- every wall's best draft re-run with rtu_match in its CURRENT real TU: func_80011380 DIFF 6 (--o0, §474 PROVED),
func_80020DA4 DIFF 2, func_8017DF28 DIFF 2, func_801834A4 DIFF 6 ×3 variants; leaf match_one re-measured the CC1 rows
(func_80032A74 1, func_80039DEC 2 permuter / 9 sonnet, func_800391D4 3)
- the three CC1-FAIL rows: func_80032A74 = 7 typedefs the TU provides via 800_shared.h + 4 decl spellings → synced copy
(.run/P32/t4/drafts/func_80032A74_tuclean.c) DIFF 1 in the real TU (idx 244 lh vs lhu); func_80039DEC = the TU's narrow
prototype (800_c.c:3496) vs the K&R def → sandbox TU (.run/P32/t4/tu/, no-proto decl) DIFF 2; func_800391D4 = the
load-bearing `D_80073140[][1]` vs the TU's `[]` → sandbox TU DIFF 3 (TU-compatible spellings regress to 65 @ 76)
- config/wave_exclude.txt: each of the 7 lines carries its S83 re-probe verdict; exclude_audit --assert-fresh 7/7
- backlog: rows for all 7 walls (the path-less func_80011380/func_801834A4 given existing drafts, R62; two rows re-logged
after a shell-quoting mangle); docs/backlog.md 16 open
- CURRENT_PHASE.md: T4 row DONE, the wall ledger table (row · ins · class · leaf/real-TU closeness · mechanism+citation ·
attempt record · verdict · best draft; func_800CF3E8 listed as an unpinned candidate), the T4 log entry, 🛑 block → T5
(R27 Max prompt + the gate-2 procedure)
- cookbook §500-I (the sandbox-TU re-probe method + the verdict table); accelerators (8); decision-log P32 S83 (R31)
- CURRENT_PHASE.md: T3 row DONE with the close numbers; the S83 steps 8–9 log entry; the 🛑 SESSION CHECKPOINT rewritten
(T3 CLOSED, T4 NEXT; the 15-row census with draft paths and mechanisms; the T4 procedure incl. the §376 re-probe of the
three CC1-FAIL walls before any verdict; T5 carry)
- step 8 tail: func_8001BC6C BANKED (commit:3948); func_800CD674 plateau ledgered; func_800CF3E8 Opus second look 27 HOLDS —
§500-D1's mechanism corrected to cse.c find_best_addr (fold_rtx MEM, COST pseudo 0 vs hard reg 1), the alias lever refuted
5/5, a new zero-byte pinned-pointer launder found (79 @ 470) — cookbook §500-H, backlog row with cost (245k tokens / 29 min)
- make report: fleet instr 13,484,739 / 13,488,497 = 100.0% · distinct 5,812,831 / 5,816,589 = 99.9% (90,975 / 90,984 unique)
· fn-count 363,199 / 363,214 = 100.00% · INCLUDE_ASM 15; main REAL 783 · LINKED 1,256 · VERBATIM 3 · stubs 6 ·
byte-identical 2,085 / 2,091 = 99.71% · 143dbb89; census .run/P32/frontier_t3_close.json; twin_rescan 0 free
- R22 (clean + extract-all + check-all) after the Makefile guard + the main bank: 218 passed / 0 failed, exits 0/0/0
(.run/P32/t3s3/r22c_full.log) — the third green fleet sweep of the session (10:46, 11:09, 12:00)
- docs/accelerators.md (5)–(7): the build is the batch verdict / read a waypoint's diff both ways / a live probe in src/ is
build input; docs/backlog.md 14 open; verdicts.jsonl 50 rows; the s83 Opus draft + report kept (R20)
- kill gate: 29 banks + 3 new verdicts this session, the three bounded tail attempts spent — T3 closes on the evidence
- seed: the Opus NEAR-6 draft (.run/P32/t3/opus/func_8001BC6C.c; §500-C REGALLOC-PERM $v0<->$v1 across the six OT-chain insns,
local-alloc qty_compare one span unit). permuter_ils 8x150s -j3 --klass REGALLOC: cycles 6/7/8 = 6, 5, 1 (output-1-1)
- R63 read of the "1": three mutations — (a) `idx` computed AFTER `color`, (b) an early dead `tag = (a1 << 8) | k;` before
k's assignment, (c) `(D_800B9A02 & 0xFFu) << 14` — and (c) turns the target's `lhu` into an `lbu` (semantically WRONG:
the masked score rewards it; second witness after S80). (a)+(b) alone = leaf MATCH 69/69; (a) alone 8, (b) alone 21
- well-defined re-spelling: `k = 0; tag = (a1 << 8) | k;` at the top (I1) MATCHES; k-initialised-first (15), tag=a1<<8 (19),
tag=a1 (8), tag=(a1<<8)|K (20), tag=0 (8), tag-then-k (8) all regress — the lever is the early BIRTH of the tag/k pseudos
(§47 live-length: qty_compare = floor_log2(n_refs)·n_refs·size/(death−birth)), documented in the source comment
- rtu_match MATCH 69/69 in src/800.c; gate_main slate_main3: "slate 1 -> 1 compatible … BANKED 1 of 1 … 143dbb89 BYTE-IDENTICAL",
EXIT 0 (.run/P32/t3s3/gate/gate_main3.log); main open 7 -> 6 (5 pinned walls + func_80039308 NEAR 17)
- func_800CD674's ILS plateaued at the SAME $a3<->$t1 pair (output-2-1 = 2 rows, no drift) — ledgered with its cost (R41)
- variants kept under .run/P32/t3s3/p1bc6c/ (the 11 spellings measured)
- phase-ends/DIGEST.md (NEW, Drew-directed 2026-09-05): every phase's synopsis (P1–P32), every rule R1–R64 in full, the
corrections that supersede parts of PROJECT_CONTEXT.md (P8→R19, commit cadence→R42, H1→R1, headless Ghidra, roadmap v2,
effort doctrine, the pinned triple), and the doc map. Maintained at every PhaseEnd (CLAUDE.md Phase Boundary step 3b, P7).
- CLAUDE.md Session Start Protocol rewritten: PROJECT_CONTEXT → DIGEST → the THREE most recent PhaseEnds → CURRENT_PHASE
(+ cookbook head/newest § + SETUP §5.4 for matching phases); rules transcribed in full from the digest; the 🛑 SESSION
CHECKPOINT block reproduced VERBATIM in chat as the session's only in-phase seed. Measured load order ≈55k tokens
(was ~150k reading all 32 PhaseEnds). phase-ends/README.md + SETUP §7 pointer updated (R21).
- CURRENT_PHASE.md: the T3 🛑 block REFRESHED and SUPERSEDING the 09:30 one — written to be replayed: what happened in the
dead session (times, hashes, the overflow, the swept dir), what the successor did, the 44-stub census with every row's
state/draft path, the 10 banked with hashes+shas, the 9-step resume order with exact invocations, the file/tool
inventory and gotchas, carried context for T4/T5, environment, the plain-English recap; Log entry for the protocol change.
- .run/P32/t3/PROMPT_TEMPLATE.md (tracked): the verbatim agent prompts (Haiku / Haiku+twin / Sonnet escalation / Opus /
Sonnet) for launching the 17 queued rows under the amended output contract.
- memories updated outside the repo: checkpoint-current-phase-before-pause (the verbatim-replay contract; a dead session's
checkpoint is written by the successor from the transcripts) and session-start-list-rules-in-full (the ~100k protocol).
- verdict ledger .run/P32/t3/verdicts.jsonl rebuilt from the 31 T3 transcripts (agent_verdicts.py); every unbanked draft
re-verified with rtu_match in its real TU: 10 MATCH awaiting the gate (main func_80015B6C 120 + func_8002FDE8 73;
md_SC03_054 func_801EF6D8 604 + six jtbls; md_SC03_053 func_801EF734 44 + func_801EF7E4 72; md_MAIN_007
func_800CF148/2BC/EEFC/EF94/068) + func_800CF3B0 leaf-exact behind the TU's void/3-arg decl; 9 NEAR at exact length
(2/6/15/17/27/35/46/49/137), each with its class and inert-lever list
- R48 incident: one agent's `find .run/P32/t3/opus -maxdepth 1 -type f ! -name <mine> -exec mv {} _scratch/` swept 11
sibling deliverables (two MATCHes among them); found in _scratch/, restored to the contract paths, byte-verified;
tools/agent_drafts_restore.py (NEW: transcript replay) as the fallback; .gitignore allowlist for .run/P32/** so the
drafts, ledger and census files are committed (R20)
- harvest (R16/R30): cookbook §500 (10 banked closers, 10 MATCH closers, 9 NEAR classes, two NEW mechanisms — the
pinned-base-vs-pseudo-address alias basin and #line-equalised ASM_OPERANDS for cross_jump — and the wave-process
defects); wave-playbook §S80 addendum-2 (per-function work dirs, JSON-only final message, the 20-agent cap, the
recovery tools); accelerators P32 T3; decision-log P32 S82 (R31); SETUP tooling row (R21); cookbook-index
regenerated; .run/P32/t3/BRIEF.md output contract amended for the 17 queued launches
- CURRENT_PHASE: T3 row IN PROGRESS, Log entry, 🛑 SESSION CHECKPOINT (census 44 stubs / 5,313 ins with every row's
state and draft path, the 9-step resume order, the dead session's read-only T4 pre-read); harness task list rebuilt
- no src/ or config/ change in this commit; no fleet R22 has run since the 10 T3 banks — the resume order starts with one
- md_SC03_056 (TEXT_LO 0x4, 4 stubs / 61 ins): 15/17 pointers cluster inside at 0x801CBB50; one outward call
(0x8018151C) hits a function only 3 overlays have, ov_SC03_002 among them; req_fit 9/9 for ov_SC03_002
- payload_base_evidence.py v2 (controls 7/7 throughout): (a) STRONG = internal jals + fn-ptr-table entries on the
module's own starts >= 2 (SC03/53 STRONG); (b) OUTWARD-EXPLAINED — a pure jal-vote base whose "internal" targets
are function starts of the fleet's overlays is downgraded: SC03/56's 0x80178C8C was two SHARED-engine functions
spaced like two of its five starts (and nobody's DESTPTR), a false STRONG; (c) the requester cross-check is
informational only — shared engine code makes every requester fit (an R39 control caught it scoring: 6/7)
- memory-map §S45 p7 amended: all five rows ONBOARDED + the two instrument findings (the first build is a NULL
oracle for FINE base errors — +8 builds byte-identical, +0x1000 fails the link; outward-explained vote bases);
SETUP row amended. The parked-for-L3 ledger is EMPTY pending `make audit-disc` (T2c).
- the instrument: module-id word, TEXT_LO estimate, absolute-pointer set, lui hi-half histogram, and a
jal->function-start VOTE (starts = prologues ∪ the word after every `jr $ra`+delay — leaf functions have no
prologue, the recall killer of S45's vote_base 4/12); scores a BOUNDED candidate list (5 §S44 slots ∪ 134
IDXTAB DESTPTRs ∪ vote bases): STRONG / CONSISTENT / INCONSISTENT / NO-EVIDENCE; AMBIGUOUS tie sets are
printed, never picked; a payload with no self-reference is REFUSED as base-independent (R43)
- R39 controls run before any emission: md_MAIN_008/011/013/042, md_SC03_073, md_SC02_009, md_SC07_004
re-derive their byte-proven bases top-ranked from their payloads alone (7/7); TEXT_LO estimates == yaml
(incl. the header-table modules 0x7C/0x14/0x158). The first draft of the scorer FAILED 5/7 (prologue-only
starts; a top-rank assertion on modules the bytes cannot discriminate) — fixed by the controls, not shipped
- the five (G5 static-derived, US): MAIN/7 STRONG 0x800CEDF8 (9/9 jals, 14/16 ptrs on starts); MAIN/9 STRONG
0x800CD348 (6/6, 9/9); SC03/53 + SC03/54 CONSISTENT with 0x801EF468 top of a 12-way tie; SC03/56 SPLIT
(jal vote 0x80178C8C vs pointers/lui ~0x801CBB50). T2b probes each with new_binary.sh — the byte gate decides
- SETUP row (R21); evidence rows .run/P32/t2a/evidence.json
- the census's best_draft (.run/wave_g0c/shard30, 174 ins, 7 pins) was a DIFFERENT, wrong body under the bare
name (R48); the journal (R38) named the real one — .run/O21/opus/func_800CB00C.c (88 lines, 7 BLOCK-scope
callee externs: gcc-2.7.2 demotes the later-definition type conflict to a warning at block scope). rtu_match
MATCH 123/123 in the real TU (the S75 redraft too); the S72 resolver had gated only the wrong file, 3x.
- raw splice into src/md_MAIN_034/md_MAIN_034.c; module island pads derived at build (§303); make build
BINARY=md_MAIN_034 -j8 rc 0, sha 46153c06bca859dec05aff59fb1a77d3add3d02b == check (R53); verbatim strict ok
- config/wave_exclude.txt regenerated (exclude_audit --write): the md_MAIN_034 WALL pin labelled a wrong draft,
not a wall — 8 -> 7 entries; docs/backlog.md re-rendered (matched rows drop)
- 0 drafting tokens; no Sonnet agent needed (plan T1c adjusted: no redraft)
- BANK: the stored S71 closeness-0 draft spliced into src/resident/resident_jr_800D128C.c; jtbl_carve --func
carved jtbl_80113FB8 (119 entries, 1 pad word trimmed) + jtbl_80114198 into [0x451c0, .rodata,
resident_jr_800D128C] + [0x453c4, data, tail3]; JTBL_PADS 0,4; make extract + make build BINARY=resident -j8
rc 0, sha 8e17e02ff8954d07c979449198f7e1645046b353 == check (R53). pads_audit ok/ok; interleave_check
ALIGNED n=5; verbatim_check --strict 5==5. Resident stubs 2 -> 1 (func_800D06E8 remains).
- WHY THE GATE SAID DIFF (parallel_gate banked 0/DIFF on an rtu_match MATCH): jtbl_carve.set_overlays_var
regenerated resident_JTBL_INTERLEAVE from the carve set and DROPPED the resident's `--pre hdr.rodata.o`
(§8f leading-rodata sandwich); make extract refused (ld_interleave: hdr.rodata.o would be parked with
.text), the build linked the STALE script (249,252 differing bytes from file offset 0x4), and
harvest_verify._jtbl_prep_one never read the post-carve extract's exit code (R49/R61).
- FIXES (R35/R40/R57): jtbl_carve._merge_pre carries an existing --pre forward (idempotent; overlays
unchanged, 4-shape unit control); harvest_verify refuses loudly on a failed post-carve extract and
restores the snapshot (CARVE refusal, NOT a draft verdict); interleave_check's anchor accepts a leading
--pre (was a false DRIFT n=0 on the resident; control ov_SC02_017 ALIGNED n=44 unchanged).
- cookbook §498 (+ the stale-asm-after-a-failed-extract sequencing law); SETUP rows for all three
- _type_names returned the TAG for `typedef struct Rec801806C8_s Rec801806C8;`, so the typedef block and the
tag's own packed struct definition collided under one key with different bodies and the R43 "CONFLICTING
bodies — a rename is needed" refusal fired on legal C. Now keyed by the alias (_TYPEDEF_TAG_ALIAS); the
`carried` set learns the alias; `typedef struct X X;` (alias == tag) keeps the old key so a second one
still dedupes/refuses. Unit control on 7 block shapes PASS; ov_SC02_017 --only func_80186C64 --dry-run:
2 region files, no carve repoints. cookbook §497; SETUP row.
- jr_isolate_all resident --only func_800D128C: [0x4 c resident] [0x12ec c resident_jr_800D00E4]
[0x2494 c resident_jr_800D128C]; the banked jr func_800D00E4's .rodata carve + JTBL_PADS + --order
repointed to resident_jr_800D00E4.o (config/overlays.mk resident block only, R60); make extract +
make build BINARY=resident -j8 rc 0, sha 8e17e02ff8954d07c979449198f7e1645046b353 == check (R53)
- TOOL FIX (R43/R33): the carried-type test consulted _engine_types() (engine_types.h + common.h) for
every TU, assuming each region includes engine_core.h; the resident includes only common.h, so its
file-local `typedef struct {...} CdFileLoc;` (a name engine_types.h also defines) was silently NOT
carried -> `parse error before cdFileLocTable` in both region TUs, build rc 2 while the stale binary
on disk read green. Now _provided_types(header) derives the set from the TU's own #include lines
(engine_core.h => engine_types.h + common.h, never engine_core's macro-internal typedefs; common.h
=> common.h) and _file_scope_decls(items, provided) uses it at both decision points. R39 controls:
overlay header == legacy set (1,197 names); resident set lacks CdFileLoc. cookbook §496; SETUP row
- rtu_match func_800D128C --split resident_jr_800D128C: MATCH (243 ins) on the stored S71 draft;
the gate is the next commit
Stubs 32 -> 31 after the func_80015760 bank (commit:3877); R22 fleet 213/213 (.run/S79_check_all_8.log);
main game-code 93.5% (38,854 / 41,534). Permuter ILS plateaus recorded with their residual named:
func_80015608 best 1, func_80039B20 best 7, func_80038698 pinned seed refused (11). The ILS runner
had reported "no waypoint" for 8 cycles in 20 s on a seed the permuter's C parser rejects; it now
prints [permuter] REFUSED and leaves PERMUTER_REFUSED.txt (positive-controlled on func_80038698).
Stubs 35 -> 32 after the #7 banks (commit:3873 commit:3874); R22 fleet 213/213 (.run/S79_check_all_7.log).
ov_SC05_018:func_80180BE0 and ov_SC06_010:func_801809E4 have NO draft: their ledger drafts were other
overlays' same-named functions (.run/backlog_drafts/<fn>.c is keyed by bare fn name) -> drafting pool.
config/wave_exclude.txt: main:func_80011380 pinned WALL with the §474 proof (fold-const split_tree +
stupid.c adjacency), 4 entries.
Stubs 38 -> 35 after the #6 banks (commit:3868 commit:3869 commit:3870 commit:3871); R22 fleet 213/213
(.run/S79_check_all_6.log); frontier_classify 35 rows (main 16, md_MAIN_003 5, resident 2, ov 12).
jtbl_pads_fix's PAD_ERR_MORE regex carried jtbl_rodata_pads' old wording and reported "no
pad-count drift" over a red build; it now accepts both spellings and, positive-controlled with a
deliberately short spec, reports "emits >4 table(s), spec declares 4". The deferred carves and
their blockers are itemised in §491 and in the checkpoint's task #7 brief.
800c3 (0x8005CE18-0x8005FC68, one contiguous run of 33 interleaved Sony objects) is now four
stub rows — libapi1 (21 BIOS trampolines + COUNTER), libpad1 (PADENTRY + PADMAIN 760), libapi2
(L02/L03), libpad2 (PADCMD PADIF PADPORTD PADSEQD WAITRC2) — fed by two WINDOWED psyq_integrate
calls from the raw .run/obj42/{libapi42,libpad421} dirs (integrate tiles each stub with one
library; every boundary checked against .text SECTION sizes). The apicard region's three
"game code" rows were libapi 4.2's C objects to the byte: 800c2 = FIRST.o (firstfile + the
"no jump table wall" stub func_80062144), 800c2_2 = PAD.o, 800c2_3 = PATCH.o + CHCLRPAD.o ->
apicard5/6/7; make_apicard_used.py sources libapi from 4.2 (the EXE's real libapi; libcard
stays 4.0) into .run/obj42/apicard_used, 26 objects / 7 blocks, no game code left in
0x80061F38-0x80062888. src/800c3.c (129 hand-matched "C", 62 verbatim bodies, 19 stubs incl.
the four §332 %lo-in-a-delay-slot "walls"), src/800c2.c, src/800c2_2.c, src/800c2_3.c removed;
REORDER_TUS is empty (mechanism kept). Cookbook §490.
Two stale instruments fixed: exclude_audit let a pinned WALL outrank LINKED (PopMatrix/
PushMatrix had sat as walls since S68 while living in libgte3, linked since Phase 8) — LINKED
dominates now, config/wave_exclude.txt 13 -> 3; frontier_classify carried a hard-coded 49-name
LINKED set (R51) and reported 337 "stubs" — derived from the Makefile now.
Verified: main 143dbb89f34491258bbc27810d0a12ec8b43a8dd WITH all SDK dirs and WITHOUT them from
a fresh extract; make tools-health OK; R22 fleet extract-all 212/212 + check-all 213/213.
Metrics: main REAL 839->773, LINKED 1,150->1,256, VERBATIM 29->3, stubs 29->16, byte-identical
2,075/2,091 = 99.2%; game-code weighted 93.3% (38,748/41,534), remainder 2,786 = the open-stub
sum; fleet stubs 51->38 (frontier_classify: 39 rows incl. the data word). Verbatim manifest
33 -> 6. Docs: worklist rows + "S79 task #5", SETUP (fresh-clone obj42 commands, Makefile
blocks, exclude_audit), decision-log "S79 addendum 2", accelerators "S79 (2)", CURRENT_PHASE
S79 FINAL refreshed (census, metrics, the task #6 brief).
The bounded hunt succeeded on its first lead. archive.org item
`play-station-programmer-tool-runtime-library-version-4.2.7z` (383 KB) is the PsyQ Runtime
Library 4.2 (LIB/*.LIB + INCLUDE, 1998-01-21) plus LIB/42PATCH/J421PD.ZIP — SCE R&D's
1998-02-26 "Libpad.lib version 4.2.1 for the Analog Controller (DUAL SHOCK)" patch, shipping
LIBPAD.LIB 4.2.1 with LIBAPI.LIB 4.2 and LIBPAD.H/LIBAPI.H/KERNEL.H.
Placed and byte-verified against the EXE (psyq_identify 0x8005CE18-0x800629DC, then
psyq_link.py per object): libpad 4.2.1 7/11 — PADENTRY, PADMAIN (760 ins, the 4.2.1 build,
exact), PADCMD, PADIF, PADPORTD, PADSEQD, WAITRC2 — and libapi 4.2 39/88 — the 21 band
trampolines, COUNTER, L02/L03, and the apicard-region C112/A50/A51/A54/A65/A67/A69/FIRST/A66/
PAD/A18-21/PATCH/CHCLRPAD. All 46 PASS. Neighbours for the record: plain libpad 4.2 and the
4.3 disc (DTL-S2340, 1998-05-18; PADMAIN 832 / PADIF 380 / PADSEQD 292) each place only 4;
4.2.1 is the unique exact match, so the game was built between Feb and May 1998.
Banked (R20): the 7z tracked under tools/psyq/ with sha256 + provenance in CHECKSUMS.sha256;
extracted to gitignored tools/psyq/lib42/ and lib421/ (the 4.2.1 headers are the band's
prototype oracle from now on); ELF in .run/obj42/{libpad421,libapi42}. Docs: psyq-worklist
"S79 task #13", SETUP archive table + §5.1 + S79 tool table, CURRENT_PHASE (#13 log; the S79
FINAL block's §5 records the archive and §6 is the re-scoped task #5 brief: link the whole
0x8005CE18-0x8005FC68 band and re-source the apicard region's libapi from 4.2).
The §9.1 "scattered .bss commons" exclusion class (Phase 8 → P31) is closed 3/3. New
tools/psyq_bss_split.py (own ELF32 REL reader/writer) cuts an object's packed .bss into
per-base NOBITS pieces: bases derived from the game bytes per HI16/LO16 pair, references
walked in offset order into single-base runs, cuts snapped to symbol starts (the linker
scattered SYMBOLS), symbols moved, a LOCAL section symbol per piece inserted, relocs
retargeted with the addend rewritten in the immediates, self-diffed. It runs inside the one
prepare step shared by psyq_link.link_object / psyq_link_region.build_region /
psyq_integrate.integrate (prepare_object before classify), re-derived every build.
GS_001.o was certified "5 interleaved bases, NOT splittable" by the S77 probe, which grouped
by BASE; by RUN it is six symbol-aligned pieces. All seven cuts across the three objects are
confirmed by the other objects' by-name recoveries (_que 0x800C5510, _svm_sreg_buf
0x800B9B58, PSDBASEX/CLIP2/PSDBASEY/POSITION/GsDRAWENV). R39 negative control: 235 placed
objects across 9 curated dirs, 0 refusals, exactly 3 splits (a libcd .bss+size end pointer
refused the first build → reference problems are fatal only when a split is needed).
Wiring: yaml 800c→libgpu2, sgap_6→sgap_6+snd12, gsgap3→libgs8 (comments rewritten);
LIBGPU_ELF := .run/obj40/libgpu (curated libgpu_used retired); libgs 34 objs/8 blocks
(make_libgs.sh +GS_001); snd 63/12 (make_snd_used.py exclusions 4→3). src/800c.c and
src/gsgap3.c removed (Sony code hand-matched as REAL/verbatim), sgap_6.c keeps only
func_8003FA54; splat-emitted libgpu2.c/libgs8.c/snd12.c stubs for the no-SDK fallback.
Verified: main 143dbb89f34491258bbc27810d0a12ec8b43a8dd WITH the SDK objects and WITHOUT
them from a fresh extract; make tools-health OK; R22 fleet clean extract-all 212/212 +
check-all 213/213. Metrics: main REAL 886→839, LINKED 1,040→1,150, VERBATIM 85→29, stubs 29
(unchanged); game-code weighted 91.1% (40,895/44,870) — both terms lost the 3,667 SDK ins;
the remainder is still exactly the 3,975-ins open-stub sum. Verbatim manifest --update
200→33 rows (subtractive). Docs: cookbook §489 (+index), psyq-worklist rows + "S78 task #4",
SETUP S79 R21 table, decision-log S79 addendum, accelerators S79, CURRENT_PHASE S79 FINAL 🛑.
- exact tiles, 0 tokens: libgte23-26 (MSC01/02/05/09, SMP_00, FGO_01-06, PATCHGTE), libgte9 re-derived
as SMP_05 NormalClip (SMP_06 NormalClipS = nested sub-pattern; psyq_integrate now drops nested
placements), libgte27-30 (the libgs-gap MTX_05/07/11, REG03+REG11), libgs7 (2D_BG0+2D_BG1), snd10
(VM_NO1), snd11 (VM_NOWON carved off sgap_8). LINKED 959->1040, REAL 912->886 (SDK inline-asm wrappers
re-provenanced), VERBATIM 146->85, 13 TUs deleted; splat re-emits the stub records.
- main 143dbb89 WITH and WITHOUT the SDK objects. The no-SDK fallback had been red since S7x
(CdReadyCallback called by its SDK name while the libcd stub carried func_800435B4) — curated
CdReadyCallback = 0x800435B4, refs unified. R22 clean fleet 213/213; tools-health OK.
- METRIC CORRECTION (R35): progress.py's "MAIN game-code weighted" sig never excluded the LINKED
objects (its comment said it did) — ~31k linked-SDK ins sat in the denominator as unmatched game
code. Exclusion now derived LIVE from the Makefile stub lists + yaml ranges: 91.8% (44,562/48,537),
not 59.8%; the 3,975-ins remainder equals the open-stub sum exactly.
- VM_F.o probed SPLITTABLE at .bss 0x50c (SYS.o's class -> task #4). cookbook §488; worklist S78 #3;
decision-log + accelerators; SETUP rows.
- provenance: the psx loader's per-version PsyQ signature sets place PADENTRY/PADCMD/PADPORTD/
PADSEQD (4.2), WAITRC2 (4.3), COUNTER/C114/FIRST/PAD/PATCH/CHCLRPAD (libapi 4.2) byte-exact in
0x8005CE48-0x8005FC68 / 800c2 -> 12 of main's 29 stubs incl. all four §332 walls are Sony's
DualShock library in reorder mode. 46 names -> symbols.us.txt (count 1081), band TUs, verbatim
manifest, wave_exclude; firstfile/firstfile2 (4.2 naming); CdGetToc @0x800430B8 (was the Phase-21
xdedup mislabel DecDCToutCallback). SETUP §5.1 corrected; psyq-worklist S78; cookbook §487;
decision-log + accelerators S78; CHECKSUMS +Psy-Q_46.zip +PSYQ_SDevTC_v4.5.zip.
- psyq_integrate: --yaml maps stub<->objects by SUBSEG RANGE with an exact-tiling check and PRINTS
the located-but-unwired residue (libgte: 13 objs / 1,264 ins) — main's LINKED build had been RED
at HEAD since the S77 psyq_identify fix (22 libgte blocks merged to 3; gate worktrees take the
stub fallback so it never showed); a library object's exported symbol whose recovered address the
curated file names differently is --redefine-sym'd (R15; A66 firstfile->firstfile2).
- Ghidra: 47 MCP renames did NOT persist through the sentinel stop (R9 caught it) -> NEW
tools/ghidra_scripts/ApplySymbols.java + tools/ghidra_apply_symbols.sh mirror the curated file
headless with a real save: 73 renamed, R9-verified x4. SETUP inventory rows (R21).
- lint_symbol_refs: scans verbatim __asm__ bodies (`.ent\tfunc_X` is invisible to \b and to the
string-masked scan); negative-controlled (red on the pre-fix TUs, green on the passing tree).
- R22: clean extract-all 212/212 + check-all green on the final config; main rebuilt byte-identical
143dbb89 after the last src-only fix -> 213/213; tools-health OK.
The fleet report still printed 'caveat is R34: no independent second oracle for
a PS-X EXE'. That was true until this session; make sig-main-oracle +
audit-corpus now cover main at 0 phantom / 0 truncated / 1 explained pad-tail.
A stale caveat is the same class of false statement as a stale wall verdict.
The yaml has excluded SYS.o/GS_001.o/2D_BG0.o/VM_NO1.o from the LINKED build
since Phase 8 for 'scattered-.bss commons ... no single NOLOAD base reproduces
it'. Every word of that is true, and it does not imply unlinkable.
psyq_bss_probe derives each object's .bss bases FROM THE BYTES (for each
HI16/LO16 pair against the bare .bss section, the object's immediates give the
addend and the game's give the resolved address, so base = resolved - addend)
and then asks the unasked question: are the offset ranges DISJOINT?
SYS.o 3,109 ins 2 bases 0x0000-0x0044 @ 0x80078830
0x0148-0x0150 @ 0x800c53cc -> SPLITTABLE at 0x148
GS_001.o 384 ins 5 bases interleaved -> the genuine wall
2D_BG0.o 526 ins NO .bss -> reason cannot apply
VM_NO1.o 305 ins NO .bss -> reason cannot apply
§9.2's escape (weaken the .bss symbol, --defsym it) really cannot reach these —
a relocation against the bare SECTION has no name to defsym — and that is what
made 'unlinkable' look like the conclusion. But a section reference only needs
the section PLACED, and a section can be split.
Completeness checked before believing it (R32): the probe counts .bss refs from
EVERY section; SYS.o's .data has zero, so the two-way split covers every
reference. Placement is derived, not configured — the object is located by
masking relocated fields and requiring a UNIQUE match, which independently
reproduced SYS.o @ 0x80059234 / 3,109 ins, agreeing with both the yaml subseg
bounds and the manifest's psyq_identify count.
Incidental: src/800c.c is 100% SYS.o (its span is exactly the object's .text
size), despite the subseg comment calling it '-O2 game code'.
Cookbook §484; yaml comment corrected in the same change.
The roadmap's completion contract requires both audit oracles green before any
100% claim on main, and main had none: audit-corpus covered overlays and
resident only, and R34 is explicit that the byte gate is a perfect CORRECTNESS
oracle and a NULL COVERAGE oracle — green whether a function was sliced right
or invented, because the .s pieces paste back either way.
sig_image gains multi-range signing, closing all three blockers
docs/second-oracle.md scoped:
* the 0x800 PS-X EXE header -> --vram-base 0x8000F800 puts file offset 0 at
vram, so the header falls below the first range
* interleaved data + linked islands -> --segments derives 28 game-code ranges
from the splat yaml's SEGMENT rows
* one text range -> the signer loops ranges, bootstrapping INSIDE each, which
is what stops the linear partition running through a data island and minting
functions out of it (the detector manufacturing the class it detects)
INDEPENDENCE IS PRESERVED, NOT WORKED AROUND. Ranges come from segment TYPES,
never from splat's function boundaries; entries are still found by byte-derived
jal-closure. Seeding from splat's symbols would make every phantom look real —
the trap the design doc names. .run/sig.main.jsonl (the splat-SEEDED atlas sig)
is a different file and corpus.ORACLE_SIG keeps the audit off it.
RESULT: 986 functions signed. main audit = 0 PHANTOM, 0 TRUNCATED, 1 PAD-TAIL.
Fleet audit-corpus = 0 + 0, unchanged for resident and overlays.
NEW AUDIT CLASS, from the first real finding. func_80062144: splat .s 65 ins,
oracle 64 — the extra line is a nop one line BELOW endlabel. That is an
alignment pad the matching side already emits from C (§295; two S77 wave agents
did it on func_8005E13C and func_8005D538), not a mis-slice. Lumping it with
TRUNCATED would make the oracle's first finding look like a defect and bury the
class that is one.
COVERAGE ASSERTED both ways before trusting it (R32): all 30 game-code stubs
fall inside a range, and 0 of 199 addr-parseable LINKED stubs do.