Commit Graph

63 Commits

Author SHA1 Message Date
Drew T d9a6af0669 phase-36: S104 R22 218/218 after e6 (3 closes + 15 copies + a shared header) and the TU batches; census 4,473 / 0 unmarked (exit 0); R38 pass: 831 classes, 0 candidates (its population is spent) | 🛑 T7 RUNNING 2026-09-11 01:37:21 -06:00
Drew T 34db194a8a phase-36: S104 checkpoint refresh — R22 218/218, census 4,603 / 0 unmarked (exit 0); 32 agent closes; d20/d29 parked; d34–d38 in flight | 🛑 T7 RUNNING 2026-09-10 23:55:47 -06:00
Drew T 39d814fed2 phase-36: S104 — R22 218/218 after d21–d27; census 4,661 / 0 unmarked (exit 0); d29 parked for the structs phase (a void→s32 signature); METHOD step 15 | 🛑 T7 RUNNING 2026-09-10 23:25:28 -06:00
Drew T eadfa5977d phase-36: S104 checkpoint — d1–d19 all at 0, generators R27–R34, census 4,732 / 0 unmarked (exit 0), R22 218/218; d20–d24 in flight; METHOD step 14 | 🛑 T7 RUNNING 2026-09-10 22:51:40 -06:00
Drew T c48582300c phase-36: S104 R22 check-all 218/218 after d11–d19 + copies; census 4,753 sites, 0 unmarked, exit 0; lever_progress snapshot | 🛑 T7 RUNNING 2026-09-10 22:35:45 -06:00
Drew T 830650946c phase-36: S104 R22 check-all 218/218 after the d1–d9 + sweep banks; census 5,097 → 4,963 sites, 0 unmarked; lever_progress snapshot | 🛑 T7 RUNNING 2026-09-10 21:35:39 -06:00
Drew T b27c987ba9 phase-36: S103 ends — c51 func_8012E364 at two marked pins (134 bodies); 46 orphan markers scrubbed (one scrub false positive restored, the defect recorded); census 5,097 sites, 0 unmarked, exit 0; checkpoint final (R22 218/218) 2026-09-10 19:13:58 -06:00
Drew T 94520756e0 phase-36: the R26 regen closes 28 classes (71 bodies); c55 and c53 close five tier classes; census 5,231 sites, 0 unmarked — exit 1 on 45 orphan !FAKE markers, scrubbed next (R22 218/218) 2026-09-10 19:05:22 -06:00
Drew T baac1f851c phase-36: c56 ports the func_8013D9B0 minimum-lever text to ov_MAIN_012's 7-copy class; c54 ports func_8017B238 (8 bodies) (R22 218/218) 2026-09-10 18:48:23 -06:00
Drew T c02fc7cd55 phase-36: minimum-lever banks — func_8013D9B0 (2 marked GTE asm instead of 34 levers) and func_80140958 (2 marked levers), 266 bodies; c52 closes four ov_SC06_010 classes with the R26 alias (R22 218/218) 2026-09-10 18:44:29 -06:00
Drew T 433aa07018 phase-36: c50 closes func_80136824 with zero levers body-only (off the types-phase list, 130 bodies); c49 func_8013F350 at two marked head levers (133 bodies); delever_regen survives stale sites (R22 218/218) 2026-09-10 18:38:42 -06:00
Drew T aada3bdc2b phase-36: the first minimum-lever bank (func_80177B5C: 1 marked launder instead of 23 levers, 133 bodies); c43/c44/c45/c37 closes with their cross-address copies (delever --port-scan); generator R26 alias_repeated_addresses (known-true: c45's close from its start text) (R22 218/218) 2026-09-10 18:32:46 -06:00
Drew T 8bc06a2cb8 phase-36: T7 agent c42 — func_80186A8C and func_80182058 closed through cross-jump readings (10 bodies); related.txt requires evidence before calling a same-name body a variant (R22 218/218) 2026-09-10 18:17:41 -06:00
Drew T 54311fa359 phase-36: T7 agents c38 + c40 — func_80180EDC, func_8018431C, func_80185DD8, func_80184854 closed (30 bodies) (R22 218/218) 2026-09-10 18:11:17 -06:00
Drew T 321b540e7f phase-36: propagate ignores body-local externs (re-propagation: 97 siblings banked of 145 candidates); R19 cast-arity regen 8 classes; c39 ports two variants; c41, c34, c32 closes; related.txt lists the same function lever-free elsewhere; cc1_dumps_tu.sh -dd (R22 218/218) 2026-09-10 18:07:41 -06:00
Drew T 7d5964b279 phase-36: T7 agents c36 + c35 — four tier classes closed (func_8014305C, func_80141874, func_8017DBE4, func_80185994; 39 bodies); R19 reads the arity a call's own cast asserts (known-true: c35's close from its start text) (R22 218/218) 2026-09-10 17:49:55 -06:00
Drew T dd5e44c247 phase-36: T7 agent c33 — func_80169058 and func_80168D94 closed (per-arm call results, a load born last), 12 bodies; c31 proves func_80178970's pin irreducible in plain C (two passes each delete the copy; the milestone question raised) (R22 218/218) 2026-09-10 17:38:58 -06:00
Drew T a2a1fc1865 phase-36: re-draw c30 — func_8017B614 closed with no do-while (one pointer across both arms; struct/array spellings let sched2 restore the order), 125 bodies (R22 218/218) 2026-09-10 17:32:29 -06:00
Drew T 01f066923d phase-36: re-draw c21 — func_801397B0 closed (a do-while reference-weight wrapper, on the a4/c15 precedent), 125 bodies; c22's and c28's readings (func_8012E364 at 4, func_8013F350's head irreducible); --try parallel-safe per call with --keep (R22 218/218) 2026-09-10 17:14:30 -06:00
Drew T e984e5822f phase-36: re-draws c25 (func_80166F58, a narrowing copy) and c26 (func_80133CD4, split temps) closed, 254 bodies; tools/localalloc_sim.py (c26's local-alloc simulator, 0 mismatches over 150 blocks); propagate no longer trusts stale ledger hashes; R25 regen 3 classes; regen reports COMPILE-ERROR (14,xxx -> 13,083 sites, R22 218/218) 2026-09-10 16:58:01 -06:00
Drew T 96820256ce phase-36: re-draws c24 (func_8012956C: a phantom 4th argument + a switch) and c23 (func_80133784: the exit block inside a real loop, overturning b4's de-loop reading) closed, 252 bodies; R25 trim_arguments; argcheck reads K&R definitions (95 callees were invisible); the selftest asserts every dispatched family is registered (R22 218/218) 2026-09-10 16:45:14 -06:00
Drew T 970d88f386 phase-36: T7 agent c15 — func_80135EB0 closed (one if per case defeats jump2's cross-jump, struct-spelled stores keep the dependence; the register swap via a do-while, banked on the a4 precedent and raised with Drew), 128 bodies (R22 218/218) 2026-09-10 16:03:01 -06:00
Drew T a620e1880f phase-36: generator R24 (the addPrim copy read as a whole word, c20's move) + its regen pass (2 classes, the func_80140D68 header on 140 objects); c13's reading of func_80140958 (43 -> 4, not closed) (R22 218/218) 2026-09-10 15:57:16 -06:00
Drew T 5eb46b267f phase-36: T7 agent c20 — func_8013DD68 closed on a re-draw (the bit-field copy read as a whole word: a phantom flow-time mask reference), 128 bodies (16,273 → 16,015 sites, R22 218/218) 2026-09-10 15:49:51 -06:00
Drew T 750797a048 phase-36: T7 agent c18 — func_80176734 closed (one variable per role across blocks, s16 flag in a nested if, u8 copy), 128 bodies (R22 218/218) 2026-09-10 15:39:50 -06:00
Drew T 164825b5d8 phase-36: delever_regen — R22+R23 re-run over the whole residue closes 17 classes / 22 bodies with no agent; --try learns header TUs (24 classes had never been scorable) (17,715 → 17,692 sites, R22 218/218)
- tools/delever_regen.py: read-only pass (both starting texts, only the named families, delever_search --try --body,
  one worker per class) + --bank (re-score on the current tree, apply_body_core, propagate); dictionary + SETUP rows
- pass 1: 1169 classes in 127 s, 14 MATCH; the 25 UNSCORED read before banking: 24 were header-TU classes whose
  includer's ../shared include never resolved in --try (fixed; controlled: unchanged body 0, lever-free 32, mutated 1),
  1 a body-local #define (R22/R23 now refuse preprocessor lines); pass 2 over header TUs: 104 judged, 3 MATCH
- banked: 14/14 + 3/3 (two shared headers IDENTICAL on 141 objects each); R23 12 classes, R22 5
- check-all 218 passed 0 failed; lever_census 17,692 marked 0 UNMARKED
2026-09-10 15:36:01 -06:00
Drew T a060705725 phase-36: T7 agents c14 + c16 — func_801670E4 (all seven levers; its refuted @stuck note replaced in 136 copies) and func_8013D178 (one pointer per if-group), 261 bodies; R23 widened to one open block and now closes func_8013D178 alone; c9's reading of func_8013CF68 (38 -> 10, not closed) (18,776 → 17,715 sites, R22 218/218) 2026-09-10 15:24:01 -06:00
Drew T 6252516263 phase-36: T7 agent c11 — func_80175AB8 closed (derived-pointer reads, one temp for both $a1 values, a cast-wrapped table read), 124 bodies; cc1_dumps_tu.sh dumps .cse2 and .jump2 (R22 218/218) 2026-09-10 15:15:34 -06:00
Drew T e6a8f35052 phase-36: T7 agents c12 + c10 — the func_80148E54/D44 twins (implicit handler argument) and func_80135A4C (cross-jump tails, parameters passed through), 395 bodies; delever_pack writes related.txt (20,206 → 19,276 sites, R22 218/218)
- c12: c3's reading held on both twins — the angle as the handler's first argument + tmp reused as the later operand;
  the stale 'jalr with no args' comment corrected in the 135 files whose body now passes it
- c10: jump2 cross-jump merged two walk tails (exits now fall to the single final return), the s16 SUBREG gate, and
  func_80135480 called at its real arity; its answer was func_80135888 in another file
- delever_pack related.txt: lever-free bodies in the overlay sharing a func_/D_ symbol, ranked (known-true: top hit for
  func_80135A4C is func_80135888); METHOD_S103 +6 emitter entries; SETUP rows
- apply-body IDENTICAL x3, propagate 131/131 x2 + 133/133; check-all 218 passed 0 failed; lever_census 19,276 marked 0 UNMARKED
2026-09-10 15:03:27 -06:00
Drew T 2e61220bde phase-36: T7 wave c — seven agent closes (c4 c6 c1 c7 c3 c5 c8) + func_8017EEC0's parameter, ~1,000 bodies; generator R23; CI's verbatim_check fixed and wired into tools-health (23,988 → 20,206 sites, R22 218/218)
- closes, each --try 0 then apply-body IDENTICAL + propagate N/N 0 refused: func_80133AB0 (u16 width moves), func_80130D48
  (one call per goto-tail site), func_80135168 (reused temps split + H16 member store), func_80134A74 (widths + join
  statement in both arms), func_80148AFC (implicit handler argument + later operand), func_8015D738 (jump threading:
  re-read + a do-while on precedent, the class raised with Drew), func_80135004 (temp split + argument from its global)
- func_8017EEC0: the uninitialised a0v T4 tus10 left is the parameter (8/8, IDENTICAL)
- CI red since cb2fb5e6d: verbatim_check --strict saw the DECOMPILE-NOW row func_8017EEC0 converted; row removed (one
  row), --update keeps order + UTF-8 (proven equal to the hand fix), verbatim_check --strict now in make tools-health
- delever.split_reused_locals = family R23 (selftest + two refusals; known-true: joint split = the agents' measured 12/26)
- check-all 218 passed 0 failed (twice); lever_census 20,206 marked 0 UNMARKED; Drew: at most five concurrent agents
2026-09-10 14:56:17 -06:00
Drew T 205331765f phase-36: T7 agent c2 — func_8013D8FC closed (the walked-pointer merge), 131 bodies; harvested as generator R22 (24,119 → 23,988 sites, R22 218/218)
- agent c2 (Opus): a second pointer q = p + 5 stepped in lockstep with p kept a second biv alive (loop.c strength
  reduction, -dL 'Cannot eliminate biv'); one pointer lets combine_givs fold every field read onto one base
- bank: apply-body IDENTICAL, propagate 130/130, check-all 218 passed 0 failed, lever_census 23,988 marked 0 UNMARKED
- delever.merge_walked_pointers = family R22 (selftest + two refusal controls; known-true: the agent's start text's
  candidate is its closing body, --try score 0); leads the COUNT class after R19 in delever_search; SETUP row
- S103 opening: the method addendum .run/P36/agents/METHOD_S103.md; wave c launched (six agents); Fable out of credits,
  c5/c6 relaunched on Opus
2026-09-10 14:30:30 -06:00
Drew T 8a22254bfc phase-36: wave b close — the census and the series brought to this tree (24,119 sites, fleet 218/218) 2026-09-10 13:54:25 -06:00
Drew T d30ccc9a72 phase-36: T7 agent b8 — func_80135888, the largest class left, closed with all five levers gone (134 bodies; 24,789 → 24,119 sites, R22 218/218)
check-all: 218 passed, 0 failed of 218
  lever_census --check: 24,119 pin/asm sites, 24,119 marked !FAKE, 0 UNMARKED — OK

Three moves, each predicted from a dump before it was compiled:
- while -> a guarded do-while (29 to 22). Cross-jump (jump.c:1969 -> find_cross_jump :2371, from toplev.c:3142) had
  matched the load in front of the jump against the one in front of the bottom test and deleted three instructions; the
  guarded form makes the two tails differ.
- the duplicated pre-loop call block -> goto (22 to 6). This is an allocno_compare rank move (global.c:585-611): the
  priority is floor_log2(refs)*refs/live, reg_n_refs is loop-weighted (flow.c:2067), the in-loop copy of that call is
  worth two references, and deleting the out-of-loop copy takes exactly one off — 8 to 7 crosses a floor_log2 step and
  drops the pointer's priority from 3157.9 to 1891.9. The predicted allocation order matched the dump exactly. The
  rewrite is byte-neutral on its own: reorg steals the target's first insn into the delay slot and retargets.
- the two-arm mask temp inlined (6 to 0): set in two arms it has two deaths, fails local-alloc.c:472, and combine_regs
  bails at :1774, so it went to global allocation and took its copy preference.

Harvested as R21 second_consumer, from agents b2 and b6 together: give a computed value a second consumer before its
copy, either by chaining (v = slot = E) or by hoisting the store above it. cse deletes such a copy only when the
producer sits immediately before it (cse.c:7440-7501, guard :7454-7460), and flow links only the FIRST following use
(flow.c:2076-2091), so a store in between defeats both. R9 can never produce it — the two statements share the
identifier, so its independence guard refuses the swap. Known-true: the joint form scores 0 on b6's pre-bank text, and
the single-site forms do not, which is the third measured case this session of a joint edit no hill-climb can reach.

Also recorded from b8, worth a pre-check later: declaration-order moves are PROVABLY DEAD on a register residual whose
allocnos have distinct priorities, because global.c:604-610 compares priority first and only ties by allocno number —
4,811 compiles of those candidates sat flat because of it.
2026-09-10 13:31:47 -06:00
Drew T 0d92d10299 phase-36: T7 agent b7 — func_80166690 closed from a residual of 41 (126 bodies; 24,915 → 24,789 sites)
- the moves: retype four accumulators int -> short in ONE edit, delete the five hand temps that were spelling the
  truncation, and type the colour temp to its destination field's own width (u8). Measured A/B/C on bytes: unsigned int
  34, short 1, unsigned short 1, u8 0.
- mechanism: all four missing instructions were the same one — a move after an addiu whose result is re-read through a
  16-bit shift. A narrowing assignment expands to a mode-changing copy, and combine_regs ties source into destination
  only when the source DIES there (local-alloc.c:1855, return 0 at :1881); the wide temp is still live in the following
  sign-extended test, so the copy survives. At int the copy is same-mode, the source dies, the tie happens, and combine
  then re-selects the whole counter into the pre-shifted domain. The last instruction is cse's mode gate in insert_regs
  (cse.c:1019-1021, :1029-1032).
- it confirms R20's shape and refines it: the group retype must be keyed on the residual's missing-move SET, since R12
  is per-declarator and its single moves topped out at 24 here — a hill-climb cannot reach a four-way retype.
- delever_pack.py was missing an import for the neighbours block added an hour ago, so two packs shipped without
  neighbours.txt and both agents said so. Fixed; all 34 packs now carry it.
- method note from the agent, now in the briefs: dump the target function WHOLE off the tree's own object rather than
  reading the residual's hunks — the hunk view had scrambled two moves into branch delay slots and hid that four
  differences were one repeated shape.
2026-09-10 13:17:56 -06:00
Drew T 17d192d243 phase-36: T7 wave b — four agent closes plus the engine's own two (766 bodies; 26,074 → 24,915 sites, R22 218/218)
check-all: 218 passed, 0 failed of 218
  lever_census --check: 24,915 pin/asm sites, 24,915 marked !FAKE, 0 UNMARKED — OK

- b2 func_80162438 (127 bodies): hoist the store above the assignment and store the EXPRESSION, so the temp falls out.
  cse's 'REG0 is the cheapest' rewrite (cse.c:7440-7501, guarded :7454-7460) deletes a copy only when the insn
  immediately before it set the source; putting a USE between compute and copy defeats that and flow's LOG_LINK, which
  goes only to the first following use (flow.c:2076-2091), so combine is never offered the pair.
- b6 func_80161E08 (127 bodies): the same three blocks written as a CHAINED assignment, p = slot = base + K. The value
  gains a second consumer, flow's only link goes to the store, and the copy survives — the instruction the pin faked.
- b5 func_80145934 + its sibling func_80145A2C (126 + 126 bodies): a body-local symbol ALIAS. Cross-jump's equality test
  compares symbol names by POINTER (jump.c:2440), so two arms referencing one extern merge; an asm-label alias makes the
  identifier distinct, the blocks survive, and assemble_name strips the star so the bytes and relocations are unchanged.
  The barrier it replaces was standing in for symbol identity, not for ordering or liveness.
- the engine banked two of its own while the agents worked: R20 closed func_80139BE0 (129 bodies) by chain-narrowing —
  the body agent a14 could only reach with an INVENTED identically-zero term, which I refused. The refusal was right and
  the honest close arrived hours later from the generator.
- R19 closed func_8017A3D8's ov_SC07_006 copy (16 bodies) by restoring a dropped argument.

Two things to act on, both reported by agents:
- 'a @stuck: note claiming a lever is required should be re-tested, not trusted' — two such notes were refuted on bytes
  today ('natural C ALWAYS coalesces that copy', 'no pure-C spelling survives that fold').
- one pack lacked neighbours.txt because the packs predate that change; the next --build carries it.
2026-09-10 13:12:08 -06:00
Drew T 9d78fc4085 phase-36: T7 agent b3 — func_8016CBC0 closed from a residual of 55 (128 bodies), and its move toolified as R20
- the move: narrow every local in the counter's def-use chain together — the counter, its +/-1 temp and the copy-back —
  and do it for BOTH chains at once. Four instructions were MISSING, not miscoloured, three of them the moves the $0 pin
  was faking. insert_regs (cse.c:1029-1032, early bail :1018-1020) puts two pseudos in one equivalence class only when
  their MODES match, so an all-int copy-back is collapsed and swept, while the narrowed one is a truncation: no
  equivalence, the wide temp stays live and reaches reload as the move the target has. The fourth instruction is
  strength_reduce minting a shift giv from a wide counter whose every use is a cast; a HImode pseudo cannot be that giv.
  delever --propagate: 127 of 127 sibling(s) banked, 0 refused. 26,202 -> the census below.

- R20 narrow_chains: the agent PROVED the joint form is necessary, and the generator reproduces it. Single declarations
  scored 45/72/51/24, each chain alone 43, both chains together 0 — every intermediate worse than the search's own best
  of 11, so a beam over R12's one-declaration width moves cannot reach the answer from either side. Seven runs and 4,811
  compiles stalled at 11; R20 offers six candidates and the right one is a single compile.
- known-true check: run on b3's pre-bank text, R20's joint signed candidate scores 0 (MATCH) and its single-chain
  candidates score 43 and 51 — the agent's own hand-measured numbers, reproduced by the tool.
- chains are built conservatively from the body's text (two locals linked when one is assigned from the other, through a
  cast or a +/- constant), and only whole components are offered, so the partial narrowings the measurement showed are
  always worse are never generated. Selftest: the chain is found whole, an unlinked local is not pulled in, and a body
  with no linked pair offers nothing.
2026-09-10 12:57:06 -06:00
Drew T acba5c59df phase-36: T7 agent b1 — func_801651B8 closed on its FIRST try (127 bodies), and its lesson made part of every pack
- the move: delete the hand-walked pointer's self-increment and recompute p = &tbl[i] from the loop counter each
  iteration. The lever-free body had TWO induction variables — the loop dump says 'Cannot eliminate biv 73: biv used in
  insn 50' (loop.c:5976) because the pointer is itself a call argument — and combine_givs (loop.c:5494/:5527) then
  merged the three +12 field addresses into one giv whose benefit clears the not-worth-while gate at loop.c:3822-3828,
  reducing it to a THIRD walking register and forcing a fourth callee-saved one: the +4 instructions and the whole
  recolouring. Indexing instead leaves one biv, the +12 rides as an immediate, and the body is byte-identical.
  delever --propagate: 126 of 126 sibling(s) banked, 0 refused. 26,456 -> 26,202 sites.

- THE HEADLINE IS THE METHOD, not the crack: the answer was written in English thirty lines above, in the // @class:
  header of an already-matched sibling in the same file, which spells out 'recompute p = &D[i] each iteration (NOT p++)
  so gcc reduces base+i*0x10 into a SINGLE pointer IV'. The pack sent agents to the cookbook and to the compiler source
  and never to the target's own neighbours. This project has been leaving itself notes for months and nobody was reading
  them.
- delever_pack.py now writes PACK/neighbours.txt — the comment headers of the three matched functions either side of the
  target, plus every @class/@stuck/@crack note in the translation unit — and the brief makes reading it step 0.
2026-09-10 12:49:36 -06:00
Drew T 69d83f7b61 phase-36: 16,759 lying call declarations repaired across 3,439 units, byte-identical (R22 218/218) + the Gen3 readability series
Drew: we do want C correctness on all funcs, and log it for the story and the chart.

- decl_repair --apply rewrote 3,439 units and repaired 16,759 declarations. check-all: 218 passed, 0 failed of 218.
  lever_census --check: 26,456 pin/asm sites, 0 UNMARKED — unchanged, as expected: this pass fixed TRUTH, not levers.
- only the free set was touched: a declaration is repaired when every call to that function in the unit already passes
  the arguments, so the code was right and only the promise was wrong. Calls that pass too few remain R19's population,
  where the argument must be chosen and the bytes decide.
- tools/readability_progress.py: the Gen3 series beside docs/levers.md, because levers are only one way the source is
  untrue. It counts lying call declarations (split by the K&R-empty and (void) forms, and how many sit in a body still
  holding an argument-register pin) and raw cast dereferences against struct member reads — the struct debt. Each row
  carries its date and commit so the chart is generated, never typed (R75). docs/readability.md renders it.
  First row after the repair: 94,001 lying declarations over 1,564 callees (86,701 (), 7,300 (void)), 461 in 314 pinned
  bodies; 414,148 raw cast dereferences against 173,286 struct member reads.
- dictionary rows for decl_repair and readability_progress; kit corpus regenerated; tool_census --check OK.
2026-09-10 12:11:22 -06:00
Drew T 51028a78d3 phase-36: R19's first sweep (3 classes closed in 2 compiles each) and the declaration scan rebuilt after its control failed
search: 3 of 55 exemplars matched lever-free in 0.33 h (3 of 730 bodies behind them; 12,034 compiles) — NO-MATCH 51 · MATCH 3 · UNSCORED 1
  check-all: 218 passed, 0 failed of 218
  lever_census --check: 26,456 pin/asm sites, 26,456 marked !FAKE, 0 UNMARKED — OK

Every one of the three closes is R19 restoring a dropped call argument, each at depth 1 in two compiles — the class that
seven earlier runs and thousands of compiles could not touch.

THE DECLARATION SCAN, AND THE INSTRUMENT FAILURE IT TOOK TWO TRIES TO SEE (R39/R40):
- first framing: widen every lying declaration and leave the call sites alone. That is not a repair — a prototype
  demanding an argument the call does not pass is a hard error — so 1,766 of the first 3,250 units failed to compile BY
  CONSTRUCTION and none was identical. A measurement that cannot come out any other way is not a measurement. The tool
  now only repairs a declaration when every call to it in that unit ALREADY passes the arguments; calls that pass too
  few are R19's population, where the argument must be chosen and the bytes decide.
- second failure, worse because it looked like a finding: the corrected scan still returned 0 free of 3,634 units. The
  negative control I had not run — compile the UNCHANGED text through the same path — came back DIFFERENT by 9,176
  bytes, because the candidate is built from a scratch copy and the object records its own source filename. Comparing
  only .text/.rodata/.data removes the path, and the control then matches exactly. The control is now part of every
  unit's judgement rather than something I remember to run.
- the corrected result: 3,414 units / 16,732 declarations are FREE to repair (byte-identical with the declarations made
  honest), only 2 units / 3 declarations actually depend on the false declaration, 117 compile errors and 101 units
  whose control failed and are therefore reported as harness failures, not results.
- scope limit stated: declarations inside src/shared headers are not units with recipes and were not tested here.
2026-09-10 11:36:56 -06:00
Drew T fc7d8c4019 phase-36: T7 burst — a22 banked (126 bodies), a14 refused as an invented zero term, and the struct question answered on the record
- a22: func_8017B238 closed by giving the if-arm's pointer and the else arm's first table address one function-scope
  local. Three decisions turn on that edit, all dump-proven: make_regs_eqv's head rule (cse.c:840-857), set_preference
  stripping one RTX level so an arithmetic set inherits its operand's register (global.c:1535), and combine_regs with
  birthing_insn_p's reg_n_sets == 1 (local-alloc.c:1765-1788, sched.c:2469) — which is why the merge must be with the
  else arm's non-call-crossing temp. 26,714 -> 26,462 sites.
- a14 reaches score 0 on func_80139BE0 but only by an INVENTED identically-zero term whose sole purpose is to keep a
  value live. NOT BANKED: an invented no-op expression is a compiler-forcing construct in C clothing, and worse than the
  marked launder it replaces because the launder is counted and this would be silent. The phase's own rule is ban the
  silence, not the lever. Parked for the structs/types phase with its reading; the tree comment above it ('no pure-C
  spelling survives that fold') is refuted.
- a6 corrects cookbook 455: cse1 (cse.c:7439-7502) rewrites the producer's destination to the copy's whenever the
  producer is the immediately preceding insn; combine only finishes the job once that adjacency is broken. It enumerated
  the three lever-free blockers can_combine_p admits and showed the body can pay for none, then scanned all 4,284 built
  objects for the shape — 101 hits, every lever-free precedent paying with a genuine second use, a narrow local with two
  consumers, or a join label.
- a24's residual was one absent load: cse forwards a just-stored halfword so no lh is emitted, and seven branch
  displacement mismatches were downstream of it. Its method gap is the instrument to fix next — three agents have now
  asked for local-alloc's quantity table in the pack, and alloc_table.py prints an empty or one-row table because it
  keys on dump lines that are often absent.
- Drew's struct question answered on the record: structs are not in the binary (types are erased; no metadata in a
  retail build), what is there is base + offset + width + stride, so a struct is an inference across every function
  touching a base — which makes per-function struct invention the wrong unit and is the failure P35 already recorded.
  Recommendation: keep pins as the main lane, build a zero-token struct evidence census beside it, park stuck pins with
  their evidence, and fix call signatures first because they are the bigger and cheaper blocker (471 narrow call sites
  in 323 pinned bodies). Measured: 372,224 raw cast dereferences against 92,624 struct member accesses.
2026-09-10 11:02:14 -06:00
Drew T 3464a25cd0 phase-36: T7 burst — five more banks (631 bodies) and two concurrency defects the agents found
Banked: func_80136334 (126, all four levers), func_8016B234 (129), func_8015FBE0 (125), func_80143D28 (131),
func_8014D820 (126 of 128). 27,984 -> 26,714 sites.
  lever_census --check: 26,714 pin/asm sites, 26,714 marked !FAKE, 0 UNMARKED — OK

THE MISSING CALL ARGUMENT CLASS IS NOW CONFIRMED SIX TIMES, independently, by six agents that never saw each other's
work: a7, a8, a11, a12, a13, a25. In every case the source declares a call with fewer arguments than the callee really
takes — m2c drops arguments at unprototyped and indirect call sites — and the register pin was hired to fake the
instruction the missing argument would have produced. Mechanisms differ and were each proven on bytes: combine.c:1458's
added_sets_2 gate; set_preference (global.c:1535/1589) applied ahead of first-fit at :997-1030, the argument copy
degenerating to a self-move deleted at toplev.c:3142 / jump.c:424-443 so it costs zero instructions; and reorg.c:3374's
liveness half, where restoring the argument adds a use to CALL_INSN_FUNCTION_USAGE (reorg.c:428) so a delay-slot steal
is refused. No generator can reach any of it: every family rewrites statements and declarations, none edits a call's
argument list.

Two concurrency defects, both found by agents rather than by me:
- the includers cache wrote through a FIXED temp name, so concurrent processes clobbered each other's os.replace and the
  loser saw FileNotFoundError, which reads like a compiler crash on the candidate. Now a unique tempfile per process.
- the agent brief now mandates PACK/scratch/ for helper scripts and dumps, and says to retry once when a --try failure
  names something that is not your own text. Three agents had scripts overwritten mid-run by another agent.

One valuable negative: func_80178970 does not close, and the agent proved why by construction rather than by exhaustion
— only a call or a return writes $v0 in plain C, and a return's hard write is always emitted after its guarding branch,
so combine deletes the call-result copy (combine.c:914-917, use_crosses_set_p at :10127-10130; the SMALL_REGISTER_CLASSES
arm at :944-957 is not defined for MIPS). Its early-return rewrite still improves the source from 6 to 2 and reads
better than the pinned original.
2026-09-10 10:46:06 -06:00
Drew T c6b380fcd0 phase-36: T7 burst — 503 more bodies banked, and the per-file scratch-object collision fixed at its cause
The scorer named its scratch object after the FILE (compile_obj tag="score"), so the nine burst agents sharing one
translation unit wrote and read one object. Two reported it independently without seeing the code: spurious
COMPILE-ERRORs naming an unrelated header, and one agent scoring four candidates against another agent's function. The
tag is now per function. Every landed body was re-verified after the fix and all still score 0; the banks were never at
risk, the agents' intermediate readings were.

- banked: func_801627E8 (132), func_8017A3D8 (118), func_80141874 (119 of 125), func_801345F8 (134). 28,887 -> 27,984.
  lever_census --check: 27,984 pin/asm sites, 27,984 marked !FAKE, 0 UNMARKED — OK
- THE FINDING: the biggest lever class in this phase is a WRONG DECLARATION, not codegen. Four agents independently
  reached score 0 by restoring a call's real arity, each in a different spelling — a function-pointer cast, a widened
  block-scope prototype, a call given its argument, and a definition given its two parameters. The mechanisms differ
  (combine.c:1458's added_sets_2 gate; set_preference global.c:1589 ahead of first-fit at :1001-1015, the argument copy
  becoming a self-move deleted at toplev.c:3142 so it costs zero instructions; assign_parms' parameter home copies) but
  the class is one: a truncated (void) declaration removes an instruction the pin was then hired to fake. No generator
  can reach it — every generator rewrites statements that exist, and this changes a call's arity.
- func_80157D20 does not bank body-only (gcc rejects a block-scope redeclaration), so its Path A joins func_80136824 and
  func_80168828 as the third measured case for the types phase.
- two more new classes, byte-proven: a store sinking past a load because true_dependence's exception (sched.c:837-839)
  discards the edge, fixed by declaring the global an array and storing through [0] to set MEM_IN_STRUCT_P; and a
  post-decrement queued by expand_increment until the next sequence point, fixed by splitting the statement plus a u16
  destination cse refuses to join (cse.c:1017-1019).
- correction to record: an uninitialised register __asm__("$0") is an opaque operand, not a constant holder — R16 must
  refuse it.
- snapshot row 20.
2026-09-10 10:38:24 -06:00
Drew T fb6c857f7c phase-36: the build/ coupling fixed (a baseline snapshot the fleet gate cannot wipe) + T7 agent a4 — func_8016C49C closed by one do-while on the last statement (126 bodies)
Drew: fix the build issue so agents' effort doesn't get wiped, this needs to be parallelizable.

- every score compares a candidate with the fleet run's object under build/, and the R22 gate starts with make clean,
  which deletes exactly that. With agents scoring in parallel, a fleet gate would make every live --try compare against a
  missing or half-written baseline and report nonsense in the agent's own voice.
- fixed at the single accessor: delever_oracle.baseline_path(obj) returns the snapshot under .run/P36/delever/baseline/
  when it holds the object and falls back to build/ when it does not, so nothing silently scores against half a snapshot.
  baseline_bytes and both direct readers in delever_search.py go through it. --snapshot-baseline refreshes it:
  7,428 objects, 188 MB, taken at 9f5b22176. Valid until the fleet stops being green: the baseline is the original game's
  bytes and a bank is byte-identical by construction.
- known-true test both ways: func_800123F0 in src/800.c scores 0 MATCH with build/src/800.o present; the object was moved
  away and it scores 0 MATCH unchanged; restored.
- a4: func_8016C49C from a seed of 34 to score 0 by one move — do { param_1[1] = sVar1; } while (0); on the function's
  LAST statement. The residual was a single qsort comparison in global_alloc lost by 142 units out of 6666 (global.c:546
  sort, :587 priority, :904 first-fit). reg_n_refs is loop-weighted and computed before combine and sched, so the
  reference inside the do-while is counted twice (flow.c:434, :440-443, :2067/:2501/:2711): refs 23->24, priority
  6524->6808 > 6666, the order flips and all 34 words fall into place. A plain block at the same site still scores 34,
  which proves it is the loop notes and not the scope.
  delever --propagate: 125 of 125 sibling(s) banked, 0 refused
  lever_census --check: 28,887 pin/asm sites, 28,887 marked !FAKE, 0 UNMARKED — OK
- two instrument findings to act on: the candidate ranking buried the winning move at 438 of 439 so --cap 48 discarded it
  in six runs (~4,300 compiles), and history.txt's 'R15 sink @2777 -> 1' is not reproducible (the generator's own text
  scores 40) — to be checked against the bytes before either is trusted.
- snapshot row 19.
2026-09-10 10:30:38 -06:00
Drew T 9f5b221766 phase-36: T7 agent a7 — func_801287B8 closed lever-free: a truncated local extern was faking a $4 pin (127 bodies)
A new class, and the cheapest one found so far. ov_SC04_011.c:197 declares extern void func_8013BC7C(void); while that
function's real byte-verified definition, src/shared/ov/func_8013BC7C__8042ae05.h:3, is void func_8013BC7C(void *arg0).
The $a0 instruction the pin was forcing is the argument the TU's own declaration denies.

- the move: a block-local s32 *p = &D_801F1640; tested and passed through a function-pointer cast,
  ((void (*)(void *))func_8013BC7C)(p); — the idiom this TU already uses for two other calls. Score 0 on the first
  spelling tried, where seven mechanical runs and 4,000+ compiles had sat at 3, because every generator rewrites
  statements already present and this move adds an argument.
- mechanism, both halves proven on bytes: update_equiv_regs (local-alloc.c:947, the referenced-exactly-twice test at
  :1066, substitution at :1085-1112) — the second reference keeps the address in a register, which is what the volatile
  was faking; and combine_regs (local-alloc.c:1722, hard-reg path :1797-1818) records $4 in qty_phys_copy_sugg so
  find_free_reg (:2073, restricted at :2145-2150) colours the quantity $4, which is what the pin was faking.
  Controls: reading the global directly scores 9; declaring the pointer at function top scores 4.
- unlike agent a2's case this truncation is a LOCAL extern, so the cast keeps the bank body-only.
  delever --apply-body: ... IDENTICAL on 1 object(s) — KEPT, ledgered (rung E, a7)
  delever --propagate: 126 of 126 sibling(s) banked, 0 refused
  lever_census --check: 29,013 pin/asm sites, 29,013 marked !FAKE, 0 UNMARKED — OK
- the R22 fleet gate is deferred until the burst of 20 agents drains: make clean deletes the build/ baseline object that
  every live --try scores against. Banking and propagation only read build/, so the writing lane runs beside the agents.
- snapshot row 18.
2026-09-10 10:26:45 -06:00
Drew T c43f760fe5 phase-36: T7 s7 stopped to restore the agent cadence — 5 banks kept, 3 leftover candidates reconciled, R22 218/218
Drew, on waking: he expected dozens of agents overnight and got three. The cause is the cadence, not the agents — the loop
ran strictly serially (agent, gate, toolify, sweep) and the sweeps are hours long, so most of the night had no agent
running. His rule was one agent at a time so the methodology is honed each time one lands, not one agent per sweep.

- correction: agents run back-to-back, the next launched the moment the last lands; a sweep runs only when it does not
  stand between two agents, and never on the TU a live agent is scoring in (the scratch object is keyed by the TU).
- stopping s7 cost a lesson worth keeping: the kill landed mid-write, inflight.json was empty, and --restore refused
  loudly with instructions instead of guessing (R102). 8 dirty files: 5 the run's recorded banks, 3 with no bank; the
  fleet named exactly those 3 binaries (ov_SC03_113, ov_SC04_004, ov_SC04_011), restored from HEAD.
  check-all: 218 passed, 0 failed of 218
  lever_census --check: 29,140 pin/asm sites, 29,140 marked !FAKE, 0 UNMARKED — OK
- snapshot row 17.
2026-09-10 10:09:46 -06:00
Drew T 724c688591 phase-36: T7 sweep s6 — the last never-attempted exemplars: 25 of 337 (29,204 → 29,148 sites, R22 218/218)
search: 25 of 337 exemplars matched lever-free in 1.39 h (25 of 337 bodies behind them; 57,838 compiles) — NO-MATCH 307 · MATCH 25 · UNSTRIPPABLE 4 · UNSCORED 1

- the draw asked for 1,200 and the ledger could offer 337: s5 had taken the easy half and the never-attempted pool is now
  empty — every remaining residue class has been offered at least one shape. The yield falling from 36% to 7% on exactly
  the bodies s5's ordering left for last is what an exhausted pool looks like, not a broken instrument.
- check-all: 218 passed, 0 failed of 218
  lever_census --check: 29,148 pin/asm sites, 29,148 marked !FAKE, 0 UNMARKED — OK
- what is left and what it costs (R41): 9,010 bodies in ~1,300 classes, every one already refuted at beam 3 x depth 2 x
  cap 48. The next zero-token lever is a wider re-draw over the NO-MATCH population (--include-done, beam 4 x depth 3-4),
  the same move that took g1's 1-of-16 to g3's 13-of-64 in S101. The head's 57 classes remain the agents'.
- snapshot row 16.
2026-09-10 08:47:31 -06:00
Drew T 67e91ad4d4 phase-36: T7 sweep s5 — the TAIL closes at 36%: 285 of 800 bodies lever-free for zero tokens (29,527 → 29,204 sites, R22 218/218)
search: 285 of 800 exemplars matched lever-free in 2.32 h (285 of 800 bodies behind them; 94,627 compiles) — NO-MATCH 499 · MATCH 285 · UNSTRIPPABLE 9 · UNSCORED 7

- the first broad draw of non-head classes, at the cheap width, with the full generator set. By first move:
  R7 105, R10 59, R12 42, R6 26, R9 20, R18 13, R8 9, R3 6, R15 4, R14 1 — and 242 of the 285 closed in ONE move.
  These are not deep searches; they are bodies nobody had ever offered a single shape to. R18, one day old, is 13 of them.
- the contrast that steers the rest of T7: 36% of the tail closes mechanically, against 6 closes in ~128,000 compiles on
  the head. The head's 57 classes are the agents' work; everything else is the engine's, at zero tokens. Sweep the whole
  residue before spending another agent.
- check-all: 218 passed, 0 failed of 218
  lever_census --check: 29,204 pin/asm sites, 29,204 marked !FAKE, 0 UNMARKED — OK
- snapshot row 15.
2026-09-10 07:21:39 -06:00
Drew T 3ba4d6fec1 phase-36: T7 sweep s3b — the constant-holder draw re-run: 1 of 80 (6 bodies), BUDGET 59 of 80
search: 1 of 80 exemplars matched lever-free in 0.89 h (6 of 486 bodies behind them; 28,042 compiles) — BUDGET 59 · NO-MATCH 18 · UNSTRIPPABLE 2 · MATCH 1

- func_801621CC by R6 inline lo + R7 do-while; delever --propagate: 5 of 5 sibling(s) banked, 0 refused.
- the figure that prices the draw is BUDGET 59 of 80: three quarters of the remaining bodies exhausted 400 compiles rather
  than being refuted, so this family is sampled, not measured. s3 had already taken its cheap half (10 bodies).
- two UNSTRIPPABLE recorded by name: func_8017DC80 (a launder with 2 outputs), func_80181A4C (instruction lw has no C
  spelling in the table).
- check-all: 218 passed, 0 failed of 218
  lever_census --check: 29,527 pin/asm sites, 29,527 marked !FAKE, 0 UNMARKED — OK
- snapshot row 14. Loop economics two agents in (R41): 30,358 -> 29,527 sites, 9,747 -> 9,320 bodies; the agents' own two
  bodies account for 255 of that and their toolified moves for the other 576, at zero drafting tokens.
2026-09-10 03:44:53 -06:00
Drew T 5603a114c2 phase-36: T7 sweeps s2/s3 — the constant-holder census corrected (537 of 17,302, not 284 of 10,958) and 10 bodies closed; the propagate namespace bug fixed
- s2 (the head, with R16/R17 added): search: 0 of 140 exemplars matched lever-free in 0.24 h (0 of 7,085 bodies behind
  them; 23,689 compiles). The two new generators closed nothing on the head; recorded as measured.
- agent a2's "284 constant-holder pins of 10,958" verified against the source rather than believed (R14), and my first
  instrument was wrong (R40): asking R16 directly answered 33, because R16 only fires on a split declaration while most
  pins carry their value as an initialiser. R3 converts one form to the other, so the reachable family is R3+R16.
  Corrected, both figures derived: 537 constant-holder pin sites of 17,302, in 510 bodies (152 initialiser, 385 separate
  assignment; by register $2 282, $20 136, $3 28).
- s3 drew exactly those 99 function names and closed 10 bodies before crashing with
  AttributeError: 'Namespace' object has no attribute 'allow_residue'
  in propagate — the a2 fix read the flag off the caller's namespace and the search engine builds its own Namespace for
  that in-process call. Fixed with getattr(a, "allow_residue", False): a library must not assume its caller's namespace
  shape (R43).
- the ten banks were real, proven by gating the tree the crash left:
  check-all: 218 passed, 0 failed of 218
  lever_census --check: 29,533 pin/asm sites, 29,533 marked !FAKE, 0 UNMARKED — OK
- by first move the ten are R15 x3, R6 x4, R7 x2, R9 x1 — the draw was right about the family even though R16 did not fire.
- snapshot row 13; s3 re-runs from the top with the fix.
2026-09-10 02:49:05 -06:00
Drew T 9c5ca46a2a phase-36: T7 agent a2 — func_80168828 at score 0 with the constant-holder pin deleted (125 bodies; 29,697 → 29,572 sites, R22 218/218)
- two moves: delete `register s32 c40 __asm__("$3")` and its `c40 = 0x40;`, writing the literal at its four uses (byte-neutral
  on its own — the pin was never doing the work); then swap the adjacent `f1e = 0x40;` and `f1a = 0x10;` so the 0x10 store
  splits the run of 0x40 stores.
- the residual reads like cse/sched and the decision is local-alloc's. Dumps of the real TU in both orderings differ on one
  .lreg line — `Register 76 used 5 times across 10 insns` -> `across 14 insns`, `Register 76 in 2.` -> `in 3.` — which is
  find_free_reg's live-range scan at local-alloc.c:2109-2110: unswapped the two constants' ranges are disjoint and share $v0,
  swapped they overlap and the first takes $v1.
- the $4 pin STAYS, and not as a lever: src/shared/ov/func_801687CC.h declares extern void func_80168828(void), so the
  target's `move s1,a0` has no C source. An uninitialised local, a pointer-typed one, a split declaration and deleting it
  outright all give the identical score-25 residual; both parameter forms are hard cc1 errors against that header. This is
  the first measured pin that only a declaration fix can remove — one of the 51 conflicts P35 ledgered for the types phase.
  The engine's score-1 text is a coincidence (its andi truncates garbage in $s1 and never reads $a0); not proposed.
- instrument fixed in the same change: --propagate refused all 124 siblings because the reshape deliberately keeps a lever.
  The allowance is now derived from the exemplar's own banked text (its surviving !FAKE markers), and a sibling whose remap
  would carry more levers than the exemplar is refused by name.
  delever --propagate: 124 of 124 sibling(s) banked, 0 refused
- check-all: 218 passed, 0 failed of 218
  lever_census --check: 29,572 pin/asm sites, 29,572 marked !FAKE, 0 UNMARKED — OK
- snapshot row 12; delever --selftest OK. The toolify (R16, the constant-run split) follows.
2026-09-10 01:23:22 -06:00