Commit Graph

285 Commits

Author SHA1 Message Date
Drew T c7ad41c8a3 feat(phase-30 T6/S11): the propagation lag — EXTEND 31/36, and the PROPAGATE head measured
Continues the S11 lane. Fleet 96.01 -> 96.06% fn-count / 93.6 -> 93.7% instr /
88.0% distinct; dedup 1905 -> 1907 groups, 0 failed, C1 240669/240669.
R22 clean-fleet: 140 passed, 0 failed of 140. 0 NON_MATCHING (G4).

EXTEND (SC07): the 16 volatile-blocked DIFF slots banked on retry after the
data asm-label alias -> lane total 31/36.

PROPAGATE head, measured rather than projected. .run/s8_lag.json re-split: the
checkpoint's "45 classes / 20,837 ins" is really 5 classes carrying 18,545 ins
(89%) and 41 carrying 2,316. Per-class outcome:

  func_80147364  30x137 = 4,110  BANKED x137 (definition-side asm-label alias)
  func_8012f274  29x137 = 3,973  DROPPED — byte-diverges in ~130 overlays
  func_8016ba68  29x134 = 3,886  4 of 138 banked; excluded from ~130
  func_8012a598  24x137 = 3,288  SKIPPED, cause NAMED by the tool
  func_801466f0  24x137 = 3,288  no source found — the S6b D4 gap, still open

  func_80147364's byte-true definition is `(u16, u16)` while 4,046 fleet decls
  say `(u16, s32)`. u16 is a default-promotion type, so the `()` no-prototype
  escape is ILLEGAL (the documented gcc-2.7.2 dead-end) and conforming the decl
  would change caller codegen. The DEFINITION-SIDE asm-label alias gives the def
  a distinct C identifier while emitting the real symbol -- zero blast radius on
  every caller. Probed on ONE member first (1 build, not 137 -- the S29
  discipline): byte-identical 9052dc0e first try; then 137 overlays clean.
  In-tree precedent for the form: 1,725 files.

MEASURED NEGATIVE, recorded not buried: `dedup_propagate --recover` banked only
4 of 138 on func_8016ba68 and dropped func_8012f274 entirely (137 [exclude]
lines). The caller-extern reconcile that is 16/16 lifetime ON DRAFTS does NOT
transfer to PROPAGATION of these two. Cause not yet diagnosed -- probe one
excluded overlay's build output before any further attempt (§136a), do not
re-run the lever hoping.

NAMED NEXT (cheapest first): func_8012a598 skips on `missing file-scope extern
(CARRY-FIXABLE): D_801151D4, D_80126DB8_a, D_80127504` -- the SESSION-18
preamble-backscan class. Its body is 2 statements and `struct BigCopy` is
ALREADY in the shared engine_types.h (L312) with the identical statement already
macro-ized at engine_core.h:16158, so a hand-authored macro (the func_80147364
path) should take it x137 for ~0 tokens.

Process errors recorded in CURRENT_PHASE.md, all three one mechanism -- the
signal sampled is not the thing waited for: (1) a `nohup CMD &` wrapper's exit
read as the fleet check finishing (it stood at 63/140); (2) a corpus.stubs probe
mid-rebuild, which R32's coverage assertion refused rather than answer wrongly;
(3) CORRECTION to the S10 checkpoint's own rule -- `pgrep -x make` is right for
one make and WRONG for a campaign of sequential makes (it fired in a gap and
reported a live campaign done), and `pgrep -f <pattern>` SELF-MATCHES so that
waiter can never exit. Wait on the campaign process or `treelock.sh --status`.
2026-08-03 23:41:34 -06:00
Drew T 1859266d60 feat(phase-30 S10): Sonnet wave — 13 heads + 57 members; the §136i ~120 boundary is too LOW
- DREW'S CALL (2026-08-03): route the 30-target x2-9 wave to SONNET instead of Opus. The §136i
  >=120-ins Opus threshold was MY EXTRAPOLATION, never measured; this wave (125-793 ins) probes
  exactly the region where there was no data.
- RESULT: 13 banked of 16 that ran = **81%**, vs Opus's 10/13 = 77% on the comparable S8-3 slice.
  At least 8 banked SONNET-DIRECT (65 agents spawned: 60 sonnet, 5 opus escalations). Propagated
  57 member-matches / 4 failed across 42 overlays. 70 instances. R22 clean-fleet 140/140.
  FLEET 96.01% fn / 93.6% instr / 88.0% distinct (77,550 uniq).
  => **Sonnet is at least as capable as Opus on 125-793 ins. The ~120 boundary is too low.**
  NOT rewriting it to a specific number yet: 16 samples under a throttle confound cannot name a
  cliff. The controlled A/B (task #12) is how that number gets fixed properly.
- THE REAL LIMITER IS CAPACITY, NOT CAPABILITY: 14 of 30 agents were killed by SERVER-side
  throttling ("Server is temporarily limiting requests (not your usage limit)") that 30 concurrent
  Opus agents did not trigger. Practical rule: run Sonnet waves at ~12-16 concurrency, not 30.
  The 14 unrun targets are listed in the checkpoint for a smaller-batch retry.
- Sonnet's work quality was not shallow — three examples: func_8018797C read local-alloc.c and
  forced loads into an AGGREGATE to stop find_free_reg greedily taking 3 callee-saved regs;
  func_8018D870 used §136c sibling-first for ~70% of the body then blocked a coalesce with a pin;
  func_8017E3AC diagnosed an RC-3 callee-saved-order swap and noted the pin must be s32 or a stray
  `andi 0xffff` appears.
- MY ERROR, RECORDED: `until [ -s <output> ]` fires at the FIRST LINE of output, not at completion.
  It fired mid-propagation and I ran `make clean` on top of a live family_sweep, deleting asm/ and
  aborting both the regen and the sweep (corpus's R32 assertion refused to answer rather than return
  a wrong stub set — working as designed). No bad bytes: R22 verified 140/140 immediately after, and
  the propagation simply re-ran clean. Correct waiter is `pgrep -x make` (exact process name), which
  also cannot self-match the way `pgrep -f <pattern>` did when it leaked 4 waiter shells earlier.
  Third instance today of ONE root cause: trusting a proxy instead of the thing itself (a weight
  column vs a probe §136h; an exit status vs build output §136a; file-existence vs process exit).
2026-08-03 22:27:19 -06:00
Drew T a4bc49a23d feat(phase-30 S8): the x10-99 band closes 23/23; §137 makes REGALLOC-PERM arithmetic, not a permuter job
- S8-3 (23 fresh x10-99 families, 121-328 ins — the hardest band this session): draft 16/23 ->
  capture (1 PLUMBING / 6 DIFF) -> reconcile 1/1 -> redraft 6/6 => **23/23 (100%)**.
  Propagated 206 + 81 = 287 member-matches across 80+54 overlays. R22 clean-fleet 140/140.
  FLEET 95.97% fn / 93.4% instr / 87.5% distinct (77,404 uniq); dedup 1905/0; 0 NON_MATCHING.
- §136b CLOSES AT 15/15 — no function ledgered "genuine byte-DIFF" survived a redraft, all session.
- §137 (NEW, the session's most reusable result): REGALLOC-PERM — a clean 2-register swap — is a
  TWO-COMPILE ARITHMETIC PROBLEM. global.c:allocno_compare ranks by floor_log2(R)*R/L*1e4*size;
  read R and L out of `cc1 -dl -dg` for BOTH contenders AND their ranked neighbours to get the
  admissible priority WINDOW, then place a zero-byte `__asm__ __volatile__("" ::"r"(v))` so L lands
  inside it. func_801833F0: contenders ONE unit apart (1297 vs 1296), window (1228,1296), five
  placements probed, only L=219 -> pri 1232 worked. R and L are FORCED BY THE EMITTED CODE (L is
  recomputed post-sched1), which is exactly why source-reordering is a dead end for this class.
  Converts a class the permuter banked 0 from all session into a deterministic calculation.
  Companion: floor_log2 makes ref-count a STEP function (5/6/7 refs are worthless, you must reach 8)
  — func_8017EFA8 closed 30 register-name mismatches by taking a pseudo 4 refs -> 8 with a dead read.
- §136j — the failure MIX FLIPS WITH SIZE: <=120 ins fails ~70% on declarations; 121-328 ins fails
  86% on genuine codegen. Budget reconcile for the small band, redraft for the big one — and do NOT
  read 70% on a big-function wave as a broken pipeline; that is the expected shape.
- §137a — a gate verdict has a TIMESTAMP. Two "DIFF" ledger entries were STALE (draft rewritten 28
  min after the gate ran, never re-gated); both were already byte-perfect. Compare verdict time to
  draft mtime before redrafting. Plus two offline oracles an agent built: a FULL RELOCATION RESOLVE
  (catches wrong jal/%hi/%lo targets that match_one's mask hides) and a COLLATERAL CHECK (whole-TU
  objdump with/without splice). Together they discriminate all three causes of "match_one says MATCH
  but the overlay SHA differs" without running make.
- §136f addendum — the collider is often an already-banked SIBLING BELOW the splice; locate it by
  arithmetic (draft grows the file N lines, so TU line L reports at L+N).
- cookbook-index 380 -> 382 sections.
2026-08-03 16:25:06 -06:00
Drew T 1b8f26113c feat(phase-30 S7): close the B-shape queue — 144/144 drafts banked; §136b closes 9/9
- FINAL LANES: reconcile ×5 (5/5) + redraft ×1 (1/1) -> gate BANKED 6/6 -> propagated 50 members
  across 28 overlays. **ALL 144 DRAFTED TARGETS BANKED (100%); zero stubs remain in the queue.**
  R22 clean-fleet 140/140 (seventh time this session).
  FLEET 95.88% fn / 92.9% instr / 86.5% distinct (77,106 unique fns); dedup 1905/0; 0 NON_MATCHING.
- LANE RECORDS: reconcile 15/15 lifetime · redraft 9/9 · §136b closes at 9 FOR 9 (every function
  ever ledgered "genuine byte-DIFF" banked on redraft).
- THE CAPTURE CLASSIFIER, third and final defect (§136a): it decided PLUMBING by matching a regex
  against cc1's PROSE, and cc1's vocabulary is open-ended — `too many arguments to function` matched
  nothing, so a trivially reconcilable function sat UNKNOWN through two gate rounds. Now DERIVES the
  class from the closed invariant (did the compile produce an object: `make ... Error N` +
  `Deleting file`). Re-running it moved 5 PLUMBING / 1 UNKNOWN -> 5 PLUMBING / 1 DIFF, and BOTH
  reclassified functions then banked. Three defects in one small tool in one session — an
  unreachable exit-status branch, a missed phrasing, and the prose-matching design behind both —
  each SILENTLY MIS-ROUTING REAL WORK. R33 in one line: if an invariant answers it, never re-parse.
- §136f — two declaration sub-cases: (1) a symbol you call may be DEFINED, not just declared, BELOW
  your splice point (func_8017D540 is defined 275 lines below as int(int); the draft guessed
  void(s32) from a bare jal); (2) an ARITY clash on the symbol you are DEFINING cannot be fixed by a
  cast — use the §37/§124 asm-label alias (func_801848DC; in-TU precedent at :8872).
- §136g — TWO INDEX ROUTINGS BYTE-REFUTED (func_801863B4). The index sends BRANCH-POLARITY to §3-T4
  (invert) and §34 (zero-byte fence); the agent tested BOTH at zero, read the gcc-2.7.2 source, and
  found jump.c:1806 `if (foo) bar; else break` range-swap — which runs long BEFORE reorg, so a fence
  CANNOT block it. Real lever: put a label between the if-join and the return label (wrap the loop
  in the guard). Also: same-address lh+lhu is MIPS LOAD_EXTEND_OP==ZERO_EXTEND (mips.h:1163), and
  combine collapses the pair unless the HImode pseudo has two reaching defs.
  REFUTED ROUTINGS ARE RECORDED NEXT TO THE CORRECT ONE — otherwise the next agent re-runs them.
- cookbook-index 375 -> 377 sections (§136 .. §136g earned this session).
2026-08-03 13:02:29 -06:00
Drew T b61d805b8b feat(phase-30 S7): wave 4b batch 3 — 35 heads + 305 members; the 144-family B-shape queue is worked
- BATCH 3 (37 targets, 41 agents, 2.75M tok -> 35 claimed): gate BANKED 35; family_sweep propagated
  305 member-matches / 39 failed across 77 overlays (14 STRUCT skipped by design). 340 instances.
  R22 clean-fleet 140/140 (sixth time this session).
  FLEET 95.86% fn / 92.9% instr / 86.5% distinct (77,061 unique fns); dedup 1905/0; 0 NON_MATCHING.
- WAVE 4b COMPLETE: b1 32/37 + b2 35/37 + b3 35/37; with wave 4a (30/33) the whole 144-family
  B-shape queue that opened this session is worked through — 138 of 144 drafts banked (96%).
- §136e — batch 3's two HONEST NEGATIVES, worth as much as the wins:
  (1) §136c SIBLING-FIRST HAS A PRECONDITION. func_801899AC's family has all 13 members still
      unmatched and no engine_core.h twin, so there IS no byte-verified sibling and the search is
      pure cost. Check a banked sibling EXISTS before spending the greps.
  (2) A loop increment in the loop-back DELAY SLOT + a compensating negative addiu is a SOURCE
      SHAPE, not a reorg artefact — MIPS1 has no annulling, so reorg CANNOT invent the
      compensation. Write `p += 2; if (t == cur) break; ... p -= 2;`. combine's reg_n_sets==1 guard
      stops the addiu folding into the following lw. The index's delay-slot entries point at reorg,
      which is a dead end for this class.
  Plus a new §136-L1 application on the RETURN axis (an over-scoped temp became a global allocno and
  swapped $v0/$v1 with the returned local, collapsing the target's `j` + `addu` return).
- COMPOSITION, demonstrated on func_8017D5F4 (46 ins): flat early-returns -> dead-local frame pad ->
  s16 locals -> operand order -> 3 register pins -> 2 zero-byte re-ties -> permuter for the last 2.
  THE PERMUTER IS THE LAST STEP ON AN ALREADY-PINNED BASE, not the first.
- cookbook-index 374 -> 375 sections. 6 stubs remain; per §136b none is a wall on one attempt.
2026-08-03 12:34:53 -06:00
Drew T 7f70b6850a feat(phase-30 S7): batch 2 + reconcile + redraft — 41 heads + 431 members; §136b closes 8/8
- THREE LANES: wave 4b batch 2 (37 targets, 46 agents, 3.44M tok -> 35 claimed) + the reconcile lane
  on 3 PLUMBING failures (3/3) + a REDRAFT lane on 4 DIFF-ledgered failures (4/4). Combined gate
  BANKED 41; family_sweep propagated 431 member-matches / 29 failed across 79 overlays.
  103 of 107 drafts banked (96%). R22 clean-fleet 140/140 (fifth time this session).
  FLEET 95.77% fn / 92.9% instr / 86.4% distinct (76,824 unique fns); dedup 1905/0; 0 NON_MATCHING.
- §136b CLOSES AT 8/8: every function ledgered "genuine byte-DIFF" banked on redraft — wave 3's
  four, the THREE I classified from wave 4a's capture, and one from batch 1. The classifier is
  right about what it measures ("this draft compiles clean and differs in bytes"); reading that as
  "this function resists matching" is the error. A DIFF verdict is a fact about ONE DRAFT.
- §136a CORRECTED (a reconcile agent refuted me against the bytes): I wrote "70% of gate refusals
  are paperwork, not codegen". WRONG. A declaration conflict ABORTS THE COMPILE, so a PLUMBING
  verdict says NOTHING about the body. Two of three second-round PLUMBING drafts had a real codegen
  residual behind the conflict (func_80188694 DIFF/4 SCHEDULE-REORDER, closed with a §21 zero-byte
  re-tie after six other variants failed; func_8018C638 DIFF/6 ADDRESSING/cse). Both agents ran
  match_one on the untouched draft FIRST and rejected my premise — which is what §135 asks for.
- §136c SIBLING-FIRST IS A DERIVATION SHORTCUT, not just a conflict fix: grep engine_core.h's
  DEFINE_func_* bodies for a byte-verified NEAR-TWIN before deriving from the .s. func_801859D8
  found DEFINE_func_80185978 (identical offset chain, 3 differing constants), reused its expression
  forms verbatim -> FIRST-DRAFT MATCH, and the twin generalizes to its whole 10-member family.
  Search order: near-twin -> banked same-TU sibling -> the .s -> the Ghidra seed LAST (byte-proven
  an entirely different body twice this session).
- §136d, four new gcc-2.7.2 levers from the redraft lane, each with its REFUTED axis recorded:
  RC-12 $0-add opaque copy (cse.c canonical-copy promotion; do NOT pin the pair to real regs);
  jump.c if-then-else -> conditional-overwrite collapse (defeat with TWO SEPARATE CALLS, not a
  ternary); fix the STORE not the load for a load hoisted above a constant-address store (the
  INDIRECT_REF reshape is the wrong half of the /s lattice, 2 -> 32 mismatched); a branchless flag
  is -(a != b) & 0xFF, never a ternary.
- cookbook-index 372 -> 374 sections. Batch 3 staged with all of the above promoted into its prompt.
2026-08-03 11:19:28 -06:00
Drew T cc3c49d7af feat(phase-30 S7): wave 4b batch 1 — 32 heads + 365 members; §136b (a DIFF verdict is not evidence)
- WAVE 4b BATCH 1 (37 volume-lane targets, 10-19 members, <=60 ins; wave 4a's §136 idioms promoted
  into the drafting prompt per the measured 83%->93% law): 50 agents / 4.35M tokens / 32 min ->
  34 claimed MATCH -> gate BANKED 32 -> family_sweep propagated 365 member-matches / 4 failed
  across 84 overlays (3 STRUCT skipped by design). 397 function-instances from 37 targets.
- §136b — THE FINDING THAT CHANGES THE BACKLOG: all FOUR functions wave 3 ledgered as "genuine
  byte-DIFF" BANKED on redraft. The recorded causes were never codegen:
    func_801845B0  a branch to the EPILOGUE misread as an inner early-exit -> the whole tail was
                   hoisted out of its enclosing if (control-flow misread)
    func_80184A94  a declaration conflict on a symbol declared BELOW the splice point; closed by
                   copying an already-banked family sibling's decl forms verbatim (§71)
    func_8017BEBC  the cached Ghidra seed was an ENTIRELY DIFFERENT body and the prior draft
                   followed it; the .s was the only usable source
    func_8018480C  re-derived clean
  => a DIFF verdict describes THE DRAFT THAT WAS ATTEMPTED, never the function's matchability.
  Never retire a target on one; route it to REDRAFT. And re-GATING an unchanged draft is not a
  retry — which is exactly why wave 4a's 3 DIFFs stayed stubs through this gate (same bytes
  resubmitted); they still owe an actual redraft and are now likely winnable.
  Corollary: backlog entries carrying an old closeness/class are stale by construction (P29
  measured 77% of stored drafts decayed) — re-verify before valuing one.
- The wave-4b prompt handed each retry its prior verdict EXPLICITLY LABELLED "a data point, not a
  verdict — re-derive from the .s". Every retry agent did exactly that and refuted it.
- R22 clean-fleet 140/140 (fourth time this session). FLEET 95.63% fn / 92.8% instr / 86.3% distinct
  (76,499 unique fns); dedup 1905/0; C1 240496/240496; 0 NON_MATCHING (G4).
- Orchestration: this batch's workflow script was GENERATED from the manifest files rather than
  hand-pasted — transcription had already cost this session one dead launch (args-as-string) and
  cost the prior session three agents' time (hand-typed _jr_* paths). Generate the artifact; do not
  ask yourself to be careful. cookbook-index 371 -> 372 sections.
2026-08-03 10:29:21 -06:00
Drew T d00dfe363b feat(phase-30 S7): reconcile lane 7/7 — wave 4a closes at 30/33 (91%), +76 members
- RECONCILE LANE: all 7 PLUMBING failures FIXED and banked (329K tokens — ~13x cheaper than the
  drafting wave's 4.44M). Propagated +76 member-matches / 0 failed across 51 overlays.
  Wave 4a final: 30/33 heads (91%) + 327 members = 357 function-instances from 33 drafted targets.
- THE CAPTURE CLASSIFICATION WAS EXACTLY PREDICTIVE: all 7 PLUMBING banked, all 3 DIFF stayed stubs
  (func_8017E978 / func_80184494 / func_80184960 -> redraft lane, their C is wrong). That is what
  makes the ~10-build capture step worth running before any reconcile fan-out. The lane is now
  19/19 across three waves.
- EVERY reconciled draft had a HIDDEN SECOND CONFLICT cc1 never reached (it reports only the first)
  -> "grep the whole TU in one pass" must be in the RECONCILE prompt, not just the drafting prompt.
  One agent additionally assembled the spliced TU and masked-compared its function IN TU CONTEXT
  (67/67) — proving the casts byte-neutral in situ, not merely standalone.
- NEW HAZARD, agent-surfaced (§136a corollary): an agent chose a SHARED scratch path, a concurrent
  agent overwrote it, and its verification silently compiled ANOTHER agent's TU and returned a
  meaningless rc=0. It caught the swap only because the emitted .s lacked its own function. A shared
  scratch path yields a CONFIDENT WRONG VERDICT, and no tool fix reaches it — the choice happens
  inside the agent, so the PROMPT must mandate a process-unique path. This is the Phase-28
  match_one fake-isolation defect recurring one level up.
- R22 clean-fleet 140/140 (third time this session). FLEET 95.52% fn / 92.7% instr / 86.1% distinct
  (76,273 unique fns); dedup 1905/0; C1 240496/240496; 0 NON_MATCHING in any default build (G4).
- .run/s7_extra.txt: wave 4a's idioms compiled into the wave-4b drafting prompt (the promotion that
  measured 83%->93% between waves 1 and 2).
2026-08-03 09:47:45 -06:00
Drew T fdb5813fc1 docs(phase-30 S7): S6c banked ×12 (all in the P27 SC07 quartet); blockers classified 7/3; §136a
- S6c (deterministic, ~0 agent tokens): 12 sibling banks across 3 of 9 jr zero-crack families
  (func_80178D40 890ins 4/4, func_801734BC 4/4, func_8012ACE0 4/4). The other 6 are ledgered:
  5 gate-fail (genuine byte DIFF) + 1 carve-fail (span table starts do not fit the span).
  R22 clean-fleet 140/140 over the whole S6c series.
- FINDING: all 12 banks landed in ov_SC07_006/007/010/011 — the four overlays P27 discovered and
  P28 made citizens (R36). P28 drained their h_exact backlog via dedup_extend; the jr/h_seq
  propagation lane was still owed. R14 GUARD AGAINST OVER-READING IT: the quartet are the top four
  overlays by remaining zero-crack residue (2,190-2,355 ins each vs 500-870 typical) but hold only
  7% of the 2,114 remaining slots — a per-overlay priority signal, NOT a bulk lever.
- BLOCKER CAPTURE for the 10 wave-4a gate failures -> .run/s7_blockers.json: 7 PLUMBING (all
  `conflicting types for func_X`) / 3 genuine byte-DIFF. 70% of "the gate refused" is declaration
  paperwork. New tool .run/s7_capture.py (any overlay/any draft dir; reverts the TU in a finally:).
- MY DEFECT, FIXED AND DISTILLED (§136a): the capture tool first classified on the EXIT STATUS, so
  its `rc == 0 => byte DIFF` branch was UNREACHABLE — `make build` runs `check`, so a draft that
  compiles perfectly and merely differs in bytes also exits non-zero, and all 3 real DIFFs were
  filed as "unknown". Now classifies on the OUTPUT ([FAIL]/got/want vs a non-warning error line);
  the warning-exclusion matters because `conflicting types` also appears benignly for builtins.
- Also probe-discipline: my first S6c probe reported 1/9, which was 1 bank + 8 CORRECT REFUSALS —
  jtbl_family_bank refuses on a dirty config/+src/ (its per-sibling revert restores from HEAD).
  Driver now commits between families. A uniform failure across N functions is a statement about
  the mechanism, not the functions (§134).
- cookbook-index 364 -> 371 sections, --check green. CURRENT_PHASE SESSION-31 checkpoint refreshed
  with the queue re-derived at HEAD (the S30 ROI-floor trigger stays REFUTED — do not close on it).
2026-08-03 09:32:36 -06:00
Drew T 09d96b1531 feat(phase-30 S7): wave 4a — 23 heads + 251 members banked ×N; cookbook §136 (the local-variable lever)
- WAVE 4a (T6, the 33 high-value B-shape families, 61-120 ins / >=10 members):
  33 targets, 46 agents, 4.44M tokens, 29 min -> 29 claimed match_one MATCH.
  Whole-binary gate BANKED 23/33 (70%); family_sweep --hseq --band all propagated
  251 member-matches across 69 overlays (13 failed, 4 STRUCT skipped by design).
  Total 274 function-instances from 33 drafted targets.
- R22 clean-fleet: make clean + extract-all + check-all -> 140 passed, 0 failed of 140.
  make report: fn-count 95.49% / instr 92.6% / distinct 85.9% (76,180 unique fns);
  dedup 1905 validated / 0 failed; 0 NON_MATCHING in any default build (G4).
- COOKBOOK §136 (R30, distilled in-session from 25 banked functions' index-gap reports):
  the wave's finding is that in the 60-120-ins band most "regalloc residuals" are decided
  by HOW MANY C LOCALS AND AT WHAT SCOPE, not by register pins (local-alloc.c:472 promotes
  any pseudo with REG_N_DEATHS>1 to a global allocno). 19 byte-verified idioms: 6 splitting/
  merging rules, 6 type-form rules, 5 scheduling rules refining §135-2/§135-4, 2 declaration-
  surface rules. One case explicitly REFUTES the pin as the lever for a redundant copy.
  cookbook-index regenerated 364 -> 370 sections, --check green.
- TWO SELF-CORRECTIONS (R37/R14), both caught before they could mislead sizing:
  (1) I wrote the tier split from the workflow's by_tier, which counts CLAIMED matches (29)
      not banks (23). Derived per-function: Opus-direct 10/14, Haiku-direct 3/8, Opus
      escalation-after-Haiku-miss 10/11. The operative number is the 10-of-11 rescue rate;
      on this band Haiku is triage, not a substitute (it is == Opus only at <=50 ins).
  (2) The gate printed "1/1 banked FAILED: func_X" on single-draft groups (the known
      double-list artifact) -> bank set DERIVED from corpus.stubs instead. Totals agreed.
- TOOLING: the wave scripts now parse args-as-string and assert Array.isArray, so the
  roadmap's standing "args must be an array" gotcha cannot silently kill a future wave
  (it killed wave 4a's first launch in 60ms with 0 agents).
- tools-health green + fail-closed before matching (corpus+resident 0 PHANTOM/0 TRUNCATED,
  audit-binaries 140/140 citizens, cdecl, report/lint/dedup).
2026-08-03 08:57:16 -06:00
Drew T 6fe9b66f2d feat(phase-30 S6h): wave 3 — 34/38 banked, +639 members, reconcile lane now 12/12 (R22 140/140)
- 38 targets / 44,297 templ ins, model-routed (Haiku <=89 + Opus escalation, Opus direct >=90):
  52 agents, ~4.1M tokens -> gate 27/38 (71%). All 11 failures captured + classified: 8 declaration/
  link plumbing, 3 genuine byte-DIFF. An 8-agent Opus reconcile wave fixed 8/8 (7 banked) ->
  wave-3 total 34/38 = 89%. Propagation +639 members / 1 failed / 83 overlays.
  R22 clean-fleet 140/140. Fleet 95.42% fn / 92.4% instr / 85.5% distinct.
- DESIGN (S27 law applied BEFORE it bit): six of eight reconcile targets share ONE TU, so this wave
  FORBADE agents any build — six concurrent splice-builds would have clobbered a tracked file.
- THE AGENTS OUT-DIAGNOSED MY BLOCKERS:
  * func_801848B0 — an agent REJECTED MY PREMISE: I said byte-correct + decl-blocked; it ran
    match_one first, found a real 1-ins DIFF, fixed both. R14 aimed back at me, correctly.
  * func_8017C5F0 — the "invented symbol" D_801DA0F0 is an INTERIOR ADDRESS: offset 0x6C into
    D_801DA084 (0x801DA084..0x801DA103). The lui/addiu pair builds an interior pointer.
  * func_8018A860 — the TU declares memcpy THREE times with incompatible signatures, with a latent
    byte bug behind it. One symbol declared three ways is a defect awaiting the next draft.
- Carried (4): func_80184A94 (match_one MATCH, gate-refused) + 3 genuine byte-DIFFs
  (func_801845B0, func_8017BEBC@ov_SC02_026, func_8018480C).
2026-08-01 20:28:44 -06:00
Drew T 372dc62d35 feat(phase-30 S6g): wave 2 — 93% bank rate (was 83%), all 4 reconciles closed, +342 members (R22 140/140)
- 15 targets (11 fresh Haiku + 4 gate-failed reconciles on Opus), 15 agents, ~0.74M tokens.
  Gate banked 14/15 (93%) vs wave 1's 20/24 (83%); ALL 4 RECONCILES BANKED.
  Propagation +328 members / 0 failed / 76 overlays. R22 clean-fleet 140/140.
  Fleet 95.23% fn-count / 92.1% instr / 85.0% distinct (phase opened 92.00 / 87.5 / 78.0).
- THE 83->93% CAME FROM THREE FIXES, ONE PER WAVE-1 FAILURE (the S27 finding reproducing):
  (1) args pasted from the DERIVED manifest, never typed — all 30 paths verified on disk first;
  (2) blocker-capture BEFORE the reconcile fan-out (S29 law: agents cannot run the gate, so a
      match_one-MATCH draft dying on `conflicting types` reads to them as a codegen wall) —
      each got the exact symbol+line plus the two byte-neutral levers;
  (3) wave-1's Opus DISCOVERIES became wave-2's Haiku INSTRUCTIONS (ori-vs-addiu unsigned
      destination; store-sinking scheduler order).
- THE RECONCILES OUT-DIAGNOSED MY CAPTURE: func_80189B78's error named ONE symbol; the agent found
  SIX invented prototypes, two AFTER the splice point where cc1 had not yet reached — all fixed by
  copying the TU's decls verbatim + casting at the call site, zero bytes changed. func_8018584C had
  lever (A) blocked in BOTH directions (the draft must also compile standalone for match_one) and
  closed with the DATA form of the asm-label alias. func_80180A4C was one character class (s32[] vs
  the TU's u8[], declared 11 lines after the splice point).
- Carried: func_80189C4C (the one agent that returned no structured result; gate refused).
2026-08-01 19:35:24 -06:00
Drew T 6e181db771 feat(phase-30 S6f): B-shaped wave — Haiku drafts, Opus closes, +544 members (R22 140/140)
- POOL (derived from the regenerated map): 36 families / 28,829 templatable ins, kind=modal (no
  member matched ANYWHERE so no sweep could reach them), >=20 members, <=60 ins, non-jr, and NOT
  ONE exemplar in ov_SC01_077. Hand-calibrated 3/3 one-shot before scaling (Phase-15/18 discipline).
- WAVE (ultracode; Haiku drafters + Opus escalation, 24 targets): 31 agents, 0 errors, ~2.0M tokens,
  12.5 min. Agents claimed 24/24 MATCH; the whole-binary gate banked 20/24 (83%); propagation
  +524 members / 0 failed / 91 overlays. 17 of 20 banks were HAIKU, 3 Opus — the
  cheap-tier-ab-validated call (Haiku == Opus at <=~50 ins, ~4.8x cheaper) held on real work.
- WHAT OPUS BOUGHT: (1) a `sh` of a constant with the stored width's top bit set needs a u16
  destination — via s16 gcc folds it sign-extended and li emits addiu, via u16 force_fit_type keeps
  it positive and li emits ori; (2) a schedule-reorder closed by STATEMENT ORDER not the permuter
  (gcc's list scheduler preserves relative order of disambiguable stores); (3) three loose-typing
  fn-ptr casts a cheap drafter had misread as delay-slot/permuter residuals.
- MY ERROR (R37/R14): I generated the manifest to .run/s6f_wave_targets.json then HAND-TRANSCRIBED
  the args into the Workflow call, pattern-filling _jr_8017BEBC across overlays where no such split
  exists (corpus.stubs says _jr_8017AE2C). Three agents lost time rediscovering real paths. The gate
  driver written after (.run/s6f_gate.py) DERIVES every TU/split from corpus.stubs and asserts
  nothing. Assert nothing you can derive.
- The 24->20 gap is the known match_one->gate gap (standalone compile cannot see a TU decl conflict;
  Phase 19 measured 88-92% -> 60-71%). 4 carried: func_8018584C, func_80180A4C, func_8017CC80,
  func_80189B78.
- R22 clean-fleet 140/140. Fleet 95.13% fn-count / 92.0% instr / 84.9% distinct
  (phase opened 92.00 / 87.5 / 78.0).
2026-08-01 19:17:18 -06:00
Drew T e6cec30736 feat(phase-30 S6f): calibrate the B-shaped vein — 3/3 one-shot by hand, +65 members (R22 140/140)
- func_8017E934 (ov_SC05_001, 29 ins x65): hand-drafted off the .s, match_one MATCH first try,
  whole-binary gate byte-identical, propagated 64 members / 0 failed across 63 overlays.
- That makes the B-shaped lane 3-for-3 one-shot (func_8017CDD8 17ins, func_8017CE7C 16ins,
  func_8017E934 29ins) for ~0 agent tokens = 330 member-matches from 62 instructions of C.
- THE POOL (derived from the regenerated map): 36 families / 28,829 templatable ins that are
  kind=modal (NO member matched anywhere, so no sweep could ever reach them) with >=20 members
  and <=60 ins, non-jr. NOT ONE exemplar is in ov_SC01_077 — they are invisible to exactly the
  two habits this phase already corrected (the ov077-source default and --band substantial).
- The calibrated recipe, now the wave prompt: read the .s as ground truth (a cached Ghidra-C seed
  was measured this session decompiling a DIFFERENT body) -> conform every callee decl to what the
  TU already says (the PLUMBING class: standalone-MATCH C is gate-REJECTED as `conflicting types`
  when it redeclares a callee the TU defines as (void)) -> match_one -> whole-binary gate.
- R22 clean-fleet 140/140; fleet 94.96% fn-count / 91.9% instr / 84.7% distinct.
2026-08-01 18:53:53 -06:00
Drew T 381cd56d40 feat(phase-30 B): the x138 era was NOT over — 2 tiny cracks -> 268 members (R22 140/140)
- A: frontier regen at HEAD (sigs + family_hseq) before pricing anything (R35). Also the reason
  it was needed: .run/hseq_verified.*.txt has accumulated 22,841 files across every sweep ever
  run, so any per-family analysis globbing them over-counts; the regenerated map derives state
  from sigs + corpus.stubs (R33), which is the authority.
- B / THE FINDING (third §133-class miss in a row): the S29 checkpoint's structural signal
  "after S2 the x138 era ENDS — those are the last two crackable fleet-wide families" — the stated
  TRIGGER for the phase close — is wrong. Two fresh-crack families with >=126 members were open:
    0x8017cdd8 ov_SC02_039  17 ins x 142 members  PURE
    0x8017ce7c ov_SC03_114  16 ins x 126 members  IMM
  Both kind=modal (NO member matched anywhere, so no sweep could reach them) and neither exemplar
  in ov_SC01_077 — invisible to exactly the two habits this phase already corrected.
- Both hand-drafted off the .s, match_one MATCH on the FIRST try, ~0 agent tokens. First gate
  attempt failed PLUMBING (not DIFF): the draft declared `extern void func_8017CFCC(s32 a0)` while
  the TU DEFINES `void func_8017CFCC(void)` — the target passes $a0 only because the caller's
  incoming argument still sits in the register (loose typing). Byte-true C calls it with no
  argument; re-verified MATCH, gated byte-identical, propagated 266 members / 0 failed / 118 overlays.
- R14 on the seed: the cached Ghidra-C for func_8017CE7C decompiled an entirely DIFFERENT body
  (three calls absent from the asm). Reading the .s is what made it one-shot.
- R22 clean-fleet 140/140. Fleet 94.88->94.96% fn-count, 91.9% instr, 84.6->84.7% distinct.
2026-08-01 18:43:14 -06:00
Drew T 39558b2991 fix(phase-30 S6b): MULTI-LINE BLINDNESS in family_remap — 4 faces, 3 fixed; +740 members (R22 140/140)
- ONE root cause, four faces (cookbook §134): extract_unit's preamble scanner reads C
  one line at a time, so every construct that WRAPS was misread.
  D1 the {-guard fired on a documentation comment mentioning a brace -> carry truncated
     mid-comment -> `parse error before 'the'`.
  D2 _def_head_at's "param list continues -> ANSI definition" fallback accepted a WRAPPED
     DECLARATION as a definition head -> a 16-line fragment with no body, closed by a brace
     pair inside a comment -> a silent 0/137 that reads exactly like a compiler wall.
  D5 the backscan met a multi-line typedef's CLOSING line `} T;` first and stopped -> the
     type never travelled -> `T undeclared` across 17 families / 24,332 templatable ins.
     (The code comment claimed they "route through the engine_types.h lift"; measured, they
     routed nowhere.)
  D4 wrapped __asm__("func_...") alias invisible to a single-line regex — MEASURED (1 exemplar,
     3,288 ins, second blocker behind it) and deliberately NOT fixed; it now returns None so the
     sweep reports a VISIBLE skip instead of 137 silent failures (R32).
- Fixes: _def_head_at(ln, idx, more=()) lookahead (no-lookahead keeps the historical answer);
  {-guard exempts comment-only lines + an R32 dangling-comment backstop; forward brace scan
  counts over cdecl._mask (R33, one masking oracle); _typedef_block_start carries whole blocks.
- BLAST RADIUS (R14): extract_unit diffed vs the pre-fix tool over all 181 zero-crack exemplars
  -> 157 byte-IDENTICAL, 24 changed, all in the intended direction.
- PAYOFF: D1+D2 +323 members from families that banked ZERO; D5 +417 incl. func_8012B77C 139/139
  (8,062 ins) and func_80128C98 137/275. S6 total 1,582 members (pre-fix tool scored 842).
- R22 clean-fleet 140/140. Fleet 94.43->94.88% fn-count, 91.4->91.9% instr, 84.0->84.6% distinct.
- TELL worth keeping (§134): bimodal bank rates (57 all / 52 zero / 8 partial) are a TOOLING
  signature, not codegen. Probe one member and read one compiler error before writing a family off.
2026-08-01 17:28:06 -06:00
Drew T 8a519addf7 feat(phase-30 S6a): source-agnostic zero-crack sweep — 842 members banked (R22 140/140)
- family_sweep --hseq --band all (no --source override), 117 pre-classified families:
  staged 2735 drafts / 1239 groups / 0 skips -> BANKED 842, R22 clean-fleet 140/140.
  Fleet 94.43->94.67% fn-count, 91.4->91.6% instr, 84.0->84.5% distinct.
- R37 setup: the 190 zero-crack families decomposed with ZERO builds — 117 sweepable /
  17 §94-§100 multi-line-typedef-blocked (24,332 ins incl. the 275-member 0x80128c98) /
  9 jr (§53 carve path) / 47 remap-REFUSED.
- R14 PREMISE CORRECTION: the "every sweep passed --source ov_SC01_077" mechanism in the
  post-wave checkpoint is wrong (that IS the default and overrides nothing). The real gate
  was --band substantial: only 13 of 181 non-jr families are substantial. --band all is it.
- FINDING: the residue is bimodal — 57 families ALL-banked, 52 ZERO, 8 partial — the shape
  of a per-family blocker, not per-member codegen. 8 probed via the new generic
  .run/s6_diag.py (one build per family, not 137): 7 of 8 are declaration/carry plumbing.
  Two proven family_remap defects located at source (D1 comment-line {-guard truncating the
  preamble carry; D2 _def_head_at accepting a wrapped multi-line DECLARATION as a def head).
2026-08-01 16:42:21 -06:00
Drew T 21ccb171ac feat(phase-30 UC): wave-2 propagation — 2,192 members, fleet 91.4% instr (R22 140/140)
19/19 wave-2 heads banked and propagated: 2,192 member-matches / 411 stage-but-DIFF residue
(each individually gate-rejected and reverted). FLEET 94.43% fn / 91.4% instr / 84.0% distinct;
dedup 1905/0; 0 NON_MATCHING (G4).

Session arc: 93.25->94.43 fn / 89.2->91.4 instr / 80.5->84.0 distinct.
Phase arc:   92.00->94.43 fn / 87.5->91.4 instr / 78.0->84.0 distinct.
2026-08-01 12:11:23 -06:00
Drew T 1a1463b1c6 feat(phase-30 UC): wave-1 propagation — 1,370 member instances, fleet 90.9% instr (R22 140/140)
- 9 banked heads propagated: 1,096 non-jr member-matches (family_sweep --hseq --band all, 0 failed)
  + 137 (func_80159A20, jr) + 137 (func_801549F8, jr)
- func_80176734 (371 ins, the largest single item in the frontier) banked + propagated
- FLEET 93.81% fn / 90.9% instr / 83.9% distinct; dedup 1905/0; 0 NON_MATCHING (G4)
- cookbook §132b (--span-rel: the already-matched owner that is ITSELF multi-switch) and §133
  (the DEFAULT-FILTER class — three times in one session a tool silently answered a narrower
  question than the one asked: my own >=80-ins cut, worklist's h_exact pricing, --band substantial)
2026-08-01 11:19:28 -06:00
Drew T 4a23c82a33 feat(phase-30 S2): func_8016EC0C x138 complete — 137/137 siblings, fleet 90.1% instr (R22 140/140) 2026-08-01 09:43:30 -06:00
Drew T 56210fdadd feat(phase-30 S1): zero-crack tier — 186 members banked; fleet crosses 90% instr
- head func_8014032C 137/137 (25,071 ins, --span-rel §132b) + jr tier 46 members incl.
  func_8017BEBC 13/13 (12,376), func_8015A3C8 6/6, func_8015AE2C 4/4, func_8017A4AC 4/4,
  func_8013FFD8 9/10 + non-jr pass 3.
- MY ROUTING ERROR (recorded): pass 1 ran all 28 families through jtbl_family_bank; 13 are NOT
  jr functions, so they carve-failed by construction — §123's own law ('propagate a family with
  the tool its TIER needs'), which I had quoted in the task description. Re-routed via
  family_sweep --hseq: 3 banked / 38 failed => that residue is the genuine stage-but-DIFF class.
- MEASURED: 13 of 29 zero-crack families have remaining members ONLY in the 4 P27-onboarded SC07
  overlays (18,856 ins) — not a stub-count gap; they simply missed every sweep that predates them.
- R22 clean-fleet 140/140. Fleet 93.38% fn / 90.0% instr / 82.4% distinct; dedup 1905/0.
  Phase arc: +1.38pp fn / +2.5pp instr / +4.4pp distinct.
2026-08-01 09:14:46 -06:00
Drew T bdb0b0f60a docs(phase-30 S1): digests after func_8014032C x137 — fleet 89.8% instr / 82.0% distinct (R22 140/140) 2026-08-01 08:50:12 -06:00
Drew T fc307418a5 docs(phase-30): the jr-pair sweep landed 137/137 ×2 — §132a --like over-transfer + fleet 89.6% instr
- 2 × 138 = 276 function-instances banked (exemplar + 137 siblings each); the -O0 cluster is now
  COMPLETE fleet-wide (these were the last open stubs in every overlay's _o0* region)
- §132a: --like matches by subseg ROLE NAME; ov_SC07_010 shares the exemplar's _o0 role (the only
  other overlay so named — the other 136 are _o0c, whose role never matched, which is the only
  reason the sweep worked at all). Six derived starts for three emitted tables; guard shipped.
- R22 clean-fleet 140/140. Fleet 93.33% fn-count / 89.6% instr / 81.6% distinct (+260 unique fns);
  dedup 1905/0; 0 NON_MATCHING (G4). Phase arc: 92.00->93.33 / 87.5->89.6 / 78.0->81.6.
2026-08-01 00:15:15 -06:00
Drew T b9efe66f91 fix(phase-30): the JR-PAIR "wall" was TWO instrument defects — pair banked, class retired
S28 ledgered `JR-PAIR-IN-ONE-O0-OBJECT` (two jr fns matched in one -O0 object => a clean
build that cannot link: `undefined reference to $L105` + `func_8013C938`) with §81 step 1
(isolate one into its own code subseg) as the untested escape. BOTH the class and the escape
are REFUTED — no isolation, no compiler wall, both fns banked from a genuinely clean fleet.
The 4th consecutive "structural wall" to resolve to our own tooling (§124/§125/§126/§131).

- DEFECT 1 (tools/jtbl_carve.py): ov_SC01_077_o0's carve at 0xb01a4 predates the §8e
  `tables=` persistence and is a MERGED DOUBLE (func_8013C0F8 $L75 + func_8013C414 $L105);
  the 2nd owner is MATCHED so extract pruned the stub .s naming its table. The single-table-
  predecessor inference derived 3 starts where the object emits 4 tables -> JTBL_PADS 0,4,4
  -> jtbl_rodata_pads refused mid-stream, correctly. FIX: R32 coverage assertion + payload
  recovery at the single choke point (spec_from_starts) — every zero word inside a span is an
  original `.align 3` pad (the tool's own axiom), so the word after it STARTS a table;
  recovered starts are logged. No-op where structure is known (the 134 sibling _o0c spans
  carry tables=+0x0,+0x70). Honest limit: tight (0-pad) boundaries stay unrecoverable but
  fail LOUD via the filter's count guard — never silent.
- DEFECT 2 (Makefile): no .DELETE_ON_ERROR, so `as` (a pipeline consumer) left a TRUNCATED .o
  on disk — 12 of 16 T func_, undefined $L57/$L59/$L63/$L75/$L76 — newer than its .c, and the
  NEXT build linked the corpse. That IS the S28 link error, one build downstream of a loud,
  correct compile error. Negative-control-proven on a scratch invocation.
- BANKED: func_8013B83C (272 ins) + func_8013BD74 (198 ins) in ov_SC01_077 (d19c9580).
  Byte proof: 4 tables 0x801D8254/828C/82FC/836C (13/27/27/27 entries, each zero-pad
  separated); span 0xb00fc..0xb0280 = 388 B = 52+4+108+4+108+4+108 exactly; spec 0,4,4,4.
- R22 clean-fleet (make clean + extract-all + check-all): 140 passed, 0 failed of 140.
  The incremental result was NOT trusted (§130). Fleet 93.25% fn-count / 89.2% instr /
  80.5% distinct; dedup 1905/0; 0 NON_MATCHING (G4).
- cookbook §132 + index (356 sections): the mechanism, the fingerprint (an undefined $L<n> in
  a LINK error is a truncated object, never codegen), the 30-second standalone-TU ladder that
  named the 4th table owner before any build, and the transferable rule — a fail-loud guard is
  only as trustworthy as the artifact hygiene around it.
2026-07-31 23:35:14 -06:00
Drew T b58fd82068 docs(phase-30): SS131 the jtbl OVER-SPAN + checkpoint — #9 SOLVED, JTBL-CARVE-BREAKS-BYTES retired
SS131: `sltiu N` is ground truth in BOTH directions. jtbl_range already EXTENDS a span the
dlabel cut short and WARNS when a span is shorter than the bound, but had no clamp for a
span too LONG for a NON-ZERO reason — and the trailing trim only removes ZERO words, so
ordinary data that spimdisasm ran into the dlabel slipped through and under-filled the piece.

Records the reusable FINGERPRINT of an under-fill, because it does not look like codegen:
hundreds of 1-byte diffs spread over most of the overlay, ~95% at byte 0 (mod 4) = the low
byte of a 16-bit immediate, every one changing by exactly -4. Bucket differing bytes by
offset%4 and decode a few words; uniform small deltas in the immediate field mean LAYOUT,
not codegen. (Measured: 812 of 853 at pos 0 mod 4, all -4.)

The clamp's authorization matches the extension path exactly: unambiguous sltiu bound only,
and REFUSE LOUDLY if any surplus word is a plausible code address.

This was the single instrument failure that survived SS125's retraction round — the one case
where "the tool is broken" was actually true. Now fixed, with the 710-ins behemoth banked.
2026-07-31 20:05:44 -06:00
Drew T 20e970a928 docs(phase-30): SESSION-28 CHECKPOINT — fresh-session handoff for T1/T3, Max prompt for #9
Fleet 93.25% fn-count / 89.2% instr / 80.5% distinct; R22 140/140 (thirteen runs).
Nothing running, tree clean, lock FREE.

Records for the fresh session: the ordered resume list (T1 + T3 need /effort ultracode and a
WAIT for the toggle; #9 and T5 need Max), the JR-PAIR-IN-ONE-O0-OBJECT wall with its untested
SS81-step-1 escape, and the S28 ROI evidence that a 15-target wave bought 12 banks and +0.00pp
headline — so waves are only worth resuming against HIGH-REACH targets.

Flags the milestone reality plainly rather than leaving it for T5 to discover: 89.2% instr
against a >=95% bar, with the remaining volume in main + the 39 type-1 modules (P31 scope).
P30 realistically closes on the milestone's LEDGER branch, which is an explicit either/or in
the approved milestone — Drew's call, deliberately.

Adds the S28 HONESTY LEDGER: five wrong calls this session, each caught by an oracle, none
committed. The standing consequence is stated once, at the top of the handoff: only a full
clean-fleet R22 counts, and a tool's exit status is never the oracle.

Also removes a duplicated results section left by my own earlier checkpoint edit.
2026-07-31 18:54:30 -06:00
Drew T 7281e0af57 docs(phase-30): SS129 (two jr traps) + checkpoint — 1 of 3 reach-138 targets banked, 2 ledgered
SS129a: post-carve, rtu_match/match_one COUNT THE JUMP TABLE AS INSTRUCTIONS. For
func_8013BD74 it reported `mine=198, target=226, 206 mismatched` — and 226-198=28 is
exactly the table's entry count. A draft that verified cleanly BEFORE the carve reads as a
total mismatch AFTER it, and the number looks like deep codegen trouble. SS81 says a jr fn's
match_one MATCH is not a bank; SS129a says its post-carve DIFF is not a diff either. Let the
whole-binary gate arbitrate.

SS129b: NEVER commit a carve whose owner is still a stub. harvest_verify refuses a dirty
tree (SS97) and the carve dirties config/, so committing the carve to get a clean tree is
tempting — and it STRANDS the carve. jr_inventory refused instantly (R32: "carve ownership
is not 1:1 ... UNOWNED 0x801d828c"), blocking every later jr operation on that overlay.
Reverted; R22 140/140. The route for a jr fn is the INTEGRATED jtbl_family_bank (carve ->
extract -> remap -> gate per sibling in ONE uncommitted transaction). The SS81 hand-chain is
for diagnosis; as a banking path its two constraints contradict each other.

Both were mine, both caught by oracles before any lasting damage, both now documented.
Ledger: JTBL-PAD-SPEC-DRIFT (func_8013BD74, with the exact SS8e error) and CC1-FAIL-UNREAD
(func_8013B83C — the diagnostic is genuinely unread; say so rather than guess).

Fleet 93.21% fn-count / 89.1% instr / 80.4% distinct.
2026-07-31 14:45:28 -06:00
Drew T a98d138c73 docs(phase-30): SS127 the -O0 idiom set + SESSION-28 wave checkpoint (honest ROI)
SS127/SS127a/SS127b distil what the wave's agents kept re-deriving, because the index
fired on only 3 of 15 targets:
- the -O0 CONSTANT-OFFSET FOLD: `p->f` folds to `lbu 3(r)`, `p[i]` does NOT (addiu +
  0-displacement load). At -O2 these converge, which is why nothing in SS1-SS126 covers it.
- the -O0 regime generally: spill/reload pairs are REAL named locals; load-delay nops and
  redundant copies are normal; write plain C, the -O2 steering levers are inert here.
- SS127a: SS71 sibling-first is the STRONGEST -O0 lever — an -O0 TU is a near-uniform code
  regime, so a banked sibling's shape transfers far better than at -O2.
- SS127b: two agents' decisive levers came from a SOURCE COMMENT in ov_SC01_077_o0.c, not
  from docs/. Promote levers out of source comments or every future agent re-buys them.

Checkpoint records the wave AND its honest ROI: 1.33M tokens for 12 banks and +0.00pp
headline. The value is contingent on three reach-138 functions, and all three are
currently unpropagated (func_8013C08C 0/137, SS94 type-carry) or gate-failed
(func_8013BD74 CARVE-REFUSED, func_8013B83C CC1-FAIL). Fix propagation before wave 2 —
drafting more x2-reach targets is not where the leverage is.
2026-07-31 14:05:56 -06:00
Drew T e91a6deb32 docs(phase-30): regenerate progress.fleet.md digest (93.17/89.1/80.4) 2026-07-31 11:38:47 -06:00
Drew T b5362c7b7f feat(phase-30): the -O0 cluster HARVEST — 1,364 banks for ZERO agent tokens; fleet 92.71->93.09% fn / 88.3->88.6% instr / 78.7->79.3% distinct
The payoff of routing the cluster to -O0 (commit:1270). These functions were ALREADY
CRACKED in ov_SC01_077 and could not be banked anywhere else purely because every
destination file compiled -O2. With the destinations now -O0, they template in
deterministically -- no drafting, no agents.

  dedup_propagate --recover  0x8013C360 (h_exact x138)  -> 137 overlays byte-identical
  family_sweep --hseq        10 variant families         -> 1,227 banked / 133 failed (90%)
                                                            1360 staged across 136 groups
  ------------------------------------------------------------------------------------
  1,364 new banks

FLEET: fn-count 92.71 -> 93.09% · instr 88.3 -> 88.6% · distinct-code 78.7 -> 79.3%
(71,756 / 87,459 unique fns; +1,162 unique). dedup 1904 -> 1905 groups, 0 failed;
C1 coverage 240496/240496. 0 NON_MATCHING in any default build (G4).
R22 CLEAN-FLEET: extract-all 139/139 (+main); check-all 140 passed, 0 failed of 140.

--recover WAS LOAD-BEARING (SS75): without it dedup_propagate took its historical
all-or-nothing branch -- one failing overlay (the SOURCE, ov_SC01_077) dropped the whole
function and it printed "all candidates dropped", which reads exactly like a wall. Reading
the exclusion code instead of believing the message showed the remedy: --recover excludes
only that overlay (kept x1 with its own inline match) and propagates to the other 137.

The two has_mid_jr families in the cluster were REFUSED BY DESIGN, not attempted (SS53
interlock): 0x8013C0F8 (154 ins) and 0x8013C414 (329 ins), ~137 members each = ~466
members queued behind the jtbl carve path they actually need, rather than a fake 0% from
the wrong tool.

REMAINING in the cluster: the 133 sweep failures + the 2 jr families + the 3 addresses
never cracked anywhere (0x8013B83C, 0x8013BD74, 0x8013C08C) -- the last are genuine
drafting work, now finally possible since their TU is -O0.
2026-07-31 11:00:42 -06:00
Drew T 803d73bb97 docs(phase-30): SESSION-28 checkpoint — T2 proven + tooled; fleet 92.71/88.3/78.7, R22 140/140
Records the T2 result as the phase's biggest unblock: the carve-within-a-carve is
byte-neutral (Arm-A does NOT bite), the real constraint is that an address range is
not an optimization region (SS126), and tools/o0_subsplit.py implements the correct
bound. Measured, not assumed, what it unblocks: 275 open stub instances across 18
overlays in the 0x8013B568..0x8013C98C cluster, homed in an -O2 jr split — plus a
note that the T0(f) "2,192 open members" pin is STALE and must be re-derived before
costing (R37).

Also flags my own under-count: the "15 contiguous -O0 fns" came from an asm scan that
cannot see matched functions.
2026-07-31 08:44:31 -06:00
Drew T a293eeeb6a docs(phase-30): SESSION-28 checkpoint + cookbook §124/§124a (the asm-label alias blind spot)
- §124: a "not matched" verdict can mean the definition is there under a DIFFERENT
  C NAME (the §37/§73 asm-label alias). The whole "no matched unit" skip class was
  one exemplar x 137 members. Includes the two traps in the fix (re-derive the
  pattern PER FILE; CARRY the alias declaration or the sibling emits the wrong
  symbol and still links) and the law: when corpus.stubs and a source scanner
  disagree, the SCANNER is wrong.
- §124a: `0 matched-exemplar families` from family_sweep may be the --band FILTER
  (defaults to `substantial`), not a wall — same shape as §53 / §116.
- cookbook-index regenerated (tools/cookbook_index.py, R33).
- CURRENT_PHASE: SESSION-28 checkpoint. Fleet 92.70 fn-count / 88.3 instr / 78.7
  distinct, R22 140/140. Records the 4th -O0 region VERIFIED + SIZED (30 instances
  / 1,504 ins, ov_SC03_014+015 only) and correctly BLOCKED on the T2 re-carve, and
  two R14 corrections to my own SESSION-27 checkpoint (the 137 were skips not
  failures; the cause was not "banked in the wrong binary").
2026-07-31 07:56:22 -06:00
Drew T 0130fb340a feat(phase-30): wave-4 resumed 10/10 MATCH banked + h_exact leg (14 propagated); R22 140/140
The 12 agents killed by the usage-limit pause were resumed and ALL returned MATCH (2 had already
banked from their partial drafts, so 10 ran). h_exact propagation leg completed over all 112 banked
exemplars: 14 propagated, 42 benign skips (h_seq tier, correctly routed away per §123), 0 failures
— the 0x801466F0 'halt' was a third benign-refusal phrase, not a partial write.

fn-count 92.61 -> 92.67% | instr 88.2 -> 88.3% | distinct 70,581 -> 70,590 unique fns.
2026-07-31 07:25:47 -06:00
Drew T 29cd4d4c39 feat(phase-30): T3 wave-4 — 60/68 drafts banked across 14 binaries (parallel gate); R22 140/140
Wave 4 launched 70 agents / 14 binaries; 58 returned before the pause (all match_one MATCH) and
their drafts + 10 partials gated to 60 banks. fn-count 92.59 -> 92.61%, distinct 70,506 -> 70,581.
R22 clean-fleet 140 passed / 0 failed under the campaign lock. Propagation deliberately deferred
(--no-propagate) — it runs per-function, routed by tier (§123).
2026-07-31 00:49:40 -06:00
Drew T 471314da54 feat(phase-30): T3 waves 2+3 + 4 behemoths — 52 cores banked, 911 members propagated; R22 140/140
WAVE 3 (48 agents / 8 binaries, dealt across binaries so BANKING fans out): 48/48 match_one MATCH,
48/48 banked through 8 PARALLEL per-binary gates. WAVE 2: 15/19. BEHEMOTHS: 4 non-jr confirmed
(func_8017E120 884ins x14, func_8017FA5C 728, func_8017CAD4 755, func_8017E35C 719).
Tier-routed propagation (§123): family_sweep --hseq banked 911 members across 137 overlays.

fn-count 92.32 -> 92.59% | instr 87.9 -> 88.2% | distinct 78.3 -> 78.7% (70,506 unique fns)
R22 clean-fleet 140 passed / 0 failed, under one campaign lock (treelock.sh).

CORRECTION (R14): the 'per-binary bank-rate cliff' I reported from the pre-incident gate run
(SC03_014 1/6, SC04_018 1/6, SC06_018 2/6) was an ARTIFACT — those gates ran against a tree
propagation was concurrently rewriting. Re-gated clean: 6/6 everywhere. A measurement taken during
corruption is not a measurement; I should not have theorised a cause before re-running it.
2026-07-30 22:22:35 -06:00
Drew T f3ec6ef588 fix(phase-30): treelock.sh — an flock MUTEX for tree-writing campaigns (incident 2: a poll is not a mutex)
I gated 8 binaries in parallel while wave-2's propagation loop was still running, then ran
'make clean' on top. check-all 77/140; the corpus denominator moved, so the apparent 91.4% instr
was a half-written tree, not a gain. Reverted to commit:1245 (last R22-verified) — 140/140 restored,
all 58 drafts survived because agents only ever write .run/.

ROOT CAUSE, and it was structural not unlucky: my guard was
  while pgrep -f dedup_propagate; do sleep; done
A CAMPAIGN is a LOOP of short-lived processes (15 sequential invocations), so it has gaps where no
process matches. The poll sampled a gap and started. Presence-of-a-process cannot express 'a
campaign owns the tree'.

treelock.sh holds one flock for the WHOLE campaign, released by the kernel on exit OR kill, with
--status; both drivers refuse to run unlocked. LAW: guard the CAMPAIGN, not the process.
Corollary (twice today): a killed process performs no undo — a fleet-tier write needs a lock ABOVE
it, not cleanup inside it.
2026-07-30 22:00:32 -06:00
Drew T 5d4167bb3c feat(phase-30): T3 wave-1 h_seq sweep — 548 members banked across 4 families; R22 140/140 (fn-count 92.16 -> 92.32%, distinct 78.0 -> 78.3%)
The 4 cores dedup_propagate refused (h_exact tier) templated cleanly via family_sweep --hseq once
the family map was regenerated post-bank (a bank invalidates the map: sig-overlays + family_hseq
must run BEFORE the sweep — the standing wave-loop order). 548/686 banked, 138 failed (one
consistent per-overlay slice, diagnose next). Wave-1 total: 8 cores -> 1,121 instances.
instr 87.5 -> 87.9%, distinct 69,828 -> 70,094 unique fns.
2026-07-30 20:07:41 -06:00
Drew T 159317d3fe feat(phase-30): T3 wave-1 — 8 cores banked + 4 propagated fleet-wide; R22 140/140 (fn-count 92.00 -> 92.16%)
Ultracode wave of 14 agents over fresh reach-138 cores: 14/14 match_one MATCH, 8 accepted by the
whole-binary gate (the §52b law reproduced exactly). Propagated per-function (the incident fix):
0x8012E014, 0x80151C54, 0x8012F49C, 0x80151B98 -> +573 instances. R22 clean-fleet 140/140;
instr 87.5 -> 87.7%, fn-count 92.00 -> 92.16%, distinct 69,828 -> 69,836.

The other 4 banked cores are h_seq (PURE/IMM) families: dedup_propagate is h_exact-only, so its
'reach<2' / 'not self-contained' refusals were statements about the TOOL's tier, not the functions
-> cookbook §123 (the §53 carve-law generalized to the propagation-tier axis) + a routing table.
They bank via family_sweep --hseq next.
2026-07-30 19:57:54 -06:00
Drew T fa1f6d0bf2 docs(phase-30): T1a close-out — +18 banked (+12 unique), R22 140/140, stored-draft question CLOSED (report point #2)
39% prior did not generalize (S16 measured FRESH wave drafts; this is A10's stored-backlog class,
0/958 by plain re-gate) — the driver lifted ~16% over that 0%. Residue routed to T3 redraft lanes.
§61 orphan-carve residue reverted; two T3 pre-work gaps recorded (gate_stage commit add-scope for
new carve files; no tracked writes during tree-writing campaigns). Ledger pruned: 1,350 -> 1,332.
2026-07-30 17:44:17 -06:00
Drew T ceae8bb4cd feat(phase-29): T97 — func_80151944 138/138; the "three-edit job" was ONE edit
- The last big NAMED blocker, costed across four checkpoints as §112 header + §20 call-site cast +
  a scripted §99 pass over 2,022 overlay-local decls. Probing first showed two of the three were
  unnecessary: the conflict is entirely between DEFINE_func_80151924()'s own forward-decl
  (extern s32 func_80151944(void)) and the byte-true definition (void f(void *a0)), four lines
  apart in the assembled TU. The 2,022 decls live in OTHER TUs and never entered it.
- ONE 4-line edit in engine_core.h: decl -> byte-true, call site -> ((s32 (*)(void))f)() so the
  caller's codegen is unchanged. rtu_match: conflicting types -> MATCH (15 ins). Sweep 138/138.
- Family 0x80131eec fully closed: 149 (T87) + 138 (T97) + 1 immediate-refusal = all 288 members.
- SHARED-HEADER RISK VERIFIED, NOT ARGUED: engine_core.h is included by all 138 overlays, so §20
  cast-folding is a hypothesis. Per-binary gates 138/138 are necessary but not sufficient; the
  fleet check is the one that counts. R22 clean-fleet 140/140 + tools-health RC=0 (corpus 0
  PHANTOM/0 TRUNCATED, cdecl, audit-binaries, dedup 1886/0, C1 239604/239604).
- METRICS: fn-count 91.96 -> 92.00% (+138, exact) · instr 87.4 -> 87.5% (+2,070) · distinct +72.
- COSTING LESSON: the estimate came from reading the symptom (2,022 decls of this name exist)
  instead of probing the failure (which decl actually conflicts). Probe before COSTING, not just
  before scaling.
2026-07-30 13:44:22 -06:00
Drew T 7e32da8f64 feat(phase-29): T95/T96 — func_80142B2C 136/136 (§121); all 3 byte-identical stragglers closed
- The draft calls ((void(*)(void))func_80142C84)() but nothing declares that symbol above the
  splice: it is DEFINED by DEFINE_func_80142C84() in engine_core.h, so gather_externs has no
  extern line to harvest, and the member TU instantiates the macro BELOW our function.
- The wrong guess was the useful step: a no-prototype `extern s32 func_80142C84();` turned
  `undeclared` into `conflicting types` — a DIFFERENT error, proving the diagnosis right and the
  type wrong. Synthesised from the macro's own definition head -> MATCH (34 ins) -> 136/136.
- NEW macro_def_sig_map() (1,878 signatures): the complement of header_sig_map(), which reads the
  externs a macro emits FOR ITS CALLEES; this reads the signature a macro DEFINES. Cookbook §121.
- ALL THREE byte-identical stragglers carried since SESSION-24 are now closed: func_80146750
  137/137 (T84), func_801759D8 137/137 (T93), func_80142B2C 136/136 (T95) = 410 members, and not
  one was a compiler wall (a signedness-wrong header decl, a type-name collision, a missing extern).
- Blast radius 0 (74 further families re-swept). FOUR data points now: only §117 (wrong LOGIC)
  generalised at 1,209 members; §118/§120/§121 are path-reachability gaps worth ~one family each.
- GATES: R22 clean-fleet 140/140; dedup 1886/0; 0 NON_MATCHING (G4).
- METRICS: fn-count 91.88 -> 91.96% (+273, exact) · instr 87.3 -> 87.4% (+12,296) · distinct +0
  (both byte-identical families — §111 predicted exactly that).
2026-07-30 13:13:06 -06:00
Drew T 9a1507462f feat(phase-29): T93/T94 — func_801759D8 137/137 via type-uniquify (§120) + two T92 corrections
- CORRECTION 1 (R14/P9): T92's "strip-if-ambient" recipe was WRONG. Stripping the draft's duplicate
  typedef breaks the extern that USES it (the TU's own copy sits below the spliced function), so the
  "second stacked blocker" T92 recorded (D_800AF634 used prior to declaration) was my own fix
  misfiring, not a real blocker. RENAME, don't remove: rtu_match CC1 FAIL -> MATCH (56 ins).
- CORRECTION 2: T91's wiring never RAN. family_sweep has THREE staging sites sharing the identical
  two lines (edit-remap / hseq / plain h_norm); I patched by rindex twice, which lands on the PLAIN
  site, so --hseq staged the draft unchanged and the lever looked ineffective. Re-anchored on the
  hseq site's unique write (func_{to_addr:08X}.c) and the draft came out renamed. T91's revert was
  right discipline on a false premise.
- RESULT: _uniquify_draft_types wired into the hseq path (byte-neutral — C type names never reach
  codegen). func_801759D8, one of the three long-standing byte-identical stragglers: 0 -> 137/137,
  0 failed. Blast radius 0 (74 further families re-swept, none moved) => TARGETED lever, like §118
  and unlike §117.
- Cookbook §120, incl. the law: before concluding a lever does not work, prove it RAN — diff the
  staged artifact for the change it is supposed to make.
- GATES: R22 clean-fleet 140/140; dedup 1886/0; 0 NON_MATCHING (G4).
- METRICS: fn-count 91.88 -> 91.92% (+137, exact) · instr 87.3 -> 87.4% (+7,672) · distinct +0
  (byte-identical family — §111 predicted exactly that).
2026-07-30 12:57:32 -06:00
Drew T f7c6d2eb2f feat(phase-29): T89/T90 — 0x80161c98 138/138 via the flag off-diagonal (§119) + a T84 correction
- CORRECTION (R14/P9): T84's '137 banked = all of 0x80161c98' is WRONG and committed wrong in
  commit:1193. The 137 were func_80146750 (a byte-identical straggler), banked 1-per-overlay in
  <ov>_after.c; 0x80161c98's members were still stubs. I assigned a count to the family I had
  been looking at without deriving it — third instance today of that error class. The
  --fix-def-sig-is-harmful finding itself stands (it unblocked func_80146750 x137).
- THE REAL BLOCKER was a flag OFF-DIAGONAL, not a defect. 0x80161c98's byte truth is (int,u32)
  -> sltiu; engine_core.h says (s32,s32); and an in-TU decl disagrees with the def. The levers
  pull opposite ways: --fix-def-sig bends the DEFINITION to the header; --normalize-self-decls
  bends the DECLARATIONS to the definition. both-on -> slti DIFF (T79). both-off -> correct
  sltiu but 'conflicting types' (T84/T88). NSD-only -> 138/138 (T89). Three sweeps across three
  sessions tested only the diagonal of the 2x2. Cookbook §119.
- T90 blast radius: 23 more (NSD-only) across the remaining still-zero families — targeted, not
  general; recorded so it is not over-projected.
- GATES: R22 clean-fleet 140/140; dedup 1886/0; 0 NON_MATCHING (G4).
- METRICS: fn-count 91.84 -> 91.88% (+161, exact) · distinct-code 69,593 -> 69,744 (+151).
2026-07-30 10:54:06 -06:00
Drew T bf71232d0b feat(phase-29): T87/T88 — ordinal immediate resolution (§118): 158 banked
- The T86 asm-ambiguous refusal was CORRECT (a by-value swap would corrupt the non-differing
  occurrence); the safety TEST was too strict. It compared the C literal's occurrences against
  EVERY asm use of that value, but gcc synthesises uses no C token names — e.g.
  D_80187044[*(u16 *)((s32)a0 + 0x2)]() has one C literal 0x2 and TWO asm uses of 2 (the
  per-member offset + a fixed sll ..,2 for the 4-byte stride). Unsatisfiable by construction.
- FIX (_ordinal_edits, §118): pair C occurrences to asm positions IN ORDER, accepting either
  len(spans)==len(asm_pos) (every use named) or len(spans)==len(diff_pos) (extras are implicit).
  Rewrite only occurrences whose instruction is in diff_idx. Order is a heuristic, so the
  whole-binary byte-gate stays the sole arbiter — a wrong pairing is rejected, never banked.
- T87: func_801599A4 0 -> 137 drafts, 137 banked; +12 singletons = 149 (family 0x80131eec).
- T88 blast radius: only 9 of the other 144 immediate-refusals converted (refusals 67 -> 34).
  A TARGETED lever, not a second §117 — recorded so it is not over-projected.
- GATES: R22 clean-fleet 140/140; dedup 1886/0; 0 NON_MATCHING (G4).
- METRICS: fn-count 91.79 -> 91.84% (+158, exact) · distinct-code 69,450 -> 69,593 (+143).
2026-07-30 10:26:26 -06:00
Drew T dcbeebaf49 feat(phase-29): T84/T85 — 0x80161c98 137/138 + func_801457A4 133/133 (+270 members)
- T84 (item 1): the top still-zero family's whole diff was ONE instruction — slti (signed) vs the
  target's sltiu. --fix-def-sig was conforming a byte-correct draft to engine_core.h's
  signedness-wrong decl (extern void func_80161D20(s32,s32)) while the exemplar's own def is
  (int, u32). Re-swept the 92 still-zero families WITHOUT the flag: 137 banked (all of
  0x80161c98), other 91 unmoved => family-specific, NOT a second §117. Recorded as such.
- T85 (item 2): rewrote tools/rollout_801457a4_o0.py as the two-file ATOMIC driver §116 called for
  (remapped body -> <ov>_o0b.c AND drop the INCLUDE_ASM from <ov>_after.c in one edit; build vs
  config/check.<ov>.sha; restore BOTH files on mismatch, §61). Validated on 3, then 130/130.
  No splat change — the Arm-A re-carve wall never touched.
- Item 4 PRICED AND DROPPED: STRUCT residue = 34 families / 166 members / 0.02pp.
- R14: my new_distinct estimator over-projects ~2x (priced 259, measured 125) — it counts classes
  unmatched at run time, so concurrent sweeps double-count. Ranks correctly, overstates absolutely.
- GATES: R22 clean-fleet 140/140; dedup 1886/0; 0 NON_MATCHING (G4).
- METRICS: fn-count 91.72 -> 91.79% (+270, exact) · instr 87.2 -> 87.3% (+16,946) ·
  distinct-code 69,325 -> 69,450 (+125).
2026-07-30 09:51:02 -06:00
Drew T 9d0ce20015 feat(phase-29): T83 — the §117 blast radius: 821 members, 138 families zero -> complete
- Re-swept the 229 eligible non-jr families (2,575 candidate members) that had never seen a
  correct target spelling. 821 banked / 1,538 failed; 138 families went zero -> COMPLETE (732
  members), 14 partial, 92 still zero. Top: 0x80172780 +135, 0x80128158 +31, 0x80187318 +28,
  0x8016f540 +27, 0x8017bef8 +20.
- Every one of those 138 families had been swept before and booked as a failure. None was a
  compiler problem — all were downstream of the one positional-map defect fixed in T82.
- GATES: R22 clean-fleet 140/140; dedup 1886/0; 0 NON_MATCHING (G4).
- METRICS: fn-count 91.48 -> 91.72% (+821, exact) · instr 86.9 -> 87.2% (+33,670) ·
  distinct-code 69,024 -> 69,325 unique fns (+301).
- The 92 still-zero families are the honest residue: swept with every lever this phase built
  (§114 callee, §115 named-symbol, §117 symbol-kind, def-sig, self-decl normalization), so no
  known harness defect applies to them. Correct starting population for the next diagnosis round.
2026-07-29 23:35:45 -06:00
Drew T 28dc3785f5 feat(phase-29): T82 — symbol-KIND fix in symbol_map: func_80174784 2/255 -> 251/251 (§117)
- CAUSE: family_remap.symbol_map zips exemplar/sibling reloc slots positionally and spelled the
  SIBLING's symbol from the EXEMPLAR's kind. Same-address families always agree, so it was
  invisible for 20+ phases; cross-address families need not agree — func_80174784's callback slot
  is the FUNCTION func_801747CC while member func_8017CFD4's same slot is the DATA symbol
  D_80182688. The map emitted func_80182688, the body materialized a name for an address that is
  not a function, and the fleet gate refused all 251 members.
- FIX: spell the target by what the target address IS in the SIBLING's overlay (func_ iff in that
  overlay's sig set — the same boundary oracle nins_of trusts, R33; memoized). Phase 26-A had
  already established this rule and applied it only to the exemplar side.
- WHY IT HID: rtu_match/match_one MASK HI16/LO16, so a wrong %hi/%lo symbol still reports a clean
  MATCH (measured: "MATCH (10 ins)" on a member the fleet gate rejected). masked-MATCH +
  whole-binary DIFF is the exact signature of a compiler wall. Cookbook §117 carries the law.
- Also refuted en route (cheaply): --normalize-self-decls was NOT the cause — re-swept without it,
  still 0/251.
- GATES: R22 clean-fleet 140/140; dedup 1886/0; 0 NON_MATCHING (G4).
- METRICS: fn-count 91.41 -> 91.48% (+251, exact) · distinct-code 68,782 -> 69,024 unique fns
  (+242, projected 246) · instr +2,510.
- BLAST RADIUS UNMEASURED: symbol_map serves every family sweep; 229 eligible non-jr families /
  2,575 members have never been swept with a correct target spelling, incl. the byte-identical
  families T76 measured at 0/682 (same failure shape).
2026-07-29 23:08:03 -06:00
Drew T 774592c452 feat(phase-29): T79 — byte-VARIANT re-sweep: 641 banked; T70's "1 of 10" was a pre-lever measurement
- VALIDATED FIRST, then batched: 0x80143d28 (T66's #1, T76's ApplyMatrixSV callee diagnosis)
  banked 136/136 under the §114 callee axis + §115 named-symbol widening. Batch of 8 followed:
  505/1039. Totals: 5 families outright + 1 partial of 9; 641 members ×N.
- Attribution DERIVED (R33), not parsed from the sweep log: live stubs recomputed per family from
  corpus.stubs before/after. Reconciles exactly against the metric (fn-count +641).
- §116 (NEW): optimization level is a property of the FILE, not the function. 0x801457a4 swept
  0/137 because its exemplar lives in ov_SC01_077_o0b.c (-O0 via WHALE_O0B_OBJS) while all 137
  members' stubs live in <ov>_after.c (-O2). The fix moves the STUB line, not the def: <ov>_o0b's
  .text ends exactly at 0x801457A4, so the relocation is byte-neutral by construction and needs no
  splat re-carve (which is the Arm-A +0x20 wall). 13th time a family-wide 0/N was the harness.
- R14 CORRECTION to the handoff arithmetic: the tier is 123 families / 3,100 distinct on fresh
  sigs, but 1,287 of that distinct is the -O0 cluster behind the Arm-A splat wall. Honest
  addressable tier = 113 families / 85,360 ins / 1,813 distinct. Billing the walled 1,287 as sweep
  yield would have repeated the T76 error.
- 0x80131eec (214 distinct, the biggest item left) diagnosed precisely: header macro decl +
  §20 call-site cast + a scripted §99 pass over 2,022 overlay-local decls; param is void*, so the
  T75 narrow-param refusal does not apply.
- GATES: R22 clean-fleet 140/140 from make clean + extract-all + check-all; tools-health RC=0
  (corpus 0 PHANTOM/0 TRUNCATED, cdecl, audit-binaries, dedup 1886/0, C1 239604/239604);
  report RC=0; 0 NON_MATCHING (G4).
- METRICS: instr 86.7 -> 86.9% (+28,205 ins) · distinct-code 76.9 -> 77.4% (68,196 -> 68,782
  unique fns) · fn-count 91.23 -> 91.41% (+641). The distinct-code move is the point of this tier.
2026-07-29 22:36:09 -06:00
Drew T 611622c9e7 feat(phase-29): T78 — PsyQ-symbol widening: func_8012F40C 0/137 -> 137/137 (three places, not one)
I called this "a one-line predicate widening". It was THREE, and fixing the first two changed nothing
— the sweep still reported 0/547 (cookbook §115):

  1. canonical_map     : re.fullmatch(r'func_[0-9A-Fa-f]{8}') + keyed by parsed ADDRESS
  2. DECL_LINE_RE      : (func_[0-9A-Fa-f]+) as the name group
  3. split_sig_string  : \bfunc_[0-9A-Fa-f]+\s*\(

Each is a SILENT SKIP indistinguishable from "no conflict found". With 1+2 done the symbol reached 3
and died there; only tracing transform's internals (`callees cast: 0` while the canonical map plainly
held `s32 RotTransPers(s32, s32, s32*, s32*)`) located it. THE TRAP WORTH REMEMBERING: a partial fix
to a name-form assumption produces the exact symptom of no fix at all, so a correct hypothesis looks
refuted. Curated naming increases as RE quality improves, so any func_-only predicate is
rot-by-design — the same shape as stub_map's (Phase 26-A).

RESULT: func_8012F40C 0/137 -> 137/137. The other three families (801759D8, 80146750, 80142B2C) still
fail on different causes.

GATES: R22 clean-fleet 140 passed, 0 failed of 140; tools-health OK; dedup 1886/0; 0 NON_MATCHING.
METRICS: instr 86.7% (+4,932 ins); fn-count 91.19% -> 91.23% (+137); distinct +0 (byte-identical).

NEXT: the byte-VARIANT tier is worth re-sweeping — T70 banked 1/10 BEFORE the callee axis existed, and
26 families remain unswept by the two levers added since.
2026-07-29 20:57:11 -06:00
Drew T 970559423d feat(phase-29): T77 — wire the callee-decl lever into family_sweep; func_80173A60 0/135 -> 135/135
Item 1. The T76 diagnosis was right and the fix was a lever we already owned. cast_call_sites
(§17a-1/§20) handles the callee-conflict class and lived ONLY in gate_stage, which the family sweep
deliberately does not use — the THIRD instance this session of a lever unreachable from the path that
needs it (T56 data-decl unreachable, T57 function-decl off-by-default, now T77 callee).

  the 5 byte-identical families : 0/682 -> 135/682
  func_80173A60 specifically    : 0/135 -> 135/135

Wired after scope_data_fix (orthogonal axes: data vs callee), default ON with --no-cast-callees. Two
details that matter: the canonical map is built from the TARGET sibling's TU via cpp
(canonical_map(ov, src_file=tu) -> cdecl.tu_scope) so it sees MACRO-INJECTED declarations — a
raw-text scan returns nothing for exactly the callees that conflict (§51g LAW 7) — and it is read
AFTER any tu-scope edit is on disk.

THE OTHER FOUR STILL FAIL, different causes. And the next finding is already visible:
func_8012F40C's blocker is RotTransPers, a PsyQ LIBRARY symbol — a callee conflict the cast should
have handled. It did not, because cast_call_sites' canonical map keys on
re.fullmatch(r'func_[0-9A-Fa-f]{8}'), so NAMED PsyQ callees are structurally invisible to it. That is
a one-line predicate widening with ~270 members behind it (RotTransPers + ApplyMatrixSV families).

GATES: R22 clean-fleet 140 passed, 0 failed of 140; tools-health OK; dedup 1886/0; 0 NON_MATCHING.

METRICS: instr 86.6% -> 86.7% (+7,965 ins); fn-count 91.15% -> 91.19% (+135); distinct +0
(byte-identical — §111 predicted it).

cookbook §114 — the three decl axes, and "conflicting types for X: READ X".
2026-07-29 20:34:09 -06:00