mirror of
https://github.com/Druthulu/BFM-decomp
synced 2026-10-05 00:47:54 -04:00
85fb289db582d842fc41dc059fa187bb992e76ea
34 Commits
| Author | SHA1 | Message | Date | |
|---|---|---|---|---|
|
|
974401668f |
feat(phase-30 S47-F4a): cpp-derived TU type map clears the data-conflict class (+31)
scope_data_fix detected conflicts by SCANNING TU TEXT, which cannot see a MACRO-INJECTED declaration — and that is where these conflicts live: `extern Vec8 D_80114F24;` sits inside a DEFINE_func_* macro body in engine_core.h while the overlay .c holds only `DEFINE_func_XXXX()`. That declaration is a genuine file-scope decl of every TU invoking the macro, and it is what the draft collides with. Fix: family_sweep builds a per-TU map from cdecl.tu_scope (cpp-derived, cached — 467 data decls in ov_MAIN_012 vs 0 findable by text scan) and passes it to scope_data_fix, which now takes an optional tu_types. tu_scope is the repo's stated oracle for "what does this TU declare", and its own docstring warns that the `above` form answers VISIBILITY, not CONFLICT — C requires compatibility regardless of order. scope_data_externs was built on that wrong question. Banked 5 -> 31; failures 730 -> 699. The whole data-symbol class is gone: D_80114F24 (12), D_800AE620 (10), D_80126B58, D_80078EB4, D_800183E0 all cleared. R22 clean-fleet: check-all 213 passed / 0 failed of 213. REGRESSION I CAUSED, AND FIXED: the reclassification showed 9 fresh `conflicting types for aD800B9A02` — my own alias colliding. The group-level path suffixes the alias per function precisely to prevent this; scope_data_externs did not, so two drafts aliasing one symbol declared `aD800B9A02` twice with different types — re-creating the collision one level down. Both paths now use _alias_name(sym, func). Verified: distinct names, each keeps its own type, both bind the real symbol via the asm label. |
||
|
|
3e0028c2ed |
feat(phase-30 S47-F2b): group-level draft-vs-draft data aliasing (83 aliased, 5 banked)
family_sweep stages every member of an (overlay, split) group into ONE TU before gating, so two
templated bodies routinely carry different views of one address — D_80114F24 is `s32` in one body
and `Vec8` in another. scope_data_fix is handed one draft plus the pre-splice TU and structurally
cannot see the others, so that collision was invisible to it.
_alias_group_data_conflicts(): after staging, any data symbol a group's drafts declare with >=2
distinct types gets a PER-DRAFT §37 asm-label alias. The alias is suffixed with the function name
(aD80114F24_8017B880) — aliasing both drafts to a shared name would re-create the same collision at
one remove, which the unit test exists to catch. Each body keeps its own type: for data the declared
type drives the load (lh vs lhu), so canonicalising would silently change codegen for every other
view. Codegen unchanged — the asm label pins the emitted symbol.
83 conflicts aliased across 172 groups; banked 2 -> 5. R22 clean-fleet 213 passed / 0 failed of 213.
WHY THE HEADLINE SYMBOLS DID NOT MOVE — root cause now CONFIRMED, not inferred. D_80114F24 (12)
and D_800AE620 (10) are unchanged because the conflicting declaration is MACRO-INJECTED:
`extern Vec8 D_80114F24;` lives inside a DEFINE_ macro in engine_core.h (D_800AE620 has 6 such),
while the overlay .c holds only DEFINE_func_XXXX() invocations. Neither a scan of the staged drafts
nor a scan of the TU text can see it — that needs the preprocessed TU. The sweep already does
exactly this for CALLEES (cast_call_sites' canonical map is cpp-derived "so it sees macro-injected
declarations"); the data path never got it.
This collapses F2's remainder and F4 into one fix: memcpy's 26 failures are the same shape — task B
found nine `extern void *memcpy(...)` spellings inside those same DEFINE_ macros. A cpp-derived
declaration map feeds both, and the alias mechanism is already built and control-tested; only the
detection SOURCE is wrong. For memcpy the alias is the documented house solution, not a workaround
(engine_core.h:24480 hand-writes `extern void func_8005C324(...) __asm__("memcpy")`).
Four attempts on this class for 5 members: three mechanisms proposed before reading what the
compiler actually complained about. The mechanisms are correct; they targeted the wrong collision.
|
||
|
|
b1dbfcb572 |
fix(phase-30 S45): family_sweep --hseq stub map derives ov_*+md_*+resident (R32)
- the .run/sig.ov_*.jsonl glob had no md_ entries, so every module member fell into an empty stubs.get() and booked a silent 'not-stub' skip — the I.1d glob-widening class, missed because family_sweep sat on the audit's 'auto-OK' list - negative control: --only 0x80165b28 --stage-only staged 0 md members before, 32/32 after |
||
|
|
aa600c56ef |
fix(phase-30 S6e): family_sweep snapshotted TUs it never edited — the self-decl lever measures 0, honestly
- D6: hseq_sweep took the tu_snapshots snapshot UNCONDITIONALLY, one line before the `if nfix:` that decides whether to edit. A TU that normalize_self_decls merely INSPECTED was therefore registered, and the phase-2 MISMATCH backstop attributed ANY group failure to a "self-decl edit" that was never made -> revert + `0/N banked`. Measured: 909 of 909 groups took that branch while NSD actually fires on ~25% of members (3 of 12 probed). The §103 tu-scope path below has always snapshotted inside `if _rep["moved"]:`; NSD now matches it. - After the fix: NON-NEUTRAL 909 -> 303 (consistent with the fire rate) and STILL 0 banked — the 606 groups that now take the normal path bank nothing, so the lever's verdict is REAL, not an artifact: this residue is not self-decl-conflict-bound. Lever measured, closed, zero. - R14 on my own conclusion: I byte-measured a firing case instead of trusting the backstop — func_80162CCC/ov_SC01_000 builds to 9052dc0e... WITH and WITHOUT the NSD edit (byte-NEUTRAL), so the surviving 303 verdicts are wrong too (likely accumulated multi-member edits in one TU). Logged as a named open item, not chased: the lever yields 0 either way. - The tell, twice in one session (§134): a 100% rate is a property of the mechanism, not of 1,622 different functions. Three earlier sweeps over the same population reported 0 NON-NEUTRAL. |
||
|
|
4d5bee0be8 |
fix(phase-30): T4 — 2 'Phase-22 grinder bugs' verified STALE (already fixed); real fixes: asm_subdir_for derives from corpus (R33), --fix-def-sig help carries the §119 warning
Verified against code rather than the ledger: the split-blind lookup globs */ correctly, and the churn was fixed by T5's input-signature gating. Both struck. asm_subdir_for was still a parallel oracle (silent g[0] on multi-match) -> now corpus.asm_path. --fix-def-sig defaults off correctly but advertised 'Byte-neutral; gate arbitrates' — the claim T84 refuted (signedness-wrong header decl over a byte-correct draft; 137 members held at 0 until the flag was dropped). A defect ledger nobody re-verifies decays into busywork — verify before scheduling. |
||
|
|
7e32da8f64 |
feat(phase-29): T95/T96 — func_80142B2C 136/136 (§121); all 3 byte-identical stragglers closed
- The draft calls ((void(*)(void))func_80142C84)() but nothing declares that symbol above the splice: it is DEFINED by DEFINE_func_80142C84() in engine_core.h, so gather_externs has no extern line to harvest, and the member TU instantiates the macro BELOW our function. - The wrong guess was the useful step: a no-prototype `extern s32 func_80142C84();` turned `undeclared` into `conflicting types` — a DIFFERENT error, proving the diagnosis right and the type wrong. Synthesised from the macro's own definition head -> MATCH (34 ins) -> 136/136. - NEW macro_def_sig_map() (1,878 signatures): the complement of header_sig_map(), which reads the externs a macro emits FOR ITS CALLEES; this reads the signature a macro DEFINES. Cookbook §121. - ALL THREE byte-identical stragglers carried since SESSION-24 are now closed: func_80146750 137/137 (T84), func_801759D8 137/137 (T93), func_80142B2C 136/136 (T95) = 410 members, and not one was a compiler wall (a signedness-wrong header decl, a type-name collision, a missing extern). - Blast radius 0 (74 further families re-swept). FOUR data points now: only §117 (wrong LOGIC) generalised at 1,209 members; §118/§120/§121 are path-reachability gaps worth ~one family each. - GATES: R22 clean-fleet 140/140; dedup 1886/0; 0 NON_MATCHING (G4). - METRICS: fn-count 91.88 -> 91.96% (+273, exact) · instr 87.3 -> 87.4% (+12,296) · distinct +0 (both byte-identical families — §111 predicted exactly that). |
||
|
|
9a1507462f |
feat(phase-29): T93/T94 — func_801759D8 137/137 via type-uniquify (§120) + two T92 corrections
- CORRECTION 1 (R14/P9): T92's "strip-if-ambient" recipe was WRONG. Stripping the draft's duplicate
typedef breaks the extern that USES it (the TU's own copy sits below the spliced function), so the
"second stacked blocker" T92 recorded (D_800AF634 used prior to declaration) was my own fix
misfiring, not a real blocker. RENAME, don't remove: rtu_match CC1 FAIL -> MATCH (56 ins).
- CORRECTION 2: T91's wiring never RAN. family_sweep has THREE staging sites sharing the identical
two lines (edit-remap / hseq / plain h_norm); I patched by rindex twice, which lands on the PLAIN
site, so --hseq staged the draft unchanged and the lever looked ineffective. Re-anchored on the
hseq site's unique write (func_{to_addr:08X}.c) and the draft came out renamed. T91's revert was
right discipline on a false premise.
- RESULT: _uniquify_draft_types wired into the hseq path (byte-neutral — C type names never reach
codegen). func_801759D8, one of the three long-standing byte-identical stragglers: 0 -> 137/137,
0 failed. Blast radius 0 (74 further families re-swept, none moved) => TARGETED lever, like §118
and unlike §117.
- Cookbook §120, incl. the law: before concluding a lever does not work, prove it RAN — diff the
staged artifact for the change it is supposed to make.
- GATES: R22 clean-fleet 140/140; dedup 1886/0; 0 NON_MATCHING (G4).
- METRICS: fn-count 91.88 -> 91.92% (+137, exact) · instr 87.3 -> 87.4% (+7,672) · distinct +0
(byte-identical family — §111 predicted exactly that).
|
||
|
|
970559423d |
feat(phase-29): T77 — wire the callee-decl lever into family_sweep; func_80173A60 0/135 -> 135/135
Item 1. The T76 diagnosis was right and the fix was a lever we already owned. cast_call_sites
(§17a-1/§20) handles the callee-conflict class and lived ONLY in gate_stage, which the family sweep
deliberately does not use — the THIRD instance this session of a lever unreachable from the path that
needs it (T56 data-decl unreachable, T57 function-decl off-by-default, now T77 callee).
the 5 byte-identical families : 0/682 -> 135/682
func_80173A60 specifically : 0/135 -> 135/135
Wired after scope_data_fix (orthogonal axes: data vs callee), default ON with --no-cast-callees. Two
details that matter: the canonical map is built from the TARGET sibling's TU via cpp
(canonical_map(ov, src_file=tu) -> cdecl.tu_scope) so it sees MACRO-INJECTED declarations — a
raw-text scan returns nothing for exactly the callees that conflict (§51g LAW 7) — and it is read
AFTER any tu-scope edit is on disk.
THE OTHER FOUR STILL FAIL, different causes. And the next finding is already visible:
func_8012F40C's blocker is RotTransPers, a PsyQ LIBRARY symbol — a callee conflict the cast should
have handled. It did not, because cast_call_sites' canonical map keys on
re.fullmatch(r'func_[0-9A-Fa-f]{8}'), so NAMED PsyQ callees are structurally invisible to it. That is
a one-line predicate widening with ~270 members behind it (RotTransPers + ApplyMatrixSV families).
GATES: R22 clean-fleet 140 passed, 0 failed of 140; tools-health OK; dedup 1886/0; 0 NON_MATCHING.
METRICS: instr 86.6% -> 86.7% (+7,965 ins); fn-count 91.15% -> 91.19% (+135); distinct +0
(byte-identical — §111 predicted it).
cookbook §114 — the three decl axes, and "conflicting types for X: READ X".
|
||
|
|
862e31df10 |
fix(phase-29): T75 — reconcile_def_sig no-prototype regression; func_80147364 is the narrow-param wall
Item 3 closes with 0 banks and a real answer: both routes priced, both refused.
conform_decls (4,021 sites) : ⚠ SCALAR-NARROWING (s32->u16), NOT caller-neutral — argument
promotion changes at every call site (byte-proven on func_80175DA8).
Trades a plumbing failure for a byte failure.
§99 no-prototype (9 sites) : gated 140/140 byte-neutral, but the sweep fails with
`conflicting types ... An argument type that has a default promotion`
The second is the PHASE-15 DEAD-END reproduced: gcc-2.7.2 refuses to match a `()` no-prototype decl
against a definition with a default-promotion parameter (s8/s16/u8/u16/float). func_80147364 takes
(u16, u16). The remaining route is §43 — convert the DEFINITION to K&R so its params promote to int —
which is def-side and needs the exemplar re-matched, not a header edit.
A REGRESSION I CAUSED AND FIXED IN THE SAME TASK: the §99 header change broke reconcile_def_sig —
with the canonical now `void func_80147364()`, _merge_sig saw zero canonical params and returned the
canonical verbatim, DELETING the definition's parameters so the body referenced `param_1' undeclared
x137. A no-prototype decl constrains nothing, so it now REFUSES rather than conforms, distinguishing
`()` from `(void)` on the raw text. Verified the def keeps (u16 param_1, u16 param_2).
A §61 JUDGMENT CALL, FLAGGED: the func_80147364 header edit bought 0 banks and §61's undo law says an
edit that bought nothing gets undone. I KEPT it — `()` asserts no wrong type where `(u16, s32)` did,
it is gated byte-neutral, and it is a prerequisite for the §43 route; reverting costs another full
R22 gate for no functional gain. This is a judgment call against a documented law, Drew's to overrule.
|
||
|
|
610a13c21c |
fix(phase-29): T61/T62 — items 1-4; all three families converge on one root cause (the shared header)
0 banked. Four tool fixes, one byte-neutral header correction (committed separately), and the three
families resolve to a SINGLE root problem — plus a defect I introduced and caught by measuring.
FOUR TOOL FIXES, each verified by a verdict MOVING rather than by assertion:
1. gather_externs prefers FILE-scope decls. Its contract says "file-scope extern decls" but
`^[ \t]*extern` also matches an INDENTED one — a block-scope decl inside some OTHER function, not
even in scope at the exemplar's own definition. Carried to file scope in the sibling,
`extern void func_80155FF8(void *, u8);` (ov_SC01_077 L1213) landed above that sibling's
DEFINE_func_80155FF8() macro and collided. ORDERED, not filtered — an indented decl stays the
fallback it always was, so a symbol declared only block-scope is unaffected.
2. reconcile_def_sig keeps the BODY's param names (the T60 fix, cookbook §109).
3. §85 return-axis precondition — refuses when callers consume the return (reuses
conform_decls.consumers, R33).
4. Param-use guard — refuses to retype a parameter the body indexes/dereferences (func_8014D610's
header says `void *a2` where the byte truth is `u16 *param_3` and the body does param_3[0]).
A DEFECT I INTRODUCED, CAUGHT BY MEASURING: func_8016163C read as a clean DIFF after T60 and I
reported it as "genuine codegen". It is not. match_one says SIZE-MISMATCH: draft 58 ins vs target 78
(delta -20, ratio 0.74, bucket redraft). Both overlays are 78 ins and extract_unit is fine —
--fix-def-sig demoted the return s32 -> void and gcc deleted the computation feeding it as dead. My
§85 check only asked whether CALLERS consume the return, never whether the BODY returns a value. The
tool manufactured a different-sized function and the verdict blamed the draft. Guard added. A "clean
DIFF" appearing right after a transform is a suspect, not a result.
THE CONVERGENCE: engine_core.h declares all three with types that contradict the byte truth —
func_80156044 int vs void (FIXED, byte-neutral, R22 140/140), func_8016163C void vs s32,
func_8014D610 void(s32,void*,void*) vs s32(s32,s32,u16*). Both remaining flips measure 0 §85
consumers. The fix is to correct the HEADER, not to bend the drafts.
AND ONE MORE LAYER: with its header fixed, func_80156044's verdict moved to `redefinition of
func_80155FF8` — extract_unit lifted a unit spanning TWO definitions and the sibling already defines
the wrapper via the shared macro. A unit-boundary defect, a fourth distinct cause. Three fixes peeled
three layers off one family.
|
||
|
|
50a108b5a8 |
fix(phase-29): T60 — reconcile_def_sig name bug fixed (verdicts moved); 0 banked, three causes separated
Tool fix + a sharper diagnosis. NO BANKS — the three "header-conflict" families share a SYMPTOM, not
a cause.
THE FIX (cookbook §109): reconcile_def_sig now conforms the canonical TYPES and keeps the BODY's
parameter names, parsed with cdecl (base/params/pnames, R33 — not a regex). Two re-render traps
handled: `void*` + `a1` -> `void *a1` (cdecl glues stars to the type), and an EMPTY parameter list is
handed back verbatim because `(void)` and `()` both parse to params==[] and are DIFFERENT
declarations (§99 no-prototype). Unit-tested across 6 shapes incl. both void forms and an arity
mismatch; falls back to the wholesale canonical string for fn-ptr/array params.
THE FIX IS REAL, AND THE PROOF IS THAT THE VERDICTS MOVED:
func_8016163C `param_1 undeclared` -> DIFF (plumbing CLEARED; codegen left)
func_8014D610 `param_1 undeclared` -> `void value not ignored` (the HEADER is wrong)
func_80156044 unchanged -> `conflicting types for func_80155FF8` (WRONG LEVER — callee conflict)
TWO FINDINGS UNDER THAT:
1. The §85 return-axis precondition applies to reconcile_def_sig and NOTHING CHECKS IT. Conforming a
def's return to the canonical `void` is only safe when no caller consumes the return.
func_8014D610's callers do, so engine_core.h's `void` contradicts the byte truth and conforming
yields `void value not ignored`. The HEADER is the wrong artifact; correcting it is fleet-shared
blast radius (§61/§63), not a sweep-time fix.
2. func_80156044 was never the def-signature class — its conflict is on the CALLEE func_80155FF8
(decl 2 lines above the splice). That is cast_call_sites / canon_sig_reconcile territory.
HONEST ACCOUNTING: re-swept all three with the fix -> 0/411, tree clean throughout. The lever is now
correct (it no longer manufactures a false compile failure) but it was ONE of three causes, not the
cause. My T59 write-up grouped them as a single ~30,000-instruction block; that grouping was WRONG,
and what disproved it was re-reading each verdict after the fix rather than re-running the batch and
reporting the total.
No src/ or config/ change: no bank, no metric move.
|
||
|
|
56e2d808ab |
feat(phase-29): T56 — wire the tu-scope lever into family_sweep; func_80144090 0/136 -> 136/136
T55's two-part next step as one job. +20,944 instructions banked. 1. THE LEVER WAS UNREACHABLE FROM THE PATH MOST FAMILIES USE (cookbook §107) §103 was wired into jtbl_family_bank only (T53), and that tool runs for has_mid_jr families. Everything else sweeps through family_sweep, which gates via PLAIN harvest_verify by design — so the lever existed, was byte-proven, and most families could not reach it. The symptom was indistinguishable from a compiler wall: func_80144090 swept 0/136 with `conflicting types for D_800A651C`. Why it does not violate the plain-harvest_verify rule: that rule exists because gate_stage's transforms PERTURB A CORRECT DRAFT (§19/T3). The tu-scope never touches the draft — it moves a DECLARATION IN THE TARGET TU. The test is not "is it a transform" but "does it change the draft?" Reused the existing undo instead of inventing one: family_sweep already snapshots TUs it edits at staging time (--normalize-self-decls) and reverts on a final MISMATCH (not byte-neutral) AND on a zero-bank group (§61 undo law — no dead diff). The tu-scope shares that dict and inherits both backstops; renamed nsd_snapshots -> tu_snapshots. Default ON with --no-tu-scope to A/B it (the T24 --allow-pins precedent): byte-neutral by construction, a no-op when nothing collides, auto-reverted when it buys nothing. 2. THE DUPLICATE-DECL REFUSAL RELAXED — AND IT DID NOT MATTER scope_tu_externs refused N>1 file-scope decls as "ambiguous"; duplicate-IDENTICAL externs are legal C, so N identical decls are one decl written N times. Now compares whitespace-collapsed forms and refuses only on genuine disagreement. MEASURED, and my hypothesis was WRONG: D_800B9A02 is 3 decls in 2 DIFFERENT forms, so it was correctly refused all along — the family banked 136/136 without it. RESULT: func_80144090 0/136 -> 136/136, 0 failed, with NO change to any draft. GATES: R22 clean-fleet 140 passed, 0 failed of 140. tools-health OK (corpus 0 PHANTOM + 0 TRUNCATED, cdecl, audit-binaries, report/lint/dedup 1886/0). 0 NON_MATCHING (G4). METRICS (reconciled against make report): instr-weighted 85.7% -> 85.8% 11258063 -> 11279007 = +20,944 ins fn-count 90.65% -> 90.69% 320656 -> 320792 = +136 distinct-code 76.4% -> 76.4% +0 (67812 unique, UNCHANGED) FLAGGING the third row rather than explaining it away: 136 banked functions moved distinct-code by ZERO, where T52's 132 moved it by +125, and both families are classed PURE. I do not have a verified cause and will not invent one — either a real property of this family or a gap in the metric. Worth one probe before that number is quoted again. |
||
|
|
55cd894024 |
perf(phase-29): family_sweep gates groups in PARALLEL by default (the SESSION-20 adapter, finally wired)
SESSION-20 measured serial family-sweep gating as "roughly an 8-16x throughput loss on a 32-thread box" and BUILT tools/sweep_parallel.py for it — but only reachable via a manual `--stage-only` two-step, so this path stayed serial and three sweeps in SESSION-22 (133 + 273 + 137 members) ran serially for no reason. §101, the stale-default class. SHAPE OF THE CHANGE — deliberately minimal after two failed attempts earlier today. A parallel PRE-PASS (phase 2a) runs only the per-group `harvest_verify` subprocess; phase 2b then consumes the results IN THE ORIGINAL SERIAL ORDER, so every line of post-processing (the MISMATCH backstop, the zero-bank restore, the counters, the prints) is untouched and output stays deterministic. No closure restructuring — that is exactly what broke it twice before. SAFETY, not a new claim: the Makefile already builds binaries concurrently (check-all/extract-all use `xargs -P$(JOBS)`, JOBS=16) and bulk_harvest's farm does the same with a per-binary lock. The §28 hazard is two makes racing on the SAME artifacts, prevented by the per-overlay lock (two splits of one overlay build the same binary and therefore serialise). NEGATIVE-CONTROLLED BOTH WAYS: `--stage-only` stages identically under -j1 and -j12 (4 groups each); a full gate returns IDENTICAL tallies (0 banked / 4 failed) parallel vs serial; tree clean after both. HONEST MEASUREMENT: on the only sample available (4 groups, and they fail FAST on a compile error rather than running full builds) parallel was 4s vs serial 6s — ~1.5x, NOT the 8-16x. That figure needs a large family (137 groups of full builds) to show, and every such family was already banked today. The wiring is proven correct here; the throughput claim remains SESSION-20's measurement, not mine. `-j 1` restores the old behaviour. |
||
|
|
ab065b1646 |
fix(phase-29): sweep pinned exemplars BY DEFAULT — the §42e guard's cause was removed in Phase 27
The guard skipped any exemplar carrying a `register __asm__("$N")` pin because templating it
cc1-CRASHED the sibling TUs (§42e). Phase 27 BYTE-PROVED that SIGABRT was `extract_unit` dropping the
body's file-scope macros — OUR bug — and fixed it (_carry_macros); its own roadmap delta then put the
PINS class "back on the mechanical-harvest table". The cause was removed and the default never
changed, so the guard kept skipping real work.
MEASURED THIS SESSION on one family: func_80175AB8 reported `skipped {'pinned-exemplar': 137}` and
then banked 133/137 the moment it was bypassed (R22 140/140). A protection whose cause is gone is not
free — it is a silent skip (R32) wearing a safety label, and the whole-binary byte-gate was always the
real arbiter here.
--allow-pins kept as an accepted no-op so existing recipes/docs keep working; --no-pins restores the
old behaviour. Negative control: --no-pins still reports `pinned-exemplar: 4`; the default stages them.
This is the THIRD stale default found today, after sweep_parallel being opt-in (8-16x throughput left
on the table) and conform_decls refusing a remedy it could perform. Same shape each time: correct when
written, cause since removed, still the default, opt-out only if you remember the flag.
|
||
|
|
5be4c21480 |
feat(phase-29): SESSION-21 — the ×138 member sweep: 274 members from 3 exemplar cracks (R22 140/140)
- family_sweep --hseq over the 3 newly-banked exemplars: BANKED 274 member-matches / 137 failed across 137 overlays, for ~0 agent tokens. Session total: 3 exemplars + 274 members = 277 fns. - THE STALE-MAP STEP, hit and handled: the first sweep returned "0 matched-exemplar families" because .run/family_hseq.json still listed the fresh cracks as draft-ov077. Regenerated (matched-sib families 60 -> 63) and the sweep found them — the documented bank-x1 -> regen -> sweep path (memory crack-wave-sweep-map-regen). - §86 REPRODUCED CLEANLY: 2 of 3 families templated ~137/137; the third failed ~137/137. Not a rate — a BIMODALITY. One probe per family, then sweep or skip; never a blended pool average. - R22 clean-fleet: extract-all 139/139, check-all 140 passed / 0 failed (second clean-tree verification this session). dedup 1886/0, C1 coverage 239,604/239,604, 0 NON_MATCHING (G4). - FLEET 81.7 -> 81.9% instr · 89.52 -> 89.60% fn-count · distinct-code 69.3% UNCHANGED — correct and expected: these are h_seq PURE propagation-class families, and SESSION-20's routing rule says propagation moves only the DISPLAY metric (members were already counted once via their exemplar). To move RE-completeness, target byte-VARIANT families. Stated plainly so the next session picks targets by the metric it means to move. - drive-by: family_sweep --help crashed (argparse %-expands help text; a literal "0%" needed "0%%"). |
||
|
|
2b38c68333 |
feat(phase-29): SESSION-21 T1-T3 — the frontier measured, the family-exemplar wave, 3 tool fixes
- T1 FRONTIER MEASURED (zero-token, R35: family map regenerated on fresh sigs first — it was stale by ~657 banked members): 36,020 stubs / 2,345,599 weighted ins remain, and only 9.0% are h_exact-FREE. PROPAGATION IS TAPPED (238 distinct classes / 3,245 instances); 22,498 distinct classes / 1,680,097 distinct ins is what is actually left. The mass is FLAT across all 139 binaries (~300-550 sub-500 stubs each) -> "pick the best overlay" is not a strategy. .run/s21_frontier.py + .run/s21_frontier.json - T2 THE AXIS IS THE FAMILY, NOT THE LOCATION: 1,342 substantial h_seq families / 1,298,135 templatable ins = 55% of ALL remaining weighted instructions. Routed by blocker: jr/§81 181 fams (33.6%) · DRAFT-with-cached-Ghidra-C 91 (28.6%) · DRAFT-modal 1,023 (27.5%) · zero-crack 45 (6.5%) · permanent walls 2 (3.9%). Live+cached+non-wall in ov_SC01_077 = 54 families / 589,502 ins, value steeply concentrated (top 24 = 96%). .run/s21_targets.py + .run/s21_targets.json + .run/s21_draft_pool.json - T3 WAVE 1 LAUNCHED: tools/workflows/family_core_wave.js (NEW) — 24 xHigh drafters, one per family exemplar, stake 575,488 templatable ins (24% of remaining). Supersedes worker_wave.js for family work: carries each target's family STAKE, encodes the four §58/§87 integration rules at source (splat D_<UPPERHEX> not Ghidra DAT_; never invent a symbol; canonical callee sigs; leave decl plumbing to the ladder), and requires symcheck.py on any claimed MATCH. - T3b LADDER HYGIENE, both SESSION-20 carry items fixed — one defect, two masks: a byte-NEUTRAL transform was left in the tree when it banked nothing. family_sweep's --normalize-self-decls backstop only fired on MISMATCH (left 123 files of dead diff on a 0/123 run); gate_stage's ARITY undo narrowed to src/shared/ and left ~40 TUs. Both now restore the full snapshot when NOTHING banked (no banks to preserve => the splice hazard cannot apply). §61 on the success path. - T3c BACKLOG addr DEFECT fixed (R32/R33): new addr_of() derives the address from `name`, assert_addr_coverage() fails loud on an unkeyable row, append_record fills both directions. Found a latent bug doing it: load_best() keyed on `addr or name`, splitting one function into two "best" records. Keyable rows 128/1,701 (7.5%) -> 1,701/1,701 (100%). |
||
|
|
f142a6858f |
feat(phase-29): ov_SC06_018 crack-wave — func_801365B8 x138 (fresh-exemplar sweep CONFIRMED), thesis is family-specific
- binary-aware crack wave (new tools/workflows/wave_binary.js): 8-target calibration over ov_SC06_018 substantial stubs, 7/8 match_one MATCH - func_801365B8 (155, reach 133): cracked FRESH in ov_SC06_018, swept 132/132 siblings via family_sweep --hseq --source ov_SC06_018 --allow-pins -- SESSION-10 refused this family 0/133 from an ov077 exemplar. THESIS CONFIRMED (fresh exemplar unlocks it). - func_80133AB0 (137, reach 137): cracked fresh + banked x1 (+ a byte-neutral s17a-1 cast reconcile of banked caller func_801343C4), but the family sweep FAILED 0/136 even from the fresh exemplar (reverted clean) -- THESIS REFUTED for this family. - FINDING (R14/R31 -> decision-log): the fresh-exemplar sweep is FAMILY-SPECIFIC, not a blanket mechanical x137. A fresh crack is necessary but not sufficient; the byte-gate arbitrates each family (~50% on this 2-family sample -> discount the ~1.5pp estimate). - tooling (R33): family_sweep --source override now searches matched_members (a fresh member leaves 'members' after a sig-regen); cdecl._depth0_spans consumes backslash line-continuations so a raw-draft #define macro no longer trips audit-cdecl. - R22 clean-fleet 140/140 byte-identical; tools-health green (dedup 1849/0, C1 234615); 0 NON_MATCHING. fleet 78.4->78.5% instr / 67.1->67.5% distinct / 88.14->88.18% fn-count. |
||
|
|
9591d61f78 |
fix(phase-29): family_sweep --hseq --source now overrides the manifest exemplar
The --hseq path templated from pick_exemplar's choice (hard-prefers ov_SC01_077), silently ignoring --source (wave-2 finding). Now when --source names a different overlay carrying a MATCHED member of a family, template from IT (self-correcting: only a non-stub source member is used; whole-binary gate stays the arbiter). The ov077-default path is unchanged (override skipped). |
||
|
|
ad11c491a5 |
feat(phase-29 decl-normalize): func_801670E4 family 4->137/137 (+133) via the 3rd §17a-1 direction
- new tools/normalize_self_decls.py — the SAME-FUNCTION decl-normalize: drop each decl of the templated fn F that the sibling TU's OWN already-banked callers declare divergently (block-scope, a different C form than the exemplar's fn-ptr cast) + cast its in-scope calls (byte-neutral §17a-1). cast_call_sites does the callee direction, reconcile_tu the data direction; this is the third: F itself. - family_sweep --normalize-self-decls: new per-sibling stage after reconcile_def_sig (edits the sibling TU file = harvest_verify's baseline, like edit_remap_sweep) + snapshot/final-SHA-MISMATCH revert backstop. - byte-proven the sole blocker was the caller-decl conflict, NOT --fix-def-sig (which renamed F's def params a0..a3 while the body used arg0..arg3 -> arg0 undeclared; R14 confound removed). 133/133 banked, 0 failed, 0 backstop fires; 0 func_801670E4 stubs remain fleet-wide. - R22 clean-fleet 140/140 byte-identical; tools-health OK (dedup 1846/0, C1 234205/234205); 0 NON_MATCHING linked (G4). fleet 74.6->74.9% instr / 59.4->60.1% distinct / 86.92->86.96% fn-count. cookbook §57. - R14: func_8016CBC0 (also stuck 137-family) has NO divergent self-decl -> type-lift-blocked, a SEPARATE lever (6-typedef cluster, like 8012956c), not this pass. Route by the real cc1 error. |
||
|
|
c916115291 |
feat(phase-29 T3): the §53 has_mid_jr INTERLOCK + worker_wave -O0 build-step fix
- family_sweep §53 INTERLOCK (the Task-3 deliverable): a has_mid_jr family CANNOT bank through the carve-less --hseq path — its exemplar's own bank needed a jump-table carve. The sweep now SKIPS them LOUDLY, names the right tool (jtbl_family_bank), and states that a 0% from this path is a TOOL ARTIFACT, not a wall. Uses the manifest's has_mid_jr (family_hseq already derived it — R33, one oracle, shared with dedup_extend; no re-derivation). --allow-jr is the escape hatch. WHY: a silent 0% from the wrong tool is exactly what manufactured the Phase-26 "structural families ≈0% / don't template" doctrine and steered two phases of strategy (§53, Phase-28 T1). The interlock makes the omission impossible to misread. VERIFIED (live-fire + negative control, R32/R35): manifest carries 11 has_mid_jr families / 163 member-slots of 1418 sweepable; --band substantial -> skips 9 families / 155 slots (159 -> 150 families); --allow-jr -> 159 (does NOT skip). It correctly flags 0x8017bebc (n=115) = B2, the very family whose missing carve produced the ≈0% doctrine (0/8 -> 102/115 once carved). - worker_wave.js: pass --o0 to the match_one self-check for -O0 targets (new `o0` target flag) + an -O0 prompt block (§18/§18-P29: the %lo-fold residual and the array-of-struct crack). Without it an agent iterates a -O0 target against an -O2 compile and can NEVER match — the same wrong-build-step trap that produced the Phase-28 "~3%" swing number (Task 1). Exercised live by func_8013C414. - byte-neutral: tooling only, no src/config touched. |
||
|
|
941cd37b19 |
feat(phase-29 T6): tiny-IMM mega-pools CRACKED +4,801 via family_sweep --fix-def-sig (fleet 70.4->71.0% instr)
- THE FIX (new): family_sweep --fix-def-sig (header_sig_map + reconcile_def_sig, 1005 mapped fns) — rewrites each member draft's DEF signature to the shared-header (engine_core.h) canonical decl. Root cause (byte-proven, R14/R35 after 3 masked-metric mis-reads): engine_core.h forward-declares the member (extern void func_8015FAAC(s32 *a0), a shared fn calls it) while family_remap copies the EXEMPLAR sig (void *a0) -> 'conflicting types' -> member TU never compiles. Invisible to standalone diff_regions/match_one (no header conflict) AND to --reconcile. Byte-neutral (ptr-type param, gate arbitrates G3/P9); one member hand-verified byte-identical first. - 0x80131eec 2331/2470 (94%) + 0x80130d0c 2470/2496 (99%) = 4,801 members banked across 405 overlay files. R22 clean-fleet 140/140 byte-identical; pure-reduction (0 new/dup stubs); dedup 1840/0; 0 NON_MATCHING (G4). Fleet instr 70.4->71.0% / distinct 52.3->53.2% / fn-count 84.94->86.30%. - CORRECTS the commit:0665 'symbol-definition gap' scout (WRONG). The 4th 'reproduce the build step' instance (§53-carve, -O0-flag, now the member's canonical DECLARATION). cookbook §54, decision-log R31. |
||
|
|
d40711fe5f |
chore(phase-26 T7): family_sweep --allow-pins flag + honest matched-sib finding
- family_sweep: --allow-pins bypasses the §42e pinned-exemplar skip (template WITH pins, byte-gate arbitrates) — added to TEST the func_8017A4AC pinned-×134 precedent. - FINDING (3 probes, all 0% banked): the matched-sib harvest is TAPPED. tiny-IMM 0/241, PURE reach-134 0/134, pinned-PURE-with-pins 0/133. The manifest's ~13,075 'templatable' member-slots are an over-prediction the whole-binary byte-gate refuses (collision/drift/ pin-crash). A3h + the wave propagations already banked everything cleanly templatable. - regenerated family-hseq.md. |
||
|
|
ed09ee749f |
feat(phase-26 T7): §52 sibling wave 2 — 3 more cores banked ×134 (402 instances)
Second cheap-Opus §52 wave over the close=0 regalloc cluster (armed with §52a):
- BANKED ×134: func_801379FC (97), func_801497A8 (47), func_801495C4 (34) —
3 exemplars + 399 members = 402 function-instances, 0 gate failures.
- 2 whole-binary-near (func_8012E138, func_8012F40C — match_one MATCH, A10 gap),
1 new wall (func_8012B4B8 — symbol-address-base wins-low-needs-high, a 3rd class).
- §52b: new verified de-pin levers (per-loop pseudos for register role-swap; the
RC-7 second-set dial to defeat rematerialization; value-barriers dissolve the
CSE-stack-address-common wall) + the new wall class + the match_one→whole-binary
gap-at-scale finding.
- TOOL FIX: family_sweep §42e pin-guard was a FALSE POSITIVE — it matched
'__asm__("$N")' inside COMMENTS that document a REMOVED pin (recovered
func_801495C4's 133 members). Now strips comments before the pin check.
- R22 clean-fleet 136/136 BYTE-IDENTICAL; dedup 1840/0.
- Wave 1+2 combined: 5 pin-free cracks -> 670 instances, from the walled flagship's idiom.
|
||
|
|
82d79e7a32 |
fix(phase-26a): A6/A7 — the family engine could not see half its corpus; 17 fns banked x134 free
R22: check-all 136 PASSED / 0 FAILED. dedup-check 1823 validated / 0 failed (C1 coverage 224,933/224,933).
Fleet instr-weighted 66.5% -> 66.7%.
=== dedup_propagate: it was blind to HALF the corpus ===
overlay_files() used a hardcoded suffix allowlist ("_a","_o0","_o0b","_after") that predated the
Phase-26 jr carves -> 404 of the fleet's 811 overlay .c. The 407-file gap held 36,135 INCLUDE_ASM stubs
and ~32,000 inline defs, and overlay_files gates ALL of dedup_propagate (source_text / find_site /
apply_plan / struct_check / reconcile_caller_extern). Now a GLOB — never an allowlist, because the NEXT
split family would re-open it. The asm_subdir is always the file stem, an invariant the old four entries
already satisfied.
find_site's def-detector required the signature line to END in ')' and the next non-blank line to START
with '{'. It therefore silently dropped THREE shapes: K&R definitions (`s32 f(arg0)` / `s32 arg0;` / `{`),
multi-line signatures, and single-line bodies. K&R is the project's house style for exactly the biggest,
highest-reach functions — func_8015AE2C (562 ins), func_80166994, func_80133CD4, func_8015A3C8 — and they
live in the _jr_* files overlay_files could not even open. Fixing either alone would have been useless:
the glob exposes the files, and find_site would still drop their biggest prizes. Both fixed together.
* The signature's closing paren is now found by a real paren-walk, not line.count() or split(')')[-1]:
a single-line body containing a call (`void f(int a){ g(a); }`) has balanced parens of its own, so
both shortcuts land on the WRONG paren and then misread the body's ';' as a prototype terminator.
* AGREEMENT ASSERTION (the audit's): find_site vs family_remap.extract_unit -> 701 agree / 0 disagree.
Negative controls hold (a prototype+call is rejected; a 1-line body with a call is a def).
=== THE HARVEST (free work, byte-gated) ===
--auto-from ov_SC01_077 now nominates what it could never see: 20 planned, 17 propagated x134, 3 dropped
as cross-overlay stragglers. 134 overlays rebuilt BYTE-IDENTICAL; 17 new dedup groups.
Includes ALL FOUR functions A1 caught the registry lying about (func_80128ED8 / 8012C098 / 8012C0EC /
8012C750): 0 stubs remaining, real shared macros. THE LOOP CLOSES — A1 found the lie, and THIS is the
bug that had made it true (3 of the 4 are defined in ov_SC01_077_jr_8012ACE0.c, which the allowlist could
not open, so the propagation never ran and dedup_integrate greenlit the result).
=== family_remap: 96 PHANTOM exemplars -> 0 ===
extract_unit globbed only src/<ov>/<ov>*.c, so a function matched via a SHARED body had no source form
and read as NOT MATCHED. 93-96 of 218 h_seq "matched" exemplars were phantom, carrying 2,157 candidate
members of which 1,834 are still-stubbed, PURE/IMM-clean, symbol_map-clean and unpinned — staged and
gated today, dropped before the first build then. It is now TOTAL over BOTH shared-body mechanisms:
(1) the DEFINE_func_<ADDR>() macro — reconstructed as the exact INVERSE of dedup_propagate.make_macro
(derived from the generator, not re-guessed from the text);
(2) a DIRECT definition in a shared header, #included per overlay — the whale (func_80144B9C, 770 ins,
-O0), which the registry explicitly records as "NOT a DEFINE_ macro".
CENSUS: 216 matched exemplars, 216 real, 0 PHANTOM.
symbol_map named the symbol by HOW IT WAS LOADED, not by WHAT IT IS: reloc_targets labels every lui/%lo
pair "data", and a FUNCTION's address taken via lui/%lo (an address-taken callback) is exactly that shape
(splat's own .s: %lo(func_8017E1D4), 7 occurrences). The map got a D_<ADDR> key while the C writes
func_<ADDR>, so the word-bounded substitution matched NOTHING and silently no-op'd — the sibling kept the
EXEMPLAR's function pointer and the loss was booked as a BYTE failure, indistinguishable from a compiler
wall. Now emits both keys (addresses are unique; the pass is simultaneous, so the extra key is free).
gather_externs was line-oriented, so a WRAPPED comma extern was invisible in both directions (the first
line has no ';', the continuation has no `extern`). ov_SC01_077.c:271-272 declares NINE symbols that way,
and the exemplar referencing them (func_8013D178) is a 133-member family — every sibling was staged with
NO declaration, failed to compile, and bisect-stormed its whole gate group. Now statement-oriented, and
an unresolved symbol is REPORTED, never silently dropped.
=== family_sweep.stub_map / build_engine_types ===
stub_map: func_-only -> a curated-name stub read as "already matched" -> phantom exemplar. Now corpus-derived.
build_engine_types hard-exited on 1,070 of 1,470 type-bearing overlay .c (73%; the audit measured 573/709
= 81% on its narrower set) because 1,929 TAGGED-struct typedefs tripped a guard whose own comment asserts
"our source has only ANONYMOUS-struct typedefs" — true in Phase 20, false since the harvest agents started
writing tagged structs. inject_capped_externs routes every type-bearing body HERE as the type-heavy tail's
ONLY sanctioned unblocker, so the tail's unblocker could not run on the corpus the tail lives in.
A contained def (the typedef's span encloses the body) is liftable — it just must not be counted twice;
only a PARTIAL overlap is malformed. Verified on a file that used to hard-exit: 5 tagged typedefs folded +
forward-declared, 46 types written, exit 0.
** AND THE SHARPEST LESSON IN THE AUDIT: this one was never silent. It printed "[overlap] ... handle
manually" every single time. But the message reads like a rare edge case rather than a four-fifths
coverage failure, so nobody ever COUNTED it. A loud failure that nobody counts is exactly as
invisible as a silent one. R32 must be "assert your coverage", not merely "fail loud". **
R14 self-catches, recorded because I hit both while fixing them: my first shared-header scan read a macro
body's `extern void f(void); \` as a DEFINITION (the trailing continuation means the line does not end in
';', so the decl guard never fired) — the exact bug fixed at commit:0552, reintroduced by me and caught only
because the whale resolved from the WRONG file. Column-0 anchoring fixes it by construction. And my
phantom census returned 0/0 twice because I guessed the manifest schema instead of reading it.
|
||
|
|
a0e7ff7f6f |
fix(phase-26): scope_data_externs ANSI-brace fix + wire §8d into family_sweep --hseq; 780-class diagnosed
- _body_open_brace only matched a `{` on its own line (the K&R shape), so fix() SILENTLY NO-OP'D on
every ANSI draft — the same silent-skip disease as the four catalogued in §40/§8d, caught because
the h_seq re-sweep banked 0/780. Now brace-scans forward from the signature (ANSI same-line,
ANSI own-line, and K&R all work). Load-bearing for func_80178D40's upcoming ×134 bank.
- family_sweep --hseq now applies the §8d scoped stage at staging time.
- HONEST RESULT: still 0/780 — the substantial-band h_seq rejections are a DIFFERENT (sibling) class,
now fully diagnosed against the bytes:
gcc-2.7.2 decl-conflict semantics: a VISIBLE file-scope decl + a conflicting later decl (file OR
block) is a HARD ERROR; a limbo-only block decl (scope closed) + a conflicting later decl is a
warning. The h_seq drafts carry the EXEMPLAR TU's spellings; sibling TUs legitimately spell the
same symbol differently (loose typing), and the visible decl is often MACRO-INJECTED — a
DEFINE_func_* leading extern (§8c), invisible to any col-0 scan (e.g. D_80115158's `short` decl
enters ov_SC01_000.c via DEFINE_func_8014168C() @4637; the draft carries ov077's
`unsigned short` -> conflicting types at ANY scope).
Sub-class (a) no-visible-decl -> §8d demotion (the jr class, proven x133). Sub-class (b) visible
decl, different spelling -> needs reconcile-to-TU-VISIBLE (rewrite the draft decl to the TU-visible
spelling + byte-neutral access cast; oracle = col-0 decls above the stub + engine_core.h macro
externs for the DEFINE_ invocations above). Parked as a designed follow-up task; the 780 members
are mechanical-recovery fodder once the tool exists.
|
||
|
|
62f9533024 |
feat(phase-26): +266 reconcile-class banks (2 no-jtbl cracks x133) + Fable5 batch-1 whole-binary findings
- +266 member-matches: func_8015CD20/func_8015C128 templated x133 via --reconcile-raw (each SHA-gated per-overlay vs config/check.<ov>.sha = byte-identical, G3). Full R22 deferred until func_80176218 releases asm/ (established per-overlay-gate + deferred-R22 pattern, as the committed 463 which R22'd 136/136). - family_sweep: --reconcile-raw now also covers draft-ov077 (unbanked) cracks (template from the RAW seed). - P9 CORRECTION + decision-log 2026-07-12: the 2 Fable5 cracks rtu_match-MATCH but FAIL the whole-binary gate (both jr-functions; rtu_match masks relocs + excludes neutralized INCLUDE_ASM rodata, so it never verifies the §8 jtbl rodata). TWO harvest gaps: §8 jtbl-rodata (blocks all jr cracks) + reconcile data-extern (D_801891B8-class, blocks ~15/21 no-jtbl triage cracks). 6 no-jtbl reconcile-clean cracks bank whole-binary (729 members). rtu_match is NOT a sufficient arbiter for jr-functions. |
||
|
|
7ccf48f2f4 |
feat(phase-26): Task-8 reconcile wiring (§41c h_seq) + 463 reconcile-class banks
- BUILT the per-sibling reconcile: family_remap.remap_hseq_body (h_seq-remap a RAW crack draft: symbol + immediate + cross-address self-rename) + family_sweep.reconcile_remap_hseq + --reconcile-raw. Per sibling, remap the RAW crack then canon_sig_reconcile against that sibling's own TU (the h_seq port of the h_norm M2 path) — because a reconciled body is TU-specific and can't template plainly (validation: 0/4). - HARVEST: the 4 triage isolation-cracks (func_80155800/80167540/801506A4/8016A73C) templated 463/0 x~133 via --reconcile-raw (0 failures). Metrics: instr 58.5->58.9%, distinct 30.9->31.1%. - each overlay SHA-gated by harvest_verify vs config/check.<ov>.sha (byte-identical = the match def, G3). FULL R22 clean-fleet DEFERRED until the concurrent Fable5 crack agents release asm/ (their m2c needs it); R22 fleet-confirm to follow post-window. - cookbook §40c (the h_seq per-sibling reconcile technique, R30). |
||
|
|
3ce81cbf56 |
feat(phase-26): task 4 — family_sweep --hseq mode (cross-address + imm templating)
- additive hseq_sweep(): consumes .run/family_hseq.json, templates each matched-exemplar family's
still-stubbed members via remap_hseq (reloc remap + imm subst + cross-address self-rename), stages
by (overlay,split), gates each group once via harvest_verify. h_norm path byte-UNTOUCHED (new --hseq
branch routes before it). Unique per-group verified-out fixes a latent multi-split overwrite.
- member pre-filter = remap_hseq refusal (STRUCT regalloc-drift / unresolved immediates).
- static pin guard: skip families whose matched exemplar carries a hard-reg pin __asm__("$N") — the
x1-only cracks (decision-log 2026-07-11: func_8016DF5C/8013D9B0/80133AB0) that cc1-crash sibling TUs;
they route to Task 7 pin-free re-crack instead of bisection-storming the gate.
- flags: --hseq[=manifest] --band --min-members --stage-only --only.
- VERIFIED (--stage-only): substantial band 29 families -> 1507 clean members staged / 267 groups,
1643 correctly skipped pinned (16/29 pinned); h_norm --only path intact; drafts byte-correct by
construction (V3 0-DIFF), type-using -> whole-TU gate (Task 5).
|
||
|
|
c62fe7f7ea |
feat(phase-25): task A giant #1 — func_80166994 (369 ins) cracked ×134 via Fable5 + the K&R s16-param idiom (§43)
- Fable5 subagent cracked func_80166994 (trail/afterimage ring recorder, 369 ins) — FULLY STRUCTURAL, zero register pins -> swept ×134 CLEAN (exemplar + 133 siblings byte-identical). R22 clean-fleet 136/136; instr-weighted 56.8% -> 57.2%; distinct-code 27.3% -> 28.2% - NEW IDIOM cookbook §43: a K&R s16-param DEFINITION dissolves the §17/§29 "narrow-param wall". On MIPS K&R promotes s16->int (ABI-identical to the canon-sig s32), body keeps the in-place sll aN,16 narrow/extend the (s16)cast form can't reproduce. void->s32 return-flip pair: split //@EDIT (self-fn, ov077-specific) + engine_core.h ec_edit ×5 (byte-neutral, callers discard) - family_sweep --edit-remap: split-edits now OPTIONAL (apply where present, never skip; the whole-binary byte-gate is the sole arbiter, G3/P9) — a sibling lacking the ov077 canon-sig decl still banks via ec_edit + body. edit-absent tracked, not skipped - R14: the prior wave's "@stuck: none — MATCH" note on func_80166994 was STALE/FALSE (re-ran DIFF 366/369). Verify a MATCH claim vs the bytes, never a stale note - structural cracks are the ×134-SAFE ones (contrast §42e pin-heavy families that cc1-SIGABRT in sibling TUs). Other 6 giants -> cheap-Opus applying §43+§31, Fable5 only on new-class evidence |
||
|
|
5fcb040dc3 |
feat(phase-25): task B — family_sweep --edit-remap; 2 array-decay families ×134 (+266 fns), 4 cc1-crash-walled
- family_sweep.py: new --edit-remap MANIFEST mode (§42e) — per family, symbol-remap the split-scope //@EDIT old||new per sibling + apply once-global engine_core.h ec_edits (byte-neutral), stage the family_remap body, gate via harvest_verify (the sole arbiter) - BANKED 266/266 (0 failed): func_80136824 + func_80136334 (array-decay ptr-flip) ×133 siblings each — full ×134. R22 clean-fleet 136/136, fleet 74.40% -> 74.48%, dedup 1813/0 - R14 FINDING (cookbook §42e addendum + decision-log): the other 4 byte-drift families (func_80133AB0 zero-reg pin, func_8016DF5C/8013D9B0 GTE-pin, func_80156044 trampoline) cc1-SIGABRT (Error 134) in the SIBLING TU — hand pins are ov077-TU-context-specific, NOT mechanically ×134-recoverable; backlogged as ×1/permuter fuel. rtu_match/match_one are blind here (neutralized/isolation compiles crash too); only make build is truth - 0 NON_MATCHING in any default build (G4) |
||
|
|
c908c3913a |
feat(phase-25): T7-M2 — 4,389 def-side-wall members swept ×134 (fleet 72.29→73.58%)
- tools/family_sweep.py --reconcile <rawdir>: the Q5-proven per-sibling path — symbol-remap the RAW exemplar draft (family_remap.symbol_map) then RE-RUN canon_sig_reconcile v3.2 against EACH sibling's own TU (block-scope-vs-ambient decisions depend on the sibling's decompile state), then the plain whole-binary byte-gate. Plain remap of the ov077-reconciled body banks 0; per-sibling reconcile banks 94% - swept the 35 M1 exemplars across 133 overlays: 4,389 / 4,655 member-remaps banked (266 per-sibling loose-typing-wall misses -> backlog); 266 overlay source files gained real C defs - fleet 72.29% -> 73.58% (+1.29%), REAL 251,804; R22 clean-fleet 136/136 byte-identical (make clean + extract-all-136 + check-all); dedup-check 1813 validated / 0 failed; 0 NON_MATCHING (G4) - cookbook §41c (the ×134 def-side-wall sweep). ~0 agent tokens (local cpp+build only) |
||
|
|
903d594728 |
feat(phase-25): T7.2 decl-reconcile — type-lift + mechanical sweep banks 1,729 (fleet 70.82%->71.32%)
- build_engine_types: --strip 4 base ov077 types + --file _after --exclude Buf (24 types) -> src/shared/engine_types.h; byte-neutral (ov077 stays d19c9580) - family_sweep --no-preclassify: match_one isolation cannot see engine_types.h (only -Iinclude), so it false-negatives type-lifted families; route remappable exemplars straight to the harvest_verify real-TU byte-gate (the sole arbiter, G3/P9) - banked 1,729 member-matches (base-type families 532 + _after-type families 1,197), byte-gated per (overlay,split) group across 133 overlays - R22 clean-fleet verify 136/136 byte-identical from a fully clean tree; dedup-check 1813 validated / 0 failed - deferred 16 families (~2,128 members) to Phase 26: _a.c PsyQ MATRIX/VECTOR shadowing + cross-TU Buf collision + _o0.c -O0 cluster (need per-type reconciliation, not mechanical) - tools: family_sweep.py --no-preclassify; build_engine_types.py --file <split.c> / --exclude <names> |
||
|
|
03601b0441 |
feat(phase-25): T7 sweep — func_80141100 banked ×134 mechanically (driver validated 133/133)
The family-sweep driver validated end-to-end: remap ov_SC01_077 exemplar -> 133 h_norm-siblings, plain harvest_verify banked 133/133 byte-identical (0 failed). func_80141100 now matched in all 134 overlays. Added a match_one pre-classify so the full sweep gates only clean drafts (type-using families -> .run/sweep_deferred.txt for the decl-reconcile pass, avoiding bisection blowup). |
||
|
|
fe216ff54a |
feat(phase-25): T7 mechanical family-sweep driver (tools/family_sweep.py)
Two-phase: for each matched ov_SC01_077 fn with unmatched same-address h_norm-siblings, remap (family_remap) to each sibling + byte-gate into that overlay. Stage all drafts per (overlay,split), gate each group once via PLAIN harvest_verify (remapped drafts need no transforms — T3). Sizing: 169 exemplars, 22,117 member-remaps, ~3.2 MB potential. Type-using families fail-compile -> logged for the decl-reconcile pass (not remap failures). |