aprop_autodraft: where the seed carries no decl, infer a minimal extern from the MEMBER'S OWN
target .s (decl_from_use, negative-controlled 97.4%/4,702) and place it at BLOCK scope via
insert_decls — file scope collides with the fleet's per-function loose-typing (the ov_SC04_018
lesson). Strictly additive: runs only where the old path refused; genuine refusals keep the old
behaviour with the class named.
integration_resolver: (1) a CC1/CPP verdict is billed to the DRAFT only after the split TU passes
a TU-alone compile probe WITHOUT the draft — else TU-BROKEN, no demotion, auto-reopened when the
TU's hash changes (S61: one broken TU was billed to 39 drafts; one-off sweep over the CC1 stock:
1 broken TU of 55, 39 verdicts reclassified). (2) dup-def→extern demotion: a draft that DEFINES
data a still-stubbed sibling .s in the same TU also emits dies at the assembler with 'symbol
already defined' — invisible to rtu (INCLUDE_ASM neutralized). Single-line file-scope defs whose
symbol a sibling .s emits are demoted to extern as an ADDITIONAL candidate (new sha, so the
ledger's unchanged-skip does not hide it). Smoke test: md_MAIN_003/func_800D3204 demoted
D_800D3200 → rtu MATCH (12 ins); the whole-binary SHA remains the sole arbiter.
42-case first run: 39 were one uncompilable TU (ov_SC04_018_jr_8017AE2C.c), not draft defects —
the resolver's 'undeclared' classification needs a TU-alone compile probe first (open follow-up).
gate_stage: a binary on .run/baseline_red.txt (+ fleet_red.txt) refuses its drafts with class
BASELINE-RED before any build — a RED binary rejects every draft gated against it, and 174 of the
resolver's 245 doubly-verified drafts were refused exactly that way (negative-controlled both
directions: RED refused without a build, GREEN still reaches the ladder).
jtbl_pads_fix: (1) OBJ_ERR required the make bracket to start with build/src but make prints
[Makefile:687: build/src/...] — find_drift returned None over failing builds ('no pad-count drift',
six binaries); (2) only the 'consumed N but M' phrasing was handled — the 'more rodata .align
directives than pad specs' direction (a NEW table from a banked switch) now searches declared+1/+2;
(3) write_pads split its line on ':' but ':=' contains a colon, appending a second ': JTBL_PADS'
per write, and wrote via a raw truncating open() — the fifth un-converted mk write site; now
path-split-once + mk_write.
mk_write: refuses a parse-poisoned registry line (R43) — one such line kills EVERY build of EVERY
binary at make parse time, strictly worse than the wipes the line-count floor guards.
rtu_shadow: a 0-bank wave has no commit — gatedness now comes from the ox ledger; baseline-RED
binaries are excluded from the prediction metrics with their count reported (R41).
integration_resolver: stub_removals() nets out carve moves (72 gross -> 63 real in the first pass).
tools/rtu_shadow.py: --wave X records rtu_match's verdict for every draft of a not-yet-gated wave
(mapped to its binary through the SHARD's targets file, never by bare name — 54 of wave fa's 470
cards share a name across binaries); --join X after the gate commit prints rtu-verdict x outcome,
P(bank | rtu MATCH), the false-negative rate and current-vs-inverted build counts (R41 denominators).
build_wave_atlas: a (binary, fn) whose latest resolver verdict is STAGED/BANKED/GATE-REJECTED is not
drawn — its body already matches at the real TU and on symbols; DIFF/CC1 verdicts stay drawable
with the CURRENT closeness the resolver demoted them to.
frontier-analysis-s60 §4 measured that ~571 open functions had FINISHED drafting (closeness-0 backlog
rows / reloc shape-MATCH rejects) and were being re-drafted wave after wave. tools/integration_resolver.py
treats those ledgers as an index: still-open? -> rtu_match at the real split TU (CC1: the gate ladder's
draft-side transforms, one retry) -> reloc_identity as the disagreeing oracle (rtu masks reloc fields)
-> aprop_symfix on MISMATCH/shape-MATCH -> stage -> sweep_parallel (whole-binary SHA, sole arbiter)
-> commit at once (R42). Refuses main by name (gate_main owns it), //@EDIT drafts, dirty trees, collapsed
registries; every drop is counted (R32); a negative control over recently-banked functions must pass
N/N before any verdict is trusted (R35/R39 — its first form picked carve moves as banks, 9/12 FAIL,
and was fixed before a single stock verdict was read). Ledger .run/resolver/verdicts.jsonl keyed by
(binary, fn, draft-sha, split-TU-sha) so unchanged rejects are never re-judged.
First pass (commit:2991): 1,352 nominated -> 901 already banked, 27 main -> 424 judged in 41 s ->
245 staged (57.8%; 242 raw, 3 via transforms) -> 63 banked (net INCLUDE_ASM delta; that commit's
subject says 72 = gross incl. 9 carve moves), 182 gate-refused, zero model tokens, ~10 min total.
Lane wrapper tools/lanes/resolver_lane.sh (holds .run/auto/draw.lock for judge+gate: rtu reads the
TUs a gate splices into).
campaign_status: 'today: N banked' summed '— N banked' commit subjects and missed every bank that
rode in a chore/maint commit (S60: 2,185 reported vs 2,644 net stubs removed); it now derives the
number from INCLUDE_ASM stub counts at last-commit-before-midnight / HEAD / working tree (R33), and
alive() is anchored so pgrep no longer matches its own wrapper (every lane read ok with 0 processes).
ox_campaign gater: the ledger's wall_min counts drafting + queue wait since the ready marker's t0;
gate_min is the gate alone (the '30-67 min gates' picture was this conflation).
maintenance lane: the fleet R22 sweep skipped whenever any gate was in flight, i.e. always (last
real sweep 12:54 08-25); it now takes .run/auto/draw.lock and waits its turn, skipping only for gate_main.
Every campaign process stopped deliberately at session end (0 alive, verified after settling).
.run/ox_campaign.stop and .run/auto/STOP are SET — delete both before relaunching, or every lane
exits immediately.
One dirty overlay TU left by a killed gate was BUILD-VERIFIED as an abandoned substitution (the
binary failed to build with it) and reverted rather than committed — R42's distinction between a
proven bank and mid-gate residue, decided by the bytes.
Two shutdown hazards recorded: pkill on a lane's shell leaves its python running (hit the
drafter, gater and main lane tonight — kill by PID, verify with ps -o lstart), and a bash case
pattern 'src/[a-z0-9_]*.c' matches ACROSS SLASHES, which classified an overlay TU as a main TU
and nearly reverted the wrong file.
Also committing the two lanes built today: tools/lanes/elastic.sh (starts serial idiom lanes when
the API window is idle and the gate queue is deep — it scales the work that is NOT gate-bound,
because adding drafters to a full gate queue makes the backlog worse) and
tools/lanes/grinder_lane.sh (runs tools/grinder.py, the Phase-21 LLM-free permuter, which had
never been run this campaign against 5,388 near-miss rows).
THE GATE WAS A BLACK BOX. sweep_parallel's stdout was captured and dropped, so a gate logged
"reloc_identity -> gating 216" and then THIRTY MINUTES OF SILENCE before its bank line — no
worker count, no per-binary progress, no phase-A/phase-B split. Gate times went 31 -> 37 ->
50 -> 67 min across ej/ek/en/eo with nothing to diagnose from, and I twice asserted things
about phase B that the log could not support (its absence measured LOG CAPTURE, not
behaviour). A lane that must run unattended has to leave evidence.
MEASURED WHILE DIAGNOSING, and it rules out the obvious suspects: load average 2.6 on 32
cores with 1-3 concurrent builds during a gate — the gate is NOT CPU-bound and is not
saturating its own -j 24. Raising to 32 is cheap given ~8% utilisation, but the real answer
will come from the log this change adds.
TAIL_DONE_FRAC 0.85 -> 0.80. 0.85 overcorrected: the fleet fell to 15 agents / 11 req/min
because the drafter parks between waves while the gater drains a deep queue. 0.75 was too
deep (26% 429s, draft completion sliding 94->91->73->47% across eq/er/es/et). Neither number
is really the lever: the drafter cannot start a wave the gater has no room for, so the gate
throughput is what bounds the campaign now.
Generational tiering confirmed already correct: the top-off orders by generation at both
assembly levels (group ranking and within-group) without FILTERING any tier out, so every
generation stays eligible and the scarce never-drafted work simply goes first.
A distill reviewer reported "match_one resolves targets by bare symbol name, not
(binary, address)" from 6+ observed target-confusion instances. VERIFIED AND THE CLAIM DOES
NOT HOLD as stated: match_one resolves '%s/%s.s' % (asm_subdir, fn) — an explicit path — and
the drafting path is safe because api_draft.match_one() always passes
dirname(card['asm']). The 675 "match_one MATCH but the whole-binary gate rejected" rows today
keep their real explanation: they landed in the window when config/overlays.mk was empty and
NOTHING could build.
The narrower hazard behind the report is real. --asm-subdir defaults to
asm/resident/nonmatchings/resident, function names are ADDRESS-DERIVED, and overlays share
the address space — so the same name is routinely a DIFFERENT function in another binary
(§238 homonym trap). Any caller that omits the flag gets a confident verdict about the wrong
target, and the failure is silent because the file exists.
It now warns loudly on stderr when the default is used, naming the fn and the directory, and
stays silent when the flag is passed (controlled both ways). A warning rather than a refusal:
resident-era callers legitimately rely on the default, and R43's "refuse what you cannot
handle" does not apply to a tool that CAN handle the input — it applies to one that cannot
tell whether the input is what the caller meant.
ROOT CAUSE of both wipes today. config/overlays.mk was rewritten in four places with
open(mk, "w").write(txt)
(jr_isolate_all.py:593, jtbl_carve.py:1077/1118/1165) — which TRUNCATES to zero first and only
then writes. Three ways that loses the registry: the process dies between truncate and write
(empty file); another process reads inside that window (sees an empty registry); two writers
interleave (a partial line lands after the last good one — this morning's file ended in a stray
`uto.txt` fragment, exactly that fingerprint). The jtbl carve automation runs AT THE GATE, which
is when all three wipes happened, and ONE_PER_GID=0 made it far likelier by putting many more
carve members in every wave.
BLAST RADIUS, measured twice: with no binaries registered, main's object glob sweeps every
overlay's nonmatchings/*.s into MAIN's OBJS and assembles them standalone, so main cannot build,
the main lane correctly refuses against a RED baseline, and every overlay gate rejects every
draft. Waves dn/do banked 0/224 and 0/236; waves ei..em banked 2 of ~1,100 with 675 backlog rows
reading "match_one MATCH but the whole-binary gate rejected" — the local oracle proving the
drafts were byte-correct while the tree could not build them.
tools/mk_write.py is now the only writer: atomic (tmp + fsync + os.replace, so no reader ever
sees a partial file and a crash leaves the original intact), collapse-refusing (a rewrite below
80% of the current line count raises), and flock-serialized.
TWO HONEST LIMITS, recorded rather than papered over:
* Callers still READ outside the lock, so two concurrent carves can each read-edit-write and
the second drops the first's line. That is a LOST UPDATE — a missing line, not a wiped file —
caught downstream by the fleet check and jtbl_pads_fix. Closing it means holding the lock
across read-modify-write in every caller.
* The guard now also refuses when the CURRENT file is under 100 lines. That case cost me
directly: my own verification control overwrote a registry a carve had truncated seconds
earlier, because the collapse check was skipped when the old file was empty. A control must
assert its precondition; mine did not, and now the tool enforces it instead.
Two ways to spend a free drafting window on a tail that is 92% walls.
ONE_PER_GID=0 — the sibling collapse exists because a same-gid sibling banks by mechanical
remap once its exemplar cracks, so drafting it pays for what the remap does free. That prices
AGENT TOKENS as the scarce resource. On the free ox window they are not, and the collapse is
what makes 3,271 open crackable functions look like 334 drawable skeletons — of which 308 are
gen6+ walls whose exemplars have already refused six waves each. A sibling drafted directly
can crack on its OWN terms instead of waiting on an exemplar that never will.
Measured on a live draw rather than argued:
uncollapsed 627 cards / 44,403 ins / 160 binaries / 215 gate groups = 2.9 drafts per rebuild
collapsed 334 cards / 30,926 ins / 104 binaries / 127 gate groups = 2.6 drafts per rebuild
The gate cost is per (binary, TU) group and chunked, so siblings landing in binaries the wave
already touches are close to free at the gate — the card count nearly doubles and the gate gets
MORE efficient per build, not less.
ATTEMPTS=K — K independent shots at each card. The gate cost does not multiply: reloc_filter
keys by fn and staging writes <binary>/<fn>.c, so a function still gets exactly one whole-binary
build per wave; the attempts compete to BE that build, ranked by match_one, which is local and
needs no build. Alternates stay on disk for a later recovery pass. Default 1 (no-op).
A BUG I CAUGHT IN MY OWN SELECTOR before it shipped: it passed binof[fn] (a BINARY NAME) where
match_one wants --asm-subdir (an asm DIRECTORY). Every attempt would have scored identically at
infinity and the picker would have silently degraded to first-seen while appearing to rank —
the same "true number about the wrong thing" class as the day's other defects. Fixed with a
subof map, and a missing subdir now returns neutral instead of a fake score.
idiom_serial passed `--cards .run/aprop_cards.json` to api_agent. That file is a FAMILY-card
file — rows are {family, members, seed, cls, reach}, with no per-function key — while
api_agent's --cards wants per-function wave cards and built its map with `c['fn']`. Result:
KeyError at line 647, the agent died before its first turn, and every target logged
"no-draft". The lane read as a model failure; its ledger holds 8 rows total and the tells
lane had, literally, "never yet run".
TWO FIXES, one on each side of the contract:
* api_agent REFUSES, never crashes (R43). It accepts 'fn' or 'name', skips rows with
neither, and says how many it skipped. The R32 warning two lines below — "ZERO matched —
wrong card file?" — existed to catch exactly this and was unreachable behind the crash. A
guard downstream of the failure is not a guard.
* idiom_serial passes no --cards at all. Its fuel is the --brief: the target plus every
idiom distilled so far in the run, which IS the compounding channel the 2,000-way fan-out
lacks. It never needed a wave card.
Verified: the lane now reaches `api_agent: stealth/ox-alpha -> 1 target(s), max 60 turns` and
drafts, instead of exiting in 0.1 s.
The serial lane's first-ever run on tells died 0 seconds in, on both counts:
[1/6] func_8017D1C0 @ ov_SC06_027 · 118 ins -> drafting
[2/6] func_8001382C @ main · 103 ins -> could not commit — refusing on a dirty tree
MAIN IS NOT A SERIAL-LANE TARGET. main gates through gate_main on the main lane's own cadence
(a clean whole-EXE rebuild with bisection), so this lane cannot bank it however good the draft
is — a main target burns a slot to learn that. md_* was already excluded for jtbl; main never
was, because the lane predates main being in the atlas at all.
A CONTENDED INDEX IS NOT A DIRTY TREE. Six campaign lanes plus the re-gate runner commit
continuously, so `git commit` here loses the index.lock race routinely — twice today it was a
STALE lock blocking every lane for 8 and 21 minutes. The lane refused over a tree that was
fine. It now retries the commit six times at 5 s before concluding, and the refusal is
reserved for FOREIGN DIRT it must not adopt — which is the property that rule was protecting.
Verified: pick_targets('extend-tell', 8, 80) now returns 8 overlay targets, no main.
Also in this commit: MAX_BINS 160 -> 50 in the drafter shell. Wave size was the right lever at
50% conversion (dd: 217 banked of 422 gated in 39 min); at 5% it is dead weight — dq banked 8
of 167 gated and took 98 MINUTES, while four drafted waves queued and the free-ox fleet sat at
14 agents / 10 req/min. At this conversion a 150-card wave banks what a 430-card wave banks,
in a third of the gate.
A tell-lever card named a lever and then made the agent go find its sites: it said
"extend-tell" and nothing about where or how many. atlas_features already counts the
detectors per function into .run/feat.<bin>.jsonl at atlas time, so this is a JOIN, not a
computation — one dict load per binary in the wave.
build_wave_atlas attaches 'tells' {extpair, dupselect, magic_div, sign_lh, sign_lb} to every
card that has a nonzero one — not just tell-lever cards, because a sll/sra pair site or a
repeated select is worth knowing whatever lever drew the card. Measured on a live draw: 85 of
185 cards carry counts.
api_agent._fuel renders them as a CHECKLIST rather than a hint, which is the point: the
counts come from the TARGET's own bytes, so a draft emitting fewer has provably missed sites
and should go looking before spending a turn elsewhere.
Verified: a card with {extpair 3, dupselect 2, sign_lh 1} renders all three with the zero
fields omitted; NEGATIVE CONTROL — a card with no tells renders no TELLS line at all.
Takes effect on the next draw + the next shard (api_agent is spawned per draft).
Neither extreme was right. Ignoring generations lets a card that has failed five waves
compete with one nobody has ever drafted; filtering to a single generation starved the fleet
to 46 cards. So generation becomes the PRIMARY ORDERING and the existing mass/count criterion
breaks ties, at both levels of the assembly:
* gate groups holding never-drafted cards rank ahead of all-retry groups (before the
--max-bins truncation, so an untouched group is never cut for a fat retry group);
* within a group, untouched cards are taken before retries.
Wave SIZE is untouched — only the order changes — so the fleet stays full while the scarce
never-drafted work always goes out first.
Verified on a live draw: gen0 2 · gen1 2 · gen2 14 · gen3 2 · gen4 3 · gen5+ 340. It took
EVERY card below generation 5 (all 23 available) and filled the remaining 340 slots from the
5+ pile, which is the whole point.
The gen0 count is 2 because wave dw drew the last 51 untouched skeletons an hour ago. That is
the campaign's real state: essentially everything drawable has now been drafted at least
once, and ~635 distinct skeletons have refused. The remaining work is levers, not draws.
--generational (or BFM_GENERATIONAL=1) draws ONLY the lowest generation present: no function
gets a 2nd draft while any drawable function still lacks a 1st. draw_count is derived from
the prior wave card files already being read for the already-waved filter.
MEASURED BEFORE SHIPPING, and it changed the plan. With every cap opened — no band, no
--max-bins, all levers, whole fleet minus main — generation 0 is:
232 candidates -> 46 distinct skeletons (186 are same-gid siblings the remap banks free)
against ~681 drawable skeletons in total. So "3,926 never-drafted stubs" was three illusions
stacked: ~961 are main's LINKED PsyQ stubs and data blobs (not decomp targets at all), most of
the rest are same-gid siblings that one exemplar banks mechanically, and 2,119 were already
drawn in earlier waves. Making generational the DEFAULT starved the fleet from ~640 cards to
46 — so it is opt-in, for a priority pass over the untouched population, not standing policy.
The real shape of the endgame, stated plainly: of ~681 distinct drawable skeletons, only 46
have never been drafted. The other ~635 refused at least one draft each. That is a LEVER
problem — distillation, A-prop, the o0/jtbl carves, the permuter — not a resampling problem,
and no amount of drafting throughput addresses it.
Fired as wave dw (51 cards / 1,990 ins across 36 binaries) so the untouched population is
drafted today rather than left as a policy.
The gate's dirty-tree committer swept an empty config/overlays.mk into commit:2863 and took
the whole fleet down with it. R42 says commit a dirty tree rather than revert — true for
src/, where a per-binary gate leaves PROVEN banks uncommitted and reverting destroys them.
A config file is the opposite case: it holds no proven state that exists only in the
worktree, and a collapsed one is never intended.
config_sane() runs at all three commit sites: if config/overlays.mk or config/dedup.us.yaml
has fewer than 80% of HEAD's lines, it is restored from HEAD, NOT committed, and the refusal
is logged loudly. Controls both ways — positive (min_ratio=1.5 makes the healthy registry
trip the same branch: detected, restore path runs, file intact) and negative (normal
threshold: silent, returns True). P28's registry died this way too (H5); now it is enforced
rather than remembered.
THE CLASS. JTBL_PADS is a per-object spec written by jtbl_carve at CARVE time — one entry
per rodata `.align 3`, each 0 or 4 — describing how many jump tables the object emits. That
is a DERIVED property of the current source stored as static config, so any bank carrying a
`switch` (or any bank being reverted) invalidates it and nothing re-derives it. Three of the
five REDs on 08-25 were this one design choice: ov_SC02_005 and ov_SC07_006 from wave dd
banking switch-bearing functions, ov_SC04_018 from the identical symptom with the opposite
cause — a reverted bank taking its table with it.
WHY NOT DERIVE IT. The COUNT is derivable from the assembly stream; the VALUES are not — a
pad records where the ORIGINAL image has an inter-table pad, which lives in the retail
layout, not in our source. Guessing shifts every downstream data symbol: silent corruption,
the worst outcome available. So tools/jtbl_pads_fix.py does not derive. It ENUMERATES the
2^(N-1) candidate specs (first entry 0, rest in {0,4}) and accepts one ONLY if it is the
UNIQUE candidate that rebuilds the binary byte-identical to config/check.<bin>.sha; zero or
two matches restore the original and refuse. R39 negative control: on a healthy binary it
reports "no pad-count drift" and changes nothing.
TWO INSTRUMENT BUGS THIS TOOL FOUND IN ITSELF:
* JTBL_PADS is a target-specific MAKE VARIABLE, so changing it does NOT make the .o out of
date. The first run reported "no drift" against a spec I had deliberately broken. It now
deletes the armed objects before every build — R22's incremental trap in config costume.
* A failed object build leaves the PREVIOUS binary in build/<bin>/<bin>, so
`make build; sha1sum build/<bin>/<bin>` reports the OLD artifact as if it were this
build's — a FALSE GREEN over a build that never linked, which briefly convinced me two
binaries were fixed. build_sha now deletes the output too and requires make to exit 0.
Same family as R49: an error inside something shaped like success.
CADENCE: the fleet sweep runs EVERY maintenance pass, not every 4th. A RED fails at BUILD,
so every draft gated against it is rejected regardless of quality and the wave reads as a
drafting failure — detection latency is the whole cost. Gates now finish in ~35 min rather
than 60, so the sweep is affordable each pass. It still FIXES NOTHING by design, with this
single exception, admissible only because it proves itself against the byte gate first.
1. MAIN LANE — the largest single block of unfinished work was drawing 32 cards a wave.
main_lane.draw() never passed --max-bins, so it inherited build_wave_atlas's default of
12 gate groups — a cap that exists because each group costs a whole-binary rebuild, and
main's own --only-bins docstring says the opposite applies to it: "main is gated ONCE per
SLATE, so main has no per-TU gate cost and --max-bins can be large". Nobody passed it.
Measured cost: main banked ~19 stubs/hour against 1,291 remaining while the overlay lane
ran 650-card waves beside it. Now --max-bins 400 (MAIN_MAX_BINS overrides), and the lane
shell draws 600 cards with 600 workers instead of 200/150.
2. TWO LANES GATE, SO READ BOTH LOGS — a defect I introduced this session. The in-flight
exclusion derived "this wave has been gated" from .run/gater.log only, but the main lane
gates its own waves into .run/main_lane.log. Every m## wave therefore looked permanently
in flight and main's draw lost 425 cards to an exclusion meant for work in progress.
3. TAIL_DONE_FRAC 0.80 -> 0.65. At 0.80 the fleet runs 2-3 overlapping waves at ~250
req/min; the residual troughs are the gap between one wave draining and the next ramping.
65% keeps 3-4 waves overlapping. Stragglers keep their full 700s grace in the finisher
thread — this changes when the NEXT wave starts, never what lands.
4. ATOMIC ATLAS WRITE. The lanes read .run/atlas.json at every draw and atlas.py dumped
straight onto it, leaving a truncated file readable for the length of the write. Now
written to .tmp and os.replace'd.
Context for 1-3: the atlas both lanes draw from is dated 08-23 01:13 — two days stale,
predating ~4,600 banks — and its regen chain is running now (its own R32 assertion caught a
stale family map first and named the fix).
MEASURED on a live gate: 24 workers, 32 cores, and 0-2 concurrent builds at load 2.2.
gate_stage takes the fleet-shared lock EXCLUSIVE whenever it might write shared state, and
`_writes_shared = propagate or not GATE_NO_ARITY`. sweep_parallel passes propagate=False but
never set GATE_NO_ARITY, so the arity pre-pass (default on) made EVERY worker a writer and
all 24 queued on one lock. The gate has been effectively serial for the whole campaign,
while the CPU it was supposedly rationing sat at 7% — and that gate time is what recycles
cards back into the draw, so it throttled the drafting fleet too.
bulk_harvest has documented the contract since P30 — "SET GATE_NO_ARITY=1 FOR THIS PHASE ...
route arity-needing drafts to the serial phase" — and this driver, the one the campaign
gater actually calls, was the one that did not.
PHASE A: parallel, GATE_NO_ARITY=1, workers are READERS and actually run concurrently.
ASSERT: `git status --porcelain src/shared config` must be empty afterwards — the only
cheap detector for a shared-state write escaping a worker (bulk_harvest's rule).
PHASE B: serial with the pre-pass on, for binaries whose drafts failed to COMPILE — the
backlog separates "won't compile standalone (loose-typing / missing decl)" from
"residual: N mismatch", and only the former is what fix_arity_callers fixes.
Recent rows are ~13% failed, so phase B stays small instead of handing back the
parallelism. The lever is kept, not traded away.
Tested on ov_SC07_009 with two deliberately wrong drafts: one that compiles and mismatches
(stays in phase A), one that cannot compile (routes to phase B). Both phases ran, neither
banked, shared state clean, tree clean.
Takes effect on the gater's next wave — sweep_parallel is a subprocess, no restart needed.
They were held out because each has a cheaper deterministic owner: the family remap banks a
`remap` card for zero tokens, `plumbing` belongs to recover_integration, `needs-autopsy`
wants a look before a draft. That reasoning priced AGENT TOKENS as the scarce resource. On a
free model the scarce resource is CARDS — holding 1,219 instances out of every wave to
protect a budget that does not bind starves a 2,000-agent fleet.
lever-not-in-lane drops 1,383 -> 164 in a live draw. The deterministic lanes still run and
still reach these first; the byte gate refuses a duplicate, so a card a remap already banked
costs one wasted shard, never a wrong bank.
MEASURED over 18 consecutive waves. Consecutive card sets: ck->cl 239/239 shared, co->cp
238/238, cv->cw 222/222, db->dc 208/209 — and the "different" pairs still shared 50-90%.
Yield alternated in lockstep: 47.6% / 3.8% / 35.3% / 3.6% / 29.9% / 3.7% / 43.4% / 14.6%,
because the duplicate wave gates AFTER the original banked its cards. Half of all drafting
went to work already in flight, and it read as campaign decay.
ROOT CAUSE: --retry-unbanked returns "previously waved but still an OPEN STUB" cards to the
pool — right in principle, unfinished work is not spent work. But the pre-draw for wave N+1
runs WHILE wave N drafts, when none of wave N's cards have been gated, so every one of them
is still an open stub and the filter hands the whole wave back. The ranking then rebuilds it
card for card. The filter knew about "banked" and "not banked" and had no notion of "in
flight".
FIX: a wave is finished when its GATE has run, and the gater already says so in its own log
(R33 — derive from the artifact that exists). Tags with no GATE line stay excluded; a tag
with no gate line whose cards are older than 6 h was killed, and is released so nothing is
locked out forever.
THROUGHPUT, same commit — the draw was setting the campaign's request rate:
* --max-bins 24 -> 160. Concentrating a wave into 24 gate groups was a CPU-economy choice
made when CPU was scarce. It is not: a live gate runs at load 2.7 of 32 cores (8%), one
harvest_verify at --chunk 1. Meanwhile the drafting fleet — the resource actually bounded
by the free-model clock — got 196 cards out of 699 available. Re-drawn with 160 bins:
644 drafts / 46,590 ins across 136 binaries, 3.3x the wave for the same gate economics.
* TAIL_DONE_FRAC 0.95 -> 0.80. Overlapping at 95% still left 25% of minutes under 20 req/min,
because a wave's last 5% is its SLOWEST 5% and 12 stragglers cannot fill a fleet. Handing
off at 80% starts the next ramp with ~40 agents still working. Stragglers keep their full
700s grace in the finisher thread; nothing is cut short.
* --queue-depth 2 -> 4, so a bigger wave's longer gate never parks the drafter.
Arithmetic this is aimed at: req/min = agents-in-flight x ~0.8 (a 16k-token turn at ~30
tok/s emits few requests). 644 cards x two overlapping waves puts the fleet where the
endpoint has already been measured to sustain it — 764 req/min for 15 min at 8% 429s, peak
2,755 in one minute.
rollout_o0 hardcoded `<ov>_o0b.c` as the whale object and listed SC07_006/007/010/011 as
OUT-OF-SCOPE. They were never out of scope structurally — the suffix letter just drifts:
_o0b across the fleet, _o0c in SC07_010, _o0d in SC07_006/007/011. The invariant that
actually identifies the object is that it ENDS at the whale and therefore includes
shared/func_80144B9C.h.
whale_file_of() resolves on that content, and refuses (never guesses) when two -O0 files in
one overlay match, or none do.
NEGATIVE CONTROL (R39) over the already-succeeding population: across all 134 overlays that
bank through the legacy `_o0b.c` path, content resolution returns EXACTLY that file — 134
agree, 0 disagree. The four SC07 overlays resolve to their _o0c/_o0d objects, and overlays
with no -O0 object at all (ov_MAIN_012, ov_SC02_037, ov_SC03_107 — the U3 carve group) are
still refused with `no-o0b`.
Result: func_801457A4 BANKED in all four, each proven by `make build BINARY=<ov>` matching
config/check.<ov>.sha. 4 functions / 316 instructions, no splat change, no drafting.
Also: build_ok() now takes `.run/auto/gate.<bin>.lock`, the same per-binary lock the gater,
sweep_parallel and the maintenance sweep take. This driver was written to be run by hand
between waves; with six lanes live, two processes in one build/<ov> tree would produce a
verdict about neither.
MEASURED across the harvested notes: 13 citations to sections that do not exist — §2329
(x5), §13446, §13474, §1914, §19189, §2392, §3478 — against a corpus that stops at §273.
Every one is a grep -n LINE NUMBER cited as a section number, and each resolves to a real
section that says what the note claimed: line 2329 is inside §28 (the stranded/pure-extern
class), 13446/13474 inside §164, 1914 inside §20 > §21.
The cost is compounding: the next agent greps "§2329", finds nothing, and re-derives a
lever we already own — and a distill reviewer scores the note "covered by §2329" as covered
by a section nobody ever wrote. Both directions of the flywheel corrupt.
Not a warning in the brief (R33): grep now returns the right answer. Every hit in
matching-cookbook.md is prefixed with its containing heading, nested where the corpus nests
(`§164 > §16Xy | docs/...:13446: ...`), so the number in front of the model is the one to
cite. Index is built once per process and cached by mtime; 555 headings resolve.
Takes effect on the next shard — api_agent is spawned fresh per draft, no restart needed.
Found by the S60 distill reviewers reading 218 harvested notes.
One clean whole-EXE rebuild verified the batch (gate_main), and main re-checked
BYTE-IDENTICAL against config/check.us.sha before anything was credited.
SYS_OBJ_2DD8
_clr
func_8005EA68
A marker is a CLAIM on work, not a record of it. axbm.json sat in .run/distill_ready
for 10.5 hours AFTER its waves were distilled into cookbook §269 — the reviewer landed
the sections, updated the mined state, and never removed the marker — and distill_scan's
one-pending-marker-at-a-time rule (correct, it stopped eight overlapping batches) then
refused to raise anything while 18 waves / 315 novel candidates accumulated behind it.
The marker's own waves are checkable against the mined state, so check them: a marker
whose every wave is already mined clears itself and says so. Negative control (R39): a
marker naming any still-unmined wave survives untouched.
Same family as R47 — a stage that consumes work must also consume the token that
represents it.
.run/maintenance.sh (what runs) and tools/lanes/maintenance.sh (a pre-S59 copy) had
diverged. The 150->50 threshold tune landed on the stale copy and was then copied over
the live one, silently reverting five S59 fixes:
* the R47 shape filter (staging fell back to status=='AGREE' alone — the exact defect
that staged 82 hopeless drafts every 45 minutes)
* the R48 (binary, fn) keying (bare-fn keys collide across overlays)
* reloc --fix MISMATCH auto-repair (measured 4/4 repaired to AGREE)
* rtu_second_chance (re-judges standalone COMPILE-FAILs against the real TU)
* fix_tu_ret_decls (the return-type half of the stale-decl wall)
Rebuilt from the S59 lineage with the 150->50 threshold and the periodic fleet R22
re-applied, both paths now byte-identical, `bash -n` clean, and the two-path hazard
documented in the header so the next edit cannot repeat it.
Also: relaunch_drafter_shell.sh 30s -> 5s ready-marker poll; regenerated backlog and
fleet progress artifacts.
150 was tuned for a lane that only re-swept an unchanged sibling pool and banked
nothing. The lane now consumes every verdict layer in the A-prop pipeline, carries the
free pre-gate reject recovery, and runs the periodic fleet R22 — a pass is worth
running on a much smaller refill.
Two binaries sat RED for hours today and nothing noticed: ov_SC07_010 from a
maintenance commit whose final tree state was provably never built, and ov_SC07_002
from a stale 2-table jtbl pad spec written at wave bp. Every lane only ever checks the
binary it is currently touching, so a byte-gate — a correctness oracle — was silent
about everything it did not build. They were found by accident, by an agent's scoped
R22 sweeping 141 binaries.
Every 4th maintenance pass (~3h), skipped while any gate is in flight (check-all
rebuilds stale objects and must not race a gate), it runs the fleet check and writes
any REDs to .run/fleet_red.txt with a loud log line. It FIXES NOTHING: a wrong repair
to a pad spec or a config is exactly how a silent byte shift gets committed, and the
two we fixed today each needed a different, evidence-led remedy.
OpenRouter returns a provider throttle as HTTP 200 whose body has no 'choices' and an
error of {"message": "Provider returned error", "code": 429}. That never reached the
429 handler, which keys on HTTPError, so it fell through to the 'no choices' raise and
ended the agent at turn 1 with no draft, no submit, $0.00 spent.
Measured, and it is not marginal:
wave cb: 169 of 260 shards hit a soft 429
wave cc: 115 of 260
wave cd: 187 of 260 <- 260 shards 'finished cleanly', 72 drafts produced
wave ce: 119 of 258
That is the draft-completion collapse. I had attributed 28-60% completion (against
84-89% before) to the straggler grace and raised it to 700s; the grace was never the
cause. The shard logs said 'finished cleanly' because the agent DID exit normally —
after being killed by an unretried rate limit on its first API call.
Now treated like every other transient: back off, retry, and log it as SOFT-BODY so
the rate telemetry stops under-counting 429s. Takes effect on the next wave's shards —
api_agent is spawned fresh per shard, so no lane restart is needed.
R40 again: the fleet looked like it was giving up, and the harness was hanging up on it.
Measured 23:20: the maintenance lane held .run/auto/draw.lock for a multi-minute
sweep, the pre-draw buffer happened to be empty, and the drafting fleet — the one
clock-limited resource — sat at 13 agents and 3 req/min printing 'gate holds the draw
lock and nothing is pre-drawn — waiting 30s' every thirty seconds.
That wait dates from when drawing during a gate was genuinely unsafe: corpus.stubs()
misreports for a binary whose sources carry a substituted draft (R35), so the draw
refused outright. Since 15:23 build_wave_atlas excludes exactly the binaries whose
per-binary gate lock is held and draws from the rest, so the hazard is handled at the
right granularity and the blanket wait now protects nothing.
Same lesson as the draw's own refusal earlier today: a guard scoped more broadly than
the hazard gets routed around or, worse, quietly starves the thing it sits in front of.
1. decl_for searched the DESTINATION for the SEED's name: a RENAMED symbol's
destination spelling can only exist under the MEMBER's name, so the
destination preference silently never applied to renamed data symbols
(D_801B9DF8 adopted the seed's 'short' against the TU's file-scope 's32').
dest/fleet tiers now search target_sym; seed tiers keep the seed name.
2. dest_scope is FILE-SCOPE-ONLY (brace-masked): the TUs are full of
block-scope externs inside banked bodies, and a flat regex adopted one of
those as 'the destination spelling' over the DEFINE macro's true file-scope
decl.
3. A body-embedded block extern that diverges from the destination file scope
is rewritten to the destination spelling when every use is ADDRESS-ONLY
(type is codegen-irrelevant for &sym); valued uses keep the seed spelling.
+ fix_tu_ret_decls.draft_ret now parses K&R definitions (its first run SKIPped
30 of 32 because the param decls sit between ')' and '{').
reloc_identity --fix's rowmap keyed rows by fn alone, so three same-named
func_8013BCDC rows across binaries all received ONE binary's draft — 2 of 4
'no textual occurrence' refusals were the tool editing the wrong file. Keyed
by (binary, fn): 4/4 repaired to AGREE/MATCH (byte-checked by re-run).
maintenance.sh: stage on status in {AGREE,UNRESOLVED} AND shape==MATCH keyed
(binary,fn); run reloc --fix on MISMATCH rows and re-check so repairs stage the
same pass; add rtu_second_chance for standalone COMPILE-FAILs (7/27 measured
TU-byte-MATCH, previously dropped unjudged).
aprop_autodraft decl_for gains the BORROW tier: when both home TU and seed are
silent, adopt a sibling TU's extern spelling under the same body-compatibility
guards — 'which TU may conflict' (home only) and 'where a guess may come from'
(anywhere) are different questions; refusing outright left 125 members undrafted.
Baseline measured on the 21:04 pass (117 staged, 0 banked): 82 near real-diff /
19 standalone compile-fail / 16 near-0 TU-integration; zero drafts invisible to
the gate (the 'drafts: 0' probe was the triage harness racing itself — a shared
per-fn probe dir rm -rf'd by a concurrent triage run, not lane plumbing).
1. K&R definitions (aprop_autodraft.kr_definition): the near-0 class is the TU's
own '(void)' decls + empty K&R call sites rejecting the draft's ANSI def
('too few arguments' after the arity pre-pass relaxes the decls). K&R the def
when every param is promotion-safe; byte-proven MATCH on func_80162CCC's real
TU (rtu_match) where the ANSI form CC1-failed.
2. decl_for scope: the destination is the HOME TU ONLY, macro-expanded
(dest_scope) — the whole-binary concat adopted spellings the home TU never
declares; and a dest spelling is adopted only when the seed body can compile
against it (void-return-value guard + call-arity guard; measured 42 and 15
fresh drafts died on each before the guards).
3. Ordinal IMM pairing is now a CANDIDATE SET (family_remap._ordinal_candidates):
the single-guess form paired the first spelling's occurrences only and shipped
35 of 117 drafts with value/offset swapped ('*(p+3)=2' for '*(p+2)=3',
closeness-2 forever); candidates are adjudicated with match_one at draft time.
4. Staging filter (maintenance.sh): stage only AGREE + shape==MATCH, keyed by
(binary, fn) — status-only staging burned 82 whole-binary builds per pass on
drafts match_one had already refuted, every 45 minutes.
+ tools/rtu_second_chance.py: standalone COMPILE-FAIL is the wrong oracle for a
TU-destined draft; re-judge those against the real TU (rtu_match) and stage
the MATCHes.
MY BUG, SAME DAY, SAME CLASS. recover_rejects staged by the binary field of
aprop_symfix's output slate — and aprop_symfix tags its REBASE VARIANTS into that
field (ov_MAIN_012-cn, -cn-cast, -cn-cast-rc, -s2in, -s2in-uni). Staged verbatim,
each variant became its own directory and sweep_parallel was handed 273 directories
naming binaries THAT DO NOT EXIST: 553 drafts that could never be gated against
anything, while the sweep reported 'over 331 binaries'. It now resolves the variant
tag back to a real binary, keeps ONE variant per target, and COUNTS what it cannot
resolve (R43). The 290 bogus staging dirs are cleaned; 118 real drafts remain.
aprop_autodraft, per Drew:
* decl_for prefers the DESTINATION TU's own spelling and falls back to the seed's
only when the destination is silent (wave law 2 — the destination is
authoritative; 45 of 188 staged drafts declared a conflicting type).
* it REFUSES a seed whose body is a verbatim __asm__ block. Those transcribe
instructions rather than decompiling them, trivially 'MATCH' the local oracle
because they ARE the target's bytes, and would count as matched functions in every
progress number while nothing was decompiled. 26 of 188 were this shape. §265 is a
deliberate human escape hatch for hand-written asm, not something an unattended
lane propagates across a family.
Measured before changing the drafting prompt instead: model waves bw/bx/by/bz produced
ZERO whole-body asm across 530 drafts, so this is a tool behaviour, not a model one. A
blanket 'no asm' rule on every card would have cost us the sanctioned one-line levers
(§5a fences, §17 register pins) that appear in 32-47 drafts per wave.
PROVEN: from 14:57:01 to 18:43:23 today HEAD built main to 307aa45d… against the
expected 143dbb89…, with NO draft substituted (measured under gate.main.lock, no
gate_main alive). Auto-commit commit:2693 had adopted a mid-flight gate_main
substitution — its carve-out reverted main's TUs, gate_main re-wrote them, and
`git add -A src/` swept the unverified bodies in (a TOCTOU race, 14 s after a
bisect chunk banked). Every main batch after it was doomed before its first
draft was judged: m00–m03 card cycles drafted ~737, slated 160, banked 0, and
burned ~50 clean rebuilds bisecting innocent slates. commit:2712 restored the
green content by accident (it swept this investigation's diagnostic checkout).
gate_main: on any batch failure, ONE try_batch([]) control runs first — if HEAD
itself is red it prints BASELINE RED, leaves the slate reusable, exits 3 (R40).
clean_build no longer reports a linked-but-mismatched build as "no binary" (the
build target embeds the SHA check), the compile-conflict shortcut fires only on
error-shaped lines naming a symbol some draft in the slate actually uses (the
baseline's own func_800143AC implicit-decl WARNING was matching — every m04
chunk died with "drafts declaring it: []"), reverts narrow to top-level src/*.c
(main_tus) so a main gate can never destroy overlay lanes' in-flight work, and
--assert-baseline is a first-class mode.
main_lane: every cycle opens with gate_main --assert-baseline and REFUSES to
draft or gate against a red baseline (R43) — BaselineRed parks nothing, burns
no tries, writes .run/main_lane.BASELINE_RED, re-checks every 30 min.
Adopters (ox_campaign ×3, maintenance.sh, gate_stage, gate_lane, idiom_serial):
main's TUs (top-level src/*.c) are never staged and never reverted by an
overlay/maintenance lane — one writer (gate_main), one committer (main_lane,
after the whole-EXE SHA re-checks green). Unstage-after-add is race-free where
the old revert-then-add was the losing half of the TOCTOU.
Diagnosis, evidence and the full timeline: docs/tool-designs/main-lane-fix-s59.md
STATUS BLINDNESS (Drew): status checks kept reporting the overlay drafter and the
gater — the lanes whose logs scroll — while the main, maintenance and distill lanes
went unmentioned for hours. A lane you do not report is a lane you do not notice
failing: the main lane spent an afternoon on an old config and bisected a whole batch
to zero banks without that ever reaching a status line. tools/campaign_status.py
prints every lane with ITS OWN metrics, read from artefacts rather than memory.
STRAGGLER GRACE 120 -> 700, tied to HTTP_TIMEOUT so they cannot drift. collect_drafts
queues a wave once 95% of shards finish, then waits this long for the rest — and 120s
is shorter than a single turn (~530s for a 16k generation at ~30 tok/s). So raising
the token budget converted truncated turns into agents guillotined mid-thought with NO
draft: overlay draft completion fell from 84-89% at 8k to 41% (bt) and 69% (bu).
DISTILL DEDUPE: each pass re-offers everything unmined, so the lane wrote a fresh
overlapping marker every five minutes — eight queued, each a superset of the last, and
a reviewer cannot tell which one is the work. One pending marker at a time.
Same problem as the drafter: an env/arg change (MAXTOK, HTTP_TIMEOUT) only reaches a
fresh shell, and the main lane is usually either drafting or gating. This waits for
the one safe window — no main-lane agents alive and no gate_main running, i.e.
between the gate and the next draw — then restarts. Mid-draft would discard drafted
work; mid-gate would abort a batch (safe, since gate_main reverts its own
substitution, but wasteful).
Probed ox-alpha directly on a real MIPS derivation:
no reasoning cap 265.2s finish=stop completion=8,067 reasoning=0 30 tok/s
reasoning cap 2000 22.3s finish=stop completion= 672 reasoning=0
reasoning cap 6000 41.4s finish=stop completion= 618 reasoning=0
Three findings. (1) ox reports reasoning_tokens=0 — its thinking is IN the content
stream, so the output cap was capping the reasoning; that is exactly why turns ended
in 'no tool call (finish=length)'. (2) The uncapped hard prompt wanted 8,067 tokens —
it was finishing precisely where the old 8k cap cut it off. (3) It generates at ~30
tok/s, not the ~54 I estimated from turn gaps, so a full 16k generation needs ~530s
and the 420s socket would have killed the very turns the bigger budget exists to
allow. A timeout wastes the whole turn; truncation at least leaves a partial.
HTTP_TIMEOUT=700 on both drafting lanes. The ordering that must hold is generation <
HTTP_TIMEOUT (700) < stallguard's wedged-agent kill (1200s). 420 was itself deliberate
— 1800 once parked a hung agent for thirty minutes — and 700 keeps a hang under 12
minutes without strangling legitimate deep reasoning.
Also recorded: a reasoning cap DOES work on ox, but it shortens the ANSWER too (618-672
total tokens), so it is a quality knob, not a fix for truncation.
THE OUTPUT CAP WAS EATING THE TURN BUDGET. Wave bk's shard logs: 240 of 244
turn-finishes were 'no tool call (finish=length) — NUDGE n/6'. The model was
exhausting its 8,000-token output budget BEFORE emitting a tool call, so the turn did
no work; an agent gets six nudges before giving up. That is why MATCHes average 2.8
oracle calls against a 24-turn budget — the turns are going to truncation, not
iteration. ox is free, so a bigger output budget costs latency and nothing else.
Measured alongside it, and worth recording because it redirects the obvious fix: turn
caps are NOT binding on the default lane. Across 1,166 agent completions, non-MATCH
runs used a median of 4 oracle calls and a p90 of 12, and exactly 1 of 194 reached 20
of the 24 available. Agents are not running out of turns; they are giving up early
after truncated turns. (The tells lane WAS cap-bound — 98 of 270 — which is why it
already has 40 turns.)
Plus tools/recover_rejects.py, wired into the maintenance lane: rebase the pre-gate
rejects whose body already matches and only the symbols are wrong (§171), stage them
for the lane's existing free gate. Zero model tokens; it only stages, so a bad
recovery can waste a build but never a bank.
Everything that reaches the GATE and fails gets a backlog row with closeness, class
and best draft. A draft the reloc pre-filter drops never reaches the gate, so it was
recorded nowhere and just sat on disk: 569 of 1,261 drafts across the last eight waves
— 45%.
They are not all garbage. 13% of the MISMATCH? rejects have a body that ALREADY
MATCHES and only the symbol names wrong, which is the deterministic aprop_symfix
stale-symbol class that banked 4 of 4 earlier this session. Roughly 6 recoverable
drafts per wave were being thrown away because no index existed to find them.
Now appended to .run/reloc_rejects.jsonl with the verdict, the shape (MATCH here means
right body, wrong symbols) and the first mismatches, so a recovery pass can work them
without re-drafting. Wrapped so telemetry can never break a gate.
The tells slot became redundant when build_wave_atlas started reserving 60 tell-lever
cards inside every ordinary wave: a dedicated tells wave draws 70-87 cards, a quarter
of a default wave, for a full 40-minute slot.
The 120-2000 slot is worse than redundant. Bank rate by size, measured: 57% under 50
instructions, 30% at 50-80, 22% at 80-120, 3% at 120-200, 6% above. Wave br drew 69
cards on that band — roughly 3 banks for a slot that a full-band wave turns into ~150.
Large functions are not abandoned: the full band contains them and the draw takes
mass-first within each gate group.
Takes effect at the next wave boundary via relaunch_drafter_shell.sh.
corpus.stubs() misreports for a binary while a gate has draft bodies substituted into
its sources (R35) — but only for THAT binary. The blanket refusal cost far more than
it saved: the gater runs almost continuously, so nearly every fresh draw was refused
and the drafter fell back to PRE-DRAWN waves. Measured at 15:20 — wave br refused,
wave bj (drawn hours earlier) drafted instead.
That is worse than idle time: a pre-drawn wave carries the OLD draw-time defaults, so
every feature landed today — the tells quota, the jtbl quota, the -O0 filter, the
oversize filter — was silently not reaching the fleet, while the logs showed healthy
410-shard waves.
Which binaries are mid-gate is not a guess: gate_stage and gate_main hold
.run/auto/gate.<bin>.lock for exactly that window, so a non-blocking test-lock answers
it per binary. Those are added to EXCLUDE for that draw; the refusal survives only for
--only-bins draws where every requested binary is busy.
Verified live against a running gate: the draw that would have been refused now
returns 40 cards.
A bisect can run many levels; deferring the commit left byte-proven functions sitting
uncommitted in src/ for the whole descent — precisely the window in which any other
tool's blind revert destroys them (61 banked functions died that way once). The tree
is verified byte-identical on the line where the credit is granted; that is both when
it is safe to commit and when it must be.
Three defects found by running it, all of the same family — a check that is true about
the wrong thing:
1. FALSE BANKS. The first accounting asked corpus.stubs('main') whether each name was
still a stub; that returns {addr: Stub(symbol=...)} — a dict keyed by INT. Comparing
a NAME against a set of ints is always True, so the lane reported '12 banked of 12'
from a gate that banked nothing and committed nothing. Credit now requires BOTH the
INCLUDE_ASM line gone from the working tree AND main re-checked byte-identical.
2. INNOCENT DRAFTS DYING WITH A DECL CLASH. gate_main deliberately refuses to bisect a
COMPILE conflict (right for a human caller, wrong for an unattended lane): the first
live batch hit a conflict on a symbol that was in the TU and in NO draft, so there
was nothing to drop and 40 innocent drafts died with it. The lane now halves the
slate — a main rebuild measures ~15 s, so bisecting is cheaper than discarding.
3. THE DRAW GUARD REFUSED EVERYTHING. build_wave_atlas refused to draw whenever any
gate was in flight (R35: corpus.stubs misreports mid-gate) — but only for the
binaries being gated. Main's sources are touched by gate_main alone, so a main-only
draw now watches gate_main and every other draw keeps the blanket refusal.
Failed drafts are parked with a try count instead of discarded (a failed draft is
evidence), capped at 2 so an unbankable body cannot spin the lane.
Live: 13 main functions banked, main byte-identical at 143dbb89, stubs 1713 -> 1700.
main is excluded from every wave draw for a good reason — its gate is a clean
whole-EXE rebuild that bisects, and on the overlay critical path it cost three
measured stalls (39 min unfinished on 29 drafts, 25 on 8, 65+ on 8). The consequence
was that main sat outside the loop entirely: 1,713 open stubs, no lane, no cadence,
while the overlay lane ran at ~a quarter of the API ceiling because CARD SUPPLY, not
throughput, is its constraint. Two populations, one idle half of a rate limit.
draw (main only) -> draft -> reloc pre-filter -> ONE gate_main batch -> commit.
Never sweep_parallel or gate_stage (both build incrementally; main's extract rewrites
the linker script, so an incremental build yields a FALSE diff — that is what banked
0 of 105 main cards in wave ab). Batches because one clean rebuild verifies the whole
slate; the reloc pre-filter is what keeps a batch from bisecting. Commits the moment a
batch is green (R42) since gate_main deliberately does not.
Parked drafts first: 170 main drafts sit in .run/main_queue from before the exclusion —
already drafted, never gated, free.
TELLS QUOTA (Drew approved): a dedicated tells wave drew only 70-87 cards — a full
40-minute drafting slot at a quarter of a default wave — because the 5-80 size cap and
the tells pool cannot fill more. Tells now ride inside ordinary waves with a 60-card
quota, same as jtbl. The size cap moved into the draw itself: tell-lever members above
--tells-max-ins (80) are not drawn at all, because the measured bank rate is 27-40%
at 5-80, 10% at 81-120, 1% at 121-200 and 0% above — those 383 members / 51,941 ins
are idiom_serial's work, and the skip counter names it (R45).
A QUOTA IS A FLOOR UNLESS IT IS ALSO A CEILING. First test: putting the tell levers in
the default list let them win the ranked fill too, and a 300-card wave came back 122
tells (41%). The size cap held; the mix did not. Tells now enter through the quota or
not at all.
GATE JOBS 24. The quotas deliberately pull cards from binaries outside the ranked gate
groups, so a measured draw went from ~24 groups to 63 — 63 whole-binary rebuilds per
wave, five serial batches at 12 jobs. The box is 32 cores at ~6% (load 3.1) with 39 GB
free. Lands via restart_gater_when_idle.sh so no sweep is killed mid-flight.
Correction to the record: the live draw already passed --max-bins 24 (plus
--one-per-gid and --exclude-bins main). An earlier measurement of mine used the tool's
default of 12 without those flags and read as 'max-bins is the cap' — it is not;
--one-per-gid is, and deliberately: it defers same-skeleton siblings to the free
deterministic remap instead of paying an agent twice.
Balance $2.56 and falling ~$1.43/h over the last three waves ($4.56 at 11:54 ->
$2.56 at 13:18) — about 23 minutes from --credit-floor 2.0. That floor does NOT pause
the paid lane: it breaks the whole drafting loop, and the shell then restarts a python
that breaks again, so the clock-limited resource dies on a check about money.
ox-alpha is free for the rest of this window, so drafting continues on ox alone at zero
burn, and the floor drops to 0.25 because with a free model the balance stops being a
proxy for 'can we draft'. deepseek was 280 of 2,000 workers — its value was an
independent 429 ceiling, not throughput.
Takes effect at the next wave boundary via relaunch_drafter_shell.sh, so wave bp's
in-flight drafts are not lost. Restoring it after a top-up is two edits, named in the
script's header.