- The loop: permuter (§31 schedule, 900s -j12) 5 -> 1, closing the 4-ins INSN_LUID scheduler tie the
drafting agent had swept by hand and recorded as un-steerable; read the last instruction (andi vs
addu); fixed it from the byte-verified sibling func_801778A8's pinned plain-copy idiom; permuter
again from the corrected seed (cse profile, 1800s) -> MATCH.
- The diagnosis was byte-driven, not guessed: dropping the redundant & 0xf alone COLLAPSED the copy
(100 vs 101 ins, 52 mismatched), proving the target needs a distinct PINNED register.
- GATE: harvest_verify --chunk 1 -> verified 1 / failed 0, d19c9580 BYTE-IDENTICAL; stub gone from
source (checked by grep, not the report). R22 clean-fleet: check-all 140 passed, 0 failed of 140.
- NEGATIVE recorded: the pin does NOT transfer to func_8014D820 (pinning its temp t to $v1 -> 285
mismatched, 303 vs 304 ins). Its run improved 33 -> 27 and plateaued; seed kept for ILS.
- REFUTES the .run/giants README's "pycparser/permuter CANNOT ingest it as-is": p16_permute.setup's
b64-pragma pin carrier handles it (6 pins -> 6 carriers, 0 raw __asm__, target.o built, §31 profile).
Checked against the tool, not the note (R35) — the 3rd recorded wall this session to dissolve.
- Drift-check first (R14): all preserved drafts reproduce their recorded closeness exactly (5/33/76/116).
func_801670E4 (close=16) is ALREADY BANKED fleet-wide — the README is stale; it is not work.
- 900s @ -j12: 5 -> 1. The permuter closed the 4-ins INSN_LUID scheduler tie the drafting agent had
recorded as un-steerable after sweeping all 6 assign orders + pin combos by hand.
- Last instruction (andi vs addu) diagnosed from the byte-verified sibling func_801778A8, whose
"nib = uVar1;" plain-copy idiom (both vars hard-pinned) after the identical (x << 16) >> 28 shift
pair is what materializes the addu. Dropping my redundant & 0xf alone COLLAPSES the copy (100 vs
101 ins, 52 mismatched), so the target needs a distinct pinned register. Pinning n to $a2 ->
101/101 with 6 left, class ADDRESSING [permuter] -> handed back to the permuter from the
structurally-correct seed rather than hand-designed.
- FIX: run_permuter's cleanup pkill matched EVERY concurrent run (two permuters silently killed each
other); scoped to the run's own scratch dir -> concurrent giant grinding is now safe.
The exclusion set built from the backlog alone missed .run/giants/ (false work: ~2.6M tokens of
characterized permuter-only drafts would have been re-bought); corrected to scan .run/**/func_*.c it
swept in the Ghidra-C INPUT cache (false exhaustion: 5,488 phantom attempts). Records the query that
actually answers 'is there fuel' and the structural point that high-reach fuel is CREATED by a
per-overlay Ghidra-C prefetch, not found.
- build_wave_args --min-live 100: ov_SC07_006 37 candidates / 0 fresh; ov_SC06_018 163 / 33 fresh,
all reach-1. Fleet-wide (139 binaries, 983 cached Ghidra-C): cached & live>=100 = 141 -> 111 gated,
30 with a preserved draft, 0 never attempted. Only fresh cached fuel anywhere = 40 fns at live 1-4.
- So the queue's '6 drafters -> ~3 banks x138' economics have no fuel. Fresh high-reach fuel is
CREATED by a per-overlay Ghidra-C prefetch (Task 5's greedy cover, imports 2-8 = +0.59pp), which
needs an MCP restart + Drew running /mcp (R23/R29).
- TWO selection bugs in my own filter, caught before spending: (1) the exclusion set missed
.run/giants/ (would have re-bought ~2.6M tokens of characterized permuter-only work); (2) it then
counted .run/ghidra_c/*.c -- the Ghidra INPUT -- as drafts, making every pool read 'exhausted'.
- Nothing spent; no agents launched.
- THE FREE TEST (cookbook §66): reverted func_801778A8's bank to its INCLUDE_ASM stub (stub state
rebuilds BYTE-IDENTICAL 7ca772be — a faithful revert proves itself; needs `make extract` first,
the R22 corollary) and re-banked it THROUGH recover_integration.py --commit --r22.
pass1 1/1 -> exact restore -> pass2 1/1 -> commit commit:0928 -> R22 140/140 -> report.json.
Bank confirmed from SOURCE (stub gone), never the report (§55b trap 4). EQUIVALENCE: git diff vs
the pre-revert commit = ONE blank line (mine) -> the driver reproduced SESSION-16's state exactly.
- DEFECT 1 (SAFETY, found by reading before firing): PROPAGATION is a fleet-tier write
(dedup_propagate --auto-from -> src/shared/engine_core.h + up to 138 overlay .c) that was both
UNDECLARED and the DEFAULT, so --max-tier binary still permitted the widest write in the toolchain.
assert_write_set cannot catch it (it runs before the gate; under --commit git status is clean).
FIXED up front: propagate now requires --max-tier fleet AND --r22, and is REFUSED after a
demacroize stage (those banks are x1 by construction; --auto-from would re-macroize and undo them).
Both refusals negative-control-tested, exit 1. The "standing hazard" is now a refusal.
- DEFECT 2 (METRIC): gate_stage scraped the fleet % via a progress.py label that no longer exists ->
fp=None -> 50 gate commits recorded "fleet None%". Now reads FLEET instr-weighted (legacy fallback
+ loud stderr warning if neither matches); parses 79.6.
- STALE DIGEST (R14): docs/progress.fleet.md at HEAD disagreed with HEAD's own source by 45 in the
dedup-shared column — generated during the §65g local_type trial whose edits were then reverted.
Regenerated (reproduced identically in-gate + standalone); headline %s unaffected.
- cookbook §66/§66a/§66b distilled in-session (R30); SETUP.md gains the missing recover_integration
row (R21 debt). tools-health OK: corpus 0/0, cdecl green, audit-binaries 140 citizens, lint OK,
dedup-check 1879/0. Fleet unchanged 79.6% instr / 67.7% distinct / 88.86% fn-count.
Records that recover_integration.py's SUCCESS path (pass 2, --commit, r22(), --report) has NEVER
executed -- the end-to-end run banked 0. Names the free, agent-free test that exercises it: revert one
of the 14 banks and re-bank it through the driver before pointing it at a fresh wave.
- 0 of 4 banked; reverted; make check BYTE-IDENTICAL; nothing landed.
- Ordering bug found+fixed: uniquifying the draft's type also renames it inside the draft's own
`extern <T> D_x;` decls, trading `redefinition of struct T` for `conflicting types for D_x`. With
uniquify moved BEFORE the reconcile one compiles -- and then DIFFs 48/53, because the data
reconcile's cast-at-use changes real codegen when the body depends on its own struct layout.
- func_8014C4AC: rtu MATCH but the gate returned a REAL final SHA != locked, i.e. the de-macroize edit
itself shifted a macro's OWN already-matched function. The §63 failure mode relocated somewhere the
per-binary gate catches it for free. MEASURED BOUNDARY: de-macroize is byte-neutral 14 of 15.
- Rule recorded: read the FINAL SHA, not the verified count -- `None` = no image (compile/link break),
a real hash != locked = the TU edit moved bytes. Different faults, different fixes.
- Two consecutive honest negatives (T8, T9): the EXISTING transforms stop at 14/36 (39%). §65f/§65g so
the next session does not re-buy this.
The () skip is confirmed blind to RETURN-type conflicts (func_801376E8 normalizes 0). The other two
targets produced edits that broke the build outright (final SHA None, not a byte-DIFF) -- consistent
with §57a's SURGICAL-ONLY classification: NSD edits the TU file, so a bad edit poisons the group and
cannot be bisected per-member. Reverted; make check BYTE-IDENTICAL; tree clean; nothing landed.
The self_decl_tu class stays OPEN and needs its own diagnosis session. Measured recovery holds at 14/36.
Extended, not replaced: it already owned exact snapshot/restore, split-aware grouping and the two-pass
gate-all -> restore -> re-stage-winners protocol. A new driver would be a 7th snapshot impl (R33).
- --draft-dir (repeatable): consume a WAVE dir instead of the backlog (unreliable closeness,
overlay-specific drafts). Strict ^func_[0-9A-Fa-f]{8}\.c$ filter -- the wave dirs carry scratch
(_b.c, try2.c, scratch/) and run_gate globs *.c blindly.
- --run-id: all scratch under .run/recover/<id>/, and run-local verified_out/failed_out passed into
run_gate -- closes §55b trap 4 (the accumulating .run/harvest_verified.txt phantom bank), which the
cookbook still lists as "still armed".
- --stages with the new demacroize stage; --max-tier; --r22; --probe-only; --report.
- TIERS ENFORCED not documented: stages declare T0/T1/T2, the driver MEASURES the write set
(git status before/after) and ABORTS if a stage writes outside its blast radius (§61d). A fleet-tier
stage is refused without --max-tier fleet AND --r22. Both refusals negative-control-tested.
- stub_map now derives from corpus.stubs (R33, coverage-asserting) instead of a private regex that
could silently return a short map; banked_from_source() is the sole bank oracle for reporting.
- End-to-end on the remaining 22: excluded 26 already-banked by name, demacroize ran on 12, banked 0,
restored exactly (src/ clean), 14/14 prior banks intact. A clean negative -- it does not manufacture
banks. Those 22 need normalize_self_decls / draft type-uniquify wired next.
- func_8012F40C banked (the callee-conflict variant): relaxing demacroize from "the draft's own
function" to "any decl the DRAFT declares incompatibly" reaches macros that declare a CALLEE
differently than the draft does (RotTransPers/RotTransSV). 14 banks total, R22 140/140.
- THE ONE FAILURE, kept honest: func_8012F49C was rtu-MATCH but the whole-binary gate REJECTED it.
rtu_match is relocation-masked, so a wrong call TARGET is invisible to it -- and this was a callee
case, exactly where the mask hides the error. Trust rtu MATCH for self-decl corrections, distrust it
for callee ones (§65c). Reverted its edits and re-banked only the winner rather than leave
byte-neutral churn on matched code (§57a-4).
- DISTILLED IN-SESSION (R30/R16/R31/R21): cookbook §65 + §65a-§65e (blast-radius tiers; the
de-macroize escape and the §20 refutation; the rtu-vs-gate divergence; the existing-ladder baseline;
two-oracle practice); decision-log entry with the HONEST multiple (~2.3x, not the projected 3.7x,
and it lands on distinct-code not the display number); calibration.md measured table; SETUP.md rows
for blocker_probe + demacroize PLUS the three the inventory was missing (lift_types, uniquify_type,
fix_header_decl-as-retired).
- Carried and NAMED, not dropped: 10 match_one-MATCH drafts still blocked by stacked classes, and the
11 `near` drafts which are unfinished drafts, not recovery fuel.
Every real-TU rtu_match MATCH converted to a whole-binary bank: 13/13, 0 failed.
- BANKED (all BYTE-IDENTICAL, whole-binary gate, stub-gone confirmed by grep not by report):
func_8012CC88 func_80138DE0 func_80144B14 func_80146750 func_80147364 func_8014CF04
func_8014D12C func_8014D610 func_80161374 func_8016163C func_80161774 func_80161888 func_801778A8
- Mechanism: existing draft-side transforms (cast_call_sites + reconcile_tu) then tools/demacroize.py
expands the conflicting DEFINE_func_* instantiations in the overlay's OWN TU with the self-decl
corrected to the draft's byte-true signature. Writes confined to src/ov_SC07_006/**.
- R22 clean-fleet after the batch: 140 passed, 0 failed of 140. Write-set asserted T1 (3 TU files).
- METRICS, honest: distinct-code 64,860 -> 64,873 unique fns (+13) -- the FULL credit, since
progress.py marks an h_exact class matched if ANY instance is. instr-weighted 79.6% and fn-count
88.86% are ~flat, because a de-macroized bank is x1 and cannot propagate x138. That price was
stated before the work, not after it.
- dedup-check 1879 validated / 0 failed; 0 NON_MATCHING in any default build (G4).
S0 measured all 36 stranded drafts in 9.2s, two oracles agreeing 36/36.
- POPULATION CORRECTED (R14): the audit's "~92% byte-correct" is a whole-wave figure; among the
STRANDED residue match_one says 24/36 MATCH / 11 near / 1 ERR = 67%. The 11 near are unfinished
drafts, not integration problems -- and they are exactly the ones that compile and DIFF.
- BLOCKERS (they STACK; cc1 reveals only the first): self_decl_hdr=21, callee_decl=19, data_decl=16,
self_decl_tu=5, local_type=5. Per function by MAX tier: T0=6, T1=26, not-integration=4.
- T3 BASELINE, measured free: the existing draft-side ladder clears callee_decl 19->3 and data_decl
16->0 yet converts 1 of 36 to compiling, which then DIFFs -- §61d verbatim. The wave's gate
orchestration was NOT broken; the ladder simply cannot reach this population.
- NEW tools/demacroize.py: the conflicting extern lives INSIDE a DEFINE_func_* macro BODY, so it
exists only where instantiated. Expanding those instantiations in the overlay's OWN TU, correcting
only the conflicting decl to the draft's byte-true sig (never dropping it, §57a-1), dissolves the
conflict with nothing written outside src/ov_SC07_006/. This is §63's own unexplored
"per-overlay-local decl" -- and it refutes §20's "the DEF-conflict class is byte-proven
unrecoverable by text transform" for the per-overlay case.
- MEASURED on the 14 clean candidates: 13 MATCH / 1 DIFF in the real TU.
- END-TO-END: func_8012CC88 banked whole-binary BYTE-IDENTICAL (stub gone per grep, not per report);
R22 clean-fleet 140 passed / 0 failed of 140 -> the T1 blast-radius claim validated empirically
(the difference from fix_header_decl, which broke 139/140 from the same per-binary green light).
- GATE A: 32/36 real decl errors (>=12) and 13/36 rtu-MATCH simulated (>=12). PASS.
Price stated honestly: a de-macroized bank is x1 -- full distinct-code credit, ~1/138 of instr.
Task 16 (the integration-recovery pass) T1. The SESSION-15 audit measured the wave bottleneck as
INTEGRATION (~92% of drafts byte-correct, ~27% bank); 36 stranded byte-correct reach-138 drafts are
the fuel. Before building any recovery, measure the REAL blocker per draft.
- tools/rtu_match.py: --stderr-out (atexit flush, covers every sys.exit path) + \n in //@EDIT
replacements (T6 needs a multi-line macro expansion). The inline tail is truncated and these TUs
emit hundreds of benign warnings -- on the first real run it was 100% warnings while the actual
errors sat ~180 lines earlier (the §58 red-herring, one level down).
- tools/blocker_probe.py (NEW, read-only, two oracles R34): static (cdecl.compatible -- never text
equality, which is what made the deleted scanner report u8-vs-unsigned-char as a conflict) and
real cc1 via rtu_match (ONE compile implementation, R33). Leads with the DISAGREEMENT table.
- DELETED .run/diag_plumbing.py (R3 tooling under tools/; R33 net -1 scanner).
- Two build-forced corrections: (1) cdecl.tu_scope runs real cpp, so it already expands instantiated
DEFINE_func_* macros -- the macro scan's job is ATTRIBUTION (tu-text vs shared-header macro body:
different transforms, same T1 tier), byte-checked against engine_core.h:7533 for func_80161374;
(2) blockers STACK and cc1 reveals only the first, so a function's tier is the MAX over blockers.
- Smoke test 3 fns: oracles agree 3/3. src/ untouched (write-set asserted). Not yet population
evidence -- that is T2 / KILL GATE A.
The near-miss ledger (.run/backlog.jsonl) is append-only, so it filled with already-banked noise:
6,867 rows, ~98% banked. load_best()/render() already filtered on READ (docs/backlog.md was correct),
but the raw log drifted stale and every render re-scanned all 6,867 rows against the stub oracle.
- backlog.py: new `prune` subcommand — atomic rewrite (temp + os.replace) to load_best()'s output
(drop-now-matched P9 + best-per-addr collapse). Idempotent. 6,867 -> 1,704 open near-misses.
- Makefile: `backlog.py prune` wired into `make report` (BINARY=main block) so the ledger tracks
reality every cycle instead of drifting.
- Finding (Drew's question): crack waves DO log every non-byte-match to the backlog durably
(gate_stage copies best_draft -> .run/backlog_drafts/). BUT the `closeness` field is UNRELIABLE —
byte-correct drafts (match_one MATCH) are logged with closeness>0 (e.g. func_8012F49C logged 29,
actually MATCH). And a reach-N function's draft is overlay-SPECIFIC (per-location symbols), so the
backlog is a messy recovery source vs the fresh per-wave stranded drafts. Integration-recovery
should consume the fresh wave-dir strandeds, not re-derive from the backlog.
- 5 of the 6 s15 fresh cores propagated ×138 (func_801483E8/8014680C/8017129C/80177AD4/801759D8;
func_8014A51C §20-capped). R22 clean-fleet 140/140. fn-count 88.66->88.86%, instr 79.4->79.6%,
distinct-code count 64854->64860, dedup 1879/0.
- EFFICIENCY AUDIT (decision-log): the 2 LLM waves ran 92% match_one MATCH but only ~27% whole-binary
bank; 6 spot-checked non-banks are ALL match_one MATCH (byte-correct bodies). NOT a missing idiom —
an INTEGRATION wall (def-side sig / data-extern / unshared struct). We strand ~16 paid-for correct
functions per wave; a fleet-safe integration-recovery pass would ~3.7× yield for 0 new drafting
tokens. Next investment = integration tooling, not more drafting. Waves held per Drew.
wave_binary over 24 fresh reach-138 ov_SC07_006 families -> 22 match_one MATCH / 2 near.
Whole-binary byte-gate banked 6: func_8014A51C func_801483E8 func_8014680C func_8017129C
func_80177AD4 func_801759D8. R22 clean-fleet 140/140 (engine_core.h reconcile edits verified
fleet-wide, §61).
- The s15 drafter-prompt fix HELD AT SCALE: all 24 winners persisted to the canonical path
(vs s14's 3/24, recovered from transcripts). match_one isolation (per-pid --work) confirmed.
- Consistent integration ceiling: ~22 match_one MATCH -> 6 whole-binary banks (27%), same as s14.
The 16 nears are def-side plumbing / data-extern / struct-def reconcile the gate ladder doesn't
clear; fix_header_decl is off-limits (fleet-blind, §63 UPDATE). Integration recovery is the lever
to improve before the next batch, NOT the drafter prompt.
- 6 genuinely-unmatched cores -> distinct-code movers (propagation follows).
The grinder ran the targeted permuter sweep to EXHAUSTION (all 75 permuter-shaped candidates;
correctly skipped 1575 redraft/structural/integration). It banked 29 distinct functions autonomously
(gate_stage commit=True, byte-gated, fail-closed, §55b un-propagated), 39% conversion.
- All 29 are LOW-REACH (1-5) overlay-unique code in the 0x8017-0x8018 range — confirming the map's
finding that the permuter-admissible set is the low-leverage tail (the high-reach near-misses like
func_8014F3E8 close=1 reach=134 are redraft/structural, NOT permuter-shaped).
- Propagation of the 22 reach>1 banks filled only 1 (0x80180710 ×2); the rest are genuinely
overlay-unique (siblings byte-diverge) — as predicted.
- R22 clean-fleet 140/140 (the 27 overnight per-binary-gated commits verified fleet-wide, §61).
- distinct-code 64837 -> 64854 (+17 unique fns); session total +22 unique (wave +5, permuter +17) —
the first real distinct-code progress in many sessions. instr 79.4%, fn-count 88.66%, dedup 1874/0.