Commit Graph

61 Commits

Author SHA1 Message Date
Drew T 21d2ccc141 phase-37: T3 (in progress) — the engine's first bank: tools/struct_layout.py (the layout engine + the writer + the naming invariant), delever_oracle's LINKED mode (the build's own ld on the candidate object; f3 known-true + negative; the snapshot guard that caught T2's contaminated build/ object), tools/restruct.py (rungs S/S2/S+A/X/R/D/L, the ledger, inflight restore, selftest 48/48 + --real 51/51); rung D batch t3d1 on ov_SC04_011: 258 units — 242 canonical / 6 K&R marked / 16 kept | R22 check-all: 218 passed, 0 failed of 218 | 🛑 T3 in progress (S107) 2026-09-12 09:40:36 -06:00
Drew T 5c80301196 phase-36: S105 — the strip keeps a block-comment tail and drops the marker rung B wrote inside it: the six comment-boundary UNSTRIPPABLE classes strip (0 orphans); selftests OK 2026-09-11 18:35:38 -06:00
Drew T bb2012f78d phase-36: S105 harvest f7 — R22 tries every same-base sibling (not only the literal base) and no longer reads a cast store as a set; known-true 37 → 0 on func_8017FD14; selftest OK 2026-09-11 14:07:56 -06:00
Drew T 4a503fce1e phase-36: S105 harvest f5 — generators R45 derived_pointer_store (known-true 0 alone on two f5 bodies) and R46 set_once_chain (ALL 0 on func_8018FA34); selftest OK; SETUP rows 2026-09-11 13:25:01 -06:00
Drew T bd44b1c131 phase-36: S105 — the instruction table learns addu %0,$zero,$zero (= 0): func_8018FB8C's pack now strips (was UNSTRIPPABLE); f5/f6 packs built 2026-09-11 12:03:43 -06:00
Drew T ae522dbc49 phase-36: S105 harvest f2 — generator R44 counter_derived_pointer (known-true 0 on e21's start text, 18 on f2's loop 2), R22 extended to same-base offsets, the && read-as-&p refusal in R22/R44 fixed; selftest OK 2026-09-11 11:56:31 -06:00
Drew T 2fe2d27f1f phase-36: generator R43 sign_test_to_mask (+ dead-pad drop; a composition move); e26 (11) + e28 (6) banked 2026-09-11 04:06:10 -06:00
Drew T b93e3cab89 phase-36: R39 widened — 1–3 statements after the join, blank lines skipped (e24's store pair; known-true 0 on all three) 2026-09-11 03:16:25 -06:00
Drew T c621e6d82f phase-36: generator R42 move_statement_far (e19; a composition move — alone 8 on its start text); e19 banked 4 (ov_SC01_080) 2026-09-11 02:49:19 -06:00
Drew T 99355f6723 phase-36: generators R40 return_preincrement and R41 swap_if_else_arms (e2/e16), known-true 0 on all three; e16 banked 4 (800_b_2) 2026-09-11 02:35:25 -06:00
Drew T bd6fc3c5c1 phase-36: generator R39 duplicate_join_statement (the integer-tie split of e12/e14; known-true 0 on two of three) 2026-09-11 02:30:13 -06:00
Drew T d737200579 phase-36: generator R38 shift_to_division (e7's hand-expanded signed division as a real division; a composition move — alone 6 → 6/7 on e7's start text) 2026-09-11 01:21:37 -06:00
Drew T 8fb959e077 phase-36: R31 emits an all-shifts cast candidate (d39) and R35 handles cast copies of a parameter (d38), both known-true 0; named_definitions indexes func_X_body asm-label definitions 2026-09-11 00:13:37 -06:00
Drew T bbe0d66336 phase-36: generator R37 return_constants (d27: a pinned result local as constant returns; known-true 0) 2026-09-10 23:26:58 -06:00
Drew T ba98d26df8 phase-36: R23 accepts a case/default label as a statement boundary (d22's split, known-true 0); generators R35 drop_param_copies (d24) and R36 merge_set_chains (d25, known-true 0) 2026-09-10 23:11:13 -06:00
Drew T d94d993102 phase-36: generators R28 merge_pinned_twins, R29 fold_store_temps, R31 shift_operand_casts, R32 compound_assignments, R33 else_arm_assignments, R34 merge_disjoint_locals — harvested from d1/d5/d8/d12/d13/d14/d15/d19, each run against its agent's start text (R31/R32/R33 reproduce the close, R28/R29 the measured single-move score); METHOD step 13 2026-09-10 22:27:07 -06:00
Drew T 06302b97c2 phase-36: S104 — the census counts a marker on a kept ordinary-C fake (do-while / dead init, Drew's ruling (a)) apart instead of as an orphan; R7 marks its do-while; log: d1–d10 all at 0, R27, the R97 correction for 830650946 | 🛑 T7 RUNNING, census 4,928 / 0 unmarked, exit 0 2026-09-10 21:51:49 -06:00
Drew T 30fd6796f9 phase-36: generator R27 named_ports — the same function lever-free in another binary, ported by pairing the two original objects' relocation sequences (+ carried file-scope externs, the target's return type); wired into delever_regen and recipe_candidates; 511/1,010 residue classes have a donor, a 24-class probe closed 4; METHOD step 12 (S104's landings) 2026-09-10 21:43:05 -06:00
Drew T aada3bdc2b phase-36: the first minimum-lever bank (func_80177B5C: 1 marked launder instead of 23 levers, 133 bodies); c43/c44/c45/c37 closes with their cross-address copies (delever --port-scan); generator R26 alias_repeated_addresses (known-true: c45's close from its start text) (R22 218/218) 2026-09-10 18:32:46 -06:00
Drew T 321b540e7f phase-36: propagate ignores body-local externs (re-propagation: 97 siblings banked of 145 candidates); R19 cast-arity regen 8 classes; c39 ports two variants; c41, c34, c32 closes; related.txt lists the same function lever-free elsewhere; cc1_dumps_tu.sh -dd (R22 218/218) 2026-09-10 18:07:41 -06:00
Drew T 7d5964b279 phase-36: T7 agents c36 + c35 — four tier classes closed (func_8014305C, func_80141874, func_8017DBE4, func_80185994; 39 bodies); R19 reads the arity a call's own cast asserts (known-true: c35's close from its start text) (R22 218/218) 2026-09-10 17:49:55 -06:00
Drew T e984e5822f phase-36: re-draws c25 (func_80166F58, a narrowing copy) and c26 (func_80133CD4, split temps) closed, 254 bodies; tools/localalloc_sim.py (c26's local-alloc simulator, 0 mismatches over 150 blocks); propagate no longer trusts stale ledger hashes; R25 regen 3 classes; regen reports COMPILE-ERROR (14,xxx -> 13,083 sites, R22 218/218) 2026-09-10 16:58:01 -06:00
Drew T 96820256ce phase-36: re-draws c24 (func_8012956C: a phantom 4th argument + a switch) and c23 (func_80133784: the exit block inside a real loop, overturning b4's de-loop reading) closed, 252 bodies; R25 trim_arguments; argcheck reads K&R definitions (95 callees were invisible); the selftest asserts every dispatched family is registered (R22 218/218) 2026-09-10 16:45:14 -06:00
Drew T a620e1880f phase-36: generator R24 (the addPrim copy read as a whole word, c20's move) + its regen pass (2 classes, the func_80140D68 header on 140 objects); c13's reading of func_80140958 (43 -> 4, not closed) (R22 218/218) 2026-09-10 15:57:16 -06:00
Drew T 164825b5d8 phase-36: delever_regen — R22+R23 re-run over the whole residue closes 17 classes / 22 bodies with no agent; --try learns header TUs (24 classes had never been scorable) (17,715 → 17,692 sites, R22 218/218)
- tools/delever_regen.py: read-only pass (both starting texts, only the named families, delever_search --try --body,
  one worker per class) + --bank (re-score on the current tree, apply_body_core, propagate); dictionary + SETUP rows
- pass 1: 1169 classes in 127 s, 14 MATCH; the 25 UNSCORED read before banking: 24 were header-TU classes whose
  includer's ../shared include never resolved in --try (fixed; controlled: unchanged body 0, lever-free 32, mutated 1),
  1 a body-local #define (R22/R23 now refuse preprocessor lines); pass 2 over header TUs: 104 judged, 3 MATCH
- banked: 14/14 + 3/3 (two shared headers IDENTICAL on 141 objects each); R23 12 classes, R22 5
- check-all 218 passed 0 failed; lever_census 17,692 marked 0 UNMARKED
2026-09-10 15:36:01 -06:00
Drew T a060705725 phase-36: T7 agents c14 + c16 — func_801670E4 (all seven levers; its refuted @stuck note replaced in 136 copies) and func_8013D178 (one pointer per if-group), 261 bodies; R23 widened to one open block and now closes func_8013D178 alone; c9's reading of func_8013CF68 (38 -> 10, not closed) (18,776 → 17,715 sites, R22 218/218) 2026-09-10 15:24:01 -06:00
Drew T 2e61220bde phase-36: T7 wave c — seven agent closes (c4 c6 c1 c7 c3 c5 c8) + func_8017EEC0's parameter, ~1,000 bodies; generator R23; CI's verbatim_check fixed and wired into tools-health (23,988 → 20,206 sites, R22 218/218)
- closes, each --try 0 then apply-body IDENTICAL + propagate N/N 0 refused: func_80133AB0 (u16 width moves), func_80130D48
  (one call per goto-tail site), func_80135168 (reused temps split + H16 member store), func_80134A74 (widths + join
  statement in both arms), func_80148AFC (implicit handler argument + later operand), func_8015D738 (jump threading:
  re-read + a do-while on precedent, the class raised with Drew), func_80135004 (temp split + argument from its global)
- func_8017EEC0: the uninitialised a0v T4 tus10 left is the parameter (8/8, IDENTICAL)
- CI red since cb2fb5e6d: verbatim_check --strict saw the DECOMPILE-NOW row func_8017EEC0 converted; row removed (one
  row), --update keeps order + UTF-8 (proven equal to the hand fix), verbatim_check --strict now in make tools-health
- delever.split_reused_locals = family R23 (selftest + two refusals; known-true: joint split = the agents' measured 12/26)
- check-all 218 passed 0 failed (twice); lever_census 20,206 marked 0 UNMARKED; Drew: at most five concurrent agents
2026-09-10 14:56:17 -06:00
Drew T 205331765f phase-36: T7 agent c2 — func_8013D8FC closed (the walked-pointer merge), 131 bodies; harvested as generator R22 (24,119 → 23,988 sites, R22 218/218)
- agent c2 (Opus): a second pointer q = p + 5 stepped in lockstep with p kept a second biv alive (loop.c strength
  reduction, -dL 'Cannot eliminate biv'); one pointer lets combine_givs fold every field read onto one base
- bank: apply-body IDENTICAL, propagate 130/130, check-all 218 passed 0 failed, lever_census 23,988 marked 0 UNMARKED
- delever.merge_walked_pointers = family R22 (selftest + two refusal controls; known-true: the agent's start text's
  candidate is its closing body, --try score 0); leads the COUNT class after R19 in delever_search; SETUP row
- S103 opening: the method addendum .run/P36/agents/METHOD_S103.md; wave c launched (six agents); Fable out of credits,
  c5/c6 relaunched on Opus
2026-09-10 14:30:30 -06:00
Drew T d30ccc9a72 phase-36: T7 agent b8 — func_80135888, the largest class left, closed with all five levers gone (134 bodies; 24,789 → 24,119 sites, R22 218/218)
check-all: 218 passed, 0 failed of 218
  lever_census --check: 24,119 pin/asm sites, 24,119 marked !FAKE, 0 UNMARKED — OK

Three moves, each predicted from a dump before it was compiled:
- while -> a guarded do-while (29 to 22). Cross-jump (jump.c:1969 -> find_cross_jump :2371, from toplev.c:3142) had
  matched the load in front of the jump against the one in front of the bottom test and deleted three instructions; the
  guarded form makes the two tails differ.
- the duplicated pre-loop call block -> goto (22 to 6). This is an allocno_compare rank move (global.c:585-611): the
  priority is floor_log2(refs)*refs/live, reg_n_refs is loop-weighted (flow.c:2067), the in-loop copy of that call is
  worth two references, and deleting the out-of-loop copy takes exactly one off — 8 to 7 crosses a floor_log2 step and
  drops the pointer's priority from 3157.9 to 1891.9. The predicted allocation order matched the dump exactly. The
  rewrite is byte-neutral on its own: reorg steals the target's first insn into the delay slot and retargets.
- the two-arm mask temp inlined (6 to 0): set in two arms it has two deaths, fails local-alloc.c:472, and combine_regs
  bails at :1774, so it went to global allocation and took its copy preference.

Harvested as R21 second_consumer, from agents b2 and b6 together: give a computed value a second consumer before its
copy, either by chaining (v = slot = E) or by hoisting the store above it. cse deletes such a copy only when the
producer sits immediately before it (cse.c:7440-7501, guard :7454-7460), and flow links only the FIRST following use
(flow.c:2076-2091), so a store in between defeats both. R9 can never produce it — the two statements share the
identifier, so its independence guard refuses the swap. Known-true: the joint form scores 0 on b6's pre-bank text, and
the single-site forms do not, which is the third measured case this session of a joint edit no hill-climb can reach.

Also recorded from b8, worth a pre-check later: declaration-order moves are PROVABLY DEAD on a register residual whose
allocnos have distinct priorities, because global.c:604-610 compares priority first and only ties by allocno number —
4,811 compiles of those candidates sat flat because of it.
2026-09-10 13:31:47 -06:00
Drew T 9d78fc4085 phase-36: T7 agent b3 — func_8016CBC0 closed from a residual of 55 (128 bodies), and its move toolified as R20
- the move: narrow every local in the counter's def-use chain together — the counter, its +/-1 temp and the copy-back —
  and do it for BOTH chains at once. Four instructions were MISSING, not miscoloured, three of them the moves the $0 pin
  was faking. insert_regs (cse.c:1029-1032, early bail :1018-1020) puts two pseudos in one equivalence class only when
  their MODES match, so an all-int copy-back is collapsed and swept, while the narrowed one is a truncation: no
  equivalence, the wide temp stays live and reaches reload as the move the target has. The fourth instruction is
  strength_reduce minting a shift giv from a wide counter whose every use is a cast; a HImode pseudo cannot be that giv.
  delever --propagate: 127 of 127 sibling(s) banked, 0 refused. 26,202 -> the census below.

- R20 narrow_chains: the agent PROVED the joint form is necessary, and the generator reproduces it. Single declarations
  scored 45/72/51/24, each chain alone 43, both chains together 0 — every intermediate worse than the search's own best
  of 11, so a beam over R12's one-declaration width moves cannot reach the answer from either side. Seven runs and 4,811
  compiles stalled at 11; R20 offers six candidates and the right one is a single compile.
- known-true check: run on b3's pre-bank text, R20's joint signed candidate scores 0 (MATCH) and its single-chain
  candidates score 43 and 51 — the agent's own hand-measured numbers, reproduced by the tool.
- chains are built conservatively from the body's text (two locals linked when one is assigned from the other, through a
  cast or a +/- constant), and only whole components are offered, so the partial narrowings the measurement showed are
  always worse are never generated. Selftest: the chain is found whole, an unlinked local is not pulled in, and a body
  with no linked pair offers nothing.
2026-09-10 12:57:06 -06:00
Drew T f3de70fce5 phase-36: R19 — the argument-restore generator: call signatures become engine work, not agent work
Six T7 agents independently reached score 0 by restoring an argument the decompiled source had dropped, and no generator
could reach the class because every other family rewrites statements that exist while this changes a call's ARITY. R19
closes that gap without cracking anything: it finds every call whose in-scope declaration is narrower than the callee's
real definition, then offers one candidate per value already in scope (each parameter, each local declared before the
call) and lets the byte oracle pick. The missing argument is never inferred.

- known-true check: run on the pre-bank text of func_8017A3D8, which agent a12 solved by hand, R19 emits that agent's
  exact fix and --try scores it 0 (OTHER; mine 53 ins, target 53) — MATCH.
- two spellings were wrong before that passed. It took the return type from the DEFINITION and produced
  ((void (*)(s32))f)(a) != 0, which cannot compile because the defining TU says void where this one says int — it now
  repairs the arity only and keeps the TU's declared return type. And it required a simple statement, so it found
  nothing on the very body it was written from: these calls live in  and  far more often
  than in a plain statement.
- it also sees the cast-wrapped form ((s32 (*)(void))f)(), which is how m2c usually spells a dropped argument, and
  replaces the whole wrapper rather than nesting a second cast.
- ranked FIRST in every residual class: it emits candidates only for calls whose declaration provably disagrees with the
  definition, so it costs nothing when it does not apply. The engine selftest's ordering invariant is updated to say so
  rather than being widened again.
- argcheck now carries each definition's return type, which the cast route needs.
- selftest: two positive assertions and two controls (the declared return type is kept; the definition's is refused; a
  call inside a return statement is seen; a matching declaration offers nothing).
2026-09-10 11:13:34 -06:00
Drew T 3464a25cd0 phase-36: T7 burst — five more banks (631 bodies) and two concurrency defects the agents found
Banked: func_80136334 (126, all four levers), func_8016B234 (129), func_8015FBE0 (125), func_80143D28 (131),
func_8014D820 (126 of 128). 27,984 -> 26,714 sites.
  lever_census --check: 26,714 pin/asm sites, 26,714 marked !FAKE, 0 UNMARKED — OK

THE MISSING CALL ARGUMENT CLASS IS NOW CONFIRMED SIX TIMES, independently, by six agents that never saw each other's
work: a7, a8, a11, a12, a13, a25. In every case the source declares a call with fewer arguments than the callee really
takes — m2c drops arguments at unprototyped and indirect call sites — and the register pin was hired to fake the
instruction the missing argument would have produced. Mechanisms differ and were each proven on bytes: combine.c:1458's
added_sets_2 gate; set_preference (global.c:1535/1589) applied ahead of first-fit at :997-1030, the argument copy
degenerating to a self-move deleted at toplev.c:3142 / jump.c:424-443 so it costs zero instructions; and reorg.c:3374's
liveness half, where restoring the argument adds a use to CALL_INSN_FUNCTION_USAGE (reorg.c:428) so a delay-slot steal
is refused. No generator can reach any of it: every family rewrites statements and declarations, none edits a call's
argument list.

Two concurrency defects, both found by agents rather than by me:
- the includers cache wrote through a FIXED temp name, so concurrent processes clobbered each other's os.replace and the
  loser saw FileNotFoundError, which reads like a compiler crash on the candidate. Now a unique tempfile per process.
- the agent brief now mandates PACK/scratch/ for helper scripts and dumps, and says to retry once when a --try failure
  names something that is not your own text. Three agents had scripts overwritten mid-run by another agent.

One valuable negative: func_80178970 does not close, and the agent proved why by construction rather than by exhaustion
— only a call or a return writes $v0 in plain C, and a return's hard write is always emitted after its guarding branch,
so combine deletes the call-result copy (combine.c:914-917, use_crosses_set_p at :10127-10130; the SMALL_REGISTER_CLASSES
arm at :944-957 is not defined for MIPS). Its early-return rewrite still improves the source from 6 to 2 and reads
better than the pinned original.
2026-09-10 10:46:06 -06:00
Drew T 449acd8cb3 phase-36: T7 sweep s4 and the OUT-OF-BODY defect fixed at its cause (R14 refuses what the body-only bank cannot take)
search: 0 of 139 exemplars matched lever-free in 0.54 h (0 of 7,077 bodies behind them; 52,566 compiles) — NO-MATCH 136 · BANK-REFUSED 3

- the three refusals are the three fleet copies of func_80136824, each a real score 0 (R15 sink + R12 width + R14
  param-width) blocked by a contract rather than by a bad body: the engine verifies the whole candidate text but hands
  apply_body_core only the definition, and --propagate remaps that body to siblings, so a generator that edits lines
  outside the definition can never bank. R14 is the only such generator.
- my first diagnosis was wrong and was discarded rather than shipped: I guessed the conflicting declaration was in a
  shared header and built a 2,431-name index to refuse on, and the index said the function is not in it. Reading cmd_run
  gave the real answer.
- two fixes: param_widths refuses outright when the TU declares the function anywhere but at its definition
  (protos_outside_definition; the earlier R14 banks had no such prototype, so nothing that worked is lost), and the engine
  names the condition itself with a new OUT-OF-BODY verdict instead of letting the bank die on a compiler error that reads
  like a bad body. Controls both ways in the selftest.
- the steering measurement (R41): across s1-s4 the head's 57 classes have absorbed ~128,000 compiles for 6 closes, all of
  them R15's and all in the first sweep. The head is resistant to every mechanical generator at this width; sweeps pay on
  the tail and on targeted families, and the head is what agents are for.
- open by name for the types phase: func_80136824 (133 copies) has a real crack that needs its prototype widened with its
  definition — the second measured case where a declaration, not codegen, stands between us and the bytes.
2026-09-10 05:00:01 -06:00
Drew T d71836107c phase-36: T7 agent a3 — func_801397B0 not closed (best 2), its reading toolified as R18 the bystander move
The third agent produced no bank and a precise refutation plus a generator, which is the deliverable the brief asks for.

- it refuted the a2 hypothesis on its own body: git grep returns 1,770 declarations in two forms, both (s32 a0), no (void)
  anywhere, and the pin is on a local rather than the parameter. Three lever-free spellings reach the target's complete
  register assignment, so the class is reachable from plain C.
- its best is score 2, class ORDER, 89/89 instructions, every register correct, one displaced bystander store. The target's
  sw sits inside the lbu->addiu window and that position is forced: anti_dependence and true_dependence (sched.c:817/845)
  both hold, so the store can neither hoist nor sink. Post-sched1 stream and reg_live_length then match ours, leaving
  reg_n_refs — computed by flow on the pre-combine RTL — as the only remaining input.
- R18 moves one simple statement to each other position in its own block, up to six away. R9's adjacent swap is the special
  case; the distance is the point. It costs no instruction where R7's LOOP notes are a full sched1 barrier and always cost
  one displaced insn, so R18 is ranked ahead of R7 in every class.
- two wrong spellings before the known-true check passed: identifier-disjointness as a requirement offered three candidates
  and none of them the agent's (it is only an ordering preference now — byte-identical output is the same program, so the
  oracle is the whole correctness proof, which is R9's own footing), and a blank line counted as an obstacle, so the
  generator never offered the very move it was written from. It now reproduces that body exactly: bystander @21->17.
- delever_pack.py now writes each trace candidate's residual class beside its score, from the agent's method note: a bare
  number hid that a move had already turned this body's residual from REG into ORDER.
- delever --selftest OK (3 new controls incl. the nested-block refusal); delever_search --selftest OK; tool_census OK.
2026-09-10 04:26:00 -06:00
Drew T 5603a114c2 phase-36: T7 sweeps s2/s3 — the constant-holder census corrected (537 of 17,302, not 284 of 10,958) and 10 bodies closed; the propagate namespace bug fixed
- s2 (the head, with R16/R17 added): search: 0 of 140 exemplars matched lever-free in 0.24 h (0 of 7,085 bodies behind
  them; 23,689 compiles). The two new generators closed nothing on the head; recorded as measured.
- agent a2's "284 constant-holder pins of 10,958" verified against the source rather than believed (R14), and my first
  instrument was wrong (R40): asking R16 directly answered 33, because R16 only fires on a split declaration while most
  pins carry their value as an initialiser. R3 converts one form to the other, so the reachable family is R3+R16.
  Corrected, both figures derived: 537 constant-holder pin sites of 17,302, in 510 bodies (152 initialiser, 385 separate
  assignment; by register $2 282, $20 136, $3 28).
- s3 drew exactly those 99 function names and closed 10 bodies before crashing with
  AttributeError: 'Namespace' object has no attribute 'allow_residue'
  in propagate — the a2 fix read the flag off the caller's namespace and the search engine builds its own Namespace for
  that in-process call. Fixed with getattr(a, "allow_residue", False): a library must not assume its caller's namespace
  shape (R43).
- the ten banks were real, proven by gating the tree the crash left:
  check-all: 218 passed, 0 failed of 218
  lever_census --check: 29,533 pin/asm sites, 29,533 marked !FAKE, 0 UNMARKED — OK
- by first move the ten are R15 x3, R6 x4, R7 x2, R9 x1 — the draw was right about the family even though R16 did not fire.
- snapshot row 13; s3 re-runs from the top with the fix.
2026-09-10 02:49:05 -06:00
Drew T 975850ff84 phase-36: T7 toolify a2 — generators R16 (constant holder inlined) and R17 (constant-run split), the directed form of a move R9 reached only by luck
- R16 writes a local whose only assignment is one integer literal at every use and deletes it. R6 stops at a temp read
  exactly once, so a holder read four times was invisible to the search and its whole family with it. Deleting it is
  byte-neutral alone but removes a quantity from the block, which is what lets the next move reach the allocator.
- R17 splits a run of consecutive same-literal assignments by moving the nearest differently-valued one into it, at each
  interior split point. find_free_reg's live-range scan (local-alloc.c:2109-2110): while the two constants' ranges are
  disjoint they share a caller-saved register; splitting makes the first live across the second and it takes another colour.
- known-true check: on the seed that keeps func_80168828's semantically-forced $4 pin, R16 then R17 reaches
  score 0 (OTHER; mine 108 ins, target 108) — MATCH at three of the six offered split points, in ten compiles where the
  blind search needed 2,271.
- the engine selftest's caller-saved assertion is now the ordering invariant (every targeted lever before every blind
  family) rather than a fixed window widened once per new generator.
- delever --selftest OK (4 new controls); delever_search --selftest OK; tool_census --check OK; SETUP row (R21).
2026-09-10 01:27:20 -06:00
Drew T 9c5ca46a2a phase-36: T7 agent a2 — func_80168828 at score 0 with the constant-holder pin deleted (125 bodies; 29,697 → 29,572 sites, R22 218/218)
- two moves: delete `register s32 c40 __asm__("$3")` and its `c40 = 0x40;`, writing the literal at its four uses (byte-neutral
  on its own — the pin was never doing the work); then swap the adjacent `f1e = 0x40;` and `f1a = 0x10;` so the 0x10 store
  splits the run of 0x40 stores.
- the residual reads like cse/sched and the decision is local-alloc's. Dumps of the real TU in both orderings differ on one
  .lreg line — `Register 76 used 5 times across 10 insns` -> `across 14 insns`, `Register 76 in 2.` -> `in 3.` — which is
  find_free_reg's live-range scan at local-alloc.c:2109-2110: unswapped the two constants' ranges are disjoint and share $v0,
  swapped they overlap and the first takes $v1.
- the $4 pin STAYS, and not as a lever: src/shared/ov/func_801687CC.h declares extern void func_80168828(void), so the
  target's `move s1,a0` has no C source. An uninitialised local, a pointer-typed one, a split declaration and deleting it
  outright all give the identical score-25 residual; both parameter forms are hard cc1 errors against that header. This is
  the first measured pin that only a declaration fix can remove — one of the 51 conflicts P35 ledgered for the types phase.
  The engine's score-1 text is a coincidence (its andi truncates garbage in $s1 and never reads $a0); not proposed.
- instrument fixed in the same change: --propagate refused all 124 siblings because the reshape deliberately keeps a lever.
  The allowance is now derived from the exemplar's own banked text (its surviving !FAKE markers), and a sibling whose remap
  would carry more levers than the exemplar is refused by name.
  delever --propagate: 124 of 124 sibling(s) banked, 0 refused
- check-all: 218 passed, 0 failed of 218
  lever_census --check: 29,572 pin/asm sites, 29,572 marked !FAKE, 0 UNMARKED — OK
- snapshot row 12; delever --selftest OK. The toolify (R16, the constant-run split) follows.
2026-09-10 01:23:22 -06:00
Drew T 861dd0651c phase-36: T7 toolify a1 — generator R15, the sink (agent a1's crack made mechanical; reproduces it from the pre-bank text at score 0)
The harvest half of the one-at-a-time loop (R16): agent a1's reading of func_80156044 is now a move the engine can make
on any body, so the remaining head classes get it for free.

- R15 sinks the statement AFTER an if/else chain into every arm and deletes the variables it consumed:
  `if (c) { v = e1; } else { v = e2; } w = f(v);` -> `if (c) { w = f(e1); } else { w = f(e2); }`.
- it is a REGISTER move, not a scheduling one. A value set in every arm and read after the merge is a cross-block pseudo
  local-alloc never gives a quantity (local-alloc.c:472, next_qty reset at :517), so the arm holds two quantities and
  takes block_alloc's unrolled case 2 (:1499-1502, qty_compare :1578-1596). Sinking makes it a third block-local
  quantity, and case 3 (:1491-1496) falls through into case 2 and applies that comparison a second time, undoing its own
  exchange — the two caller-saved colours swap. It also takes the value out of global.c, where set_preference
  (global.c:1535+) had given it a copy preference through the merge result's argument copy.
- applicability is checked, never assumed: each consumed variable must be assigned exactly once in every arm by a simple
  statement, appear in the merge statement, and occur nowhere else in the function.
- if_chains() counts a line's CLOSING braces before its opening ones. On a `} else if (...) {` line the two net to zero
  and the first version's depth counter never closed the arm — the generator found 0 candidates on the very body it was
  written from. Caught by running it on that known-true case before believing it.
- ranked third in REG-caller / REG-mixed / COUNT; the engine selftest's "R5 in the first three" assertion widened to
  "R5 and R15 in the first four" rather than de-ranking the new move.
- verified: delever --selftest OK (3 new controls: a variable read after the merge, a variable one arm does not set, the
  brace walk's three arms); delever_search --selftest OK; and the known-true check — R15 run on func_80156044's
  pre-bank text emits the agent's crack and `--try` scores it
  `score 0 (OTHER; mine 74 ins, target 74) — MATCH`.
- SETUP row rewritten (R21), kit corpus regenerated, tool_census --check OK (371 copies + 30 pointers, 0 gaps).
- no src/ change in this commit; the sweep of the other 56 head classes follows.
2026-09-10 00:45:15 -06:00
Drew T 7b2200edad phase-36: the tail pass g6 + g6b (47 + 63 of 400 small classes; 186/191 siblings propagated), R22 218/218; 30,806 → 30,358 sites; --try (a candidate scored without a tree write), delever_pack.py (the 57 T7 packs + PROMPT.md), --restore refuses an empty snapshot; the checkpoint: T7 as one agent at a time, approved, starts in the fresh session 2026-09-09 23:32:57 -06:00
Drew T 2f3ce92a15 phase-36: rung G run g5 — the head re-drawn wide: 5 of 70 (small classes, 62 bodies), R22 218/218; 30,892 → 30,806 sites; the wide-search lever is spent on the big classes (112,216 compiles); R14 rewrites prototypes, R8 names repeated operands/groups, R12 splits multi-declarator lines; C/D-only bodies are done and not drawn, the seed keeps class C/D sites 2026-09-09 22:07:17 -06:00
Drew T 1ec67f6677 phase-36: rung G run g4s — func_8016E9EC's shape closed in three classes (133 bodies, R22 218/218; 31,025 → 30,892 sites); generators R12 widths (u8/short/int), R14 parameter width, R8 shared base, R10 cast alias; the bank and propagation in process (apply_body_core); the per-tag scratch-object race fixed; propagate's empty-list return 2026-09-09 20:18:43 -06:00
Drew T 584031c717 phase-36: rung G generators R10 (parameter copy), R12 (width), R13 (reassociation), R8 common-subexpression; --explain reads a residual as mnemonic blocks; four declaration-run/statement defects fixed; the 6-distance class read: one surviving copy the width move does not reach 2026-09-09 18:28:59 -06:00
Drew T a4cbe0d5a3 phase-36: rung G run g1 — 1 of 16 exemplars (func_801424E4, the count-changing body rung D left at 2) closed by three composed moves, 132 bodies banked + propagated 131/131, R22 218/218; 33,427 → 33,295 sites; R5 skips constant operands (lane B's fold claim verified on bytes); bottom-up order within a file 2026-09-09 18:22:01 -06:00
Drew T 623e553408 phase-36: rung G — tools/delever_search.py, the guided search (the score is the oracle's own object read as an edit distance, the residual classified to pick the move families, a beam composing 2–3 moves; positive controls 1–2 PASS, 3 FAIL on a missing inverse); R8/R9 + the unwrap in delever's generator registry; the 301-row ledger hash defect fixed at its cause and repaired; lane B's residual→move map banked 2026-09-09 18:11:16 -06:00
Drew T 72a9ab1129 phase-36: the free-bank sweep measured — rung R is replication, not discovery (0 of 300 at cap 40 AND at cap 400; the cap was never binding at ~57 candidates/body; the instrument cleared by hand) 2026-09-09 16:10:11 -06:00
Drew T 1c2b8f2cc8 phase-36: rung R orders its candidates by distance to the NEEDED site — the lever says where to look; a flat cap had been truncating the tail (the aborted cap-40 sweep judged ~200 bodies and closed none, while the shape that closed func_80135D20 was a block wrap well down its body) 2026-09-09 15:56:36 -06:00
Drew T 2d8ee30a10 phase-36: rung R made TU-parallel — a worker owns a whole translation unit (the oracle writes each candidate to the real source path and names its scratch object after the object it builds), shared headers stay serial (two headers can share an includer's object), bodies judged bottom-up within a file so a bank never shifts a body still to come, and the in-flight map is per-file under the lock so a killed run restores every worker's file 2026-09-09 15:56:07 -06:00
Drew T aef1159488 phase-36: T6 CLOSE — both yield lines measured (permuter 5 of 16 exemplars / 665 of 2,131 bodies; recipes 134 of 134 in 6.0 min), 664 sites gone (34,091 -> 33,427), R22 218/218 at every step; the S99 checkpoint written for T7 (which starts only on Drew's direct approval) with the parallelised rung-R sweep as the drawable work meanwhile 2026-09-09 13:02:51 -06:00
Drew T a2da99b130 src(phase-36): T6 rung D banked — the four exemplars the permuter closed, tidied and byte-judged (R22 218/218)
- delever_permute --bank: 4 winners applied through delever --apply-body, each IDENTICAL on its own object; the winner is
  now TIDIED first (pycparser reprints a body it parsed: two-space indent and a corpse `;` where a statement was inlined
  away) and the tidy is judged like any other candidate, so the source keeps the tree's shape; parenthesisation and brace
  style are deliberately left to the formatting phase, over the whole tree at once
- a slip, named: --bank re-applied a permuter body over the ONE-LINE version rung R had already banked for
  func_80135D20; the clean text was restored through the oracle (label d1fix) and --bank now skips any body the ledger
  already calls LEVER-FREE
- --recipes is killable now: the oracle writes the candidate into the tree to compile it, so the original goes into
  inflight.json first (P35's rule: a tool restores from its own snapshot) — a killed run had left a candidate in src/
- rung R's R6 generalised from "assigned once, read once" to "dead after one read" (the lever rung D actually found:
  uVar5 is assigned in two branches and only one was inlined); it still does not reproduce that class's win, which is
  recorded as an open item rather than papered over
- lever_census: 33,953 sites (was 33,957), 0 UNMARKED; lever_progress snapshot "T6 d1"; R22 218 passed, 0 failed of 218
2026-09-09 12:21:42 -06:00
Drew T 71312c0061 phase-36: T6 — rung R gains R7 (one statement wrapped in a block, the readable spelling first), the move that closed func_80135D20 in 24 s; --cap bounds the candidates per body 2026-09-09 11:19:16 -06:00