's 94 symbols the §8b carried layer re-declares 3,
and 2 conflict: D_801274D0 (layer `s32 (*)(s32)`) and D_801274CC (layer `void *`) vs the
header's canonical `s32`. Dropped both: nothing in the region uses them, they are carried
from an earlier region of the old object, and 0 of the 137 other whale-including files
carry either. Decls emit no code => byte-neutral (§8c), and byte-gated.

ov_SC06_030/func_8017E120 needed NO work — it is already banked (defined at
ov_SC06_030_jr_8017C8D0.c:3491). S38 reverted the surrounding batch, not that function.

VERIFIED: make clean && make extract-all && make check-all -> 140 passed, 0 failed of 140
(config changed => fleet blast radius, R22 mandatory). Fleet instr-weighted
12405402 -> 12406172 = +770, exactly the whale's size. distinct-code unchanged by design:
that h_exact class was already matched via the other 137, so the 138th adds fleet
instructions but no new DISTINCT function. audit-digest OK (the new S1e gate, on its first
real use). 0 NON_MATCHING (G4).

Metric note (R30, same class as S1e): a body banked by #include-ing a shared header is
invisible to fn-count's NUMERATOR (the definition is not in the .c) while its stub leaves
the denominator -- 341186/353718 -> 341186/353717. The weighted metrics counted it
correctly because they derive from corpus.stubs, not re-parsed C. Trust the weighted pair.

Still open from S3: the 61 SC07 -O0 members (untouched).
2026-08-04 21:58:53 -06:00
Drew T 1576570271 fix(phase-30 S1e): the distinct-code "regression" was a STALE DIGEST — alias lever ungated
The S38 checkpoint gated the phase's best lever ("do NOT scale the alias lever") on
distinct-code falling 89.3 -> 89.2. It never fell.

PROOF (each commit's metric recomputed from its OWN committed tree, 0 unresolved):
  commit:1426 TRUE     : instr 12394533  distinct 5022306  (77895 uniq)
  commit:1426 COMMITTED: instr 12402412  distinct 5029324  (78025 uniq)   <- stale
  HEAD TRUE == COMMITTED: instr 12405402  distinct 5025082  (77952 uniq)
  => true delta 843->HEAD: instr +10869, distinct +2776 ins / +57 uniq. ALL ROSE.
The 843 digest was generated from a working tree still holding work REVERTED before the
commit landed (+7,879 ins / +130 uniq overstated) and never regenerated, so the next
HONEST digest read as a fall. => THE ALIAS LEVER IS UNGATED (scale it, §61 small batches).

Both recorded leads were wrong (R14): progress.py:423's SIG regex feeds fn-count ONLY
(neither weighted metric sees a C identifier — both derive matched = sig - corpus.stubs),
and "the harvest reverted functions to INCLUDE_ASM" died on one grep (483 removed, 0 added).
The 3-grep proof: identical sigs + unchanged tools/ + zero +INCLUDE_ASM => HEAD's stub set
is a strict subset => both numerators are FORBIDDEN to fall.

THREE INSTRUMENT DEFECTS, all one class (a bare except around a fail-CLOSED oracle):
- progress.py stub_addrs wrapped corpus.stubs in `except Exception: return set()`. An empty
  stub set means "could not answer", not "no stubs", so matched = sig - stubs credited EVERY
  function. Byte-witnessed: instr 100.00% / distinct 100.00% in a tree with no asm/. Now
  propagates.
- cast_call_sites.tu_for + reconcile_tu.tu_for had the identical swallow, falling back to the
  default <ov>.c instead of the jr/-O0 split TU — silently reinstating the exact bug
  cast_call_sites' own docstring says it exists to fix. A wrong-TU reconcile fails the gate,
  and this phase's base rate is ~24k PLUMBING vs 4,917 DIFF, so it presents as a codegen wall.
  Now propagate CorpusError; ValueError fallback for curated names preserved; derived-TU path
  re-verified (a _jr_ split stub resolves correctly, both tools agree).

NEW GATE (R34 — the byte-gate is a null oracle for DOCUMENTS; check-all stays 140/140 over a
stale digest forever): tools/audit_digest.py + `make audit-digest`, wired into tools-health
after report. Recomputes the three headline metrics from the current tree and fails if the
committed digest disagrees. Compares INTEGERS, not percentages — the +7,879-instruction
staleness printed as "94.4%" on both sides. Negative-control-proven against the stale 843
digest (fails, exit 1) and green on HEAD.

Verified: make report exit 0 (dedup-check 1910 validated / 0 failed, C1 coverage
241216/241216); audit-digest OK; cookbook-index OK (398 sections); metrics unchanged by the
fix (94.40% / 89.18%). No src/ or config/ edits — no bytes touched, nothing banked.

cookbook §140 · decision-log 2026-08-04 · SETUP.md inventory (R21) · R14/R32/R34/R35.
2026-08-04 21:48:57 -06:00
Drew T d8016c49c8 docs(phase-30 S38): checkpoint v4 — POST-S1d, fresh-session safe
Refreshes a checkpoint that had gone stale (v3 predated S1d) — stale is worse than absent.

FLEET 96.46 / 94.4 / 89.2, +37,166 instructions this session, ~0 agent tokens after the opening
wave. R22 run thirteen times: 140/140 on eleven, TWO REAL FAILURES (ov_SC07_010, ov_SC06_030), both
caught by the clean-tree rebuild after passing their per-binary gate, both reverted and recorded.

Records the session's biggest find: the §37/§124 DEFINITION-SIDE ASM-LABEL ALIAS is a CLASS lever,
not a one-off. It cracked the 208-conflict narrow-parameter class 138/138 after cast_call_sites,
--normalize-self-decls and --fix-def-sig were each eliminated BY MEASUREMENT. S33 proved it once and
it was never generalised.

Carries the unresolved accounting anomaly prominently (new task #11 / S1e): distinct-code FELL
89.3 -> 89.2 across the alias harvest while fn-count ROSE, which no pure naming artifact explains.
The bytes are proven; the yield number is not. Next session starts there, before scaling the lever.

Also records eleven tool defects fixed (nine of ten "walls" were our own instruments, two of them
mine), that §134 has now appeared in SIX tools and wants cdecl._mask rather than a seventh patch,
and seven process errors of my own including piping away a gate summary I then could not report.
2026-08-04 21:25:18 -06:00
Drew T a5c5526a8a docs(phase-30 S38): checkpoint v3 — S3 lands at 137/138, and the session's one R22 failure
FLEET 96.32 / 94.4 / 89.3 — +34,176 instructions this session, the great majority for ~0 agent
tokens. R22 run ten times: 140/140 on nine, ONE REAL FAILURE.

That failure is the most important line in the checkpoint: ov_SC07_010 passed its PER-BINARY build
and failed the clean-tree R22. Committing on that per-binary "BANKED" would have shipped a broken
overlay and reported 138/138. A per-binary pass is not a fleet byte claim (§61).

S3's recorded framing ("the T2 Arm-A %lo +0x20 carve defect") was WRONG and is corrected in place:
the carve was byte-neutral on the first attempt in all four overlays. The blocker is that carving
out of a jr file hoists the parent's file-scope decls into the region as its ambient set, so the
fleet's loose-typed spellings meet the shared header's for the first time.

Ten tool defects fixed this session, two of them mine — including an alias scanner that reproduced
the exact §134 comment-blindness defect I had documented hours earlier, caught by the R32 guard I
had added that same morning. §134 has now appeared in SIX tools, and the checkpoint records that the
real fix is routing line-shape decisions through cdecl._mask (R33) rather than patching a seventh.

Seven process errors of my own recorded, including reporting 138/138 before R22 had spoken.
2026-08-04 20:10:11 -06:00
Drew T f9eaa671b7 docs(phase-30 S38): checkpoint v2 — S1/S2 landed; the residue is TWO symbols, not a missing tool
FLEET 96.32 / 94.3 / 89.1 (+19,300 instructions this session, the great majority for ~0 agent
tokens). R22 140/140 seven times.

S38 was eight tool defects, not a compiler problem — all eight enumerated in the checkpoint. The
headline: harvest_verify._reload_corpus deleting the stub it had just followed through a carve (10
of 16 wave-6 drafts vanished with no verdict), and jr_isolate_all SILENTLY DELETING definition-side
__asm__-alias functions during a repartition (the fifth tool with that same blindness, already fixed
in family_remap and never propagated).

T7 progress: S1a done (895 types lifted), S1c done (97 members banked, were 0), S2 done (10 members
banked + 7 families now CLASSIFIED by the reporting fix), S1b CLOSED BY MEASUREMENT — its premise
was wrong, cast_call_sites/tu-scope/scope_data_fix are all already on by default in hseq_sweep, and
--normalize-self-decls got a fair post-fix re-test and does nothing here.

The real residue is 383 of ~398 conflicts on TWO symbols: func_80146A6C (fleet decls UNIFORM -> the
draft is wrong, a bug hunt) and func_80161208 (four incompatible fleet shapes -> the genuine
Phase-16 loose-typing wall). Recorded as task S1d, explicitly NOT scoped as "add a reconcile pass".

Six process errors of my own recorded, the worst being that I asserted family_sweep hides its
per-member errors when 23,211 classified files exist and both of the day's zeros were already
diagnosed in them.
2026-08-04 19:44:31 -06:00
Drew T 97a6864677 docs(phase-30): adopt the Fable-5 frontier plan as T7 + persist the report
The Fable-5 agent's harness blocked it from writing to disk, so its full analysis existed ONLY in
the completion notification — one session away from being lost. Transcribed verbatim to
.run/fable_frontier/ANALYSIS.md and force-added (with its computed pools, pool_ovres.json), and
CURRENT_PHASE.md's new T7 points at it so future sessions know where the detail lives.

T7 supersedes T6's wave ordering on one number: across every sweep run this project has done,
blockers are ~24k PLUMBING vs 4,917 DIFF (5:1). Fixing plumbing moves work from the ~490 tok/ins
wave column to ~0, and S1 restores the propagation multiplier that makes every later wave ~3x
cheaper. DO S1 BEFORE ANY WAVE.

S1-S7 recorded with reachable-ins and tok/ins estimates. Provenance is explicit: the two headline
refutations were independently re-verified (23,211 classified files exist; 0x801833f0 went 0/6 ->
6/6 after the type lift, R22 140/140); the POOL NUMBERS are the agent's own computation and are
NOT re-verified — flagged in the file to verify before scaling a wave onto them (R14).

Standing pre-probe rule added: check h_norm identity across members BEFORE probing (an h_norm-
identical family returning 0% is a compile-error certainty), and read the classified files before
theorising about a sweep failure.
2026-08-04 18:40:14 -06:00
Drew T d053d71a27 docs(phase-30 S38): STRIKE my "x138 era is over" reading — the base rate is 5:1 PLUMBING, not codegen
A Fable5 frontier pass (read-only) refuted four S38 claims, each against data already in the repo:
 - "4 of the 8 big families collide by chance" -> all four classify PURE or IMM x138, and PURE means
   every differing word sits at a RELOC position, i.e. the OPPOSITE of chance collision. I printed
   diff_class in my own table and misread it. 0x80161418 has 552 already-matched siblings.
 - "0x80175820 / 0x80132018 are not templatable" -> IMM x137 (7,535 ins) and PURE x132 (6,072 ins).
 - "the free-sweep zeros are undiagnosed" -> both were PLUMBING, both diagnoses written by the sweep
   itself at probe time into .run/hseq_failed.*.classified.txt (23,211 such files exist).
 - "family_sweep hides the per-member error" -> false, struck.
THE BASE RATE settles it: across all sweep runs, blockers are ~24k PLUMBING vs 4,917 DIFF (5:1).

What survives: the open-member distribution really does skew small. What does not: the conclusion I
drew from it. Only the 2 GIANT walls survive scrutiny, and they are EXEMPLAR walls whose 138 members
each classify PURE — 50,094 ins riding on 2 cracks.

Newly visible and untargeted: 1,689 open-only h_norm clusters / 5,956 fns / 326,261 ins = 46% of all
open overlay instructions, at a 2.7x propagation multiplier; plus 250 fns / 12,981 ins byte-identical
to matched code (incl. the whale, open only in the 4 SC07s).

Ranked plan recorded: S1 (fix the 2 plumbing classes, re-sweep the 148 matched-exemplar families)
reaches 35-60k ins at ~10-25 tok/ins against a 490 t/ins wave baseline. S1-S4 move 80-115k ins to
~0 tokens and restore the propagation multiplier. DO S1 BEFORE ANY WAVE.

Standing pre-probe rule added: check h_norm identity across members first — if they are h_norm
identical, a 0% is a compile-error certainty, not evidence about codegen.
2026-08-04 18:36:51 -06:00
Drew T c21a310cce docs(phase-30 S38): measure the family frontier — the x138 era is over; the free-sweep lane is 0/0 UNDIAGNOSED
Answers "can we still derive an exemplar and free-crack hundreds?" with the distribution:
families YES, hundreds-per-crack NO. Only 8 families have 100+ open members — 2 permanent walls,
2 ledgered not-templatable, and 4 that are 14-25-ins functions whose h_seq skeleton collides by
CHANCE (0x80128c98 probed 0/138). The frontier is now 1,534 families at 2-4 members plus 3,807
singletons. A crack is worth 2-9 members, not 138 — wave 6's func_8017FEE0 (19 members, 4,485 ins)
was near the TOP of what remains. Throughput of cracks now beats leverage per crack, which argues
FOR the 64-target wave shape rather than against it.

The 147 matched-sibling families (66,971 ins) looked like free sweep fuel. Two probes returned 0
(0/138 small-skeleton, 0/6 on the top 328-ins PURE non-jr family). RECORDED AS A PENDING QUESTION,
NOT A WALL: the cause is undiagnosed, and this project has manufactured a false wall from exactly
this evidence before (P26's "families template ~0%" was overturned in P28 when the 0/8 turned out
to be a missing carve and the family then banked 102/115). family_sweep reports banked/failed
without the per-member build error, so DIFF and PLUMBING are indistinguishable at this level —
the same missing-payload gap as jtbl_family_bank's bare "gate-fail". One member through
harvest_verify with the error read settles ~26k instructions.
2026-08-04 18:20:12 -06:00
Drew T bc04f65562 docs(phase-30 S38): checkpoint — wave 6 banked (+10,616 ins), the gate defect fixed, 9 drafts diagnosed
FLEET 96.29% fn / 94.2% instr / 88.9% distinct, R22 140/140 twice. Session banked 7 wave-6 heads
+ 25 propagated siblings = +10,616 instructions (12,368,236 -> 12,378,852; the digest delta matches
the hand-derivation exactly).

wave-metrics.md gains Findings 5 and 6:
 - RANK WAVES BY INSTRUCTIONS, NOT HEADS. Wave 6 banked ~45% more instructions than wave 5 while
   banking less than half as many heads, because a bigger head carries more instructions AND its
   family propagates at the same cost per sibling (func_8017FEE0: ONE 299-ins head -> 4,485 ins
   across 15 siblings, ~0 agent tokens). The metric to beat is POOL REALISATION (21%), not bank
   rate — and wave 6's bank rate is NOT comparable to waves 3-5 because the difficulty knob moved
   deliberately (median target 438 ins vs 143, mostly has_mid_jr).
 - A WAVE TALLY IS A COVERAGE CLAIM and needs its own assertion.

The 9 unbanked drafts are diagnosed and preserved, and 6 of them are ONE class worth cracking
first: `undefined reference` to a sibling that IS defined in the overlay but only via a
definition-side __asm__ alias (§37/§124) — the carve repartitions the object and separates the call
site from the alias definition. One fix frees 6 already-paid-for drafts and will recur in every
carve-heavy wave. The other two are genuine near-misses (close=47 REGALLOC-PERM, close=370).

Tooling committed for reuse: w6_pool.py (the pool derivation, now a script), w6_diag.py (runs the
REAL gate path — s36_capture.py splices without the carve and is wrong for jr targets),
w6_jtbl_prop.py (carve-path propagation with the per-family commit jtbl_family_bank requires).
2026-08-04 18:10:19 -06:00
Drew T 139e21118b docs(phase-30 S38): wave 6 launched — pool derivation is a script now, + 2 derive-don't-assert fixes
- .run/w6_pool.py: THE pool derivation, finally a script instead of inline python (R33).
  Ranks by OPEN templatable weight (corpus.stubs over the family map's member list, §138 rule 4 —
  never off the map's `exemplar` field), carries the walls/ledgered-residual exclusion set, drops
  any family whose address was attempted-and-still-open in a prior wave (83 addrs), and enforces
  one target per (overlay, TU) so a wave cannot manufacture its own §138-rule-2 type-tag conflict.
  Pool: 2,928 fresh families / 476,611 open templatable ins.
- wave 6 = 16 targets / 50,596 open templatable ins (3x wave 5), large-function heavy
  (median ~270 ins, max 947); prompt carries the S37/W6 block (stage the big ones; cross-address
  families need STEP 0 because searching by address cannot find their twin; the PAIR rule).
- TWO R37 FIXES TO THE MANIFEST ITSELF, both "asserted, never derived":
  * `seed` was an arbitrary i%2 alternation carried over from the previous wave's shape — it
    controls whether the prompt claims a cached Ghidra seed EXISTS. Now derived from
    .run/ghidra_c/ on disk: 9 of 16, not 8 by alternation.
  * `model` routed by MEASURED band, not the stale §136i ladder: Sonnet is measured 81-100%
    first-pass over 125-793 ins, so func_8017C974 (947) is outside it and goes to Opus directly.
- CURRENT_PHASE.md: in-flight checkpoint (the wave-5 restart lost 2.7M tokens of ungated drafts;
  this block says force-add the drafts and resume by GATING, never by re-running).
2026-08-04 16:13:14 -06:00
Drew T bd097a9010 docs(phase-30): checkpoint — name the code commit correctly + add a staleness self-check 2026-08-04 13:47:42 -06:00
Drew T b42b1885ae docs(phase-30): SESSION-33..37 checkpoint — wave 5 banked, nothing owed; wave-metrics findings reordered 2026-08-04 13:43:53 -06:00
Drew T 3f51101ca9 docs(phase-30): SESSION-33..37 checkpoint — PAUSED; 16 ungated wave-5 drafts preserved in git
Paused at Drew's request for a Windows restart. Nothing running, tree lock free,
tree clean (R23 db churn aside). R22 run 19x this session, 140/140 every time.

THE ONE THING OWED: `.run/s37/*/func_*.c` — 16 wave-5 drafts, all claiming MATCH,
NONE gated. Force-added to git (.run/ is gitignored) because they cost ~2.7M
agent tokens and Workflow's resumeFromRunId cache is SAME-SESSION-ONLY, so it
does not survive the restart. Resume by GATING them, not by re-running the wave.
Also preserved: the wave scripts (.run/s36w.js, .run/s37w.js), manifests, the
hardened gate driver, and the four capture drivers.

MEASURED THIS SESSION (both answer questions Drew asked):
- The wave PROMPT is the lever. Bank rate 76% -> 77% -> 100% -> 100% on the same
  models and the same gate, prompt the only variable. The jump was STEP 0 (a
  magic-literal grep of src/, ahead of engine_core.h) — and that step came from a
  wave-2 agent's index_gap report, i.e. the agents write the next prompt.
- The pipeline() fix, before/after: wave 4 parallel() 14 targets / 136 min /
  2.5x parallelism; wave 5 pipeline() 16 targets / 82 min / 3.8x. 40% faster on
  14% more targets. The two-batch design was a hard barrier with 46-min dead gaps
  at each boundary; the harness already caps at 16 so the batching bought nothing.

Housekeeping: removed 3 stray cc1 intermediates (t.i, t.i.greg, t.s) that an
agent left at the repo ROOT — scratch belongs under .run/ (R12), same class as
the gccdump.lreg noted at the Phase-24 close.
2026-08-04 13:29:51 -06:00
Drew T 6b30335eb7 docs(phase-30): SESSION-33/34/35 checkpoint — fresh-session safe; 5 distilled rules, the h_seq ceiling re-confirmed by probe 2026-08-04 07:16:55 -06:00
Drew T 4f6b0e8de1 feat(phase-30 S33b): PROPAGATE head 82% banked — 15,257 of 18,545 ins, four levers
Fleet 96.10 -> 96.17% fn-count / 93.7 -> 93.8% instr / 88.0% distinct.
dedup 1908 -> 1909 groups, 0 failed, C1 241078/241078.
R22 clean-fleet: 140 passed, 0 failed of 140.

  func_80147364  4,110  x137  definition-side asm-label alias
  func_8016BA68  3,886  x134  dedup_extend + the MIRROR decl relax
  func_8012F274  3,973  x136  hand-authored macro, source overlay excluded
  func_8012A598  3,288  x138  cdecl._mask backscan fix + shared-type switch
  func_801466F0  3,288  OPEN  the wrapped-alias regex — measured as ONE function

THREE DISTINCT CARRY VARIANTS were hiding in one "CARRY-FIXABLE" bucket, and
only one is a tool bug (-> cookbook §138):
  - a MULTI-LINE comment halts the preamble backscan -> fix the tool (cdecl._mask)
  - a draft-local `struct Tag {…}` -> switch the exemplar to the SHARED type
  - a file-scope `static inline` helper -> hand-author, EXCLUDE the source overlay
The third is the sneakiest: gcc-2.7.2 accepts implicit function declarations, so
the extracted body PASSED compiles_standalone with the helper undeclared and the
miss surfaced only as a whole-binary byte DIFF 137 gates later. Instantiating
that macro in the SOURCE overlay is a duplicate definition (its file-scope helper
is still there), so the shape is `--source-overlay X --binaries <all-but-X>`;
`--binaries` alone removes the source from the scan pool and errors.

TOOL BOUNDARY: once a group's members are DEFINE_func_*() sites, dedup_propagate
cannot extend it (find_site never returns a `def`). dedup_extend is the tool for
an already-macro-ized group — and `dedup_extend --check-only` across ordinary
overlays is a cheap fleet-wide wiring census (measured: exactly 1 group per
overlay, so no hidden backlog).

MEASURED, NOT INHERITED (R37): the S6b note frames _alias_decl_for's single-line
regex as a CLASS of missed work. It is not — 91 asm-label alias decls exist
fleet-wide, the regex matches 90, and the single miss is func_801466F0. Worth
3,288 ins, but a one-function fix. Correcting the expectation so a future session
does not scope against it.
2026-08-04 00:30:56 -06:00
Drew T 356373efab fix(phase-30 S33b): the PAIR rule — my 42-decl relax did NOT unblock the lane; the mirror form did
HONEST CORRECTION to commit:1382. That commit's message implies the 42 `(void)`
relaxes unblocked the PROPAGATE remainder. They did NOT: the re-run banked 0/1
in all 134 overlays with the same error, because DEFINE_func_8016BA68 declares
func_80146C3C `(u8*)` — the MIRROR of the EXTEND-lane pair — and my relax only
touched the `(void)` direction.

Root cause is the R37 shape a third time: I bucketed by SYMBOL and stopped. The
lever is set by the (macro-shape, TU-shape) PAIR, and the same symbol conflicts
in BOTH directions across this fleet. One awk over the macro I was ACTUALLY
fixing — which I ran for the EXTEND macros and not for this one — shows the pair
before a 134-build run. §138 amended with the PAIR rule; correction logged in
CURRENT_PHASE.md rather than rewritten out of history.

The 42-decl relax still stands: byte-neutral, R22 140/140, removes a real
conflict class. It just did not do what I predicted.

THIS commit relaxes the 2 remaining `(u8*)` decls (uses are cast; `()` is
compatible with the (void)/()/(u8*) forms the fleet carries and no decl of this
symbol has a default-promotion param). R22 clean-fleet: 140 passed, 0 failed.

ALSO: tools/overlay_src_split.py `_split_macro_body` — the §134 sweep's one real
target, fixed. It carried the identical single-line-only comment test, and it
decides where a macro body's file-scope externs END, so a multi-line comment
truncated the extern set. SIZED FIRST: 38 live lines in engine_core.h macro
bodies hit it today. Now decides on cdecl._mask (one oracle, R33) with the
length-preservation invariant asserted (R32). Proven both directions by a
control: pre-fix it stopped at `/* multi` carrying 1 of 2 externs and treated the
comment as the definition head; post-fix both externs carry and the def head is
correct. Not in the gate path (only o0_subsplit + jr_isolate_all import it).
2026-08-04 00:16:23 -06:00
Drew T 7a6a09379f fix(phase-30 S33b): relax all 42 func_80146C3C decls — the PROPAGATE remainder is the SAME symbol
Diagnosed the 11,147-ins PROPAGATE remainder with one probe, in §138's order:
1. ONE COMMAND, NO BUILD: the originals of BOTH 0x8016BA68 and 0x8012F274 are
   sha1-identical across ov_SC07_006 / ov_SC06_025 / ov_SC01_000 / ov_SC01_077 /
   ov_SC03_001 -> the registry is sound; the cause is TU context.
2. ONE BUILD in an excluded overlay named it: `conflicting types for
   func_80146C3C` — the SAME symbol as the EXTEND lane, same (void)-vs-(u8*)
   shape, same one-token lever. The 137 [exclude] lines were one declaration.

Relaxed the remaining 42 `extern void func_80146C3C(void);` in engine_core.h to
`()`. Measured safe BEFORE editing (§138): every fleet decl of the symbol is
`(void)/()/(u8*)/(u8 *a0)` — no default-promotion param anywhere, so gcc-2.7.2's
`()` rule cannot bite — and every use in the header is a no-arg call or already
cast, so it is codegen-neutral. R22 clean-fleet: 140 passed, 0 failed of 140.

TOOL BOUNDARY worth recording: `dedup_propagate` CANNOT finish this one. The 4
SC07 members are now `macro` sites, so `find_site` never returns a `def` and the
auto-source scan errors with "no source overlay has it matched". Extending an
already-macro-ized group is `dedup_extend`'s job. Probe: exactly 1 extendable
group per ordinary overlay — so the fleet has no hidden wiring backlog beyond
this function (a useful negative, R32-shaped).

Also logged: the §134 scanner sweep is sized and has ONE real target —
tools/overlay_src_split.py:345 (_split_macro_body) carries the identical
single-line-only comment test, and it decides where a macro body's file-scope
externs END, so a multi-line comment there silently truncates the extern set.
The other scanners in that file track block-comment state; split_src_region.py
and family_remap.py already handle the multi-line form.
2026-08-04 00:11:42 -06:00
Drew T 3daa647bb3 docs(phase-30 S11): cookbook §138 + SESSION-33 checkpoint
§138 — "the propagation lanes: a gate refusal is a DECLARATION, and which lever
you owe depends on blast radius". The durable content of this session:
- the 4-lever triage table ranked by blast radius, and the rule to grep the
  fleet's decl shapes BEFORE relaxing to `()` (illegal only against a
  default-promotion param — 4,020 decls measured, 8 of 36 banked for one token)
- `volatile` in the host TU is a SCHEDULING BARRIER that masquerades as a codegen
  wall; the tell is a positional shift with a `nop` at a delay slot, and the
  h_exact contract is confirmed/refuted in ONE command with no build
- the DEFINITION-side asm-label alias as the only zero-radius escape when the
  fleet canon disagrees on a promoting param (1,725 in-tree precedents)
- rank a lane by measured concentration, not class count (5 of 45 classes carried
  89%), and `--recover` is not a retry (16/16 on drafts, 4/138 on a propagation)
- §134 multi-line blindness recurring in a second tool; decide on `cdecl._mask`
- the waiter rule CORRECTED: `pgrep -x make` is wrong for a campaign of
  sequential makes, `pgrep -f` self-matches, `nohup … &` signals the wrapper

Checkpoint refreshed and placed below the task checklist (fresh-session safe):
fleet 96.10 / 93.7 / 88.0, dedup 1908/0, R22 140/140 four times this session,
nothing running, lock free. Three named next items, none yet diagnosed against a
build — the PROPAGATE head remainder (11,147 ins), the 41-class tail (2,316),
and EXTEND's last 5 (the whale needs the §38 -O0 route; dedup_extend should
refuse-and-name that class per R32).
2026-08-03 23:55:53 -06:00
Drew T 62042f65ca fix(phase-30 S11): multi-line-comment blindness in dedup_propagate; func_8012A598 x138
Fleet 96.06 -> 96.10% fn-count / 93.7% instr / 88.0% distinct; dedup 1907 -> 1908
groups, 0 failed, C1 240807/240807. R22 clean-fleet: 140 passed, 0 failed of 140.

func_8012A598 (3,288 templatable ins) was being written off as CARRY-FIXABLE.
It took TWO fixes; either alone leaves it skipped.

1. TOOL (R33) — find_site's preamble backscan. The SESSION-18 fix handled blank,
   `//`, and SINGLE-LINE `/* … */` lines, but a MULTI-LINE block comment still
   halted the walk: its middle lines start with `*` and its last line ends `*/`
   without starting `/*`. So the three externs above the body were dropped and
   the body then failed compiles_standalone on now-undeclared data. This is the
   §134 multi-line-blindness class — S6b fixed the identical shape three times in
   family_remap (D1/D2/D5) and this copy was never reached.

   Fixed by deciding skippability on `cdecl._mask` — the project's ONE masking
   oracle — instead of on line syntax: it subsumes every comment form at once and
   cannot be fooled by a `/*` inside a string, with an R32 assertion on the
   length-preservation invariant it rests on. Strictly monotone (it can only
   carry MORE preamble), and dedup_propagate is a byte-gate feeder, so a bug here
   can fail to bank but never falsely bank.

2. EXEMPLAR — the body also declared a draft-local `struct BigCopy164` tag, which
   the tool refuses by design (two macros defining one tag would redefine it in a
   single TU). The shared `struct BigCopy` (engine_types.h L312) is the identical
   layout and is ALREADY used this exact way at engine_core.h:16158, so switching
   the exemplar to it is byte-neutral and drops the alias too.

Probed on ONE member before scaling (R37/S29): byte-identical 9052dc0e first try;
then 138 overlays byte-identical.

PROPAGATE head accounting after this: 7,398 of 18,545 ins banked (func_80147364
4,110 + func_8012A598 3,288). Still open, each with a NAMED cause and none yet
diagnosed against a build: func_8012f274 (3,973, dropped), func_8016ba68 (3,886,
4/138), func_801466f0 (3,288, the S6b D4 wrapped-alias gap).
2026-08-03 23:53:50 -06:00
Drew T c7ad41c8a3 feat(phase-30 T6/S11): the propagation lag — EXTEND 31/36, and the PROPAGATE head measured
Continues the S11 lane. Fleet 96.01 -> 96.06% fn-count / 93.6 -> 93.7% instr /
88.0% distinct; dedup 1905 -> 1907 groups, 0 failed, C1 240669/240669.
R22 clean-fleet: 140 passed, 0 failed of 140. 0 NON_MATCHING (G4).

EXTEND (SC07): the 16 volatile-blocked DIFF slots banked on retry after the
data asm-label alias -> lane total 31/36.

PROPAGATE head, measured rather than projected. .run/s8_lag.json re-split: the
checkpoint's "45 classes / 20,837 ins" is really 5 classes carrying 18,545 ins
(89%) and 41 carrying 2,316. Per-class outcome:

  func_80147364  30x137 = 4,110  BANKED x137 (definition-side asm-label alias)
  func_8012f274  29x137 = 3,973  DROPPED — byte-diverges in ~130 overlays
  func_8016ba68  29x134 = 3,886  4 of 138 banked; excluded from ~130
  func_8012a598  24x137 = 3,288  SKIPPED, cause NAMED by the tool
  func_801466f0  24x137 = 3,288  no source found — the S6b D4 gap, still open

  func_80147364's byte-true definition is `(u16, u16)` while 4,046 fleet decls
  say `(u16, s32)`. u16 is a default-promotion type, so the `()` no-prototype
  escape is ILLEGAL (the documented gcc-2.7.2 dead-end) and conforming the decl
  would change caller codegen. The DEFINITION-SIDE asm-label alias gives the def
  a distinct C identifier while emitting the real symbol -- zero blast radius on
  every caller. Probed on ONE member first (1 build, not 137 -- the S29
  discipline): byte-identical 9052dc0e first try; then 137 overlays clean.
  In-tree precedent for the form: 1,725 files.

MEASURED NEGATIVE, recorded not buried: `dedup_propagate --recover` banked only
4 of 138 on func_8016ba68 and dropped func_8012f274 entirely (137 [exclude]
lines). The caller-extern reconcile that is 16/16 lifetime ON DRAFTS does NOT
transfer to PROPAGATION of these two. Cause not yet diagnosed -- probe one
excluded overlay's build output before any further attempt (§136a), do not
re-run the lever hoping.

NAMED NEXT (cheapest first): func_8012a598 skips on `missing file-scope extern
(CARRY-FIXABLE): D_801151D4, D_80126DB8_a, D_80127504` -- the SESSION-18
preamble-backscan class. Its body is 2 statements and `struct BigCopy` is
ALREADY in the shared engine_types.h (L312) with the identical statement already
macro-ized at engine_core.h:16158, so a hand-authored macro (the func_80147364
path) should take it x137 for ~0 tokens.

Process errors recorded in CURRENT_PHASE.md, all three one mechanism -- the
signal sampled is not the thing waited for: (1) a `nohup CMD &` wrapper's exit
read as the fleet check finishing (it stood at 63/140); (2) a corpus.stubs probe
mid-rebuild, which R32's coverage assertion refused rather than answer wrongly;
(3) CORRECTION to the S10 checkpoint's own rule -- `pgrep -x make` is right for
one make and WRONG for a campaign of sequential makes (it fired in a gap and
reported a live campaign done), and `pgrep -f <pattern>` SELF-MATCHES so that
waiter can never exit. Wait on the campaign process or `treelock.sh --status`.
2026-08-03 23:41:34 -06:00
Drew T ef1d8c9fab docs(phase-30): SESSION-31/32 checkpoint — fresh-session safe; Sonnet finding, 3 live lanes, stale P32 ledger flagged 2026-08-03 22:28:16 -06:00