Commit Graph

843 Commits

Author SHA1 Message Date
Drew T 936d7d741c feat(phase-33): B5 Ghidra regenerability PROVEN — the RE work as text (config/ghidra/*.jsonl + ROSTER.md), six programs rebuilt from disc + symbol files + that file with PROOF PASS
- ImportAnnotations.java: the S86 OSGi-bundle blocker was 3 javac errors (Long->int unboxing x2, a nonexistent
  LocalVariableImpl ctor -> VariableStorage); "/undefined" resolves to DataType.DEFAULT (it lives in neither type
  manager — main's first proof passed the cmp with failed=13 because the plate-comment rows had set the same function
  comments); ghidra_rebuild.sh now dies unless the import printed failed=0 (R49), writes .proof markers
- ghidra_annotations_delta.py: analysis drift measured and encoded as three counted classes — Error/Analysis bookmarks;
  auto-named DEFAULT functions the rebuild did not create (29 in main's LINKED regions); auto-named rows lagging the curated
  symbol file (10 sep8 + 5 aug31, R15). Result: main 38 hand-authored rows (13 annotated fns incl. 3 the ELF does not
  define, 22 comments, 3 labels); resident/overlays/protos container rows only; the DB holds no hand-authored types
- controls (R39): mutated block row -> PROOF FAIL; synthetic comment/bookmark/label/signature round-trip -> PROOF PASS
  twice (idempotent); the filter keeps the synthetic rows and a hand-renamed name-only diff; fake failed=2 refused,
  resident re-proven; roster --check controls both ways
- proofs, all PASS failed=0: resident 65s, ov_SC01_077 169s, ov_SC06_018 173s, SLUS_007.26 210s, sep8 202s, aug31 206s
- tools/ghidra_roster.py -> config/ghidra/ROSTER.md (--check in tools-health, ignores the per-machine proof column)
- .claude/settings.json hooks $CLAUDE_PROJECT_DIR-relative; ghidra_mcp_start.sh is a silent exit 0 without Ghidra or
  the project (both controlled); SETUP P33 B5 section + 5 inventory rows + §2.8 (R21); CURRENT_PHASE log + checkpoint
2026-09-06 20:32:35 -06:00
Drew T 6e37e8ec62 docs(phase-32): T4c harvest + checkpoint — the frontier is EMPTY (census 0 stubs / 0 ins); cookbook §501-Q (the combine self-update ghost slot) + §501-R (a hoisted invariant read three times: inline temps merged by combine_movables, u16 as a cse firewall, the allocation order IS the callee-saved bank; every pin came off), accelerators (15)(16), decision-log P32 S85 T4c, tools/cc1_dumps_tu.sh + tools/alloc_table.py promoted (+ SETUP rows, cc1_dumps.sh -dL), wave_exclude 0 entries, backlog 1 legacy row, .run/P32/t4e (56 variants, 18+8 reproducers, NOTES, banks, slates); 🛑 checkpoint refreshed as the T5 seed (the fleet R22 + report chain runs in the background — its logs are recorded by the next session) 2026-09-06 16:13:19 -06:00
Drew T b6fd3fff28 docs(phase-32): T4b hand pass — func_80032A74 PROVED at 1 by producer census (§501-M); ghost_census.py + cc1_dumps.sh repair; backlog tie-break repair
- main:func_80032A74 (422 ins, closeness 1): the residual is ONE reload-time slot at sp+0x48 (u16 draft = 422/422 code, DIFF 22 frame
  rows; s16 draft = DIFF 1 at idx 244 lh vs lhu). Every post-parameter slot producer enumerated from gcc-2.7.2 (reload1.c:658 ghost
  alter_reg / caller-save.c:249 area / reload1.c:879 invalid-equiv / reload1.c:3499 spill_stack_slot) and refuted on the bytes: combine's
  newi2pat ghosts re-derive a narrow load and the site is lhu (no lb, no double load); a save area without sw/lw needs sched.c:4962
  staleness and no register-only insn shares a block with a call; $t0 holds no pseudo; LO mult results retry into GR_REGS. Verdict
  PROVED at 1 (pin kept with the verdict; ledger WALL-PROVED).
- NEW mechanism measured: local-alloc.c optimize_reg_copy_2 (tmp = x; tmp op= c; x = tmp) mints a ghost with stale refs, but after
  regclass -> GR_REGS, allocated, no slot (P13/P14). 18 isolated reproducers, 0 draft variants; cookbook §501-M; accelerators (12).
- tools/ghost_census.py (new): ghosts in a .lreg dump with their class (ST_REGS => slot). tools/cc1_dumps.sh: prints the .frame line,
  ins count, spill lines and the census; the under-counting standalone-(use) grep is gone. SETUP rows (R21).
- tools/backlog.py: load_best kept the EARLIEST record at equal closeness (docstring said latest) — the S84 row never rendered; fixed.
- CURRENT_PHASE.md: S84 log + refreshed 🛑 checkpoint (rows (b)(c)(d) next, then T5). No src/config/carve change; fleet check-all
  218/218 rc 0 at the S84 preflight.
2026-09-06 11:44:40 -06:00
Drew T 444e8ab4b5 docs(phase-32): T4b (10) ledger — func_80011380 unpinned (1 wall remains: func_80032A74), backlog re-rendered, the Fable draft + report + verdict kept 2026-09-05 23:22:09 -06:00
Drew T 3c6d20991f docs(phase-32): T4b — func_80032A74 stays NEAR 1 (Fable, 402k tokens): the 0x48 slot is a GHOST pseudo (combine.c:2306-2313), the caller-save-area hypothesis REFUTED with citations, the only memory-value ghost species is the lh SIGN_EXTEND split; pin annotated, backlog row, draft + report kept 2026-09-05 18:35:27 -06:00
Drew T 1081b02b66 docs(phase-32): T4b (6) ledger — func_801834A4 unpinned (2 walls remain), backlog re-rendered, the Fable draft + report + verdict kept; queue updated 2026-09-05 18:25:29 -06:00
Drew T 9564314095 docs(phase-32): T4b (5) ledger — func_80020DA4 unpinned (3 walls remain), backlog 11 open, the Fable draft + report + verdict kept; resume queue (3-at-a-time) tracked 2026-09-05 18:16:50 -06:00
Drew T 32ff170bf3 docs(phase-32): T4b (4) ledger — func_8017DF28 unpinned (4 walls remain), backlog re-rendered, the Fable draft + report + verdict kept; bank.sh takes SPLIT for _jr_ TUs and prints rtu's tail when no verdict line appears 2026-09-05 13:28:35 -06:00
Drew T d913bca9b7 docs(phase-32): T4b (2) ledger — func_80039DEC unpinned (5 walls remain), backlog re-rendered, the Fable draft + report + verdict kept (R20) 2026-09-05 13:20:36 -06:00
Drew T 177f4a7dfd docs(phase-32): T4b (1) ledger — func_800391D4 unpinned (config/wave_exclude.txt 6 kept / 1 dropped by exclude_audit), backlog re-rendered (15 open), the Fable draft + report + verdict kept (R20) 2026-09-05 13:15:53 -06:00
Drew T 90acd6902f docs(phase-32): T4 DONE — the walls' FINAL ledger: 7 pinned rows re-probed in TU context (3 CC1 FAILs were plumbing, re-probed in a sandbox TU), 1 PROVED + 6 CANDIDATE, no verdict changed; pins annotated, backlog rows for all 7 (R62 paths fixed), cookbook §500-I, decision-log
- every wall's best draft re-run with rtu_match in its CURRENT real TU: func_80011380 DIFF 6 (--o0, §474 PROVED),
  func_80020DA4 DIFF 2, func_8017DF28 DIFF 2, func_801834A4 DIFF 6 ×3 variants; leaf match_one re-measured the CC1 rows
  (func_80032A74 1, func_80039DEC 2 permuter / 9 sonnet, func_800391D4 3)
- the three CC1-FAIL rows: func_80032A74 = 7 typedefs the TU provides via 800_shared.h + 4 decl spellings → synced copy
  (.run/P32/t4/drafts/func_80032A74_tuclean.c) DIFF 1 in the real TU (idx 244 lh vs lhu); func_80039DEC = the TU's narrow
  prototype (800_c.c:3496) vs the K&R def → sandbox TU (.run/P32/t4/tu/, no-proto decl) DIFF 2; func_800391D4 = the
  load-bearing `D_80073140[][1]` vs the TU's `[]` → sandbox TU DIFF 3 (TU-compatible spellings regress to 65 @ 76)
- config/wave_exclude.txt: each of the 7 lines carries its S83 re-probe verdict; exclude_audit --assert-fresh 7/7
- backlog: rows for all 7 walls (the path-less func_80011380/func_801834A4 given existing drafts, R62; two rows re-logged
  after a shell-quoting mangle); docs/backlog.md 16 open
- CURRENT_PHASE.md: T4 row DONE, the wall ledger table (row · ins · class · leaf/real-TU closeness · mechanism+citation ·
  attempt record · verdict · best draft; func_800CF3E8 listed as an unpinned candidate), the T4 log entry, 🛑 block → T5
  (R27 Max prompt + the gate-2 procedure)
- cookbook §500-I (the sandbox-TU re-probe method + the verdict table); accelerators (8); decision-log P32 S83 (R31)
2026-09-05 12:11:10 -06:00
Drew T 5ff842dfd3 feat(phase-32): T3 (3) — resident: func_800D06E8 (344 ins) BANKED byte-identical 8e17e02f — THE RESIDENT IS 100% C (145/145)
- the Opus drafter recovered the closeness-0 body the journals (attempts 1-3) pointed at (.run/S71b_1/fable/) — the
  pack's inline 292-draft was the wrong one — and found the real blocker: the TU defines Struct80078E78 AFTER the
  slot with a layout lacking bytes 0x36/0x37; only a BLOCK-scoped typedef under a distinct tag (Blk80078E78) + a
  block-scoped extern compiles (decl-hoisting resolver variants recreate the S7x 'conflicting types'). Idioms:
  §162k1 QImode (u8)(c-3)<2; explicit flag temp t=(u32)(r-0x64)<0x1E, s1=t^1; switch decision trees for both
  currentLocationId dispatches. reloc_identity AGREE 50/50; rtu_match MATCH 344/344 (verified by the coordinator)
- jtbl_carve --func: jtbl_80113FA4 (5 words, the old tail2) joins the resident_jr_800D00E4 .rodata piece
  (0x450e0..0x451c0, JTBL_PADS 0,0,0,0, tables +0x0/+0x3c/+0xb4/+0xcc); carve set 5 -> 4 pieces, --pre kept
- make extract + make build BINARY=resident -j8 rc 0; sha 8e17e02ff8954d07c979449198f7e1645046b353 == check;
  pads_audit ok/ok; interleave_check ALIGNED n=4
2026-09-05 01:03:07 -06:00
Drew T 1e843c607a feat(phase-32): T2b (4) — SC03/56 ONBOARDED as md_SC03_056 @0x801CBB50 (ov_SC03_002's DESTPTR), byte-identical bc768a6b; ALL FIVE parked payloads are now binaries (fleet 213 -> 218); evidence tool v2
- md_SC03_056 (TEXT_LO 0x4, 4 stubs / 61 ins): 15/17 pointers cluster inside at 0x801CBB50; one outward call
  (0x8018151C) hits a function only 3 overlays have, ov_SC03_002 among them; req_fit 9/9 for ov_SC03_002
- payload_base_evidence.py v2 (controls 7/7 throughout): (a) STRONG = internal jals + fn-ptr-table entries on the
  module's own starts >= 2 (SC03/53 STRONG); (b) OUTWARD-EXPLAINED — a pure jal-vote base whose "internal" targets
  are function starts of the fleet's overlays is downgraded: SC03/56's 0x80178C8C was two SHARED-engine functions
  spaced like two of its five starts (and nobody's DESTPTR), a false STRONG; (c) the requester cross-check is
  informational only — shared engine code makes every requester fit (an R39 control caught it scoring: 6/7)
- memory-map §S45 p7 amended: all five rows ONBOARDED + the two instrument findings (the first build is a NULL
  oracle for FINE base errors — +8 builds byte-identical, +0x1000 fails the link; outward-explained vote bases);
  SETUP row amended. The parked-for-L3 ledger is EMPTY pending `make audit-disc` (T2c).
2026-09-04 23:52:58 -06:00
Drew T b52d67be0b feat(phase-32): T2b (3) — SC03/53 + SC03/54 ONBOARDED as md_SC03_053 / md_SC03_054 @0x801EF468 (the script slot), byte-identical c0848f30 / 06bd73df
- md_SC03_053 (TEXT_LO 0x4, 15 stubs / 372 ins) and md_SC03_054 (TEXT_LO 0xF0 — a 19-entry fn-ptr header, 7 stubs
  / 764 ins) share ov_SC03_001's DESTPTR slot 0x801EF468, the slot the S45 tracer watched other SC03 scripts load into
- BASE EVIDENCE (memory-map §S45 p7, static-derived STRONG at 0x801EF468 and nowhere else): SC03/53 — 52/75 absolute
  pointers inside, 3 of them + its one internal jal exactly on its own function starts (0 at every rival); SC03/54 —
  106/115 pointers inside, 5 header-table entries exactly on starts (0 at every rival); lui 0x801F ×18 / ×46
- first builds byte-identical (base-lenient, R34 — the base rests on the alignment; the first internal-call C bank
  byte-proves it); the §S45 p6 "onboard at 0x801EF468, let the first build decide" step, finally run
2026-09-04 23:51:45 -06:00
Drew T 10aaf5c296 feat(phase-32): T2b (2) — MAIN/9 ONBOARDED as md_MAIN_009 @0x800CD348 (TEXT_LO 0x3C), byte-identical d270f695; the OPDEMO1 module leaves the parked ledger
- tools/new_binary.sh md_MAIN_009 extracted/retail/MAIN.CD.dir/FILE_009.dir/0.1 0x800CD348 0x3C -> first build
  BYTE-IDENTICAL sha d270f695b793b5c03db159b7aabcc066daa87eda; 11 stubs (609 ins); window 0x800CD348..0x800CDD38
  lies below the resident's symbol region, so the default symbol stack stands (no A4 edit)
- BASE EVIDENCE (memory-map §S45 p7, static-derived STRONG): 6/6 internal jals and 9/9 absolute pointers land
  on the module's own function starts at exactly ONE base, 0x800CD348 — inside slot B's region (+0x82C from
  0x800CCB1C), not a previously known slot; lui 0x800C/0x800D ×51. Same caveat as md_MAIN_007: the first build
  is base-lenient (R34), the base rests on the alignment and will be byte-proven by the first internal-call C bank.
2026-09-04 23:51:08 -06:00
Drew T 1a696a851a feat(phase-32): T2b (1) — MAIN/7 ONBOARDED as md_MAIN_007 @0x800CEDF8 (TEXT_LO 0x34), byte-identical 2ff702b6; the OPDEMO0 module leaves the parked ledger
- tools/new_binary.sh md_MAIN_007 extracted/retail/MAIN.CD.dir/FILE_007 0x800CEDF8 0x34 -> first build
  BYTE-IDENTICAL sha 2ff702b605ab5cfc18474c464c4c07e5f8ffd48c; A4 applied (symbols.resident.txt not stacked —
  the window lies inside the resident's symbol region), re-extract + rebuild byte-identical; 19 stubs (802 ins)
- BASE EVIDENCE (memory-map §S45 p7, static-derived): STRONG — 9/9 internal jals and 14/16 absolute pointers
  land on the module's own function starts at 0x800CEDF8 (the boot slot of md_MAIN_001/008/011); lui 0x800C/0x800D
- HONEST CAVEAT (R34, measured 2026-09-05): the all-INCLUDE_ASM first build is a NULL oracle for FINE base
  errors — the same payload builds byte-identical at 0x800CEE00 (+8) — and catches only GROSS ones (at +0x1000
  two internal jal targets leave the window: `undefined reference to func_800CEEA4/func_800CF3F4`, link fails).
  The base therefore rests on the static alignment, and will be byte-proven by the first C bank that calls an
  internal sibling. Controls: .run/P32/t2b/{control_full,control_fine}.log
- registered in modules.mk + the report/diff dicts (R36 citizenship asserted by tools-health at T2c)
2026-09-04 23:49:05 -06:00
Drew T 059266afca feat(phase-32): T1c — md_MAIN_034: func_800CB00C (123 ins) BANKED byte-identical 46153c06 from the stored S72 body; its S68 "compiler wall" pin dropped
- the census's best_draft (.run/wave_g0c/shard30, 174 ins, 7 pins) was a DIFFERENT, wrong body under the bare
  name (R48); the journal (R38) named the real one — .run/O21/opus/func_800CB00C.c (88 lines, 7 BLOCK-scope
  callee externs: gcc-2.7.2 demotes the later-definition type conflict to a warning at block scope). rtu_match
  MATCH 123/123 in the real TU (the S75 redraft too); the S72 resolver had gated only the wrong file, 3x.
- raw splice into src/md_MAIN_034/md_MAIN_034.c; module island pads derived at build (§303); make build
  BINARY=md_MAIN_034 -j8 rc 0, sha 46153c06bca859dec05aff59fb1a77d3add3d02b == check (R53); verbatim strict ok
- config/wave_exclude.txt regenerated (exclude_audit --write): the md_MAIN_034 WALL pin labelled a wrong draft,
  not a wall — 8 -> 7 entries; docs/backlog.md re-rendered (matched rows drop)
- 0 drafting tokens; no Sonnet agent needed (plan T1c adjusted: no redraft)
2026-09-04 23:38:03 -06:00
Drew T c7f5b498ac feat(phase-32): T1b (3) — ov_SC02_017: func_80186C64 (209 ins) BANKED byte-identical c0253499 — the d=2 RELOC-ONLY twin of ov_SC02_016:func_801810C8 via family_remap + four TU spellings
- family_remap --addr 0x801810C8 --from ov_SC02_016 --to ov_SC02_017 --to-addr 0x80186C64 (23 per-overlay
  symbols remapped); rtu_match then named four §376 TU spellings (func_8012A828 (s32, void *); D_801E0F44 s32
  — address-only use; func_80131E00 (); func_80185F88 (s32) — calls already fn-ptr cast) + one TU-provided
  typedef to strip (Prim_8016E7C8, §491 gap 2) -> MATCH 209/209 in the old TU and in the new region TU
- jtbl_carve --func: jtbl_801EE414 clamped to its `sltiu 6` (6 entries) into
  [.rodata, ov_SC02_017_jr_80186C64] + tail19; JTBL_PADS 0,0; carve set 45 -> 46 pieces
- make extract + make build BINARY=ov_SC02_017 -j8 rc 0, sha c0253499eed71309d731862ffc76766d183d031e ==
  check (R53); pads_audit all ok; interleave_check ALIGNED n=46; verbatim_check --strict no drift
- 0 drafting tokens (the journal's S69/S70 lever drafts carried the same body; R38)
2026-09-04 23:36:52 -06:00
Drew T 599dba3ba0 feat(phase-32): T1b (2) — ov_SC02_017: func_80186C64 isolated into its own code subseg [0x5eb0c, c, ov_SC02_017_jr_80186C64] (byte-identical c0253499)
- jr_isolate_all ov_SC02_017 --only func_80186C64 (CLEAN after the §497 carrier fix — no source rename);
  2 region files; make extract + make build BINARY=ov_SC02_017 -j8 rc 0, sha
  c0253499eed71309d731862ffc76766d183d031e == check (R53). Carve state only; the bank is the next commit.
2026-09-04 23:35:19 -06:00
Drew T c513e1fbbd feat(phase-32): T1a (2) — resident: func_800D128C (243 ins) BANKED byte-identical 8e17e02f via the raw splice + a 5-piece carve; three instrument fixes (§498)
- BANK: the stored S71 closeness-0 draft spliced into src/resident/resident_jr_800D128C.c; jtbl_carve --func
  carved jtbl_80113FB8 (119 entries, 1 pad word trimmed) + jtbl_80114198 into [0x451c0, .rodata,
  resident_jr_800D128C] + [0x453c4, data, tail3]; JTBL_PADS 0,4; make extract + make build BINARY=resident -j8
  rc 0, sha 8e17e02ff8954d07c979449198f7e1645046b353 == check (R53). pads_audit ok/ok; interleave_check
  ALIGNED n=5; verbatim_check --strict 5==5. Resident stubs 2 -> 1 (func_800D06E8 remains).
- WHY THE GATE SAID DIFF (parallel_gate banked 0/DIFF on an rtu_match MATCH): jtbl_carve.set_overlays_var
  regenerated resident_JTBL_INTERLEAVE from the carve set and DROPPED the resident's `--pre hdr.rodata.o`
  (§8f leading-rodata sandwich); make extract refused (ld_interleave: hdr.rodata.o would be parked with
  .text), the build linked the STALE script (249,252 differing bytes from file offset 0x4), and
  harvest_verify._jtbl_prep_one never read the post-carve extract's exit code (R49/R61).
- FIXES (R35/R40/R57): jtbl_carve._merge_pre carries an existing --pre forward (idempotent; overlays
  unchanged, 4-shape unit control); harvest_verify refuses loudly on a failed post-carve extract and
  restores the snapshot (CARVE refusal, NOT a draft verdict); interleave_check's anchor accepts a leading
  --pre (was a false DRIFT n=0 on the resident; control ov_SC02_017 ALIGNED n=44 unchanged).
- cookbook §498 (+ the stale-asm-after-a-failed-extract sequencing law); SETUP rows for all three
2026-09-04 23:28:59 -06:00
Drew T 380ccdc843 feat(phase-32): T1a (1) — resident code subseg split (3 regions, byte-identical 8e17e02f) + jr_isolate_all include-derived provided types (§496)
- jr_isolate_all resident --only func_800D128C: [0x4 c resident] [0x12ec c resident_jr_800D00E4]
  [0x2494 c resident_jr_800D128C]; the banked jr func_800D00E4's .rodata carve + JTBL_PADS + --order
  repointed to resident_jr_800D00E4.o (config/overlays.mk resident block only, R60); make extract +
  make build BINARY=resident -j8 rc 0, sha 8e17e02ff8954d07c979449198f7e1645046b353 == check (R53)
- TOOL FIX (R43/R33): the carried-type test consulted _engine_types() (engine_types.h + common.h) for
  every TU, assuming each region includes engine_core.h; the resident includes only common.h, so its
  file-local `typedef struct {...} CdFileLoc;` (a name engine_types.h also defines) was silently NOT
  carried -> `parse error before cdFileLocTable` in both region TUs, build rc 2 while the stale binary
  on disk read green. Now _provided_types(header) derives the set from the TU's own #include lines
  (engine_core.h => engine_types.h + common.h, never engine_core's macro-internal typedefs; common.h
  => common.h) and _file_scope_decls(items, provided) uses it at both decision points. R39 controls:
  overlay header == legacy set (1,197 names); resident set lacks CdFileLoc. cookbook §496; SETUP row
- rtu_match func_800D128C --split resident_jr_800D128C: MATCH (243 ins) on the stored S71 draft;
  the gate is the next commit
2026-09-04 23:20:04 -06:00
Drew T 452975e852 docs(phase-31): S80 #10 CLOSE — the verbatim end-state: manifest 6 → 5 rows (the five PERMANENT rows RATIFIED in _README; the GAME-C row decompiled), cookbook §495 (two def-side declaration walls, the S79 assembly "bank" P9 correction, the gate that dropped a bank on exit 0), decision-log S80 addendum (R31), SETUP rows; tools/parallel_gate.py: banked-but-not-merged now exits 2 with the worker's raw git status kept + per-run .run/pgate_runs/<ts>.json; CURRENT_PHASE #10 bullet + the S80 #10 CLOSE checkpoint (R22 213/213, tools-health OK, census 21 stubs / 4,554 ins, NEXT #11 = PhaseEnd, gate 2); regenerated digests 2026-09-04 22:07:35 -06:00
Drew T dd45617982 chore(phase-31): S80 #10 — verbatim end-state plumbing, byte-neutral: (1) ov_SC03_107:func_8017D878's file-scope __asm__ block (the manifest's one GAME-C row) converted back to an INCLUDE_ASM stub with tools/verbatim_to_stub.py --gate (87d02b57 byte-identical) and the TU's extern void func_8017D878(void) corrected to the real s32 (s32) signature (only its address is taken; ov_SC03_107 rebuilt byte-identical) — the void decl was the def-side wall that refused 37 drafts; (2) md_MAIN_020:func_800CB17C — S79 #7's "raw splice" had committed the function's ASSEMBLY as a verbatim __asm__ body (every stored 'draft' was the asm; verbatim_check --strict flagged it as a new verbatim) → converted back to a stub (0990e041 byte-identical): that bank was not a decompile (P9), the function is open again; (3) manifest _README: the five PERMANENT-VERBATIM rows RATIFIED 2026-09-04 21:45:31 -06:00
Drew T 09e0b27811 docs(phase-31): S80 #9c — the S79 drafting task's NEAR/WALL ledger: 15 rows logged to the backlog (each with the residual's gcc mechanism), the ≤3 residuals pinned as WALL candidates in config/wave_exclude.txt after an 8-seed permuter_ils sweep on the now-permutable pinned seeds (no score-0; func_80039DEC 9→2 = the K&R raw-preserve register, func_80023BF0 18→11 ADDRESSING, func_8017DF28's "1" was a divergent store rewrite — closeness stays 2, R14); cookbook §494 v2 (ten banks, the Opus verdicts' idioms: P_TAG bitfield store, inverted arms, sibling-reading, the 518-ins spelling laws, gdb-on-cc1 allocno arithmetic, K&R s16 params, true_dependence, field-boundary fences, extendhisi2 orphans, [][1] decls) + the final ledger; .run/S79w allowlisted (27 drafts + 3 permuter waypoints + verdict ledger + briefs, 264 KB — R20) 2026-09-04 21:21:05 -06:00
Drew T 96c0fc02a7 feat(phase-31): S79 #9 (7) — ov_SC05_010: func_8017FFA8 (88 ins, 6-way jtbl switch) banked from a Sonnet agent's fresh draft (loop index s32 not s16 — §241 fused sign-extend; the D_801922B8 lookup into its own temp before the found/zero stores); tail jtbl carve at gate time; worktree gate + in-tree byte-identical 2026-09-04 19:45:16 -06:00
Drew T 80ddd40d23 docs(phase-31): S79 #7 close — cookbook §492 (plumbing was three things: a raw-splice bank, an -O0 checker flag, two R48 same-name phantoms), census 32, report, backlog ledger, checkpoint (task #8 brief); func_80011380 pinned as the §474 proved wall
Stubs 35 -> 32 after the #7 banks (commit:3873 commit:3874); R22 fleet 213/213 (.run/S79_check_all_7.log).
ov_SC05_018:func_80180BE0 and ov_SC06_010:func_801809E4 have NO draft: their ledger drafts were other
overlays' same-named functions (.run/backlog_drafts/<fn>.c is keyed by bare fn name) -> drafting pool.
config/wave_exclude.txt: main:func_80011380 pinned WALL with the §474 proof (fold-const split_tree +
stupid.c adjacency), 4 entries.
2026-09-04 18:35:38 -06:00
Drew T 62475f7883 feat(phase-31): S79 #6 (3) — two twin banks: ov_SC04_018:func_80181CB8 (67 ins, tail jtbl carve, pads 0,0,0,0,4) and ov_SC05_005:func_80181828 (87 ins, exact clone of ov_SC05_003:func_80181720 via family_remap)
Both gated in parallel worktrees (parallel_gate, pinned at commit:3870) and rebuilt in-tree
byte-identical: ov_SC04_018 fe9b413f (after `make extract` — the merge changed the yaml carve
rows tail18-20 and the JTBL_PADS spec, and the main tree's split was stale until re-extracted),
ov_SC05_005 452897fc. The ov_SC05_005 remap needed two plumbing fixes: the TU's stale
`extern void` prototype (committed byte-neutral in commit:3870) and the draft's duplicate
Prim_8016E7C8 typedef (identical to the TU's, still a redeclaration for gcc 2.7.2).
2026-09-04 18:10:59 -06:00
Drew T af1644c02b feat(phase-31): S79 #6 (2) — ov_SC04_018: func_80181804 banked from its ov_SC04_019 twin (77 ins, byte-identical fe9b413f); its jump table was already inside the TU's carve, only the JTBL_PADS spec had been trimmed to 3 tables (S62) — now 0,0,0,0 2026-09-04 18:08:03 -06:00
Drew T 02f060f607 feat(phase-31): S79 #5 — the libpad 4.2.1 + libapi 4.2 band and the apicard region LINKED from real objects: 13 stubs + 4 TUs + the reorder island gone; main 16 stubs, fleet 38
800c3 (0x8005CE18-0x8005FC68, one contiguous run of 33 interleaved Sony objects) is now four
stub rows — libapi1 (21 BIOS trampolines + COUNTER), libpad1 (PADENTRY + PADMAIN 760), libapi2
(L02/L03), libpad2 (PADCMD PADIF PADPORTD PADSEQD WAITRC2) — fed by two WINDOWED psyq_integrate
calls from the raw .run/obj42/{libapi42,libpad421} dirs (integrate tiles each stub with one
library; every boundary checked against .text SECTION sizes). The apicard region's three
"game code" rows were libapi 4.2's C objects to the byte: 800c2 = FIRST.o (firstfile + the
"no jump table wall" stub func_80062144), 800c2_2 = PAD.o, 800c2_3 = PATCH.o + CHCLRPAD.o ->
apicard5/6/7; make_apicard_used.py sources libapi from 4.2 (the EXE's real libapi; libcard
stays 4.0) into .run/obj42/apicard_used, 26 objects / 7 blocks, no game code left in
0x80061F38-0x80062888. src/800c3.c (129 hand-matched "C", 62 verbatim bodies, 19 stubs incl.
the four §332 %lo-in-a-delay-slot "walls"), src/800c2.c, src/800c2_2.c, src/800c2_3.c removed;
REORDER_TUS is empty (mechanism kept). Cookbook §490.

Two stale instruments fixed: exclude_audit let a pinned WALL outrank LINKED (PopMatrix/
PushMatrix had sat as walls since S68 while living in libgte3, linked since Phase 8) — LINKED
dominates now, config/wave_exclude.txt 13 -> 3; frontier_classify carried a hard-coded 49-name
LINKED set (R51) and reported 337 "stubs" — derived from the Makefile now.

Verified: main 143dbb89f34491258bbc27810d0a12ec8b43a8dd WITH all SDK dirs and WITHOUT them from
a fresh extract; make tools-health OK; R22 fleet extract-all 212/212 + check-all 213/213.
Metrics: main REAL 839->773, LINKED 1,150->1,256, VERBATIM 29->3, stubs 29->16, byte-identical
2,075/2,091 = 99.2%; game-code weighted 93.3% (38,748/41,534), remainder 2,786 = the open-stub
sum; fleet stubs 51->38 (frontier_classify: 39 rows incl. the data word). Verbatim manifest
33 -> 6. Docs: worklist rows + "S79 task #5", SETUP (fresh-clone obj42 commands, Makefile
blocks, exclude_audit), decision-log "S79 addendum 2", accelerators "S79 (2)", CURRENT_PHASE
S79 FINAL refreshed (census, metrics, the task #6 brief).
2026-09-04 17:56:31 -06:00
Drew T 757bd82a0f feat(phase-31): S79 #4 — scattered-.bss split at link-prepare (psyq_bss_split): SYS.o→libgpu2, VM_F.o→snd12, GS_001.o→libgs8 LINKED; libgpu_used retired
The §9.1 "scattered .bss commons" exclusion class (Phase 8 → P31) is closed 3/3. New
tools/psyq_bss_split.py (own ELF32 REL reader/writer) cuts an object's packed .bss into
per-base NOBITS pieces: bases derived from the game bytes per HI16/LO16 pair, references
walked in offset order into single-base runs, cuts snapped to symbol starts (the linker
scattered SYMBOLS), symbols moved, a LOCAL section symbol per piece inserted, relocs
retargeted with the addend rewritten in the immediates, self-diffed. It runs inside the one
prepare step shared by psyq_link.link_object / psyq_link_region.build_region /
psyq_integrate.integrate (prepare_object before classify), re-derived every build.

GS_001.o was certified "5 interleaved bases, NOT splittable" by the S77 probe, which grouped
by BASE; by RUN it is six symbol-aligned pieces. All seven cuts across the three objects are
confirmed by the other objects' by-name recoveries (_que 0x800C5510, _svm_sreg_buf
0x800B9B58, PSDBASEX/CLIP2/PSDBASEY/POSITION/GsDRAWENV). R39 negative control: 235 placed
objects across 9 curated dirs, 0 refusals, exactly 3 splits (a libcd .bss+size end pointer
refused the first build → reference problems are fatal only when a split is needed).

Wiring: yaml 800c→libgpu2, sgap_6→sgap_6+snd12, gsgap3→libgs8 (comments rewritten);
LIBGPU_ELF := .run/obj40/libgpu (curated libgpu_used retired); libgs 34 objs/8 blocks
(make_libgs.sh +GS_001); snd 63/12 (make_snd_used.py exclusions 4→3). src/800c.c and
src/gsgap3.c removed (Sony code hand-matched as REAL/verbatim), sgap_6.c keeps only
func_8003FA54; splat-emitted libgpu2.c/libgs8.c/snd12.c stubs for the no-SDK fallback.

Verified: main 143dbb89f34491258bbc27810d0a12ec8b43a8dd WITH the SDK objects and WITHOUT
them from a fresh extract; make tools-health OK; R22 fleet clean extract-all 212/212 +
check-all 213/213. Metrics: main REAL 886→839, LINKED 1,040→1,150, VERBATIM 85→29, stubs 29
(unchanged); game-code weighted 91.1% (40,895/44,870) — both terms lost the 3,667 SDK ins;
the remainder is still exactly the 3,975-ins open-stub sum. Verbatim manifest --update
200→33 rows (subtractive). Docs: cookbook §489 (+index), psyq-worklist rows + "S78 task #4",
SETUP S79 R21 table, decision-log S79 addendum, accelerators S79, CURRENT_PHASE S79 FINAL 🛑.
2026-09-04 17:19:29 -06:00
Drew T a85733a487 feat(phase-31): S78 #3 — 13 "game code" subsegs were PsyQ objects: wired LINKED (libgte 70/30, libgs 33/7, snd 62/11); main's game-code metric corrected to 91.8%
- exact tiles, 0 tokens: libgte23-26 (MSC01/02/05/09, SMP_00, FGO_01-06, PATCHGTE), libgte9 re-derived
  as SMP_05 NormalClip (SMP_06 NormalClipS = nested sub-pattern; psyq_integrate now drops nested
  placements), libgte27-30 (the libgs-gap MTX_05/07/11, REG03+REG11), libgs7 (2D_BG0+2D_BG1), snd10
  (VM_NO1), snd11 (VM_NOWON carved off sgap_8). LINKED 959->1040, REAL 912->886 (SDK inline-asm wrappers
  re-provenanced), VERBATIM 146->85, 13 TUs deleted; splat re-emits the stub records.
- main 143dbb89 WITH and WITHOUT the SDK objects. The no-SDK fallback had been red since S7x
  (CdReadyCallback called by its SDK name while the libcd stub carried func_800435B4) — curated
  CdReadyCallback = 0x800435B4, refs unified. R22 clean fleet 213/213; tools-health OK.
- METRIC CORRECTION (R35): progress.py's "MAIN game-code weighted" sig never excluded the LINKED
  objects (its comment said it did) — ~31k linked-SDK ins sat in the denominator as unmatched game
  code. Exclusion now derived LIVE from the Makefile stub lists + yaml ranges: 91.8% (44,562/48,537),
  not 59.8%; the 3,975-ins remainder equals the open-stub sum exactly.
- VM_F.o probed SPLITTABLE at .bss 0x50c (SYS.o's class -> task #4). cookbook §488; worklist S78 #3;
  decision-log + accelerators; SETUP rows.
2026-09-04 16:26:12 -06:00
Drew T a7394f44dc feat(phase-31): S78 #12 — the 800c3 "wall" band is LIBPAD 4.2.1 + LIBAPI 4.2: 46 names applied; integrate wired by subseg range; renames via ApplySymbols
- provenance: the psx loader's per-version PsyQ signature sets place PADENTRY/PADCMD/PADPORTD/
  PADSEQD (4.2), WAITRC2 (4.3), COUNTER/C114/FIRST/PAD/PATCH/CHCLRPAD (libapi 4.2) byte-exact in
  0x8005CE48-0x8005FC68 / 800c2 -> 12 of main's 29 stubs incl. all four §332 walls are Sony's
  DualShock library in reorder mode. 46 names -> symbols.us.txt (count 1081), band TUs, verbatim
  manifest, wave_exclude; firstfile/firstfile2 (4.2 naming); CdGetToc @0x800430B8 (was the Phase-21
  xdedup mislabel DecDCToutCallback). SETUP §5.1 corrected; psyq-worklist S78; cookbook §487;
  decision-log + accelerators S78; CHECKSUMS +Psy-Q_46.zip +PSYQ_SDevTC_v4.5.zip.
- psyq_integrate: --yaml maps stub<->objects by SUBSEG RANGE with an exact-tiling check and PRINTS
  the located-but-unwired residue (libgte: 13 objs / 1,264 ins) — main's LINKED build had been RED
  at HEAD since the S77 psyq_identify fix (22 libgte blocks merged to 3; gate worktrees take the
  stub fallback so it never showed); a library object's exported symbol whose recovered address the
  curated file names differently is --redefine-sym'd (R15; A66 firstfile->firstfile2).
- Ghidra: 47 MCP renames did NOT persist through the sentinel stop (R9 caught it) -> NEW
  tools/ghidra_scripts/ApplySymbols.java + tools/ghidra_apply_symbols.sh mirror the curated file
  headless with a real save: 73 renamed, R9-verified x4. SETUP inventory rows (R21).
- lint_symbol_refs: scans verbatim __asm__ bodies (`.ent\tfunc_X` is invisible to \b and to the
  string-masked scan); negative-controlled (red on the pre-fix TUs, green on the passing tree).
- R22: clean extract-all 212/212 + check-all green on the final config; main rebuilt byte-identical
  143dbb89 after the last src-only fix -> 213/213; tools-health OK.
2026-09-04 15:57:06 -06:00
Drew T a13b2a5c38 carve(main): 3-way -O0 island split of 800_b for func_8002C410
func_8002C410 MATCHES 299/299 at -O0 and DIFFs 228-vs-299 at -O2 (verified
independently with match_one --o0 vs --no-auto-o0). gcc-2.7.2 has no
per-function optimize pragma, so opt level is per FILE, and the function needs
its own object. Main had no path to one: the Makefile's -O0 wildcard covered
src/ov_*/ and src/md_*/ but NOT top-level src/*.c, and o0_subsplit.py is
overlay-shaped -- it died on config/splat.main.yaml, which does not exist.

Measured the scope first (R37): the -O0 detector flags exactly TWO open main
stubs -- this one, and func_80011380, which already lives in -O0 boot.c and is
the proved floor. So this unblocks one function, not a class.

FIVE COUPLED PIECES, which is why the carve is worth recording:
  1. splat code rows: 800_b cut 3 ways -- 800_b / 800_b_o0a / 800_b_2
  2. splat .rodata: span B SPLIT, because the 3-way cut put its two jtbl owners
     in different objects -- func_8002B0B4 into 800_b, func_800335B8 into
     800_b_2 -- and one code object may contribute exactly ONE contiguous
     .rodata run. The boundary is DERIVED, not guessed: 800_b.o's compiled
     .rodata is 0xf8 bytes, so the front run ends at 0x80072E44+0xf8. The
     build's own jtbl_rodata_pads caught the missing piece.
  3. src/800_b.c split 3 ways -- 86-line prologue duplicated, 3 defs before the
     island, 97 after
  4. Makefile -O0 glob widened to top-level src/*_o0?.c
  5. ld_interleave --order: 800_b_2.o inserted after 800_b.o. Missing this
     floated the tail rodata and shifted every data symbol by exactly its size,
     +0x204, across 704 two-byte runs -- which is how it was found.

o0_subsplit.py now REFUSES main loudly instead of dying on a missing file
(R43/R61a) and names the manual procedure.

VERIFIED BYTE-NEUTRAL BEFORE ANY BANKING: main builds
143dbb89f34491258bbc27810d0a12ec8b43a8dd with the split in place and
func_8002C410 still an INCLUDE_ASM stub.
2026-09-03 22:20:57 -06:00
Drew T 5399845172 feat(psyq_bss_probe): a Phase-8 link exclusion re-derived from the bytes — 3 of 4 objects are not blocked as recorded
The yaml has excluded SYS.o/GS_001.o/2D_BG0.o/VM_NO1.o from the LINKED build
since Phase 8 for 'scattered-.bss commons ... no single NOLOAD base reproduces
it'. Every word of that is true, and it does not imply unlinkable.

psyq_bss_probe derives each object's .bss bases FROM THE BYTES (for each
HI16/LO16 pair against the bare .bss section, the object's immediates give the
addend and the game's give the resolved address, so base = resolved - addend)
and then asks the unasked question: are the offset ranges DISJOINT?

  SYS.o     3,109 ins  2 bases  0x0000-0x0044 @ 0x80078830
                                0x0148-0x0150 @ 0x800c53cc  -> SPLITTABLE at 0x148
  GS_001.o    384 ins  5 bases  interleaved                 -> the genuine wall
  2D_BG0.o    526 ins  NO .bss                              -> reason cannot apply
  VM_NO1.o    305 ins  NO .bss                              -> reason cannot apply

§9.2's escape (weaken the .bss symbol, --defsym it) really cannot reach these —
a relocation against the bare SECTION has no name to defsym — and that is what
made 'unlinkable' look like the conclusion. But a section reference only needs
the section PLACED, and a section can be split.

Completeness checked before believing it (R32): the probe counts .bss refs from
EVERY section; SYS.o's .data has zero, so the two-way split covers every
reference. Placement is derived, not configured — the object is located by
masking relocated fields and requiring a UNIQUE match, which independently
reproduced SYS.o @ 0x80059234 / 3,109 ins, agreeing with both the yaml subseg
bounds and the manifest's psyq_identify count.

Incidental: src/800c.c is 100% SYS.o (its span is exactly the object's .text
size), despite the subseg comment calling it '-O2 game code'.

Cookbook §484; yaml comment corrected in the same change.
2026-09-03 22:07:31 -06:00
Drew T 48df1a900f config(wave_exclude): two 'compiler wall' entries were stale wrong-oracle verdicts
func_8005F0C8 and func_8005ECC0 both live in the 800c3 REORDER_TUS island,
whose real build path is reorder_passthrough + as -O2. Their S68 wall verdicts
were measured under maspsx + as -O1 — the oracle S76 fixed. Re-measured under
the correct path they are ordinary near-misses: 3 of 88 (ADDRESSING) and 2 of
35 (DELAY-SLOT), not walls.

Both stay excluded because neither is SOLVED (permuter_ils reached 3 and 5, not
0), but the reason now says UNSOLVED rather than impossible. An exclude list
records what the tooling could not do; a wrong reason is how real work gets
filtered out permanently.

Found because a wave agent noted that six prior 'IMMOVABLE §177/§188 epilogue'
verdicts on func_8005FA94 were all wrong-oracle artifacts — the same
provenance, so the same suspicion applied to the neighbouring entries.
2026-09-03 20:21:42 -06:00
Drew T e059f85298 config(wave_exclude): pin the 4 §332 delay-slot walls wall_sweep names in main
wall_sweep --emit-exclude lists 9 fleet-wide; the list carried 5 of them.
func_8005D734, func_8005D8B4, func_8005ED4C and func_8005F450 each have a
%lo in a branch/jal delay slot — the second half of an assembler macro gcc
emits as ONE atomic insn, so no C can place it there. An agent handed one
returns a NEAR with an unexplainable tail, which is indistinguishable from a
hard function; the playbook measured a main wave spending 4 of 7 slots that way.
2026-09-03 20:03:15 -06:00
Drew T a0c855648c feat(decomp): bank ov_SC01_084:func_80182A00 (§378 chain, 207 ins)
harvest_verify: verified 1 / failed 0, ef86fe1e403998a82ead42f4466ac4bc80f2c8d1
BYTE-IDENTICAL. The static probe had called this a `local_type' Blk16 conflict;
the real gate strips TU-provided typedefs and then named the true blocker.
2026-09-03 19:42:05 -06:00
Drew T 2eac966cc5 fix(manifest): six §179-C fragments are PERMANENT-VERBATIM, not decompilable
Reverts my six src/800c.c stub conversions from commit:3772 and corrects the
manifest to match the evidence. main still builds 143dbb89.

Each of the six has NO `jr $ra` of its own: it ends mid-basic-block or
tail-jumps into a sibling's label, and the shared lw $ra / addiu $sp / jr $ra
tail lives in the NEXT symbol. gcc-2.7.2 has no sibcall pass and appends an
epilogue to every C function it compiles, so no C spelling can ever match —
cookbook §179-C, which already NAMED func_8005C1C0 as a follow-up.

I converted them anyway on a `rows == 1` filter that meant "the manifest
listed one row", not "this is an independent function", ignoring the
DECOMPILE-AS-PARENT disposition whose whole meaning is "this row is a
FRAGMENT". Three drafting agents then rediscovered §179-C independently, one
citing the very cookbook line naming its own target, before a mechanical
no-jr-$ra sweep confirmed all six at once.

Also corrects func_8017D810 and func_80181828 from UNCERTAIN: both are
handwritten GTE (SQR lane), per agents that transcribed the .s 1:1.

The guard that prevents a repeat shipped in commit:3773.
2026-09-03 15:42:56 -06:00
Drew T 096fe153cc feat(decomp): parallel gate — 10 fns across 4 binaries (8 workers)
ov_SC02_005    func_8018DFC4
  md_MAIN_003    func_800D0204 func_800D0440 func_800D05B4 func_800D0664 func_800D09A0 func_800D0A7C func_800D0B1C
  ov_SC03_105    func_80180EC0
  ov_SC02_003    func_80187B40
2026-09-03 14:40:01 -06:00
Drew T 20fea212df fix(config): drop the stale SaveLoadRoutine symbol + its two wall entries
SaveLoadRoutine is `case 0:` inside func_8002B0B4, not a function of its
own (S75). The lingering `= 0x8002B154; // func` declaration kept splat
emitting asm/nonmatchings/800_b/SaveLoadRoutine.s, which progress.py
reported as the single UNPLACED parse hole. The two config/wave_exclude.txt
WALL entries described the same misconception.

UNPLACED 1 -> 0. Build stays byte-identical at 143dbb89.
2026-09-03 12:30:05 -06:00
Drew T fc7caf599b refactor(tools): retire asm_in_c.py — the taxonomy is DATA now, not a regex census
R33, "the best outcome is a DELETED SCANNER, not a fixed regex". asm_in_c.py
existed to DISCOVER the §265 verbatim class by parsing __asm__ blocks. That job
is done, and regex was the wrong instrument: five successive censuses returned
116 -> 112 -> 108 -> 178 -> 199, and the classification was worse than the count
-- it called 154 rows "game code" where the authoritative answer is 24.

The real answers came from evidence a regex cannot see:
  * the <OBJ>_OBJ_<hex> naming key -- every one is placed_object.text_start +
    hex, so those symbols are OFFSETS INTO LIBRARY OBJECTS, not functions;
  * the PsyQ archive symbol tables in .run/obj40/, which keep statics as W
    symbols, so for a byte-identical object the archive IS the function map
    (checkRECT = SYS.o+0x52C = func_80059760, and NONE of the 44 SYS_OBJ_*
    symbols in SYS.o is a function).

So:

config/verbatim_manifest.json (NEW, committed) -- the authoritative census.
200 rows, derived once from the ROM image + archives + naming key, each with a
class and a DISPOSITION:
    PERMANENT-VERBATIM   69 rows / 57 units   hand asm; never decompilable
    DECOMPILE-AS-PARENT  57 rows / 23 units   a FRAGMENT; decompile unit_entry,
                                              never the fragment itself
    DECOMPILE-NOW        41 rows / 41 units
    DECOMPILE-LOW-VALUE  20 rows /  4 units
    UNCERTAIN             5 / NOT-VERBATIM 7 / NOT-CODE 1

tools/verbatim_check.py (NEW) -- a GUARD, not a census. Detects verbatim bodies
(the cheap part, and the only part regex is good at), diffs the NAMES against the
manifest, and reports NEW / GONE / MOVED. A NEW row means someone banked assembly
and it is about to become invisible work; it is never allowed to inherit a
disposition by default. It deliberately does not classify or count units.
Compares case-insensitively on the hex, because an address is a NUMBER (R48).

tools/verbatim_target_s.py -- put on the MANIFEST LEASH. It used to enumerate
every verbatim SYMBOL, and 62 of those are not functions (fragments, bare
epilogue tails, padding, trampolines). Emitting per-symbol targets for them is
what sent two drafting bursts at things no C function can express. It now takes
only DRAFTABLE dispositions: 66 targets emitted, 134 skipped and SAID SO.

tools/verbatim_to_stub.py -- repointed to verbatim_check for detection, so there
is ONE detector in the tree rather than three copies.

tools/asm_in_c.py -- REMOVED.
2026-09-03 12:05:37 -06:00
Drew T f5f4c2eeec feat(decomp): bank func_801806F8 + func_80180ABC (498 ins) + frontier_classify reads the journals
Two banks from the S75 redraft workflow (7 overlay functions, one agent each,
every claimed MATCH re-verified by an independent agent instructed to refute
it). Both were carried as F-FAR "a draft exists but is materially wrong":

  func_801806F8  ov_SC03_105  241 ins   (recorded closeness 235)
  func_80180ABC  ov_SC03_105  257 ins   (recorded closeness 250)

Neither needed a better model. Both needed the recorded closeness not to be
believed -- see below.

frontier_classify.py, THREE fixes, each caught by testing against a case whose
answer was already known:

1. BEST closeness, not LAST. .run/backlog.jsonl is append-only, one row per
   attempt across every lane and session, so the last row is evidence about
   THAT LANE'S SEED, not about the function. Caught func_80180B3C (best 125,
   last 287) and moved func_80181294 from "redraft" to "permuter" (best 19).
   The draft that ACHIEVED the best score is kept, not the last one written.

2. journal_notes.py wired in as a SECOND, DISAGREEING oracle (R34). The backlog
   does not have what the agent journals have. Measured on func_8017DB98:
   backlog best == last == 115, so best-vs-last could not help, while the
   journal holds "Attempt 2 (MATCH · closeness 0) ... MATCH 122/122 ... BANK
   BLOCKER is TU plumbing, not the body (§376/§378)" WITH the draft path and the
   exact declaration to change. Reclassified 37 functions; G-DRAFTED-UNKNOWN
   fell 47 -> 10 and a new C-PLUMBING class holds 16 functions / 1,547 ins whose
   BODIES ARE PROVEN and are blocked only by the TU.

3. A consuming-regex bug in my own extractor -- the session's signature defect,
   committed a third time in the tool written to find it. The first cut used
   `re.finditer(r'\*\*Attempt \d+\*\* \(([^)]*)\)(.{0,400})', ..., re.S)`, whose
   400-char body window SWALLOWS THE NEXT ATTEMPT'S HEADER, so every record
   following another was invisible. On func_8017DB98 it hid attempts 2 AND 6,
   both `MATCH · closeness 0`, and returned attempt 1's NEAR (2) as the best --
   exactly the records the oracle exists to find. Now splits on the marker
   rather than consuming past it. A regex that consumes an unbounded body cannot
   enumerate the items after the first.

Rows now carry attempts, closeness_last, journal_closeness, and a
!!WARMSTART-REGRESSION flag when a later attempt scored materially worse than
the best -- the shape a wave's warm-start regression makes, which from inside
the wave is indistinguishable from an unsolved function.

Gate ledger for the batch of 7: 2 banked, 3 near, 2 failed. func_800CB00C failed
despite being adversarially upheld -- it owns a jump table, and both matchers
compare .text only, so a verified .text MATCH proves nothing about table
placement (the agent's own write-up says so).
2026-09-03 00:12:07 -06:00
Drew T abea9f0ac2 feat(decomp): bank func_8016AE5C (85 ins) + frontier_classify — the frontier is not a drafting problem
func_8016AE5C (ov_SC03_108) was logged "match_one MATCH but the whole-binary
gate rejected -- CAUSE NOT DETERMINED". Determined: the body is byte-perfect (0
differing words inside the function; all 1,168 diffs are uniform +0x20 shifts
outside it) and it emits an 8-entry jump table that was never carved. It banked
unchanged the moment the §446 jtbl_carve per-table bound landed.

tools/frontier_classify.py (NEW) — classify every open stub by its TRUE BLOCKER
from artifacts already on disk (R33/offline-tooling-first: zero tokens, no
agents, no builds). "69 functions left" is a stub count, not a difficulty
measure, and routing drafting agents at carve or plumbing problems wastes them.

    A-TWIN-REMAP   3    302  a byte-identical copy is already banked elsewhere
    B-CARVE       11  3,301  owns a switch jump table -> the §446 class
    D-NEAR         2    106  closeness <=25 -> permuter fuel, not drafting
    F-FAR          3    223  draft materially wrong -> redraft
    G-DRAFTED-UNK 49  8,724  drafted before, no usable verdict on record
    H-VIRGIN       1      1  never drafted (and it is a DATA BLOB, not a function)

68 of 69 remaining functions already have a draft on disk. The endgame is a
verification/integration problem, not a drafting one.

TWO SELF-INFLICTED DEFECTS FOUND BY CHECKING AGAINST KNOWN-TRUE CASES, both the
session's recurring shape (a scan narrower than the claim it supports, R32):
  * The sig directory is NOT the fleet. Alongside the 213 real binaries `.run/`
    holds `SLUS_007.26` (a STALE duplicate of main under the ROM filename),
    `resident_image`, and two CROSS-BUILD binaries (`sep8_SLUS_007.26`,
    `aug31_USA_DEMO.EXE`). Counting them as peers reported 38 fns / 7,516 ins of
    free twin-remaps -- mostly main "already banked" in ITSELF, the rest proven
    in a PROTOTYPE that R13 forbids as evidence. Now derives the fleet from the
    Makefile and prints what it ignored. True figure: 3 fns / 302 ins.
  * The draft scan globbed `.run/S7*` only, missing `.run/S69m2`, `.run/S68m1`,
    `.run/s67m1`, `.run/wave_ds2`, `.run/gate_lane`, `.run/backlog_drafts`. All
    32 drafted main functions read as "never drafted", which would have sent
    agents to redraft 6,328 instructions that already have drafts. Now one
    pruned os.walk of .run (worktrees excluded -- 7.4 GB of duplicate sources).

Honest negative result: resident:func_800D06E8 (344 ins) did NOT bank. I
predicted the carve fix would clear it; it did not. Its blocker is still open.
2026-09-02 22:35:50 -06:00
Drew T cb948a6bbc feat(decomp): the ov_SC01 reloc-only cluster + its 5th latent victim — 5 fns, 1,301 ins
S74 handed this forward as "1,116 instructions behind one question": family_remap
on ov_SC01_004/005/006/008 gated DIFF 4/4 against the banked exemplar
ov_SC01_009:func_8017EB08, and the class had been carried as a codegen wall since
S70. The four bodies were byte-identical to the exemplar the entire time.

Word-level classification vs the exemplar, computed independently twice (a Fable
agent's script, then mine from scratch against the retail images), identical:

    nins=279   EQ 213 · RELOC-HI16 23 · RELOC-LO16 24 · INTERNAL-J 19 · CODEGEN 0

Zero register-allocation, instruction-selection or scheduling differences.

ROOT CAUSE — tools/jtbl_carve.py reserved ONE WORD TOO MANY per table:
  * spimdisasm runs an island's LAST `jtbl_` dlabel one word into the following
    NON-ZERO data (string bytes 0x696F760A / 0x000013FF / 0x62647020), so the
    zero-word trim cannot see it; and
  * the over-span clamp that would have caught it was guarded by
    `len(sltiu_bounds) == 1` -- but `sltiu` is ALSO how gcc emits an unsigned
    range check ((u32)(x-lo) < n, I1). These four carry five distinct sltiu
    immediates, so the guard silently disabled itself on precisely the functions
    that needed it.
  0x2C reserved for a 0x28 table => image 4 bytes short => ~850 %lo immediates
  shift => whole-binary DIFF about a function whose own bytes are perfect.
Fixed with a PER-TABLE bound: gcc-2.7.2's dispatch is a fixed idiom, so the
`sltiu` nearest ABOVE that table's own %hi(jtbl_X) is unambiguous whatever else
the function tests. Second defect stacked behind it: a carve span whose
JTBL_PADS line lacks a `tables=` comment lost its existing table's start on
merge and refused "table starts do not fit the span" -- which harvest_verify
then "repaired" with a needless jr_isolate_all that walked back into the first.

THE NEGATIVE CONTROL IS THE STORY. Run over every other open table-bearing stub
fleet-wide, the fixed bound changed exactly one more table: ov_SC06_022/
func_80185B80 (185 ins), a FIFTH victim nobody had drafted against. A guard that
disables itself on a common idiom does not fail once -- it fails quietly across
the whole corpus.

Banked, each with its own byte-gate verdict (--no-propagate, clean re-gate):
  func_8017EB30  ov_SC01_004  279
  func_8017F2D4  ov_SC01_005  279
  func_8017F2D4  ov_SC01_006  279
  func_8017EC68  ov_SC01_008  279
  func_80185B80  ov_SC06_022  185

Also here:
  * dedup_propagate: memoize find_site's mask (lru_cache) -- 54 ms of masking
    per call over the whole source, recomputed though it depends only on the
    text. 2x on that loop (58.3 -> 33.0 ms/call), NC identical on 120 addrs.
    Scoped honestly: that loop is ~2.4 min of a 30-min run; the profiler puts
    43% in family_remap._alias_decl_for, which is NOT fixed here.
  * Makefile: `clean` says out loud that BINARY= is ignored and it is fleet-wide
    (cookbook §445) -- it silently deleted asm/ for all 213 binaries this session.
  * Cookbook §446 (the carve law: when a standalone-MATCH jtbl draft gates DIFF,
    diff the carve extent against 4 x sltiu before touching the body), §445, and
    SETUP rows for both tools (R21).
  * CURRENT_PHASE: the S75 log, incl. the measured fleet dedup-hygiene census
    (~2,073 fns / ~12,116 items, all ALREADY MATCHED -- cleanup, not work) and
    Drew's decision to leave it and gate --no-propagate from here.
2026-09-02 22:15:20 -06:00
Drew T 5208f2279d feat(decomp): parallel gate — 2 fns across 1 binaries (1 workers)
ov_SC06_029    func_80182ED8 func_80184084
2026-09-02 19:35:21 -06:00
Drew T 6e840730a9 feat(carve): bank 4 more via the carve chain — and §8b's "non-adjacent => ISOLATE" is over-strict
resident:func_800D00E4/func_800D02D0/func_800D0488 + ov_SC07_002:func_80180248, all byte-verified
from clean rebuilds (resident 8e17e02f, ov_SC07_002 fad71342) and counted from the SOURCE.
ov_SC06_029's two are re-gated separately against HEAD — this agent's worktree predated five banks
there, so its numbers for that binary no longer apply.

TWO OF THE SIX NEEDED NO CARVE WORK AT ALL, AND CARVE-REFUSED WAS AN INSTRUMENT VERDICT.
ov_SC07_002:func_80180248's table is ALREADY inside a carve bound to its own subseg: in stub state
spimdisasm migrates the table into the fn's .s and the object fills the piece exactly, so banking
just swaps that block for cc1's identical one. `island_probe` classified it `tail` on the table's
ADDRESS, `apply()` routed it to build_carve, which resolves spans out of the RAW data asm where a
carved table no longer is -> "not found in the raw data asm" -> harvest_verify booked CARVE-REFUSED.
A verdict about the route we chose, not about the function (R43). jtbl_carve now has a `covered`
verdict (table inside an existing carve bound to the fn's OWN subseg) and a `covered-tpad` wall (the
retail copy carries a trailing §8a pad the matched body won't emit — bankable, needs a `0t<n>`
entry); a fully-covered batch is a no-op before either route.

THE RESIDENT CAN CARVE LIKE AN OVERLAY. Its three tables are adjacent and lead the island
(0x450e0..0x451ac, one span, all in subseg `resident`). The genuinely new part: the resident opens
with `- [0x0, rodata, hdr]`, a 1-word .rodata header BEFORE the code, so its layout is
rodata -> text -> data -> rodata(carve) -> data, which `ld_interleave --order` cannot express (every
listed piece lands after TEXT_START, and hdr.rodata.o would fall into the unchecked `empties` bucket
and be parked after the text, moving every byte). New `--pre` places a leading-rodata piece ahead of
the text; resident_JTBL_INTERLEAVE uses it.

NEW LAW, BYTE-PROVEN (§8b was over-strict — EXTEND the carve, do not isolate): a .rodata carve piece
binds to a code SUBSEG, not a function, and the object's .rodata is the address-ordered
concatenation of cc1's tables for BANKED functions and still-stubbed functions' MIGRATED tables. So
a span may legitimately hold a MIX, and extending a carve across an align-pad word and two unrelated
STILL-STUBBED tables was byte-identical with nothing banked — where the tooling demanded a
jr-isolation. Corollaries, all measured: migrated tables self-align (spimdisasm emits `.align 3` iff
the table's SPAN-RELATIVE offset is 8-aligned), so stubbed tables need no spec; JTBL_PADS counts cc1
tables only, so a mixed span's spec GROWS as each sibling banks; and the zero-word rule is INVALID
across a migrated boundary, because that zero is supplied by the preceding migrated block.

ALSO REPORTED, NOT FIXED (harness gap worth its own change): verify_worktree.provision omits
`.run/sig.<bin>.jsonl` — main clone 259 files, provisioned worktree 0 — and jr_isolate_all's
carve-ownership scan swallows the resulting FileNotFoundError in a bare `except: continue`. Measured:
2603 of 2603 functions raised, the scan found 0 owners, and the run aborted with a CONFIDENT FALSE
verdict ("committed .rodata carve ownership is not 1:1 — stranded/duplicated carve"). Both resolve
instantly once the sigs are present. Any worktree-run isolation before that is fixed reports a
corruption that is not there.
2026-09-02 19:34:09 -06:00
Drew T 2954b250ec feat(decomp): parallel gate — 5 fns across 1 binaries (1 workers)
ov_SC06_029    func_801801D8 func_80180A70 func_801867D0 func_80187660 func_801898CC
2026-09-02 19:25:24 -06:00
Drew T 5e10215269 feat(md): bank the 4 -O0-stranded functions — and the class is now essentially empty
md_MAIN_011:func_800CF28C · md_MAIN_003:func_800D0268/func_800D0740/func_800D0C50, all byte-verified
from a clean rebuild and counted from the SOURCE: md_MAIN_011 is now FULLY MATCHED (0 open stubs),
md_MAIN_003 is down to 1 (func_800CF3E8).

THE PREMISE I HANDED THE AGENT WAS WRONG, AND IT SAID SO. md_MAIN_011 is already a whole-object -O0
module — no carve was needed. Its real blocker was tools/jtbl_rodata_pads._s_rodata_span ignoring a
trailing `.align`, the SAME defect this session fixed for md_SC07_003 from the other direction: two
agents converged on it independently. Adopted this agent's stricter form (only a TRULY trailing
align rounds `hi`; an interior one is followed by data that sets `hi` higher anyway).

Note WHY it stayed latent: `derive`'s zero_gap self-corrects a 1-3 byte undershoot whenever the next
stream item is an anchor. A C jump table has NO anchor — so the bug can only fire the moment someone
banks a switch function into such an object, and when it fires it accuses the CARVE ("island layout
drift"), not itself.

md_MAIN_003 needed one new -O0 object, and the boundary I proposed (0x1f74 -> 0x1e58) was both too
narrow and off by 0x2B8. The carve made is `md_MAIN_003_o0e` at 0x1308 (vram 0x800D0100) running to
the existing o0c boundary: everything in that span is a §265 verbatim __asm__ body or an INCLUDE_ASM
stub — zero optimizable C — so the whole tail flips with one cut. Proved byte-identical with NOTHING
banked first (§431 discipline), then the three drafts gated one at a time.

TWO MORE GENERAL DEFECTS FIXED IN jr_isolate_all, both of which silently mis-place a boundary:
 * an item-less CLOSING region emitted a duplicate `- [off, c, …]` line and the validator refused;
   the empty-region skip covered only region 0, and `_partition`'s empty `footer` made the closing
   region look non-empty.
 * A §265 VERBATIM __asm__ BODY IS PREAMBLE, AND PREAMBLE IS ASSUMED BYTE-NEUTRAL. It is not — it
   emits bytes. `parse_overlay_c` has four addressed-anchor forms and a verbatim body is none of
   them, so it attaches to the NEXT anchor: cutting at func_800D0268 would have moved 0x168 bytes of
   other functions into the new object while the yaml claimed the region starts higher. New
   `_region_emit_start()` derives the yaml offset from the region's CONTENT (item addresses + every
   .globl/.ent the text names that resolves inside the object) and takes min(cut, emit), so a
   boundary can only move DOWN. Where no verbatim asm is in play it equals the cut — every existing
   isolate is unchanged.

BLAST RADIUS PROVEN, not argued: jtbl_rodata_pads is in the build path (`--derive` for md_*/main),
so the agent rebuilt main + all 70 md_* from scratch (71/71) and then ran the full fleet:
**make check-all 213/213 passed, 0 failed**, main 143dbb89 BYTE-IDENTICAL.

CENSUS, denominator asserted (1057 live stubs, 0 without a .s): exactly ONE -O0-prologue stub
remains stranded in an -O2 TU fleet-wide — main:func_8002C410 in src/800_b.c, 299 ins. Nothing more
should be built for this class; the general tool already existed and what was missing was
correctness, not coverage.
2026-09-02 19:23:25 -06:00
Drew T d0389352d7 feat(decomp): parallel gate — 1 fns across 1 binaries (1 workers)
ov_SC03_105    func_801818E8
2026-09-02 19:09:29 -06:00
Drew T 7ce27c0d1f feat(decomp): parallel gate — 2 fns across 2 binaries (6 workers)
ov_SC05_010    func_8017F5B8
  ov_SC03_024    func_801830A8
2026-09-02 18:57:20 -06:00