# Cookbook index — find the entry by the SYMPTOM you are looking at > **Generated by `tools/cookbook_index.py` — do not hand-edit** (R33). Regenerate after adding a cookbook section. > > `docs/matching-cookbook.md` is ~716 KB / 1099 sections. Grepping it blind is how three P30 wave-1 agents each "discovered" an idiom that was already written down. **Start here, then read the section.** A section appears under every symptom it addresses. **How to use:** name what you SEE in the diff (a stolen delay slot, an extra `la`, a swapped register pair, a `conflicting types` error), find that symptom below, read those sections first. If nothing fits, THEN grind — and add a section when you win. ## Start here — the symptoms that come up most, with the section that fixes them > Hand-curated from what agents actually hit and, in several cases, RE-DERIVED because keyword matching alone did not surface the entry (P30 wave-2 feedback). If your symptom is here, read the named section before anything else. - **wrong branch sense / arms swapped / `beq` where the target has `bne` (match_one prints this class as **BRANCH-POLARITY**)** → **§3-T4** (invert the source condition) + **§32**.2; for a trailing `return 0` vs an early return see the shared-ret0 note (cookbook L1344) - **`conflicting types` on YOUR OWN function's definition, where the fleet canon is `(void)`** → **§73** (the PARAMS axis) + **§42** — keep the `(void)` signature and read the incoming arg via `register s32 a0v __asm__("$4")`; §42 is otherwise indexed only under regalloc - **a shared global declared at a conflicting type (u8 vs s32, signedness) blocking your draft** → **§37** asm-label alias `extern T X __asm__("D_x")` — beats `*(T*)&X`, whose address-of perturbs regalloc. Works for FUNCTION definitions too (P30 wave 2) - **target reuses ONE address register across two different offsets of the same global** → **§20** (the pointer-var-to-the-global bullet, cookbook L1907-1918) — take `T *p = &D_x;` and index off `p`, never the bare symbol twice - **an extra `la` / the address hoisted into a callee-saved register across calls** → **§20** + `gcc-2.7.2-map/cse_expr.md` §H — `*(T*)&sym` force_regs the address; the asm-label alias (§37) keeps the direct `%lo` mem form - **`andi $x,0xFF` folded away in your output but present in the target** → **§1/I2** + **§12** name the family; if the prescribed `& 0xff` at the use folds, hold the masked byte in a **u16** local so only a QI->HI extend survives (P30 wave 2, byte-tested) - **`slti` where the target has `sltiu` (or vice versa)** → **§35** — a separate SIGNED int copy of an unsigned load keeps `slti`; chained bounds get range-folded, so write each bound as its own `if`/`goto` (**§21**) - **you are about to hand-derive a body that some overlay already matched** → **§71** — grep the callees/globals for an already-matched SIBLING first; in wave 2 this alone produced iteration-1 MATCHes on 4 of 19 targets - **gcc stole an instruction into a branch delay slot that the target leaves as `nop`** → **§5a** + the zero-byte `__asm__("")` fence (**§34** toolkit) — `reorg.c stop_search_p` halts the eager filler on an asm insn - **`void` vs `s32` return — is promoting it byte-neutral?** → **NO, not always: §41d** (byte-proven; a `void` body with no `return` gains an instruction). P30 adds a second mechanism: an `s32` return keeps `$v0` live-out and blocks dbr from filling a loop-back delay slot - **`match_one` says **SIZE-MISMATCH/short** and the target has a frame-pointer prologue (`addu $fp,$sp,$zero` / `21F0A003`)** → **The target is -O0.** Pass `--o0` to `match_one`/`rtu_match` — nothing else will ever match (§116: opt level is a property of the FILE). Known -O0 regions: boot, `ov_SC01_077_o0*`, the whale `_o0b`, and 0x8013B568..0x8013C98C — a target outside all four still needs checking - **same instruction multiset, one contiguous window, loads/registers ROTATED inside it** → pure sched1 statement-order (`gcc-2.7.2-map/sched.md` §S1/§S4). **Cheapest lever: brute-force it** — N independent statements, script all N! orders through `match_one` (24 runs ≈ 2 min) instead of reasoning about `rank_for_schedule` - **a two-constant `if/else` or `?:` result lands in **$v1** where the target reuses the condition's **$v0**** → **§76** — fold the condition into a NAMED local and overwrite that SAME variable with the two constants (an s16 temp, a fresh temp, an inner scope, and both ternary polarities all stay $v1; only reusing one `s32` local coalesces onto $v0). §76 reads as behemoth-only; it is not - **a load HOISTED above a store (match_one may call it a WIDTH class)** → usually **§76 regalloc**, not a width bug: a missing WAR dependency lets sched2 hoist it. Same fix — one variable for the compare temp and the result - **`ori $v0,0xffd8` in yours vs `addiu $v0,-0x28` in the target** → a NEGATIVE constant stored into an **unsigned** narrow local materialises via zero-extended `ori`; make the local **signed** to get `addiu`. It does NOT cost you the `lhu` on readback — gcc-2.7.2 emits `lhu` for any plain HImode load feeding an `sh` (P30 wave 4, byte-tested) - **LENGTH-DRIFT −1 and the missing instruction is a reg-to-reg COPY in a `jal` delay slot** → a narrow **prototyped** param (plain ANSI `s16 arg3`) — §43 is indexed as the K&R-definition lever, but the ANSI form is the fix as often - **your narrow load lost its load-delay `nop` right after an inline block move** → an `lwl/lwr`+`swl/swr` pair is a delay-slot **SPONGE** for the following load — the inverse of the §5a/§34 fence case. Align-1 4×u8 struct assign emits the inline form (§38 covers only the -O0 memcpy-call form) - **your `e = param_1` copy VANISHED (target addresses every field off a copy at a join block)** → cse.c `make_regs_eqv` keeps a param copy only when the new pseudo's live range escapes the cse block AND outlives the param's last mention — reach that by REUSING the same variable in a later block. Copy-in-the-arms gets hoisted into the delay slot; copy-assigned-in-an-arm goes global allocno → callee-saved + 2 prologue insns - **⚠️ the `.run/ghidra_c/.c` seed looks like a DIFFERENT function entirely** → it may be — overlays share VAs, so a seed can be decompiled from another overlay mapped at the same address. Trust the target `.s`, not the seed (P30 wave 4) ## By symptom ### delay slots & branches (67) - **§3-T4** — Branch polarity: invert the source condition to flip gcc's chosen branch L90 - **§5a** — Cross-jump tail-merge — gcc collapses two byte-identical blocks the original kept separate (FIX FOUND) L211 - **§3-D.** — THE CROSS-JUMP RATCHET (the sharpest new trap — `func_80131340` L-C) L3542 - **§3-C.** — Inner-block declaration does NOT delay slot allocation — BYTE-REFUTED L10102 - **§162** — CROSS-JUMP DIRECTION: the surviving copy is always the LATER one, so a BACKWARD `j` into a sibling arm is a source `goto` (P30 S48) L11300 - **§162** — The cross-jump "CALL veto" is a COUNT law, not a CALL law (BOUNDS §88a; P30 S48, `func_80189540`) L11336 - **§177** — 🔴 THE EPILOGUE RETURN-DELAY SLOT IS DECIDED BY YOUR SAVED-REGISTER SET, NOT BY SCHEDULING L17223 - **§176-A** — "SCHEDULE / DELAY-SLOT / LENGTH-DRIFT ±1" ⇒ check STATEMENT ORDER around the call first L17680 - **§186** — CROSS-JUMPING RUNS **AFTER** SCHEDULING, SO NO C-LEVEL BARRIER CAN STEER IT L18133 - **§194-H** — §164-29's WAR fence runs again at SCHED2 ON HARD REGISTERS: an in-place `v &= K` before a branch fences the store that reads v, and when TWO independent stores compete for the one delay slot the fence picks the winner at ZERO length drift (a WIDTH/sh!=sw swap, not a nop). Corrects §167-42's reconstruction (pseudo arm → hard-reg arm) and supplies its first re-runnable A/B. L19352 - **§194-M** — A STORE in a CONDITIONAL branch's delay slot proves its C statement DOMINATES the branch — reorg can never pull a store out of either thread (gcc-2.7.2, -mips1) L19611 - **§195-D** — §195 — `masked_diff.mask_for` returns 0 for EVERY `j`/`jal` word, so an internal `j` destination is invisible to match_one, the permuter scorer AND every similarity tier: a control-flow semantic error (which calls execute) surfaces as a 1-instruction residual mislabelled `DELAY-SLOT / profile=schedule`, or as an outright false MATCH L19925 - **§195-E** — A 0/1 materialised at a JOIN immediately before the controlling `beqz`/`bnez` proves the source NAMED the condition — a truth expression in an `if`'s controlling position reaches `do_jump`, which has no value path L19993 - **§195-F** — fold-const.c:4825 canonicalises a `?:` whose THEN arm is zero (or constant against a non-constant ELSE) by inverting the condition and swapping the arms — so a ternary's written arm order is byte-inert there, and `c ? 0 : X` is unspellable: it always compiles as `!c ? X : 0` L20051 - **§195-G** — §NEW — TWO ARMS CALLING THE SAME CALLEE MERGE INTO ONE `jal` UNLESS EACH ARM'S OWN CODE CONSUMES THE RESULT: the C dial that keeps two call sites apart is WHERE the consumer test lives, and the branch SENSE you spell it with is byte-inert (jump.c:1737 canonicalises it) L20103 - **§195-J** — GTE / PsyQ op CALL-vs-INLINE is a PER-SITE SOURCE FACT, not a TU style — both forms coexist in one TU (measured in 2 TUs), and the tell is the target's own opcodes (`lwc2`/`sqr`/`swc2` vs `jal`), not the sibling. Costs -8 ins on func_8018505C. Corollary: the game's inline `sqr` macro emits TWO hazard nops, the SDK's `Square0` body emits ONE — so the inline form is provably not `Square0` inlined (a second instance of §187's SDK-vs-game GTE nop divergence). L20263 - **§195-N** — In a call-bearing chain of N≥2 `if (f(...)) return 1;` tests closed by `return 0;`, the LAST test must stay in STATEMENT form — the value form (`return f() != 0;` / `? 1 : 0` / `!!f()`) costs +1 `j` and empties the other N−1 delay slots. The cause is REORG block placement, not jump.c's `delete_jump`. L20460 - **§197-B** — A REPEATED COMPARE OF ONE VALUE AGAINST ONE CONSTANT IS DELETED BY cse's `qty_comparison_code` CHANNEL (the non-EQ complement of §165-03) — and a front-end-opaque mask on EITHER compare is a pure-C dial that keeps the target's second branch L20660 - **§199-F** — §164-36b — THE TARGET-HEAD FENCE IS A DELAY-SLOT THREAD SELECTOR, AND IT ONLY FIRES WHEN `mostly_true_jump > 0` (amendment to §164-36; its "−1 instruction" tell is falsified) L21020 - **§199-G** — At TWO case nodes the switch-vs-if oracle is not blind — but the tell is ALL tests positive + a trailing `j default`, NOT the first test's polarity L21074 - **§201-C** — §X — A CALL'S OWN DELAY SLOT AND THE UPSTREAM CONDITIONAL BRANCH'S SLOT COMPETE FOR ONE INSN (the call's argument copy), AND ONE STATEMENT'S POSITION RELATIVE TO THE CALL DECIDES BOTH — the residual is visible at the BRANCH, not at the call L21311 - **§204-A** — A COMPARE THAT APPEARS BOTH IN A BRANCH'S DELAY SLOT AND AGAIN ON THE FALL-THROUGH IS A JOIN WITH TWO INCOMING EDGES: THE TWO GUARDS ARE SEQUENTIAL `if`s, NEVER `if/else if` L21607 - **§211** — HOIST THE LOOP INIT ABOVE THE DOMINATING GUARD: it fills the guard's delay slot AND flips the counter/pointer register pair (P31 S58) L22415 - **§221** — A CONSTANT SHARED BY TWO STORES DIES AT THE CALL WHOSE DELAY SLOT REFILLS ITS REGISTER **(single observation — not yet cross-confirmed)** (P31 S58) L22819 - **§223** — READING A `jal` DELAY SLOT: the value in it was produced BEFORE the call, so it is NEVER that call's return (P31 S58) L22877 - **§224** — CROSS-JUMP: WRITE THE DUPLICATE, AND READ A SHARED DELAY SLOT AS THE MERGE SIGNATURE (P31 S58) L22939 - **§232** — WHEN THE `jr` DELAY SLOT'S STORE STORES THE RETURN VALUE, TIE THEM WITH ONE PSEUDO **(single observation — not yet cross-confirmed)** (P31 S58) L23221 - **§243** — SPELL THE CSE BARRIER AS A REASSIGNED POINTER; AND THE `nop`-AFTER-EVERY-`lh` SIGNATURE (P31 S58b) L23721 - **§247** — TWO BRANCHES TO **ONE** LABEL MEANS THE SOURCE CONDITION IS NEGATED (P31 S58b) L23873 - **§224** — addendum (P31 S58b) — CROSS-JUMP MERGES *CALLS*, AND THE DELAY SLOT IS THE DISCRIMINATOR L24560 - **§263** — A STOLEN DELAY SLOT WHOSE INSTRUCTION IS AN ARG-REGISTER COPY IS AN ARITY ERROR, NOT A SCHEDULE (P31 S59, byte-proven) L24927 - **ADD-4** — → §225-3/-4 addendum — THE MIRROR ROW: VALUE-RETURN IN THE *TAKEN* ARM + TRAILING BARE `return 0` L25159 - **ADD-5** — → §1/I1 addendum — THE INVERTED RANGE TEST: `(u32)(x-lo) >= N` WITH THE ZERO-ARM AS THE TRAILING `else` L25173 - **ADD-5** — → §267-ADD-6 / §172b-1 addendum — THE SIGN-TEST FACE: `(s16)v < 0` IS `sll 16` + `bgez` ON THE SHIFTED COPY, RAW STAYS LIVE — AND THE HALFWORD-ABS SHAPE NEEDS NO RITUAL L25411 - **ADDENDUM** — to §224 — CROSS-JUMP: THE DUPLICATE CAN BE A PLAIN STORE, NOT ONLY A CALL L26004 - **ADDENDUM** — to §172a — RE-READING MEMORY (NOT NAMING A TEMP) IS WHAT KEEPS AN INCREMENT'S DELAY-SLOT FILL ALIVE L26304 - **ADDENDUM** — to §225 / §256 — A GOTO TO A SHARED SET-POINT PREVENTS IF-CONVERSION FROM COLLAPSING A LATER BRANCH TEST L26335 - **§277** — RETURN-TAIL C SPELLING PICKS THE DELAY-SLOT-FILL vs TRAILING-MOVE TOPOLOGY, AND A NARROWER SECOND VARIABLE KEEPS TWO PSEUDOS INSTEAD OF ONE (P31 S60; `func_801846F0` ov_SC03_104, `func_801A44C4` md_SC07_004, both byte-proven) L26561 - **ADDENDUM** — to §22 (`volatile`-qualified-global reload lever, cookbook ~L1922) — for a NON-constant, same-address double RMW, a plain memory clobber beats `volatile`, and `volatile` actively breaks a delay-slot fill L27226 - **ADDENDUM** — to §220 — REFERENCING THE RAW PARAMETER (NO NAMED COPY, NOT EVEN A PIN) LETS THE CALLEE-SAVED SPILL LAND IN THE FIRST CALL'S OWN DELAY SLOT L27480 - **ADDENDUM** — to §252 — a `>=0`/`<0` split on an unconditionally-decremented value needs the POSTFIX operator INSIDE the branch condition, not a prior statement L27538 - **ADDENDUM** — to §20's cross-jump EXPLOIT bullet (func_8017E360, ov_SC05_007 — wave dg) L27832 - **ADDENDUM** — §NNN — sharpens §55a / §164-37 / §165-28 (switch-vs-tree cluster): A SHAPE THAT LOOKS LIKE A SWITCH DISPATCH CAN BE PLAIN NESTED `if`s WHOSE SHARED BODY WAS TRIPLICATED BY THE SOURCE AND THEN CROSS-JUMP-MERGED BACK DOWN L28223 - **§285** — PRE-INITIALIZING A VARIABLE WITH A SHARED CONSTANT BEFORE A BRANCH MAKES BOTH ARMS OF THE FOLLOWING if/else DESTRUCTIVELY REUSE THE SAME DESTINATION REGISTER FOR THEIR BITWISE RESULT (byte-proven; `func_801811F0`, ov_SC03_102, independently rediscovered across waves di/dj) (P31 S60; waves #, byte-proven) L29078 - **§286** — FOLD A STATEMENT'S SIDE EFFECT INTO A COMMA-EXPRESSION IN AN ARGUMENT POSITION TO PLACE ITS RTL RELATIVE TO A CALL'S OWN DELAY SLOT (P31 S60/dj; `func_80180A88`, ov_SC06_010, byte-proven 411/411) (P31 S60; waves #, byte-proven) L29082 - **§291** — THE DELAY-SLOT FALSE-VALUE: A CONDITIONAL BRANCH'S ZERO ARM MUST BE A FALL-THROUGH-ADJACENT BLOCK ENDING IN AN EXPLICIT JUMP, OR REORG CANNOT MATERIALIZE IT INSIDE THE BRANCH'S OWN DELAY SLOT (P31 S60; waves #, byte-proven) L29102 - **ADDENDUM** — to §253 — SECOND byte-proven card (upgrade from single-observation), and the placement face: postfix-in-condition parks the RMW store in the branch delay slot L29336 - **§306** — A HAZARD `nop` IN FRONT OF A DIV-RESULT STORE IS A STATEMENT-ORDER DEFECT: THE INDEPENDENT TRAILING STATEMENT MUST BE WRITTEN *BEFORE* THE DIVISION-CONSUMING ONE (P31 S62 T4; byte-proven func_8017E7D0) L29874 - **§308** — A NAIVE FINAL `goto` DELETES THE TARGET'S `j`+`nop`: SPELL THAT EDGE AS A TAUTOLOGICAL `if` SO cse FOLDS IT TO AN UNCONDITIONAL JUMP *AFTER* jump1's WINDOW HAS CLOSED (P31 S63 t5e-t5i; byte-proven func_80180808) L29983 - **§308a** — A TWO-INSTRUCTION ARM STUB LAID *BEFORE* THE OTHER ARM AND REACHED ONLY BY A TRAILING `j` SURVIVES ONLY BEHIND A SHORT-CIRCUIT `&&` GUARD PLUS A SEPARATE RE-TEST; EVERY PLAIN if/else-if, GOTO-LADDER, NESTED-INVERTED-if AND 1-/2-NODE switch LETS jump1 INLINE IT (−2 ins) (P31 S63 t5e-t5i; byte-proven func_80180808) L30012 - **§309** — A FRAME-ADDRESS EQUIVALENCE RIDES *THROUGH* A SKIPPABLE CONDITIONAL: POST-`if` STORES FOLD ONTO `$sp` UNLESS THE `if` SURVIVES jump1 AS A BARRIER-PRECEDED DIAMOND (P31 S63 t5e-t5i; byte-proven func_801812AC) L30046 - **§311** — A JOIN-BLOCK STORE CAN SWALLOW AN ARM'S LOAD-DELAY `nop`: WHEN ONE ARM'S VALUE COMES FROM A LOAD, DUPLICATE THE STORE INTO BOTH ARMS (P31 S64 t5j-t5m; byte-proven func_8017D7E0) L30117 - **§314** — AN IF/ELSE-IF ABS-RANGE CHECK'S C SPELLING IS INERT: FOUR STRUCTURALLY DIFFERENT REWRITES ALL COMPILE BYTE-IDENTICAL, AND NONE REACHES A TARGET THAT SINKS THE NEGATIVE ARM INTO AN OUT-OF-LINE BLOCK (P31 S65; UNPROVEN, gate-refused draft func_80181720) L30241 - **Addendum** — A §5a BARRIER SITS IN REORG'S FILL WINDOW TOO, SO ITS SIDE OF THE INNER `goto` IS CHOSEN P (func_80181D08) L30489 - **§NNN** — REFUTED: A `sw %lo(SYM)($at)` IN A JUMP'S DELAY SLOT WITH ITS `lui $at` STRANDED ABOVE THE JUMP IS **ASSEMBLER** MACRO-EXPANSION, NOT A cse SPLIT — OUR PIPELINE CANNOT EMIT IT FROM ANY C, AND THE +1 IS A `maspsx` GAP (P31 S66 round2, `func_8005DBD8`, byte-probed) L30591 - **Addendum** — REGALLOC-PERM store in a cross-jump shared tail defeats §137's barrier (func_8017EDE8) L30630 - **Addendum** — LENGTH-DRIFT nop clears when offset math precedes the symbol launder (func_80039B20) L30634 - **Addendum** — Return-0 statement order: extra j+move vs delay-slot fusion (func_8018BB50) L30721 - **§331** — OPEN GAP: NO LEVER ELIMINATES AN *UNWANTED DUPLICATE* COPY AT A BRANCH-TARGET BLOCK HEAD (P31 S67; main/func_80013154, closeness 12, NOT solved) L31059 - **§332** — THE maspsx `la`-IN-A-DELAY-SLOT GAP: gcc EMITS A SYMBOLIC ADDRESS LOAD AS ONE ATOMIC length-2 INSN, SO IT CAN NEVER FILL A JUMP DELAY SLOT — 6 FUNCTIONS FLEET-WIDE, NONE BANKABLE FROM C (P31 S67; byte-traced main/func_80062144, func_8005DBD8) L31071 - **§336** — THE §5a CROSS-JUMP BARRIER GOES AT THE *BOTTOM* OF THE TWIN, NOT THE TOP: `find_cross_jump` WALKS BACKWARD FROM THE CONVERGING JUMP (P31 S67; byte-proven ov_SC05_001/func_80183C9C) L31149 - **§339** — A 2-CASE SWITCH OMITS THE LOW-BOUND RANGE TEST, SO THE PRESENCE OF `slti/bnez` BETWEEN THE `beq`s IS A **COUNT TELL** FOR A THIRD CASE NODE (P31 S67; byte-proven ov_SC02_005/func_80190538, 197 ins) L31181 - **§346** — `c ? X : -X` TAKES expand_expr's COND_EXPR **SINGLETON** PATH (copy, then negate IN PLACE) — AN if/else STATEMENT GIVES THE TWO-ARM FORM (P31 S67; byte-proven ov_SC03_102/func_80180C38, closed the last instruction) L31322 - **§370** — ★★ — A **HARD BOUND** FROM sched.c, AND THE reorg SLOT-STEAL DIAGNOSTIC (P31 S68; main/func_8001BC6C, 69 ins, NOT closed — 33 → 28 over ~45 measured compiles) L31838 - **§396g** — ★★ — A GUARD LADDER'S RUNGS MUST STAY SYMMETRIC OR `reorg.c` LOSES ITS BRANCH REDIRECT (P31 S69; byte-proven ov_SC03_028/func_80184C90, 92 ins) L32818 - **§428** — ★★★ — A ZERO-BYTE CROSS-JUMP BARRIER: ADVANCE THE POINTER INSIDE EACH SWITCH ARM (P31 S72; `main/func_80026D64`, 218 ins, MATCH in 2 compiles) L33950 - **§430** — ★★★ — A SHARED TAIL IS A LATE CROSS-JUMP MERGE, NOT A SOURCE `goto` — AND SPELLING IT AS ONE CAN INVALIDATE A LOOP (P31 S72; `main/CdReadSectorReadyCB`, 422/424 ins, verified with `cc1 -dL`) L34023 ### instruction scheduling (88) - **§3-T2** — Source statement order drives instruction scheduling L78 - **§3** — When a diff is pure scheduling → decomp-permuter (harness built, Phase 6) L107 - **§10** — Closing the regalloc/scheduling hard tail by hand (LZSS, Phase 7 session F — the full close) L854 - **§25** — The "schedule" class is mostly COALESCING (pin-crackable), not scheduling; + the gate two-stage + h_exact over-counts ×134 (Phase 21, cont.6) L2151 - **§3-The** — crack: the residual was gcc-2.7.2 COPY-COALESCING, not the instruction scheduler L2163 - **§3-The** — genuine scheduler — `rank_for_schedule` (sched.c), for when it IS scheduling L2179 - **§3-The** — genuine schedule WALLS (do NOT re-grind — stub) L2188 - **§32** — The region-a CAMERA-GIANT idiom set: struct-base hoisting + 4 sibling levers (Phase 24 T7, Fable5-cracked on `func_80129CF8` 191 ins, match_one MATCH; transferable to the 6 sibling giants) L2441 - **§34** — The `func_80138ED0` giant crack: gcc-2.7.2's **3-qty sort bug** + the **zero-byte asm allocation toolkit** + the **giv-init fence** (Phase 24 T5; Opus→close=21, Fable5→MATCH ×134) L2473 - **§35** — The region-a sibling-giant harvest: difficulty ≠ $s-reg count (it's global-array hoisting) + the banking recipe + new loop idioms (Phase 24 T7, 5 parallel Opus-Max agents) L2490 - **§3-A4** — SINK THE CONSUMER CALL INTO THE ARMS (the inverse of A1; `func_8016AB6C`, byte-proven) L3478 - **§49** — The LUID DIAL: a zero-byte SCHEDULING dial (the sched.c analogue of §47) — `func_8017A4AC` (536 ins ×134), Phase 26 session 8 L3561 - **§66d-5** — `residual_class`'s "structural ⇒ permuter CPU is waste" is WRONG for schedule permutations (measured, Phase 29 SESSION-18) L5525 - **§3-The** — attribution primitive (use this before calling anything a scheduling residual) L6091 - **§3-The** — scheduling rules (refining §135-2 and §135-4) L8946 - **Consequence** — for the family (a real scheduling decision) L10129 - **§148** — The loop.c hoisting THRESHOLD is arithmetic you can compute, and the `?:` clamp that folds to MIN_EXPR (P30 S42, `func_8017C6F4`, 947 ins) L10179 - **§3-A.** — `move_movables` hoists iff `threshold × savings × lifetime ≥ insn_count` — and you can read it L10185 - **§16Z** — SHARPENS *(sharpens §37 "the /s-DEP LATTICE", §136-13, §136-14, §16Xy, §162q, `gcc-2.7.2-map/sched.md` §64)* L14394 - **§175** — A CALLER-SAVED REGISTER PIN CAN BE A CORRECTNESS BUG, NOT JUST A SCHEDULING CHOICE (P31 wave H, 2026-08-15) L16776 - **§177** — 🔴 THE EPILOGUE RETURN-DELAY SLOT IS DECIDED BY YOUR SAVED-REGISTER SET, NOT BY SCHEDULING L17223 - **§3-B.** — A `return ` IS A PRIORITY-1 HARD-REG SET THE SCHEDULER PLACES FIRST (func_8001BE30, 92 ins) L17308 - **§176-A** — "SCHEDULE / DELAY-SLOT / LENGTH-DRIFT ±1" ⇒ check STATEMENT ORDER around the call first L17680 - **§176-C** — 🔴 WALL REFUTATION: a hard-register pin CANNOT schedule around a call, because of a genuine gcc-2.7.2 bug L17750 - **§186** — CROSS-JUMPING RUNS **AFTER** SCHEDULING, SO NO C-LEVEL BARRIER CAN STEER IT L18133 - **§193-C** — gcc-2.7.2 cross_jump merges the SCHEDULED common SUFFIX only — there is no prefix/head merge, so §8/§48-A1's "duplicate into both arms and cross_jump refunds it" is a TAIL-only lever L18588 - **§193-D** — A COMPILER-GENERATED ARGUMENT COPY IS A `optimize_reg_copy_1` TRIGGER: when the pointer's LAST use in a block precedes a call that takes the pointer *as a register*, sched1 hoists the implicit `move $aN,$sN` to the block top and local-alloc re-bases the WHOLE block's memory operands onto `$aN`. The only C dial is a label (the §165-24 goto-join) between the block and the call. L18622 - **§193-F** — §148-A2 — The `threshold -= 3` STAIRCASE: `move_movables` admits a COUNT of invariants, not a boolean — two identical merged constants split hoisted/not-hoisted by LIST ORDER, and `insn_count` picks the rank cutoff L18723 - **§194-A** — A zero-byte scheduling fence goes AFTER the defining statement to make that computation emit FIRST in its block — and the barrier predicate is `volatile`-or-colon-less, not the `"memory"` clobber (COMPLEMENTS §165-40; does not refute it) L18991 - **§194-D** — Declared width of a computed-value local is a sched1 dial (count-neutral) — a replication + attribution correction of §165-17, NOT a new argument-register law L19158 - **§194-H** — §164-29's WAR fence runs again at SCHED2 ON HARD REGISTERS: an in-place `v &= K` before a branch fences the store that reads v, and when TWO independent stores compete for the one delay slot the fence picks the winner at ZERO length drift (a WIDTH/sh!=sw swap, not a nop). Corrects §167-42's reconstruction (pseudo arm → hard-reg arm) and supplies its first re-runnable A/B. L19352 - **§194-K** — Blind sched1's alias oracle with a second SET of a pointer pseudo — the first zero-byte, non-volatile, dependence-CREATING lever (corrects §167-05's "volatile is the only door"; fourth consumer of reg_n_sets) L19485 - **§194-N** — §193-D's C dial is misstated: the lever is a SURVIVING CODE_LABEL (a label with a real incoming edge), not "a label between the block and the call" — a bare label, or a `goto L; L:` pair whose target is the next active insn, is deleted by jump1 (jump.c:663-669 → delete_insn → jump.c:3458-3461, and jump.c:243 for the bare case) long before sched1/local-alloc, and costs exactly zero bytes L19669 - **§195-D** — §195 — `masked_diff.mask_for` returns 0 for EVERY `j`/`jal` word, so an internal `j` destination is invisible to match_one, the permuter scorer AND every similarity tier: a control-flow semantic error (which calls execute) surfaces as a 1-instruction residual mislabelled `DELAY-SLOT / profile=schedule`, or as an outright false MATCH L19925 - **§199-A** — §189-A's asm→source inference is byte-FALSE: an interloper between a split constant's `lui`/`ori` is a SCHEDULE fact, not a source fact — and the separator is the BIRTHING BOOST, not a "priority floor" (§189-A's split-timing half survives; its "no statement order / no pin" absolute and the candidate's own forward-scheduler narrative both fall) L20759 - **§199-F** — §164-36b — THE TARGET-HEAD FENCE IS A DELAY-SLOT THREAD SELECTOR, AND IT ONLY FIRES WHEN `mostly_true_jump > 0` (amendment to §164-36; its "−1 instruction" tell is falsified) L21020 - **§205** — THE CHAINED ASSIGNMENT IS ITS OWN SCHEDULING DIAL: `*b = *a = v;` moves an argument copy that no local, no pin and no statement reorder will move (P31 S56) L22098 - **§211** — HOIST THE LOOP INIT ABOVE THE DOMINATING GUARD: it fills the guard's delay slot AND flips the counter/pointer register pair (P31 S58) L22415 - **§219** — COMPOUND `+=`, FULL ASSIGNMENT, AND AN EXPLICIT TEMP ARE THREE DIFFERENT SCHEDULES OF ONE READ-MODIFY-WRITE (P31 S58) L22752 - **§30** — addendum (P31 S58) — the `/s` grant closes a SCHEDULING residual and a REGISTER residual with one edit L23257 - **§165-40** — addendum (P31 S58) — the barrier goes at the COPY SITE, not inside the region it protects L23289 - **§239** — TWO-STATEMENT INTEGER-SPACE MATERIALISATION REORDERS `la` vs `sll`; AND THE PLUS-TREE OPERAND ORDER (P31 S58b) L23601 - **§243** — SPELL THE CSE BARRIER AS A REASSIGNED POINTER; AND THE `nop`-AFTER-EVERY-`lh` SIGNATURE (P31 S58b) L23721 - **§245** — THE CALL'S ARGUMENT LIST IS A SCHEDULING SLOT (P31 S58b) L23786 - **§211** — addendum (P31 S58b) — INIT PLACEMENT: FIVE MORE DIALS BEYOND THE GUARD HOIST L24316 - **§263** — A STOLEN DELAY SLOT WHOSE INSTRUCTION IS AN ARG-REGISTER COPY IS AN ARITY ERROR, NOT A SCHEDULE (P31 S59, byte-proven) L24927 - **ADD-8** — → §245 addendum — THE RE-TIE BARRIER PINS CALL-ARG SETUP TO SOURCE ORDER (construct 6) L25203 - **ADDENDUM** — to §244 — THE COMPILER BARRIER, NOT `volatile`, BLOCKS A STORE→LOAD HOIST THROUGH A POINTER-OFFSET FIELD L26069 - **§281** — GROUP COPY-THEN-RMW BY OPERATION KIND, NOT FIELD BY FIELD: sched1 does the interleaving, the source must not (P31 S60; wave cf, func_80180FB4, ov_SC03_111, byte-proven) L26990 - **§NNN** — A DEPENDENT COPY-THEN-RMW BLOCK MUST BE SOURCE-GROUPED BY OPERATION KIND, NOT BY FIELD, AND SCHED1 DOES THE INTERLEAVING (P31 S60; `func_80180FB4`, ov_SC03_111, byte-proven) L26991 - **§282** — gcc's OWN LOOP REVERSAL PUTS THE COUNTER INIT AFTER THE HOISTED MOVABLES — a position no hand-written down-count can reach (P31 S60; wave cf, func_80180DD8, ov_SC04_005, byte-proven) L27036 - **§NNN** — WRITE THE UP-COUNT LOOP: gcc's OWN REVERSAL PRODUCES A COUNTER-INIT INSTRUCTION THAT LANDS AFTER HOISTED MOVABLES, WHICH A HAND-WRITTEN DOWN-COUNT LOOP CANNOT REPRODUCE (P31 S60; `func_80180DD8`, ov_SC04_005, byte-proven) L27037 - **ADDENDUM** — to §195-N — a GNU statement-expression slider must sit INSIDE the conditional arm's value position, not as a post-hoc barrier, to block the store-flag transform on a ternary chain L27307 - **ADDENDUM** — §NNN — sharpens §167-13's boundary: CHAINING TWO IDENTICAL SIDE-BY-SIDE STORES INTO ONE C ASSIGNMENT STATEMENT IS A MID-BLOCK SCHEDULING-PRIORITY DIAL, NOT ONLY A STORE-ORDER SPELLING L28260 - **§284** — COMBINE CAN REASSOCIATE TWO SEQUENTIAL BITWISE-AND MASKS INTO ONE AGAINST THE PRE-MASK VALUE; AN ASM IN/OUT FENCE RIGHT AFTER THE FIRST MASK BLOCKS IT (P31, wave dd, `func_8018087C`, ov_SC04_020, byte-proven) (P31 S60; waves #, byte-proven) L29074 - **§298** — THE SHARED-TAIL POSITION DIAGNOSTIC: A FOLDED TAIL *BETWEEN* SWITCH ARMS MEANS PER-ARM DUPLICATED STATEMENTS, NOT A HOISTED POST-SWITCH STATEMENT (P31 S61; waves g0e/g0f, `func_80181B68`, ov_SC06_016, byte-proven 68/68) L29542 - **§299** — TWO INDEPENDENT EXTRACTION CHAINS EMIT CONTIGUOUSLY INSIDE ONE EXPRESSION; ONLY A STATEMENT BOUNDARY MAKES THE SCHEDULER INTERLEAVE THEM (P31 S61; wave m0a, `func_8003A404`, main, byte-proven 8/8) L29567 - **§307** — THE BRUTE-FORCE-THE-STATEMENT-ORDERS LEVER HAS A BOUND: A FAN-OUT COPY'S PRIORITY IS SCHEDULER-INTERNAL, AND NO SOURCE ORDER REACHES IT (P31 S63; byte-evidenced NEGATIVE result, main wave) L29939 - **§309** — A FRAME-ADDRESS EQUIVALENCE RIDES *THROUGH* A SKIPPABLE CONDITIONAL: POST-`if` STORES FOLD ONTO `$sp` UNLESS THE `if` SURVIVES jump1 AS A BARRIER-PRECEDED DIAMOND (P31 S63 t5e-t5i; byte-proven func_801812AC) L30046 - **§314** — AN IF/ELSE-IF ABS-RANGE CHECK'S C SPELLING IS INERT: FOUR STRUCTURALLY DIFFERENT REWRITES ALL COMPILE BYTE-IDENTICAL, AND NONE REACHES A TARGET THAT SINKS THE NEGATIVE ARM INTO AN OUT-OF-LINE BLOCK (P31 S65; UNPROVEN, gate-refused draft func_80181720) L30241 - **Addendum** — A §5a BARRIER SITS IN REORG'S FILL WINDOW TOO, SO ITS SIDE OF THE INNER `goto` IS CHOSEN P (func_80181D08) L30489 - **Addendum** — Loop sentinel wrongly hoisted out of a call-containing loop (func_801835B0) L30493 - **Addendum** — REGALLOC-PERM: one memory-clobber barrier insufficient — stack two (func_80182D1C) L30523 - **Addendum** — A plain global-RMW triplet is a fillable scheduling window too — zero drift, and the fille (func_800CB058) L30533 - **Addendum** — Shared arithmetic that CONSUMES the selected value cannot be hoisted above the `if` — narr (func_80183DA0) L30537 - **Addendum** — Truncating assign must be the lazy `||` operand, not hoisted (func_80012B58) L30560 - **Addendum** — WIDTH sh!=lhu residual: hoist a sibling field's load first (func_80182538) L30572 - **Addendum** — REGALLOC-PERM store in a cross-jump shared tail defeats §137's barrier (func_8017EDE8) L30630 - **Addendum** — Volatile zero-byte asm slider scrambles the prologue schedule (func_801814B0) L30747 - **Addendum** — §194-A addendum — the bare/colon-less fence measured NULL and only the "memory"-clobber fo (func_8017E464) L30761 - **§336** — THE §5a CROSS-JUMP BARRIER GOES AT THE *BOTTOM* OF THE TWIN, NOT THE TOP: `find_cross_jump` WALKS BACKWARD FROM THE CONVERGING JUMP (P31 S67; byte-proven ov_SC05_001/func_80183C9C) L31149 - **§340** — §194-K COROLLARY: **FLIP THE FALSE EDGE YOU CANNOT DELETE.** A "scheduler" residual can be sched.c's ALIAS ORACLE emitting a FALSE true-dependence; source order chooses its DIRECTION (P31 S67; byte-proven ov_SC03_107/func_8017CF48, 10 -> 0 in one compile, zero bytes) L31209 - **§341** — AN HImode STORE TEMP REWEIGHTS A sched2 TIE-BREAK THAT NO STATEMENT ORDER CAN REACH (P31 S67; byte-proven ov_SC03_006/func_801823B8, last 4 ins) L31243 - **§349** — RE-ASSIGN A BASE POINTER AT THE END OF THE LOOP BODY TO MAKE `n_times_set > 1` — THAT KILLS BOTH loop.c's INVARIANT HOIST **AND** THE ADDRESS GIV, REPRODUCING A REMATERIALISED `addiu $aN,$sp,K` (P31 S67; byte-proven ov_SC06_029/func_801804C8, 255 ins) L31414 - **§350** — A ZERO-BYTE RE-TIE SETS `reg_n_sets=2`, WHICH KILLS sched1's `birthing_insn_p` LAUNCH_PRIORITY BOOST — THE MECHANISM BEHIND "MY ADDS ARE GLUED TO THEIR STORES" (P31 S67; byte-proven ov_SC04_011/func_80180B24, 215 ins) L31435 - **§352** — ⚠ TWO IDENTICAL `__asm__ __volatile__("")` BARRIERS **MERGE WITH EACH OTHER** — SPELL THE SECOND ONE DIFFERENTLY (P31 S67; byte-proven resident/func_800D128C, measured closeness 105 when they merged) L31486 - **§361** — ★ — A LOOP-TAIL BYTE SIGNATURE THAT NAMES ITS SOURCE SHAPE — AND THE LAW THAT A "SCHEDULING TIE" MAY BE YOUR OWN EARLIER LEVER (P31 S68; byte-proven main/func_800241C0, fable escalation, 19 → 0 in 3 iterations) L31637 - **§370** — ★★ — A **HARD BOUND** FROM sched.c, AND THE reorg SLOT-STEAL DIAGNOSTIC (P31 S68; main/func_8001BC6C, 69 ins, NOT closed — 33 → 28 over ~45 measured compiles) L31838 - **§373** — ★★★ — THE **DEAD-RESET CSE-BREAKER**, THE PIN THAT BREAKS A sched2 ANTI-DEP, AND WHY AN `asm` CAN NEVER RAISE PRIORITY (P31 S68; byte-proven ov_SC06_010/func_8017E764, 438 ins, fable escalation closed 8 → 0) L31977 - **§3-2.** — A REGISTER PIN THAT DELETES A sched2 ANTI-DEPENDENCE L31997 - **§3-3.** — HARD FACT FOR THE SCHEDULING MAP — an `asm` ALWAYS has priority 1 L32010 - **§379** — ★★★ — **MEM_IN_STRUCT_P**: THE SAME LOAD, WRITTEN AS A STRUCT MEMBER, SCHEDULES WHERE A CAST CANNOT (P31 S69; byte-proven main/func_80021284 220 ins and main/func_8002D904 217 ins, found INDEPENDENTLY by two agents) L32164 - **§381** — THE `insn_count` HOIST THRESHOLD IS A DIAL YOU CAN READ WITH `cc1 -dL` (P31 S69; four independent uses in one wave) L32216 - **§385** — ★★★ — THE **SCHED2 PRIORITY-DONOR ASM**: closing the "hoisted-invariant vs IV-init preheader swap" class (P31 S69; byte-proven main/func_80038A58, 347 ins, fable escalation 2 → 0) L32309 - **§393** — ★★ — THE **BIRTHING BOOST**: A SINGLE-SET LOCAL IS SCHEDULED LAST; GIVE IT A SECOND SET (P31 S69; byte-proven ov_SC02_017/func_8017FCFC) L32543 - **§3-B.** — THE SCHEDULER DIALS (the dominant residual family this wave) L33108 - **§424** — ★★★ — EQUAL-PRIORITY STORES COME OUT **REVERSED**: sched1's LUID tie picks the LAST statement first (P31 S71; byte-proven `ov_SC07_006/func_801890FC`, 387 ins) L33807 - **§428** — ★★★ — A ZERO-BYTE CROSS-JUMP BARRIER: ADVANCE THE POINTER INSIDE EACH SWITCH ARM (P31 S72; `main/func_80026D64`, 218 ins, MATCH in 2 compiles) L33950 ### register allocation & pins (131) - **§10** — Closing the regalloc/scheduling hard tail by hand (LZSS, Phase 7 session F — the full close) L854 - **Residual** — A — commutative `|`/`&`/`+` result lands in the wrong source-operand register L875 - **Register-allocation** — ORDER (call-crossing $s0/$s1 swap) → FORCE it with register pins (byte-proven) L1403 - **§3-The** — LOOSE-TYPING wall is real for narrow params (Phase 16, reconfirmed) L1447 - **§3-THE** — CAP: at this tail the match_one→gate gap is the LOOSE-TYPING CALL-GRAPH wall (not cheap plumbing) L1656 - **§22** — DEF-side loose-typing recovery + grinder blacklist (Phase 21) L2024 - **§24** — The `ov_SC01_077_a.c` split-file vein: split-aware propagation, but loose-typing-gated (Phase 21) L2104 - **§25** — The "schedule" class is mostly COALESCING (pin-crackable), not scheduling; + the gate two-stage + h_exact over-counts ×134 (Phase 21, cont.6) L2151 - **§42** — The F-band ≤28 regalloc crack wave: register-pin/DENSITY levers beat the permuter (Phase 25 T7 F-band, 2026-07-10; Ultracode 9-worker wave, 4/9 banked byte-identical, 266 swept ×134) L2934 - **§43** — The K&R s16-param definition DISSOLVES the "narrow-param wall" for by-value register args (Phase 25 task A, Fable5 crack of the 369-ins giant `func_80166994` ×134, 2026-07-11) L3229 - **§45** — The flagship `func_80133CD4` crack (399 ins ×134): the merged-variable permutation-breaker + the 1-death local-alloc gate (Phase 25 task A giant escalation, Fable5 gdb-on-cc1, 2026-07-11) L3332 - **§47** — The live-length SLIDER: splitting a global.c allocno-priority TIE with one zero-byte asm (Phase 26 session 8, Fable5 Max, byte-proven on `func_8017BEBC` 952 ins ×113) L3399 - **§48** — The 12-core jr crack wave: the ALLOCNO-PRICING dials and the EBB rule (Phase 26 session 8, Ultracode, 9/12 MATCH first pass) L3439 - **§3-A.** — ALLOCNO-PRICING DIALS — move a value into the register you want, byte-neutrally L3447 - **§52** — The WALKER-FAMILY skeleton: 6 regalloc-order levers + a deeply-characterized intrinsic wall (`func_80178004`, 165 ins ×134; Phase 26, Fable5, 2026-07-15) L3947 - **§52a** — The regalloc sibling wave: new levers + two new wall classes (cheap-Opus applying §52, 2026-07-15) L3993 - **§52b** — Sibling wave 2: more de-pin levers, a third wall class, and the match_one→whole-binary gap at scale (2026-07-15) L4031 - **§66d-1** — What transfers between giants is the LOOP, not the PIN L5314 - **§70** — The giv-init base register: walk the PARAMETER, not a copy of it (Phase 29 SESSION-18, `func_801777BC`) L5653 - **§71** — Before mapping a giant, look for an already-matched SIBLING beside it (Phase 29 SESSION-18, `func_8017D960`, 3,338 ins) L5694 - **§72** — A `register __asm__` pin is a PREFERENCE, not a reservation (Phase 29 SESSION-18, `func_8017F510`) L5760 - **§74** — Auditing a pinned draft: the §72 hazard is CALLER-SAVED pins spanning a call, and only the disassembly can tell you (Phase 29 SESSION-19, `func_8017D960` b2, 5 pins) L5856 - **§76** — The allocno CLASS (local vs global) is the dominant regalloc lever, and C reaches it ONLY through declaration scope and variable reuse (Phase 29 SESSION-19, behemoth #3 `func_8017F510` 1,511 ins, 97 → MATCH, pin-free) L6062 - **§78** — A LENGTH drift can be a register grant in disguise; and `fold` never leaves a literal first in an `|` chain (Phase 29 SESSION-19, behemoth #2 `func_8017D960` 3,338 ins, 1806 → 0, pin-free) L6208 - **§76** — confirmed at scale, and a pin nuance L6285 - **§80** — A do-not-re-buy entry is scoped to its BASE, not to the function; and the pin's hidden cost is an unconditional `qty_phys_sugg` (Phase 29 SESSION-19, `func_8017BF14` 45 → 0) L6304 - **§3-The** — pin's hidden cost, with the citation L6325 - **§83** — The parameterised-repeat law, the spill-area trap, and why a per-case edit cannot move a per-case symptom (Phase 29 SESSION-20, `func_80183814` 5,122 ins, cold-ish start → 36 structural / 99.3%) L6446 - **§83c** — TRAP: a "dead local" in a prior draft may be gcc's OWN spill area L6479 - **§86** — Pinned-exemplar templatability is a PER-FAMILY property, not a per-member rate; and the §42e pin guard is now over-conservative (Phase 29 SESSION-20) L6623 - **§3-Two** — further notes worth keeping L8282 - **§137** — REGALLOC-PERM is a TWO-COMPILE ARITHMETIC PROBLEM, not a permuter job L9378 - **§3-The** — same swallow, twice more, in the integration spine L9743 - **§3-B.** — A `?:` on MEMORY operands costs ~16 bytes of invisible frame; on REGISTER operands, zero L10091 - **§3-D.** — A lone `$t8`/`$t9` in the target is RELOAD SCRATCH — reproduce the spill, don't pin the register L10107 - **§3-C.** — A zero-byte ALLOCNO-PRIORITY slider L10218 - **§150** — A register ROTATION across symmetric blocks is VARIABLE-IDENTITY evidence, not an allocator tie (P30 S43, `func_8017C6F4`, 947 ins ×4) L10346 - **§152** — BYTE SIZE is the family key that name- and h_seq-grouping both miss (P30 S43, the 0xECC family: 1 crack → 12 overlays → 11,364 ins) L10452 - **§155** — hi/lo literal scanning MUST track base registers (S45) L10592 - **§158** — The RANGE-EXTENDER: a fourth zero-emission asm lever completes the allocno toolkit (P30 S46 tier-3, `func_8017CE58`, 733 ins) L10746 - **Bonus** — facts worth keeping L10791 - **§156** — THE PREFERENCE-DONOR MERGE: cross-region variable reuse is what fills a0-a3, and a call-arg use in ONE region steers the fill in ALL of them (P30 S46 tier-3, `func_80186E24`, 611 ins: 236-off "S11 regalloc-order" → MATCH, zero new pins) L10806 - **§175** — A CALLER-SAVED REGISTER PIN CAN BE A CORRECTNESS BUG, NOT JUST A SCHEDULING CHOICE (P31 wave H, 2026-08-15) L16776 - **§176j** — STOPPING A WAVE MID-FLIGHT COSTS THE IN-FLIGHT TAIL (and how much is recoverable) L17160 - **§177** — 🔴 THE EPILOGUE RETURN-DELAY SLOT IS DECIDED BY YOUR SAVED-REGISTER SET, NOT BY SCHEDULING L17223 - **§179-A** — 🔴 A LOOP-WALKED POINTER **PARAMETER** HANDS ITS ARGUMENT REGISTER TO THE GIV (9 byte-proofs) L17377 - **§179-F** — PINNING A LOOP-WALKED POINTER IS A TOTAL OFF-SWITCH FOR STRENGTH REDUCTION L17573 - **§179-G** — 🟡 A PIN CAN **CREATE** A COMBINE `LOG_LINK` AND DELETE AN `andi` (sixth RC-5 channel, n=1) L17596 - **§176** — SEVEN LEVERS FROM THE P31 OVERNIGHT WAVES (2026-08-15): statement order, false regalloc, and the pin that fights back L17674 - **§176-B** — "REGALLOC-PERM, 1-4 instructions off" ⇒ it is usually NOT register allocation L17704 - **§176-C** — 🔴 WALL REFUTATION: a hard-register pin CANNOT schedule around a call, because of a genuine gcc-2.7.2 bug L17750 - **§3-18** — of 20 reconciled while keeping the match. The two that did not are mechanism, not effort. L18003 - **§186** — CROSS-JUMPING RUNS **AFTER** SCHEDULING, SO NO C-LEVEL BARRIER CAN STEER IT L18133 - **§186c** — WHERE A VALUE IS LOADED DECIDES WHICH ALLOCATOR OWNS IT, AND THEREFORE ITS REGISTER L18162 - **§193-B** — A NARROW CAST OF A WIDE PARAMETER COSTS ONE EXTRA INSTRUCTION WHEN ITS STATEMENT SITS AFTER AN INTERVENING `jal` — AND THE DECIDER IS `combine.c:929`'s CROSS-CALL GUARD, NOT REGISTER ALLOCATION L18550 - **§193-D** — A COMPILER-GENERATED ARGUMENT COPY IS A `optimize_reg_copy_1` TRIGGER: when the pointer's LAST use in a block precedes a call that takes the pointer *as a register*, sched1 hoists the implicit `move $aN,$sN` to the block top and local-alloc re-bases the WHOLE block's memory operands onto `$aN`. The only C dial is a label (the §165-24 goto-join) between the block and the call. L18622 - **§194-B** — A `addu $rA,$rB,$zero` copy feeding ≥2 `sh` stores is a SECOND, 16-BIT-DECLARED local — the width, not the clamp or the join liveness, is what keeps the copy (and func_80183094's pin + `"memory"` clobber are both provably inert) L19057 - **§194-C** — A CALLER-SAVED loop counter proves its live range crosses ZERO calls — so it cannot share a pseudo with any value LIVE ACROSS a call (but it may freely share one with values that merely sit between calls) L19095 - **§194-D** — Declared width of a computed-value local is a sched1 dial (count-neutral) — a replication + attribution correction of §165-17, NOT a new argument-register law L19158 - **§194-G** — Reading the integer half of a 16.16 stack aggregate: REGISTER-LIVENESS, not the C spelling, decides `sra` vs `lhu` — and the break is count-neutral L19309 - **§194-H** — §164-29's WAR fence runs again at SCHED2 ON HARD REGISTERS: an in-place `v &= K` before a branch fences the store that reads v, and when TWO independent stores compete for the one delay slot the fence picks the winner at ZERO length drift (a WIDTH/sh!=sw swap, not a nop). Corrects §167-42's reconstruction (pseudo arm → hard-reg arm) and supplies its first re-runnable A/B. L19352 - **§194-N** — §193-D's C dial is misstated: the lever is a SURVIVING CODE_LABEL (a label with a real incoming edge), not "a label between the block and the call" — a bare label, or a `goto L; L:` pair whose target is the next active insn, is deleted by jump1 (jump.c:663-669 → delete_insn → jump.c:3458-3461, and jump.c:243 for the bare case) long before sched1/local-alloc, and costs exactly zero bytes L19669 - **§195-B** — A CALL_INSN does not start a basic block in gcc-2.7.2 — so a call-crossing temp can be a LOCAL-alloc quantity (the missing precondition under §48-A2 / §52 / regalloc.md K8) L19835 - **§195-F** — fold-const.c:4825 canonicalises a `?:` whose THEN arm is zero (or constant against a non-constant ELSE) by inverting the condition and swapping the arms — so a ternary's written arm order is byte-inert there, and `c ? 0 : X` is unspellable: it always compiles as `!c ? X : 0` L20051 - **§197-C** — Fix A1 (operand order) cannot move a commutative destination whose .greg conflict set already contains BOTH operand hard registers — split the accumulate so the destination IS the load's pseudo L20688 - **§199-A** — §189-A's asm→source inference is byte-FALSE: an interloper between a split constant's `lui`/`ori` is a SCHEDULE fact, not a source fact — and the separator is the BIRTHING BOOST, not a "priority floor" (§189-A's split-timing half survives; its "no statement order / no pin" absolute and the candidate's own forward-scheduler narrative both fall) L20759 - **§199-B** — A permutation sweep that holds ANY statement fixed is not a sweep: the statement an agent pins as "obviously load-bearing" is the one carrying the signal, and the partial sweep returns a FLAT residual that reads as proof of order-invariance L20808 - **§199-E** — §189-A BOUNDED AND CORRECTED — the discriminator is INSN_PRIORITY, not "is the interloper a constant": an insn between a `lui`/`ori` pair proves NOTHING about the source spelling unless it TIES the `ori` on priority, and on the pinned `-mcpu=3000` triple a dependent load never does L20961 - **§205** — THE CHAINED ASSIGNMENT IS ITS OWN SCHEDULING DIAL: `*b = *a = v;` moves an argument copy that no local, no pin and no statement reorder will move (P31 S56) L22098 - **§208** — TWO NAMED LOCALS FOR ONE RELOADED EXPRESSION BUY TWO ALLOCNOS — the naming granularity owns the REGISTER SPLIT, not just the load count (P31 S58) L22243 - **§211** — HOIST THE LOOP INIT ABOVE THE DOMINATING GUARD: it fills the guard's delay slot AND flips the counter/pointer register pair (P31 S58) L22415 - **§215** — PIN ECONOMY: the twin's pins are NOT part of the shape, and §17's "pin every call-crossing value" is over-broad (P31 S58) L22601 - **§220** — THE PARAMETER ITSELF IS A REGALLOC DIAL: use it directly, prefer `s32` to `void*`, and place the save-copy AFTER the first call (P31 S58) L22779 - **§221** — A CONSTANT SHARED BY TWO STORES DIES AT THE CALL WHOSE DELAY SLOT REFILLS ITS REGISTER **(single observation — not yet cross-confirmed)** (P31 S58) L22819 - **§30** — addendum (P31 S58) — the `/s` grant closes a SCHEDULING residual and a REGISTER residual with one edit L23257 - **§244** — `volatile` IS A COUNTING INSTRUMENT, A STORE-ORDER PIN, AND MUST SOMETIMES BE ASYMMETRIC (P31 S58b) L23751 - **§248** — SPLIT THE LOAD FROM THE ARITHMETIC: A FUSED `g + K` DENIES THE CALLEE-SAVED REGISTER ITS DIRECT HOME (P31 S58b) L23907 - **§253** — POSTFIX `++` vs `+= 1` PICKS A DIFFERENT SCRATCH REGISTER **(single observation — not yet cross-confirmed)** (P31 S58b) L24053 - **§254** — THE DEAD PARAMETER IS A REGISTER-PLACEMENT TOOL **(single observation — not yet cross-confirmed)** (P31 S58b) L24067 - **§215** — addendum (P31 S58b) — PIN ECONOMY, PART 2: NINE REFINEMENTS L24424 - **§223** — addendum (P31 S58b) — FIVE MORE CONFIRMATIONS, AND THE CONSTANT-IN-`$v0` CASE L24536 - **§263** — A STOLEN DELAY SLOT WHOSE INSTRUCTION IS AN ARG-REGISTER COPY IS AN ARITY ERROR, NOT A SCHEDULE (P31 S59, byte-proven) L24927 - **ADD-8** — → §245 addendum — THE RE-TIE BARRIER PINS CALL-ARG SETUP TO SOURCE ORDER (construct 6) L25203 - **§268** — A `register __asm__` PIN ON A CALL-CLOBBERED REGISTER IS HONORED EXACTLY WHEN THE PINNED RANGE CROSSES NO CALL (P31 S59c; three A/B'd cards, unifying §257-2's two) L25285 - **ADD-6** — → §220-addendum — THE FOURTH FACE: WHEN THE NAMED COPY ITSELF BUYS THE EXTRA CALLEE-SAVED, PIN THE COPY TO `$16` L25427 - **ADD-7** — → §229 addendum — THE VALUE FACE: A LOOP-STORE CONSTANT SPELLED AS A LITERAL HAS NO SOURCE POSITION; NAME IT TO PIN THE PROLOGUE INIT ORDER L25443 - **ADDENDUM** — to §82 — struct copies must stay MEMBER-WISE, not block-moved, to match a spill-slot save L25743 - **ADDENDUM** — to §136d-1 (RC-12, the `$0`-add / opaque-copy family) — two symptoms beyond "compare reads the wrong register" L25781 - **ADDENDUM** — to §164-64 — AN EMPTY CLOBBER ON AN ARGUMENT REGISTER CAN BE THE DELIBERATE FIX, NOT JUST THE ACCIDENTAL BUG L26038 - **§275** — THE LEFTOVER-REGISTER READ L26412 - **§NNN** — A DO-WHILE'S GUARD AND LATCH MUST REPEAT THE SAME BOUND EXPRESSION, NOT SHARE ONE LOCAL: THE REPETITION IS WHAT BUYS THE CSE'D COPY INTO A SECOND REGISTER (P31 S60; `func_8017F2A4`, ov_SC03_096, byte-proven 25/25) L26923 - **ADDENDUM** — to §176-B2 — in a micro-function with no long/short lifetime asymmetry, BOTH contending pseudos need their own hard-register pin L27364 - **ADDENDUM** — to §220 — REFERENCING THE RAW PARAMETER (NO NAMED COPY, NOT EVEN A PIN) LETS THE CALLEE-SAVED SPILL LAND IN THE FIRST CALL'S OWN DELAY SLOT L27480 - **ADDENDUM** — to §215 — FIFTH SHAPE: reused mask constants across two call-free merge sites each get their own whole-function hard-register pin, and a shared sub-expression at the second site must be its own statement L27565 - **ADDENDUM** — to §194-B (func_8017EB34, ov_SC03_117 — wave dk; distinct from the §74 co-pinning finding on the SAME function below) L27973 - **ADDENDUM** — §NNN — sharpens §162a3/§60b: A `sll $v0,16 / sltiu $v0,1` ZERO-TEST OF A JUST-DECREMENTED HALFWORD IS A SIGNED-TEMP WIDTH TELL OUTSIDE ANY SWITCH/RANGE-TEST CONTEXT L28293 - **§285** — PRE-INITIALIZING A VARIABLE WITH A SHARED CONSTANT BEFORE A BRANCH MAKES BOTH ARMS OF THE FOLLOWING if/else DESTRUCTIVELY REUSE THE SAME DESTINATION REGISTER FOR THEIR BITWISE RESULT (byte-proven; `func_801811F0`, ov_SC03_102, independently rediscovered across waves di/dj) (P31 S60; waves #, byte-proven) L29078 - **§287** — A STACK-FRAME HOLE BELOW TWO ADDRESS-TAKEN AGGREGATE LOCALS IS A LEADING PAD MEMBER OF ONE COMBINED STRUCT, NOT SEPARATE LOCALS OR A REGISTER PIN (P31 S60/dj; `func_8017D104`, ov_SC06_027, byte-proven 47/47) (P31 S60; waves #, byte-proven) L29086 - **§288** — A REGISTER PIN DECLARED UNINITIALIZED AND ASSIGNED ONLY AT ITS LATE, SOLE USE STILL FORCES THE FIXED REGISTER'S SAVE/RESTORE, AND THE ASSIGNMENT'S SOURCE POSITION CONTROLS WHERE THE VALUE MATERIALIZES (P31; `func_80186530`, ov_SC02_017, byte-proven, match_one MATCH re-verified) (P31 S60; waves #, byte-proven) L29090 - **§290** — A SINGLE STRENGTH-REDUCED GIV CAN DRIVE STORES TO SEVERAL DISTINCT RELOCATABLE SYMBOLS, EACH KEEPING ITS OWN `%hi`/`%lo` ANCHOR (P31 S60; waves #, byte-proven) L29098 - **ADDENDUM** — to §172b-1 (counter-type dial) — the sll's SOURCE REGISTER is the placement discriminator L29268 - **ADDENDUM** — to §282 — the ADDRESS-GIV face: write the walked address INLINE so strength reduction births the induction register at loop.c's own insertion point L29313 - **§310** — A TWO-OPERAND `subu`'s DESTINATION TIES ONLY TO THE OPERAND THAT IS BLOCK-LOCAL: SHARE *ONE* SIDE ACROSS BLOCKS TO CHOOSE WHICH OPERAND'S REGISTER IT LANDS IN (P31 S64 t5j-t5m; byte-proven func_8017F578) L30086 - **§312** — A BARE RELATIONAL IN AN `if` GIVES THE `slt` NO TARGET: ASSIGN THE COMPARISON INTO THE ALREADY-ALLOCATED VARIABLE TO CHOOSE ITS DESTINATION REGISTER, AT ZERO INSTRUCTION COST (P31 S64 t5o-t5r; byte-proven func_80180DCC) L30159 - **Addendum** — §312 addendum — naming the compare's dest is the vehicle, the hard-reg pin on that name is (func_80184A68) L30461 - **Addendum** — subu/sh dest reuses a pinned operand's dying register (func_8017F498) L30465 - **Addendum** — Addendum to §312 — the compare's named destination must itself carry a hard register: nami (func_80184A68) L30481 - **Addendum** — REGALLOC-PERM: one memory-clobber barrier insufficient — stack two (func_80182D1C) L30523 - **REFUTED** — claim — Dead call-arg register address-fold: no C-level lever found (func_8017ECAC) L30541 - **Addendum** — REGALLOC-PERM: the store reads the narrow copy's register — split the one narrow local by (func_801838CC) L30626 - **Addendum** — REGALLOC-PERM store in a cross-jump shared tail defeats §137's barrier (func_8017EDE8) L30630 - **§319** — N TEXTUALLY DUPLICATED `return v;` TAILS PUT THE LAST `or` AND THE RETURN-REGISTER MOVE IN ONE BASIC BLOCK, SO combine FOLDS THEM AND YOU ARE EXACTLY −1; A `goto done;` JOIN WITH REAL INCOMING EDGES RESTORES THE SEPARATE `addu $v0,$a0,$zero` (P31 S66 round4; byte-proven func_801809F0) L30671 - **Addendum** — LENGTH-DRIFT −1 on a coalesced-away copy: a CALLER-SAVED SOURCE pin can resurrect it, boun (func_8017D72C) L30714 - **Addendum** — The dying-pinned-register reuse on a sign-extend chain: route every later read through a s (func_80186868) L30743 - **Addendum** — Register-pinned helper pointer local regresses closeness; use plain local (func_80013CFC) L30757 - **§325** — REGALLOC: A SHARED SMALL CONSTANT STORED TWICE IN THE PRE-LOOP BLOCK IS A *local-alloc* $s-OCCUPANT THAT STEALS THE ARGUMENT ALLOCNO'S REGISTER — PIN THE ARGUMENT-DERIVED LOCAL, NOT THE CONSTANT (P31 S67; byte-proven ov_SC03_119/func_80184F18, 153 ins) L30987 - **§329** — fold-const NARROWS `(int)s16_var & 0xFFF` ONTO THE *RAW HImode PSEUDO*, BREAKING THE SIGN-EXTEND/MASK REGISTER TIE — A ZERO-BYTE WIDENING TEMP RESTORES IT (P31 S67; byte-proven ov_SC01_084/func_80183244, 157 ins) L31034 - **§334** — A RELOAD SPILL SLOT IS ROUNDED TO `BIGGEST_ALIGNMENT` (8B), SO ONE SPILLED 4-BYTE PSEUDO CAN GROW THE FRAME BY 16 (P31 S67; byte-proven ov_SC05_008/func_8017DF68, 82 -> 53 residual) L31129 - **§342** — A `void *` PARAMETER CAST TO ITS REAL TYPE IN A LOCAL IS **NOT** BYTE-NEUTRAL WHEN A LATER PARAMETER ALSO NEEDS A CALLEE-SAVED REGISTER (P31 S67; byte-proven ov_SC07_002/func_80181394, NEW LAW) L31257 - **§344** — RAISE A BIV'S global_alloc PRIORITY WITH A ZERO-BYTE REFERENCE INSTEAD OF PINNING IT; PINNING THE COUNTER KILLS LSR ENTIRELY (P31 S67; byte-proven ov_SC03_121/func_80180E64, 222 ins) L31296 - **§347** — LOOP REGISTER ASSIGNMENT IS A **DECLARATION-ORDER + LIVE-RANGE** DIAL: FIVE COMPOSABLE LEVERS, 178 -> 0 (P31 S67; byte-proven ov_SC06_029/func_8017EF34, 243 ins) L31342 - **§365** — PIN **BOTH** MASKS OR NEITHER (P31 S68; ov_SC01_000/func_8017E594, 357 ins) L31748 - **§368** — ★★★ — THE **RELOAD-REMAT CONSTANT**: REACH A REGISTER NO PIN CAN REACH (P31 S68; ov_SC03_105/func_80187A30, 339 ins, fable escalation closed 8 → 0 in ONE edit) L31792 - **§373** — ★★★ — THE **DEAD-RESET CSE-BREAKER**, THE PIN THAT BREAKS A sched2 ANTI-DEP, AND WHY AN `asm` CAN NEVER RAISE PRIORITY (P31 S68; byte-proven ov_SC06_010/func_8017E764, 438 ins, fable escalation closed 8 → 0) L31977 - **§3-2.** — A REGISTER PIN THAT DELETES A sched2 ANTI-DEPENDENCE L31997 - **§374** — A `register … __asm__("$30")` RESERVATION IS **NOT HONOURED** BY `move_movables` (P31 S68; main/func_80015608, 86 ins) L32026 - **§375** — AN `$a0`-`$a3` PIN USED LATE RELOCATES AN **EARLIER** OUTGOING-CALL USE OF THAT REGISTER (P31 S68; main/func_8005F0C8, 88 ins) L32042 - **§3-C.** — REGISTER ALLOCATION FROM C, WITHOUT PINS L33124 - **§410** — ★★★ — COPY THEN ACCUMULATE ON THE COPY: resolving the birthing-boost vs register-allocation dilemma (P31 S71; byte-proven `ov_SC04_015/func_8017EB78`, 98 ins) L33353 - **§417** — ★★★ — A REGISTER PIN CAN BLOCK `jump.c`'s SELECT COLLAPSE, AND UNPINNING THEN EXPOSES A `cse` SKIP-BLOCKS MERGE (P31 S71; byte-proven `ov_SC03_013/func_8017E6F4`, 182 ins) L33605 - **§419** — ★★★ — WHEN A PIN IS IMPOSSIBLE, WIN THE local-alloc DENSITY CONTEST INSTEAD (P31 S71; byte-proven `ov_SC01_000/func_8017DD04`, 297 ins) L33658 ### CSE / redundancy / rematerialization (45) - **§46** — The `func_80178D40` crack (890 ins ×134, the heaviest core in the game): four LOOP-STRUCTURE levers cheap-Opus found by reading loop.c/jump.c/cse.c (Phase 26 session 8, 2026-07-13) L3347 - **§83d** — CSE's quantity budget is WHOLE-FUNCTION, so a local rewrite cannot fix a local symptom L6486 - **§153** — THE ADDRESS-REMATERIALISATION LAUNDER: a third zero-emission asm lever (P30 S43, `func_8018D98C`, 710 ins) L10500 - **§176-D** — CSE-class levers used in reverse (two sharpenings of §153 and cse_expr §2) L17776 - **§193-E** — A varying-address (pointer) load is re-emitted once per CSE-LIVE INTERVAL, and naming it in a C local is the only C-level lever over that count — no store SPELLING has any reach L18693 - **§193-F** — §148-A2 — The `threshold -= 3` STAIRCASE: `move_movables` admits a COUNT of invariants, not a boolean — two identical merged constants split hoisted/not-hoisted by LIST ORDER, and `insn_count` picks the rank cutoff L18723 - **§193-H** — A pointer-derived base load `*(s32*)(p+K)` is uncacheable across ANY memory write or call (cse's third kill disjunct) — so the target emits one `lw` per store-separated RUN of spellings, and a run of stores sharing one `lw` is a C local you must declare L18848 - **§194-A** — A zero-byte scheduling fence goes AFTER the defining statement to make that computation emit FIRST in its block — and the barrier predicate is `volatile`-or-colon-less, not the `"memory"` clobber (COMPLEMENTS §165-40; does not refute it) L18991 - **§194-J** — Back-to-back identical stores: flow.c's `last_mem_set` deletes the first, and only `volatile` saves it L19433 - **§194-K** — Blind sched1's alias oracle with a second SET of a pointer pseudo — the first zero-byte, non-volatile, dependence-CREATING lever (corrects §167-05's "volatile is the only door"; fourth consumer of reg_n_sets) L19485 - **§195-H** — §165-27g — ON A FIXED-SYMBOL GLOBAL, `extern T D[];` + `D[0]` IS THE CSE RELOAD DIAL, AT ZERO ADDRESSING COST, AND THE ELEMENT COUNT IS INERT (§165-27's `T v[2]` CAVEAT IS A LOCAL-FRAME FACT AND DOES NOT TRANSFER) L20151 - **§195-I** — §145(b) AMENDED — the pointer-bump `addiu` is saved by cse, not combine: ANY second SET of a pseudo in the address's equivalence chain (in-place `p += K`, §145(b)'s `p = r;` copy, or an asm re-tie) kills the fold; the pass is cse and the gate is `invalidate`'s `reg_tick++` L20198 - **§195-L** — The cse store-re-seed does not cross a JOIN LABEL: per-arm stores + a join read keep the reload that one join store deletes (bounds §193-E BOUND 1/BOUND 3 with §48-B's EBB boundary) L20359 - **§197-A** — A NARROW SIGNED MEMORY READ FEEDING A CONSTANT `>>` LOSES ITS `lh`, AND THE CURE IS AN ASM RE-TIE (attribution CONTESTED: cse vs combine) L20622 - **§197-B** — A REPEATED COMPARE OF ONE VALUE AGAINST ONE CONSTANT IS DELETED BY cse's `qty_comparison_code` CHANNEL (the non-EQ complement of §165-03) — and a front-end-opaque mask on EITHER compare is a pure-C dial that keeps the target's second branch L20660 - **§199-D** — A narrow UNSIGNED value compared in an ordered `if` emits `sltiu`/`sltu`; the only dial is the WIDTH of a real object, and a widening `(s32)` cast is inert — AMENDS §35 (whose stated "only CSE-reuse canonicalizes" mechanism is byte-wrong) and does NOT apply inside a `switch` L20901 - **§201-E** — §194-J-2 — The `last_mem_set` deletion window is measured in SOURCE/expand order, not in the printed stream; a foreign store moved between the pair in C source is a real lever, and `volatile` is not always the better one L21409 - **§204-D** — A LOOP-INVARIANT LOAD IS ADMITTED AS A MOVABLE ONLY IF ITS ADDRESS CANNOT TRAP: `local.field` PASSES, THE SAME READ THROUGH A POINTER LOCAL IS REFUSED L21804 - **§243** — SPELL THE CSE BARRIER AS A REASSIGNED POINTER; AND THE `nop`-AFTER-EVERY-`lh` SIGNATURE (P31 S58b) L23721 - **§244** — `volatile` IS A COUNTING INSTRUMENT, A STORE-ORDER PIN, AND MUST SOMETIMES BE ASYMMETRIC (P31 S58b) L23751 - **ADD-1** — → §257-8 addendum — THE INTERPOSED ASM'S `__volatile__` IS A PER-SHAPE DIAL, AND THE "NO-OUTPUT ASM IS IMPLICITLY VOLATILE" LORE IS BYTE-FALSE IN gcc-2.7.2 L25354 - **ADDENDUM** — to §244 — THE COMPILER BARRIER, NOT `volatile`, BLOCKS A STORE→LOAD HOIST THROUGH A POINTER-OFFSET FIELD L26069 - **ADDENDUM** — to §211 — AN IN-LOOP ACCUMULATOR WANTS A CLOSED-FORM EXPRESSION WHEN THE TARGET REMATERIALISES ITS CONSTANT AFTER EVERY CALL L26377 - **§276** — MIXED ADDRESS-EXPRESSION SPELLING FOR ADJACENT RELOCATABLE SYMBOLS IS A CSE-UNIFICATION DIAL, NOT JUST A BYTE-ENCODING CHOICE (P31 S60; `func_80180FE8`, ov_SC06_006, byte-proven) L26452 - **§NNN** — A DO-WHILE'S GUARD AND LATCH MUST REPEAT THE SAME BOUND EXPRESSION, NOT SHARE ONE LOCAL: THE REPETITION IS WHAT BUYS THE CSE'D COPY INTO A SECOND REGISTER (P31 S60; `func_8017F2A4`, ov_SC03_096, byte-proven 25/25) L26923 - **ADDENDUM** — to §22 (`volatile`-qualified-global reload lever, cookbook ~L1922) — for a NON-constant, same-address double RMW, a plain memory clobber beats `volatile`, and `volatile` actively breaks a delay-slot fill L27226 - **§302** — A RED BINARY IS A DRIFTED SPEC, NOT A MYSTERY: THE THREE CARVE-STATE INVARIANTS AND HOW TO DERIVE EACH FROM THE BYTES (P31 S62 T2; five reds healed in one session, 5/5, +39 held banks) L29719 - **§308** — A NAIVE FINAL `goto` DELETES THE TARGET'S `j`+`nop`: SPELL THAT EDGE AS A TAUTOLOGICAL `if` SO cse FOLDS IT TO AN UNCONDITIONAL JUMP *AFTER* jump1's WINDOW HAS CLOSED (P31 S63 t5e-t5i; byte-proven func_80180808) L29983 - **§317** — A NARROW STRUCT-FIELD STORE TURNS A *LIVE SImode VARIABLE* INTO A `li`: convert.c's TRUNCATION-DISTRIBUTION MINTS A HImode COPY, AND cse REWRITES THAT COPY'S SOURCE TO THE EQUIVALENT CONSTANT (P31 S66; byte-proven func_8017EF94) L30344 - **Addendum** — Addendum to §167-12 — the single-operand volatile keepalive, re-confirmed at a gated MATCH (func_8017F498) L30485 - **REFUTED** — claim — REFUTED — the `j`-slot store is an ASPSX macro-expansion hop, not a cse split; maspsx hard (func_8005DBD8) L30589 - **§NNN** — REFUTED: A `sw %lo(SYM)($at)` IN A JUMP'S DELAY SLOT WITH ITS `lui $at` STRANDED ABOVE THE JUMP IS **ASSEMBLER** MACRO-EXPANSION, NOT A cse SPLIT — OUR PIPELINE CANNOT EMIT IT FROM ANY C, AND THE +1 IS A `maspsx` GAP (P31 S66 round2, `func_8005DBD8`, byte-probed) L30591 - **Addendum** — Volatile zero-byte asm slider scrambles the prologue schedule (func_801814B0) L30747 - **§326** — DEFEATING ADDRESS-CSE: SPELL TWO READS OF THE SAME HALFWORD DIFFERENTLY AND GCC CANNOT SHARE THE ADDRESS (P31 S67; byte-proven ov_SC01_077/func_8017FAAC, 154 ins) L31000 - **§327** — A RANGE TEST MUST BE HImode: WITH `s32` + A `(u16)` CAST GCC *PROVES* THE MASK REDUNDANT AND DROPS THE `andi` (P31 S67; byte-proven ov_SC02_039/func_8017EC34, 154 ins) L31009 - **§328** — THE VOLATILE ALIAS MUST BE AN *OBJECT*, NOT A CAST: `*(volatile s32*)&sym` UNFOLDS %lo INTO A SEPARATE `addiu` (P31 S67; byte-proven ov_SC07_007/func_80181B8C, 156 ins, NEW LAW) L31024 - **§345** — A VOLATILE **STORE** EVICTS THE MEM FROM cse AND KEEPS `sh`; A VOLATILE **LOAD** BLOCKS combine AND DEGRADES `lh` INTO `lhu+sll+sra` (P31 S67; byte-proven ov_SC01_084/func_80181A7C) L31312 - **§349** — RE-ASSIGN A BASE POINTER AT THE END OF THE LOOP BODY TO MAKE `n_times_set > 1` — THAT KILLS BOTH loop.c's INVARIANT HOIST **AND** THE ADDRESS GIV, REPRODUCING A REMATERIALISED `addiu $aN,$sp,K` (P31 S67; byte-proven ov_SC06_029/func_801804C8, 255 ins) L31414 - **§351** — `/s` (MEM_IN_STRUCT_P) IS A DIAL YOU CHOOSE PER ACCESS: A COMPONENT_REF GRANTS IT AND LETS cse KEEP AN INDEX ACROSS THE STORE; A PLAIN CAST DENIES IT (P31 S67; ov_SC01_000/func_8017DD04, 186 -> 5) L31456 - **§352** — ⚠ TWO IDENTICAL `__asm__ __volatile__("")` BARRIERS **MERGE WITH EACH OTHER** — SPELL THE SECOND ONE DIFFERENTLY (P31 S67; byte-proven resident/func_800D128C, measured closeness 105 when they merged) L31486 - **§368** — ★★★ — THE **RELOAD-REMAT CONSTANT**: REACH A REGISTER NO PIN CAN REACH (P31 S68; ov_SC03_105/func_80187A30, 339 ins, fable escalation closed 8 → 0 in ONE edit) L31792 - **§373** — ★★★ — THE **DEAD-RESET CSE-BREAKER**, THE PIN THAT BREAKS A sched2 ANTI-DEP, AND WHY AN `asm` CAN NEVER RAISE PRIORITY (P31 S68; byte-proven ov_SC06_010/func_8017E764, 438 ins, fable escalation closed 8 → 0) L31977 - **§3-1.** — DEAD-RESET CSE-BREAKER — the zero-footprint replacement for a §195-I asm re-tie L31979 - **§385** — ★★★ — THE **SCHED2 PRIORITY-DONOR ASM**: closing the "hoisted-invariant vs IV-init preheader swap" class (P31 S69; byte-proven main/func_80038A58, 347 ins, fable escalation 2 → 0) L32309 - **§417** — ★★★ — A REGISTER PIN CAN BLOCK `jump.c`'s SELECT COLLAPSE, AND UNPINNING THEN EXPOSES A `cse` SKIP-BLOCKS MERGE (P31 S71; byte-proven `ov_SC03_013/func_8017E6F4`, 182 ins) L33605 ### loops & induction variables (48) - **§3-T1** — Loop pointer: top-of-body for `addu` induction, not constant-folded `addiu` L71 - **§34** — The `func_80138ED0` giant crack: gcc-2.7.2's **3-qty sort bug** + the **zero-byte asm allocation toolkit** + the **giv-init fence** (Phase 24 T5; Opus→close=21, Fable5→MATCH ×134) L2473 - **§35** — The region-a sibling-giant harvest: difficulty ≠ $s-reg count (it's global-array hoisting) + the banking recipe + new loop idioms (Phase 24 T7, 5 parallel Opus-Max agents) L2490 - **§46** — The `func_80178D40` crack (890 ins ×134, the heaviest core in the game): four LOOP-STRUCTURE levers cheap-Opus found by reading loop.c/jump.c/cse.c (Phase 26 session 8, 2026-07-13) L3347 - **§66d** — The permuter⇄reader loop: alternate a random search with a byte-verified idiom, and let `residual_class` decide whose turn it is (Phase 29 SESSION-17) L5279 - **§66d-1** — What transfers between giants is the LOOP, not the PIN L5314 - **§70** — The giv-init base register: walk the PARAMETER, not a copy of it (Phase 29 SESSION-18, `func_801777BC`) L5653 - **§145** — Three loop/combine levers from the S40 wave-2 drafters (16/16 match_one) L9961 - **§148** — The loop.c hoisting THRESHOLD is arithmetic you can compute, and the `?:` clamp that folds to MIN_EXPR (P30 S42, `func_8017C6F4`, 947 ins) L10179 - **§171a** — THE MECHANICAL A-PROP DRAFT (P30 S50): 256 members banked with no agent in the loop L16474 - **§179-A** — 🔴 A LOOP-WALKED POINTER **PARAMETER** HANDS ITS ARGUMENT REGISTER TO THE GIV (9 byte-proofs) L17377 - **§179-E** — A `>2*MAX_MOVE_BYTES` BLOCK COPY IS A **STRUCT ASSIGNMENT**, NOT A HAND LOOP L17547 - **§179-F** — PINNING A LOOP-WALKED POINTER IS A TOTAL OFF-SWITCH FOR STRENGTH REDUCTION L17573 - **§194-C** — A CALLER-SAVED loop counter proves its live range crosses ZERO calls — so it cannot share a pseudo with any value LIVE ACROSS a call (but it may freely share one with values that merely sit between calls) L19095 - **§204-B** — A LOOP COUNT THAT ARRIVES ON THE STACK IS DECREMENTED IN PLACE: a fresh counter local can cost a real `move` AND permute the whole callee-saved file L21682 - **§204-D** — A LOOP-INVARIANT LOAD IS ADMITTED AS A MOVABLE ONLY IF ITS ADDRESS CANNOT TRAP: `local.field` PASSES, THE SAME READ THROUGH A POINTER LOCAL IS REFUSED L21804 - **§211** — HOIST THE LOOP INIT ABOVE THE DOMINATING GUARD: it fills the guard's delay slot AND flips the counter/pointer register pair (P31 S58) L22415 - **§246** — THREE-LIVE-VALUE SCAN LOOPS WANT ADDRESS-FROM-INDEX; AND TWO SYMBOLS CAN SHARE ONE giv (P31 S58b) L23833 - **ADD-7** — → §229 addendum — THE VALUE FACE: A LOOP-STORE CONSTANT SPELLED AS A LITERAL HAS NO SOURCE POSITION; NAME IT TO PIN THE PROLOGUE INIT ORDER L25443 - **ADD-8** — → §30a addendum — THE THIRD COLUMN: `*p++` IS ALSO SERIALIZED BUT BURNS `addiu`; ONLY CAST-PLUS GIVES SERIALIZATION *AND* DISPLACEMENT FOLDING L25456 - **ADDENDUM** — to §172b-1 — TWO PLACEMENT DIALS THE PROMOTION LAW DOESN'T NAME: NARROW THE COUNTER'S DECLARED TYPE, AND MOVE THE CAST INTO THE LOOP BODY L26100 - **ADDENDUM** — to §211 — AN IN-LOOP ACCUMULATOR WANTS A CLOSED-FORM EXPRESSION WHEN THE TARGET REMATERIALISES ITS CONSTANT AFTER EVERY CALL L26377 - **§279** — A `do/while (p < end)` LOOP UNDER AN ENTRY GUARD: the guard decides the compare, not the loop (P31 S60; wave cf, func_8017F2A4, ov_SC03_096, byte-proven) L26922 - **§NNN** — A DO-WHILE'S GUARD AND LATCH MUST REPEAT THE SAME BOUND EXPRESSION, NOT SHARE ONE LOCAL: THE REPETITION IS WHAT BUYS THE CSE'D COPY INTO A SECOND REGISTER (P31 S60; `func_8017F2A4`, ov_SC03_096, byte-proven 25/25) L26923 - **§NNN** — A LOOP CURSOR'S C TYPE (POINTER vs PLAIN INTEGER) SELECTS `sltu` vs `slt` FOR ITS BOUND TEST, INDEPENDENT OF THE VALUES INVOLVED (P31 S60; `func_800CAE74`, md_MAIN_031, byte-proven; cross-confirmed same wave by `func_8017F2A4`, ov_SC03_096) L26957 - **§282** — gcc's OWN LOOP REVERSAL PUTS THE COUNTER INIT AFTER THE HOISTED MOVABLES — a position no hand-written down-count can reach (P31 S60; wave cf, func_80180DD8, ov_SC04_005, byte-proven) L27036 - **§NNN** — WRITE THE UP-COUNT LOOP: gcc's OWN REVERSAL PRODUCES A COUNTER-INIT INSTRUCTION THAT LANDS AFTER HOISTED MOVABLES, WHICH A HAND-WRITTEN DOWN-COUNT LOOP CANNOT REPRODUCE (P31 S60; `func_80180DD8`, ov_SC04_005, byte-proven) L27037 - **§290** — A SINGLE STRENGTH-REDUCED GIV CAN DRIVE STORES TO SEVERAL DISTINCT RELOCATABLE SYMBOLS, EACH KEEPING ITS OWN `%hi`/`%lo` ANCHOR (P31 S60; waves #, byte-proven) L29098 - **ADDENDUM** — to §282 — the ADDRESS-GIV face: write the walked address INLINE so strength reduction births the induction register at loop.c's own insertion point L29313 - **ADDENDUM** — to the L1800 anchor-steer bullet — a DERIVED-POINTER local silently flips the merged giv's anchor END L29357 - **§297** — ONE GIV SERVING MIXED-WIDTH LOADS *AND* A STORE NEEDS STRUCT-MEMBER SPELLING; CAST/INDEX SPELLINGS RE-SPLIT THE PSEUDO (P31 S61; wave m0a, `func_800347C8`, main, byte-proven 31/31) L29499 - **§312** — A BARE RELATIONAL IN AN `if` GIVES THE `slt` NO TARGET: ASSIGN THE COMPARISON INTO THE ALREADY-ALLOCATED VARIABLE TO CHOOSE ITS DESTINATION REGISTER, AT ZERO INSTRUCTION COST (P31 S64 t5o-t5r; byte-proven func_80180DCC) L30159 - **Addendum** — Loop sentinel wrongly hoisted out of a call-containing loop (func_801835B0) L30493 - **§325** — REGALLOC: A SHARED SMALL CONSTANT STORED TWICE IN THE PRE-LOOP BLOCK IS A *local-alloc* $s-OCCUPANT THAT STEALS THE ARGUMENT ALLOCNO'S REGISTER — PIN THE ARGUMENT-DERIVED LOCAL, NOT THE CONSTANT (P31 S67; byte-proven ov_SC03_119/func_80184F18, 153 ins) L30987 - **§344** — RAISE A BIV'S global_alloc PRIORITY WITH A ZERO-BYTE REFERENCE INSTEAD OF PINNING IT; PINNING THE COUNTER KILLS LSR ENTIRELY (P31 S67; byte-proven ov_SC03_121/func_80180E64, 222 ins) L31296 - **§346** — `c ? X : -X` TAKES expand_expr's COND_EXPR **SINGLETON** PATH (copy, then negate IN PLACE) — AN if/else STATEMENT GIVES THE TWO-ARM FORM (P31 S67; byte-proven ov_SC03_102/func_80180C38, closed the last instruction) L31322 - **§347** — LOOP REGISTER ASSIGNMENT IS A **DECLARATION-ORDER + LIVE-RANGE** DIAL: FIVE COMPOSABLE LEVERS, 178 -> 0 (P31 S67; byte-proven ov_SC06_029/func_8017EF34, 243 ins) L31342 - **§348** — THE BASE SPELLING PICKS THE ADDRESSING MODE: A SYMBOL GIVES THE 3-INSN `lui/%lo` FORM, A POINTER VARIABLE GIVES THE 2-INSN `addu/lw` FORM (P31 S67; byte-proven ov_SC07_007/func_80182184, 264 -> 30 on this row alone) L31397 - **§349** — RE-ASSIGN A BASE POINTER AT THE END OF THE LOOP BODY TO MAKE `n_times_set > 1` — THAT KILLS BOTH loop.c's INVARIANT HOIST **AND** THE ADDRESS GIV, REPRODUCING A REMATERIALISED `addiu $aN,$sp,K` (P31 S67; byte-proven ov_SC06_029/func_801804C8, 255 ins) L31414 - **§354** — THE giv **WORTH-WHILE TEST** IS A DIAL: RE-ASSOCIATE THE ADDEND INTO THE INDEX TERM AND `strength_reduce` DECLINES (P31 S68; byte-proven ov_SC03_105/func_801824CC, 320 ins, 201 → 5 → 0) L31542 - **§357** — ONE STRUCT POINTER, NOT TWO: A SECOND SOURCE VARIABLE BUILDS A THIRD IV (P31 S68; byte-proven ov_SC06_029/func_80181DF8, 335 ins, 330 → 13) L31589 - **§361** — ★ — A LOOP-TAIL BYTE SIGNATURE THAT NAMES ITS SOURCE SHAPE — AND THE LAW THAT A "SCHEDULING TIE" MAY BE YOUR OWN EARLIER LEVER (P31 S68; byte-proven main/func_800241C0, fable escalation, 19 → 0 in 3 iterations) L31637 - **§366** — ★★ — `group_case_nodes` MERGES **STACKED CONSECUTIVE** CASE LABELS: GIVE EVERY CASE ITS OWN BODY (P31 S68; ov_SC01_001/func_8017EC28, **first-try MATCH 360/360**, 96/96 relocs audited) L31757 - **§385** — ★★★ — THE **SCHED2 PRIORITY-DONOR ASM**: closing the "hoisted-invariant vs IV-init preheader swap" class (P31 S69; byte-proven main/func_80038A58, 347 ins, fable escalation 2 → 0) L32309 - **§386** — ★★★ — A BYTE LOAD ON THE **BIV** BASE WAS BORN IN THE COMBINE PASS: SPELL IT AS A SHIFT-MASK, NEVER A DEREF (P31 S69; byte-proven main/func_80020598, 292 ins, escalation 1 → 0) L32335 - **§393** — ★★ — THE **BIRTHING BOOST**: A SINGLE-SET LOCAL IS SCHEDULED LAST; GIVE IT A SECOND SET (P31 S69; byte-proven ov_SC02_017/func_8017FCFC) L32543 - **§418** — ★★★ — TWO LOOP-STRUCTURE LEVERS: MAKE THE SECOND INDEX A GIV, AND KEEP A TABLE ADDRESS UNFOLDED (P31 S71; byte-proven `ov_SC04_016/func_8017DF8C`, 184 ins, 32 → 0 in seven compiles) L33632 - **§430** — ★★★ — A SHARED TAIL IS A LATE CROSS-JUMP MERGE, NOT A SOURCE `goto` — AND SPELLING IT AS ONE CAN INVALIDATE A LOOP (P31 S72; `main/CdReadSectorReadyCB`, 422/424 ins, verified with `cc1 -dL`) L34023 ### structs, block moves & memcpy (88) - **§3-T2** — Source statement order drives instruction scheduling L78 - **§5** — Known hard-residual classes (instruction-identical, one byte-exact blocker) L199 - **§13** — Add a location overlay — the canonical runbook (Phase 13; the Phase-15 fleet recipe) L1075 - **§15** — Struct-heavy shared-core pipeline (Phase 16) — empirical determinations (S0) L1332 - **§16** — Guided hand-matching the struct-heavy core (Phase 17 — beats the §15 brute-force) L1354 - **§3-The** — crack: the residual was gcc-2.7.2 COPY-COALESCING, not the instruction scheduler L2163 - **§28** — Banking a "close=0 gate-rejected" giant: the canonical-extern recovery (Phase 22 T1, byte-proven on func_8015126C ×134) L2344 - **§28b** — The struct-walled close=0 giant (§28 case #3) IS bankable: the engine_types.h type-lift (Phase 22 T2, byte-proven on func_80156B74 ×134) L2376 - **§30** — Fable5Max cracks §20/§10 "unsteerable" from the gcc SOURCE: store-vs-load is a `/s` aliasing flag, the def-side wall has a macro escape, + the birthing-boost (Phase 23, byte-proven on giant `func_8014EE14` 248 ins ×134) L2401 - **§32** — The region-a CAMERA-GIANT idiom set: struct-base hoisting + 4 sibling levers (Phase 24 T7, Fable5-cracked on `func_80129CF8` 191 ins, match_one MATCH; transferable to the 6 sibling giants) L2441 - **§38** — The WHALE `func_80144B9C` (770 ins): the -O0 struct-assign memcpy idiom + the -O0 reach-134 ×134 rollout (Phase 24 T7 §G, cheap Opus — no Fable5, no calls.c) L2546 - **§40** — Structural families: the MECHANICAL symbol-remap (crack one exemplar → remap the rest, ~0 tokens) (Phase 25 T3/T7, 2026-07-08) L2572 - **§41** — The DEF-SIDE canonical-sig wall: mechanically banking a drafted giant past `conflicting types` (Phase 25 T5b batch-2, 2026-07-09; `tools/canon_sig_reconcile.py`, byte-proven on `func_8013B274`) L2729 - **§42a** — addendum — wave 2 (residuals + 29-100 band): iso-MATCH ≠ real-TU bank, the memcpy→struct-assign fix, +5 levers (2026-07-10b) L2987 - **§44** — The Phase-25 cheap-Opus giant batch: 5 structural levers + the §43 extension (2026-07-11, 6 crackers over the frontier giants) L3276 - **§46** — The `func_80178D40` crack (890 ins ×134, the heaviest core in the game): four LOOP-STRUCTURE levers cheap-Opus found by reading loop.c/jump.c/cse.c (Phase 26 session 8, 2026-07-13) L3347 - **§3-Why** — 0/8 was structural, and predictable from two words L4079 - **§54** — `--fix-def-sig`: the member's CANONICAL DECLARATION is a build step too (tiny-IMM mega-pools, +4,801, Phase 29 T6, 2026-07-16) L4197 - **§56b** — PROPAGATING an h_seq giant: the exemplar's externs MUST be fleet-canonical, not the draft's types L4266 - **§65a** — The blast-radius taxonomy (makes §61's law structural instead of remembered) L5064 - **§66d-5** — `residual_class`'s "structural ⇒ permuter CPU is waste" is WRONG for schedule permutations (measured, Phase 29 SESSION-18) L5525 - **§83** — The parameterised-repeat law, the spill-area trap, and why a per-case edit cannot move a per-case symptom (Phase 29 SESSION-20, `func_80183814` 5,122 ins, cold-ish start → 36 structural / 99.3%) L6446 - **§84** — The DERIVED-OFFSET remap bug: a hand-computed literal that encodes the DISTANCE between two per-overlay symbols, and why `match_one` is structurally blind to it (Phase 29 SESSION-20, `func_8013D53C`) L6506 - **§3-The** — construct L6511 - **§91** — A structure-TRANSFER is only valid where the structure corresponds: the `--like` role trap (Phase 29 SESSION-21, `func_8012AAAC` ×137) L6876 - **§3-The** — three-hypothesis trail, because two of them were wrong and the wrongness is instructive L6905 - **§129** — Post-carve, `rtu_match`/`match_one` COUNT THE JUMP TABLE AS INSTRUCTIONS; and a carve must never be committed without its owner (P30 S28, `func_8013BD74`) L8471 - **§129a** — the target instruction count is INFLATED after a carve L8475 - **§3-The** — DEFINITION-side alias is the only escape when the fleet canon disagrees on a promoting param L9507 - **§3-Two** — errors of mine, both instructive L10043 - **§160** — THE REACH-15 WAVE HARVEST: an align-1 block move, and the instrument that called it a wall (P30 S47) L10927 - **§16Xy** — SHARPENS *(sharpens §136d-3, §37 /s-DEP LATTICE, §135-2, §136-13, §162q)* L12334 - **§3-The** — `/s` drop clause is in ALL THREE dependence predicates, so the FIXED-ADDRESS STORE is what floats (P30 S48, `func_8017CA18`, ov_MAIN_012) L12336 - **§16Z** — SHARPENS *(sharpens §37 "the /s-DEP LATTICE", §136-13, §136-14, §16Xy, §162q, `gcc-2.7.2-map/sched.md` §64)* L14394 - **§3-The** — ADDRESS-CLASS TABLE: which load/store pairs even REACH the `/s` clause (P30 S48 wave 4, `func_80185B44`, ov_SC03_014) L14396 - **§176g** — SIZE A WAVE BY INSTRUCTIONS, NOT BY CARDS (P31 S52 — the adopted doctrine) L16994 - **§3-F.** — `MEM_IN_STRUCT_P` ASYMMETRY IN `true_dependence` (func_80037144, 124 ins) L17345 - **§179-E** — A `>2*MAX_MOVE_BYTES` BLOCK COPY IS A **STRUCT ASSIGNMENT**, NOT A HAND LOOP L17547 - **§176-B** — "REGALLOC-PERM, 1-4 instructions off" ⇒ it is usually NOT register allocation L17704 - **§189** — FIVE COMPILER LAWS MINED FROM THE WAVE R/S JOURNALS (P31 S53), each source-cited and re-derived by a second agent L18267 - **§193-A** — The wave card ships only OPEN-set pointers and discards the atlas's BANKED one — `exemplar`/`sibs` are stubs 100% by construction (tools/atlas.py:96/657), while `seed.ref` (matched pool, atlas.py:505-536) is dropped at build_wave_atlas.py:143 L18483 - **§193-B** — A NARROW CAST OF A WIDE PARAMETER COSTS ONE EXTRA INSTRUCTION WHEN ITS STATEMENT SITS AFTER AN INTERVENING `jal` — AND THE DECIDER IS `combine.c:929`'s CROSS-CALL GUARD, NOT REGISTER ALLOCATION L18550 - **§193-I** — A DECLARED AGGREGATE LOCAL HAS AN 8-BYTE FRAME STRIDE — CEIL(size,8), NOT size. N ARRAYS THEREFORE COST 8·k MORE THAN ONE HAND-LAID STRUCT (k = how many of them have size mod 8 ≠ 0), AND THE TELL IS IDENTICAL INSTRUCTION COUNT WITH EVERY $sp DISPLACEMENT SHIFTED BY THE SAME CONSTANT. L18888 - **§194-E** — The wave card's `exemplar` is the TARGET ITSELF on 42/73 wave-U and 36/71 wave-T cards — a construction consequence of `atlas.py:657` (exemplar = max-nins OPEN member) meeting `build_wave_atlas.py:166` (one card per gid); and the shipped §193-A `seed_ref` is same-binary on 0/51, so no card field can ever name a destination-TU sibling L19199 - **§194-H** — §164-29's WAR fence runs again at SCHED2 ON HARD REGISTERS: an in-place `v &= K` before a branch fences the store that reads v, and when TWO independent stores compete for the one delay slot the fence picks the winner at ZERO length drift (a WIDTH/sh!=sw swap, not a nop). Corrects §167-42's reconstruction (pseudo arm → hard-reg arm) and supplies its first re-runnable A/B. L19352 - **§195-D** — §195 — `masked_diff.mask_for` returns 0 for EVERY `j`/`jal` word, so an internal `j` destination is invisible to match_one, the permuter scorer AND every similarity tier: a control-flow semantic error (which calls execute) surfaces as a 1-instruction residual mislabelled `DELAY-SLOT / profile=schedule`, or as an outright false MATCH L19925 - **§195-F** — fold-const.c:4825 canonicalises a `?:` whose THEN arm is zero (or constant against a non-constant ELSE) by inverting the condition and swapping the arms — so a ternary's written arm order is byte-inert there, and `c ? 0 : X` is unspellable: it always compiles as `!c ? X : 0` L20051 - **§195-G** — §NEW — TWO ARMS CALLING THE SAME CALLEE MERGE INTO ONE `jal` UNLESS EACH ARM'S OWN CODE CONSUMES THE RESULT: the C dial that keeps two call sites apart is WHERE the consumer test lives, and the branch SENSE you spell it with is byte-inert (jump.c:1737 canonicalises it) L20103 - **§195-K** — At -O2 the §18 array-of-struct lever is a FRAME lever, not a length lever — but only when the N reads carry DISTINCT index expressions; with a SHARED index §18's +2-instruction residual is still alive at -O2 (the submitted "memory-loaded narrow index" precondition and unconditional length-neutrality are both falsified) L20307 - **§199-D** — A narrow UNSIGNED value compared in an ordered `if` emits `sltiu`/`sltu`; the only dial is the WIDTH of a real object, and a widening `(s32)` cast is inert — AMENDS §35 (whose stated "only CSE-reuse canonicalizes" mechanism is byte-wrong) and does NOT apply inside a `switch` L20901 - **§199-F** — §164-36b — THE TARGET-HEAD FENCE IS A DELAY-SLOT THREAD SELECTOR, AND IT ONLY FIRES WHEN `mostly_true_jump > 0` (amendment to §164-36; its "−1 instruction" tell is falsified) L21020 - **§204-D** — A LOOP-INVARIANT LOAD IS ADMITTED AS A MOVABLE ONLY IF ITS ADDRESS CANNOT TRAP: `local.field` PASSES, THE SAME READ THROUGH A POINTER LOCAL IS REFUSED L21804 - **§225** — THREE CONTROL-FLOW SHAPES NO STRUCTURED SPELLING REACHES (P31 S58) L22975 - **§30** — addendum (P31 S58) — the `/s` grant closes a SCHEDULING residual and a REGISTER residual with one edit L23257 - **§249** — THE SELF-ASSIGN, THE DEAD RE-ASSIGN, AND THE `+ zr` COPY: THREE WAYS TO MAKE A DELETED INSTRUCTION REAL (P31 S58b) L23931 - **§30** — addendum (P31 S58b) — THE ANONYMOUS STRUCT MEMBER REF GRANTS `/s`, AND THAT IS A TWO-FOR-ONE L24199 - **§263** — A STOLEN DELAY SLOT WHOSE INSTRUCTION IS AN ARG-REGISTER COPY IS AN ARITY ERROR, NOT A SCHEDULE (P31 S59, byte-proven) L24927 - **ADD-8** — → §245 addendum — THE RE-TIE BARRIER PINS CALL-ARG SETUP TO SOURCE ORDER (construct 6) L25203 - **ADD-11** — → Cross-confirmation card block (per §259's standing instruction: confirmation, not news) L25234 - **ADD-4** — → §167-37 addendum — THE FIFTH PRECONDITION, NOW MEASURED: DOWNSTREAM FIELD RE-READS ⇒ NAME IT **AND** STORE **INSIDE** THE ARM L25394 - **ADD-10** — → Cross-confirmation card block (per §259's standing instruction: confirmation, not news) L25485 - **ADDENDUM** — to §82 — struct copies must stay MEMBER-WISE, not block-moved, to match a spill-slot save L25743 - **ADDENDUM** — to §244 — THE COMPILER BARRIER, NOT `volatile`, BLOCKS A STORE→LOAD HOIST THROUGH A POINTER-OFFSET FIELD L26069 - **§281** — GROUP COPY-THEN-RMW BY OPERATION KIND, NOT FIELD BY FIELD: sched1 does the interleaving, the source must not (P31 S60; wave cf, func_80180FB4, ov_SC03_111, byte-proven) L26990 - **§NNN** — A DEPENDENT COPY-THEN-RMW BLOCK MUST BE SOURCE-GROUPED BY OPERATION KIND, NOT BY FIELD, AND SCHED1 DOES THE INTERLEAVING (P31 S60; `func_80180FB4`, ov_SC03_111, byte-proven) L26991 - **§NNN** — WRITE THE UP-COUNT LOOP: gcc's OWN REVERSAL PRODUCES A COUNTER-INIT INSTRUCTION THAT LANDS AFTER HOISTED MOVABLES, WHICH A HAND-WRITTEN DOWN-COUNT LOOP CANNOT REPRODUCE (P31 S60; `func_80180DD8`, ov_SC04_005, byte-proven) L27037 - **§285** — PRE-INITIALIZING A VARIABLE WITH A SHARED CONSTANT BEFORE A BRANCH MAKES BOTH ARMS OF THE FOLLOWING if/else DESTRUCTIVELY REUSE THE SAME DESTINATION REGISTER FOR THEIR BITWISE RESULT (byte-proven; `func_801811F0`, ov_SC03_102, independently rediscovered across waves di/dj) (P31 S60; waves #, byte-proven) L29078 - **§287** — A STACK-FRAME HOLE BELOW TWO ADDRESS-TAKEN AGGREGATE LOCALS IS A LEADING PAD MEMBER OF ONE COMBINED STRUCT, NOT SEPARATE LOCALS OR A REGISTER PIN (P31 S60/dj; `func_8017D104`, ov_SC06_027, byte-proven 47/47) (P31 S60; waves #, byte-proven) L29086 - **§297** — ONE GIV SERVING MIXED-WIDTH LOADS *AND* A STORE NEEDS STRUCT-MEMBER SPELLING; CAST/INDEX SPELLINGS RE-SPLIT THE PSEUDO (P31 S61; wave m0a, `func_800347C8`, main, byte-proven 31/31) L29499 - **§308a** — A TWO-INSTRUCTION ARM STUB LAID *BEFORE* THE OTHER ARM AND REACHED ONLY BY A TRAILING `j` SURVIVES ONLY BEHIND A SHORT-CIRCUIT `&&` GUARD PLUS A SEPARATE RE-TEST; EVERY PLAIN if/else-if, GOTO-LADDER, NESTED-INVERTED-if AND 1-/2-NODE switch LETS jump1 INLINE IT (−2 ins) (P31 S63 t5e-t5i; byte-proven func_80180808) L30012 - **§312** — A BARE RELATIONAL IN AN `if` GIVES THE `slt` NO TARGET: ASSIGN THE COMPARISON INTO THE ALREADY-ALLOCATED VARIABLE TO CHOOSE ITS DESTINATION REGISTER, AT ZERO INSTRUCTION COST (P31 S64 t5o-t5r; byte-proven func_80180DCC) L30159 - **§314** — AN IF/ELSE-IF ABS-RANGE CHECK'S C SPELLING IS INERT: FOUR STRUCTURALLY DIFFERENT REWRITES ALL COMPILE BYTE-IDENTICAL, AND NONE REACHES A TARGET THAT SINKS THE NEGATIVE ARM INTO AN OUT-OF-LINE BLOCK (P31 S65; UNPROVEN, gate-refused draft func_80181720) L30241 - **§315** — ALL-CONSTANT AGGREGATE FILL: THE EMISSION ORDER IS SHARED-LITERAL GROUPS × DESCENDING INDEX, WITH PAIRED SUB-FIELDS INTERLEAVED (P31 S66; ⚠ **UNPROVEN** — `func_80185214`, gate-REFUSED draft, closeness 32→5, never MATCHed) L30273 - **§316** — A GUARD CHAIN THAT GATES A SUCCESS BLOCK ROUTES ITS FAILING GUARDS TO A LABEL **BEFORE** THE FLAG TEST, NOT TO THE EPILOGUE: THE RESIDUAL IS IMM-OFFSET-ONLY AT AN EXACTLY EQUAL INSTRUCTION COUNT (P31 S66; byte-proven func_80180284) L30310 - **§317** — A NARROW STRUCT-FIELD STORE TURNS A *LIVE SImode VARIABLE* INTO A `li`: convert.c's TRUNCATION-DISTRIBUTION MINTS A HImode COPY, AND cse REWRITES THAT COPY'S SOURCE TO THE EQUIVALENT CONSTANT (P31 S66; byte-proven func_8017EF94) L30344 - **Addendum** — WIDTH sh!=lhu residual: hoist a sibling field's load first (func_80182538) L30572 - **Addendum** — Masked-OR field-merge plateaus at close=10; bitfield store clears it (func_8017FD64) L30700 - **§321** — FILE-SCOPE DUPLICATE ANONYMOUS-STRUCT TYPEDEFS ARE A HARD ERROR; THE SAME TEXT AT BLOCK SCOPE IS A WARNING (P31 S66; byte-proven func_80180728, func_8017F9F8, func_8017E07C) L30845 - **§335** — AN `extern u16 A[]` READ AT A VARIABLE SUBSCRIPT ALLOCATES DEAD STACK TEMPS (~8B PER ACCESS) THAT INFLATE THE FRAME WHILE EMITTING ZERO EXTRA INSTRUCTIONS (P31 S67; byte-proven ov_SC06_025/func_8017EA74, closeness 141 -> 20) L31140 - **§346** — `c ? X : -X` TAKES expand_expr's COND_EXPR **SINGLETON** PATH (copy, then negate IN PLACE) — AN if/else STATEMENT GIVES THE TWO-ARM FORM (P31 S67; byte-proven ov_SC03_102/func_80180C38, closed the last instruction) L31322 - **§351** — `/s` (MEM_IN_STRUCT_P) IS A DIAL YOU CHOOSE PER ACCESS: A COMPONENT_REF GRANTS IT AND LETS cse KEEP AN INDEX ACROSS THE STORE; A PLAIN CAST DENIES IT (P31 S67; ov_SC01_000/func_8017DD04, 186 -> 5) L31456 - **§357** — ONE STRUCT POINTER, NOT TWO: A SECOND SOURCE VARIABLE BUILDS A THIRD IV (P31 S68; byte-proven ov_SC06_029/func_80181DF8, 335 ins, 330 → 13) L31589 - **§364** — ★ — THE libgpu `P_TAG` BITFIELD SPELLING IS **OPT-LEVEL DEPENDENT** (P31 S68; two functions, opposite verdicts, same session) L31734 - **§379** — ★★★ — **MEM_IN_STRUCT_P**: THE SAME LOAD, WRITTEN AS A STRUCT MEMBER, SCHEDULES WHERE A CAST CANNOT (P31 S69; byte-proven main/func_80021284 220 ins and main/func_8002D904 217 ins, found INDEPENDENTLY by two agents) L32164 - **§391** — ★★ — A BYTE-ALIGNED STRUCT COPIES IN FOUR INSTRUCTIONS, A WORD-ALIGNED ONE IN TWO (P31 S69) L32488 - **§395** — ★★★ — FIVE NARROWING/PLACEMENT LEVERS FROM ONE 91-INSTRUCTION CRACK (P31 S69; byte-proven ov_SC06_018/func_80189E60, warm start 32 off → MATCH 91/91) L32611 - **§418** — ★★★ — TWO LOOP-STRUCTURE LEVERS: MAKE THE SECOND INDEX A GIV, AND KEEP A TABLE ADDRESS UNFOLDED (P31 S71; byte-proven `ov_SC04_016/func_8017DF8C`, 184 ins, 32 → 0 in seven compiles) L33632 - **§425** — ★★★ — `sb` ALIASES SCALAR GLOBALS WHILE `sh`/`sw` STRUCT STORES DO NOT, AND TWO MORE ALIAS/BOOST RULES (P31 S71; `md_MAIN_003/func_800CF3E8`, 467 of 469 ins, all four byte-verified from `-dS`/`-dR`/`-dl`/`-dr`) L33829 ### types, signedness & load/store width (95) - **§3-I1** — Unsigned range check: `(x - lo) < (hi-lo)` → `addiu`+`sltiu` L41 - **§3-I2** — Byte mask forces `andi` even after `lbu` L47 - **§3-T3** — Types L85 - **§7** — PsyQ SDK types & symbols (the library-call prerequisite) L322 - **§14c** — Callee-signature-aware harvest — breaking the extern-type-conflict wall (Phase 15, T6) L1232 - **Phase-20** — RESOLUTION — `tools/cast_call_sites.py` BUILT + the cap re-diagnosed (R14, byte-proven) L1720 - **§23** — Giant `func_80153E00` cracked (scalar-data CAST); BUT most giant drafts are STALE+INCOMPLETE, and a diag MUST remove artifacts (Phase 21 — byte-proven + a self-correction) L2051 - **§28b** — The struct-walled close=0 giant (§28 case #3) IS bankable: the engine_types.h type-lift (Phase 22 T2, byte-proven on func_80156B74 ×134) L2376 - **§33** — Automating the giant decl-reconcile: `tools/reconcile_decls.py` (the DATA analog of §20's `cast_call_sites`) + a fleet-majority type oracle (Phase 24 T7b, byte-proven on `func_80129CF8`) L2453 - **§40a** — The DECL-RECONCILE pass (type-lift so remapped drafts compile in the sibling TU) (Phase 25 T7.2, 2026-07-08) L2620 - **§41** — The DEF-SIDE canonical-sig wall: mechanically banking a drafted giant past `conflicting types` (Phase 25 T5b batch-2, 2026-07-09; `tools/canon_sig_reconcile.py`, byte-proven on `func_8013B274`) L2729 - **§41d** — `void`→`s32` is NOT always byte-neutral: gate the RAW draft FIRST (Phase 26 session 6, byte-proven) L2912 - **§42b** — addendum — wave 3 (Max, 2026-07-10c): THE STALE-OBJECT GATE TRAP + the read-global `&`-cast drift + fix L3028 - **§43** — The K&R s16-param definition DISSOLVES the "narrow-param wall" for by-value register args (Phase 25 task A, Fable5 crack of the 369-ins giant `func_80166994` ×134, 2026-07-11) L3229 - **§3-C.** — TYPE- AND SHAPE-DRIVEN CODEGEN (the C type literally selects the addressing mode) L3518 - **§56b** — PROPAGATING an h_seq giant: the exemplar's externs MUST be fleet-canonical, not the draft's types L4266 - **§64** — The §20 type-lift's three laws: fold the tagged typedef, check VISIBILITY, and strip only what is TEXTUALLY IDENTICAL (`lift_types.py`, Phase 29 SESSION-14, 2026-07-23) L4942 - **§64a** — VARIANT types: UNIQUIFY the camps, do not reconcile them (`uniquify_type.py`, Phase 29 SESSION-14) L4991 - **§65g** — Where the cheap levers STOP: the local-type and in-TU-self-decl classes did not yield L5173 - **§68** — A comment-only line halted the extern scan, and the skip label blamed the type cap (Phase 29 SESSION-18) L5558 - **§73** — A def-side self-decl conflict has TWO axes: RETURN (fleet widen, T2) and PARAMS (casts at each use, T0). Diagnose which before paying for the expensive one (Phase 29 SESSION-19, `func_8014F3E8` + `func_8014D4C0`) L5817 - **§75c** — Class-B's remedy is the FULL §17a-1 PAIR (decl **and** call-site cast); a decl-only fix moves the error and looks like a new wall (Phase 29 SESSION-19, `func_8012F14C`) L6031 - **§3-The** — defect this exposed: a shared type that is present but invisible L6388 - **§92** — Conforming a DECLARATION: pointer changes are caller-neutral, scalar-WIDTH changes are not (Phase 29 SESSION-21, `tools/conform_decls.py`) L6925 - **§94** — A family sweep's `0/N` is a TYPE-CARRY failure until proven otherwise: lift the exemplar's local types, ALL of them, transitively (Phase 29 SESSION-21, `func_8016B6BC` 0/137 → 137/137) L6981 - **§100** — Prefer the DRAFT-LOCAL fix: a type only one function uses belongs in its BODY, not in a shared header (Phase 29 SESSION-22, `func_80175DA8` 0/137 → 137/137) L7250 - **§120** — Uniquify draft-defined TYPE names; and check which of N staging sites you actually patched (Phase 29 T93) L8060 - **§3-Do** — NOT "strip the duplicate typedef" — it breaks the extern that uses it L8071 - **§3-The** — type-form rules L8913 - **§143** — `cast_call_sites` read a RETURN STATEMENT as a prototype and deleted it. A 0/39 sweep became 18/39. (P30 S40) L9868 - **Then** — propagation returned 0/137 TWICE — both times a missing TYPE L10034 - **§154** — Reading a disc payload: the module-id word, static base derivation, and "type 1 = uncompressed overlay" (P30 S44) L10556 - **§3-C.** — PAC type 1 = the same payload class as type 4, just NOT compressed L10582 - **§155b** — check the TYPE your oracle returns before comparing against it (S45 p5) L10621 - **§3-B.** — Typedef handling — the only strategy that survives contact L17058 - **§3-D.** — A NARROW TYPE BLOCKS COPY ELISION (func_8001D3FC — new idiom) L17329 - **§185** — EDIT THE SIDE THAT IS CHEAP TO VERIFY, AND CHECK A TU RETYPE AT ITS USE SITES L18101 - **§186b** — A NO-SAVE 16-BYTE FRAME IN A LEAF FUNCTION MEANS `s16` LOCALS, NOT A HIDDEN CALL L18154 - **§193-B** — A NARROW CAST OF A WIDE PARAMETER COSTS ONE EXTRA INSTRUCTION WHEN ITS STATEMENT SITS AFTER AN INTERVENING `jal` — AND THE DECIDER IS `combine.c:929`'s CROSS-CALL GUARD, NOT REGISTER ALLOCATION L18550 - **§193-G** — §164-54's "scope to ≥4 arms" bound is byte-wrong — the dispatch-topology oracle goes live at THREE case nodes (`balance_case_nodes` splits at `i > 2`), but only for a signed-after-promotion index L18787 - **§193-H** — A pointer-derived base load `*(s32*)(p+K)` is uncacheable across ANY memory write or call (cse's third kill disjunct) — so the target emits one `lw` per store-separated RUN of spellings, and a run of stores sharing one `lw` is a C local you must declare L18848 - **§194-B** — A `addu $rA,$rB,$zero` copy feeding ≥2 `sh` stores is a SECOND, 16-BIT-DECLARED local — the width, not the clamp or the join liveness, is what keeps the copy (and func_80183094's pin + `"memory"` clobber are both provably inert) L19057 - **§194-D** — Declared width of a computed-value local is a sched1 dial (count-neutral) — a replication + attribution correction of §165-17, NOT a new argument-register law L19158 - **§194-G** — Reading the integer half of a 16.16 stack aggregate: REGISTER-LIVENESS, not the C spelling, decides `sra` vs `lhu` — and the break is count-neutral L19309 - **§194-H** — §164-29's WAR fence runs again at SCHED2 ON HARD REGISTERS: an in-place `v &= K` before a branch fences the store that reads v, and when TWO independent stores compete for the one delay slot the fence picks the winner at ZERO length drift (a WIDTH/sh!=sw swap, not a nop). Corrects §167-42's reconstruction (pseudo arm → hard-reg arm) and supplies its first re-runnable A/B. L19352 - **§194-I** — §16N+2's magic-per-odd-part ladder has exactly one broken row — read the divisor arithmetically instead: d = round(2^(32 + post_shift) / magic_read_as_unsigned) L19390 - **§197-A** — A NARROW SIGNED MEMORY READ FEEDING A CONSTANT `>>` LOSES ITS `lh`, AND THE CURE IS AN ASM RE-TIE (attribution CONTESTED: cse vs combine) L20622 - **§199-D** — A narrow UNSIGNED value compared in an ordered `if` emits `sltiu`/`sltu`; the only dial is the WIDTH of a real object, and a widening `(s32)` cast is inert — AMENDS §35 (whose stated "only CSE-reuse canonicalizes" mechanism is byte-wrong) and does NOT apply inside a `switch` L20901 - **§201-D** — THE SIGNEDNESS OF A div/mod MAGIC IS DECIDED BY THE STATIC TYPE OF THE DIVIDEND TREE AFTER `get_narrower` STRIPS WIDENING CONVERSIONS — NEVER BY A PROVABLE RANGE. AN `& 0xFF` IS NOT A CONVERSION, SO IT NEVER FLIPS THE MAGIC; A DECLARED-UNSIGNED LOCAL *OR* A NARROWING CAST WRITTEN AT THE DIVIDE BOTH DO. L21362 - **§203** — A DEDUPED TYPEDEF MUST PRECEDE EVERY SPLICE POINT, NOT JUST ITS OWN (P31 S56) L21527 - **§204-E** — `decl_prior`'s `%hi/%lo` ARM HAS NEVER FIRED: the card's promised GLOBAL-TYPE row is 0 of 1,210 L21879 - **§218** — A NARROW TYPE AT THE ABI BOUNDARY COSTS AN IN-PLACE `sll/sra` PAIR — on the RETURN as well as on the PARAMETER (P31 S58) L22723 - **§220** — THE PARAMETER ITSELF IS A REGALLOC DIAL: use it directly, prefer `s32` to `void*`, and place the save-copy AFTER the first call (P31 S58) L22779 - **§227** — TYPE THE SOURCE BY THE **LOAD** WIDTH, NOT BY THE STORE WIDTH (P31 S58) L23059 - **§234** — CONSTANT MATERIALISATION: THE STORE LVALUE'S SIGNEDNESS PICKS `addiu` vs `li`/`ori` (P31 S58b) L23357 - **§237** — THE CAST-AT-CALL-SITE DECISION TABLE: WHAT §17a-1 FIXES, WHAT IT CANNOT, AND THE FOUR ESCAPES (P31 S58b) L23506 - **§242** — `*k` vs `<>n`: EXPRESSION SPELLING OWNS THE LOAD WIDTH AND THE ROUNDING CHAIN (P31 S58b) L23693 - **§243** — SPELL THE CSE BARRIER AS A REASSIGNED POINTER; AND THE `nop`-AFTER-EVERY-`lh` SIGNATURE (P31 S58b) L23721 - **§251** — IMMEDIATE-SPELLING TRIGGERS: `+= 0xFF`, FULL-WIDTH `~K`, AND THE TWO-OR SPLIT (P31 S58b) L24010 - **ADD-5** — → §1/I1 addendum — THE INVERTED RANGE TEST: `(u32)(x-lo) >= N` WITH THE ZERO-ARM AS THE TRAILING `else` L25173 - **ADD-2** — → §236 addendum (item 1 corollary) — THE SILENT-SPLICE DECLARATION LADDER: WHERE THE TU HAS NO SPELLING, UNPROTOTYPED `()` BEATS THE FLEET VOTE L25367 - **ADD-5** — → §267-ADD-6 / §172b-1 addendum — THE SIGN-TEST FACE: `(s16)v < 0` IS `sll 16` + `bgez` ON THE SHIFTED COPY, RAW STAYS LIVE — AND THE HALFWORD-ABS SHAPE NEEDS NO RITUAL L25411 - **ADD-8** — → §30a addendum — THE THIRD COLUMN: `*p++` IS ALSO SERIALIZED BUT BURNS `addiu`; ONLY CAST-PLUS GIVES SERIALIZATION *AND* DISPLACEMENT FOLDING L25456 - **ADDENDUM** — to §179-C — the `.type NAME, @function` requirement L25640 - **ADDENDUM** — to §134 — a typedef defined BELOW the splice point is stripped anyway L25687 - **ADDENDUM** — to §172b-1 — TWO PLACEMENT DIALS THE PROMOTION LAW DOESN'T NAME: NARROW THE COUNTER'S DECLARED TYPE, AND MOVE THE CAST INTO THE LOOP BODY L26100 - **ADDENDUM** — to §172b-4 — THE PLAIN CAST-DIVISION ALREADY PRODUCES THE PATTERN; DON'T HAND-ROLL THE BIAS, AND KEEP THE OPERAND WIDE L26192 - **§280** — THE CURSOR'S DECLARED TYPE PICKS `sltu` vs `slt`: a `T*` bound test is UNSIGNED by C rule, an integer cursor is signed (P31 S60; wave cf, func_800CAE74, md_MAIN_031, byte-proven) L26956 - **§NNN** — A LOOP CURSOR'S C TYPE (POINTER vs PLAIN INTEGER) SELECTS `sltu` vs `slt` FOR ITS BOUND TEST, INDEPENDENT OF THE VALUES INVOLVED (P31 S60; `func_800CAE74`, md_MAIN_031, byte-proven; cross-confirmed same wave by `func_8017F2A4`, ov_SC03_096) L26957 - **ADDENDUM** — to §21 — the `bltz`+`slti` (or N-separate-compares) signed-range-split bullet is now CONFIRMED on three independent functions, and generalizes beyond `lbu`/u8 L27157 - **ADDENDUM** — to §202 — the DEF-SIDE ALIAS also resolves a function-vs-DATA-symbol identifier clash, not only a function-vs-function prototype clash L27203 - **ADDENDUM** — §NNN — sharpens §162a3/§60b: A `sll $v0,16 / sltiu $v0,1` ZERO-TEST OF A JUST-DECREMENTED HALFWORD IS A SIGNED-TEMP WIDTH TELL OUTSIDE ANY SWITCH/RANGE-TEST CONTEXT L28293 - **§288** — A REGISTER PIN DECLARED UNINITIALIZED AND ASSIGNED ONLY AT ITS LATE, SOLE USE STILL FORCES THE FIXED REGISTER'S SAVE/RESTORE, AND THE ASSIGNMENT'S SOURCE POSITION CONTROLS WHERE THE VALUE MATERIALIZES (P31; `func_80186530`, ov_SC02_017, byte-proven, match_one MATCH re-verified) (P31 S60; waves #, byte-proven) L29090 - **§292** — DECLARING A SYMBOL UPSTREAM OF AN ALREADY-BANKED SIBLING THAT RELIES ON THAT SYMBOL'S IMPLICIT (K&R) DECLARATION CAN SILENTLY REPROTOTYPE THE SIBLING'S OWN CALL SITE (P31 S60; waves #, byte-proven) L29106 - **ADDENDUM** — to §172b-1 (counter-type dial) — the sll's SOURCE REGISTER is the placement discriminator L29268 - **ADDENDUM** — to §31's asm→layout inference — TWO WIDTH-PAIR DISCRIMINATORS (same offset, different widths) L29380 - **§297** — ONE GIV SERVING MIXED-WIDTH LOADS *AND* A STORE NEEDS STRUCT-MEMBER SPELLING; CAST/INDEX SPELLINGS RE-SPLIT THE PSEUDO (P31 S61; wave m0a, `func_800347C8`, main, byte-proven 31/31) L29499 - **§318** — A UNARY MINUS STORED BACK INTO THE SAME HALFWORD IS COMPUTED IN HImode, SO ITS LOAD IS `lhu`; AN INLINE `(s32)` CAST IS PROVABLY INERT AND ONLY A NAMED SImode LOCAL BUYS `lh` (P31 S66; `func_8018568C`, ov_SC03_028 — **`match_one`-only, NOT byte-gated**) L30378 - **Addendum** — Reversed-operand sltu then xori 1 means unsigned less-or-equal (func_8017D948) L30505 - **Addendum** — WIDTH sh!=lhu residual: hoist a sibling field's load first (func_80182538) L30572 - **Addendum** — Static local_type blocker survives typedef removal — it's textual (func_801588CC) L30615 - **§320** — THE §43 "RETURN-TYPE FLIP PAIR" IS **NOT** TU-EDIT-REQUIRED: THREE DRAFT-ONLY ESCAPES (P31 S66; byte-proven func_800CCBC0, func_800D30D0, func_800D2A24) L30786 - **§321** — FILE-SCOPE DUPLICATE ANONYMOUS-STRUCT TYPEDEFS ARE A HARD ERROR; THE SAME TEXT AT BLOCK SCOPE IS A WARNING (P31 S66; byte-proven func_80180728, func_8017F9F8, func_8017E07C) L30845 - **§323** — CARRYING FILE-SCOPE TYPES BETWEEN SPLIT TUs: DEDUPE BY NAME, SKIP HEADER-PROVIDED, AND THE GUARD TRAVELS WITH THE BLOCK (P31 S67; ov_SC02_000, two defects fixed, one open) L30896 - **§327** — A RANGE TEST MUST BE HImode: WITH `s32` + A `(u16)` CAST GCC *PROVES* THE MASK REDUNDANT AND DROPS THE `andi` (P31 S67; byte-proven ov_SC02_039/func_8017EC34, 154 ins) L31009 - **§328** — THE VOLATILE ALIAS MUST BE AN *OBJECT*, NOT A CAST: `*(volatile s32*)&sym` UNFOLDS %lo INTO A SEPARATE `addiu` (P31 S67; byte-proven ov_SC07_007/func_80181B8C, 156 ins, NEW LAW) L31024 - **§335** — AN `extern u16 A[]` READ AT A VARIABLE SUBSCRIPT ALLOCATES DEAD STACK TEMPS (~8B PER ACCESS) THAT INFLATE THE FRAME WHILE EMITTING ZERO EXTRA INSTRUCTIONS (P31 S67; byte-proven ov_SC06_025/func_8017EA74, closeness 141 -> 20) L31140 - **§342** — A `void *` PARAMETER CAST TO ITS REAL TYPE IN A LOCAL IS **NOT** BYTE-NEUTRAL WHEN A LATER PARAMETER ALSO NEEDS A CALLEE-SAVED REGISTER (P31 S67; byte-proven ov_SC07_002/func_80181394, NEW LAW) L31257 - **§345** — A VOLATILE **STORE** EVICTS THE MEM FROM cse AND KEEPS `sh`; A VOLATILE **LOAD** BLOCKS combine AND DEGRADES `lh` INTO `lhu+sll+sra` (P31 S67; byte-proven ov_SC01_084/func_80181A7C) L31312 - **§351** — `/s` (MEM_IN_STRUCT_P) IS A DIAL YOU CHOOSE PER ACCESS: A COMPONENT_REF GRANTS IT AND LETS cse KEEP AN INDEX ACROSS THE STORE; A PLAIN CAST DENIES IT (P31 S67; ov_SC01_000/func_8017DD04, 186 -> 5) L31456 - **§378** — ★★★ — THE **SELF-CALLER CAST**: LET A TU KEEP CALLING THE FUNCTION IT IS ABOUT TO DEFINE (P31 S69; byte-proven ov_SC04_010/func_8017D6CC) L32114 - **§379** — ★★★ — **MEM_IN_STRUCT_P**: THE SAME LOAD, WRITTEN AS A STRUCT MEMBER, SCHEDULES WHERE A CAST CANNOT (P31 S69; byte-proven main/func_80021284 220 ins and main/func_8002D904 217 ins, found INDEPENDENTLY by two agents) L32164 - **§392** — ★★★ — THE SONNET-WAVE HARVEST (P31 S69): SEVEN TYPE/ORDER LEVERS THAT EACH CLOSED A MATCH L32502 - **§422** — ★★ — QImode ARITHMETIC VIA `(u8)(x - K)`, AND `flag ^ 1` NEEDS ITS OWN TEMP (P31 S71; byte-proven `resident/func_800D06E8`, 344 ins) L33760 - **§423** — ★★★ — "MATCH IN ISOLATION + GATE REJECTS + CAUSE NOT DETERMINED" ⇒ GREP THE TU FOR A FILE-SCOPE TYPEDEF THE DRAFT ALSO CARRIES (P31 S71; byte-proven `ov_SC03_092/func_8017FA74`) L33780 ### declarations, prototypes & K&R (114) - **§3-T4** — Branch polarity: invert the source condition to flip gcc's chosen branch L90 - **§8c** — Splitting a TU means rebuilding its DECLARATION ENVIRONMENT, not moving text (Phase 26 session 6) L456 - **§8d** — Templating a body INTO a TU must not CHANGE its declaration environment — demote the carried data externs (Phase 26 session 8, byte-proven on `func_8015AE2C` ×133) L502 - **§13** — Add a location overlay — the canonical runbook (Phase 13; the Phase-15 fleet recipe) L1075 - **§14c** — Callee-signature-aware harvest — breaking the extern-type-conflict wall (Phase 15, T6) L1232 - **§3-The** — pipeline gotcha — match_one ≠ the gate; `sig_unify` is MANDATORY L1440 - **§3-The** — gate two-stage — sig_unify is a FALLBACK, not unconditional (`gate_stage.py`, §19 folded in) L2208 - **§28** — Banking a "close=0 gate-rejected" giant: the canonical-extern recovery (Phase 22 T1, byte-proven on func_8015126C ×134) L2344 - **§28d** — The "macro-extern-injection" lever: freeing reach-134 inline matches dedup_propagate skips as "not self-contained" (Phase 23, `tools/inject_capped_externs.py`) L2385 - **§33** — Automating the giant decl-reconcile: `tools/reconcile_decls.py` (the DATA analog of §20's `cast_call_sites`) + a fleet-majority type oracle (Phase 24 T7b, byte-proven on `func_80129CF8`) L2453 - **§40a** — The DECL-RECONCILE pass (type-lift so remapped drafts compile in the sibling TU) (Phase 25 T7.2, 2026-07-08) L2620 - **§41** — The DEF-SIDE canonical-sig wall: mechanically banking a drafted giant past `conflicting types` (Phase 25 T5b batch-2, 2026-07-09; `tools/canon_sig_reconcile.py`, byte-proven on `func_8013B274`) L2729 - **§41b** — addendum — M4 "reconcile_decls" tier is ALSO a probe over-count: 0/8 mechanical (Phase 25 T7-M4, 2026-07-10) L2892 - **§41d** — `void`→`s32` is NOT always byte-neutral: gate the RAW draft FIRST (Phase 26 session 6, byte-proven) L2912 - **§43** — The K&R s16-param definition DISSOLVES the "narrow-param wall" for by-value register args (Phase 25 task A, Fable5 crack of the 369-ins giant `func_80166994` ×134, 2026-07-11) L3229 - **§51g** — When the thing you are scanning has a GRAMMAR, parse the grammar (`tools/cdecl.py`) L3803 - **§54** — `--fix-def-sig`: the member's CANONICAL DECLARATION is a build step too (tiny-IMM mega-pools, +4,801, Phase 29 T6, 2026-07-16) L4197 - **§56** — Banking a hand-drafted GIANT into its exemplar TU: self-contained draft vs live-TU decls, 4 reconciliation tactics (`func_8013FAF8`, 312 ins ×138, Phase 29 T4, 2026-07-17) L4221 - **§56b** — PROPAGATING an h_seq giant: the exemplar's externs MUST be fleet-canonical, not the draft's types L4266 - **§57** — The SELF-decl normalize: the sibling's OWN caller declares the templated fn divergently (the third §17a-1 direction; `tools/normalize_self_decls.py`, func_801670E4 ×137, Phase 29, 2026-07-18) L4290 - **§61** — Task 14: the gate ladder's missing stage is the ARITY pre-pass, and it is TU-side not draft-side (Phase 29, 2026-07-21) L4579 - **§63** — The fresh-138 DEF-SIDE blocker: fix the HEADER decl, not the draft (`fix_header_decl.py`, Phase 29 SESSION-13, 2026-07-23) L4911 - **§63** — UPDATE (Phase 29 SESSION-14) — `fix_header_decl`'s "SAFE" verdict is FLEET-BLIND; it MUST be R22-validated L5034 - **§65c** — `rtu_match` MATCH → bank held 13/13 on self-decl, but broke on the FIRST callee-decl case L5115 - **§65g** — Where the cheap levers STOP: the local-type and in-TU-self-decl classes did not yield L5173 - **§66a** — The widest write in a pipeline is the one most likely to be UNDECLARED L5215 - **§68** — A comment-only line halted the extern scan, and the skip label blamed the type cap (Phase 29 SESSION-18) L5558 - **§73** — A def-side self-decl conflict has TWO axes: RETURN (fleet widen, T2) and PARAMS (casts at each use, T0). Diagnose which before paying for the expensive one (Phase 29 SESSION-19, `func_8014F3E8` + `func_8014D4C0`) L5817 - **§75** — A propagation cap is usually a MINORITY-SPELLING SOURCE OVERLAY, not a wall: census the carried extern before believing the exclusion message (Phase 29 SESSION-19, `func_8014F3E8` ×4 → ×138) L5900 - **§75b** — A body's preamble can carry `#define`s, not just `extern`s; extraction lifts only the externs (Phase 29 SESSION-19, `func_80165CA0` ×3 → fleet) L5982 - **§75c** — Class-B's remedy is the FULL §17a-1 PAIR (decl **and** call-site cast); a decl-only fix moves the error and looks like a new wall (Phase 29 SESSION-19, `func_8012F14C`) L6031 - **§76** — The allocno CLASS (local vs global) is the dominant regalloc lever, and C reaches it ONLY through declaration scope and variable reuse (Phase 29 SESSION-19, behemoth #3 `func_8017F510` 1,511 ins, 97 → MATCH, pin-free) L6062 - **§79** — For a 0-callee giant, fingerprint by DATA symbols (§71 cannot fire); and the STACK-SLOT ORDER is a declaration-order oracle (Phase 29 SESSION-19, `func_8017BF14` 4,763 ins, cold start → 45/4763) L6254 - **§3-NEW** — LEVER — the frame layout reads back the original declaration order L6274 - **§3-1.** — The inlined-helper signature L6409 - **§92** — Conforming a DECLARATION: pointer changes are caller-neutral, scalar-WIDTH changes are not (Phase 29 SESSION-21, `tools/conform_decls.py`) L6925 - **§95** — `reconcile_tu` dropped the SIBLING declarators of a multi-symbol `extern` line (Phase 29 SESSION-21, `func_80176218`) L7017 - **§96** — The same rewrite, one shape down: `reconcile_tu` matched statements to lines by TEXT, so every COMMENTED declaration was silently skipped (Phase 29 SESSION-22, `func_80176218` banked) L7052 - **§98** — `conform_decls` had three defects, and only the third needed R22 to find (Phase 29 SESSION-22, `func_8014CF04`) L7147 - **§99** — The narrow-param wall is a DEF-side problem with a ZERO-blast-radius fix: convert the definition to K&R (Phase 29 SESSION-22, `func_80175AB8` + `func_80175DA8`) L7201 - **§102** — A PLUMBING verdict can MASK a DIFF; and K&R is not always a codegen change (Phase 29 SESSION-22, `func_8016EC0C`) L7306 - **§103** — A FILE-scope `extern` in a shared overlay TU is a GLOBAL constraint on every LATER function; move the DECL, not the draft (Phase 29 T48/T51, `func_80135260` — the fleet-wide half) L7341 - **§104** — Two silent-skip defects in one scan: match on MASKED text, emit from the ORIGINAL (Phase 29 T53, `gather_externs`) L7429 - **§112** — A macro-scoped declaration only collides where the macro is INSTANTIATED (Phase 29 T67/T69, `audit_header_sigs.py`) L7764 - **§113** — An ARITY blocker only exists if the macro CALLS the function; an address-taken use has no call site (Phase 29 T72) L7810 - **§114** — The THIRD decl axis: a CALLEE the draft declares differently from the target TU (Phase 29 T76/T77) L7842 - **§3-Do** — NOT "strip the duplicate typedef" — it breaks the extern that uses it L8071 - **§121** — Synthesise externs for macro-DEFINED callees from the macro's own definition head (Phase 29 T95) L8095 - **§3-The** — declaration surface (integration, not codegen) L8975 - **§136f** — Two declaration sub-cases the reconcile lane surfaced (lane now 15/15 lifetime) L9220 - **§138** — The propagation lanes: a gate refusal is a DECLARATION, and which lever you owe depends on blast radius L9449 - **Reconciling** — a gate-refused draft: which way you edit depends on WHERE the TU's decl is L9599 - **§141** — The §134 class is CLOSED: every line-shape decision now routes through `cdecl._mask` (P30 S39) L9774 - **§143** — `cast_call_sites` read a RETURN STATEMENT as a prototype and deleted it. A 0/39 sweep became 18/39. (P30 S40) L9868 - **§3-C.** — Inner-block declaration does NOT delay slot allocation — BYTE-REFUTED L10102 - **§159** — THE DECLARATION AXIS: conform to byte-truth, and make every guard state its COVERAGE (P30 S47; ~10,930 sites across 8 axes, fleet byte-identical) L10862 - **§168** — THE COUSIN TIER (P30 S49, 2026-08-12): h_seq's exact-hash brittleness, measured — and the similarity map above it L16265 - **§176f** — THE DECLARATION FORM IS A MATCHING LEVER, SO RECONCILE TOWARD THE FORM THE MATCH NEEDS (P31 S52) L16963 - **§183** — THE DECLARATION-RECONCILIATION PLAYBOOK (P31 S53, measured on 20 byte-verified drafts) L18002 - **§193-H** — A pointer-derived base load `*(s32*)(p+K)` is uncacheable across ANY memory write or call (cse's third kill disjunct) — so the target emits one `lw` per store-separated RUN of spellings, and a run of stores sharing one `lw` is a C local you must declare L18848 - **§193-I** — A DECLARED AGGREGATE LOCAL HAS AN 8-BYTE FRAME STRIDE — CEIL(size,8), NOT size. N ARRAYS THEREFORE COST 8·k MORE THAN ONE HAND-LAID STRUCT (k = how many of them have size mod 8 ≠ 0), AND THE TELL IS IDENTICAL INSTRUCTION COUNT WITH EVERY $sp DISPLACEMENT SHIFTED BY THE SAME CONSTANT. L18888 - **§194-B** — A `addu $rA,$rB,$zero` copy feeding ≥2 `sh` stores is a SECOND, 16-BIT-DECLARED local — the width, not the clamp or the join liveness, is what keeps the copy (and func_80183094's pin + `"memory"` clobber are both provably inert) L19057 - **§194-D** — Declared width of a computed-value local is a sched1 dial (count-neutral) — a replication + attribution correction of §165-17, NOT a new argument-register law L19158 - **§195-A** — §167-08's "an $aN READ before the jal is scratch" has a byte-proven FALSE-NEGATIVE class: an argument that DIES at the call is allocated straight into $aN, so its only def is a plain load far above the jal and every intervening use reads $aN — there is no positive tell in either direction, only the two-arity A/B L19764 - **§195-C** — A call-argument `%hi/%lo` pair sitting at the block head, far above its `jal`, is a load-delay-gap filler chosen by SOURCE STATEMENT ORDER — swap the two independent statements nearest the call; a single-use `void *p = &SYM;` call-arg temp is OUTPUT-inert against it (but NOT expand-stream-inert) L19877 - **§195-D** — §195 — `masked_diff.mask_for` returns 0 for EVERY `j`/`jal` word, so an internal `j` destination is invisible to match_one, the permuter scorer AND every similarity tier: a control-flow semantic error (which calls execute) surfaces as a 1-instruction residual mislabelled `DELAY-SLOT / profile=schedule`, or as an outright false MATCH L19925 - **§195-F** — fold-const.c:4825 canonicalises a `?:` whose THEN arm is zero (or constant against a non-constant ELSE) by inverting the condition and swapping the arms — so a ternary's written arm order is byte-inert there, and `c ? 0 : X` is unspellable: it always compiles as `!c ? X : 0` L20051 - **§195-G** — §NEW — TWO ARMS CALLING THE SAME CALLEE MERGE INTO ONE `jal` UNLESS EACH ARM'S OWN CODE CONSUMES THE RESULT: the C dial that keeps two call sites apart is WHERE the consumer test lives, and the branch SENSE you spell it with is byte-inert (jump.c:1737 canonicalises it) L20103 - **§195-H** — §165-27g — ON A FIXED-SYMBOL GLOBAL, `extern T D[];` + `D[0]` IS THE CSE RELOAD DIAL, AT ZERO ADDRESSING COST, AND THE ELEMENT COUNT IS INERT (§165-27's `T v[2]` CAVEAT IS A LOCAL-FRAME FACT AND DOES NOT TRANSFER) L20151 - **§196** — PUT ON THE CARD WHAT THE TREE ALREADY KNOWS: the fleet's declaration consensus (P31 S54) L20553 - **§199-D** — A narrow UNSIGNED value compared in an ordered `if` emits `sltiu`/`sltu`; the only dial is the WIDTH of a real object, and a widening `(s32)` cast is inert — AMENDS §35 (whose stated "only CSE-reuse canonicalizes" mechanism is byte-wrong) and does NOT apply inside a `switch` L20901 - **§199-G** — At TWO case nodes the switch-vs-if oracle is not blind — but the tell is ALL tests positive + a trailing `j default`, NOT the first test's polarity L21074 - **§200** — THE ALIAS IS THE UNIVERSAL DECLARATION ESCAPE: stop negotiating with the TU's spelling (P31 S55) L21140 - **§201-A** — §150-B applies to `decl_prior`'s DEF row: for an overlay-window symbol the banked "definition" is usually another overlay's function, and the card ranks it ABOVE the destination TU L21199 - **§201-D** — THE SIGNEDNESS OF A div/mod MAGIC IS DECIDED BY THE STATIC TYPE OF THE DIVIDEND TREE AFTER `get_narrower` STRIPS WIDENING CONVERSIONS — NEVER BY A PROVABLE RANGE. AN `& 0xFF` IS NOT A CONVERSION, SO IT NEVER FLIPS THE MAGIC; A DECLARED-UNSIGNED LOCAL *OR* A NARROWING CAST WRITTEN AT THE DIVIDE BOTH DO. L21362 - **§202** — THE ALIAS CARRIES A DEFINITION, NOT JUST A DECLARATION: the DEF-SIDE-RETURN wall (P31 S56) L21490 - **§204-C** — WHEN A LOCAL BUFFER'S ADDRESS IS PASSED TO A CALL, ITS SIZE IS A FACT ABOUT THE CALLEE'S BODY, NOT ABOUT THE CALL SITE: grep the callee's proven definition and count the stores through the pointer parameter before you declare the local L21746 - **§204-E** — `decl_prior`'s `%hi/%lo` ARM HAS NEVER FIRED: the card's promised GLOBAL-TYPE row is 0 of 1,210 L21879 - **§208** — TWO NAMED LOCALS FOR ONE RELOADED EXPRESSION BUY TWO ALLOCNOS — the naming granularity owns the REGISTER SPLIT, not just the load count (P31 S58) L22243 - **§214** — THE BANKED TWIN MAY BE A MACRO, A DELETED `.s`, OR A SEMANTIC INVERSE — six ways a ≥0.9 similarity lies (P31 S58) L22555 - **§216** — DISTINCT ADJACENT SCALARS vs ONE ARRAY: one `lui` per access is the tell, and the array decl is UNUSABLE (P31 S58) L22657 - **§220** — THE PARAMETER ITSELF IS A REGALLOC DIAL: use it directly, prefer `s32` to `void*`, and place the save-copy AFTER the first call (P31 S58) L22779 - **§224** — CROSS-JUMP: WRITE THE DUPLICATE, AND READ A SHARED DELAY SLOT AS THE MERGE SIGNATURE (P31 S58) L22939 - **§236** — THE DECLARATION LAYER IS THE DOMINANT BANK-BLOCKER: NINE WAYS A BYTE-PERFECT BODY FAILS THE GATE (P31 S58b) L23427 - **§243** — SPELL THE CSE BARRIER AS A REASSIGNED POINTER; AND THE `nop`-AFTER-EVERY-`lh` SIGNATURE (P31 S58b) L23721 - **§250** — `%hi/%lo` vs `lw`: THE EXTERN'S ARRAY-vs-SCALAR SHAPE DECIDES ADDRESS MATERIALISATION (P31 S58b) L23973 - **§214** — addendum (P31 S58b) — FOUR MORE WAYS A HIGH-SIMILARITY TWIN LIES L24388 - **§226** — addendum (P31 S58b) — THE FRAME CATALOGUE: SEVEN MORE LEVERS, AND SLOT ORDER IS DECLARATION ORDER L24617 - **§263** — A STOLEN DELAY SLOT WHOSE INSTRUCTION IS AN ARG-REGISTER COPY IS AN ARITY ERROR, NOT A SCHEDULE (P31 S59, byte-proven) L24927 - **ADD-10** — → §237 addendum (arity-evidence paragraph) — AN `la` PAIR ABOVE THE PROLOGUE `sw $ra` IS AN OUTGOING-ARGUMENT MATERIALISATION L25225 - **ADD-2** — → §236 addendum (item 1 corollary) — THE SILENT-SPLICE DECLARATION LADDER: WHERE THE TU HAS NO SPELLING, UNPROTOTYPED `()` BEATS THE FLEET VOTE L25367 - **§272** — The `(void)`-decl + empty-call wall: K&R the DEFINITION, not just the decls (P31 S59) L25599 - **ADDENDUM** — to §20 — a global declared as `T *` may itself BE the array base, not a pointer to dereference L25820 - **ADDENDUM** — to §172b-1 — TWO PLACEMENT DIALS THE PROMOTION LAW DOESN'T NAME: NARROW THE COUNTER'S DECLARED TYPE, AND MOVE THE CAST INTO THE LOOP BODY L26100 - **§280** — THE CURSOR'S DECLARED TYPE PICKS `sltu` vs `slt`: a `T*` bound test is UNSIGNED by C rule, an integer cursor is signed (P31 S60; wave cf, func_800CAE74, md_MAIN_031, byte-proven) L26956 - **ADDENDUM** — to §202 — the DEF-SIDE ALIAS also resolves a function-vs-DATA-symbol identifier clash, not only a function-vs-function prototype clash L27203 - **ADDENDUM** — §NNN — sharpens §37/§124 (unspecified-parameter-list family): DERIVE A CALLEE'S ARITY LOWER BOUND FROM ITS OWN `.s` STACK-ARGUMENT READS, NOT FROM ANY SINGLE CALL SITE L28326 - **§288** — A REGISTER PIN DECLARED UNINITIALIZED AND ASSIGNED ONLY AT ITS LATE, SOLE USE STILL FORCES THE FIXED REGISTER'S SAVE/RESTORE, AND THE ASSIGNMENT'S SOURCE POSITION CONTROLS WHERE THE VALUE MATERIALIZES (P31; `func_80186530`, ov_SC02_017, byte-proven, match_one MATCH re-verified) (P31 S60; waves #, byte-proven) L29090 - **§292** — DECLARING A SYMBOL UPSTREAM OF AN ALREADY-BANKED SIBLING THAT RELIES ON THAT SYMBOL'S IMPLICIT (K&R) DECLARATION CAN SILENTLY REPROTOTYPE THE SIBLING'S OWN CALL SITE (P31 S60; waves #, byte-proven) L29106 - **Addendum** — Counter zero in the DECLARATION slot, empty for-init — the prologue SHIFT-DRIFT/+K face of (func_8018275C) L30725 - **§324** — THE ARITY-SELF WALL NEEDS *BOTH* HALVES: A K&R DEFINITION **AND** A NO-PROTO TU DECL; EITHER ALONE STILL FAILS (P31 S67; rtu-proven ov_SC01_005/func_8017FBCC, 14 instances measured) L30949 - **§333** — FRAME SIZE IS SET BY *DECLARED* AGGREGATES, NOT USED ONES: AN UNREFERENCED TRAILING LOCAL IS A REAL DIAL (P31 S67; three independent byte-proven instances in one wave) L31115 - **§335** — AN `extern u16 A[]` READ AT A VARIABLE SUBSCRIPT ALLOCATES DEAD STACK TEMPS (~8B PER ACCESS) THAT INFLATE THE FRAME WHILE EMITTING ZERO EXTRA INSTRUCTIONS (P31 S67; byte-proven ov_SC06_025/func_8017EA74, closeness 141 -> 20) L31140 - **§342** — A `void *` PARAMETER CAST TO ITS REAL TYPE IN A LOCAL IS **NOT** BYTE-NEUTRAL WHEN A LATER PARAMETER ALSO NEEDS A CALLEE-SAVED REGISTER (P31 S67; byte-proven ov_SC07_002/func_80181394, NEW LAW) L31257 - **§343** — `decl_prior`'s FLEET MAJORITY CAN BE WRONG ABOUT THE TRUE SIGNATURE — READ THE RIVALS, NOT JUST THE WINNER (P31 S67; measured on func_8012BD14 / func_8012D624 / func_80143C74) L31274 - **§347** — LOOP REGISTER ASSIGNMENT IS A **DECLARATION-ORDER + LIVE-RANGE** DIAL: FIVE COMPOSABLE LEVERS, 178 -> 0 (P31 S67; byte-proven ov_SC06_029/func_8017EF34, 243 ins) L31342 - **§343-addendum** — SECOND INSTANCE OF THE WRONG-MAJORITY DECL (same function) L31390 - **§354** — THE giv **WORTH-WHILE TEST** IS A DIAL: RE-ASSOCIATE THE ADDEND INTO THE INDEX TERM AND `strength_reduce` DECLINES (P31 S68; byte-proven ov_SC03_105/func_801824CC, 320 ins, 201 → 5 → 0) L31542 - **§361** — ★ — A LOOP-TAIL BYTE SIGNATURE THAT NAMES ITS SOURCE SHAPE — AND THE LAW THAT A "SCHEDULING TIE" MAY BE YOUR OWN EARLIER LEVER (P31 S68; byte-proven main/func_800241C0, fable escalation, 19 → 0 in 3 iterations) L31637 - **§367** — RECONCILING A DECL CONFLICT BETWEEN TWO DRAFTS FOR THE SAME TU (P31 S68; main) L31777 - **§378b** — ★★★ — THE FOUR VARIANTS OF THE DECL BLOCKER, AND THE TWO PLACES §378 DOES **NOT** APPLY (P31 S69, all four measured the same day) L32572 - **§378c** — ★★ — THE FIFTH DECL-BLOCKER VARIANT: THE DRAFT REDECLARES WHAT THE TU ALREADY OWNS (P31 S69) L32722 - **§398** — ★★★ — `family_remap` CARRIES THE **SOURCE** TU's DECL ENVIRONMENT INTO A DESTINATION THAT ALREADY OWNS THOSE NAMES (P31 S69; measured 3 banked of 22) L32835 - **§415** — ★★ — A FILE-SCOPE DECL MAKES gcc-2.7.2 MERGE THE TU'S LATER *BLOCK-SCOPE* EXTERNS INTO IT (P31 S71; byte-proven `ov_SC04_011/func_80180B24`, 215 ins) L33547 ### jump tables & switches (61) - **§8** — rodata island (compiler jump tables) — the `.data→.rodata→.data` sandwich (Phase 7) L339 - **§8a** — rodata island in a flat OVERLAY — the tail sandwich, per matched jr-function (Phase 26 — PoC PROVEN) L361 - **§8a-pad** — a trailing `.word 0x00000000` under a jtbl dlabel is `.align` PAD, not an entry (Phase 26 session 6, byte-proven) L399 - **§8b** — MULTI-jtbl per overlay — the `ld_interleave --order` sandwich + the same-subseg cases (Phase 26 session 4) L423 - **§8e** — The jtbl ALIGNMENT LAW + the pad-spec filter — multi-table .rodata spans (Phase 29, byte-proven; `.run/probe_jtbl/verdict.md`) L549 - **§3-The** — clean object-level metric (use this, not the permuter score, for jtbl/rodata functions) L863 - **§41b** — T7 execution: the object-only probe OVER-counts BANKABLE by two link/rodata classes (Phase 25 T7-M1, 2026-07-10) L2843 - **§48** — The 12-core jr crack wave: the ALLOCNO-PRICING dials and the EBB rule (Phase 26 session 8, Ultracode, 9/12 MATCH first pass) L3439 - **§53** — SWEEP A FAMILY WITH THE TOOL ITS EXEMPLAR NEEDED: the jr/switch carve, and how omitting it manufactured the "families don't template" doctrine (Phase 28 T1, 2026-07-15) L4062 - **§61b** — The jtbl gate stage: built, and the ORDERING law it exposed (Phase 29 Task-14 stage 4, 2026-07-21) L4692 - **§61c** — The jtbl bank is INCREMENTALLY valid and CLEAN-INVALID (Phase 29, 2026-07-21) — the blocking finding L4747 - **§62** — The jtbl RECONCILE must also follow the carve: the post-carve draft reconcile (`harvest_verify._jtbl_reconcile`, Phase 29 SESSION-11, 2026-07-22) L4867 - **§81** — Banking a jr (jump-table) function: the 3-step carve chain, and why `match_one` cannot see the problem (Phase 29 SESSION-19, `func_8017C954`) L6357 - **§88d** — BANKING ORDER: run the §81 carve chain BEFORE banking, never after L6735 - **§97** — The gate's own tree hygiene: a refused carve, an unchecked recovery, and a snapshot that captured a dirty tree (Phase 29 SESSION-22) L7100 - **§105** — A gate's revert must survive an EXCEPTION, not just a failure (Phase 29 T53, `jtbl_family_bank`) L7465 - **§125** — Split the CARVE from the BODY before calling a jr residue a wall — and measure it by SHA from a CLEAN tree (P30 SESSION-28; **this section's first draft was WRONG and the method caught it**) L8240 - **§126** — The carve-within-a-carve: an ADDRESS RANGE is not an OPTIMIZATION REGION (P30 T2, byte-proven end-to-end) L8298 - **§129** — Post-carve, `rtu_match`/`match_one` COUNT THE JUMP TABLE AS INSTRUCTIONS; and a carve must never be committed without its owner (P30 S28, `func_8013BD74`) L8471 - **§129a** — the target instruction count is INFLATED after a carve L8475 - **§129b** — never commit a carve whose owner is still a stub (it strands the carve) L8496 - **§130** — An INCREMENTAL build can report BYTE-IDENTICAL for a change the CLEAN build cannot even LINK (P30 S28, the jr pair) L8520 - **§131** — The jtbl OVER-SPAN: `sltiu N` is ground truth in BOTH directions, and the zero-word rule only guards one (P30 S28, `func_80191C50`) L8567 - **§132** — The `JR-PAIR-IN-ONE-O0-OBJECT` "wall" was TWO instrument defects: a merged-double span the carve could not see, and a truncated object no rule deleted (P30 S29, `func_8013B83C` + `func_8013BD74`) L8604 - **§132b** — When the span's already-matched owner is ITSELF multi-switch: `--span-rel` (P30 S1, `func_8014032C`) L8694 - **§139** — A GATE THAT GREPS FOR VERDICTS MUST ASSERT 1:1 ACCOUNTING; and a `--src` filter must not survive a carve (P30 S38, wave 6: 10 of 16 drafts vanished) L9628 - **§161** — THE RETRY-WAVE HARVEST: a jump table indexed from zero, and two allocator traps (P30 S47) L11003 - **§179-F** — PINNING A LOOP-WALKED POINTER IS A TOTAL OFF-SWITCH FOR STRENGTH REDUCTION L17573 - **§188** — 🔴 THE `jr $ra` + `addiu $sp` TAIL IS AN **ASSEMBLER** ARTIFACT, NOT A FRAME SHAPE L18217 - **§199-D** — A narrow UNSIGNED value compared in an ordered `if` emits `sltiu`/`sltu`; the only dial is the WIDTH of a real object, and a widening `(s32)` cast is inert — AMENDS §35 (whose stated "only CSE-reuse canonicalizes" mechanism is byte-wrong) and does NOT apply inside a `switch` L20901 - **§199-G** — At TWO case nodes the switch-vs-if oracle is not blind — but the tell is ALL tests positive + a trailing `j default`, NOT the first test's polarity L21074 - **§206** — THE JTBL-CARVE DRAFTING IDIOM: the bounds check is the entry count, and an EMPTY case owns a slot (P31 S56) L22153 - **§222** — SWITCH vs IF-CHAIN, PART 3: source arm order IS emission order, a leading EMPTY case buys the median split, and a 2-way dispatch with a shared post-block is a `switch` (P31 S58) L22835 - **§232** — WHEN THE `jr` DELAY SLOT'S STORE STORES THE RETURN VALUE, TIE THEM WITH ONE PSEUDO **(single observation — not yet cross-confirmed)** (P31 S58) L23221 - **§256** — GOTOS IN THE TARGET'S BLOCK ORDER REPRODUCE SWITCH PLACEMENT WITHOUT SWITCH'S SIDE EFFECTS (P31 S58b) L24114 - **§222** — addendum (P31 S58b) — IF-CHAIN vs SWITCH: THREE MORE DISCRIMINATORS L24518 - **§260-A** — STAGE 2 IS PROVEN, AND THE WHOLE jtbl PIPELINE IS AUTOMATED AT THE GATE (P31 S59, same day) L24813 - **ADDENDUM** — to §8 — WHEN `INCLUDE_RODATA` NEEDS A STANDALONE `.s` YOU CAN'T CREATE, CARRY THE FRAGMENT AS A FILE-SCOPE `__asm__` BLOB L26222 - **ADDENDUM** — §NNN — sharpens §55a / §164-37 / §165-28 (switch-vs-tree cluster): A SHAPE THAT LOOKS LIKE A SWITCH DISPATCH CAN BE PLAIN NESTED `if`s WHOSE SHARED BODY WAS TRIPLICATED BY THE SOURCE AND THEN CROSS-JUMP-MERGED BACK DOWN L28223 - **ADDENDUM** — §NNN — sharpens §162a3/§60b: A `sll $v0,16 / sltiu $v0,1` ZERO-TEST OF A JUST-DECREMENTED HALFWORD IS A SIGNED-TEMP WIDTH TELL OUTSIDE ANY SWITCH/RANGE-TEST CONTEXT L28293 - **§295** — THE KERNEL-TRAP STUB: §81's jr-DETECTOR WITHOUT A TABLE IS A PsyQ SYSCALL TRAMPOLINE — ROUTE TO §265, NEVER INTO THE CARVE CHAIN (P31 S61; wave m0a, 9 cards byte-proven; resolves §182's held cluster) L29401 - **§298** — THE SHARED-TAIL POSITION DIAGNOSTIC: A FOLDED TAIL *BETWEEN* SWITCH ARMS MEANS PER-ARM DUPLICATED STATEMENTS, NOT A HOISTED POST-SWITCH STATEMENT (P31 S61; waves g0e/g0f, `func_80181B68`, ov_SC06_016, byte-proven 68/68) L29542 - **§302** — A RED BINARY IS A DRIFTED SPEC, NOT A MYSTERY: THE THREE CARVE-STATE INVARIANTS AND HOW TO DERIVE EACH FROM THE BYTES (P31 S62 T2; five reds healed in one session, 5/5, +39 held banks) L29719 - **§304** — SELF-DEFINING RODATA: WHEN A FUNCTION'S `.s` IS THE ONLY OWNER OF THE DATA IT REFERENCES, THE C BODY MUST DEFINE IT (P31 S62 T3; byte-proven md_MAIN_011/func_800D04F4) L29799 - **§305** — "CARVE-REFUSED" AT GATE TIME IS THREE NAMED, DETERMINISTIC CLASSES — NONE OF THEM A CARVE (P31 S62 T3; 28 resolver drafts autopsied 28/28) L29822 - **§308a** — A TWO-INSTRUCTION ARM STUB LAID *BEFORE* THE OTHER ARM AND REACHED ONLY BY A TRAILING `j` SURVIVES ONLY BEHIND A SHORT-CIRCUIT `&&` GUARD PLUS A SEPARATE RE-TEST; EVERY PLAIN if/else-if, GOTO-LADDER, NESTED-INVERTED-if AND 1-/2-NODE switch LETS jump1 INLINE IT (−2 ins) (P31 S63 t5e-t5i; byte-proven func_80180808) L30012 - **REFUTED** — claim — REFUTED: a block shared across TWO switch statements is ordinary forward cross_jump, not a (func_8001B0D4) L30638 - **§NNN** — REFUTED: A CODE BLOCK SHARED BY TWO *DIFFERENT* SWITCH STATEMENTS IS ORDINARY FORWARD `cross_jump`, NOT A SHAPE C CANNOT REACH — §164-11 ALREADY BANKS IT FROM PLAIN NESTED SWITCHES (P31 S66 round3, `func_8001B0D4`; ⚠ **UNPROVEN** — gate-REFUSED draft, closeness 68→45, never MATCHed) L30640 - **§322** — A PROBE THAT ANSWERS A *NECESSARY BUT NOT SUFFICIENT* QUESTION WILL PRICE BLOCKED WORK AS FREE: RUN THE REAL PLANNER WHEN THE PLANNER IS PURE (P31 S67; measured, 96 of 159 open jtbl functions) L30866 - **§338** — `jtbl_carve._sltiu_bounds` MISREADS A NON-SWITCH `sltiu` AS A BOUNDS CHECK, OVER-SPANNING THE TABLE (P31 S67; ov_SC06_022/func_80185B80, byte-diagnosed) L31171 - **§339** — A 2-CASE SWITCH OMITS THE LOW-BOUND RANGE TEST, SO THE PRESENCE OF `slti/bnez` BETWEEN THE `beq`s IS A **COUNT TELL** FOR A THIRD CASE NODE (P31 S67; byte-proven ov_SC02_005/func_80190538, 197 ins) L31181 - **§362** — TWO TRAPS WHEN A CARVE MOVES A STUB INTO THE `-O0` TU (P31 S68; byte-proven, 6 fns / 2,547 ins across ov_MAIN_012 / ov_SC02_037 / ov_SC03_107) L31682 - **§371** — ★★ — CARVING A **SINGLE-OBJECT MODULE BINARY**, AND THE spimdisasm RODATA-MIGRATION TRAP THAT FOLLOWS (P31 S68; byte-proven md_MAIN_003, func_800D0D6C 345 ins) L31890 - **§384** — ★★★ — A CARVE-CONFIG BANK IS RED UNTIL YOU RE-EXTRACT, AND THAT LOOKS EXACTLY LIKE A FALSE BANK (P31 S69; measured twice, cost one destroyed match) L32259 - **§387** — ★★ — **SPLIT-FOLD DISPATCH CLOBBER**: one switch case needs a reload, another must keep the fold (P31 S69; byte-proven main/func_80030F80, 343 ins, escalation 3 → 0) L32361 - **§322b** — ★★★ — THE CARVE CLASS IS COMPLETABLE, AND EVERY WORKTREE `CARVE-REFUSED` WAS AN INSTRUMENT VERDICT (P31 S69, Fable-3 audit; byte-proven end-to-end) L32667 - **§3-A.** — THE ORACLE HAS A HOLE: match_one cannot see a jump table (§405-A) L33098 - **§412** — ★★★ — §323 CARVE BLOCKER 2 WAS A REGEX THAT COULD NOT SEE PAST `__attribute__` (P31 S71) L33424 - **§426** — ★★★ — main's SWITCH FUNCTIONS WERE NEVER A CODEGEN WALL: ONE RODATA CARVE HAD BEEN MISSING SINCE PHASE 7 (P31 S72; 3 of the 11 "PROVEN gate-rejects" banked byte-identical in 14 s) L33855 - **§428** — ★★★ — A ZERO-BYTE CROSS-JUMP BARRIER: ADVANCE THE POINTER INSIDE EACH SWITCH ARM (P31 S72; `main/func_80026D64`, 218 ins, MATCH in 2 compiles) L33950 - **§431** — ★★★ — SPLITTING A 27,000-LINE TU AT ITS ORIGINAL BOUNDARIES: THE JTBL SPANS TELL YOU WHERE, AND THE COMPILER TELLS YOU WHAT CROSSES (P31 S72; `src/800.c` -> `800.c`/`800_b.c`/`800_c.c`, byte-identical with nothing banked) L34061 ### optimisation level (-O0/-O2) (22) - **§6** — Per-module optimization mixing — the -O0 boot module (Phase 7) L265 - **Detecting** — the opt level (do this first) L273 - **Build** — mechanism — per-file opt override (splat resegmentation) L307 - **§18** — Per-file `-O0` split inside an overlay/blob (Phase 19 T1) L1538 - **§38** — The WHALE `func_80144B9C` (770 ins): the -O0 struct-assign memcpy idiom + the -O0 reach-134 ×134 rollout (Phase 24 T7 §G, cheap Opus — no Fable5, no calls.c) L2546 - **§39** — The ×1→×134 giant-endgame: propagate a matched **-O2** giant via the NATIVE DEFINE-macro path (Phase 24 T7 §G close, 2026-07-08) L2556 - **§116** — Optimization level is a property of the FILE, not the function: read a family 0/N against the member's stub HOME (Phase 29 T79) L7911 - **§3-The** — finding: opt level is per FILE, so the file's contents must be opt-HOMOGENEOUS L8313 - **§127** — The `-O0` regime: the CONSTANT-OFFSET FOLD, and why `-O0` needs its own idiom set (P30 T3 wave, 15 targets) L8383 - **§3-The** — rest of the `-O0` regime (write PLAIN C, and mean it) L8401 - **§127a** — §71 (sibling-first) is the strongest `-O0` lever, and it beats the index L8411 - **§132** — The `JR-PAIR-IN-ONE-O0-OBJECT` "wall" was TWO instrument defects: a merged-double span the carve could not see, and a truncated object no rule deleted (P30 S29, `func_8013B83C` + `func_8013BD74`) L8604 - **§195-K** — At -O2 the §18 array-of-struct lever is a FRAME lever, not a length lever — but only when the N reads carry DISTINCT index expressions; with a SHARED index §18's +2-instruction residual is still alive at -O2 (the submitted "memory-loaded narrow index" precondition and unconditional length-neutrality are both falsified) L20307 - **§261** — THE -O0 ORACLE: DERIVE THE OPT LEVEL FROM THE TARGET, AND `$fp` IS NOT THE TELL (P31 S59) L24849 - **§261a** — THE -O0 FRAME-RELOAD GRAMMAR: reload COUNT disambiguates the C spelling (P31 S59, byte-proven) L24875 - **§265** — THE VERBATIM-ASM BANK LANE: A FUNCTION NO -O2 C CAN EVER MATCH BANKS AS A RAW `__asm__` BODY (P31 S59b; two banked cards, two in-tree precedents) L25018 - **ADDENDUM** — to §127 — the -O0 constant-offset fold keys on the MEMBER-ACCESS tree shape, not on the index being constant L29170 - **ADDENDUM** — to §261a — FOUR MORE -O0 DIALS BEYOND THE RELOAD COUNT (boot.c + md_MAIN_011/003, wave m0a/g0a/g0f, byte-proven) L29198 - **Addendum** — Addendum to §261a — the -O0 increment-operator copy also fires on the POINTER LOCAL itself (func_8001212C) L30473 - **Addendum** — Addendum to §164-XX/§165-06 — at -O0 a bare local IS a memory lvalue, so the increment ope (func_8001212C) L30477 - **§362** — TWO TRAPS WHEN A CARVE MOVES A STUB INTO THE `-O0` TU (P31 S68; byte-proven, 6 fns / 2,547 ins across ov_MAIN_012 / ov_SC02_037 / ov_SC03_107) L31682 - **§388** — ★★★ — THE **-O0 COLOURING ORACLE**: simulate `stupid.c` instead of grinding spellings (P31 S69; main/func_80011380 proved a C-level WALL at 6) L32384 ### family propagation & sweeps (122) - **§8d** — Templating a body INTO a TU must not CHANGE its declaration environment — demote the carried data externs (Phase 26 session 8, byte-proven on `func_8015AE2C` ×133) L502 - **§11** — Cross-binary dedup & code-sharing (Phase 11 — "one match unlocks many") L927 - **§3-The** — mechanism: game-code dedup is SOURCE-LEVEL, not an object swap (R-D1, the key lesson) L945 - **§3-The** — flat-blob overlay config (what the template encodes) L1090 - **§3-THE** — NON-4-ALIGNED-OVERLAY GOTCHA (≈75% of the fleet; fixed in the template + Makefile, automatic) L1098 - **§14** — Propagate a matched function across the fleet — `tools/dedup_propagate.py` (Phase 15) L1145 - **§19** — Scaling the toolkit waves — the recovery PIPELINE + the propagation CAP (Phase 19 T3) L1616 - **§24** — The `ov_SC01_077_a.c` split-file vein: split-aware propagation, but loose-typing-gated (Phase 21) L2104 - **§25** — The "schedule" class is mostly COALESCING (pin-crackable), not scheduling; + the gate two-stage + h_exact over-counts ×134 (Phase 21, cont.6) L2151 - **§3-h** — _exact OVER-COUNTS ×134 — verify shareability before crediting a class's "reach-134" (R14) L2196 - **Where** — this leaves the reach-134 tail (cont.6 option-3, now CONFIRMED byte-backed) L2252 - **§28** — Banking a "close=0 gate-rejected" giant: the canonical-extern recovery (Phase 22 T1, byte-proven on func_8015126C ×134) L2344 - **§28c** — The close=0 recovery is NOT fully exhausted (§26 corrected, R14); + the dedup_propagate registry-skip recovery (Phase 22 T2) L2371 - **§28b** — The struct-walled close=0 giant (§28 case #3) IS bankable: the engine_types.h type-lift (Phase 22 T2, byte-proven on func_80156B74 ×134) L2376 - **§28d** — The "macro-extern-injection" lever: freeing reach-134 inline matches dedup_propagate skips as "not self-contained" (Phase 23, `tools/inject_capped_externs.py`) L2385 - **§30** — Fable5Max cracks §20/§10 "unsteerable" from the gcc SOURCE: store-vs-load is a `/s` aliasing flag, the def-side wall has a macro escape, + the birthing-boost (Phase 23, byte-proven on giant `func_8014EE14` 248 ins ×134) L2401 - **§34** — The `func_80138ED0` giant crack: gcc-2.7.2's **3-qty sort bug** + the **zero-byte asm allocation toolkit** + the **giv-init fence** (Phase 24 T5; Opus→close=21, Fable5→MATCH ×134) L2473 - **§38** — The WHALE `func_80144B9C` (770 ins): the -O0 struct-assign memcpy idiom + the -O0 reach-134 ×134 rollout (Phase 24 T7 §G, cheap Opus — no Fable5, no calls.c) L2546 - **§39** — The ×1→×134 giant-endgame: propagate a matched **-O2** giant via the NATIVE DEFINE-macro path (Phase 24 T7 §G close, 2026-07-08) L2556 - **§40** — Structural families: the MECHANICAL symbol-remap (crack one exemplar → remap the rest, ~0 tokens) (Phase 25 T3/T7, 2026-07-08) L2572 - **§40a** — The DECL-RECONCILE pass (type-lift so remapped drafts compile in the sibling TU) (Phase 25 T7.2, 2026-07-08) L2620 - **§40b** — The reloc-tracker blind spot: the indexed-global idiom that hid the "reach-1 tail" (Phase 26 Task 1, 2026-07-11, byte-verified V0/V1) L2653 - **§40c** — The h_seq per-sibling reconcile: templating a reconcile-class crack ×134 (Phase 26 Task 8, 2026-07-12, byte-proven) L2695 - **§41c** — T7-M2: the ×134 def-side-wall sweep via per-sibling RE-reconcile (Phase 25, 2026-07-10; 4,389 banks, ~0 agent tokens) L2873 - **§42** — The F-band ≤28 regalloc crack wave: register-pin/DENSITY levers beat the permuter (Phase 25 T7 F-band, 2026-07-10; Ultracode 9-worker wave, 4/9 banked byte-identical, 266 swept ×134) L2934 - **§42e** — propagating a CRACK ×134: the def-finder bug + the byte-drift residual (the "remap-fail" misdiagnosis) L3155 - **§43** — The K&R s16-param definition DISSOLVES the "narrow-param wall" for by-value register args (Phase 25 task A, Fable5 crack of the 369-ins giant `func_80166994` ×134, 2026-07-11) L3229 - **§45** — The flagship `func_80133CD4` crack (399 ins ×134): the merged-variable permutation-breaker + the 1-death local-alloc gate (Phase 25 task A giant escalation, Fable5 gdb-on-cc1, 2026-07-11) L3332 - **§46** — The `func_80178D40` crack (890 ins ×134, the heaviest core in the game): four LOOP-STRUCTURE levers cheap-Opus found by reading loop.c/jump.c/cse.c (Phase 26 session 8, 2026-07-13) L3347 - **§47** — The live-length SLIDER: splitting a global.c allocno-priority TIE with one zero-byte asm (Phase 26 session 8, Fable5 Max, byte-proven on `func_8017BEBC` 952 ins ×113) L3399 - **§49** — The LUID DIAL: a zero-byte SCHEDULING dial (the sched.c analogue of §47) — `func_8017A4AC` (536 ins ×134), Phase 26 session 8 L3561 - **§52** — The WALKER-FAMILY skeleton: 6 regalloc-order levers + a deeply-characterized intrinsic wall (`func_80178004`, 165 ins ×134; Phase 26, Fable5, 2026-07-15) L3947 - **§3-The** — 6 levers (the "walker-family skeleton" — apply to the 12 siblings; levers 1-5 retire ~half the residual) L3958 - **§53** — SWEEP A FAMILY WITH THE TOOL ITS EXEMPLAR NEEDED: the jr/switch carve, and how omitting it manufactured the "families don't template" doctrine (Phase 28 T1, 2026-07-15) L4062 - **§55c** — Sizing the propagate: a TARGETED propagate is ~4 min/core, and "it's slow" was a BROKEN-TREE ARTIFACT L4175 - **§54** — `--fix-def-sig`: the member's CANONICAL DECLARATION is a build step too (tiny-IMM mega-pools, +4,801, Phase 29 T6, 2026-07-16) L4197 - **§56** — Banking a hand-drafted GIANT into its exemplar TU: self-contained draft vs live-TU decls, 4 reconciliation tactics (`func_8013FAF8`, 312 ins ×138, Phase 29 T4, 2026-07-17) L4221 - **§56b** — PROPAGATING an h_seq giant: the exemplar's externs MUST be fleet-canonical, not the draft's types L4266 - **§57** — The SELF-decl normalize: the sibling's OWN caller declares the templated fn divergently (the third §17a-1 direction; `tools/normalize_self_decls.py`, func_801670E4 ×137, Phase 29, 2026-07-18) L4290 - **§57a** — Two NSD corrections + the SURGICAL-ONLY law + the honest broad-sweep yield (Phase 29, 2026-07-18) L4337 - **§59** — Three h_seq sweep-residual classes match_one/the-exemplar-bank don't reveal (Phase 29 crack-wave close, 2026-07-18) L4411 - **§3-Two** — corollaries worth remembering L4484 - **§65a** — The blast-radius taxonomy (makes §61's law structural instead of remembered) L5064 - **§3-Giv** — record order (the §70 family) L5794 - **§75** — A propagation cap is usually a MINORITY-SPELLING SOURCE OVERLAY, not a wall: census the carried extern before believing the exclusion message (Phase 29 SESSION-19, `func_8014F3E8` ×4 → ×138) L5900 - **§75a** — The exclusion classes, enumerated with named causes (Phase 29 SESSION-19, the 134-binary `dedup_extend` sweep) L5959 - **§75b** — A body's preamble can carry `#define`s, not just `extern`s; extraction lifts only the externs (Phase 29 SESSION-19, `func_80165CA0` ×3 → fleet) L5982 - **§76** — The allocno CLASS (local vs global) is the dominant regalloc lever, and C reaches it ONLY through declaration scope and variable reuse (Phase 29 SESSION-19, behemoth #3 `func_8017F510` 1,511 ins, 97 → MATCH, pin-free) L6062 - **§77** — Every extraction tool carries a NARROW hard-coded preamble set; anything outside it silently caps the body's reach. Diff the preamble before you gate. (Phase 29 SESSION-19 — three variants in one session, two different tools) L6118 - **§84** — The DERIVED-OFFSET remap bug: a hand-computed literal that encodes the DISTANCE between two per-overlay symbols, and why `match_one` is structurally blind to it (Phase 29 SESSION-20, `func_8013D53C`) L6506 - **§86** — Pinned-exemplar templatability is a PER-FAMILY property, not a per-member rate; and the §42e pin guard is now over-conservative (Phase 29 SESSION-20) L6623 - **§3-THE** — LAW: all-or-nothing PER FAMILY L6634 - **§3-Why** — the two live families differ from the three dead ones — the open question L6661 - **§3-The** — cheap discriminator, before spending a sweep L6700 - **§89b** — the parallel gate farm existed; the family path could not reach it (`tools/sweep_parallel.py`) L6779 - **§91** — A structure-TRANSFER is only valid where the structure corresponds: the `--like` role trap (Phase 29 SESSION-21, `func_8012AAAC` ×137) L6876 - **§94** — A family sweep's `0/N` is a TYPE-CARRY failure until proven otherwise: lift the exemplar's local types, ALL of them, transitively (Phase 29 SESSION-21, `func_8016B6BC` 0/137 → 137/137) L6981 - **§105** — A gate's revert must survive an EXCEPTION, not just a failure (Phase 29 T53, `jtbl_family_bank`) L7465 - **§107** — A lever wired into ONE gate path is a lever most families cannot reach (Phase 29 T56, `func_80144090` 0/136 → 136/136) L7547 - **§108** — Diagnosing a family `0/N`: the four causes, and the third opt-in lever (Phase 29 T59) L7585 - **§111** — The distinct-code metric is not noisy: a family pays it only if its members are byte-VARIANT (Phase 29 T66) L7715 - **§116** — Optimization level is a property of the FILE, not the function: read a family 0/N against the member's stub HOME (Phase 29 T79) L7911 - **§123** — PROPAGATE A FAMILY WITH THE TOOL ITS TIER NEEDS: `dedup_propagate` is h_exact-only; its refusals are statements about the TOOL (P30 wave 1, 2026-07-30) L8150 - **§124** — A "not matched" verdict can mean the definition is there under a DIFFERENT C NAME: the asm-label alias blind spot (P30 SESSION-28, `func_8016191C` ×137) L8187 - **§124a** — a family sweep's `0 matched-exemplar families` may be a FILTER, not a wall L8232 - **§134** — MULTI-LINE BLINDNESS: one root cause, four faces, in `family_remap`'s preamble scanner (P30 S6, 190 zero-crack families) L8745 - **§136c** — SIBLING-FIRST is a DERIVATION shortcut, not just a conflict fix (the fastest route in a family wave) L9103 - **§138** — The propagation lanes: a gate refusal is a DECLARATION, and which lever you owe depends on blast radius L9449 - **§142** — An open stub whose `h_exact` class is MATCHED elsewhere is FREE. Propagate the body; do not gate a draft. (P30 S39, +7,710 ins in two commands) L9812 - **§143** — `cast_call_sites` read a RETURN STATEMENT as a prototype and deleted it. A 0/39 sweep became 18/39. (P30 S40) L9868 - **Then** — propagation returned 0/137 TWICE — both times a missing TYPE L10034 - **§3-A.** — The frame has THREE strata, and stratum 3 is unreachable from C L10075 - **§3-E.** — A `qty_compare` TIE is not spelling-reachable — recognise it and stop L10117 - **Consequence** — for the family (a real scheduling decision) L10129 - **§150** — A register ROTATION across symmetric blocks is VARIABLE-IDENTITY evidence, not an allocator tie (P30 S43, `func_8017C6F4`, 947 ins ×4) L10346 - **§151** — THE GHOST WEDGE: when a load-before-store transposition is unreachable by ANY statement order (P30 S43, `func_8017EF68`, 969 ins) L10401 - **When** — to reach for it L10441 - **§152** — BYTE SIZE is the family key that name- and h_seq-grouping both miss (P30 S43, the 0xECC family: 1 crack → 12 overlays → 11,364 ins) L10452 - **§156** — an ORPHANED reconcile poisons the fleet: `dedup_propagate`'s kept edit (S45 p6/p7) L10674 - **§160** — THE REACH-15 WAVE HARVEST: an align-1 block move, and the instrument that called it a wall (P30 S47) L10927 - **§162** — S48 WAVE-1 HARVEST (P30, 2026-08-11): the reach-ordered sibling campaign's first 12 targets L11048 - **§163z** — THE UNVETTED REMAINDER (do not cite as law; each needs a dedupe pass) L11862 - **§3-The** — ADDRESS-CLASS TABLE: which load/store pairs even REACH the `/s` clause (P30 S48 wave 4, `func_80185B44`, ov_SC03_014) L14396 - **§168** — THE COUSIN TIER (P30 S49, 2026-08-12): h_seq's exact-hash brittleness, measured — and the similarity map above it L16265 - **§171a** — THE MECHANICAL A-PROP DRAFT (P30 S50): 256 members banked with no agent in the loop L16474 - **§171b** — THREE CARRIES THE MECHANICAL DRAFT NEEDS (P30 S50, banking the top-reach families) L16524 - **§3-G.** — TWO MODELLING TRAPS THAT COST THESE AGENTS SWEEPS OF HUNDREDS OF COMPILES L17351 - **§193-E** — A varying-address (pointer) load is re-emitted once per CSE-LIVE INTERVAL, and naming it in a C local is the only C-level lever over that count — no store SPELLING has any reach L18693 - **§194-E** — The wave card's `exemplar` is the TARGET ITSELF on 42/73 wave-U and 36/71 wave-T cards — a construction consequence of `atlas.py:657` (exemplar = max-nins OPEN member) meeting `build_wave_atlas.py:166` (one card per gid); and the shipped §193-A `seed_ref` is same-binary on 0/51, so no card field can ever name a destination-TU sibling L19199 - **§195-E** — A 0/1 materialised at a JOIN immediately before the controlling `beqz`/`bnez` proves the source NAMED the condition — a truth expression in an `if`'s controlling position reaches `do_jump`, which has no value path L19993 - **§199-B** — A permutation sweep that holds ANY statement fixed is not a sweep: the statement an agent pins as "obviously load-bearing" is the one carrying the signal, and the partial sweep returns a FLAT residual that reads as proof of order-invariance L20808 - **§203** — A DEDUPED TYPEDEF MUST PRECEDE EVERY SPLICE POINT, NOT JUST ITS OWN (P31 S56) L21527 - **§225** — THREE CONTROL-FLOW SHAPES NO STRUCTURED SPELLING REACHES (P31 S58) L22975 - **§30** — addendum (P31 S58b) — THE ANONYMOUS STRUCT MEMBER REF GRANTS `/s`, AND THAT IS A TWO-FOR-ONE L24199 - **§3-1a.** — The §266 sweep — every solo-lever A/B run for this batch L25526 - **ADDENDUM** — to §179-D (GTE macro reference family) — `gte_SetRotMatrix`/`gte_SetTransMatrix` bodies L25717 - **ADDENDUM** — to §82 — struct copies must stay MEMBER-WISE, not block-moved, to match a spill-slot save L25743 - **ADDENDUM** — to §136d-1 (RC-12, the `$0`-add / opaque-copy family) — two symptoms beyond "compare reads the wrong register" L25781 - **§282** — gcc's OWN LOOP REVERSAL PUTS THE COUNTER INIT AFTER THE HOISTED MOVABLES — a position no hand-written down-count can reach (P31 S60; wave cf, func_80180DD8, ov_SC04_005, byte-proven) L27036 - **ADDENDUM** — to the zero-byte-asm-slider family (§47 / §148-C / §153) (func_800CB874, md_MAIN_040 — wave dj; open tension with a more cautious dm-wave card — see closing) L27955 - **ADDENDUM** — the zero-emission-asm family gains a REF-SLIDER PLACEMENT LAW and a paired RESTORER (func_800CB900, md_MAIN_026) L28165 - **ADDENDUM** — §NNN — sharpens §37/§124 (unspecified-parameter-list family): DERIVE A CALLEE'S ARITY LOWER BOUND FROM ITS OWN `.s` STACK-ARGUMENT READS, NOT FROM ANY SINGLE CALL SITE L28326 - **ADDENDUM** — to §199-F family (func_8017EFB0, ov_SC02_021, wave cu) L28478 - **§287** — A STACK-FRAME HOLE BELOW TWO ADDRESS-TAKEN AGGREGATE LOCALS IS A LEADING PAD MEMBER OF ONE COMBINED STRUCT, NOT SEPARATE LOCALS OR A REGISTER PIN (P31 S60/dj; `func_8017D104`, ov_SC06_027, byte-proven 47/47) (P31 S60; waves #, byte-proven) L29086 - **ADDENDUM** — to §127 — the -O0 constant-offset fold keys on the MEMBER-ACCESS tree shape, not on the index being constant L29170 - **§296** — THE FRAME CHECK OUTRANKS THE ATLAS LEVER: READ PROLOGUE/EPILOGUE BEFORE DRAFTING ANY C — A REAL TELL CAN LIVE INSIDE AN UNREACHABLE FRAGMENT (P31 S61; wave m0a, 16 cards byte-proven; extends §179-C) L29456 - **§297** — ONE GIV SERVING MIXED-WIDTH LOADS *AND* A STORE NEEDS STRUCT-MEMBER SPELLING; CAST/INDEX SPELLINGS RE-SPLIT THE PSEUDO (P31 S61; wave m0a, `func_800347C8`, main, byte-proven 31/31) L29499 - **§307** — THE BRUTE-FORCE-THE-STATEMENT-ORDERS LEVER HAS A BOUND: A FAN-OUT COPY'S PRIORITY IS SCHEDULER-INTERNAL, AND NO SOURCE ORDER REACHES IT (P31 S63; byte-evidenced NEGATIVE result, main wave) L29939 - **§308a** — A TWO-INSTRUCTION ARM STUB LAID *BEFORE* THE OTHER ARM AND REACHED ONLY BY A TRAILING `j` SURVIVES ONLY BEHIND A SHORT-CIRCUIT `&&` GUARD PLUS A SEPARATE RE-TEST; EVERY PLAIN if/else-if, GOTO-LADDER, NESTED-INVERTED-if AND 1-/2-NODE switch LETS jump1 INLINE IT (−2 ins) (P31 S63 t5e-t5i; byte-proven func_80180808) L30012 - **§314** — AN IF/ELSE-IF ABS-RANGE CHECK'S C SPELLING IS INERT: FOUR STRUCTURALLY DIFFERENT REWRITES ALL COMPILE BYTE-IDENTICAL, AND NONE REACHES A TARGET THAT SINKS THE NEGATIVE ARM INTO AN OUT-OF-LINE BLOCK (P31 S65; UNPROVEN, gate-refused draft func_80181720) L30241 - **§NNN** — REFUTED: A CODE BLOCK SHARED BY TWO *DIFFERENT* SWITCH STATEMENTS IS ORDINARY FORWARD `cross_jump`, NOT A SHAPE C CANNOT REACH — §164-11 ALREADY BANKS IT FROM PLAIN NESTED SWITCHES (P31 S66 round3, `func_8001B0D4`; ⚠ **UNPROVEN** — gate-REFUSED draft, closeness 68→45, never MATCHed) L30640 - **§323** — CARRYING FILE-SCOPE TYPES BETWEEN SPLIT TUs: DEDUPE BY NAME, SKIP HEADER-PROVIDED, AND THE GUARD TRAVELS WITH THE BLOCK (P31 S67; ov_SC02_000, two defects fixed, one open) L30896 - **§341** — AN HImode STORE TEMP REWEIGHTS A sched2 TIE-BREAK THAT NO STATEMENT ORDER CAN REACH (P31 S67; byte-proven ov_SC03_006/func_801823B8, last 4 ins) L31243 - **§355** — A REMAPPED SIBLING'S **SOURCE BIAS IS NOT ITS EMITTED BIAS** — DO NOT HAND-SHIFT OFFSETS TO MATCH THE ASM (P31 S68; byte-proven ov_SC07_007/func_8013DD68, 187/187 in 2 iterations) L31560 - **§368** — ★★★ — THE **RELOAD-REMAT CONSTANT**: REACH A REGISTER NO PIN CAN REACH (P31 S68; ov_SC03_105/func_80187A30, 339 ins, fable escalation closed 8 → 0 in ONE edit) L31792 - **§379** — ★★★ — **MEM_IN_STRUCT_P**: THE SAME LOAD, WRITTEN AS A STRUCT MEMBER, SCHEDULES WHERE A CAST CANNOT (P31 S69; byte-proven main/func_80021284 220 ins and main/func_8002D904 217 ins, found INDEPENDENTLY by two agents) L32164 - **§396** — ★★★ — SIX LEVERS FROM THE S69 SINGLETON ROUND, INCLUDING ONE THAT ONLY A `COND_EXPR` REACHES (P31 S69) L32737 - **§398** — ★★★ — `family_remap` CARRIES THE **SOURCE** TU's DECL ENVIRONMENT INTO A DESTINATION THAT ALREADY OWNS THOSE NAMES (P31 S69; measured 3 banked of 22) L32835 - **§3-B.** — THE SCHEDULER DIALS (the dominant residual family this wave) L33108 - **§408** — ★★★ — §406 REFUTED AS A SWEEP: THE SHAPE IS THE FAMILY, THE DISAGREEMENT IS THE DEFECT (P31 S71; 0 MATCH / 14 applied, 0 / 210) L33209 - **§420** — ★★★ — A MULTI-CLUSTER SYMBOL REBASE, AND THE BARE-NAME DEDUP THAT HID THREE QUARTERS OF IT (P31 S71; 4 banked in 57 s) L33692 - **§421** — ★★★ — A `la $tN` + `addiu` PAIR CAN BE A **RELOAD** ARTIFACT THAT NO C SPELLING REACHES (P31 S71; byte-proven `md_SC07_003/func_801A293C`, 313 ins, 6 → 0) L33729 ### integration / TU plumbing (78) - **§8c** — Splitting a TU means rebuilding its DECLARATION ENVIRONMENT, not moving text (Phase 26 session 6) L456 - **§8d** — Templating a body INTO a TU must not CHANGE its declaration environment — demote the carried data externs (Phase 26 session 8, byte-proven on `func_8015AE2C` ×133) L502 - **§9.3** — Make it the build: resegment + swap + resolve (`tools/psyq_integrate.py`, libcd DONE) L704 - **§9.4** — Integrating a SECOND library (libgs block 6 after libcd) — multi-library gotchas L731 - **§9.5** — Integrating a WHOLE multi-block library in one call (full libgs — Phase 7 session G) L759 - **§17a** — The TOOLKIT at WAVE scale (Phase-18 Step-3b/Step-1 — measured) + the pipeline-integration gotchas L1464 - **§3-THE** — CAP: at this tail the match_one→gate gap is the LOOSE-TYPING CALL-GRAPH wall (not cheap plumbing) L1656 - **Diagnostic** — lesson: a failed in-TU build leaves a STALE `.o` L1673 - **§28d** — The "macro-extern-injection" lever: freeing reach-134 inline matches dedup_propagate skips as "not self-contained" (Phase 23, `tools/inject_capped_externs.py`) L2385 - **§30a** — §30 generalizes to the FULL near-miss backlog (via STANDARD Opus agents, not just Fable5) + 2 more steer levers + the mechanical-integration throughput unlock (Phase 23 (a)) L2413 - **§40a** — The DECL-RECONCILE pass (type-lift so remapped drafts compile in the sibling TU) (Phase 25 T7.2, 2026-07-08) L2620 - **§42a** — addendum — wave 2 (residuals + 29-100 band): iso-MATCH ≠ real-TU bank, the memcpy→struct-assign fix, +5 levers (2026-07-10b) L2987 - **§42c** — addendum — wave 3 (Max orchestrator + CORRECTED Ultracode fan-out, 2026-07-10c): the real-TU-faithful parallel harness (rtu_match) + 7/9 crack, ZERO iso-drift L3067 - **§56** — Banking a hand-drafted GIANT into its exemplar TU: self-contained draft vs live-TU decls, 4 reconciliation tactics (`func_8013FAF8`, 312 ins ×138, Phase 29 T4, 2026-07-17) L4221 - **§61** — Task 14: the gate ladder's missing stage is the ARITY pre-pass, and it is TU-side not draft-side (Phase 29, 2026-07-21) L4579 - **§61a** — The Task-5 wave: 11/12 MATCH, 0 banked — three DISTINCT integration walls, each now named (Phase 29, 2026-07-21) L4640 - **§63** — The fresh-138 DEF-SIDE blocker: fix the HEADER decl, not the draft (`fix_header_decl.py`, Phase 29 SESSION-13, 2026-07-23) L4911 - **§63** — UPDATE (Phase 29 SESSION-14) — `fix_header_decl`'s "SAFE" verdict is FLEET-BLIND; it MUST be R22-validated L5034 - **§65** — The stranded-draft recovery: BLAST-RADIUS TIERS, and the per-overlay de-macroize that refutes §20's DEF-conflict wall (`tools/demacroize.py` + `tools/blocker_probe.py`, Phase 29 SESSION-16, 2026-07-24) L5049 - **§65b** — The escape: de-macroize the instantiation, don't touch the shared header L5079 - **§65f** — The de-macroize lever's BOUNDARY, measured: byte-neutral 14 times of 15, and the 15th is why the gate exists L5152 - **§65g** — Where the cheap levers STOP: the local-type and in-TU-self-decl classes did not yield L5173 - **§85** — The RETURN-axis fleet widen is ALL-OR-NOTHING: widening the shared header alone guarantees a conflict in the source overlay (Phase 29 SESSION-20, `func_8012CC88` / `func_8014D12C`) L6573 - **§95** — `reconcile_tu` dropped the SIBLING declarators of a multi-symbol `extern` line (Phase 29 SESSION-21, `func_80176218`) L7017 - **§96** — The same rewrite, one shape down: `reconcile_tu` matched statements to lines by TEXT, so every COMMENTED declaration was silently skipped (Phase 29 SESSION-22, `func_80176218` banked) L7052 - **§3-Two** — `reconcile_tu` bugs found underneath, one introduced while fixing the other L7224 - **§100** — Prefer the DRAFT-LOCAL fix: a type only one function uses belongs in its BODY, not in a shared header (Phase 29 SESSION-22, `func_80175DA8` 0/137 → 137/137) L7250 - **§102** — A PLUMBING verdict can MASK a DIFF; and K&R is not always a codegen change (Phase 29 SESSION-22, `func_8016EC0C`) L7306 - **§103** — A FILE-scope `extern` in a shared overlay TU is a GLOBAL constraint on every LATER function; move the DECL, not the draft (Phase 29 T48/T51, `func_80135260` — the fleet-wide half) L7341 - **§109** — Conforming a definition to a shared header: fix the NAMES, then check the RETURN precondition (Phase 29 T60) L7634 - **§112** — A macro-scoped declaration only collides where the macro is INSTANTIATED (Phase 29 T67/T69, `audit_header_sigs.py`) L7764 - **§114** — The THIRD decl axis: a CALLEE the draft declares differently from the target TU (Phase 29 T76/T77) L7842 - **§3-The** — integration idioms (these decide whether a byte-correct draft BANKS) L8838 - **§3-The** — declaration surface (integration, not codegen) L8975 - **Reconciling** — a gate-refused draft: which way you edit depends on WHERE the TU's decl is L9599 - **§3-The** — same swallow, twice more, in the integration spine L9743 - **§3-A.** — Payload word0 is a global MODULE ID; code starts after the header L10561 - **§162** — THE LICM PAIR: what makes an address a movable AT ALL, and why the preheader order is the body order (P30 S47, `ov_MAIN_012`) L11177 - **§166** — THE DESTINATION-TU ORACLE (P30 S48): the seven-attempt bug that was never codegen L14956 - **§173** — THE STORED-PLUMBING RECOVERY RECIPE (P31 T6): symfix-first, per-group isolation, and where the verdicts have no drafts L16670 - **§176d** — THE CONFLICT TABLE MUST BE SEEDED FROM THE TU, AND KEYED PER FILE (P31 S52, 2026-08-15) L16867 - **§180b** — WHAT THE PRE-GATE LADDER ACTUALLY FINDS IN A COLD PILE (the shape of integration debt) L17883 - **§185** — EDIT THE SIDE THAT IS CHEAP TO VERIFY, AND CHECK A TU RETYPE AT ITS USE SITES L18101 - **§194-E** — The wave card's `exemplar` is the TARGET ITSELF on 42/73 wave-U and 36/71 wave-T cards — a construction consequence of `atlas.py:657` (exemplar = max-nins OPEN member) meeting `build_wave_atlas.py:166` (one card per gid); and the shipped §193-A `seed_ref` is same-binary on 0/51, so no card field can ever name a destination-TU sibling L19199 - **§195-J** — GTE / PsyQ op CALL-vs-INLINE is a PER-SITE SOURCE FACT, not a TU style — both forms coexist in one TU (measured in 2 TUs), and the tell is the target's own opcodes (`lwc2`/`sqr`/`swc2` vs `jal`), not the sibling. Costs -8 ins on func_8018505C. Corollary: the game's inline `sqr` macro emits TWO hazard nops, the SDK's `Square0` body emits ONE — so the inline form is provably not `Square0` inlined (a second instance of §187's SDK-vs-game GTE nop divergence). L20263 - **§199-D** — A narrow UNSIGNED value compared in an ordered `if` emits `sltiu`/`sltu`; the only dial is the WIDTH of a real object, and a widening `(s32)` cast is inert — AMENDS §35 (whose stated "only CSE-reuse canonicalizes" mechanism is byte-wrong) and does NOT apply inside a `switch` L20901 - **§200** — THE ALIAS IS THE UNIVERSAL DECLARATION ESCAPE: stop negotiating with the TU's spelling (P31 S55) L21140 - **§201-A** — §150-B applies to `decl_prior`'s DEF row: for an overlay-window symbol the banked "definition" is usually another overlay's function, and the card ranks it ABOVE the destination TU L21199 - **§203** — A DEDUPED TYPEDEF MUST PRECEDE EVERY SPLICE POINT, NOT JUST ITS OWN (P31 S56) L21527 - **§210** — THE SINGLE-BIT MASK IN A BOOLEAN TAIL: `andi K ; sltu $zero,v` vs `srl n ; andi 1` is a STATEMENT-SHAPE dial, not an operator choice (P31 S58) L22369 - **ADD-2** — → §42a addendum — A SHARED CONSTANT *NAMED IN A LOCAL* ACROSS A `jal` IS AN ISO→TU DRIFT HAZARD; WRITE BARE LITERALS L25137 - **ADD-3** — → §236, item 10 — THE UN-DELETED `INCLUDE_ASM` STUB IS A DUPLICATE DEFINITION L25149 - **ADD-2** — → §236 addendum (item 1 corollary) — THE SILENT-SPLICE DECLARATION LADDER: WHERE THE TU HAS NO SPELLING, UNPROTOTYPED `()` BEATS THE FLEET VOTE L25367 - **§273** — A standalone compile is the WRONG oracle for a TU-destined draft (P31 S59) L25619 - **ADDENDUM** — to §134 — a typedef defined BELOW the splice point is stripped anyway L25687 - **ADDENDUM** — to §8 — WHEN `INCLUDE_RODATA` NEEDS A STANDALONE `.s` YOU CAN'T CREATE, CARRY THE FRAGMENT AS A FILE-SCOPE `__asm__` BLOB L26222 - **§280** — THE CURSOR'S DECLARED TYPE PICKS `sltu` vs `slt`: a `T*` bound test is UNSIGNED by C rule, an integer cursor is signed (P31 S60; wave cf, func_800CAE74, md_MAIN_031, byte-proven) L26956 - **§NNN** — A LOOP CURSOR'S C TYPE (POINTER vs PLAIN INTEGER) SELECTS `sltu` vs `slt` FOR ITS BOUND TEST, INDEPENDENT OF THE VALUES INVOLVED (P31 S60; `func_800CAE74`, md_MAIN_031, byte-proven; cross-confirmed same wave by `func_8017F2A4`, ov_SC03_096) L26957 - **ADDENDUM** — to §199-G — A `default:` LABEL GROUPED ONTO THE LAST CASE REMOVES THE `j default` TAIL, EVEN THOUGH THE 2-NODE HEADER STAYS ALL-POSITIVE L27411 - **§301** — AN INTERNAL `j` CARRIES `R_MIPS_26 .text`: rtu/match_one "MATCH" COULD NOT SEE WHICH LABEL A `j` TAKES — FIXED (`jrel`), AND THE TWO DRAFT SHAPES IT HID (P31 S62 T1; byte-proven 2/2, negative-controlled over 3,297 stubs) L29671 - **Addendum** — Reversed-operand sltu then xori 1 means unsigned less-or-equal (func_8017D948) L30505 - **§NNN** — REFUTED: A `sw %lo(SYM)($at)` IN A JUMP'S DELAY SLOT WITH ITS `lui $at` STRANDED ABOVE THE JUMP IS **ASSEMBLER** MACRO-EXPANSION, NOT A cse SPLIT — OUR PIPELINE CANNOT EMIT IT FROM ANY C, AND THE +1 IS A `maspsx` GAP (P31 S66 round2, `func_8005DBD8`, byte-probed) L30591 - **§320** — THE §43 "RETURN-TYPE FLIP PAIR" IS **NOT** TU-EDIT-REQUIRED: THREE DRAFT-ONLY ESCAPES (P31 S66; byte-proven func_800CCBC0, func_800D30D0, func_800D2A24) L30786 - **§323** — CARRYING FILE-SCOPE TYPES BETWEEN SPLIT TUs: DEDUPE BY NAME, SKIP HEADER-PROVIDED, AND THE GUARD TRAVELS WITH THE BLOCK (P31 S67; ov_SC02_000, two defects fixed, one open) L30896 - **§324** — THE ARITY-SELF WALL NEEDS *BOTH* HALVES: A K&R DEFINITION **AND** A NO-PROTO TU DECL; EITHER ALONE STILL FAILS (P31 S67; rtu-proven ov_SC01_005/func_8017FBCC, 14 instances measured) L30949 - **§337** — THE CC1-ONLY BLOCKER CLASS: `blocker_probe`'s STATIC ORACLE REPORTS "none" AND THE WHOLE-TU COMPILE STILL FAILS (P31 S67; ov_SC04_011/func_801827DC, md_MAIN_027/func_800CB4A4) L31157 - **§356** — MEASURE A DRAFT IN THE TU IT WILL LIVE IN, NOT IN THE STANDALONE PROBE (P31 S68; measured over 47 stored drafts) L31574 - **§362** — TWO TRAPS WHEN A CARVE MOVES A STUB INTO THE `-O0` TU (P31 S68; byte-proven, 6 fns / 2,547 ins across ov_MAIN_012 / ov_SC02_037 / ov_SC03_107) L31682 - **§367** — RECONCILING A DECL CONFLICT BETWEEN TWO DRAFTS FOR THE SAME TU (P31 S68; main) L31777 - **§376** — ★★★ — A STANDALONE `match_one` CLOSENESS OF 0 IS A CLAIM ABOUT THE **BODY**, NEVER ABOUT THE **TU** (P31 S69; measured 0/28) L32055 - **§378** — ★★★ — THE **SELF-CALLER CAST**: LET A TU KEEP CALLING THE FUNCTION IT IS ABOUT TO DEFINE (P31 S69; byte-proven ov_SC04_010/func_8017D6CC) L32114 - **§385** — ★★★ — THE **SCHED2 PRIORITY-DONOR ASM**: closing the "hoisted-invariant vs IV-init preheader swap" class (P31 S69; byte-proven main/func_80038A58, 347 ins, fable escalation 2 → 0) L32309 - **§378c** — ★★ — THE FIFTH DECL-BLOCKER VARIANT: THE DRAFT REDECLARES WHAT THE TU ALREADY OWNS (P31 S69) L32722 - **§398** — ★★★ — `family_remap` CARRIES THE **SOURCE** TU's DECL ENVIRONMENT INTO A DESTINATION THAT ALREADY OWNS THOSE NAMES (P31 S69; measured 3 banked of 22) L32835 - **§3-D.** — INTEGRATION IS STILL THE BOTTLENECK, AND THE TU IS THE AUTHORITY L33140 - **§415** — ★★ — A FILE-SCOPE DECL MAKES gcc-2.7.2 MERGE THE TU'S LATER *BLOCK-SCOPE* EXTERNS INTO IT (P31 S71; byte-proven `ov_SC04_011/func_80180B24`, 215 ins) L33547 - **§423** — ★★★ — "MATCH IN ISOLATION + GATE REJECTS + CAUSE NOT DETERMINED" ⇒ GREP THE TU FOR A FILE-SCOPE TYPEDEF THE DRAFT ALSO CARRIES (P31 S71; byte-proven `ov_SC03_092/func_8017FA74`) L33780 - **§431** — ★★★ — SPLITTING A 27,000-LINE TU AT ITS ORIGINAL BOUNDARIES: THE JTBL SPANS TELL YOU WHERE, AND THE COMPILER TELLS YOU WHAT CROSSES (P31 S72; `src/800.c` -> `800.c`/`800_b.c`/`800_c.c`, byte-identical with nothing banked) L34061 ### build graph, splat & the harness (195) - **§4** — Flag/toolchain gotchas L190 - **Build** — mechanism — per-file opt override (splat resegmentation) L307 - **§8c** — Splitting a TU means rebuilding its DECLARATION ENVIRONMENT, not moving text (Phase 26 session 6) L456 - **§9** — Link real PsyQ library objects byte-exact (Phase 7 — GO proven) L632 - **§9.1** — Generalised per-object linker — `tools/psyq_link.py` (+ `psyq_link_lib.py`), 18/18 libcd byte-exact L661 - **§9.2** — Wire a library region into the build with NOLOAD — no data carving (`tools/psyq_link_region.py`) L685 - **§9.3** — Make it the build: resegment + swap + resolve (`tools/psyq_integrate.py`, libcd DONE) L704 - **§9.6** — Scaling library linking to the whole EXE (Phase 8 — 8 libs linked, 20%→50% byte-identical) L785 - **§9.7** — Binary-agnostic toolchain refactor (Phase 9) — the reusable pattern for Gen2 L821 - **§3-The** — clean object-level metric (use this, not the permuter score, for jtbl/rodata functions) L863 - **§3-The** — mechanism: game-code dedup is SOURCE-LEVEL, not an object swap (R-D1, the key lesson) L945 - **Per-binary** — toolchain provenance (R24) L978 - **§12** — Ultracode harvest — parallel-draft + byte-gate at scale (Phase 12, resident: 1.4%→71.7% in one session) L983 - **One-command** — onboarding — `tools/new_overlay.sh ` L1081 - **§3-THE** — NON-4-ALIGNED-OVERLAY GOTCHA (≈75% of the fleet; fixed in the template + Makefile, automatic) L1098 - **Fleet** — build — `make build-all` / `make check-all` L1139 - **§14** — Propagate a matched function across the fleet — `tools/dedup_propagate.py` (Phase 15) L1145 - **§14b** — Harvesting the UNMATCHED shared core — the match_one wall (Phase 15) L1211 - **§14c** — Callee-signature-aware harvest — breaking the extern-type-conflict wall (Phase 15, T6) L1232 - **§17** — The compiler-quirk wall — the matching TOOLKIT (Phase 18; gcc-2.7.2 source + byte-gated) L1395 - **§3-The** — pipeline gotcha — match_one ≠ the gate; `sig_unify` is MANDATORY L1440 - **§17a** — The TOOLKIT at WAVE scale (Phase-18 Step-3b/Step-1 — measured) + the pipeline-integration gotchas L1464 - **§19** — Scaling the toolkit waves — the recovery PIPELINE + the propagation CAP (Phase 19 T3) L1616 - **§20** — The wave-at-scale GATE CAP + residual-class verdicts (Phase 20) L1651 - **§3-THE** — CAP: at this tail the match_one→gate gap is the LOOSE-TYPING CALL-GRAPH wall (not cheap plumbing) L1656 - **Diagnostic** — lesson: a failed in-TU build leaves a STALE `.o` L1673 - **Phase-20** — RESOLUTION — `tools/cast_call_sites.py` BUILT + the cap re-diagnosed (R14, byte-proven) L1720 - **§24** — The `ov_SC01_077_a.c` split-file vein: split-aware propagation, but loose-typing-gated (Phase 21) L2104 - **§25** — The "schedule" class is mostly COALESCING (pin-crackable), not scheduling; + the gate two-stage + h_exact over-counts ×134 (Phase 21, cont.6) L2151 - **§3-The** — gate two-stage — sig_unify is a FALLBACK, not unconditional (`gate_stage.py`, §19 folded in) L2208 - **§28** — Banking a "close=0 gate-rejected" giant: the canonical-extern recovery (Phase 22 T1, byte-proven on func_8015126C ×134) L2344 - **§28c** — The close=0 recovery is NOT fully exhausted (§26 corrected, R14); + the dedup_propagate registry-skip recovery (Phase 22 T2) L2371 - **§28d** — The "macro-extern-injection" lever: freeing reach-134 inline matches dedup_propagate skips as "not self-contained" (Phase 23, `tools/inject_capped_externs.py`) L2385 - **§29** — Reasoning-model (GLM5.2) DEF-side reconciliation idioms + the wall's hard limit (Phase 23 T10.7, `tools/glm_reconcile.py`) L2393 - **§33** — Automating the giant decl-reconcile: `tools/reconcile_decls.py` (the DATA analog of §20's `cast_call_sites`) + a fleet-majority type oracle (Phase 24 T7b, byte-proven on `func_80129CF8`) L2453 - **§34** — The `func_80138ED0` giant crack: gcc-2.7.2's **3-qty sort bug** + the **zero-byte asm allocation toolkit** + the **giv-init fence** (Phase 24 T5; Opus→close=21, Fable5→MATCH ×134) L2473 - **§35** — The region-a sibling-giant harvest: difficulty ≠ $s-reg count (it's global-array hoisting) + the banking recipe + new loop idioms (Phase 24 T7, 5 parallel Opus-Max agents) L2490 - **§37** — The T7 §G giant endgame: 6/8 cracked, meta-laws + transferable levers (Phase 24, 2026-07-07; FULL byte-verified detail + gcc-2.7.2 line cites in `docs/gcc-2.7.2-map/t7g-giant-harvest.md`) L2525 - **§39** — The ×1→×134 giant-endgame: propagate a matched **-O2** giant via the NATIVE DEFINE-macro path (Phase 24 T7 §G close, 2026-07-08) L2556 - **§41** — The DEF-SIDE canonical-sig wall: mechanically banking a drafted giant past `conflicting types` (Phase 25 T5b batch-2, 2026-07-09; `tools/canon_sig_reconcile.py`, byte-proven on `func_8013B274`) L2729 - **§41a** — v3.1: the def-side wall was ~71% TOOL-shaped — the five measured defects + the laws that dissolve them (Phase 25 T6, Fable5, 2026-07-09) L2788 - **§41b** — T7 execution: the object-only probe OVER-counts BANKABLE by two link/rodata classes (Phase 25 T7-M1, 2026-07-10) L2843 - **§41d** — `void`→`s32` is NOT always byte-neutral: gate the RAW draft FIRST (Phase 26 session 6, byte-proven) L2912 - **§42b** — addendum — wave 3 (Max, 2026-07-10c): THE STALE-OBJECT GATE TRAP + the read-global `&`-cast drift + fix L3028 - **§45** — The flagship `func_80133CD4` crack (399 ins ×134): the merged-variable permutation-breaker + the 1-death local-alloc gate (Phase 25 task A giant escalation, Fable5 gdb-on-cc1, 2026-07-11) L3332 - **§51** — TOOLING INTEGRITY: the silent skip, and how to hunt it L3664 - **§51b** — Why the byte-gate cannot save you L3686 - **§51f** — Checklist for any new corpus-scanning tool L3789 - **§51g** — When the thing you are scanning has a GRAMMAR, parse the grammar (`tools/cdecl.py`) L3803 - **§53** — SWEEP A FAMILY WITH THE TOOL ITS EXEMPLAR NEEDED: the jr/switch carve, and how omitting it manufactured the "families don't template" doctrine (Phase 28 T1, 2026-07-15) L4062 - **§55** — Core-crack wave levers + the GATE-ORCHESTRATION law (Phase 29 T3, 13-agent ultracode wave, 2026-07-17) L4127 - **§55b** — THE GATE-ORCHESTRATION LAW (3 traps, ~3.5h lost; all recovered, 0 data lost) L4156 - **§55c** — Sizing the propagate: a TARGETED propagate is ~4 min/core, and "it's slow" was a BROKEN-TREE ARTIFACT L4175 - **§54** — `--fix-def-sig`: the member's CANONICAL DECLARATION is a build step too (tiny-IMM mega-pools, +4,801, Phase 29 T6, 2026-07-16) L4197 - **§57** — The SELF-decl normalize: the sibling's OWN caller declares the templated fn divergently (the third §17a-1 direction; `tools/normalize_self_decls.py`, func_801670E4 ×137, Phase 29, 2026-07-18) L4290 - **§61** — Task 14: the gate ladder's missing stage is the ARITY pre-pass, and it is TU-side not draft-side (Phase 29, 2026-07-21) L4579 - **§61b** — The jtbl gate stage: built, and the ORDERING law it exposed (Phase 29 Task-14 stage 4, 2026-07-21) L4692 - **§61d** — The undo was eating the tree: two tools, one defect, invisible to the byte-gate (Phase 29, 2026-07-22) L4813 - **§62** — The jtbl RECONCILE must also follow the carve: the post-carve draft reconcile (`harvest_verify._jtbl_reconcile`, Phase 29 SESSION-11, 2026-07-22) L4867 - **§65** — The stranded-draft recovery: BLAST-RADIUS TIERS, and the per-overlay de-macroize that refutes §20's DEF-conflict wall (`tools/demacroize.py` + `tools/blocker_probe.py`, Phase 29 SESSION-16, 2026-07-24) L5049 - **§65d** — Existing-ladder baseline, measured (do this before building a recovery stage) L5125 - **§65e** — Two oracles, and the disagreement is the finding (R34 in practice) L5135 - **§65f** — The de-macroize lever's BOUNDARY, measured: byte-neutral 14 times of 15, and the 15th is why the gate exists L5152 - **§66b** — A metric parsed out of another tool's prose goes NULL silently when the label changes L5234 - **§67a** — Run the symbol-set guard BEFORE you pay for a gate (`tools/symcheck.py`, Phase 29 SESSION-18) L5439 - **§77** — Every extraction tool carries a NARROW hard-coded preamble set; anything outside it silently caps the body's reach. Diff the preamble before you gate. (Phase 29 SESSION-19 — three variants in one session, two different tools) L6118 - **§3-The** — CANDIDATE gate and the REAL gate need DIFFERENT preambles — keep the difference out of the bank L6158 - **§79** — For a 0-callee giant, fingerprint by DATA symbols (§71 cannot fire); and the STACK-SLOT ORDER is a declaration-order oracle (Phase 29 SESSION-19, `func_8017BF14` 4,763 ins, cold start → 45/4763) L6254 - **§82** — Two source-shape oracles from behemoth #6: a duplicated `addiu $aN,$sp,K` across a `jal` means the block was INLINED, and scalar-vs-aggregate decides WHEN a stack slot is allocated (Phase 29 SESSION-19, `func_8017C730` 1,061 ins) L6404 - **§3-2.** — Scalar vs aggregate decides *when* the slot is allocated L6423 - **§3-Why** — it survived every candidate gate L6529 - **§3-THE** — FIX IS MECHANICAL — the tool already holds the answer L6544 - **§87** — `match_one` COMPILES but never LINKS, so an unresolvable data symbol reads as MATCH; and stored drafts go STALE against the tree (Phase 29 SESSION-20) L6667 - **§88f** — the missing rung: a RELOCATION gate between `match_one` and the binary L6752 - **§89a** — MEASURE the write set; do not assert its tier (`tools/blast_radius.py`) L6766 - **§89b** — the parallel gate farm existed; the family path could not reach it (`tools/sweep_parallel.py`) L6779 - **§90** — Five tool-integrity laws from one session, each of which changed an answer (Phase 29 SESSION-21, 2026-07-27) L6800 - **§90a** — A comparison tool MUST share its reference oracle's index space, exactly L6806 - **§92** — Conforming a DECLARATION: pointer changes are caller-neutral, scalar-WIDTH changes are not (Phase 29 SESSION-21, `tools/conform_decls.py`) L6925 - **§97** — The gate's own tree hygiene: a refused carve, an unchecked recovery, and a snapshot that captured a dirty tree (Phase 29 SESSION-22) L7100 - **§105** — A gate's revert must survive an EXCEPTION, not just a failure (Phase 29 T53, `jtbl_family_bank`) L7465 - **§107** — A lever wired into ONE gate path is a lever most families cannot reach (Phase 29 T56, `func_80144090` 0/136 → 136/136) L7547 - **§3-Why** — it survived so long: a MASKED oracle will MATCH a wrong symbol L7987 - **§122** — GATE RAW BEFORE TRANSFORMING; the undo belongs to the WRITER, as a per-edit journal (P30 T0a, 2026-07-30) L8118 - **§123** — PROPAGATE A FAMILY WITH THE TOOL ITS TIER NEEDS: `dedup_propagate` is h_exact-only; its refusals are statements about the TOOL (P30 wave 1, 2026-07-30) L8150 - **§126a** — a bare `except: continue` around a coverage-asserting oracle re-creates the silent skip (P30 S28) L8351 - **§130** — An INCREMENTAL build can report BYTE-IDENTICAL for a change the CLEAN build cannot even LINK (P30 S28, the jr pair) L8520 - **§132** — The `JR-PAIR-IN-ONE-O0-OBJECT` "wall" was TWO instrument defects: a merged-double span the carve could not see, and a truncated object no rule deleted (P30 S29, `func_8013B83C` + `func_8013BD74`) L8604 - **§133** — The DEFAULT-FILTER class: three times in one session, a tool silently answered a narrower question than the one asked (P30 S1–S3) L8719 - **§134** — MULTI-LINE BLINDNESS: one root cause, four faces, in `family_remap`'s preamble scanner (P30 S6, 190 zero-crack families) L8745 - **§3-The** — splitting/merging rules (each closed a residual, byte-gated) L8887 - **§137a** — A gate verdict has a TIMESTAMP; re-check it against the draft's mtime L9420 - **§138** — The propagation lanes: a gate refusal is a DECLARATION, and which lever you owe depends on blast radius L9449 - **§134** — again, in a second tool — and the waiter rule corrected L9560 - **Reconciling** — a gate-refused draft: which way you edit depends on WHERE the TU's decl is L9599 - **§139** — A GATE THAT GREPS FOR VERDICTS MUST ASSERT 1:1 ACCOUNTING; and a `--src` filter must not survive a carve (P30 S38, wave 6: 10 of 16 drafts vanished) L9628 - **§140** — A METRIC IS NOT A MEASUREMENT UNTIL IT IS REPRODUCIBLE FROM THE COMMITTED TREE (P30 S1e: a phantom regression that gated the session's best lever) L9694 - **§142** — An open stub whose `h_exact` class is MATCHED elsewhere is FREE. Propagate the body; do not gate a draft. (P30 S39, +7,710 ins in two commands) L9812 - **§3-The** — measurement (do this before any wave; it is ~20 lines and needs no builds) L9824 - **§155b** — check the TYPE your oracle returns before comparing against it (S45 p5) L10621 - **§156** — an ORPHANED reconcile poisons the fleet: `dedup_propagate`'s kept edit (S45 p6/p7) L10674 - **§158** — The RANGE-EXTENDER: a fourth zero-emission asm lever completes the allocno toolkit (P30 S46 tier-3, `func_8017CE58`, 733 ins) L10746 - **§160** — THE REACH-15 WAVE HARVEST: an align-1 block move, and the instrument that called it a wall (P30 S47) L10927 - **§161** — THE RETRY-WAVE HARVEST: a jump table indexed from zero, and two allocator traps (P30 S47) L11003 - **§162** — S48 WAVE-1 HARVEST (P30, 2026-08-11): the reach-ordered sibling campaign's first 12 targets L11048 - **§163** — S48 WAVES 2-3 HARVEST (P30, 2026-08-11/12): the five that were byte-probed and are actionable L11794 - **§165** — S48 WAVE-4 HARVEST (P30, 2026-08-12): banked the same day the wave landed L13736 - **§166** — THE DESTINATION-TU ORACLE (P30 S48): the seven-attempt bug that was never codegen L14956 - **§167** — S48 WAVE-5/6 HARVEST (P30, 2026-08-12): the saturation point L15012 - **§176e** — SYMBOL IDENTITY IS COMPUTABLE OFFLINE (P31 S52): `tools/reloc_identity.py` L16906 - **§3-A.** — The seven under-reporting holes (all in `gate_main`, all the same shape) L17040 - **§3-C2.** — RECONCILE BEFORE THE FIRST GATE — a parked draft gets HARDER to bank, not easier L17087 - **§3-D.** — The measured cost shape, and what to build next L17110 - **§176i** — WHAT A STATIC PRE-GATE CHECK CAN AND CANNOT PROVE (P31 S52, wave Q) L17128 - **§179** — IDIOMS MINED FROM THE WAVE P/Q JOURNALS (P31 S52, harvest pass) L17367 - **§179-G** — 🟡 A PIN CAN **CREATE** A COMBINE `LOG_LINK` AND DELETE AN `andi` (sixth RC-5 channel, n=1) L17596 - **§176c** — MAIN (SLUS_007.26) CANNOT BE GATED INCREMENTALLY L17663 - **§180** — THE LEFTOVER-DRAFT HARVEST: RE-VERIFY WHAT YOU ALREADY HAVE BEFORE DRAFTING ANYTHING NEW L17854 - **§180b** — WHAT THE PRE-GATE LADDER ACTUALLY FINDS IN A COLD PILE (the shape of integration debt) L17883 - **§181** — WHAT A WAVE'S GATE ACTUALLY REJECTS (P31 S53, measured on wave R's 45-draft main pile) L17920 - **§184** — COMMENT-BLINDNESS IS A DEFECT CLASS, NOT A BUG (P31 S53: three tools, one root cause, one session) L18073 - **§187** — 🔴 "SAME SOURCE" IS NOT "SAME OBJECT": THE SDK BUILD AND THE GAME BUILD DISAGREE ON GTE NOPS L18179 - **§190** — THREE PRESCRIPTIONS FROM THE SAME HARVEST (weaker evidence than §189, honestly labelled) L18342 - **§191** — WHAT THIS HARVEST DID **NOT** BANK (4 rejected, 4 narrowed) — recorded so it is not re-derived L18379 - **§192** — THE PRE-GATE LADDER WAS MAIN-ONLY, AND NOBODY COULD SEE IT (P31 S54) L18401 - **§193** — THE WAVE-T HARVEST (P31 S54): 71 index_gap reports -> 9 laws, 5 rejected, 61 already-covered L18466 - **§193-A** — The wave card ships only OPEN-set pointers and discards the atlas's BANKED one — `exemplar`/`sibs` are stubs 100% by construction (tools/atlas.py:96/657), while `seed.ref` (matched pool, atlas.py:505-536) is dropped at build_wave_atlas.py:143 L18483 - **§193-G** — §164-54's "scope to ≥4 arms" bound is byte-wrong — the dispatch-topology oracle goes live at THREE case nodes (`balance_case_nodes` splits at `i > 2`), but only for a signed-after-promotion index L18787 - **§193-I** — A DECLARED AGGREGATE LOCAL HAS AN 8-BYTE FRAME STRIDE — CEIL(size,8), NOT size. N ARRAYS THEREFORE COST 8·k MORE THAN ONE HAND-LAID STRUCT (k = how many of them have size mod 8 ≠ 0), AND THE TELL IS IDENTICAL INSTRUCTION COUNT WITH EVERY $sp DISPLACEMENT SHIFTED BY THE SAME CONSTANT. L18888 - **§193-REJECTED** — what this harvest did NOT bank (recorded so it is not re-derived) L18947 - **§194** — THE WAVE-U HARVEST (P31 S54): 64 index_gap reports -> 14 laws, 5 rejected, 44 already-covered L18974 - **§194-E** — The wave card's `exemplar` is the TARGET ITSELF on 42/73 wave-U and 36/71 wave-T cards — a construction consequence of `atlas.py:657` (exemplar = max-nins OPEN member) meeting `build_wave_atlas.py:166` (one card per gid); and the shipped §193-A `seed_ref` is same-binary on 0/51, so no card field can ever name a destination-TU sibling L19199 - **§194-G** — Reading the integer half of a 16.16 stack aggregate: REGISTER-LIVENESS, not the C spelling, decides `sra` vs `lhu` — and the break is count-neutral L19309 - **§194-K** — Blind sched1's alias oracle with a second SET of a pointer pseudo — the first zero-byte, non-volatile, dependence-CREATING lever (corrects §167-05's "volatile is the only door"; fourth consumer of reg_n_sets) L19485 - **§194-REJECTED** — what this harvest did NOT bank (recorded so it is not re-derived) L19729 - **§195** — THE WAVE-V HARVEST (P31 S54): 67 index_gap reports -> 14 laws, 9 rejected, 76 already-covered L19750 - **§195-I** — §145(b) AMENDED — the pointer-bump `addiu` is saved by cse, not combine: ANY second SET of a pseudo in the address's equivalence chain (in-place `p += K`, §145(b)'s `p = r;` copy, or an asm re-tie) kills the fold; the pass is cse and the gate is `invalidate`'s `reg_tick++` L20198 - **§195-M** — Frame `vars` is a SEQUENTIAL bump-allocation, not a flat sum: §193-I's CEIL(aggregate,8) term and §165-03/§167-06's 8×orphan term are the SAME frame_offset walk at two different compiler stages, and each stage re-CEILs frame_offset to 8 before it allocates L20411 - **§195-REJECTED** — what this harvest did NOT bank (recorded so it is not re-derived) L20507 - **§197** — THE WAVE-W HARVEST (P31 S54): 68 index_gap reports -> 4 laws, 3 rejected, 41 already-covered L20608 - **§199** — THE WAVE-X HARVEST (P31 S54/S55): 63 index_gap reports -> 7 laws, 2 rejected, 56 already-covered L20748 - **§199-C** — A NEGATIVE CONSTANT MULTIPLY ALWAYS TAKES expmed's negate_variant — but whether you ever SEE the neg is decided by COMBINE, and for an EVEN |K| it never disappears L20853 - **§199-D** — A narrow UNSIGNED value compared in an ordered `if` emits `sltiu`/`sltu`; the only dial is the WIDTH of a real object, and a widening `(s32)` cast is inert — AMENDS §35 (whose stated "only CSE-reuse canonicalizes" mechanism is byte-wrong) and does NOT apply inside a `switch` L20901 - **§199-G** — At TWO case nodes the switch-vs-if oracle is not blind — but the tell is ALL tests positive + a trailing `j default`, NOT the first test's polarity L21074 - **§201** — THE WAVE-Y HARVEST (P31 S55): 67 gap reports -> 5 laws, 8 rejected, 53 already-covered L21189 - **§204** — THE WAVE-Z HARVEST (P31 S56): 82 gap reports -> 5 laws, 16 rejected, 30 already-covered L21588 - **§207** — THE WAVE ab–ag HARVEST (P31 S58): 278 byte-banked notes → 25 laws, 103 self-reported no-gap L22222 - **§233** — THE WAVE aa–bg HARVEST (P31 S58b): 1,101 byte-banked notes → 24 new laws, 21 addenda, ~700 already-covered L23313 - **§236** — THE DECLARATION LAYER IS THE DOMINANT BANK-BLOCKER: NINE WAYS A BYTE-PERFECT BODY FAILS THE GATE (P31 S58b) L23427 - **§247** — TWO BRANCHES TO **ONE** LABEL MEANS THE SOURCE CONDITION IS NEGATED (P31 S58b) L23873 - **§254** — THE DEAD PARAMETER IS A REGISTER-PLACEMENT TOOL **(single observation — not yet cross-confirmed)** (P31 S58b) L24067 - **§259** — THE DISCARD LEDGER FOR THE aa–bg HARVEST (P31 S58b): WHAT WAS MINED AND REJECTED, AND WHY L24724 - **§260-A** — STAGE 2 IS PROVEN, AND THE WHOLE jtbl PIPELINE IS AUTOMATED AT THE GATE (P31 S59, same day) L24813 - **§261** — THE -O0 ORACLE: DERIVE THE OPT LEVEL FROM THE TARGET, AND `$fp` IS NOT THE TELL (P31 S59) L24849 - **§267** — ADDENDA HARVESTED FROM WAVES at/bh/bk/bl (P31 S59b) L25120 - **ADD-9** — → §213-3 / §217 addendum — ADJACENT PRE-CALL FRAME STORES ARE ONE AGGREGATE; THE UNESCAPED SCALAR NEIGHBOR IS DEAD-STORED L25215 - **§269** — ADDENDA HARVESTED FROM WAVES ax/bm (P31 S59c) L25339 - **§271** — Ordinal IMM pairing: text order is NOT emission order; emit CANDIDATES, let the oracle pick (P31 S59) L25577 - **§273** — A standalone compile is the WRONG oracle for a TU-destined draft (P31 S59) L25619 - **§274** — ADDENDA HARVESTED FROM 18 WAVES (P31 S60): 315 candidates, 255 already covered, 21 sharpenings, 3 new laws L25634 - **§278** — ADDENDA HARVESTED FROM WAVE cf (P31 S60): 34 candidates, 13 already covered, 8 sharpenings, 4 new laws L26625 - **§283** — ADDENDA HARVESTED FROM THE 36-WAVE BATCH (P31 S60): 1,216 candidates, 859 already covered, 46 sharpenings, 9 new laws L27121 - **§287** — A STACK-FRAME HOLE BELOW TWO ADDRESS-TAKEN AGGREGATE LOCALS IS A LEADING PAD MEMBER OF ONE COMBINED STRUCT, NOT SEPARATE LOCALS OR A REGISTER PIN (P31 S60/dj; `func_8017D104`, ov_SC06_027, byte-proven 47/47) (P31 S60; waves #, byte-proven) L29086 - **§293** — THE "WHOLE-OBJECT GATE NEEDS EVERY SIBLING" LAW, WRITTEN PROPERLY: IT IS THREE LAWS, AND THE LOAD-BEARING ONE IS "THE BASELINE, NOT THE SIBLINGS" (P31 S61; byte-proven on 15 binaries in one night) L29109 - **§294** — ADDENDA HARVESTED FROM THE S61 GEN0/MAXTOK/MAIN/DEEPSEEK BATCH (waves ab8/ab16/ab24/ab32 · g0a–g0f · m0a · ds1/ds2): 99 candidates, 52 covered, 15 notes → 10 addenda, 29 notes → 5 new laws (§295–§299), 3 refuted L29159 - **§303** — MODULE ISLAND TABLES: DERIVE THE PADS AT BUILD TIME, PEEL NOTHING — THE §154-A/§260 "island-pads"/"island-blocked" WALLS DISSOLVE (P31 S62 T3a; byte-proven md_SC03_076 func_801F0A9C + func_801F0F28, sha 9a165e36…) L29763 - **§305** — "CARVE-REFUSED" AT GATE TIME IS THREE NAMED, DETERMINISTIC CLASSES — NONE OF THEM A CARVE (P31 S62 T3; 28 resolver drafts autopsied 28/28) L29822 - **§313** — A RECOVERY STAGE THAT REWRITES THE DRAFT IS PART OF THE MEASUREMENT: GATE THE RAW DRAFT FIRST, THE REWRITE ONLY AS A FALLBACK (P31 S65 t5r-recovery; byte-proven func_8017BEBC, 246 ins) L30185 - **§314** — AN IF/ELSE-IF ABS-RANGE CHECK'S C SPELLING IS INERT: FOUR STRUCTURALLY DIFFERENT REWRITES ALL COMPILE BYTE-IDENTICAL, AND NONE REACHES A TARGET THAT SINKS THE NEGATIVE ARM INTO AN OUT-OF-LINE BLOCK (P31 S65; UNPROVEN, gate-refused draft func_80181720) L30241 - **§315** — ALL-CONSTANT AGGREGATE FILL: THE EMISSION ORDER IS SHARED-LITERAL GROUPS × DESCENDING INDEX, WITH PAIRED SUB-FIELDS INTERLEAVED (P31 S66; ⚠ **UNPROVEN** — `func_80185214`, gate-REFUSED draft, closeness 32→5, never MATCHed) L30273 - **§316** — A GUARD CHAIN THAT GATES A SUCCESS BLOCK ROUTES ITS FAILING GUARDS TO A LABEL **BEFORE** THE FLAG TEST, NOT TO THE EPILOGUE: THE RESIDUAL IS IMM-OFFSET-ONLY AT AN EXACTLY EQUAL INSTRUCTION COUNT (P31 S66; byte-proven func_80180284) L30310 - **§318** — A UNARY MINUS STORED BACK INTO THE SAME HALFWORD IS COMPUTED IN HImode, SO ITS LOAD IS `lhu`; AN INLINE `(s32)` CAST IS PROVABLY INERT AND ONLY A NAMED SImode LOCAL BUYS `lh` (P31 S66; `func_8018568C`, ov_SC03_028 — **`match_one`-only, NOT byte-gated**) L30378 - **Addendum** — Addendum to §167-12 — the single-operand volatile keepalive, re-confirmed at a gated MATCH (func_8017F498) L30485 - **§NNN** — REFUTED: A CODE BLOCK SHARED BY TWO *DIFFERENT* SWITCH STATEMENTS IS ORDINARY FORWARD `cross_jump`, NOT A SHAPE C CANNOT REACH — §164-11 ALREADY BANKS IT FROM PLAIN NESTED SWITCHES (P31 S66 round3, `func_8001B0D4`; ⚠ **UNPROVEN** — gate-REFUSED draft, closeness 68→45, never MATCHed) L30640 - **§323a** — R53, TWICE IN ONE HOUR: A FAILED BUILD LEAVES THE PREVIOUS BINARY, AND `sha1sum` READS GREEN (P31 S67) L30926 - **§328** — THE VOLATILE ALIAS MUST BE AN *OBJECT*, NOT A CAST: `*(volatile s32*)&sym` UNFOLDS %lo INTO A SEPARATE `addiu` (P31 S67; byte-proven ov_SC07_007/func_80181B8C, 156 ins, NEW LAW) L31024 - **§332a** — MAIN'S RESIDUAL FRONTIER IS CONTAMINATED WITH TOOLCHAIN WALLS: 4 OF 7 IN ONE WAVE (P31 S67, measured) L31096 - **§333** — FRAME SIZE IS SET BY *DECLARED* AGGREGATES, NOT USED ONES: AN UNREFERENCED TRAILING LOCAL IS A REAL DIAL (P31 S67; three independent byte-proven instances in one wave) L31115 - **§337** — THE CC1-ONLY BLOCKER CLASS: `blocker_probe`'s STATIC ORACLE REPORTS "none" AND THE WHOLE-TU COMPILE STILL FAILS (P31 S67; ov_SC04_011/func_801827DC, md_MAIN_027/func_800CB4A4) L31157 - **§340** — §194-K COROLLARY: **FLIP THE FALSE EDGE YOU CANNOT DELETE.** A "scheduler" residual can be sched.c's ALIAS ORACLE emitting a FALSE true-dependence; source order chooses its DIRECTION (P31 S67; byte-proven ov_SC03_107/func_8017CF48, 10 -> 0 in one compile, zero bytes) L31209 - **§346** — `c ? X : -X` TAKES expand_expr's COND_EXPR **SINGLETON** PATH (copy, then negate IN PLACE) — AN if/else STATEMENT GIVES THE TWO-ARM FORM (P31 S67; byte-proven ov_SC03_102/func_80180C38, closed the last instruction) L31322 - **§353** — USE `-fno-thread-jumps` AS AN **ORACLE** TO PROVE A RESIDUAL IS thread_jumps, THEN LAUNDER THE *VALUE* TO KEEP A DEAD RE-TEST (P31 S67; byte-proven ov_SC01_008/func_8017EC68, 279 ins) L31519 - **§357** — ONE STRUCT POINTER, NOT TWO: A SECOND SOURCE VARIABLE BUILDS A THIRD IV (P31 S68; byte-proven ov_SC06_029/func_80181DF8, 335 ins, 330 → 13) L31589 - **§358** — (sharpens §333) — AN **UNREFERENCED** FIXED-SIZE AGGREGATE LOCAL IS LOAD-BEARING (P31 S68; same function) L31598 - **§371** — ★★ — CARVING A **SINGLE-OBJECT MODULE BINARY**, AND THE spimdisasm RODATA-MIGRATION TRAP THAT FOLLOWS (P31 S68; byte-proven md_MAIN_003, func_800D0D6C 345 ins) L31890 - **§383** — TWO TOOLCHAIN FACTS THE PACKS DID NOT CARRY (P31 S69) L32244 - **§388** — ★★★ — THE **-O0 COLOURING ORACLE**: simulate `stupid.c` instead of grinding spellings (P31 S69; main/func_80011380 proved a C-level WALL at 6) L32384 - **§392** — ★★★ — THE SONNET-WAVE HARVEST (P31 S69): SEVEN TYPE/ORDER LEVERS THAT EACH CLOSED A MATCH L32502 - **§332b** — ★★★ — THE §332 "WALLS" ARE A PER-OBJECT ASSEMBLER MODE, NOT A C LIMIT — 6 CLOSE AS REAL C (P31 S69, Fable-3) L32702 - **§405** — ★★★ — THE S70 WAVE HARVEST: 130 agents, 113 MATCH, and the laws they brought back L33092 - **§3-A.** — THE ORACLE HAS A HOLE: match_one cannot see a jump table (§405-A) L33098 - **§414** — ★★★ — `parallel_gate` ON `main` IS A FALSE PASS, AND THE RULE WAS ALREADY WRITTEN DOWN (P31 S71) L33510 - **§423** — ★★★ — "MATCH IN ISOLATION + GATE REJECTS + CAUSE NOT DETERMINED" ⇒ GREP THE TU FOR A FILE-SCOPE TYPEDEF THE DRAFT ALSO CARRIES (P31 S71; byte-proven `ov_SC03_092/func_8017FA74`) L33780 - **§426** — ★★★ — main's SWITCH FUNCTIONS WERE NEVER A CODEGEN WALL: ONE RODATA CARVE HAD BEEN MISSING SINCE PHASE 7 (P31 S72; 3 of the 11 "PROVEN gate-rejects" banked byte-identical in 14 s) L33855 - **§427** — ★★ — A HASH IS A CORRECTNESS ORACLE WITH ZERO DIAGNOSTIC CONTENT; PRESERVE THE RED ARTIFACT BEFORE ANYTHING REBUILDS OVER IT (P31 S72) L33931 ### process, measurement & doctrine (133) - **§8e** — The jtbl ALIGNMENT LAW + the pad-spec filter — multi-table .rodata spans (Phase 29, byte-proven; `.run/probe_jtbl/verdict.md`) L549 - **§3-The** — mechanism: game-code dedup is SOURCE-LEVEL, not an object swap (R-D1, the key lesson) L945 - **Per-binary** — toolchain provenance (R24) L978 - **§17a** — The TOOLKIT at WAVE scale (Phase-18 Step-3b/Step-1 — measured) + the pipeline-integration gotchas L1464 - **Diagnostic** — lesson: a failed in-TU build leaves a STALE `.o` L1673 - **Phase-20** — RESOLUTION — `tools/cast_call_sites.py` BUILT + the cap re-diagnosed (R14, byte-proven) L1720 - **§23** — Giant `func_80153E00` cracked (scalar-data CAST); BUT most giant drafts are STALE+INCOMPLETE, and a diag MUST remove artifacts (Phase 21 — byte-proven + a self-correction) L2051 - **§3-h** — _exact OVER-COUNTS ×134 — verify shareability before crediting a class's "reach-134" (R14) L2196 - **§28c** — The close=0 recovery is NOT fully exhausted (§26 corrected, R14); + the dedup_propagate registry-skip recovery (Phase 22 T2) L2371 - **§31-triage** — R17 applies to CODEGEN residuals, never to a compile ERROR (Phase 26 session 7, Drew asked) L2712 - **§41a** — v3.1: the def-side wall was ~71% TOOL-shaped — the five measured defects + the laws that dissolve them (Phase 25 T6, Fable5, 2026-07-09) L2788 - **§41b** — T7 execution: the object-only probe OVER-counts BANKABLE by two link/rodata classes (Phase 25 T7-M1, 2026-07-10) L2843 - **§41b** — addendum — M4 "reconcile_decls" tier is ALSO a probe over-count: 0/8 mechanical (Phase 25 T7-M4, 2026-07-10) L2892 - **§53** — SWEEP A FAMILY WITH THE TOOL ITS EXEMPLAR NEEDED: the jr/switch carve, and how omitting it manufactured the "families don't template" doctrine (Phase 28 T1, 2026-07-15) L4062 - **§3-The** — meta-lesson (R35, and why this one is expensive) L4112 - **§55** — Core-crack wave levers + the GATE-ORCHESTRATION law (Phase 29 T3, 13-agent ultracode wave, 2026-07-17) L4127 - **§55b** — THE GATE-ORCHESTRATION LAW (3 traps, ~3.5h lost; all recovered, 0 data lost) L4156 - **§57a** — Two NSD corrections + the SURGICAL-ONLY law + the honest broad-sweep yield (Phase 29, 2026-07-18) L4337 - **§58** — match_one MATCH ≠ BANK: the four blind spots + the crack-wave reconcile-before-bank law (Phase 29 crack-wave, 2026-07-18) L4377 - **§60** — Classify the residual, don't rank it: the deterministic residual→class classifier and what it measured about the backlog (Phase 29 Task-13A, 2026-07-21) L4441 - **What** — it measured — the whole open backlog, byte-grounded L4465 - **§3-The** — parallel-probe race this surfaced L4497 - **§61b** — The jtbl gate stage: built, and the ORDERING law it exposed (Phase 29 Task-14 stage 4, 2026-07-21) L4692 - **§62** — The jtbl RECONCILE must also follow the carve: the post-carve draft reconcile (`harvest_verify._jtbl_reconcile`, Phase 29 SESSION-11, 2026-07-22) L4867 - **§63** — UPDATE (Phase 29 SESSION-14) — `fix_header_decl`'s "SAFE" verdict is FLEET-BLIND; it MUST be R22-validated L5034 - **§65** — The stranded-draft recovery: BLAST-RADIUS TIERS, and the per-overlay de-macroize that refutes §20's DEF-conflict wall (`tools/demacroize.py` + `tools/blocker_probe.py`, Phase 29 SESSION-16, 2026-07-24) L5049 - **§65a** — The blast-radius taxonomy (makes §61's law structural instead of remembered) L5064 - **§65d** — Existing-ladder baseline, measured (do this before building a recovery stage) L5125 - **§65e** — Two oracles, and the disagreement is the finding (R34 in practice) L5135 - **§65f** — The de-macroize lever's BOUNDARY, measured: byte-neutral 14 times of 15, and the 15th is why the gate exists L5152 - **§66c** — Before a wave, verify the FUEL exists; an "already attempted" set built from the wrong directory lies in BOTH directions L5251 - **§66d-5** — `residual_class`'s "structural ⇒ permuter CPU is waste" is WRONG for schedule permutations (measured, Phase 29 SESSION-18) L5525 - **§3-The** — honest fix was source-level and cheap L5784 - **§3-The** — residual, and the honest read L6294 - **§83** — The parameterised-repeat law, the spill-area trap, and why a per-case edit cannot move a per-case symptom (Phase 29 SESSION-20, `func_80183814` 5,122 ins, cold-ish start → 36 structural / 99.3%) L6446 - **Scope** — , measured (do not over-generalise — §80) L6552 - **§3-Two** — ladder lessons banked with it L6562 - **§3-Do** — the WHOLE axis in one edit, then R22 once L6601 - **§3-THE** — LAW: all-or-nothing PER FAMILY L6634 - **§88b** — the `slti` literal-position law (extends §78 to comparisons) L6720 - **§88e** — a wrong diagnosis, refuted properly (the model for how to treat an inherited lever) L6742 - **§89a** — MEASURE the write set; do not assert its tier (`tools/blast_radius.py`) L6766 - **§90d** — Do not measure a live wave's drafts (§87 in real time) L6844 - **§98** — `conform_decls` had three defects, and only the third needed R22 to find (Phase 29 SESSION-22, `func_8014CF04`) L7147 - **§106** — Persist the MEASUREMENT, derive the POLICY: a stored route let a stale file out-vote the live table (Phase 29 T54, `residual_class._ROUTE`) L7504 - **§125** — Split the CARVE from the BODY before calling a jr residue a wall — and measure it by SHA from a CLEAN tree (P30 SESSION-28; **this section's first draft was WRONG and the method caught it**) L8240 - **§3-The** — meta-lesson L8291 - **Wave** — economics (measured, for the next batch's sizing) L8987 - **§136b** — A prior wave's "genuine byte-DIFF" verdict is NOT reliable evidence (4 of 4 refuted) L9067 - **§136g** — When the index points at the WRONG lever: two byte-refuted routings (func_801863B4) L9245 - **§136h** — CORRECTION: the zero-crack pool does NOT "refill with cheap work" (my error, byte-measured) L9274 - **§136j** — The failure MIX flips with function size (measured across four bands, one session) L9336 - **Rank** — the lane by measured concentration, not by class count L9515 - **§140** — A METRIC IS NOT A MEASUREMENT UNTIL IT IS REPRODUCIBLE FROM THE COMMITTED TREE (P30 S1e: a phantom regression that gated the session's best lever) L9694 - **§3-The** — measurement (do this before any wave; it is ~20 lines and needs no builds) L9824 - **§3-And** — the report-vs-bytes lesson attached to it L9856 - **§146** — RE-MEASURE A WALL BEFORE YOU RESPECT IT. Both "permanent" giants fell to drafts already on disk. (P30 S6, +50,094 ins) L10011 - **§147** — The three-stratum FRAME LAW, and four "stop searching" verdicts (P30 S42, `func_8017C294`, serial run) L10070 - **§3-C.** — Inner-block declaration does NOT delay slot allocation — BYTE-REFUTED L10102 - **§3-D.** — "Cheap fuel" that was never probed: 0 of 31 templatable L10327 - **§3-Two** — corrections to the record L10379 - **§3-The** — two fallouts, and how to close them (both measured, in order) L10429 - **What** — does NOT work (14 byte-measured probes) L10520 - **§157** — the cheap-tier size cliff, measured (S45 p6) L10721 - **§162** — The cross-jump "CALL veto" is a COUNT law, not a CALL law (BOUNDS §88a; P30 S48, `func_80189540`) L11336 - **§3-The** — law L11583 - **DIAGNOSTIC** — TELL — two faces, one law L11625 - **§163** — S48 WAVES 2-3 HARVEST (P30, 2026-08-11/12): the five that were byte-probed and are actionable L11794 - **§163z** — THE UNVETTED REMAINDER (do not cite as law; each needs a dedupe pass) L11862 - **§164z** — REFUTED CLAIMS: do NOT re-derive these L13670 - **§165z** — REFUTED THIS WAVE: do NOT re-derive L14912 - **§167z** — REFUTED IN WAVES 5/6: do NOT re-derive L16208 - **§168** — THE COUSIN TIER (P30 S49, 2026-08-12): h_seq's exact-hash brittleness, measured — and the similarity map above it L16265 - **§176g** — SIZE A WAVE BY INSTRUCTIONS, NOT BY CARDS (P31 S52 — the adopted doctrine) L16994 - **§176h** — THE BATCH-SUBSTITUTION HAZARD MAP (P31 S52): seven holes, three wrong fixes, one law L17032 - **§3-D.** — The measured cost shape, and what to build next L17110 - **§176j-2** — THE REPAIR PASS, MEASURED (do this instead of resuming) L17186 - **§176-C** — 🔴 WALL REFUTATION: a hard-register pin CANNOT schedule around a call, because of a genuine gcc-2.7.2 bug L17750 - **§176-E** — Two cheap source spellings, both cc1-probed L17802 - **§180** — THE LEFTOVER-DRAFT HARVEST: RE-VERIFY WHAT YOU ALREADY HAVE BEFORE DRAFTING ANYTHING NEW L17854 - **§181** — WHAT A WAVE'S GATE ACTUALLY REJECTS (P31 S53, measured on wave R's 45-draft main pile) L17920 - **§182** — §177's HONEST NEGATIVE: the epilogue lever cracked 4 of 16, and the `800c3` cluster held L17976 - **§183** — THE DECLARATION-RECONCILIATION PLAYBOOK (P31 S53, measured on 20 byte-verified drafts) L18002 - **§185** — EDIT THE SIDE THAT IS CHEAP TO VERIFY, AND CHECK A TU RETYPE AT ITS USE SITES L18101 - **§190** — THREE PRESCRIPTIONS FROM THE SAME HARVEST (weaker evidence than §189, honestly labelled) L18342 - **§194-A** — A zero-byte scheduling fence goes AFTER the defining statement to make that computation emit FIRST in its block — and the barrier predicate is `volatile`-or-colon-less, not the `"memory"` clobber (COMPLEMENTS §165-40; does not refute it) L18991 - **§194-D** — Declared width of a computed-value local is a sched1 dial (count-neutral) — a replication + attribution correction of §165-17, NOT a new argument-register law L19158 - **§195-J** — GTE / PsyQ op CALL-vs-INLINE is a PER-SITE SOURCE FACT, not a TU style — both forms coexist in one TU (measured in 2 TUs), and the tell is the target's own opcodes (`lwc2`/`sqr`/`swc2` vs `jal`), not the sibling. Costs -8 ins on func_8018505C. Corollary: the game's inline `sqr` macro emits TWO hazard nops, the SDK's `Square0` body emits ONE — so the inline form is provably not `Square0` inlined (a second instance of §187's SDK-vs-game GTE nop divergence). L20263 - **§201-E** — §194-J-2 — The `last_mem_set` deletion window is measured in SOURCE/expand order, not in the printed stream; a foreign store moved between the pair in C source is a real lever, and `volatile` is not always the better one L21409 - **§230** — THE ANCHOR PROBE: with `%hi`/`%lo` masked, the surviving `addiu` deltas tell you which assignment was written first **(single observation — not yet cross-confirmed)** (P31 S58) L23165 - **§257** — THE DEAD-END LEDGER (P31 S58b): ELEVEN LEVERS THAT MEASURED NULL OR BACKFIRED L24151 - **§194-B** — / §209 addendum (P31 S58b) — TWO MORE INSTANCES, AND THE BOUND IS NOW REFUTED FOUR WAYS L24220 - **§266** — THE INERT-RIDER LAW: A LEVER IS ONLY CITABLE WHEN ITS SOLO REMOVAL BREAKS THE MATCH (P31 S59b; measured 4-of-8 on this batch) L25080 - **ADD-4** — → §167-37 addendum — THE FIFTH PRECONDITION, NOW MEASURED: DOWNSTREAM FIELD RE-READS ⇒ NAME IT **AND** STORE **INSIDE** THE ARM L25394 - **ADD-9** — → §255 "AND CASE-BODY PLACEMENT" bound / §222-addendum-3 — ON A LARGE SPARSE TREE, BODIES FOLLOW **SOURCE** ORDER (measured by a one-word probe) L25471 - **ADDENDUM** — to §172b-1 — TWO PLACEMENT DIALS THE PROMOTION LAW DOESN'T NAME: NARROW THE COUNTER'S DECLARED TYPE, AND MOVE THE CAST INTO THE LOOP BODY L26100 - **What** — I could not verify L27074 - **ADDENDUM** — to §164-75 — the fold-reassociation law also fires at a variable's INITIALIZER, not only a later expression L27131 - **What** — I could not verify L27648 - **ADDENDUM** — to §153 / §236-5 (func_801A419C, md_SC07_003 — waves di and dl, corroborating; refutes a contradicted dj-wave card) L27865 - **What** — I could not verify L28105 - **ADDENDUM** — to §174 Law 4 (func_8017E9A8, ov_SC06_015) L28125 - **ADDENDUM** — the zero-emission-asm family gains a REF-SLIDER PLACEMENT LAW and a paired RESTORER (func_800CB900, md_MAIN_026) L28165 - **What** — I could not verify L28663 - **What** — I could not verify L28969 - **§293** — THE "WHOLE-OBJECT GATE NEEDS EVERY SIBLING" LAW, WRITTEN PROPERLY: IT IS THREE LAWS, AND THE LOAD-BEARING ONE IS "THE BASELINE, NOT THE SIBLINGS" (P31 S61; byte-proven on 15 binaries in one night) L29109 - **§294** — ADDENDA HARVESTED FROM THE S61 GEN0/MAXTOK/MAIN/DEEPSEEK BATCH (waves ab8/ab16/ab24/ab32 · g0a–g0f · m0a · ds1/ds2): 99 candidates, 52 covered, 15 notes → 10 addenda, 29 notes → 5 new laws (§295–§299), 3 refuted L29159 - **§313** — A RECOVERY STAGE THAT REWRITES THE DRAFT IS PART OF THE MEASUREMENT: GATE THE RAW DRAFT FIRST, THE REWRITE ONLY AS A FALLBACK (P31 S65 t5r-recovery; byte-proven func_8017BEBC, 246 ins) L30185 - **REFUTED** — claim — REFUTED — the `j`-slot store is an ASPSX macro-expansion hop, not a cse split; maspsx hard (func_8005DBD8) L30589 - **§NNN** — REFUTED: A `sw %lo(SYM)($at)` IN A JUMP'S DELAY SLOT WITH ITS `lui $at` STRANDED ABOVE THE JUMP IS **ASSEMBLER** MACRO-EXPANSION, NOT A cse SPLIT — OUR PIPELINE CANNOT EMIT IT FROM ANY C, AND THE +1 IS A `maspsx` GAP (P31 S66 round2, `func_8005DBD8`, byte-probed) L30591 - **REFUTED** — claim — REFUTED: a block shared across TWO switch statements is ordinary forward cross_jump, not a (func_8001B0D4) L30638 - **§NNN** — REFUTED: A CODE BLOCK SHARED BY TWO *DIFFERENT* SWITCH STATEMENTS IS ORDINARY FORWARD `cross_jump`, NOT A SHAPE C CANNOT REACH — §164-11 ALREADY BANKS IT FROM PLAIN NESTED SWITCHES (P31 S66 round3, `func_8001B0D4`; ⚠ **UNPROVEN** — gate-REFUSED draft, closeness 68→45, never MATCHed) L30640 - **Addendum** — §194-A addendum — the bare/colon-less fence measured NULL and only the "memory"-clobber fo (func_8017E464) L30761 - **§322** — A PROBE THAT ANSWERS A *NECESSARY BUT NOT SUFFICIENT* QUESTION WILL PRICE BLOCKED WORK AS FREE: RUN THE REAL PLANNER WHEN THE PLANNER IS PURE (P31 S67; measured, 96 of 159 open jtbl functions) L30866 - **§323a** — R53, TWICE IN ONE HOUR: A FAILED BUILD LEAVES THE PREVIOUS BINARY, AND `sha1sum` READS GREEN (P31 S67) L30926 - **§324** — THE ARITY-SELF WALL NEEDS *BOTH* HALVES: A K&R DEFINITION **AND** A NO-PROTO TU DECL; EITHER ALONE STILL FAILS (P31 S67; rtu-proven ov_SC01_005/func_8017FBCC, 14 instances measured) L30949 - **§328** — THE VOLATILE ALIAS MUST BE AN *OBJECT*, NOT A CAST: `*(volatile s32*)&sym` UNFOLDS %lo INTO A SEPARATE `addiu` (P31 S67; byte-proven ov_SC07_007/func_80181B8C, 156 ins, NEW LAW) L31024 - **§332a** — MAIN'S RESIDUAL FRONTIER IS CONTAMINATED WITH TOOLCHAIN WALLS: 4 OF 7 IN ONE WAVE (P31 S67, measured) L31096 - **§337** — THE CC1-ONLY BLOCKER CLASS: `blocker_probe`'s STATIC ORACLE REPORTS "none" AND THE WHOLE-TU COMPILE STILL FAILS (P31 S67; ov_SC04_011/func_801827DC, md_MAIN_027/func_800CB4A4) L31157 - **§342** — A `void *` PARAMETER CAST TO ITS REAL TYPE IN A LOCAL IS **NOT** BYTE-NEUTRAL WHEN A LATER PARAMETER ALSO NEEDS A CALLEE-SAVED REGISTER (P31 S67; byte-proven ov_SC07_002/func_80181394, NEW LAW) L31257 - **§343** — `decl_prior`'s FLEET MAJORITY CAN BE WRONG ABOUT THE TRUE SIGNATURE — READ THE RIVALS, NOT JUST THE WINNER (P31 S67; measured on func_8012BD14 / func_8012D624 / func_80143C74) L31274 - **§352** — ⚠ TWO IDENTICAL `__asm__ __volatile__("")` BARRIERS **MERGE WITH EACH OTHER** — SPELL THE SECOND ONE DIFFERENTLY (P31 S67; byte-proven resident/func_800D128C, measured closeness 105 when they merged) L31486 - **§356** — MEASURE A DRAFT IN THE TU IT WILL LIVE IN, NOT IN THE STANDALONE PROBE (P31 S68; measured over 47 stored drafts) L31574 - **§361** — ★ — A LOOP-TAIL BYTE SIGNATURE THAT NAMES ITS SOURCE SHAPE — AND THE LAW THAT A "SCHEDULING TIE" MAY BE YOUR OWN EARLIER LEVER (P31 S68; byte-proven main/func_800241C0, fable escalation, 19 → 0 in 3 iterations) L31637 - **§370** — ★★ — A **HARD BOUND** FROM sched.c, AND THE reorg SLOT-STEAL DIAGNOSTIC (P31 S68; main/func_8001BC6C, 69 ins, NOT closed — 33 → 28 over ~45 measured compiles) L31838 - **§376** — ★★★ — A STANDALONE `match_one` CLOSENESS OF 0 IS A CLAIM ABOUT THE **BODY**, NEVER ABOUT THE **TU** (P31 S69; measured 0/28) L32055 - **§384** — ★★★ — A CARVE-CONFIG BANK IS RED UNTIL YOU RE-EXTRACT, AND THAT LOOKS EXACTLY LIKE A FALSE BANK (P31 S69; measured twice, cost one destroyed match) L32259 - **§378b** — ★★★ — THE FOUR VARIANTS OF THE DECL BLOCKER, AND THE TWO PLACES §378 DOES **NOT** APPLY (P31 S69, all four measured the same day) L32572 - **§398** — ★★★ — `family_remap` CARRIES THE **SOURCE** TU's DECL ENVIRONMENT INTO A DESTINATION THAT ALREADY OWNS THOSE NAMES (P31 S69; measured 3 banked of 22) L32835 - **§3-E.** — WHAT THE AGENTS REFUTED L33148 - **§408** — ★★★ — §406 REFUTED AS A SWEEP: THE SHAPE IS THE FAMILY, THE DISAGREEMENT IS THE DEFECT (P31 S71; 0 MATCH / 14 applied, 0 / 210) L33209 - **§411** — ★★★ — THE PACK MUST CARRY THAT FUNCTION'S OWN HISTORY (P31 S71; measured 38/39 vs 124/131) L33386 - **§428a** — ★★★ — TWO RESIDUALS THAT MOVE IN OPPOSITE DIRECTIONS UNDER EVERY LEVER USUALLY SHARE ONE CAUSE (P31 S72; `main/func_8001B0D4`, NEAR/53 -> MATCH; **my first answer here was WRONG and is kept below as the refutation**) L33988 ### (unbucketed — title matched no symptom vocabulary) (325) - **§3-How** — to use this L30 - **§1** — Idiom catalog (asm pattern → C that produces it) L39 - **§3-I3** — Division by a constant → magic multiply L54 - **§3-I4** — Runtime (variable) division → `divu` + zero-check `break` (NEEDS `--expand-div`) L60 - **§2** — Writing matching C (what makes gcc emit X) L69 - **§3a** — Escalation TIER above the permuter — web-research the compiler internals (HIGH VALUE, proven) L128 - **§3b** — §31-directed permuter mutation — bias the search over the class's levers (Phase 24 T5) L147 - **Residual** — B — a `return ` materialised late / merged instead of distributed per-site L886 - **§3-The** — A→B→C per-overlay workflow L1110 - **Dedup-credit** — (§11) for overlays — two shapes L1127 - **§14a** — The fleet bulk run (Phase 15 — `--auto-from`, 947 REAL → 74,527; 3.82% → 22.14% in one pass) L1188 - **§14d** — Deterministic recovery beats agent waves on the hard tail (Phase 15, the final-session finding) L1288 - **§14e** — Two hard-tail dead-ends (Phase 15 — documented so they aren't re-attempted) L1317 - **§3-The** — STEERABLE idioms (byte-confirmed this phase) L1423 - **Strategic** — conclusion — the match-% lever post-research L1454 - **§3-NEW** — / CONFIRMED residual classes (this session) L1679 - **Operational** — gotchas (cost real time) L1700 - **What** — WORKED — the Phase-20 reusable wins L1708 - **§21** — wave-distilled idioms (Phase 21) L1771 - **§26** — The cheap close=0 recovery lever is EXHAUSTED; `idiom_loop --assess` was DOUBLY inflated (Phase 21, cont.7) L2218 - **§3-The** — `_a` close=0 recovery banks 0/20 — same def-side wall as MAIN (0/40) L2224 - **§27** — Giant matching recipe (Phase 21 cont.7b — validated on func_80176D94, 152 ins) L2278 - **§28a** — decomp.wiki GCC patterns worth trying on BFM giants (decomp.wiki/compilers/GCC, raw at decompals/decompedia; PS1-applicable subset) L2364 - **§31** — THE gcc-2.7.2 CODEGEN MAP: pass → residual → C-lever catalog (Phase 23; 4 Fable5 agents read the compiler source) L2421 - **§36** — Fable5 giant-crack levers (Phase 24 T7 Fable5 batch; accumulates as each lands — full RTL dumps in `.run/t7/fable/`) L2506 - **§42d** — addendum — wave 4 (rtu_match fan-out over the mapped frontier, 2026-07-10c): 24/26 MATCH, +5 durable levers L3116 - **§3-B.** — THE EBB RULE — the general form of §46-L2 L3502 - **§3-E.** — Meta L3552 - **§50** — Refinements that BOUND §47/§48 (from the `func_80135EB0` wall, 21→6; Phase 26 session 8) L3610 - **§51a** — The bug class L3670 - **§51c** — THE METHOD (do not audit by reading the regex) L3696 - **§51d** — THE LAWS L3711 - **§51e** — The false-wall pipeline (why this is not just hygiene) L3773 - **§3-Why** — the wall is (probably) intrinsic L3979 - **§3-The** — case L4067 - **§3-The** — rule L4096 - **§55a** — New byte-proven levers (each from a banked or near draft) L4132 - **§60a** — What the first DIRECTED grinder run exposed (Phase 29 Task-13B, 2026-07-21) L4506 - **§60b** — The plateau autopsy's verdict: a `partial` drift is a WRONG DRAFT, not a missing transform (Phase 29 Task-13B close, 2026-07-21) L4544 - **§66** — Exercise a banking driver's SUCCESS path before pointing it at a wave: the free re-bank test (Phase 29 SESSION-17, 2026-07-24) L5193 - **§66d-2** — Two operational sharp edges L5323 - **§66d-3** — Read the ILS per-cycle SERIES, not its final best: a repeated score and a still-falling one look identical in a summary line and mean opposite things L5334 - **§67** — The arg-copy PLACEMENT lever: launder a parameter into a fresh pseudo AT the statement where the target's copy lands (Phase 29 SESSION-18, `func_8014D820` 25 → 16) L5349 - **§66d-4** — "ILS converged" means converged FOR THAT WEIGHT PROFILE, not a floor (amends §66d-3; Phase 29 SESSION-18) L5472 - **§69** — How to attack a behemoth: map it, don't draft it (Phase 29 SESSION-18, `func_80183814`, 5,122 ins) L5603 - **What** — is left, and what is byte-recorded as SPENT L5800 - **§3-The** — mechanism, with citations L6071 - **§3-Two** — diagnosis traps this function proved L6098 - **Practice** — Practice L6108 - **§3-The** — drift was an allocation decision, not missing code L6214 - **§3-The** — economics L6245 - **§71** — has a blind spot, and this is it L6260 - **§3-The** — flagged "#1 move" LOST — and why the failure is informative L6336 - **§78** — 's attribution primitive, run and reproduced L6346 - **Cold-start** — economics, now complete L6352 - **Also** — reproduced on this function L6435 - **§3-And** — the banking footnote (§75a class A, one line) L6439 - **§83a** — READ THE HEADLINE NUMBER CORRECTLY: a LENGTH drift makes `match_one`'s count meaningless L6453 - **§83b** — THE LEVER: find the parameterised REPEAT before decoding case-by-case L6461 - **§83e** — §80 vindicated again, on the same day it was written L6500 - **§3-The** — conflict L6578 - **§3-THE** — FAILURE MODE — widening only `engine_core.h` is worse than not starting L6586 - **§3-The** — precondition, and how to check it in one grep L6593 - **Reading** — , for the next person L6610 - **§3-The** — guard refuses a class that largely works L6625 - **§3-The** — blindness ladder, now complete — FOUR classes `match_one` cannot see L6683 - **Consequence** — for the backlog ledger L6693 - **§88** — `cross_jump` will not merge a common suffix containing a CALL; and §78 is scoped to ORDERED comparisons only (Phase 29 SESSION-20, the behemoth close-out) L6708 - **§88a** — repeated CALL-shaped blocks are left UNMERGED; call-free tails are merged for you L6713 - **§89** — Two throughput rules the project already had written down and was not following (Phase 29 SESSION-20) L6760 - **§3-The** — standing sequence L6792 - **§90b** — "Byte-neutral" is not "wanted": undo on the SUCCESS path too L6823 - **§90c** — A library-callable function must FAIL CLOSED on an unconfigured module L6833 - **§90e** — An agent's CONCLUSION and its EVIDENCE fail independently — re-derive the premise, not the fix L6852 - **§93** — `set -o pipefail` attributes a pipeline failure to the LAST stage, not the failing one (Phase 29 SESSION-21, `func_8014D820`) L6956 - **§101** — The STALE DEFAULT class: a guard whose cause was removed is a silent skip wearing a safety label (Phase 29 SESSION-22, three instances in one session) L7279 - **§110** — A unit must define exactly ONE function, and "ends in `;`" does not tell you which line defines it (Phase 29 T65) L7674 - **§115** — A `func_XXXXXXXX` predicate rots by design: the same name-form assumption in THREE places (Phase 29 T78) L7884 - **§3-The** — fix moves the DEFINITION, not the stub — and here is why the obvious shortcut fails L7929 - **§117** — Spell the sibling's symbol from the SIBLING's address, not the exemplar's kind (Phase 29 T82) L7960 - **§118** — Ordinal (positional) immediate resolution: compare C tokens to the DIFFERING asm uses (Phase 29 T87) L7997 - **§119** — Two levers on the SAME axis, opposite directions: test the off-diagonal (Phase 29 T89) L8031 - **§3-The** — wiring trap that cost two attempts L8077 - **§3-The** — method (keep this) L8247 - **§3-The** — instrument rules that make its answer trustworthy (this is where I failed) L8257 - **§3-The** — corrected results (each SHA-verified, from a clean tree, restore re-verified) L8272 - **§3-The** — instrument trap that hid it (and it is §124's shape again) L8324 - **§3-The** — mechanics L8333 - **§3-The** — idiom they kept re-deriving: the constant-offset fold L8390 - **§127b** — the knowledge was in a SOURCE COMMENT, not the cookbook L8420 - **§128** — A raw NUL in C source makes grep SILENTLY SKIP the file (P30 S28, 137 files) L8427 - **§128a** — a negative control must corrupt a SCRATCH COPY, never the tracked file L8459 - **§3-The** — real blocker underneath, for the record L8511 - **§3-The** — diagnostic ladder that finally located it (reusable) L8557 - **Defect** — 1 — a pre-§8e MERGED DOUBLE is not a single-table predecessor L8613 - **Defect** — 2 — `as` writes a corpse and nothing deletes it L8631 - **§3-The** — fingerprint, and the 30-second ladder that found it L8641 - **§3-The** — transferable rule L8662 - **§132a** — `--like` is for a sibling with NO record; against one that HAS a record it over-derives (P30 S29, `ov_SC07_010`) L8669 - **§135** — Six byte-verified gcc-2.7.2 idioms from the P30 S6f-h waves (and the two-lane wave shape that found them) L8799 - **§3-The** — codegen idioms L8804 - **§3-The** — wave shape that produced these L8853 - **§136** — The LOCAL-VARIABLE lever: how many C locals, at what scope (P30 wave 4a, 25 byte-verified banks) L8871 - **§136a** — Blocker capture: classify on the OUTPUT, never on the exit status L9010 - **§136d** — Four gcc-2.7.2 levers the redraft lane found (each closed a residual no other lever moved) L9128 - **§136e** — §136c's PRECONDITION, and two more symptom keys (wave 4b batch 3) L9172 - **§136i** — The drafter model LADDER: Haiku → **Sonnet** → Opus → Fable5 (Drew, 2026-08-03) L9304 - **§3-The** — triage, cheapest first L9455 - **THREE** — carry variants hide in one "CARRY-FIXABLE" bucket — and they need different fixes L9524 - **STEP** — 0 of sibling-first: grep `src/` for a distinctive LITERAL from the `.s` L9580 - **§3-The** — generalisation — three corollaries worth more than the bug L9660 - **§3-And** — the inverse-lookup trap, same session L9677 - **§3-The** — three-line proof (do this before diagnosing any metric movement) L9714 - **§3-The** — two instrument defects it exposed L9723 - **§3-Two** — wrong mechanisms I chased first, and why they were wrong L9754 - **§3-The** — trap that hid it — SAME FUNCTION, TWO ROUTES, ONLY ONE IS FREE L9839 - **Route** — selection (why `--addr` sometimes says "nothing changed") L9848 - **§144** — THE LITERAL'S SPELLING PICKS THE IMMEDIATE ENCODING (P30 S40 wave 1, `func_801822E0`) L9922 - **§3-Why** — a correct draft can read as an intrinsic wall L10022 - **§3-The** — rule L10057 - **§3-B.** — `(v < 0x40) ? v : 0x3F` is folded to `MIN_EXPR` and expands to the WRONG SHAPE L10204 - **§3-D.** — Reproduce the original's BUGS verbatim L10228 - **§149** — Four instrument defects in one session, and the two questions they were hiding (P30 S43) L10277 - **§3-A.** — A prep step that returns its input on failure is indistinguishable from a search that found nothing L10283 - **§3-B.** — Same address + same name ≠ same body — and the ledger keys on address L10301 - **§3-C.** — `make: *** [...] Error N` is a summary, never a diagnosis L10317 - **§3-The** — fix L10353 - **§3-The** — method that found it (this is the transferable part) L10363 - **Diagnostic** — order (adopt this) L10390 - **§3-The** — mechanism (read from cc1's own `-dR` trace, not inferred) L10406 - **§3-The** — lever — a zero-emission insn that absorbs the blocked tick L10421 - **§3-The** — finding L10457 - **§3-The** — key L10466 - **§3-Two** — cautions that must travel with this technique L10477 - **§3-The** — companion defect (open) L10488 - **Symptom** — Symptom L10508 - **Mechanism** — (gcc source + RTL dumps, not inferred) L10513 - **§3-The** — cure — a fresh launder per site, each in its own block L10526 - **Companion** — levers from the same function L10536 - **§3-B.** — Two static base-derivation methods that must AGREE (use both) L10570 - **§155a** — the same failure class, one level up: SHAPE-blind table scanning (S45 p5) L10601 - **§155c** — the ZERO-REFERENCE trap: gcc splits a global-array address across the `lui` and the LOAD (S46) L10644 - **Symptom** — Symptom L10755 - **§3-Why** — the fork is chained (gcc source, validated insn-by-insn against -dS/-dR dumps) L10761 - **§3-The** — method (dump-arithmetic first, then place — no probing) L10774 - **§162a** — SHARPENS *(sharpens §161a, §131, §8a-pad, §129a)* L11075 - **§162b** — SHARPENS *(sharpens §48-A3, §156, §150, §76)* L11104 - **§162d** — SHARPENS *(sharpens §31, §21, §30, §55a)* L11133 - **§162e** — NEW L11175 - **§162f** — SHARPENS *(sharpens §42d, §41d, §73, §10)* L11243 - **§162g** — NEW L11298 - **§162h** — SHARPENS *(sharpens §88, §88a, §50-B, §8)* L11334 - **§162i** — SHARPENS *(sharpens §135, §21, §42, §32)* L11402 - **§162j** — SHARPENS *(sharpens §25, §136d-1, §48-B, §46-L2)* L11427 - **§162k** — SHARPENS *(sharpens §1-I2, §12, §160d, §21)* L11456 - **§162l** — SHARPENS *(sharpens §48-B, §48-C1, §20, §21)* L11519 - **§162m** — SHARPENS *(sharpens §36, §158, §148, §153)* L11574 - **§158a** — THE FIFTH LEVER IS NOT AN ASM: `do { } while (0)` is a REGION ref-multiplier you MINT (P30 S48, `func_8017CBC8`, ov_MAIN_012 / jr_801789AC, 188 ins → MATCH) L11576 - **Size** — it before you write it (§158 step 1-2, applied) L11594 - **§3-The** — wrap BOUNDARY is the dial — and it is indiscriminate L11615 - **§3-Not** — a pure dial L11621 - **§162n** — NEW L11647 - **§162o** — SHARPENS *(sharpens §158, §136-1, §136-6, §79)* L11680 - **§162p** — SHARPENS *(sharpens §48-B, §46-L2, §156, §136d-1)* L11739 - **§162q** — SHARPENS *(sharpens §30, §30a, §135-2, §136-13)* L11756 - **§164** — S48 §163z SKEPTIC PASS (P30, 2026-08-12): 190 claims vetted, 82 banked L11882 - **§169** — THE MICRO-ADAPT LANE (P30 S49): edit a proven body, don't crack a new one L16317 - **§170** — THE A-PROP WORD-DIFF CARD (P30 S49): the lane that had no owner L16364 - **§171** — THE STALE SEED SYMBOL (P30 S50, 2026-08-13): why §170's 91%→57% was never codegen L16408 - **§172** — THE ORPHAN-SLOT MECHANISM v2 (P30 S50-Max): the complete frame-residue model for gcc-2.7.2 MIPS L16557 - **§172a** — TWO DECOMPILATION TELLS FROM THE SAME DIG (P30 S50-Max) L16611 - **§172b** — THREE MORE TELLS FROM THE GCC READ (P30 S50-Max, banked on Drew's ask) L16627 - **§174** — THE ADAPT-CARD WAVE RECIPE (P31 waves A/B, 2026-08-14): prevention beats recovery L16706 - **§176a** — THE VERIFICATION-LAYER LAWS (P31 overnight, 2026-08-15). What each check can and cannot prove. L16801 - **§176b** — BATCH-GATING MECHANICS (P31): what changes when N drafts land in ONE .c L16841 - **§3-C.** — The limit that remains (recorded, not solved) L17080 - **§176k** — TWO SELECTOR BUGS THAT SILENTLY SHRINK A WAVE L17206 - **§178** — SIX LEVERS MINED FROM THE WAVE-P JOURNALS (P31 S52), each byte-proven and source-cited L17280 - **§3-A.** — THE `$0`-ADD OPAQUE COPY defeats `make_regs_eqv` (func_80033398, 93 ins) L17292 - **§3-C.** — SINGLE-SET TEMPS GET THE BIRTHING BOOST (func_8001D3FC, 196 ins) L17321 - **§3-E.** — THE ZERO-OFFSET ALIAS HOLE (func_80037028, 71 ins) L17336 - **§179-B** — 🔴 THE HAND-WRITTEN-ASM TRANSCRIPTION CHECKLIST (maspsx + masked_diff; 10 byte-proofs) L17426 - **§179-C** — 🔴 A FUNCTION WITH NO EPILOGUE (falls into a sibling's shared tail) MUST BE FILE-SCOPE `__asm__` L17476 - **§179-D** — `gte_stflg` MUST CLOBBER `"$12"` OR THE WHOLE TEMP FILE ROTATES BY ONE L17527 - **§179-H** — A MID-BODY `.global LABEL` PAIR SLICES A BYTE-COMPARABLE FRAGMENT OUT OF A LARGER ROUTINE L17623 - **Considered** — and NOT banked L17646 - **§176-F** — Misdiagnosis triage: four residual verdicts that were lying L17824 - **What** — is NOT banked here L17841 - **§180c** — WHEN A BINARY'S MASS BAND IS SPENT, THE FLEET-WIDE DRAW IS STRICTLY BETTER L17902 - **Only** — ONE of 27 blocked drafts was wrong. The other 26 were correct and unbankable. L17921 - **§180d** — THE `pgrep` BRACKET TRICK PROTECTS THE PATTERN, NOT THE COMMAND LINE L17990 - **Three** — defects in one call path; the overlay slates that carry most of the wave work were being waved through L18402 - **§194-F** — `if ((*p = v = f()) == 0)` is an expand-time pseudo SPLITTER (store_expr's `want_value && MEM` path), not a fold — it partitions one value between local_alloc and global_alloc. BOUNDS §21's L1872 bullet, whose stated direction is byte-wrong on 3 of 4 instances, and CLOSES the control §167-37 asked for. L19236 - **§194-L** — §88b and §189-E are BOTH half-wrong, but not the way the candidate says: the compare-constant shape is a 2-D lookup (cmp_info ROW × constant-in-window), and naming matters on OPPOSITE sides of the window for the GE/LT rows vs the GT/LE rows L19563 - **§197-REJECTED** — §197-REJECTED L20733 - **§199-REJECTED** — §199-REJECTED L21129 - **§201-B** — In a narrowed PLUS/MINUS/AND/IOR/XOR expression the destination pointee is INERT — the sign of the materialized constant is decided by an OR over the UNWIDENED operands (convert.c trunc1), which bounds §1841 to direct constant stores L21231 - **§201-REJECTED** — eight, the session's highest L21465 - **§204-CONFIRMED** — 30 reports that the index already answered L21931 - **§204-REJECTED** — sixteen, twice the previous record L22025 - **§209** — THE NARROW LOCAL IS A DIAL IN TWO OPPOSITE DIRECTIONS, AND §194-B's "≥2 `sh` STORES" BOUND IS BYTE-WRONG (P31 S58) L22292 - **§212** — THE WALKING CURSOR IS COUNTABLE: `*wp++` emits one `addiu` PER STORE, `wp[0..2]` emits one (P31 S58) L22474 - **§213** — INDEPENDENT SAME-BASE STORES: THE EMISSION ORDER IS A PERMUTATION OF SOURCE ORDER, AND THE PERMUTATION IS NOT ALWAYS THE IDENTITY (P31 S58) L22519 - **§217** — DECODING A CALL'S STACK ARGUMENT SLOTS: `sw` at `0x10`/`0x14`/`0x18` are params 5/6/7 **(single observation — not yet cross-confirmed)** (P31 S58) L22697 - **§226** — FRAME PADS: FOUR WAYS §162i1/§2429's DEAD-LOCAL LEVER MISFIRES (P31 S58) L23018 - **§228** — READING THE DIVIDE, PART N: the off-by-one compare is `% K == 1`, and three more discriminators (P31 S58) L23079 - **§229** — THE ADDRESS IS A VALUE: NAMING IT MOVES THE `lui`/`addiu` PAIR — AND §L14410 SAYS THE OPPOSITE FOR A REASON (P31 S58) L23116 - **§231** — TRANSCRIPTION AND SEMANTIC-READ HYGIENE: six ways the listing misleads (P31 S58) L23180 - **§194-B** — addendum (P31 S58) — BOUND 2 is byte-wrong; see §209 Direction A L23277 - **§176-B** — addendum (P31 S58) — the misdiagnosis direction L23283 - **§164-63** — addendum (P31 S58) — the interposed asm works when the SECOND value is an ordinary assignment L23298 - **§193-A** — / §194-E addendum (P31 S58) — where the twin's body actually lives L23307 - **§235** — THE PHANTOM SYMBOL: A MASKED `MATCH` CAN CARRY A RELOCATION THAT DOES NOT EXIST (P31 S58b) L23398 - **§238** — SAME NAME, DIFFERENT FUNCTION: THE OVERLAY-HOMONYM TRAP (P31 S58b) L23561 - **§240** — `A + K + B`: WRITE THE CONSTANT **BETWEEN** THE TWO RUNTIME TERMS (P31 S58b) L23635 - **§241** — THE FOLDED SIGN-EXTEND-AND-SCALE: `sll 16 ; sra (16 − log2 scale)` (P31 S58b) L23664 - **§252** — THE GUARDED PRE-DECREMENT: `(x != 0) && (--x == 0)` (P31 S58b) L24032 - **§255** — THE EMPTY CASE, PART 2: FOUR TREE SHAPES IT BUYS (P31 S58b) L24079 - **§258** — ADDENDA TO EXISTING SECTIONS (P31 S58b) L24194 - **§202** — addendum (P31 S58b) — THE DEF-SIDE ALIAS ALSO CLEARS A RETURN+PARAM DOUBLE CONFLICT L24243 - **§205** — addendum (P31 S58b) — CHAINED ASSIGNMENT: N≥3 IS INNERMOST-FIRST, AND THE TEXT MIRRORS EMISSION L24254 - **§208** — addendum (P31 S58b) — IT SCALES TO SIX SITES, AND IT HAS AN EXACT INVERSE L24271 - **§210** — addendum (P31 S58b) — THREE CONFIRMED SPELLINGS OF THE BOOLEAN TAIL L24300 - **§213** — addendum (P31 S58b) — THREE MORE PERMUTATION LAWS FOR INDEPENDENT SAME-BASE STORES L24359 - **§217** — CROSS-CONFIRMED (P31 S58b) — AND THE INCOMING HOME SLOT IS THE MIRROR L24476 - **§220** — addendum (P31 S58b) — THE PARAMETER, NOT A COPY (SEVEN CARDS) L24493 - **§225** — addendum (P31 S58b) — THE GUARD-CLAUSE FINGERPRINT, AND THREE MORE SHAPES L24590 - **§229** — addendum (P31 S58b) — NAME IT **INSIDE** THE ARM L24662 - **§230** — CROSS-CONFIRMED (P31 S58b) L24673 - **§231** — addendum (P31 S58b) — FOUR MORE WAYS THE LISTING MISLEADS L24682 - **§232** — CROSS-CONFIRMED (P31 S58b) L24713 - **§260** — THE §154-A LEADING-ISLAND SPLIT: ONE CONFIG LINE, AND THE ISLAND PEELS FROM THE END (P31 S59, byte-proven) L24763 - **§262** — A LANE'S YIELD IS ONLY A LANE FACT IF IT IS SIZE-MATCHED (P31 S59) L24897 - **§264** — FOUR TELLS-LANE C RECIPES, EACH DRIVEN TO MATCH (P31 S59) L24968 - **ADD-1** — → §231 addendum (also cross-ref from §195-D) — THE MASKED-`jal` "MISSING CALL" ILLUSION L25128 - **ADD-6** — → §172b-1 / §264 addendum — SHIFT-AS-TEST: `(x << 16) != 0` TESTS THE LOW HALF WITHOUT TRUNCATING THE PSEUDO L25182 - **ADD-7** — → §256 addendum — THE SINGLE-GUARD GOTO: THEN-BLOCK OUT OF LINE AT THE TAIL L25191 - **ADD-3** — → §238 addendum — TWO BINARIES CAN EACH DEFINE THE SAME `func_` NAME WITH DIFFERENT BYTES, AND NO GENERATED REPORT SHOWS IT L25381 - **§270** — The A-prop 0-bank anatomy: a byte-correct body still needs FOUR layers to agree (P31 S59) L25559 - **ADDENDUM** — to §1-I5 L25849 - **ADDENDUM** — to §164-51 L25914 - **ADDENDUM** — to §176-F5 L25930 - **ADDENDUM** — to §225 L25959 - **ADDENDUM** — to §229 — A POINTER'S NUMBER OF USES DECIDES WHETHER ITS ADDRESS FOLDS OR SURVIVES A CALL L26147 - **ADDENDUM** — to §226 — A DEAD LOCAL SCOPED TO A NESTED BLOCK BUYS A MID-FUNCTION `addiu sp` PAIR, NOT A FRAME-SIZE CHANGE L26265 - **ADDENDUM** — to §74 (func_800D0E30, resident) L26633 - **ADDENDUM** — to §172b-4 (func_80185054, ov_SC03_097) L26669 - **ADDENDUM** — to §265 (func_8017DC80, ov_SC07_002) L26707 - **ADDENDUM** — to §17 (func_800CB794, md_MAIN_036) L26746 - **ADDENDUM** — to §162p (func_8017C120, ov_MAIN_012) L26794 - **ADDENDUM** — to §20 (~L1947) (func_80186AD0, ov_SC06_032) L26828 - **ADDENDUM** — to §164-56 (func_8017F644, ov_SC04_005) L26858 - **ADDENDUM** — to §237 (func_8017F7FC, ov_SC03_092) L26893 - **ADDENDUM** — to §195-E — a goto-ladder's STORES must sit AT the labels, after the gotos, not inline before them L27245 - **Harness-defect** — flags L27719 - **ADDENDUM** — to §167-40 (func_8017E2CC, ov_SC04_015 — wave dg) L27812 - **ADDENDUM** — to §87 (func_801815F4 ov_SC06_032; corroborating func_801840DC ov_SC05_017, func_80189C68 ov_SC03_006 — wave dg) L27846 - **ADDENDUM** — to §263 (func_801E83AC, md_SC04_029 — wave dj) L27885 - **ADDENDUM** — to §265 (func_8017D878, ov_SC03_107 — wave dj; corroborated by a REJECTED, contradicted card in wave dm — see closing) L27899 - **ADDENDUM** — to §6 (func_801811F0, ov_SC03_102 — waves dj and dl, corroborated by a self-reported "nothing new" dm-wave card) L27913 - **ADDENDUM** — to §195-G (func_80183BB0, ov_SC05_001 — wave dj) L27927 - **ADDENDUM** — to §74 (func_8017EB34, ov_SC03_117 — counter/clamp variant; wave dj, corroborated by dk/dl/dm cards on the same function) L28005 - **ADDENDUM** — §37 — merged into the §153/§236-5 entry above (func_801A419C, wave dl) L28025 - **ADDENDUM** — §6 — merged into the §6 entry above (func_801811F0, wave dl) L28033 - **ADDENDUM** — to §238 (func_80182CB4, ov_SC02_000 — wave dl) L28041 - **ADDENDUM** — to §137a (func_801684B4, ov_MAIN_012; corroborated independently by func_80189E68, func_8017FF9C, func_801822B4, func_8018DA8C — wave dl) L28059 - **ADDENDUM** — to §8c / §88d (func_8016AB6C, ov_MAIN_012 — wave dm) L28075 - **ADDENDUM** — to §73 / §30#2 (func_800D1984, resident — wave dm) L28089 - **From** — ck + cl + cm L28217 - **ADDENDUM** — to §5a (func_80181F74, ov_SC03_112, wave cn) L28359 - **ADDENDUM** — to §265 (func_8017E26C, ov_SC04_016, wave cn) L28409 - **ADDENDUM** — to §42b (func_8018247C, ov_SC07_002, waves cu + cw) L28447 - **ADDENDUM** — to §195-E (func_800CFC1C, md_MAIN_003, wave cv) L28533 - **ADDENDUM** — to §215 addendum (func_800CB2C8, md_MAIN_033, waves cv + cw) L28578 - **ADDENDUM** — to §236 item 4 (func_8017D268, ov_SC04_006, wave cw) L28634 - **Harness-defect** — flags (not idioms — flagged for the operator) L28695 - **ADDENDUM** — to §250 (func_8017D7CC, ov_SC03_115 — cx/cy/cz/dr) L28736 - **ADDENDUM** — to §225 (func_8017E190, ov_SC03_115 — cx/cy/cz) L28781 - **ADDENDUM** — to §45-A (func_8017F6A4, ov_SC02_016 — cy/cz) L28834 - **ADDENDUM** — to §249 (func_80182ED4, ov_SC04_004 — dp/dr/dt) L28878 - **ADDENDUM** — to §199-A (func_801816FC, ov_SC02_005 — dp/dr/dt) L28923 - **Harness-defect** — flags L29012 - **§289** — an array local's address-taken base keeps every element's store alive, even though only one pointer escapes (`func_80189EFC`, ov_SC04_011) (P31 S60; waves #, byte-proven) L29094 - **ADDENDUM** — to §264-3 — the explicit entry copy's BOUND: required exactly when the RAW value must outlive the call that consumes only the PROMOTED value L29248 - **ADDENDUM** — to §276 — the SHARE direction: spell the second adjacent symbol RELATIVE to force ONE anchor L29280 - **ADDENDUM** — to §31's density-dummy dial (L2460/L2497) — the dose is TWO refs, and the dummy must sit where the loser is live-through L29296 - **§300** — S61 DISTILL BATCH NOTES (waves ab8/ab16/ab24/ab32 · g0a–g0f · m0a · ds1/ds2 · m0b) L29602 - **§306a** — T4 DISTILL ADDENDA (P31 S62; four byte-proven refinements to existing laws, verified against the book by an independent verifier; each names its parent §) L29901 - **Addendum** — §148-A2 addendum — the empty-asm insn_count dial (N bare `__asm__("")` = exactly +N real i (func_801835B0) L30453 - **Addendum** — Chained *2*2 array index folds to one copy;sll, not two (func_80011380) L30509 - **Addendum** — Last if-arm's nested if un-fuses the whole preceding chain (func_8017FE88) L30529 - **Addendum** — Orphan sh triplet to $sp is a write-only local array (func_8017F274) L30622 - **RETRIEVAL** — FAILURES this round (not new knowledge — a RETRIEVAL defect) L30656 - **Addendum** — Integer-space address arithmetic is a THIRD no-movable spelling, and a distant `SYM[0]` re (func_8017D89C) L30704 - **RETRIEVAL** — FAILURES this round L30765 - **§323b** — A SCRIPT THAT PARSES argv AT IMPORT CANNOT BE SHARED; EXTRACT THE PREDICATE, DO NOT COPY IT (P31 S67) L30935 - **§330** — THE NEIGHBOUR-SHAPE LEVER IS THE CHEAPEST FIRST MOVE, AND IT IS UNDER-USED (P31 S67; four independent instances in one 20-function wave) L31042 - **§347-addendum** — A THIRD INSTANCE, AND THE SHARPEST STATEMENT OF THE RULE (md_MAIN_025/func_800CB300, 243 ins) L31372 - **§359** — (§43-adjacent) — SPELL A SIGN-WIDEN AS AN EXPLICIT TWO-STEP, FUNCTION-SCOPED TEMP (P31 S68; byte-proven main/func_80012B58, 69 ins, 58 → 3 → 0) L31608 - **§360** — THE "COMPILER FOUND A SHORTER EQUIVALENT THAN THE TARGET" PAIR (P31 S68; main/func_800241C0, 68 ins, 68 → 19) L31621 - **§363** — ★★ — THE OVERLAY-LAYOUT ASSUMPTION IS A SYSTEMIC BUG CLASS, AND `main` IS THE EXCEPTION THAT FINDS IT (P31 S68; six instances, four of them in one session) L31705 - **§369** — REUSE THE **COMPARE CONSTANT'S OWN VARIABLE** FOR A MASK THAT KEEPS COALESCING (P31 S68; md_SC07_004/func_801AEC38, 365 ins) L31822 - **§372** — ★★★ — THE **COPY-CAPTURE PAIR**, AND THE ONE ZERO-BYTE EDIT THAT DEFEATS BOTH (P31 S68; byte-proven main/func_8003491C, 78 ins, fable escalation closed 5 → 0) L31939 - **CROSS-REFERENCE** — TO §370 — checked and found INAPPLICABLE here, which is the point L32018 - **§377** — THREE HARNESS DEFECTS FOUND IN ONE GATING SESSION, ALL "A CONFIDENT NUMBER ABOUT A SMALLER WORLD" (P31 S69) L32097 - **§380** — ★★★ — **A SECOND SET OF A PSEUDO DISQUALIFIES IT FROM `move_movables`** (P31 S69; main/func_800215F4, 465 ins, closeness 106 → 59 → 39) L32195 - **§382** — TWO FOLD REASSOCIATIONS THAT NEED THEIR OWN STATEMENT (P31 S69) L32232 - **§389** — ★★★ — `h_norm` IS BLIND TO INDEXED-GLOBAL RELOCS, SO FREE WORK BECOMES AN INVISIBLE SINGLETON (P31 S69; 31 stubs / 4,811 ins recovered, 8 banked same day) L32409 - **§390** — ★★★ — MINIMUM DISTANCE IS NOT MINIMUM WORK; RANK TWIN CANDIDATES BY EFFORT, AND FILTER LOOKALIKES BY RATIO (P31 S69; byte-proven ov_SC01_077/func_80184D50, banked) L32450 - **§394** — ★★ — TWO ALIGN-1 ACCESSES IN ONE FUNCTION RESERVE A PHANTOM STACK SLOT (P31 S69; ov_SC02_005/func_80180610) L32560 - **§314b** — ★★ — TWO ABS-RANGE GUARDS IN ONE FUNCTION NEED **DIFFERENT SPELLINGS** (P31 S69; byte-proven ov_SC04_002/func_8018691C, 111 ins) L32645 - **§397** — ★★★ — RE-RUN THE TWIN SCAN AFTER EVERY EXEMPLAR BANK; A CLUSTER SIBLING IS FREE THE MOMENT ITS EXEMPLAR LANDS (P31 S69; ~250k tokens spent proving it the expensive way) L32785 - **§398b** — ★★ — NAMING A SUB-EXPRESSION IN A LOCAL CHANGES WHICH PSEUDO SURVIVES; INLINE IT AT BOTH USE SITES (P31 S69; byte-proven ov_SC03_028/func_80183264, 93 ins) L32865 - **§399** — ★★★ — FOUR LEVERS FROM THE FINAL S69 ROUND (P31 S69; each byte-proven, none previously in the cookbook) L32892 - **§400** — ★★ — A BASELINE CHECK THAT CONFLATES "ABSENT EVERYWHERE" WITH "CHANGED UNDER US" SILENTLY DROPS NEW FILES (P31 S69; 8 files, one session) L32932 - **§401** — §401 L32967 - **§402** — §402 L33000 - **§403** — §403 L33024 - **§404** — §404 L33056 - **§406** — ★★ — THE PROLOGUE-WEAVE CLASS IS MECHANICAL AND LARGE (134 open stubs) L33158 - **§407** — ★★ — LATE-WAVE ADDENDA TO §405 (the last agents in) L33180 - **§409** — ★★★ — THE S71 JOURNAL-FUELLED WAVE: 100% FIRST-PASS MATCH, AND THE NINE LAWS IT BROUGHT BACK (P31 S71) L33261 - **§3-The** — nine laws this wave produced L33288 - **§413** — ★★★ — DIFFICULTY IS THE RESIDUAL CLASS, NOT `nins` — ROUTE THE MODEL TIER OFF HISTORY (P31 S71, Drew) L33473 - **§416** — ★★ — FOUR LEVERS FROM THE S71 OVERNIGHT LANE, none of which the cookbook held (P31 S71) L33572 ## All sections, in order - **§3-How** — to use this L30 - **§1** — Idiom catalog (asm pattern → C that produces it) L39 - **§3-I1** — Unsigned range check: `(x - lo) < (hi-lo)` → `addiu`+`sltiu` L41 - **§3-I2** — Byte mask forces `andi` even after `lbu` L47 - **§3-I3** — Division by a constant → magic multiply L54 - **§3-I4** — Runtime (variable) division → `divu` + zero-check `break` (NEEDS `--expand-div`) L60 - **§2** — Writing matching C (what makes gcc emit X) L69 - **§3-T1** — Loop pointer: top-of-body for `addu` induction, not constant-folded `addiu` L71 - **§3-T2** — Source statement order drives instruction scheduling L78 - **§3-T3** — Types L85 - **§3-T4** — Branch polarity: invert the source condition to flip gcc's chosen branch L90 - **§3** — When a diff is pure scheduling → decomp-permuter (harness built, Phase 6) L107 - **§3a** — Escalation TIER above the permuter — web-research the compiler internals (HIGH VALUE, proven) L128 - **§3b** — §31-directed permuter mutation — bias the search over the class's levers (Phase 24 T5) L147 - **§4** — Flag/toolchain gotchas L190 - **§5** — Known hard-residual classes (instruction-identical, one byte-exact blocker) L199 - **§5a** — Cross-jump tail-merge — gcc collapses two byte-identical blocks the original kept separate (FIX FOUND) L211 - **§6** — Per-module optimization mixing — the -O0 boot module (Phase 7) L265 - **Detecting** — the opt level (do this first) L273 - **Build** — mechanism — per-file opt override (splat resegmentation) L307 - **§7** — PsyQ SDK types & symbols (the library-call prerequisite) L322 - **§8** — rodata island (compiler jump tables) — the `.data→.rodata→.data` sandwich (Phase 7) L339 - **§8a** — rodata island in a flat OVERLAY — the tail sandwich, per matched jr-function (Phase 26 — PoC PROVEN) L361 - **§8a-pad** — a trailing `.word 0x00000000` under a jtbl dlabel is `.align` PAD, not an entry (Phase 26 session 6, byte-proven) L399 - **§8b** — MULTI-jtbl per overlay — the `ld_interleave --order` sandwich + the same-subseg cases (Phase 26 session 4) L423 - **§8c** — Splitting a TU means rebuilding its DECLARATION ENVIRONMENT, not moving text (Phase 26 session 6) L456 - **§8d** — Templating a body INTO a TU must not CHANGE its declaration environment — demote the carried data externs (Phase 26 session 8, byte-proven on `func_8015AE2C` ×133) L502 - **§8e** — The jtbl ALIGNMENT LAW + the pad-spec filter — multi-table .rodata spans (Phase 29, byte-proven; `.run/probe_jtbl/verdict.md`) L549 - **§9** — Link real PsyQ library objects byte-exact (Phase 7 — GO proven) L632 - **§9.1** — Generalised per-object linker — `tools/psyq_link.py` (+ `psyq_link_lib.py`), 18/18 libcd byte-exact L661 - **§9.2** — Wire a library region into the build with NOLOAD — no data carving (`tools/psyq_link_region.py`) L685 - **§9.3** — Make it the build: resegment + swap + resolve (`tools/psyq_integrate.py`, libcd DONE) L704 - **§9.4** — Integrating a SECOND library (libgs block 6 after libcd) — multi-library gotchas L731 - **§9.5** — Integrating a WHOLE multi-block library in one call (full libgs — Phase 7 session G) L759 - **§9.6** — Scaling library linking to the whole EXE (Phase 8 — 8 libs linked, 20%→50% byte-identical) L785 - **§9.7** — Binary-agnostic toolchain refactor (Phase 9) — the reusable pattern for Gen2 L821 - **§10** — Closing the regalloc/scheduling hard tail by hand (LZSS, Phase 7 session F — the full close) L854 - **§3-The** — clean object-level metric (use this, not the permuter score, for jtbl/rodata functions) L863 - **Residual** — A — commutative `|`/`&`/`+` result lands in the wrong source-operand register L875 - **Residual** — B — a `return ` materialised late / merged instead of distributed per-site L886 - **§11** — Cross-binary dedup & code-sharing (Phase 11 — "one match unlocks many") L927 - **§3-The** — mechanism: game-code dedup is SOURCE-LEVEL, not an object swap (R-D1, the key lesson) L945 - **Per-binary** — toolchain provenance (R24) L978 - **§12** — Ultracode harvest — parallel-draft + byte-gate at scale (Phase 12, resident: 1.4%→71.7% in one session) L983 - **§13** — Add a location overlay — the canonical runbook (Phase 13; the Phase-15 fleet recipe) L1075 - **One-command** — onboarding — `tools/new_overlay.sh ` L1081 - **§3-The** — flat-blob overlay config (what the template encodes) L1090 - **§3-THE** — NON-4-ALIGNED-OVERLAY GOTCHA (≈75% of the fleet; fixed in the template + Makefile, automatic) L1098 - **§3-The** — A→B→C per-overlay workflow L1110 - **Dedup-credit** — (§11) for overlays — two shapes L1127 - **Fleet** — build — `make build-all` / `make check-all` L1139 - **§14** — Propagate a matched function across the fleet — `tools/dedup_propagate.py` (Phase 15) L1145 - **§14a** — The fleet bulk run (Phase 15 — `--auto-from`, 947 REAL → 74,527; 3.82% → 22.14% in one pass) L1188 - **§14b** — Harvesting the UNMATCHED shared core — the match_one wall (Phase 15) L1211 - **§14c** — Callee-signature-aware harvest — breaking the extern-type-conflict wall (Phase 15, T6) L1232 - **§14d** — Deterministic recovery beats agent waves on the hard tail (Phase 15, the final-session finding) L1288 - **§14e** — Two hard-tail dead-ends (Phase 15 — documented so they aren't re-attempted) L1317 - **§15** — Struct-heavy shared-core pipeline (Phase 16) — empirical determinations (S0) L1332 - **§16** — Guided hand-matching the struct-heavy core (Phase 17 — beats the §15 brute-force) L1354 - **§17** — The compiler-quirk wall — the matching TOOLKIT (Phase 18; gcc-2.7.2 source + byte-gated) L1395 - **Register-allocation** — ORDER (call-crossing $s0/$s1 swap) → FORCE it with register pins (byte-proven) L1403 - **§3-The** — STEERABLE idioms (byte-confirmed this phase) L1423 - **§3-The** — pipeline gotcha — match_one ≠ the gate; `sig_unify` is MANDATORY L1440 - **§3-The** — LOOSE-TYPING wall is real for narrow params (Phase 16, reconfirmed) L1447 - **Strategic** — conclusion — the match-% lever post-research L1454 - **§17a** — The TOOLKIT at WAVE scale (Phase-18 Step-3b/Step-1 — measured) + the pipeline-integration gotchas L1464 - **§18** — Per-file `-O0` split inside an overlay/blob (Phase 19 T1) L1538 - **§19** — Scaling the toolkit waves — the recovery PIPELINE + the propagation CAP (Phase 19 T3) L1616 - **§20** — The wave-at-scale GATE CAP + residual-class verdicts (Phase 20) L1651 - **§3-THE** — CAP: at this tail the match_one→gate gap is the LOOSE-TYPING CALL-GRAPH wall (not cheap plumbing) L1656 - **Diagnostic** — lesson: a failed in-TU build leaves a STALE `.o` L1673 - **§3-NEW** — / CONFIRMED residual classes (this session) L1679 - **Operational** — gotchas (cost real time) L1700 - **What** — WORKED — the Phase-20 reusable wins L1708 - **Phase-20** — RESOLUTION — `tools/cast_call_sites.py` BUILT + the cap re-diagnosed (R14, byte-proven) L1720 - **§21** — wave-distilled idioms (Phase 21) L1771 - **§22** — DEF-side loose-typing recovery + grinder blacklist (Phase 21) L2024 - **§23** — Giant `func_80153E00` cracked (scalar-data CAST); BUT most giant drafts are STALE+INCOMPLETE, and a diag MUST remove artifacts (Phase 21 — byte-proven + a self-correction) L2051 - **§24** — The `ov_SC01_077_a.c` split-file vein: split-aware propagation, but loose-typing-gated (Phase 21) L2104 - **§25** — The "schedule" class is mostly COALESCING (pin-crackable), not scheduling; + the gate two-stage + h_exact over-counts ×134 (Phase 21, cont.6) L2151 - **§3-The** — crack: the residual was gcc-2.7.2 COPY-COALESCING, not the instruction scheduler L2163 - **§3-The** — genuine scheduler — `rank_for_schedule` (sched.c), for when it IS scheduling L2179 - **§3-The** — genuine schedule WALLS (do NOT re-grind — stub) L2188 - **§3-h** — _exact OVER-COUNTS ×134 — verify shareability before crediting a class's "reach-134" (R14) L2196 - **§3-The** — gate two-stage — sig_unify is a FALLBACK, not unconditional (`gate_stage.py`, §19 folded in) L2208 - **§26** — The cheap close=0 recovery lever is EXHAUSTED; `idiom_loop --assess` was DOUBLY inflated (Phase 21, cont.7) L2218 - **§3-The** — `_a` close=0 recovery banks 0/20 — same def-side wall as MAIN (0/40) L2224 - **Where** — this leaves the reach-134 tail (cont.6 option-3, now CONFIRMED byte-backed) L2252 - **§27** — Giant matching recipe (Phase 21 cont.7b — validated on func_80176D94, 152 ins) L2278 - **§28** — Banking a "close=0 gate-rejected" giant: the canonical-extern recovery (Phase 22 T1, byte-proven on func_8015126C ×134) L2344 - **§28a** — decomp.wiki GCC patterns worth trying on BFM giants (decomp.wiki/compilers/GCC, raw at decompals/decompedia; PS1-applicable subset) L2364 - **§28c** — The close=0 recovery is NOT fully exhausted (§26 corrected, R14); + the dedup_propagate registry-skip recovery (Phase 22 T2) L2371 - **§28b** — The struct-walled close=0 giant (§28 case #3) IS bankable: the engine_types.h type-lift (Phase 22 T2, byte-proven on func_80156B74 ×134) L2376 - **§28d** — The "macro-extern-injection" lever: freeing reach-134 inline matches dedup_propagate skips as "not self-contained" (Phase 23, `tools/inject_capped_externs.py`) L2385 - **§29** — Reasoning-model (GLM5.2) DEF-side reconciliation idioms + the wall's hard limit (Phase 23 T10.7, `tools/glm_reconcile.py`) L2393 - **§30** — Fable5Max cracks §20/§10 "unsteerable" from the gcc SOURCE: store-vs-load is a `/s` aliasing flag, the def-side wall has a macro escape, + the birthing-boost (Phase 23, byte-proven on giant `func_8014EE14` 248 ins ×134) L2401 - **§30a** — §30 generalizes to the FULL near-miss backlog (via STANDARD Opus agents, not just Fable5) + 2 more steer levers + the mechanical-integration throughput unlock (Phase 23 (a)) L2413 - **§31** — THE gcc-2.7.2 CODEGEN MAP: pass → residual → C-lever catalog (Phase 23; 4 Fable5 agents read the compiler source) L2421 - **§32** — The region-a CAMERA-GIANT idiom set: struct-base hoisting + 4 sibling levers (Phase 24 T7, Fable5-cracked on `func_80129CF8` 191 ins, match_one MATCH; transferable to the 6 sibling giants) L2441 - **§33** — Automating the giant decl-reconcile: `tools/reconcile_decls.py` (the DATA analog of §20's `cast_call_sites`) + a fleet-majority type oracle (Phase 24 T7b, byte-proven on `func_80129CF8`) L2453 - **§34** — The `func_80138ED0` giant crack: gcc-2.7.2's **3-qty sort bug** + the **zero-byte asm allocation toolkit** + the **giv-init fence** (Phase 24 T5; Opus→close=21, Fable5→MATCH ×134) L2473 - **§35** — The region-a sibling-giant harvest: difficulty ≠ $s-reg count (it's global-array hoisting) + the banking recipe + new loop idioms (Phase 24 T7, 5 parallel Opus-Max agents) L2490 - **§36** — Fable5 giant-crack levers (Phase 24 T7 Fable5 batch; accumulates as each lands — full RTL dumps in `.run/t7/fable/`) L2506 - **§37** — The T7 §G giant endgame: 6/8 cracked, meta-laws + transferable levers (Phase 24, 2026-07-07; FULL byte-verified detail + gcc-2.7.2 line cites in `docs/gcc-2.7.2-map/t7g-giant-harvest.md`) L2525 - **§38** — The WHALE `func_80144B9C` (770 ins): the -O0 struct-assign memcpy idiom + the -O0 reach-134 ×134 rollout (Phase 24 T7 §G, cheap Opus — no Fable5, no calls.c) L2546 - **§39** — The ×1→×134 giant-endgame: propagate a matched **-O2** giant via the NATIVE DEFINE-macro path (Phase 24 T7 §G close, 2026-07-08) L2556 - **§40** — Structural families: the MECHANICAL symbol-remap (crack one exemplar → remap the rest, ~0 tokens) (Phase 25 T3/T7, 2026-07-08) L2572 - **§40a** — The DECL-RECONCILE pass (type-lift so remapped drafts compile in the sibling TU) (Phase 25 T7.2, 2026-07-08) L2620 - **§40b** — The reloc-tracker blind spot: the indexed-global idiom that hid the "reach-1 tail" (Phase 26 Task 1, 2026-07-11, byte-verified V0/V1) L2653 - **§40c** — The h_seq per-sibling reconcile: templating a reconcile-class crack ×134 (Phase 26 Task 8, 2026-07-12, byte-proven) L2695 - **§31-triage** — R17 applies to CODEGEN residuals, never to a compile ERROR (Phase 26 session 7, Drew asked) L2712 - **§41** — The DEF-SIDE canonical-sig wall: mechanically banking a drafted giant past `conflicting types` (Phase 25 T5b batch-2, 2026-07-09; `tools/canon_sig_reconcile.py`, byte-proven on `func_8013B274`) L2729 - **§41a** — v3.1: the def-side wall was ~71% TOOL-shaped — the five measured defects + the laws that dissolve them (Phase 25 T6, Fable5, 2026-07-09) L2788 - **§41b** — T7 execution: the object-only probe OVER-counts BANKABLE by two link/rodata classes (Phase 25 T7-M1, 2026-07-10) L2843 - **§41c** — T7-M2: the ×134 def-side-wall sweep via per-sibling RE-reconcile (Phase 25, 2026-07-10; 4,389 banks, ~0 agent tokens) L2873 - **§41b** — addendum — M4 "reconcile_decls" tier is ALSO a probe over-count: 0/8 mechanical (Phase 25 T7-M4, 2026-07-10) L2892 - **§41d** — `void`→`s32` is NOT always byte-neutral: gate the RAW draft FIRST (Phase 26 session 6, byte-proven) L2912 - **§42** — The F-band ≤28 regalloc crack wave: register-pin/DENSITY levers beat the permuter (Phase 25 T7 F-band, 2026-07-10; Ultracode 9-worker wave, 4/9 banked byte-identical, 266 swept ×134) L2934 - **§42a** — addendum — wave 2 (residuals + 29-100 band): iso-MATCH ≠ real-TU bank, the memcpy→struct-assign fix, +5 levers (2026-07-10b) L2987 - **§42b** — addendum — wave 3 (Max, 2026-07-10c): THE STALE-OBJECT GATE TRAP + the read-global `&`-cast drift + fix L3028 - **§42c** — addendum — wave 3 (Max orchestrator + CORRECTED Ultracode fan-out, 2026-07-10c): the real-TU-faithful parallel harness (rtu_match) + 7/9 crack, ZERO iso-drift L3067 - **§42d** — addendum — wave 4 (rtu_match fan-out over the mapped frontier, 2026-07-10c): 24/26 MATCH, +5 durable levers L3116 - **§42e** — propagating a CRACK ×134: the def-finder bug + the byte-drift residual (the "remap-fail" misdiagnosis) L3155 - **§43** — The K&R s16-param definition DISSOLVES the "narrow-param wall" for by-value register args (Phase 25 task A, Fable5 crack of the 369-ins giant `func_80166994` ×134, 2026-07-11) L3229 - **§44** — The Phase-25 cheap-Opus giant batch: 5 structural levers + the §43 extension (2026-07-11, 6 crackers over the frontier giants) L3276 - **§45** — The flagship `func_80133CD4` crack (399 ins ×134): the merged-variable permutation-breaker + the 1-death local-alloc gate (Phase 25 task A giant escalation, Fable5 gdb-on-cc1, 2026-07-11) L3332 - **§46** — The `func_80178D40` crack (890 ins ×134, the heaviest core in the game): four LOOP-STRUCTURE levers cheap-Opus found by reading loop.c/jump.c/cse.c (Phase 26 session 8, 2026-07-13) L3347 - **§47** — The live-length SLIDER: splitting a global.c allocno-priority TIE with one zero-byte asm (Phase 26 session 8, Fable5 Max, byte-proven on `func_8017BEBC` 952 ins ×113) L3399 - **§48** — The 12-core jr crack wave: the ALLOCNO-PRICING dials and the EBB rule (Phase 26 session 8, Ultracode, 9/12 MATCH first pass) L3439 - **§3-A.** — ALLOCNO-PRICING DIALS — move a value into the register you want, byte-neutrally L3447 - **§3-A4** — SINK THE CONSUMER CALL INTO THE ARMS (the inverse of A1; `func_8016AB6C`, byte-proven) L3478 - **§3-B.** — THE EBB RULE — the general form of §46-L2 L3502 - **§3-C.** — TYPE- AND SHAPE-DRIVEN CODEGEN (the C type literally selects the addressing mode) L3518 - **§3-D.** — THE CROSS-JUMP RATCHET (the sharpest new trap — `func_80131340` L-C) L3542 - **§3-E.** — Meta L3552 - **§49** — The LUID DIAL: a zero-byte SCHEDULING dial (the sched.c analogue of §47) — `func_8017A4AC` (536 ins ×134), Phase 26 session 8 L3561 - **§50** — Refinements that BOUND §47/§48 (from the `func_80135EB0` wall, 21→6; Phase 26 session 8) L3610 - **§51** — TOOLING INTEGRITY: the silent skip, and how to hunt it L3664 - **§51a** — The bug class L3670 - **§51b** — Why the byte-gate cannot save you L3686 - **§51c** — THE METHOD (do not audit by reading the regex) L3696 - **§51d** — THE LAWS L3711 - **§51e** — The false-wall pipeline (why this is not just hygiene) L3773 - **§51f** — Checklist for any new corpus-scanning tool L3789 - **§51g** — When the thing you are scanning has a GRAMMAR, parse the grammar (`tools/cdecl.py`) L3803 - **§52** — The WALKER-FAMILY skeleton: 6 regalloc-order levers + a deeply-characterized intrinsic wall (`func_80178004`, 165 ins ×134; Phase 26, Fable5, 2026-07-15) L3947 - **§3-The** — 6 levers (the "walker-family skeleton" — apply to the 12 siblings; levers 1-5 retire ~half the residual) L3958 - **§3-Why** — the wall is (probably) intrinsic L3979 - **§52a** — The regalloc sibling wave: new levers + two new wall classes (cheap-Opus applying §52, 2026-07-15) L3993 - **§52b** — Sibling wave 2: more de-pin levers, a third wall class, and the match_one→whole-binary gap at scale (2026-07-15) L4031 - **§53** — SWEEP A FAMILY WITH THE TOOL ITS EXEMPLAR NEEDED: the jr/switch carve, and how omitting it manufactured the "families don't template" doctrine (Phase 28 T1, 2026-07-15) L4062 - **§3-The** — case L4067 - **§3-Why** — 0/8 was structural, and predictable from two words L4079 - **§3-The** — rule L4096 - **§3-The** — meta-lesson (R35, and why this one is expensive) L4112 - **§55** — Core-crack wave levers + the GATE-ORCHESTRATION law (Phase 29 T3, 13-agent ultracode wave, 2026-07-17) L4127 - **§55a** — New byte-proven levers (each from a banked or near draft) L4132 - **§55b** — THE GATE-ORCHESTRATION LAW (3 traps, ~3.5h lost; all recovered, 0 data lost) L4156 - **§55c** — Sizing the propagate: a TARGETED propagate is ~4 min/core, and "it's slow" was a BROKEN-TREE ARTIFACT L4175 - **§54** — `--fix-def-sig`: the member's CANONICAL DECLARATION is a build step too (tiny-IMM mega-pools, +4,801, Phase 29 T6, 2026-07-16) L4197 - **§56** — Banking a hand-drafted GIANT into its exemplar TU: self-contained draft vs live-TU decls, 4 reconciliation tactics (`func_8013FAF8`, 312 ins ×138, Phase 29 T4, 2026-07-17) L4221 - **§56b** — PROPAGATING an h_seq giant: the exemplar's externs MUST be fleet-canonical, not the draft's types L4266 - **§57** — The SELF-decl normalize: the sibling's OWN caller declares the templated fn divergently (the third §17a-1 direction; `tools/normalize_self_decls.py`, func_801670E4 ×137, Phase 29, 2026-07-18) L4290 - **§57a** — Two NSD corrections + the SURGICAL-ONLY law + the honest broad-sweep yield (Phase 29, 2026-07-18) L4337 - **§58** — match_one MATCH ≠ BANK: the four blind spots + the crack-wave reconcile-before-bank law (Phase 29 crack-wave, 2026-07-18) L4377 - **§59** — Three h_seq sweep-residual classes match_one/the-exemplar-bank don't reveal (Phase 29 crack-wave close, 2026-07-18) L4411 - **§60** — Classify the residual, don't rank it: the deterministic residual→class classifier and what it measured about the backlog (Phase 29 Task-13A, 2026-07-21) L4441 - **What** — it measured — the whole open backlog, byte-grounded L4465 - **§3-Two** — corollaries worth remembering L4484 - **§3-The** — parallel-probe race this surfaced L4497 - **§60a** — What the first DIRECTED grinder run exposed (Phase 29 Task-13B, 2026-07-21) L4506 - **§60b** — The plateau autopsy's verdict: a `partial` drift is a WRONG DRAFT, not a missing transform (Phase 29 Task-13B close, 2026-07-21) L4544 - **§61** — Task 14: the gate ladder's missing stage is the ARITY pre-pass, and it is TU-side not draft-side (Phase 29, 2026-07-21) L4579 - **§61a** — The Task-5 wave: 11/12 MATCH, 0 banked — three DISTINCT integration walls, each now named (Phase 29, 2026-07-21) L4640 - **§61b** — The jtbl gate stage: built, and the ORDERING law it exposed (Phase 29 Task-14 stage 4, 2026-07-21) L4692 - **§61c** — The jtbl bank is INCREMENTALLY valid and CLEAN-INVALID (Phase 29, 2026-07-21) — the blocking finding L4747 - **§61d** — The undo was eating the tree: two tools, one defect, invisible to the byte-gate (Phase 29, 2026-07-22) L4813 - **§62** — The jtbl RECONCILE must also follow the carve: the post-carve draft reconcile (`harvest_verify._jtbl_reconcile`, Phase 29 SESSION-11, 2026-07-22) L4867 - **§63** — The fresh-138 DEF-SIDE blocker: fix the HEADER decl, not the draft (`fix_header_decl.py`, Phase 29 SESSION-13, 2026-07-23) L4911 - **§64** — The §20 type-lift's three laws: fold the tagged typedef, check VISIBILITY, and strip only what is TEXTUALLY IDENTICAL (`lift_types.py`, Phase 29 SESSION-14, 2026-07-23) L4942 - **§64a** — VARIANT types: UNIQUIFY the camps, do not reconcile them (`uniquify_type.py`, Phase 29 SESSION-14) L4991 - **§63** — UPDATE (Phase 29 SESSION-14) — `fix_header_decl`'s "SAFE" verdict is FLEET-BLIND; it MUST be R22-validated L5034 - **§65** — The stranded-draft recovery: BLAST-RADIUS TIERS, and the per-overlay de-macroize that refutes §20's DEF-conflict wall (`tools/demacroize.py` + `tools/blocker_probe.py`, Phase 29 SESSION-16, 2026-07-24) L5049 - **§65a** — The blast-radius taxonomy (makes §61's law structural instead of remembered) L5064 - **§65b** — The escape: de-macroize the instantiation, don't touch the shared header L5079 - **§65c** — `rtu_match` MATCH → bank held 13/13 on self-decl, but broke on the FIRST callee-decl case L5115 - **§65d** — Existing-ladder baseline, measured (do this before building a recovery stage) L5125 - **§65e** — Two oracles, and the disagreement is the finding (R34 in practice) L5135 - **§65f** — The de-macroize lever's BOUNDARY, measured: byte-neutral 14 times of 15, and the 15th is why the gate exists L5152 - **§65g** — Where the cheap levers STOP: the local-type and in-TU-self-decl classes did not yield L5173 - **§66** — Exercise a banking driver's SUCCESS path before pointing it at a wave: the free re-bank test (Phase 29 SESSION-17, 2026-07-24) L5193 - **§66a** — The widest write in a pipeline is the one most likely to be UNDECLARED L5215 - **§66b** — A metric parsed out of another tool's prose goes NULL silently when the label changes L5234 - **§66c** — Before a wave, verify the FUEL exists; an "already attempted" set built from the wrong directory lies in BOTH directions L5251 - **§66d** — The permuter⇄reader loop: alternate a random search with a byte-verified idiom, and let `residual_class` decide whose turn it is (Phase 29 SESSION-17) L5279 - **§66d-1** — What transfers between giants is the LOOP, not the PIN L5314 - **§66d-2** — Two operational sharp edges L5323 - **§66d-3** — Read the ILS per-cycle SERIES, not its final best: a repeated score and a still-falling one look identical in a summary line and mean opposite things L5334 - **§67** — The arg-copy PLACEMENT lever: launder a parameter into a fresh pseudo AT the statement where the target's copy lands (Phase 29 SESSION-18, `func_8014D820` 25 → 16) L5349 - **§67a** — Run the symbol-set guard BEFORE you pay for a gate (`tools/symcheck.py`, Phase 29 SESSION-18) L5439 - **§66d-4** — "ILS converged" means converged FOR THAT WEIGHT PROFILE, not a floor (amends §66d-3; Phase 29 SESSION-18) L5472 - **§66d-5** — `residual_class`'s "structural ⇒ permuter CPU is waste" is WRONG for schedule permutations (measured, Phase 29 SESSION-18) L5525 - **§68** — A comment-only line halted the extern scan, and the skip label blamed the type cap (Phase 29 SESSION-18) L5558 - **§69** — How to attack a behemoth: map it, don't draft it (Phase 29 SESSION-18, `func_80183814`, 5,122 ins) L5603 - **§70** — The giv-init base register: walk the PARAMETER, not a copy of it (Phase 29 SESSION-18, `func_801777BC`) L5653 - **§71** — Before mapping a giant, look for an already-matched SIBLING beside it (Phase 29 SESSION-18, `func_8017D960`, 3,338 ins) L5694 - **§72** — A `register __asm__` pin is a PREFERENCE, not a reservation (Phase 29 SESSION-18, `func_8017F510`) L5760 - **§3-The** — honest fix was source-level and cheap L5784 - **§3-Giv** — record order (the §70 family) L5794 - **What** — is left, and what is byte-recorded as SPENT L5800 - **§73** — A def-side self-decl conflict has TWO axes: RETURN (fleet widen, T2) and PARAMS (casts at each use, T0). Diagnose which before paying for the expensive one (Phase 29 SESSION-19, `func_8014F3E8` + `func_8014D4C0`) L5817 - **§74** — Auditing a pinned draft: the §72 hazard is CALLER-SAVED pins spanning a call, and only the disassembly can tell you (Phase 29 SESSION-19, `func_8017D960` b2, 5 pins) L5856 - **§75** — A propagation cap is usually a MINORITY-SPELLING SOURCE OVERLAY, not a wall: census the carried extern before believing the exclusion message (Phase 29 SESSION-19, `func_8014F3E8` ×4 → ×138) L5900 - **§75a** — The exclusion classes, enumerated with named causes (Phase 29 SESSION-19, the 134-binary `dedup_extend` sweep) L5959 - **§75b** — A body's preamble can carry `#define`s, not just `extern`s; extraction lifts only the externs (Phase 29 SESSION-19, `func_80165CA0` ×3 → fleet) L5982 - **§75c** — Class-B's remedy is the FULL §17a-1 PAIR (decl **and** call-site cast); a decl-only fix moves the error and looks like a new wall (Phase 29 SESSION-19, `func_8012F14C`) L6031 - **§76** — The allocno CLASS (local vs global) is the dominant regalloc lever, and C reaches it ONLY through declaration scope and variable reuse (Phase 29 SESSION-19, behemoth #3 `func_8017F510` 1,511 ins, 97 → MATCH, pin-free) L6062 - **§3-The** — mechanism, with citations L6071 - **§3-The** — attribution primitive (use this before calling anything a scheduling residual) L6091 - **§3-Two** — diagnosis traps this function proved L6098 - **Practice** — Practice L6108 - **§77** — Every extraction tool carries a NARROW hard-coded preamble set; anything outside it silently caps the body's reach. Diff the preamble before you gate. (Phase 29 SESSION-19 — three variants in one session, two different tools) L6118 - **§3-The** — CANDIDATE gate and the REAL gate need DIFFERENT preambles — keep the difference out of the bank L6158 - **§78** — A LENGTH drift can be a register grant in disguise; and `fold` never leaves a literal first in an `|` chain (Phase 29 SESSION-19, behemoth #2 `func_8017D960` 3,338 ins, 1806 → 0, pin-free) L6208 - **§3-The** — drift was an allocation decision, not missing code L6214 - **§3-The** — economics L6245 - **§79** — For a 0-callee giant, fingerprint by DATA symbols (§71 cannot fire); and the STACK-SLOT ORDER is a declaration-order oracle (Phase 29 SESSION-19, `func_8017BF14` 4,763 ins, cold start → 45/4763) L6254 - **§71** — has a blind spot, and this is it L6260 - **§3-NEW** — LEVER — the frame layout reads back the original declaration order L6274 - **§76** — confirmed at scale, and a pin nuance L6285 - **§3-The** — residual, and the honest read L6294 - **§80** — A do-not-re-buy entry is scoped to its BASE, not to the function; and the pin's hidden cost is an unconditional `qty_phys_sugg` (Phase 29 SESSION-19, `func_8017BF14` 45 → 0) L6304 - **§3-The** — pin's hidden cost, with the citation L6325 - **§3-The** — flagged "#1 move" LOST — and why the failure is informative L6336 - **§78** — 's attribution primitive, run and reproduced L6346 - **Cold-start** — economics, now complete L6352 - **§81** — Banking a jr (jump-table) function: the 3-step carve chain, and why `match_one` cannot see the problem (Phase 29 SESSION-19, `func_8017C954`) L6357 - **§3-The** — defect this exposed: a shared type that is present but invisible L6388 - **§82** — Two source-shape oracles from behemoth #6: a duplicated `addiu $aN,$sp,K` across a `jal` means the block was INLINED, and scalar-vs-aggregate decides WHEN a stack slot is allocated (Phase 29 SESSION-19, `func_8017C730` 1,061 ins) L6404 - **§3-1.** — The inlined-helper signature L6409 - **§3-2.** — Scalar vs aggregate decides *when* the slot is allocated L6423 - **Also** — reproduced on this function L6435 - **§3-And** — the banking footnote (§75a class A, one line) L6439 - **§83** — The parameterised-repeat law, the spill-area trap, and why a per-case edit cannot move a per-case symptom (Phase 29 SESSION-20, `func_80183814` 5,122 ins, cold-ish start → 36 structural / 99.3%) L6446 - **§83a** — READ THE HEADLINE NUMBER CORRECTLY: a LENGTH drift makes `match_one`'s count meaningless L6453 - **§83b** — THE LEVER: find the parameterised REPEAT before decoding case-by-case L6461 - **§83c** — TRAP: a "dead local" in a prior draft may be gcc's OWN spill area L6479 - **§83d** — CSE's quantity budget is WHOLE-FUNCTION, so a local rewrite cannot fix a local symptom L6486 - **§83e** — §80 vindicated again, on the same day it was written L6500 - **§84** — The DERIVED-OFFSET remap bug: a hand-computed literal that encodes the DISTANCE between two per-overlay symbols, and why `match_one` is structurally blind to it (Phase 29 SESSION-20, `func_8013D53C`) L6506 - **§3-The** — construct L6511 - **§3-Why** — it survived every candidate gate L6529 - **§3-THE** — FIX IS MECHANICAL — the tool already holds the answer L6544 - **Scope** — , measured (do not over-generalise — §80) L6552 - **§3-Two** — ladder lessons banked with it L6562 - **§85** — The RETURN-axis fleet widen is ALL-OR-NOTHING: widening the shared header alone guarantees a conflict in the source overlay (Phase 29 SESSION-20, `func_8012CC88` / `func_8014D12C`) L6573 - **§3-The** — conflict L6578 - **§3-THE** — FAILURE MODE — widening only `engine_core.h` is worse than not starting L6586 - **§3-The** — precondition, and how to check it in one grep L6593 - **§3-Do** — the WHOLE axis in one edit, then R22 once L6601 - **Reading** — , for the next person L6610 - **§86** — Pinned-exemplar templatability is a PER-FAMILY property, not a per-member rate; and the §42e pin guard is now over-conservative (Phase 29 SESSION-20) L6623 - **§3-The** — guard refuses a class that largely works L6625 - **§3-THE** — LAW: all-or-nothing PER FAMILY L6634 - **§3-Why** — the two live families differ from the three dead ones — the open question L6661 - **§87** — `match_one` COMPILES but never LINKS, so an unresolvable data symbol reads as MATCH; and stored drafts go STALE against the tree (Phase 29 SESSION-20) L6667 - **§3-The** — blindness ladder, now complete — FOUR classes `match_one` cannot see L6683 - **Consequence** — for the backlog ledger L6693 - **§3-The** — cheap discriminator, before spending a sweep L6700 - **§88** — `cross_jump` will not merge a common suffix containing a CALL; and §78 is scoped to ORDERED comparisons only (Phase 29 SESSION-20, the behemoth close-out) L6708 - **§88a** — repeated CALL-shaped blocks are left UNMERGED; call-free tails are merged for you L6713 - **§88b** — the `slti` literal-position law (extends §78 to comparisons) L6720 - **§88d** — BANKING ORDER: run the §81 carve chain BEFORE banking, never after L6735 - **§88e** — a wrong diagnosis, refuted properly (the model for how to treat an inherited lever) L6742 - **§88f** — the missing rung: a RELOCATION gate between `match_one` and the binary L6752 - **§89** — Two throughput rules the project already had written down and was not following (Phase 29 SESSION-20) L6760 - **§89a** — MEASURE the write set; do not assert its tier (`tools/blast_radius.py`) L6766 - **§89b** — the parallel gate farm existed; the family path could not reach it (`tools/sweep_parallel.py`) L6779 - **§3-The** — standing sequence L6792 - **§90** — Five tool-integrity laws from one session, each of which changed an answer (Phase 29 SESSION-21, 2026-07-27) L6800 - **§90a** — A comparison tool MUST share its reference oracle's index space, exactly L6806 - **§90b** — "Byte-neutral" is not "wanted": undo on the SUCCESS path too L6823 - **§90c** — A library-callable function must FAIL CLOSED on an unconfigured module L6833 - **§90d** — Do not measure a live wave's drafts (§87 in real time) L6844 - **§90e** — An agent's CONCLUSION and its EVIDENCE fail independently — re-derive the premise, not the fix L6852 - **§91** — A structure-TRANSFER is only valid where the structure corresponds: the `--like` role trap (Phase 29 SESSION-21, `func_8012AAAC` ×137) L6876 - **§3-The** — three-hypothesis trail, because two of them were wrong and the wrongness is instructive L6905 - **§92** — Conforming a DECLARATION: pointer changes are caller-neutral, scalar-WIDTH changes are not (Phase 29 SESSION-21, `tools/conform_decls.py`) L6925 - **§93** — `set -o pipefail` attributes a pipeline failure to the LAST stage, not the failing one (Phase 29 SESSION-21, `func_8014D820`) L6956 - **§94** — A family sweep's `0/N` is a TYPE-CARRY failure until proven otherwise: lift the exemplar's local types, ALL of them, transitively (Phase 29 SESSION-21, `func_8016B6BC` 0/137 → 137/137) L6981 - **§95** — `reconcile_tu` dropped the SIBLING declarators of a multi-symbol `extern` line (Phase 29 SESSION-21, `func_80176218`) L7017 - **§96** — The same rewrite, one shape down: `reconcile_tu` matched statements to lines by TEXT, so every COMMENTED declaration was silently skipped (Phase 29 SESSION-22, `func_80176218` banked) L7052 - **§97** — The gate's own tree hygiene: a refused carve, an unchecked recovery, and a snapshot that captured a dirty tree (Phase 29 SESSION-22) L7100 - **§98** — `conform_decls` had three defects, and only the third needed R22 to find (Phase 29 SESSION-22, `func_8014CF04`) L7147 - **§99** — The narrow-param wall is a DEF-side problem with a ZERO-blast-radius fix: convert the definition to K&R (Phase 29 SESSION-22, `func_80175AB8` + `func_80175DA8`) L7201 - **§3-Two** — `reconcile_tu` bugs found underneath, one introduced while fixing the other L7224 - **§100** — Prefer the DRAFT-LOCAL fix: a type only one function uses belongs in its BODY, not in a shared header (Phase 29 SESSION-22, `func_80175DA8` 0/137 → 137/137) L7250 - **§101** — The STALE DEFAULT class: a guard whose cause was removed is a silent skip wearing a safety label (Phase 29 SESSION-22, three instances in one session) L7279 - **§102** — A PLUMBING verdict can MASK a DIFF; and K&R is not always a codegen change (Phase 29 SESSION-22, `func_8016EC0C`) L7306 - **§103** — A FILE-scope `extern` in a shared overlay TU is a GLOBAL constraint on every LATER function; move the DECL, not the draft (Phase 29 T48/T51, `func_80135260` — the fleet-wide half) L7341 - **§104** — Two silent-skip defects in one scan: match on MASKED text, emit from the ORIGINAL (Phase 29 T53, `gather_externs`) L7429 - **§105** — A gate's revert must survive an EXCEPTION, not just a failure (Phase 29 T53, `jtbl_family_bank`) L7465 - **§106** — Persist the MEASUREMENT, derive the POLICY: a stored route let a stale file out-vote the live table (Phase 29 T54, `residual_class._ROUTE`) L7504 - **§107** — A lever wired into ONE gate path is a lever most families cannot reach (Phase 29 T56, `func_80144090` 0/136 → 136/136) L7547 - **§108** — Diagnosing a family `0/N`: the four causes, and the third opt-in lever (Phase 29 T59) L7585 - **§109** — Conforming a definition to a shared header: fix the NAMES, then check the RETURN precondition (Phase 29 T60) L7634 - **§110** — A unit must define exactly ONE function, and "ends in `;`" does not tell you which line defines it (Phase 29 T65) L7674 - **§111** — The distinct-code metric is not noisy: a family pays it only if its members are byte-VARIANT (Phase 29 T66) L7715 - **§112** — A macro-scoped declaration only collides where the macro is INSTANTIATED (Phase 29 T67/T69, `audit_header_sigs.py`) L7764 - **§113** — An ARITY blocker only exists if the macro CALLS the function; an address-taken use has no call site (Phase 29 T72) L7810 - **§114** — The THIRD decl axis: a CALLEE the draft declares differently from the target TU (Phase 29 T76/T77) L7842 - **§115** — A `func_XXXXXXXX` predicate rots by design: the same name-form assumption in THREE places (Phase 29 T78) L7884 - **§116** — Optimization level is a property of the FILE, not the function: read a family 0/N against the member's stub HOME (Phase 29 T79) L7911 - **§3-The** — fix moves the DEFINITION, not the stub — and here is why the obvious shortcut fails L7929 - **§117** — Spell the sibling's symbol from the SIBLING's address, not the exemplar's kind (Phase 29 T82) L7960 - **§3-Why** — it survived so long: a MASKED oracle will MATCH a wrong symbol L7987 - **§118** — Ordinal (positional) immediate resolution: compare C tokens to the DIFFERING asm uses (Phase 29 T87) L7997 - **§119** — Two levers on the SAME axis, opposite directions: test the off-diagonal (Phase 29 T89) L8031 - **§120** — Uniquify draft-defined TYPE names; and check which of N staging sites you actually patched (Phase 29 T93) L8060 - **§3-Do** — NOT "strip the duplicate typedef" — it breaks the extern that uses it L8071 - **§3-The** — wiring trap that cost two attempts L8077 - **§121** — Synthesise externs for macro-DEFINED callees from the macro's own definition head (Phase 29 T95) L8095 - **§122** — GATE RAW BEFORE TRANSFORMING; the undo belongs to the WRITER, as a per-edit journal (P30 T0a, 2026-07-30) L8118 - **§123** — PROPAGATE A FAMILY WITH THE TOOL ITS TIER NEEDS: `dedup_propagate` is h_exact-only; its refusals are statements about the TOOL (P30 wave 1, 2026-07-30) L8150 - **§124** — A "not matched" verdict can mean the definition is there under a DIFFERENT C NAME: the asm-label alias blind spot (P30 SESSION-28, `func_8016191C` ×137) L8187 - **§124a** — a family sweep's `0 matched-exemplar families` may be a FILTER, not a wall L8232 - **§125** — Split the CARVE from the BODY before calling a jr residue a wall — and measure it by SHA from a CLEAN tree (P30 SESSION-28; **this section's first draft was WRONG and the method caught it**) L8240 - **§3-The** — method (keep this) L8247 - **§3-The** — instrument rules that make its answer trustworthy (this is where I failed) L8257 - **§3-The** — corrected results (each SHA-verified, from a clean tree, restore re-verified) L8272 - **§3-Two** — further notes worth keeping L8282 - **§3-The** — meta-lesson L8291 - **§126** — The carve-within-a-carve: an ADDRESS RANGE is not an OPTIMIZATION REGION (P30 T2, byte-proven end-to-end) L8298 - **§3-The** — finding: opt level is per FILE, so the file's contents must be opt-HOMOGENEOUS L8313 - **§3-The** — instrument trap that hid it (and it is §124's shape again) L8324 - **§3-The** — mechanics L8333 - **§126a** — a bare `except: continue` around a coverage-asserting oracle re-creates the silent skip (P30 S28) L8351 - **§127** — The `-O0` regime: the CONSTANT-OFFSET FOLD, and why `-O0` needs its own idiom set (P30 T3 wave, 15 targets) L8383 - **§3-The** — idiom they kept re-deriving: the constant-offset fold L8390 - **§3-The** — rest of the `-O0` regime (write PLAIN C, and mean it) L8401 - **§127a** — §71 (sibling-first) is the strongest `-O0` lever, and it beats the index L8411 - **§127b** — the knowledge was in a SOURCE COMMENT, not the cookbook L8420 - **§128** — A raw NUL in C source makes grep SILENTLY SKIP the file (P30 S28, 137 files) L8427 - **§128a** — a negative control must corrupt a SCRATCH COPY, never the tracked file L8459 - **§129** — Post-carve, `rtu_match`/`match_one` COUNT THE JUMP TABLE AS INSTRUCTIONS; and a carve must never be committed without its owner (P30 S28, `func_8013BD74`) L8471 - **§129a** — the target instruction count is INFLATED after a carve L8475 - **§129b** — never commit a carve whose owner is still a stub (it strands the carve) L8496 - **§3-The** — real blocker underneath, for the record L8511 - **§130** — An INCREMENTAL build can report BYTE-IDENTICAL for a change the CLEAN build cannot even LINK (P30 S28, the jr pair) L8520 - **§3-The** — diagnostic ladder that finally located it (reusable) L8557 - **§131** — The jtbl OVER-SPAN: `sltiu N` is ground truth in BOTH directions, and the zero-word rule only guards one (P30 S28, `func_80191C50`) L8567 - **§132** — The `JR-PAIR-IN-ONE-O0-OBJECT` "wall" was TWO instrument defects: a merged-double span the carve could not see, and a truncated object no rule deleted (P30 S29, `func_8013B83C` + `func_8013BD74`) L8604 - **Defect** — 1 — a pre-§8e MERGED DOUBLE is not a single-table predecessor L8613 - **Defect** — 2 — `as` writes a corpse and nothing deletes it L8631 - **§3-The** — fingerprint, and the 30-second ladder that found it L8641 - **§3-The** — transferable rule L8662 - **§132a** — `--like` is for a sibling with NO record; against one that HAS a record it over-derives (P30 S29, `ov_SC07_010`) L8669 - **§132b** — When the span's already-matched owner is ITSELF multi-switch: `--span-rel` (P30 S1, `func_8014032C`) L8694 - **§133** — The DEFAULT-FILTER class: three times in one session, a tool silently answered a narrower question than the one asked (P30 S1–S3) L8719 - **§134** — MULTI-LINE BLINDNESS: one root cause, four faces, in `family_remap`'s preamble scanner (P30 S6, 190 zero-crack families) L8745 - **§135** — Six byte-verified gcc-2.7.2 idioms from the P30 S6f-h waves (and the two-lane wave shape that found them) L8799 - **§3-The** — codegen idioms L8804 - **§3-The** — integration idioms (these decide whether a byte-correct draft BANKS) L8838 - **§3-The** — wave shape that produced these L8853 - **§136** — The LOCAL-VARIABLE lever: how many C locals, at what scope (P30 wave 4a, 25 byte-verified banks) L8871 - **§3-The** — splitting/merging rules (each closed a residual, byte-gated) L8887 - **§3-The** — type-form rules L8913 - **§3-The** — scheduling rules (refining §135-2 and §135-4) L8946 - **§3-The** — declaration surface (integration, not codegen) L8975 - **Wave** — economics (measured, for the next batch's sizing) L8987 - **§136a** — Blocker capture: classify on the OUTPUT, never on the exit status L9010 - **§136b** — A prior wave's "genuine byte-DIFF" verdict is NOT reliable evidence (4 of 4 refuted) L9067 - **§136c** — SIBLING-FIRST is a DERIVATION shortcut, not just a conflict fix (the fastest route in a family wave) L9103 - **§136d** — Four gcc-2.7.2 levers the redraft lane found (each closed a residual no other lever moved) L9128 - **§136e** — §136c's PRECONDITION, and two more symptom keys (wave 4b batch 3) L9172 - **§136f** — Two declaration sub-cases the reconcile lane surfaced (lane now 15/15 lifetime) L9220 - **§136g** — When the index points at the WRONG lever: two byte-refuted routings (func_801863B4) L9245 - **§136h** — CORRECTION: the zero-crack pool does NOT "refill with cheap work" (my error, byte-measured) L9274 - **§136i** — The drafter model LADDER: Haiku → **Sonnet** → Opus → Fable5 (Drew, 2026-08-03) L9304 - **§136j** — The failure MIX flips with function size (measured across four bands, one session) L9336 - **§137** — REGALLOC-PERM is a TWO-COMPILE ARITHMETIC PROBLEM, not a permuter job L9378 - **§137a** — A gate verdict has a TIMESTAMP; re-check it against the draft's mtime L9420 - **§138** — The propagation lanes: a gate refusal is a DECLARATION, and which lever you owe depends on blast radius L9449 - **§3-The** — triage, cheapest first L9455 - **§3-The** — DEFINITION-side alias is the only escape when the fleet canon disagrees on a promoting param L9507 - **Rank** — the lane by measured concentration, not by class count L9515 - **THREE** — carry variants hide in one "CARRY-FIXABLE" bucket — and they need different fixes L9524 - **§134** — again, in a second tool — and the waiter rule corrected L9560 - **STEP** — 0 of sibling-first: grep `src/` for a distinctive LITERAL from the `.s` L9580 - **Reconciling** — a gate-refused draft: which way you edit depends on WHERE the TU's decl is L9599 - **§139** — A GATE THAT GREPS FOR VERDICTS MUST ASSERT 1:1 ACCOUNTING; and a `--src` filter must not survive a carve (P30 S38, wave 6: 10 of 16 drafts vanished) L9628 - **§3-The** — generalisation — three corollaries worth more than the bug L9660 - **§3-And** — the inverse-lookup trap, same session L9677 - **§140** — A METRIC IS NOT A MEASUREMENT UNTIL IT IS REPRODUCIBLE FROM THE COMMITTED TREE (P30 S1e: a phantom regression that gated the session's best lever) L9694 - **§3-The** — three-line proof (do this before diagnosing any metric movement) L9714 - **§3-The** — two instrument defects it exposed L9723 - **§3-The** — same swallow, twice more, in the integration spine L9743 - **§3-Two** — wrong mechanisms I chased first, and why they were wrong L9754 - **§141** — The §134 class is CLOSED: every line-shape decision now routes through `cdecl._mask` (P30 S39) L9774 - **§142** — An open stub whose `h_exact` class is MATCHED elsewhere is FREE. Propagate the body; do not gate a draft. (P30 S39, +7,710 ins in two commands) L9812 - **§3-The** — measurement (do this before any wave; it is ~20 lines and needs no builds) L9824 - **§3-The** — trap that hid it — SAME FUNCTION, TWO ROUTES, ONLY ONE IS FREE L9839 - **Route** — selection (why `--addr` sometimes says "nothing changed") L9848 - **§3-And** — the report-vs-bytes lesson attached to it L9856 - **§143** — `cast_call_sites` read a RETURN STATEMENT as a prototype and deleted it. A 0/39 sweep became 18/39. (P30 S40) L9868 - **§144** — THE LITERAL'S SPELLING PICKS THE IMMEDIATE ENCODING (P30 S40 wave 1, `func_801822E0`) L9922 - **§145** — Three loop/combine levers from the S40 wave-2 drafters (16/16 match_one) L9961 - **§146** — RE-MEASURE A WALL BEFORE YOU RESPECT IT. Both "permanent" giants fell to drafts already on disk. (P30 S6, +50,094 ins) L10011 - **§3-Why** — a correct draft can read as an intrinsic wall L10022 - **Then** — propagation returned 0/137 TWICE — both times a missing TYPE L10034 - **§3-Two** — errors of mine, both instructive L10043 - **§3-The** — rule L10057 - **§147** — The three-stratum FRAME LAW, and four "stop searching" verdicts (P30 S42, `func_8017C294`, serial run) L10070 - **§3-A.** — The frame has THREE strata, and stratum 3 is unreachable from C L10075 - **§3-B.** — A `?:` on MEMORY operands costs ~16 bytes of invisible frame; on REGISTER operands, zero L10091 - **§3-C.** — Inner-block declaration does NOT delay slot allocation — BYTE-REFUTED L10102 - **§3-D.** — A lone `$t8`/`$t9` in the target is RELOAD SCRATCH — reproduce the spill, don't pin the register L10107 - **§3-E.** — A `qty_compare` TIE is not spelling-reachable — recognise it and stop L10117 - **Consequence** — for the family (a real scheduling decision) L10129 - **§148** — The loop.c hoisting THRESHOLD is arithmetic you can compute, and the `?:` clamp that folds to MIN_EXPR (P30 S42, `func_8017C6F4`, 947 ins) L10179 - **§3-A.** — `move_movables` hoists iff `threshold × savings × lifetime ≥ insn_count` — and you can read it L10185 - **§3-B.** — `(v < 0x40) ? v : 0x3F` is folded to `MIN_EXPR` and expands to the WRONG SHAPE L10204 - **§3-C.** — A zero-byte ALLOCNO-PRIORITY slider L10218 - **§3-D.** — Reproduce the original's BUGS verbatim L10228 - **§149** — Four instrument defects in one session, and the two questions they were hiding (P30 S43) L10277 - **§3-A.** — A prep step that returns its input on failure is indistinguishable from a search that found nothing L10283 - **§3-B.** — Same address + same name ≠ same body — and the ledger keys on address L10301 - **§3-C.** — `make: *** [...] Error N` is a summary, never a diagnosis L10317 - **§3-D.** — "Cheap fuel" that was never probed: 0 of 31 templatable L10327 - **§150** — A register ROTATION across symmetric blocks is VARIABLE-IDENTITY evidence, not an allocator tie (P30 S43, `func_8017C6F4`, 947 ins ×4) L10346 - **§3-The** — fix L10353 - **§3-The** — method that found it (this is the transferable part) L10363 - **§3-Two** — corrections to the record L10379 - **Diagnostic** — order (adopt this) L10390 - **§151** — THE GHOST WEDGE: when a load-before-store transposition is unreachable by ANY statement order (P30 S43, `func_8017EF68`, 969 ins) L10401 - **§3-The** — mechanism (read from cc1's own `-dR` trace, not inferred) L10406 - **§3-The** — lever — a zero-emission insn that absorbs the blocked tick L10421 - **§3-The** — two fallouts, and how to close them (both measured, in order) L10429 - **When** — to reach for it L10441 - **§152** — BYTE SIZE is the family key that name- and h_seq-grouping both miss (P30 S43, the 0xECC family: 1 crack → 12 overlays → 11,364 ins) L10452 - **§3-The** — finding L10457 - **§3-The** — key L10466 - **§3-Two** — cautions that must travel with this technique L10477 - **§3-The** — companion defect (open) L10488 - **§153** — THE ADDRESS-REMATERIALISATION LAUNDER: a third zero-emission asm lever (P30 S43, `func_8018D98C`, 710 ins) L10500 - **Symptom** — Symptom L10508 - **Mechanism** — (gcc source + RTL dumps, not inferred) L10513 - **What** — does NOT work (14 byte-measured probes) L10520 - **§3-The** — cure — a fresh launder per site, each in its own block L10526 - **Companion** — levers from the same function L10536 - **§154** — Reading a disc payload: the module-id word, static base derivation, and "type 1 = uncompressed overlay" (P30 S44) L10556 - **§3-A.** — Payload word0 is a global MODULE ID; code starts after the header L10561 - **§3-B.** — Two static base-derivation methods that must AGREE (use both) L10570 - **§3-C.** — PAC type 1 = the same payload class as type 4, just NOT compressed L10582 - **§155** — hi/lo literal scanning MUST track base registers (S45) L10592 - **§155a** — the same failure class, one level up: SHAPE-blind table scanning (S45 p5) L10601 - **§155b** — check the TYPE your oracle returns before comparing against it (S45 p5) L10621 - **§155c** — the ZERO-REFERENCE trap: gcc splits a global-array address across the `lui` and the LOAD (S46) L10644 - **§156** — an ORPHANED reconcile poisons the fleet: `dedup_propagate`'s kept edit (S45 p6/p7) L10674 - **§157** — the cheap-tier size cliff, measured (S45 p6) L10721 - **§158** — The RANGE-EXTENDER: a fourth zero-emission asm lever completes the allocno toolkit (P30 S46 tier-3, `func_8017CE58`, 733 ins) L10746 - **Symptom** — Symptom L10755 - **§3-Why** — the fork is chained (gcc source, validated insn-by-insn against -dS/-dR dumps) L10761 - **§3-The** — method (dump-arithmetic first, then place — no probing) L10774 - **Bonus** — facts worth keeping L10791 - **§156** — THE PREFERENCE-DONOR MERGE: cross-region variable reuse is what fills a0-a3, and a call-arg use in ONE region steers the fill in ALL of them (P30 S46 tier-3, `func_80186E24`, 611 ins: 236-off "S11 regalloc-order" → MATCH, zero new pins) L10806 - **§159** — THE DECLARATION AXIS: conform to byte-truth, and make every guard state its COVERAGE (P30 S47; ~10,930 sites across 8 axes, fleet byte-identical) L10862 - **§160** — THE REACH-15 WAVE HARVEST: an align-1 block move, and the instrument that called it a wall (P30 S47) L10927 - **§161** — THE RETRY-WAVE HARVEST: a jump table indexed from zero, and two allocator traps (P30 S47) L11003 - **§162** — S48 WAVE-1 HARVEST (P30, 2026-08-11): the reach-ordered sibling campaign's first 12 targets L11048 - **§162a** — SHARPENS *(sharpens §161a, §131, §8a-pad, §129a)* L11075 - **§162b** — SHARPENS *(sharpens §48-A3, §156, §150, §76)* L11104 - **§162d** — SHARPENS *(sharpens §31, §21, §30, §55a)* L11133 - **§162e** — NEW L11175 - **§162** — THE LICM PAIR: what makes an address a movable AT ALL, and why the preheader order is the body order (P30 S47, `ov_MAIN_012`) L11177 - **§162f** — SHARPENS *(sharpens §42d, §41d, §73, §10)* L11243 - **§162g** — NEW L11298 - **§162** — CROSS-JUMP DIRECTION: the surviving copy is always the LATER one, so a BACKWARD `j` into a sibling arm is a source `goto` (P30 S48) L11300 - **§162h** — SHARPENS *(sharpens §88, §88a, §50-B, §8)* L11334 - **§162** — The cross-jump "CALL veto" is a COUNT law, not a CALL law (BOUNDS §88a; P30 S48, `func_80189540`) L11336 - **§162i** — SHARPENS *(sharpens §135, §21, §42, §32)* L11402 - **§162j** — SHARPENS *(sharpens §25, §136d-1, §48-B, §46-L2)* L11427 - **§162k** — SHARPENS *(sharpens §1-I2, §12, §160d, §21)* L11456 - **§162l** — SHARPENS *(sharpens §48-B, §48-C1, §20, §21)* L11519 - **§162m** — SHARPENS *(sharpens §36, §158, §148, §153)* L11574 - **§158a** — THE FIFTH LEVER IS NOT AN ASM: `do { } while (0)` is a REGION ref-multiplier you MINT (P30 S48, `func_8017CBC8`, ov_MAIN_012 / jr_801789AC, 188 ins → MATCH) L11576 - **§3-The** — law L11583 - **Size** — it before you write it (§158 step 1-2, applied) L11594 - **§3-The** — wrap BOUNDARY is the dial — and it is indiscriminate L11615 - **§3-Not** — a pure dial L11621 - **DIAGNOSTIC** — TELL — two faces, one law L11625 - **§162n** — NEW L11647 - **§162o** — SHARPENS *(sharpens §158, §136-1, §136-6, §79)* L11680 - **§162p** — SHARPENS *(sharpens §48-B, §46-L2, §156, §136d-1)* L11739 - **§162q** — SHARPENS *(sharpens §30, §30a, §135-2, §136-13)* L11756 - **§163** — S48 WAVES 2-3 HARVEST (P30, 2026-08-11/12): the five that were byte-probed and are actionable L11794 - **§163z** — THE UNVETTED REMAINDER (do not cite as law; each needs a dedupe pass) L11862 - **§164** — S48 §163z SKEPTIC PASS (P30, 2026-08-12): 190 claims vetted, 82 banked L11882 - **§16Xy** — SHARPENS *(sharpens §136d-3, §37 /s-DEP LATTICE, §135-2, §136-13, §162q)* L12334 - **§3-The** — `/s` drop clause is in ALL THREE dependence predicates, so the FIXED-ADDRESS STORE is what floats (P30 S48, `func_8017CA18`, ov_MAIN_012) L12336 - **§164z** — REFUTED CLAIMS: do NOT re-derive these L13670 - **§165** — S48 WAVE-4 HARVEST (P30, 2026-08-12): banked the same day the wave landed L13736 - **§16Z** — SHARPENS *(sharpens §37 "the /s-DEP LATTICE", §136-13, §136-14, §16Xy, §162q, `gcc-2.7.2-map/sched.md` §64)* L14394 - **§3-The** — ADDRESS-CLASS TABLE: which load/store pairs even REACH the `/s` clause (P30 S48 wave 4, `func_80185B44`, ov_SC03_014) L14396 - **§165z** — REFUTED THIS WAVE: do NOT re-derive L14912 - **§166** — THE DESTINATION-TU ORACLE (P30 S48): the seven-attempt bug that was never codegen L14956 - **§167** — S48 WAVE-5/6 HARVEST (P30, 2026-08-12): the saturation point L15012 - **§167z** — REFUTED IN WAVES 5/6: do NOT re-derive L16208 - **§168** — THE COUSIN TIER (P30 S49, 2026-08-12): h_seq's exact-hash brittleness, measured — and the similarity map above it L16265 - **§169** — THE MICRO-ADAPT LANE (P30 S49): edit a proven body, don't crack a new one L16317 - **§170** — THE A-PROP WORD-DIFF CARD (P30 S49): the lane that had no owner L16364 - **§171** — THE STALE SEED SYMBOL (P30 S50, 2026-08-13): why §170's 91%→57% was never codegen L16408 - **§171a** — THE MECHANICAL A-PROP DRAFT (P30 S50): 256 members banked with no agent in the loop L16474 - **§171b** — THREE CARRIES THE MECHANICAL DRAFT NEEDS (P30 S50, banking the top-reach families) L16524 - **§172** — THE ORPHAN-SLOT MECHANISM v2 (P30 S50-Max): the complete frame-residue model for gcc-2.7.2 MIPS L16557 - **§172a** — TWO DECOMPILATION TELLS FROM THE SAME DIG (P30 S50-Max) L16611 - **§172b** — THREE MORE TELLS FROM THE GCC READ (P30 S50-Max, banked on Drew's ask) L16627 - **§173** — THE STORED-PLUMBING RECOVERY RECIPE (P31 T6): symfix-first, per-group isolation, and where the verdicts have no drafts L16670 - **§174** — THE ADAPT-CARD WAVE RECIPE (P31 waves A/B, 2026-08-14): prevention beats recovery L16706 - **§175** — A CALLER-SAVED REGISTER PIN CAN BE A CORRECTNESS BUG, NOT JUST A SCHEDULING CHOICE (P31 wave H, 2026-08-15) L16776 - **§176a** — THE VERIFICATION-LAYER LAWS (P31 overnight, 2026-08-15). What each check can and cannot prove. L16801 - **§176b** — BATCH-GATING MECHANICS (P31): what changes when N drafts land in ONE .c L16841 - **§176d** — THE CONFLICT TABLE MUST BE SEEDED FROM THE TU, AND KEYED PER FILE (P31 S52, 2026-08-15) L16867 - **§176e** — SYMBOL IDENTITY IS COMPUTABLE OFFLINE (P31 S52): `tools/reloc_identity.py` L16906 - **§176f** — THE DECLARATION FORM IS A MATCHING LEVER, SO RECONCILE TOWARD THE FORM THE MATCH NEEDS (P31 S52) L16963 - **§176g** — SIZE A WAVE BY INSTRUCTIONS, NOT BY CARDS (P31 S52 — the adopted doctrine) L16994 - **§176h** — THE BATCH-SUBSTITUTION HAZARD MAP (P31 S52): seven holes, three wrong fixes, one law L17032 - **§3-A.** — The seven under-reporting holes (all in `gate_main`, all the same shape) L17040 - **§3-B.** — Typedef handling — the only strategy that survives contact L17058 - **§3-C.** — The limit that remains (recorded, not solved) L17080 - **§3-C2.** — RECONCILE BEFORE THE FIRST GATE — a parked draft gets HARDER to bank, not easier L17087 - **§3-D.** — The measured cost shape, and what to build next L17110 - **§176i** — WHAT A STATIC PRE-GATE CHECK CAN AND CANNOT PROVE (P31 S52, wave Q) L17128 - **§176j** — STOPPING A WAVE MID-FLIGHT COSTS THE IN-FLIGHT TAIL (and how much is recoverable) L17160 - **§176j-2** — THE REPAIR PASS, MEASURED (do this instead of resuming) L17186 - **§176k** — TWO SELECTOR BUGS THAT SILENTLY SHRINK A WAVE L17206 - **§177** — 🔴 THE EPILOGUE RETURN-DELAY SLOT IS DECIDED BY YOUR SAVED-REGISTER SET, NOT BY SCHEDULING L17223 - **§178** — SIX LEVERS MINED FROM THE WAVE-P JOURNALS (P31 S52), each byte-proven and source-cited L17280 - **§3-A.** — THE `$0`-ADD OPAQUE COPY defeats `make_regs_eqv` (func_80033398, 93 ins) L17292 - **§3-B.** — A `return ` IS A PRIORITY-1 HARD-REG SET THE SCHEDULER PLACES FIRST (func_8001BE30, 92 ins) L17308 - **§3-C.** — SINGLE-SET TEMPS GET THE BIRTHING BOOST (func_8001D3FC, 196 ins) L17321 - **§3-D.** — A NARROW TYPE BLOCKS COPY ELISION (func_8001D3FC — new idiom) L17329 - **§3-E.** — THE ZERO-OFFSET ALIAS HOLE (func_80037028, 71 ins) L17336 - **§3-F.** — `MEM_IN_STRUCT_P` ASYMMETRY IN `true_dependence` (func_80037144, 124 ins) L17345 - **§3-G.** — TWO MODELLING TRAPS THAT COST THESE AGENTS SWEEPS OF HUNDREDS OF COMPILES L17351 - **§179** — IDIOMS MINED FROM THE WAVE P/Q JOURNALS (P31 S52, harvest pass) L17367 - **§179-A** — 🔴 A LOOP-WALKED POINTER **PARAMETER** HANDS ITS ARGUMENT REGISTER TO THE GIV (9 byte-proofs) L17377 - **§179-B** — 🔴 THE HAND-WRITTEN-ASM TRANSCRIPTION CHECKLIST (maspsx + masked_diff; 10 byte-proofs) L17426 - **§179-C** — 🔴 A FUNCTION WITH NO EPILOGUE (falls into a sibling's shared tail) MUST BE FILE-SCOPE `__asm__` L17476 - **§179-D** — `gte_stflg` MUST CLOBBER `"$12"` OR THE WHOLE TEMP FILE ROTATES BY ONE L17527 - **§179-E** — A `>2*MAX_MOVE_BYTES` BLOCK COPY IS A **STRUCT ASSIGNMENT**, NOT A HAND LOOP L17547 - **§179-F** — PINNING A LOOP-WALKED POINTER IS A TOTAL OFF-SWITCH FOR STRENGTH REDUCTION L17573 - **§179-G** — 🟡 A PIN CAN **CREATE** A COMBINE `LOG_LINK` AND DELETE AN `andi` (sixth RC-5 channel, n=1) L17596 - **§179-H** — A MID-BODY `.global LABEL` PAIR SLICES A BYTE-COMPARABLE FRAGMENT OUT OF A LARGER ROUTINE L17623 - **Considered** — and NOT banked L17646 - **§176c** — MAIN (SLUS_007.26) CANNOT BE GATED INCREMENTALLY L17663 - **§176** — SEVEN LEVERS FROM THE P31 OVERNIGHT WAVES (2026-08-15): statement order, false regalloc, and the pin that fights back L17674 - **§176-A** — "SCHEDULE / DELAY-SLOT / LENGTH-DRIFT ±1" ⇒ check STATEMENT ORDER around the call first L17680 - **§176-B** — "REGALLOC-PERM, 1-4 instructions off" ⇒ it is usually NOT register allocation L17704 - **§176-C** — 🔴 WALL REFUTATION: a hard-register pin CANNOT schedule around a call, because of a genuine gcc-2.7.2 bug L17750 - **§176-D** — CSE-class levers used in reverse (two sharpenings of §153 and cse_expr §2) L17776 - **§176-E** — Two cheap source spellings, both cc1-probed L17802 - **§176-F** — Misdiagnosis triage: four residual verdicts that were lying L17824 - **What** — is NOT banked here L17841 - **§180** — THE LEFTOVER-DRAFT HARVEST: RE-VERIFY WHAT YOU ALREADY HAVE BEFORE DRAFTING ANYTHING NEW L17854 - **§180b** — WHAT THE PRE-GATE LADDER ACTUALLY FINDS IN A COLD PILE (the shape of integration debt) L17883 - **§180c** — WHEN A BINARY'S MASS BAND IS SPENT, THE FLEET-WIDE DRAW IS STRICTLY BETTER L17902 - **§181** — WHAT A WAVE'S GATE ACTUALLY REJECTS (P31 S53, measured on wave R's 45-draft main pile) L17920 - **Only** — ONE of 27 blocked drafts was wrong. The other 26 were correct and unbankable. L17921 - **§182** — §177's HONEST NEGATIVE: the epilogue lever cracked 4 of 16, and the `800c3` cluster held L17976 - **§180d** — THE `pgrep` BRACKET TRICK PROTECTS THE PATTERN, NOT THE COMMAND LINE L17990 - **§183** — THE DECLARATION-RECONCILIATION PLAYBOOK (P31 S53, measured on 20 byte-verified drafts) L18002 - **§3-18** — of 20 reconciled while keeping the match. The two that did not are mechanism, not effort. L18003 - **§184** — COMMENT-BLINDNESS IS A DEFECT CLASS, NOT A BUG (P31 S53: three tools, one root cause, one session) L18073 - **§185** — EDIT THE SIDE THAT IS CHEAP TO VERIFY, AND CHECK A TU RETYPE AT ITS USE SITES L18101 - **§186** — CROSS-JUMPING RUNS **AFTER** SCHEDULING, SO NO C-LEVEL BARRIER CAN STEER IT L18133 - **§186b** — A NO-SAVE 16-BYTE FRAME IN A LEAF FUNCTION MEANS `s16` LOCALS, NOT A HIDDEN CALL L18154 - **§186c** — WHERE A VALUE IS LOADED DECIDES WHICH ALLOCATOR OWNS IT, AND THEREFORE ITS REGISTER L18162 - **§187** — 🔴 "SAME SOURCE" IS NOT "SAME OBJECT": THE SDK BUILD AND THE GAME BUILD DISAGREE ON GTE NOPS L18179 - **§188** — 🔴 THE `jr $ra` + `addiu $sp` TAIL IS AN **ASSEMBLER** ARTIFACT, NOT A FRAME SHAPE L18217 - **§189** — FIVE COMPILER LAWS MINED FROM THE WAVE R/S JOURNALS (P31 S53), each source-cited and re-derived by a second agent L18267 - **§190** — THREE PRESCRIPTIONS FROM THE SAME HARVEST (weaker evidence than §189, honestly labelled) L18342 - **§191** — WHAT THIS HARVEST DID **NOT** BANK (4 rejected, 4 narrowed) — recorded so it is not re-derived L18379 - **§192** — THE PRE-GATE LADDER WAS MAIN-ONLY, AND NOBODY COULD SEE IT (P31 S54) L18401 - **Three** — defects in one call path; the overlay slates that carry most of the wave work were being waved through L18402 - **§193** — THE WAVE-T HARVEST (P31 S54): 71 index_gap reports -> 9 laws, 5 rejected, 61 already-covered L18466 - **§193-A** — The wave card ships only OPEN-set pointers and discards the atlas's BANKED one — `exemplar`/`sibs` are stubs 100% by construction (tools/atlas.py:96/657), while `seed.ref` (matched pool, atlas.py:505-536) is dropped at build_wave_atlas.py:143 L18483 - **§193-B** — A NARROW CAST OF A WIDE PARAMETER COSTS ONE EXTRA INSTRUCTION WHEN ITS STATEMENT SITS AFTER AN INTERVENING `jal` — AND THE DECIDER IS `combine.c:929`'s CROSS-CALL GUARD, NOT REGISTER ALLOCATION L18550 - **§193-C** — gcc-2.7.2 cross_jump merges the SCHEDULED common SUFFIX only — there is no prefix/head merge, so §8/§48-A1's "duplicate into both arms and cross_jump refunds it" is a TAIL-only lever L18588 - **§193-D** — A COMPILER-GENERATED ARGUMENT COPY IS A `optimize_reg_copy_1` TRIGGER: when the pointer's LAST use in a block precedes a call that takes the pointer *as a register*, sched1 hoists the implicit `move $aN,$sN` to the block top and local-alloc re-bases the WHOLE block's memory operands onto `$aN`. The only C dial is a label (the §165-24 goto-join) between the block and the call. L18622 - **§193-E** — A varying-address (pointer) load is re-emitted once per CSE-LIVE INTERVAL, and naming it in a C local is the only C-level lever over that count — no store SPELLING has any reach L18693 - **§193-F** — §148-A2 — The `threshold -= 3` STAIRCASE: `move_movables` admits a COUNT of invariants, not a boolean — two identical merged constants split hoisted/not-hoisted by LIST ORDER, and `insn_count` picks the rank cutoff L18723 - **§193-G** — §164-54's "scope to ≥4 arms" bound is byte-wrong — the dispatch-topology oracle goes live at THREE case nodes (`balance_case_nodes` splits at `i > 2`), but only for a signed-after-promotion index L18787 - **§193-H** — A pointer-derived base load `*(s32*)(p+K)` is uncacheable across ANY memory write or call (cse's third kill disjunct) — so the target emits one `lw` per store-separated RUN of spellings, and a run of stores sharing one `lw` is a C local you must declare L18848 - **§193-I** — A DECLARED AGGREGATE LOCAL HAS AN 8-BYTE FRAME STRIDE — CEIL(size,8), NOT size. N ARRAYS THEREFORE COST 8·k MORE THAN ONE HAND-LAID STRUCT (k = how many of them have size mod 8 ≠ 0), AND THE TELL IS IDENTICAL INSTRUCTION COUNT WITH EVERY $sp DISPLACEMENT SHIFTED BY THE SAME CONSTANT. L18888 - **§193-REJECTED** — what this harvest did NOT bank (recorded so it is not re-derived) L18947 - **§194** — THE WAVE-U HARVEST (P31 S54): 64 index_gap reports -> 14 laws, 5 rejected, 44 already-covered L18974 - **§194-A** — A zero-byte scheduling fence goes AFTER the defining statement to make that computation emit FIRST in its block — and the barrier predicate is `volatile`-or-colon-less, not the `"memory"` clobber (COMPLEMENTS §165-40; does not refute it) L18991 - **§194-B** — A `addu $rA,$rB,$zero` copy feeding ≥2 `sh` stores is a SECOND, 16-BIT-DECLARED local — the width, not the clamp or the join liveness, is what keeps the copy (and func_80183094's pin + `"memory"` clobber are both provably inert) L19057 - **§194-C** — A CALLER-SAVED loop counter proves its live range crosses ZERO calls — so it cannot share a pseudo with any value LIVE ACROSS a call (but it may freely share one with values that merely sit between calls) L19095 - **§194-D** — Declared width of a computed-value local is a sched1 dial (count-neutral) — a replication + attribution correction of §165-17, NOT a new argument-register law L19158 - **§194-E** — The wave card's `exemplar` is the TARGET ITSELF on 42/73 wave-U and 36/71 wave-T cards — a construction consequence of `atlas.py:657` (exemplar = max-nins OPEN member) meeting `build_wave_atlas.py:166` (one card per gid); and the shipped §193-A `seed_ref` is same-binary on 0/51, so no card field can ever name a destination-TU sibling L19199 - **§194-F** — `if ((*p = v = f()) == 0)` is an expand-time pseudo SPLITTER (store_expr's `want_value && MEM` path), not a fold — it partitions one value between local_alloc and global_alloc. BOUNDS §21's L1872 bullet, whose stated direction is byte-wrong on 3 of 4 instances, and CLOSES the control §167-37 asked for. L19236 - **§194-G** — Reading the integer half of a 16.16 stack aggregate: REGISTER-LIVENESS, not the C spelling, decides `sra` vs `lhu` — and the break is count-neutral L19309 - **§194-H** — §164-29's WAR fence runs again at SCHED2 ON HARD REGISTERS: an in-place `v &= K` before a branch fences the store that reads v, and when TWO independent stores compete for the one delay slot the fence picks the winner at ZERO length drift (a WIDTH/sh!=sw swap, not a nop). Corrects §167-42's reconstruction (pseudo arm → hard-reg arm) and supplies its first re-runnable A/B. L19352 - **§194-I** — §16N+2's magic-per-odd-part ladder has exactly one broken row — read the divisor arithmetically instead: d = round(2^(32 + post_shift) / magic_read_as_unsigned) L19390 - **§194-J** — Back-to-back identical stores: flow.c's `last_mem_set` deletes the first, and only `volatile` saves it L19433 - **§194-K** — Blind sched1's alias oracle with a second SET of a pointer pseudo — the first zero-byte, non-volatile, dependence-CREATING lever (corrects §167-05's "volatile is the only door"; fourth consumer of reg_n_sets) L19485 - **§194-L** — §88b and §189-E are BOTH half-wrong, but not the way the candidate says: the compare-constant shape is a 2-D lookup (cmp_info ROW × constant-in-window), and naming matters on OPPOSITE sides of the window for the GE/LT rows vs the GT/LE rows L19563 - **§194-M** — A STORE in a CONDITIONAL branch's delay slot proves its C statement DOMINATES the branch — reorg can never pull a store out of either thread (gcc-2.7.2, -mips1) L19611 - **§194-N** — §193-D's C dial is misstated: the lever is a SURVIVING CODE_LABEL (a label with a real incoming edge), not "a label between the block and the call" — a bare label, or a `goto L; L:` pair whose target is the next active insn, is deleted by jump1 (jump.c:663-669 → delete_insn → jump.c:3458-3461, and jump.c:243 for the bare case) long before sched1/local-alloc, and costs exactly zero bytes L19669 - **§194-REJECTED** — what this harvest did NOT bank (recorded so it is not re-derived) L19729 - **§195** — THE WAVE-V HARVEST (P31 S54): 67 index_gap reports -> 14 laws, 9 rejected, 76 already-covered L19750 - **§195-A** — §167-08's "an $aN READ before the jal is scratch" has a byte-proven FALSE-NEGATIVE class: an argument that DIES at the call is allocated straight into $aN, so its only def is a plain load far above the jal and every intervening use reads $aN — there is no positive tell in either direction, only the two-arity A/B L19764 - **§195-B** — A CALL_INSN does not start a basic block in gcc-2.7.2 — so a call-crossing temp can be a LOCAL-alloc quantity (the missing precondition under §48-A2 / §52 / regalloc.md K8) L19835 - **§195-C** — A call-argument `%hi/%lo` pair sitting at the block head, far above its `jal`, is a load-delay-gap filler chosen by SOURCE STATEMENT ORDER — swap the two independent statements nearest the call; a single-use `void *p = &SYM;` call-arg temp is OUTPUT-inert against it (but NOT expand-stream-inert) L19877 - **§195-D** — §195 — `masked_diff.mask_for` returns 0 for EVERY `j`/`jal` word, so an internal `j` destination is invisible to match_one, the permuter scorer AND every similarity tier: a control-flow semantic error (which calls execute) surfaces as a 1-instruction residual mislabelled `DELAY-SLOT / profile=schedule`, or as an outright false MATCH L19925 - **§195-E** — A 0/1 materialised at a JOIN immediately before the controlling `beqz`/`bnez` proves the source NAMED the condition — a truth expression in an `if`'s controlling position reaches `do_jump`, which has no value path L19993 - **§195-F** — fold-const.c:4825 canonicalises a `?:` whose THEN arm is zero (or constant against a non-constant ELSE) by inverting the condition and swapping the arms — so a ternary's written arm order is byte-inert there, and `c ? 0 : X` is unspellable: it always compiles as `!c ? X : 0` L20051 - **§195-G** — §NEW — TWO ARMS CALLING THE SAME CALLEE MERGE INTO ONE `jal` UNLESS EACH ARM'S OWN CODE CONSUMES THE RESULT: the C dial that keeps two call sites apart is WHERE the consumer test lives, and the branch SENSE you spell it with is byte-inert (jump.c:1737 canonicalises it) L20103 - **§195-H** — §165-27g — ON A FIXED-SYMBOL GLOBAL, `extern T D[];` + `D[0]` IS THE CSE RELOAD DIAL, AT ZERO ADDRESSING COST, AND THE ELEMENT COUNT IS INERT (§165-27's `T v[2]` CAVEAT IS A LOCAL-FRAME FACT AND DOES NOT TRANSFER) L20151 - **§195-I** — §145(b) AMENDED — the pointer-bump `addiu` is saved by cse, not combine: ANY second SET of a pseudo in the address's equivalence chain (in-place `p += K`, §145(b)'s `p = r;` copy, or an asm re-tie) kills the fold; the pass is cse and the gate is `invalidate`'s `reg_tick++` L20198 - **§195-J** — GTE / PsyQ op CALL-vs-INLINE is a PER-SITE SOURCE FACT, not a TU style — both forms coexist in one TU (measured in 2 TUs), and the tell is the target's own opcodes (`lwc2`/`sqr`/`swc2` vs `jal`), not the sibling. Costs -8 ins on func_8018505C. Corollary: the game's inline `sqr` macro emits TWO hazard nops, the SDK's `Square0` body emits ONE — so the inline form is provably not `Square0` inlined (a second instance of §187's SDK-vs-game GTE nop divergence). L20263 - **§195-K** — At -O2 the §18 array-of-struct lever is a FRAME lever, not a length lever — but only when the N reads carry DISTINCT index expressions; with a SHARED index §18's +2-instruction residual is still alive at -O2 (the submitted "memory-loaded narrow index" precondition and unconditional length-neutrality are both falsified) L20307 - **§195-L** — The cse store-re-seed does not cross a JOIN LABEL: per-arm stores + a join read keep the reload that one join store deletes (bounds §193-E BOUND 1/BOUND 3 with §48-B's EBB boundary) L20359 - **§195-M** — Frame `vars` is a SEQUENTIAL bump-allocation, not a flat sum: §193-I's CEIL(aggregate,8) term and §165-03/§167-06's 8×orphan term are the SAME frame_offset walk at two different compiler stages, and each stage re-CEILs frame_offset to 8 before it allocates L20411 - **§195-N** — In a call-bearing chain of N≥2 `if (f(...)) return 1;` tests closed by `return 0;`, the LAST test must stay in STATEMENT form — the value form (`return f() != 0;` / `? 1 : 0` / `!!f()`) costs +1 `j` and empties the other N−1 delay slots. The cause is REORG block placement, not jump.c's `delete_jump`. L20460 - **§195-REJECTED** — what this harvest did NOT bank (recorded so it is not re-derived) L20507 - **§196** — PUT ON THE CARD WHAT THE TREE ALREADY KNOWS: the fleet's declaration consensus (P31 S54) L20553 - **§197** — THE WAVE-W HARVEST (P31 S54): 68 index_gap reports -> 4 laws, 3 rejected, 41 already-covered L20608 - **§197-A** — A NARROW SIGNED MEMORY READ FEEDING A CONSTANT `>>` LOSES ITS `lh`, AND THE CURE IS AN ASM RE-TIE (attribution CONTESTED: cse vs combine) L20622 - **§197-B** — A REPEATED COMPARE OF ONE VALUE AGAINST ONE CONSTANT IS DELETED BY cse's `qty_comparison_code` CHANNEL (the non-EQ complement of §165-03) — and a front-end-opaque mask on EITHER compare is a pure-C dial that keeps the target's second branch L20660 - **§197-C** — Fix A1 (operand order) cannot move a commutative destination whose .greg conflict set already contains BOTH operand hard registers — split the accumulate so the destination IS the load's pseudo L20688 - **§197-REJECTED** — §197-REJECTED L20733 - **§199** — THE WAVE-X HARVEST (P31 S54/S55): 63 index_gap reports -> 7 laws, 2 rejected, 56 already-covered L20748 - **§199-A** — §189-A's asm→source inference is byte-FALSE: an interloper between a split constant's `lui`/`ori` is a SCHEDULE fact, not a source fact — and the separator is the BIRTHING BOOST, not a "priority floor" (§189-A's split-timing half survives; its "no statement order / no pin" absolute and the candidate's own forward-scheduler narrative both fall) L20759 - **§199-B** — A permutation sweep that holds ANY statement fixed is not a sweep: the statement an agent pins as "obviously load-bearing" is the one carrying the signal, and the partial sweep returns a FLAT residual that reads as proof of order-invariance L20808 - **§199-C** — A NEGATIVE CONSTANT MULTIPLY ALWAYS TAKES expmed's negate_variant — but whether you ever SEE the neg is decided by COMBINE, and for an EVEN |K| it never disappears L20853 - **§199-D** — A narrow UNSIGNED value compared in an ordered `if` emits `sltiu`/`sltu`; the only dial is the WIDTH of a real object, and a widening `(s32)` cast is inert — AMENDS §35 (whose stated "only CSE-reuse canonicalizes" mechanism is byte-wrong) and does NOT apply inside a `switch` L20901 - **§199-E** — §189-A BOUNDED AND CORRECTED — the discriminator is INSN_PRIORITY, not "is the interloper a constant": an insn between a `lui`/`ori` pair proves NOTHING about the source spelling unless it TIES the `ori` on priority, and on the pinned `-mcpu=3000` triple a dependent load never does L20961 - **§199-F** — §164-36b — THE TARGET-HEAD FENCE IS A DELAY-SLOT THREAD SELECTOR, AND IT ONLY FIRES WHEN `mostly_true_jump > 0` (amendment to §164-36; its "−1 instruction" tell is falsified) L21020 - **§199-G** — At TWO case nodes the switch-vs-if oracle is not blind — but the tell is ALL tests positive + a trailing `j default`, NOT the first test's polarity L21074 - **§199-REJECTED** — §199-REJECTED L21129 - **§200** — THE ALIAS IS THE UNIVERSAL DECLARATION ESCAPE: stop negotiating with the TU's spelling (P31 S55) L21140 - **§201** — THE WAVE-Y HARVEST (P31 S55): 67 gap reports -> 5 laws, 8 rejected, 53 already-covered L21189 - **§201-A** — §150-B applies to `decl_prior`'s DEF row: for an overlay-window symbol the banked "definition" is usually another overlay's function, and the card ranks it ABOVE the destination TU L21199 - **§201-B** — In a narrowed PLUS/MINUS/AND/IOR/XOR expression the destination pointee is INERT — the sign of the materialized constant is decided by an OR over the UNWIDENED operands (convert.c trunc1), which bounds §1841 to direct constant stores L21231 - **§201-C** — §X — A CALL'S OWN DELAY SLOT AND THE UPSTREAM CONDITIONAL BRANCH'S SLOT COMPETE FOR ONE INSN (the call's argument copy), AND ONE STATEMENT'S POSITION RELATIVE TO THE CALL DECIDES BOTH — the residual is visible at the BRANCH, not at the call L21311 - **§201-D** — THE SIGNEDNESS OF A div/mod MAGIC IS DECIDED BY THE STATIC TYPE OF THE DIVIDEND TREE AFTER `get_narrower` STRIPS WIDENING CONVERSIONS — NEVER BY A PROVABLE RANGE. AN `& 0xFF` IS NOT A CONVERSION, SO IT NEVER FLIPS THE MAGIC; A DECLARED-UNSIGNED LOCAL *OR* A NARROWING CAST WRITTEN AT THE DIVIDE BOTH DO. L21362 - **§201-E** — §194-J-2 — The `last_mem_set` deletion window is measured in SOURCE/expand order, not in the printed stream; a foreign store moved between the pair in C source is a real lever, and `volatile` is not always the better one L21409 - **§201-REJECTED** — eight, the session's highest L21465 - **§202** — THE ALIAS CARRIES A DEFINITION, NOT JUST A DECLARATION: the DEF-SIDE-RETURN wall (P31 S56) L21490 - **§203** — A DEDUPED TYPEDEF MUST PRECEDE EVERY SPLICE POINT, NOT JUST ITS OWN (P31 S56) L21527 - **§204** — THE WAVE-Z HARVEST (P31 S56): 82 gap reports -> 5 laws, 16 rejected, 30 already-covered L21588 - **§204-A** — A COMPARE THAT APPEARS BOTH IN A BRANCH'S DELAY SLOT AND AGAIN ON THE FALL-THROUGH IS A JOIN WITH TWO INCOMING EDGES: THE TWO GUARDS ARE SEQUENTIAL `if`s, NEVER `if/else if` L21607 - **§204-B** — A LOOP COUNT THAT ARRIVES ON THE STACK IS DECREMENTED IN PLACE: a fresh counter local can cost a real `move` AND permute the whole callee-saved file L21682 - **§204-C** — WHEN A LOCAL BUFFER'S ADDRESS IS PASSED TO A CALL, ITS SIZE IS A FACT ABOUT THE CALLEE'S BODY, NOT ABOUT THE CALL SITE: grep the callee's proven definition and count the stores through the pointer parameter before you declare the local L21746 - **§204-D** — A LOOP-INVARIANT LOAD IS ADMITTED AS A MOVABLE ONLY IF ITS ADDRESS CANNOT TRAP: `local.field` PASSES, THE SAME READ THROUGH A POINTER LOCAL IS REFUSED L21804 - **§204-E** — `decl_prior`'s `%hi/%lo` ARM HAS NEVER FIRED: the card's promised GLOBAL-TYPE row is 0 of 1,210 L21879 - **§204-CONFIRMED** — 30 reports that the index already answered L21931 - **§204-REJECTED** — sixteen, twice the previous record L22025 - **§205** — THE CHAINED ASSIGNMENT IS ITS OWN SCHEDULING DIAL: `*b = *a = v;` moves an argument copy that no local, no pin and no statement reorder will move (P31 S56) L22098 - **§206** — THE JTBL-CARVE DRAFTING IDIOM: the bounds check is the entry count, and an EMPTY case owns a slot (P31 S56) L22153 - **§207** — THE WAVE ab–ag HARVEST (P31 S58): 278 byte-banked notes → 25 laws, 103 self-reported no-gap L22222 - **§208** — TWO NAMED LOCALS FOR ONE RELOADED EXPRESSION BUY TWO ALLOCNOS — the naming granularity owns the REGISTER SPLIT, not just the load count (P31 S58) L22243 - **§209** — THE NARROW LOCAL IS A DIAL IN TWO OPPOSITE DIRECTIONS, AND §194-B's "≥2 `sh` STORES" BOUND IS BYTE-WRONG (P31 S58) L22292 - **§210** — THE SINGLE-BIT MASK IN A BOOLEAN TAIL: `andi K ; sltu $zero,v` vs `srl n ; andi 1` is a STATEMENT-SHAPE dial, not an operator choice (P31 S58) L22369 - **§211** — HOIST THE LOOP INIT ABOVE THE DOMINATING GUARD: it fills the guard's delay slot AND flips the counter/pointer register pair (P31 S58) L22415 - **§212** — THE WALKING CURSOR IS COUNTABLE: `*wp++` emits one `addiu` PER STORE, `wp[0..2]` emits one (P31 S58) L22474 - **§213** — INDEPENDENT SAME-BASE STORES: THE EMISSION ORDER IS A PERMUTATION OF SOURCE ORDER, AND THE PERMUTATION IS NOT ALWAYS THE IDENTITY (P31 S58) L22519 - **§214** — THE BANKED TWIN MAY BE A MACRO, A DELETED `.s`, OR A SEMANTIC INVERSE — six ways a ≥0.9 similarity lies (P31 S58) L22555 - **§215** — PIN ECONOMY: the twin's pins are NOT part of the shape, and §17's "pin every call-crossing value" is over-broad (P31 S58) L22601 - **§216** — DISTINCT ADJACENT SCALARS vs ONE ARRAY: one `lui` per access is the tell, and the array decl is UNUSABLE (P31 S58) L22657 - **§217** — DECODING A CALL'S STACK ARGUMENT SLOTS: `sw` at `0x10`/`0x14`/`0x18` are params 5/6/7 **(single observation — not yet cross-confirmed)** (P31 S58) L22697 - **§218** — A NARROW TYPE AT THE ABI BOUNDARY COSTS AN IN-PLACE `sll/sra` PAIR — on the RETURN as well as on the PARAMETER (P31 S58) L22723 - **§219** — COMPOUND `+=`, FULL ASSIGNMENT, AND AN EXPLICIT TEMP ARE THREE DIFFERENT SCHEDULES OF ONE READ-MODIFY-WRITE (P31 S58) L22752 - **§220** — THE PARAMETER ITSELF IS A REGALLOC DIAL: use it directly, prefer `s32` to `void*`, and place the save-copy AFTER the first call (P31 S58) L22779 - **§221** — A CONSTANT SHARED BY TWO STORES DIES AT THE CALL WHOSE DELAY SLOT REFILLS ITS REGISTER **(single observation — not yet cross-confirmed)** (P31 S58) L22819 - **§222** — SWITCH vs IF-CHAIN, PART 3: source arm order IS emission order, a leading EMPTY case buys the median split, and a 2-way dispatch with a shared post-block is a `switch` (P31 S58) L22835 - **§223** — READING A `jal` DELAY SLOT: the value in it was produced BEFORE the call, so it is NEVER that call's return (P31 S58) L22877 - **§224** — CROSS-JUMP: WRITE THE DUPLICATE, AND READ A SHARED DELAY SLOT AS THE MERGE SIGNATURE (P31 S58) L22939 - **§225** — THREE CONTROL-FLOW SHAPES NO STRUCTURED SPELLING REACHES (P31 S58) L22975 - **§226** — FRAME PADS: FOUR WAYS §162i1/§2429's DEAD-LOCAL LEVER MISFIRES (P31 S58) L23018 - **§227** — TYPE THE SOURCE BY THE **LOAD** WIDTH, NOT BY THE STORE WIDTH (P31 S58) L23059 - **§228** — READING THE DIVIDE, PART N: the off-by-one compare is `% K == 1`, and three more discriminators (P31 S58) L23079 - **§229** — THE ADDRESS IS A VALUE: NAMING IT MOVES THE `lui`/`addiu` PAIR — AND §L14410 SAYS THE OPPOSITE FOR A REASON (P31 S58) L23116 - **§230** — THE ANCHOR PROBE: with `%hi`/`%lo` masked, the surviving `addiu` deltas tell you which assignment was written first **(single observation — not yet cross-confirmed)** (P31 S58) L23165 - **§231** — TRANSCRIPTION AND SEMANTIC-READ HYGIENE: six ways the listing misleads (P31 S58) L23180 - **§232** — WHEN THE `jr` DELAY SLOT'S STORE STORES THE RETURN VALUE, TIE THEM WITH ONE PSEUDO **(single observation — not yet cross-confirmed)** (P31 S58) L23221 - **§30** — addendum (P31 S58) — the `/s` grant closes a SCHEDULING residual and a REGISTER residual with one edit L23257 - **§194-B** — addendum (P31 S58) — BOUND 2 is byte-wrong; see §209 Direction A L23277 - **§176-B** — addendum (P31 S58) — the misdiagnosis direction L23283 - **§165-40** — addendum (P31 S58) — the barrier goes at the COPY SITE, not inside the region it protects L23289 - **§164-63** — addendum (P31 S58) — the interposed asm works when the SECOND value is an ordinary assignment L23298 - **§193-A** — / §194-E addendum (P31 S58) — where the twin's body actually lives L23307 - **§233** — THE WAVE aa–bg HARVEST (P31 S58b): 1,101 byte-banked notes → 24 new laws, 21 addenda, ~700 already-covered L23313 - **§234** — CONSTANT MATERIALISATION: THE STORE LVALUE'S SIGNEDNESS PICKS `addiu` vs `li`/`ori` (P31 S58b) L23357 - **§235** — THE PHANTOM SYMBOL: A MASKED `MATCH` CAN CARRY A RELOCATION THAT DOES NOT EXIST (P31 S58b) L23398 - **§236** — THE DECLARATION LAYER IS THE DOMINANT BANK-BLOCKER: NINE WAYS A BYTE-PERFECT BODY FAILS THE GATE (P31 S58b) L23427 - **§237** — THE CAST-AT-CALL-SITE DECISION TABLE: WHAT §17a-1 FIXES, WHAT IT CANNOT, AND THE FOUR ESCAPES (P31 S58b) L23506 - **§238** — SAME NAME, DIFFERENT FUNCTION: THE OVERLAY-HOMONYM TRAP (P31 S58b) L23561 - **§239** — TWO-STATEMENT INTEGER-SPACE MATERIALISATION REORDERS `la` vs `sll`; AND THE PLUS-TREE OPERAND ORDER (P31 S58b) L23601 - **§240** — `A + K + B`: WRITE THE CONSTANT **BETWEEN** THE TWO RUNTIME TERMS (P31 S58b) L23635 - **§241** — THE FOLDED SIGN-EXTEND-AND-SCALE: `sll 16 ; sra (16 − log2 scale)` (P31 S58b) L23664 - **§242** — `*k` vs `<>n`: EXPRESSION SPELLING OWNS THE LOAD WIDTH AND THE ROUNDING CHAIN (P31 S58b) L23693 - **§243** — SPELL THE CSE BARRIER AS A REASSIGNED POINTER; AND THE `nop`-AFTER-EVERY-`lh` SIGNATURE (P31 S58b) L23721 - **§244** — `volatile` IS A COUNTING INSTRUMENT, A STORE-ORDER PIN, AND MUST SOMETIMES BE ASYMMETRIC (P31 S58b) L23751 - **§245** — THE CALL'S ARGUMENT LIST IS A SCHEDULING SLOT (P31 S58b) L23786 - **§246** — THREE-LIVE-VALUE SCAN LOOPS WANT ADDRESS-FROM-INDEX; AND TWO SYMBOLS CAN SHARE ONE giv (P31 S58b) L23833 - **§247** — TWO BRANCHES TO **ONE** LABEL MEANS THE SOURCE CONDITION IS NEGATED (P31 S58b) L23873 - **§248** — SPLIT THE LOAD FROM THE ARITHMETIC: A FUSED `g + K` DENIES THE CALLEE-SAVED REGISTER ITS DIRECT HOME (P31 S58b) L23907 - **§249** — THE SELF-ASSIGN, THE DEAD RE-ASSIGN, AND THE `+ zr` COPY: THREE WAYS TO MAKE A DELETED INSTRUCTION REAL (P31 S58b) L23931 - **§250** — `%hi/%lo` vs `lw`: THE EXTERN'S ARRAY-vs-SCALAR SHAPE DECIDES ADDRESS MATERIALISATION (P31 S58b) L23973 - **§251** — IMMEDIATE-SPELLING TRIGGERS: `+= 0xFF`, FULL-WIDTH `~K`, AND THE TWO-OR SPLIT (P31 S58b) L24010 - **§252** — THE GUARDED PRE-DECREMENT: `(x != 0) && (--x == 0)` (P31 S58b) L24032 - **§253** — POSTFIX `++` vs `+= 1` PICKS A DIFFERENT SCRATCH REGISTER **(single observation — not yet cross-confirmed)** (P31 S58b) L24053 - **§254** — THE DEAD PARAMETER IS A REGISTER-PLACEMENT TOOL **(single observation — not yet cross-confirmed)** (P31 S58b) L24067 - **§255** — THE EMPTY CASE, PART 2: FOUR TREE SHAPES IT BUYS (P31 S58b) L24079 - **§256** — GOTOS IN THE TARGET'S BLOCK ORDER REPRODUCE SWITCH PLACEMENT WITHOUT SWITCH'S SIDE EFFECTS (P31 S58b) L24114 - **§257** — THE DEAD-END LEDGER (P31 S58b): ELEVEN LEVERS THAT MEASURED NULL OR BACKFIRED L24151 - **§258** — ADDENDA TO EXISTING SECTIONS (P31 S58b) L24194 - **§30** — addendum (P31 S58b) — THE ANONYMOUS STRUCT MEMBER REF GRANTS `/s`, AND THAT IS A TWO-FOR-ONE L24199 - **§194-B** — / §209 addendum (P31 S58b) — TWO MORE INSTANCES, AND THE BOUND IS NOW REFUTED FOUR WAYS L24220 - **§202** — addendum (P31 S58b) — THE DEF-SIDE ALIAS ALSO CLEARS A RETURN+PARAM DOUBLE CONFLICT L24243 - **§205** — addendum (P31 S58b) — CHAINED ASSIGNMENT: N≥3 IS INNERMOST-FIRST, AND THE TEXT MIRRORS EMISSION L24254 - **§208** — addendum (P31 S58b) — IT SCALES TO SIX SITES, AND IT HAS AN EXACT INVERSE L24271 - **§210** — addendum (P31 S58b) — THREE CONFIRMED SPELLINGS OF THE BOOLEAN TAIL L24300 - **§211** — addendum (P31 S58b) — INIT PLACEMENT: FIVE MORE DIALS BEYOND THE GUARD HOIST L24316 - **§213** — addendum (P31 S58b) — THREE MORE PERMUTATION LAWS FOR INDEPENDENT SAME-BASE STORES L24359 - **§214** — addendum (P31 S58b) — FOUR MORE WAYS A HIGH-SIMILARITY TWIN LIES L24388 - **§215** — addendum (P31 S58b) — PIN ECONOMY, PART 2: NINE REFINEMENTS L24424 - **§217** — CROSS-CONFIRMED (P31 S58b) — AND THE INCOMING HOME SLOT IS THE MIRROR L24476 - **§220** — addendum (P31 S58b) — THE PARAMETER, NOT A COPY (SEVEN CARDS) L24493 - **§222** — addendum (P31 S58b) — IF-CHAIN vs SWITCH: THREE MORE DISCRIMINATORS L24518 - **§223** — addendum (P31 S58b) — FIVE MORE CONFIRMATIONS, AND THE CONSTANT-IN-`$v0` CASE L24536 - **§224** — addendum (P31 S58b) — CROSS-JUMP MERGES *CALLS*, AND THE DELAY SLOT IS THE DISCRIMINATOR L24560 - **§225** — addendum (P31 S58b) — THE GUARD-CLAUSE FINGERPRINT, AND THREE MORE SHAPES L24590 - **§226** — addendum (P31 S58b) — THE FRAME CATALOGUE: SEVEN MORE LEVERS, AND SLOT ORDER IS DECLARATION ORDER L24617 - **§229** — addendum (P31 S58b) — NAME IT **INSIDE** THE ARM L24662 - **§230** — CROSS-CONFIRMED (P31 S58b) L24673 - **§231** — addendum (P31 S58b) — FOUR MORE WAYS THE LISTING MISLEADS L24682 - **§232** — CROSS-CONFIRMED (P31 S58b) L24713 - **§259** — THE DISCARD LEDGER FOR THE aa–bg HARVEST (P31 S58b): WHAT WAS MINED AND REJECTED, AND WHY L24724 - **§260** — THE §154-A LEADING-ISLAND SPLIT: ONE CONFIG LINE, AND THE ISLAND PEELS FROM THE END (P31 S59, byte-proven) L24763 - **§260-A** — STAGE 2 IS PROVEN, AND THE WHOLE jtbl PIPELINE IS AUTOMATED AT THE GATE (P31 S59, same day) L24813 - **§261** — THE -O0 ORACLE: DERIVE THE OPT LEVEL FROM THE TARGET, AND `$fp` IS NOT THE TELL (P31 S59) L24849 - **§261a** — THE -O0 FRAME-RELOAD GRAMMAR: reload COUNT disambiguates the C spelling (P31 S59, byte-proven) L24875 - **§262** — A LANE'S YIELD IS ONLY A LANE FACT IF IT IS SIZE-MATCHED (P31 S59) L24897 - **§263** — A STOLEN DELAY SLOT WHOSE INSTRUCTION IS AN ARG-REGISTER COPY IS AN ARITY ERROR, NOT A SCHEDULE (P31 S59, byte-proven) L24927 - **§264** — FOUR TELLS-LANE C RECIPES, EACH DRIVEN TO MATCH (P31 S59) L24968 - **§265** — THE VERBATIM-ASM BANK LANE: A FUNCTION NO -O2 C CAN EVER MATCH BANKS AS A RAW `__asm__` BODY (P31 S59b; two banked cards, two in-tree precedents) L25018 - **§266** — THE INERT-RIDER LAW: A LEVER IS ONLY CITABLE WHEN ITS SOLO REMOVAL BREAKS THE MATCH (P31 S59b; measured 4-of-8 on this batch) L25080 - **§267** — ADDENDA HARVESTED FROM WAVES at/bh/bk/bl (P31 S59b) L25120 - **ADD-1** — → §231 addendum (also cross-ref from §195-D) — THE MASKED-`jal` "MISSING CALL" ILLUSION L25128 - **ADD-2** — → §42a addendum — A SHARED CONSTANT *NAMED IN A LOCAL* ACROSS A `jal` IS AN ISO→TU DRIFT HAZARD; WRITE BARE LITERALS L25137 - **ADD-3** — → §236, item 10 — THE UN-DELETED `INCLUDE_ASM` STUB IS A DUPLICATE DEFINITION L25149 - **ADD-4** — → §225-3/-4 addendum — THE MIRROR ROW: VALUE-RETURN IN THE *TAKEN* ARM + TRAILING BARE `return 0` L25159 - **ADD-5** — → §1/I1 addendum — THE INVERTED RANGE TEST: `(u32)(x-lo) >= N` WITH THE ZERO-ARM AS THE TRAILING `else` L25173 - **ADD-6** — → §172b-1 / §264 addendum — SHIFT-AS-TEST: `(x << 16) != 0` TESTS THE LOW HALF WITHOUT TRUNCATING THE PSEUDO L25182 - **ADD-7** — → §256 addendum — THE SINGLE-GUARD GOTO: THEN-BLOCK OUT OF LINE AT THE TAIL L25191 - **ADD-8** — → §245 addendum — THE RE-TIE BARRIER PINS CALL-ARG SETUP TO SOURCE ORDER (construct 6) L25203 - **ADD-9** — → §213-3 / §217 addendum — ADJACENT PRE-CALL FRAME STORES ARE ONE AGGREGATE; THE UNESCAPED SCALAR NEIGHBOR IS DEAD-STORED L25215 - **ADD-10** — → §237 addendum (arity-evidence paragraph) — AN `la` PAIR ABOVE THE PROLOGUE `sw $ra` IS AN OUTGOING-ARGUMENT MATERIALISATION L25225 - **ADD-11** — → Cross-confirmation card block (per §259's standing instruction: confirmation, not news) L25234 - **§268** — A `register __asm__` PIN ON A CALL-CLOBBERED REGISTER IS HONORED EXACTLY WHEN THE PINNED RANGE CROSSES NO CALL (P31 S59c; three A/B'd cards, unifying §257-2's two) L25285 - **§269** — ADDENDA HARVESTED FROM WAVES ax/bm (P31 S59c) L25339 - **ADD-1** — → §257-8 addendum — THE INTERPOSED ASM'S `__volatile__` IS A PER-SHAPE DIAL, AND THE "NO-OUTPUT ASM IS IMPLICITLY VOLATILE" LORE IS BYTE-FALSE IN gcc-2.7.2 L25354 - **ADD-2** — → §236 addendum (item 1 corollary) — THE SILENT-SPLICE DECLARATION LADDER: WHERE THE TU HAS NO SPELLING, UNPROTOTYPED `()` BEATS THE FLEET VOTE L25367 - **ADD-3** — → §238 addendum — TWO BINARIES CAN EACH DEFINE THE SAME `func_` NAME WITH DIFFERENT BYTES, AND NO GENERATED REPORT SHOWS IT L25381 - **ADD-4** — → §167-37 addendum — THE FIFTH PRECONDITION, NOW MEASURED: DOWNSTREAM FIELD RE-READS ⇒ NAME IT **AND** STORE **INSIDE** THE ARM L25394 - **ADD-5** — → §267-ADD-6 / §172b-1 addendum — THE SIGN-TEST FACE: `(s16)v < 0` IS `sll 16` + `bgez` ON THE SHIFTED COPY, RAW STAYS LIVE — AND THE HALFWORD-ABS SHAPE NEEDS NO RITUAL L25411 - **ADD-6** — → §220-addendum — THE FOURTH FACE: WHEN THE NAMED COPY ITSELF BUYS THE EXTRA CALLEE-SAVED, PIN THE COPY TO `$16` L25427 - **ADD-7** — → §229 addendum — THE VALUE FACE: A LOOP-STORE CONSTANT SPELLED AS A LITERAL HAS NO SOURCE POSITION; NAME IT TO PIN THE PROLOGUE INIT ORDER L25443 - **ADD-8** — → §30a addendum — THE THIRD COLUMN: `*p++` IS ALSO SERIALIZED BUT BURNS `addiu`; ONLY CAST-PLUS GIVES SERIALIZATION *AND* DISPLACEMENT FOLDING L25456 - **ADD-9** — → §255 "AND CASE-BODY PLACEMENT" bound / §222-addendum-3 — ON A LARGE SPARSE TREE, BODIES FOLLOW **SOURCE** ORDER (measured by a one-word probe) L25471 - **ADD-10** — → Cross-confirmation card block (per §259's standing instruction: confirmation, not news) L25485 - **§3-1a.** — The §266 sweep — every solo-lever A/B run for this batch L25526 - **§270** — The A-prop 0-bank anatomy: a byte-correct body still needs FOUR layers to agree (P31 S59) L25559 - **§271** — Ordinal IMM pairing: text order is NOT emission order; emit CANDIDATES, let the oracle pick (P31 S59) L25577 - **§272** — The `(void)`-decl + empty-call wall: K&R the DEFINITION, not just the decls (P31 S59) L25599 - **§273** — A standalone compile is the WRONG oracle for a TU-destined draft (P31 S59) L25619 - **§274** — ADDENDA HARVESTED FROM 18 WAVES (P31 S60): 315 candidates, 255 already covered, 21 sharpenings, 3 new laws L25634 - **ADDENDUM** — to §179-C — the `.type NAME, @function` requirement L25640 - **ADDENDUM** — to §134 — a typedef defined BELOW the splice point is stripped anyway L25687 - **ADDENDUM** — to §179-D (GTE macro reference family) — `gte_SetRotMatrix`/`gte_SetTransMatrix` bodies L25717 - **ADDENDUM** — to §82 — struct copies must stay MEMBER-WISE, not block-moved, to match a spill-slot save L25743 - **ADDENDUM** — to §136d-1 (RC-12, the `$0`-add / opaque-copy family) — two symptoms beyond "compare reads the wrong register" L25781 - **ADDENDUM** — to §20 — a global declared as `T *` may itself BE the array base, not a pointer to dereference L25820 - **ADDENDUM** — to §1-I5 L25849 - **ADDENDUM** — to §164-51 L25914 - **ADDENDUM** — to §176-F5 L25930 - **ADDENDUM** — to §225 L25959 - **ADDENDUM** — to §224 — CROSS-JUMP: THE DUPLICATE CAN BE A PLAIN STORE, NOT ONLY A CALL L26004 - **ADDENDUM** — to §164-64 — AN EMPTY CLOBBER ON AN ARGUMENT REGISTER CAN BE THE DELIBERATE FIX, NOT JUST THE ACCIDENTAL BUG L26038 - **ADDENDUM** — to §244 — THE COMPILER BARRIER, NOT `volatile`, BLOCKS A STORE→LOAD HOIST THROUGH A POINTER-OFFSET FIELD L26069 - **ADDENDUM** — to §172b-1 — TWO PLACEMENT DIALS THE PROMOTION LAW DOESN'T NAME: NARROW THE COUNTER'S DECLARED TYPE, AND MOVE THE CAST INTO THE LOOP BODY L26100 - **ADDENDUM** — to §229 — A POINTER'S NUMBER OF USES DECIDES WHETHER ITS ADDRESS FOLDS OR SURVIVES A CALL L26147 - **ADDENDUM** — to §172b-4 — THE PLAIN CAST-DIVISION ALREADY PRODUCES THE PATTERN; DON'T HAND-ROLL THE BIAS, AND KEEP THE OPERAND WIDE L26192 - **ADDENDUM** — to §8 — WHEN `INCLUDE_RODATA` NEEDS A STANDALONE `.s` YOU CAN'T CREATE, CARRY THE FRAGMENT AS A FILE-SCOPE `__asm__` BLOB L26222 - **ADDENDUM** — to §226 — A DEAD LOCAL SCOPED TO A NESTED BLOCK BUYS A MID-FUNCTION `addiu sp` PAIR, NOT A FRAME-SIZE CHANGE L26265 - **ADDENDUM** — to §172a — RE-READING MEMORY (NOT NAMING A TEMP) IS WHAT KEEPS AN INCREMENT'S DELAY-SLOT FILL ALIVE L26304 - **ADDENDUM** — to §225 / §256 — A GOTO TO A SHARED SET-POINT PREVENTS IF-CONVERSION FROM COLLAPSING A LATER BRANCH TEST L26335 - **ADDENDUM** — to §211 — AN IN-LOOP ACCUMULATOR WANTS A CLOSED-FORM EXPRESSION WHEN THE TARGET REMATERIALISES ITS CONSTANT AFTER EVERY CALL L26377 - **§275** — THE LEFTOVER-REGISTER READ L26412 - **§276** — MIXED ADDRESS-EXPRESSION SPELLING FOR ADJACENT RELOCATABLE SYMBOLS IS A CSE-UNIFICATION DIAL, NOT JUST A BYTE-ENCODING CHOICE (P31 S60; `func_80180FE8`, ov_SC06_006, byte-proven) L26452 - **§277** — RETURN-TAIL C SPELLING PICKS THE DELAY-SLOT-FILL vs TRAILING-MOVE TOPOLOGY, AND A NARROWER SECOND VARIABLE KEEPS TWO PSEUDOS INSTEAD OF ONE (P31 S60; `func_801846F0` ov_SC03_104, `func_801A44C4` md_SC07_004, both byte-proven) L26561 - **§278** — ADDENDA HARVESTED FROM WAVE cf (P31 S60): 34 candidates, 13 already covered, 8 sharpenings, 4 new laws L26625 - **ADDENDUM** — to §74 (func_800D0E30, resident) L26633 - **ADDENDUM** — to §172b-4 (func_80185054, ov_SC03_097) L26669 - **ADDENDUM** — to §265 (func_8017DC80, ov_SC07_002) L26707 - **ADDENDUM** — to §17 (func_800CB794, md_MAIN_036) L26746 - **ADDENDUM** — to §162p (func_8017C120, ov_MAIN_012) L26794 - **ADDENDUM** — to §20 (~L1947) (func_80186AD0, ov_SC06_032) L26828 - **ADDENDUM** — to §164-56 (func_8017F644, ov_SC04_005) L26858 - **ADDENDUM** — to §237 (func_8017F7FC, ov_SC03_092) L26893 - **§279** — A `do/while (p < end)` LOOP UNDER AN ENTRY GUARD: the guard decides the compare, not the loop (P31 S60; wave cf, func_8017F2A4, ov_SC03_096, byte-proven) L26922 - **§NNN** — A DO-WHILE'S GUARD AND LATCH MUST REPEAT THE SAME BOUND EXPRESSION, NOT SHARE ONE LOCAL: THE REPETITION IS WHAT BUYS THE CSE'D COPY INTO A SECOND REGISTER (P31 S60; `func_8017F2A4`, ov_SC03_096, byte-proven 25/25) L26923 - **§280** — THE CURSOR'S DECLARED TYPE PICKS `sltu` vs `slt`: a `T*` bound test is UNSIGNED by C rule, an integer cursor is signed (P31 S60; wave cf, func_800CAE74, md_MAIN_031, byte-proven) L26956 - **§NNN** — A LOOP CURSOR'S C TYPE (POINTER vs PLAIN INTEGER) SELECTS `sltu` vs `slt` FOR ITS BOUND TEST, INDEPENDENT OF THE VALUES INVOLVED (P31 S60; `func_800CAE74`, md_MAIN_031, byte-proven; cross-confirmed same wave by `func_8017F2A4`, ov_SC03_096) L26957 - **§281** — GROUP COPY-THEN-RMW BY OPERATION KIND, NOT FIELD BY FIELD: sched1 does the interleaving, the source must not (P31 S60; wave cf, func_80180FB4, ov_SC03_111, byte-proven) L26990 - **§NNN** — A DEPENDENT COPY-THEN-RMW BLOCK MUST BE SOURCE-GROUPED BY OPERATION KIND, NOT BY FIELD, AND SCHED1 DOES THE INTERLEAVING (P31 S60; `func_80180FB4`, ov_SC03_111, byte-proven) L26991 - **§282** — gcc's OWN LOOP REVERSAL PUTS THE COUNTER INIT AFTER THE HOISTED MOVABLES — a position no hand-written down-count can reach (P31 S60; wave cf, func_80180DD8, ov_SC04_005, byte-proven) L27036 - **§NNN** — WRITE THE UP-COUNT LOOP: gcc's OWN REVERSAL PRODUCES A COUNTER-INIT INSTRUCTION THAT LANDS AFTER HOISTED MOVABLES, WHICH A HAND-WRITTEN DOWN-COUNT LOOP CANNOT REPRODUCE (P31 S60; `func_80180DD8`, ov_SC04_005, byte-proven) L27037 - **What** — I could not verify L27074 - **§283** — ADDENDA HARVESTED FROM THE 36-WAVE BATCH (P31 S60): 1,216 candidates, 859 already covered, 46 sharpenings, 9 new laws L27121 - **ADDENDUM** — to §164-75 — the fold-reassociation law also fires at a variable's INITIALIZER, not only a later expression L27131 - **ADDENDUM** — to §21 — the `bltz`+`slti` (or N-separate-compares) signed-range-split bullet is now CONFIRMED on three independent functions, and generalizes beyond `lbu`/u8 L27157 - **ADDENDUM** — to §202 — the DEF-SIDE ALIAS also resolves a function-vs-DATA-symbol identifier clash, not only a function-vs-function prototype clash L27203 - **ADDENDUM** — to §22 (`volatile`-qualified-global reload lever, cookbook ~L1922) — for a NON-constant, same-address double RMW, a plain memory clobber beats `volatile`, and `volatile` actively breaks a delay-slot fill L27226 - **ADDENDUM** — to §195-E — a goto-ladder's STORES must sit AT the labels, after the gotos, not inline before them L27245 - **ADDENDUM** — to §195-N — a GNU statement-expression slider must sit INSIDE the conditional arm's value position, not as a post-hoc barrier, to block the store-flag transform on a ternary chain L27307 - **ADDENDUM** — to §176-B2 — in a micro-function with no long/short lifetime asymmetry, BOTH contending pseudos need their own hard-register pin L27364 - **ADDENDUM** — to §199-G — A `default:` LABEL GROUPED ONTO THE LAST CASE REMOVES THE `j default` TAIL, EVEN THOUGH THE 2-NODE HEADER STAYS ALL-POSITIVE L27411 - **ADDENDUM** — to §220 — REFERENCING THE RAW PARAMETER (NO NAMED COPY, NOT EVEN A PIN) LETS THE CALLEE-SAVED SPILL LAND IN THE FIRST CALL'S OWN DELAY SLOT L27480 - **ADDENDUM** — to §252 — a `>=0`/`<0` split on an unconditionally-decremented value needs the POSTFIX operator INSIDE the branch condition, not a prior statement L27538 - **ADDENDUM** — to §215 — FIFTH SHAPE: reused mask constants across two call-free merge sites each get their own whole-function hard-register pin, and a shared sub-expression at the second site must be its own statement L27565 - **What** — I could not verify L27648 - **Harness-defect** — flags L27719 - **ADDENDUM** — to §167-40 (func_8017E2CC, ov_SC04_015 — wave dg) L27812 - **ADDENDUM** — to §20's cross-jump EXPLOIT bullet (func_8017E360, ov_SC05_007 — wave dg) L27832 - **ADDENDUM** — to §87 (func_801815F4 ov_SC06_032; corroborating func_801840DC ov_SC05_017, func_80189C68 ov_SC03_006 — wave dg) L27846 - **ADDENDUM** — to §153 / §236-5 (func_801A419C, md_SC07_003 — waves di and dl, corroborating; refutes a contradicted dj-wave card) L27865 - **ADDENDUM** — to §263 (func_801E83AC, md_SC04_029 — wave dj) L27885 - **ADDENDUM** — to §265 (func_8017D878, ov_SC03_107 — wave dj; corroborated by a REJECTED, contradicted card in wave dm — see closing) L27899 - **ADDENDUM** — to §6 (func_801811F0, ov_SC03_102 — waves dj and dl, corroborated by a self-reported "nothing new" dm-wave card) L27913 - **ADDENDUM** — to §195-G (func_80183BB0, ov_SC05_001 — wave dj) L27927 - **ADDENDUM** — to the zero-byte-asm-slider family (§47 / §148-C / §153) (func_800CB874, md_MAIN_040 — wave dj; open tension with a more cautious dm-wave card — see closing) L27955 - **ADDENDUM** — to §194-B (func_8017EB34, ov_SC03_117 — wave dk; distinct from the §74 co-pinning finding on the SAME function below) L27973 - **ADDENDUM** — to §74 (func_8017EB34, ov_SC03_117 — counter/clamp variant; wave dj, corroborated by dk/dl/dm cards on the same function) L28005 - **ADDENDUM** — §37 — merged into the §153/§236-5 entry above (func_801A419C, wave dl) L28025 - **ADDENDUM** — §6 — merged into the §6 entry above (func_801811F0, wave dl) L28033 - **ADDENDUM** — to §238 (func_80182CB4, ov_SC02_000 — wave dl) L28041 - **ADDENDUM** — to §137a (func_801684B4, ov_MAIN_012; corroborated independently by func_80189E68, func_8017FF9C, func_801822B4, func_8018DA8C — wave dl) L28059 - **ADDENDUM** — to §8c / §88d (func_8016AB6C, ov_MAIN_012 — wave dm) L28075 - **ADDENDUM** — to §73 / §30#2 (func_800D1984, resident — wave dm) L28089 - **What** — I could not verify L28105 - **ADDENDUM** — to §174 Law 4 (func_8017E9A8, ov_SC06_015) L28125 - **ADDENDUM** — the zero-emission-asm family gains a REF-SLIDER PLACEMENT LAW and a paired RESTORER (func_800CB900, md_MAIN_026) L28165 - **From** — ck + cl + cm L28217 - **ADDENDUM** — §NNN — sharpens §55a / §164-37 / §165-28 (switch-vs-tree cluster): A SHAPE THAT LOOKS LIKE A SWITCH DISPATCH CAN BE PLAIN NESTED `if`s WHOSE SHARED BODY WAS TRIPLICATED BY THE SOURCE AND THEN CROSS-JUMP-MERGED BACK DOWN L28223 - **ADDENDUM** — §NNN — sharpens §167-13's boundary: CHAINING TWO IDENTICAL SIDE-BY-SIDE STORES INTO ONE C ASSIGNMENT STATEMENT IS A MID-BLOCK SCHEDULING-PRIORITY DIAL, NOT ONLY A STORE-ORDER SPELLING L28260 - **ADDENDUM** — §NNN — sharpens §162a3/§60b: A `sll $v0,16 / sltiu $v0,1` ZERO-TEST OF A JUST-DECREMENTED HALFWORD IS A SIGNED-TEMP WIDTH TELL OUTSIDE ANY SWITCH/RANGE-TEST CONTEXT L28293 - **ADDENDUM** — §NNN — sharpens §37/§124 (unspecified-parameter-list family): DERIVE A CALLEE'S ARITY LOWER BOUND FROM ITS OWN `.s` STACK-ARGUMENT READS, NOT FROM ANY SINGLE CALL SITE L28326 - **ADDENDUM** — to §5a (func_80181F74, ov_SC03_112, wave cn) L28359 - **ADDENDUM** — to §265 (func_8017E26C, ov_SC04_016, wave cn) L28409 - **ADDENDUM** — to §42b (func_8018247C, ov_SC07_002, waves cu + cw) L28447 - **ADDENDUM** — to §199-F family (func_8017EFB0, ov_SC02_021, wave cu) L28478 - **ADDENDUM** — to §195-E (func_800CFC1C, md_MAIN_003, wave cv) L28533 - **ADDENDUM** — to §215 addendum (func_800CB2C8, md_MAIN_033, waves cv + cw) L28578 - **ADDENDUM** — to §236 item 4 (func_8017D268, ov_SC04_006, wave cw) L28634 - **What** — I could not verify L28663 - **Harness-defect** — flags (not idioms — flagged for the operator) L28695 - **ADDENDUM** — to §250 (func_8017D7CC, ov_SC03_115 — cx/cy/cz/dr) L28736 - **ADDENDUM** — to §225 (func_8017E190, ov_SC03_115 — cx/cy/cz) L28781 - **ADDENDUM** — to §45-A (func_8017F6A4, ov_SC02_016 — cy/cz) L28834 - **ADDENDUM** — to §249 (func_80182ED4, ov_SC04_004 — dp/dr/dt) L28878 - **ADDENDUM** — to §199-A (func_801816FC, ov_SC02_005 — dp/dr/dt) L28923 - **What** — I could not verify L28969 - **Harness-defect** — flags L29012 - **§284** — COMBINE CAN REASSOCIATE TWO SEQUENTIAL BITWISE-AND MASKS INTO ONE AGAINST THE PRE-MASK VALUE; AN ASM IN/OUT FENCE RIGHT AFTER THE FIRST MASK BLOCKS IT (P31, wave dd, `func_8018087C`, ov_SC04_020, byte-proven) (P31 S60; waves #, byte-proven) L29074 - **§285** — PRE-INITIALIZING A VARIABLE WITH A SHARED CONSTANT BEFORE A BRANCH MAKES BOTH ARMS OF THE FOLLOWING if/else DESTRUCTIVELY REUSE THE SAME DESTINATION REGISTER FOR THEIR BITWISE RESULT (byte-proven; `func_801811F0`, ov_SC03_102, independently rediscovered across waves di/dj) (P31 S60; waves #, byte-proven) L29078 - **§286** — FOLD A STATEMENT'S SIDE EFFECT INTO A COMMA-EXPRESSION IN AN ARGUMENT POSITION TO PLACE ITS RTL RELATIVE TO A CALL'S OWN DELAY SLOT (P31 S60/dj; `func_80180A88`, ov_SC06_010, byte-proven 411/411) (P31 S60; waves #, byte-proven) L29082 - **§287** — A STACK-FRAME HOLE BELOW TWO ADDRESS-TAKEN AGGREGATE LOCALS IS A LEADING PAD MEMBER OF ONE COMBINED STRUCT, NOT SEPARATE LOCALS OR A REGISTER PIN (P31 S60/dj; `func_8017D104`, ov_SC06_027, byte-proven 47/47) (P31 S60; waves #, byte-proven) L29086 - **§288** — A REGISTER PIN DECLARED UNINITIALIZED AND ASSIGNED ONLY AT ITS LATE, SOLE USE STILL FORCES THE FIXED REGISTER'S SAVE/RESTORE, AND THE ASSIGNMENT'S SOURCE POSITION CONTROLS WHERE THE VALUE MATERIALIZES (P31; `func_80186530`, ov_SC02_017, byte-proven, match_one MATCH re-verified) (P31 S60; waves #, byte-proven) L29090 - **§289** — an array local's address-taken base keeps every element's store alive, even though only one pointer escapes (`func_80189EFC`, ov_SC04_011) (P31 S60; waves #, byte-proven) L29094 - **§290** — A SINGLE STRENGTH-REDUCED GIV CAN DRIVE STORES TO SEVERAL DISTINCT RELOCATABLE SYMBOLS, EACH KEEPING ITS OWN `%hi`/`%lo` ANCHOR (P31 S60; waves #, byte-proven) L29098 - **§291** — THE DELAY-SLOT FALSE-VALUE: A CONDITIONAL BRANCH'S ZERO ARM MUST BE A FALL-THROUGH-ADJACENT BLOCK ENDING IN AN EXPLICIT JUMP, OR REORG CANNOT MATERIALIZE IT INSIDE THE BRANCH'S OWN DELAY SLOT (P31 S60; waves #, byte-proven) L29102 - **§292** — DECLARING A SYMBOL UPSTREAM OF AN ALREADY-BANKED SIBLING THAT RELIES ON THAT SYMBOL'S IMPLICIT (K&R) DECLARATION CAN SILENTLY REPROTOTYPE THE SIBLING'S OWN CALL SITE (P31 S60; waves #, byte-proven) L29106 - **§293** — THE "WHOLE-OBJECT GATE NEEDS EVERY SIBLING" LAW, WRITTEN PROPERLY: IT IS THREE LAWS, AND THE LOAD-BEARING ONE IS "THE BASELINE, NOT THE SIBLINGS" (P31 S61; byte-proven on 15 binaries in one night) L29109 - **§294** — ADDENDA HARVESTED FROM THE S61 GEN0/MAXTOK/MAIN/DEEPSEEK BATCH (waves ab8/ab16/ab24/ab32 · g0a–g0f · m0a · ds1/ds2): 99 candidates, 52 covered, 15 notes → 10 addenda, 29 notes → 5 new laws (§295–§299), 3 refuted L29159 - **ADDENDUM** — to §127 — the -O0 constant-offset fold keys on the MEMBER-ACCESS tree shape, not on the index being constant L29170 - **ADDENDUM** — to §261a — FOUR MORE -O0 DIALS BEYOND THE RELOAD COUNT (boot.c + md_MAIN_011/003, wave m0a/g0a/g0f, byte-proven) L29198 - **ADDENDUM** — to §264-3 — the explicit entry copy's BOUND: required exactly when the RAW value must outlive the call that consumes only the PROMOTED value L29248 - **ADDENDUM** — to §172b-1 (counter-type dial) — the sll's SOURCE REGISTER is the placement discriminator L29268 - **ADDENDUM** — to §276 — the SHARE direction: spell the second adjacent symbol RELATIVE to force ONE anchor L29280 - **ADDENDUM** — to §31's density-dummy dial (L2460/L2497) — the dose is TWO refs, and the dummy must sit where the loser is live-through L29296 - **ADDENDUM** — to §282 — the ADDRESS-GIV face: write the walked address INLINE so strength reduction births the induction register at loop.c's own insertion point L29313 - **ADDENDUM** — to §253 — SECOND byte-proven card (upgrade from single-observation), and the placement face: postfix-in-condition parks the RMW store in the branch delay slot L29336 - **ADDENDUM** — to the L1800 anchor-steer bullet — a DERIVED-POINTER local silently flips the merged giv's anchor END L29357 - **ADDENDUM** — to §31's asm→layout inference — TWO WIDTH-PAIR DISCRIMINATORS (same offset, different widths) L29380 - **§295** — THE KERNEL-TRAP STUB: §81's jr-DETECTOR WITHOUT A TABLE IS A PsyQ SYSCALL TRAMPOLINE — ROUTE TO §265, NEVER INTO THE CARVE CHAIN (P31 S61; wave m0a, 9 cards byte-proven; resolves §182's held cluster) L29401 - **§296** — THE FRAME CHECK OUTRANKS THE ATLAS LEVER: READ PROLOGUE/EPILOGUE BEFORE DRAFTING ANY C — A REAL TELL CAN LIVE INSIDE AN UNREACHABLE FRAGMENT (P31 S61; wave m0a, 16 cards byte-proven; extends §179-C) L29456 - **§297** — ONE GIV SERVING MIXED-WIDTH LOADS *AND* A STORE NEEDS STRUCT-MEMBER SPELLING; CAST/INDEX SPELLINGS RE-SPLIT THE PSEUDO (P31 S61; wave m0a, `func_800347C8`, main, byte-proven 31/31) L29499 - **§298** — THE SHARED-TAIL POSITION DIAGNOSTIC: A FOLDED TAIL *BETWEEN* SWITCH ARMS MEANS PER-ARM DUPLICATED STATEMENTS, NOT A HOISTED POST-SWITCH STATEMENT (P31 S61; waves g0e/g0f, `func_80181B68`, ov_SC06_016, byte-proven 68/68) L29542 - **§299** — TWO INDEPENDENT EXTRACTION CHAINS EMIT CONTIGUOUSLY INSIDE ONE EXPRESSION; ONLY A STATEMENT BOUNDARY MAKES THE SCHEDULER INTERLEAVE THEM (P31 S61; wave m0a, `func_8003A404`, main, byte-proven 8/8) L29567 - **§300** — S61 DISTILL BATCH NOTES (waves ab8/ab16/ab24/ab32 · g0a–g0f · m0a · ds1/ds2 · m0b) L29602 - **§301** — AN INTERNAL `j` CARRIES `R_MIPS_26 .text`: rtu/match_one "MATCH" COULD NOT SEE WHICH LABEL A `j` TAKES — FIXED (`jrel`), AND THE TWO DRAFT SHAPES IT HID (P31 S62 T1; byte-proven 2/2, negative-controlled over 3,297 stubs) L29671 - **§302** — A RED BINARY IS A DRIFTED SPEC, NOT A MYSTERY: THE THREE CARVE-STATE INVARIANTS AND HOW TO DERIVE EACH FROM THE BYTES (P31 S62 T2; five reds healed in one session, 5/5, +39 held banks) L29719 - **§303** — MODULE ISLAND TABLES: DERIVE THE PADS AT BUILD TIME, PEEL NOTHING — THE §154-A/§260 "island-pads"/"island-blocked" WALLS DISSOLVE (P31 S62 T3a; byte-proven md_SC03_076 func_801F0A9C + func_801F0F28, sha 9a165e36…) L29763 - **§304** — SELF-DEFINING RODATA: WHEN A FUNCTION'S `.s` IS THE ONLY OWNER OF THE DATA IT REFERENCES, THE C BODY MUST DEFINE IT (P31 S62 T3; byte-proven md_MAIN_011/func_800D04F4) L29799 - **§305** — "CARVE-REFUSED" AT GATE TIME IS THREE NAMED, DETERMINISTIC CLASSES — NONE OF THEM A CARVE (P31 S62 T3; 28 resolver drafts autopsied 28/28) L29822 - **§306** — A HAZARD `nop` IN FRONT OF A DIV-RESULT STORE IS A STATEMENT-ORDER DEFECT: THE INDEPENDENT TRAILING STATEMENT MUST BE WRITTEN *BEFORE* THE DIVISION-CONSUMING ONE (P31 S62 T4; byte-proven func_8017E7D0) L29874 - **§306a** — T4 DISTILL ADDENDA (P31 S62; four byte-proven refinements to existing laws, verified against the book by an independent verifier; each names its parent §) L29901 - **§307** — THE BRUTE-FORCE-THE-STATEMENT-ORDERS LEVER HAS A BOUND: A FAN-OUT COPY'S PRIORITY IS SCHEDULER-INTERNAL, AND NO SOURCE ORDER REACHES IT (P31 S63; byte-evidenced NEGATIVE result, main wave) L29939 - **§308** — A NAIVE FINAL `goto` DELETES THE TARGET'S `j`+`nop`: SPELL THAT EDGE AS A TAUTOLOGICAL `if` SO cse FOLDS IT TO AN UNCONDITIONAL JUMP *AFTER* jump1's WINDOW HAS CLOSED (P31 S63 t5e-t5i; byte-proven func_80180808) L29983 - **§308a** — A TWO-INSTRUCTION ARM STUB LAID *BEFORE* THE OTHER ARM AND REACHED ONLY BY A TRAILING `j` SURVIVES ONLY BEHIND A SHORT-CIRCUIT `&&` GUARD PLUS A SEPARATE RE-TEST; EVERY PLAIN if/else-if, GOTO-LADDER, NESTED-INVERTED-if AND 1-/2-NODE switch LETS jump1 INLINE IT (−2 ins) (P31 S63 t5e-t5i; byte-proven func_80180808) L30012 - **§309** — A FRAME-ADDRESS EQUIVALENCE RIDES *THROUGH* A SKIPPABLE CONDITIONAL: POST-`if` STORES FOLD ONTO `$sp` UNLESS THE `if` SURVIVES jump1 AS A BARRIER-PRECEDED DIAMOND (P31 S63 t5e-t5i; byte-proven func_801812AC) L30046 - **§310** — A TWO-OPERAND `subu`'s DESTINATION TIES ONLY TO THE OPERAND THAT IS BLOCK-LOCAL: SHARE *ONE* SIDE ACROSS BLOCKS TO CHOOSE WHICH OPERAND'S REGISTER IT LANDS IN (P31 S64 t5j-t5m; byte-proven func_8017F578) L30086 - **§311** — A JOIN-BLOCK STORE CAN SWALLOW AN ARM'S LOAD-DELAY `nop`: WHEN ONE ARM'S VALUE COMES FROM A LOAD, DUPLICATE THE STORE INTO BOTH ARMS (P31 S64 t5j-t5m; byte-proven func_8017D7E0) L30117 - **§312** — A BARE RELATIONAL IN AN `if` GIVES THE `slt` NO TARGET: ASSIGN THE COMPARISON INTO THE ALREADY-ALLOCATED VARIABLE TO CHOOSE ITS DESTINATION REGISTER, AT ZERO INSTRUCTION COST (P31 S64 t5o-t5r; byte-proven func_80180DCC) L30159 - **§313** — A RECOVERY STAGE THAT REWRITES THE DRAFT IS PART OF THE MEASUREMENT: GATE THE RAW DRAFT FIRST, THE REWRITE ONLY AS A FALLBACK (P31 S65 t5r-recovery; byte-proven func_8017BEBC, 246 ins) L30185 - **§314** — AN IF/ELSE-IF ABS-RANGE CHECK'S C SPELLING IS INERT: FOUR STRUCTURALLY DIFFERENT REWRITES ALL COMPILE BYTE-IDENTICAL, AND NONE REACHES A TARGET THAT SINKS THE NEGATIVE ARM INTO AN OUT-OF-LINE BLOCK (P31 S65; UNPROVEN, gate-refused draft func_80181720) L30241 - **§315** — ALL-CONSTANT AGGREGATE FILL: THE EMISSION ORDER IS SHARED-LITERAL GROUPS × DESCENDING INDEX, WITH PAIRED SUB-FIELDS INTERLEAVED (P31 S66; ⚠ **UNPROVEN** — `func_80185214`, gate-REFUSED draft, closeness 32→5, never MATCHed) L30273 - **§316** — A GUARD CHAIN THAT GATES A SUCCESS BLOCK ROUTES ITS FAILING GUARDS TO A LABEL **BEFORE** THE FLAG TEST, NOT TO THE EPILOGUE: THE RESIDUAL IS IMM-OFFSET-ONLY AT AN EXACTLY EQUAL INSTRUCTION COUNT (P31 S66; byte-proven func_80180284) L30310 - **§317** — A NARROW STRUCT-FIELD STORE TURNS A *LIVE SImode VARIABLE* INTO A `li`: convert.c's TRUNCATION-DISTRIBUTION MINTS A HImode COPY, AND cse REWRITES THAT COPY'S SOURCE TO THE EQUIVALENT CONSTANT (P31 S66; byte-proven func_8017EF94) L30344 - **§318** — A UNARY MINUS STORED BACK INTO THE SAME HALFWORD IS COMPUTED IN HImode, SO ITS LOAD IS `lhu`; AN INLINE `(s32)` CAST IS PROVABLY INERT AND ONLY A NAMED SImode LOCAL BUYS `lh` (P31 S66; `func_8018568C`, ov_SC03_028 — **`match_one`-only, NOT byte-gated**) L30378 - **Addendum** — §148-A2 addendum — the empty-asm insn_count dial (N bare `__asm__("")` = exactly +N real i (func_801835B0) L30453 - **Addendum** — §312 addendum — naming the compare's dest is the vehicle, the hard-reg pin on that name is (func_80184A68) L30461 - **Addendum** — subu/sh dest reuses a pinned operand's dying register (func_8017F498) L30465 - **Addendum** — Addendum to §261a — the -O0 increment-operator copy also fires on the POINTER LOCAL itself (func_8001212C) L30473 - **Addendum** — Addendum to §164-XX/§165-06 — at -O0 a bare local IS a memory lvalue, so the increment ope (func_8001212C) L30477 - **Addendum** — Addendum to §312 — the compare's named destination must itself carry a hard register: nami (func_80184A68) L30481 - **Addendum** — Addendum to §167-12 — the single-operand volatile keepalive, re-confirmed at a gated MATCH (func_8017F498) L30485 - **Addendum** — A §5a BARRIER SITS IN REORG'S FILL WINDOW TOO, SO ITS SIDE OF THE INNER `goto` IS CHOSEN P (func_80181D08) L30489 - **Addendum** — Loop sentinel wrongly hoisted out of a call-containing loop (func_801835B0) L30493 - **Addendum** — Reversed-operand sltu then xori 1 means unsigned less-or-equal (func_8017D948) L30505 - **Addendum** — Chained *2*2 array index folds to one copy;sll, not two (func_80011380) L30509 - **Addendum** — REGALLOC-PERM: one memory-clobber barrier insufficient — stack two (func_80182D1C) L30523 - **Addendum** — Last if-arm's nested if un-fuses the whole preceding chain (func_8017FE88) L30529 - **Addendum** — A plain global-RMW triplet is a fillable scheduling window too — zero drift, and the fille (func_800CB058) L30533 - **Addendum** — Shared arithmetic that CONSUMES the selected value cannot be hoisted above the `if` — narr (func_80183DA0) L30537 - **REFUTED** — claim — Dead call-arg register address-fold: no C-level lever found (func_8017ECAC) L30541 - **Addendum** — Truncating assign must be the lazy `||` operand, not hoisted (func_80012B58) L30560 - **Addendum** — WIDTH sh!=lhu residual: hoist a sibling field's load first (func_80182538) L30572 - **REFUTED** — claim — REFUTED — the `j`-slot store is an ASPSX macro-expansion hop, not a cse split; maspsx hard (func_8005DBD8) L30589 - **§NNN** — REFUTED: A `sw %lo(SYM)($at)` IN A JUMP'S DELAY SLOT WITH ITS `lui $at` STRANDED ABOVE THE JUMP IS **ASSEMBLER** MACRO-EXPANSION, NOT A cse SPLIT — OUR PIPELINE CANNOT EMIT IT FROM ANY C, AND THE +1 IS A `maspsx` GAP (P31 S66 round2, `func_8005DBD8`, byte-probed) L30591 - **Addendum** — Static local_type blocker survives typedef removal — it's textual (func_801588CC) L30615 - **Addendum** — Orphan sh triplet to $sp is a write-only local array (func_8017F274) L30622 - **Addendum** — REGALLOC-PERM: the store reads the narrow copy's register — split the one narrow local by (func_801838CC) L30626 - **Addendum** — REGALLOC-PERM store in a cross-jump shared tail defeats §137's barrier (func_8017EDE8) L30630 - **Addendum** — LENGTH-DRIFT nop clears when offset math precedes the symbol launder (func_80039B20) L30634 - **REFUTED** — claim — REFUTED: a block shared across TWO switch statements is ordinary forward cross_jump, not a (func_8001B0D4) L30638 - **§NNN** — REFUTED: A CODE BLOCK SHARED BY TWO *DIFFERENT* SWITCH STATEMENTS IS ORDINARY FORWARD `cross_jump`, NOT A SHAPE C CANNOT REACH — §164-11 ALREADY BANKS IT FROM PLAIN NESTED SWITCHES (P31 S66 round3, `func_8001B0D4`; ⚠ **UNPROVEN** — gate-REFUSED draft, closeness 68→45, never MATCHed) L30640 - **RETRIEVAL** — FAILURES this round (not new knowledge — a RETRIEVAL defect) L30656 - **§319** — N TEXTUALLY DUPLICATED `return v;` TAILS PUT THE LAST `or` AND THE RETURN-REGISTER MOVE IN ONE BASIC BLOCK, SO combine FOLDS THEM AND YOU ARE EXACTLY −1; A `goto done;` JOIN WITH REAL INCOMING EDGES RESTORES THE SEPARATE `addu $v0,$a0,$zero` (P31 S66 round4; byte-proven func_801809F0) L30671 - **Addendum** — Masked-OR field-merge plateaus at close=10; bitfield store clears it (func_8017FD64) L30700 - **Addendum** — Integer-space address arithmetic is a THIRD no-movable spelling, and a distant `SYM[0]` re (func_8017D89C) L30704 - **Addendum** — LENGTH-DRIFT −1 on a coalesced-away copy: a CALLER-SAVED SOURCE pin can resurrect it, boun (func_8017D72C) L30714 - **Addendum** — Return-0 statement order: extra j+move vs delay-slot fusion (func_8018BB50) L30721 - **Addendum** — Counter zero in the DECLARATION slot, empty for-init — the prologue SHIFT-DRIFT/+K face of (func_8018275C) L30725 - **Addendum** — The dying-pinned-register reuse on a sign-extend chain: route every later read through a s (func_80186868) L30743 - **Addendum** — Volatile zero-byte asm slider scrambles the prologue schedule (func_801814B0) L30747 - **Addendum** — Register-pinned helper pointer local regresses closeness; use plain local (func_80013CFC) L30757 - **Addendum** — §194-A addendum — the bare/colon-less fence measured NULL and only the "memory"-clobber fo (func_8017E464) L30761 - **RETRIEVAL** — FAILURES this round L30765 - **§320** — THE §43 "RETURN-TYPE FLIP PAIR" IS **NOT** TU-EDIT-REQUIRED: THREE DRAFT-ONLY ESCAPES (P31 S66; byte-proven func_800CCBC0, func_800D30D0, func_800D2A24) L30786 - **§321** — FILE-SCOPE DUPLICATE ANONYMOUS-STRUCT TYPEDEFS ARE A HARD ERROR; THE SAME TEXT AT BLOCK SCOPE IS A WARNING (P31 S66; byte-proven func_80180728, func_8017F9F8, func_8017E07C) L30845 - **§322** — A PROBE THAT ANSWERS A *NECESSARY BUT NOT SUFFICIENT* QUESTION WILL PRICE BLOCKED WORK AS FREE: RUN THE REAL PLANNER WHEN THE PLANNER IS PURE (P31 S67; measured, 96 of 159 open jtbl functions) L30866 - **§323** — CARRYING FILE-SCOPE TYPES BETWEEN SPLIT TUs: DEDUPE BY NAME, SKIP HEADER-PROVIDED, AND THE GUARD TRAVELS WITH THE BLOCK (P31 S67; ov_SC02_000, two defects fixed, one open) L30896 - **§323a** — R53, TWICE IN ONE HOUR: A FAILED BUILD LEAVES THE PREVIOUS BINARY, AND `sha1sum` READS GREEN (P31 S67) L30926 - **§323b** — A SCRIPT THAT PARSES argv AT IMPORT CANNOT BE SHARED; EXTRACT THE PREDICATE, DO NOT COPY IT (P31 S67) L30935 - **§324** — THE ARITY-SELF WALL NEEDS *BOTH* HALVES: A K&R DEFINITION **AND** A NO-PROTO TU DECL; EITHER ALONE STILL FAILS (P31 S67; rtu-proven ov_SC01_005/func_8017FBCC, 14 instances measured) L30949 - **§325** — REGALLOC: A SHARED SMALL CONSTANT STORED TWICE IN THE PRE-LOOP BLOCK IS A *local-alloc* $s-OCCUPANT THAT STEALS THE ARGUMENT ALLOCNO'S REGISTER — PIN THE ARGUMENT-DERIVED LOCAL, NOT THE CONSTANT (P31 S67; byte-proven ov_SC03_119/func_80184F18, 153 ins) L30987 - **§326** — DEFEATING ADDRESS-CSE: SPELL TWO READS OF THE SAME HALFWORD DIFFERENTLY AND GCC CANNOT SHARE THE ADDRESS (P31 S67; byte-proven ov_SC01_077/func_8017FAAC, 154 ins) L31000 - **§327** — A RANGE TEST MUST BE HImode: WITH `s32` + A `(u16)` CAST GCC *PROVES* THE MASK REDUNDANT AND DROPS THE `andi` (P31 S67; byte-proven ov_SC02_039/func_8017EC34, 154 ins) L31009 - **§328** — THE VOLATILE ALIAS MUST BE AN *OBJECT*, NOT A CAST: `*(volatile s32*)&sym` UNFOLDS %lo INTO A SEPARATE `addiu` (P31 S67; byte-proven ov_SC07_007/func_80181B8C, 156 ins, NEW LAW) L31024 - **§329** — fold-const NARROWS `(int)s16_var & 0xFFF` ONTO THE *RAW HImode PSEUDO*, BREAKING THE SIGN-EXTEND/MASK REGISTER TIE — A ZERO-BYTE WIDENING TEMP RESTORES IT (P31 S67; byte-proven ov_SC01_084/func_80183244, 157 ins) L31034 - **§330** — THE NEIGHBOUR-SHAPE LEVER IS THE CHEAPEST FIRST MOVE, AND IT IS UNDER-USED (P31 S67; four independent instances in one 20-function wave) L31042 - **§331** — OPEN GAP: NO LEVER ELIMINATES AN *UNWANTED DUPLICATE* COPY AT A BRANCH-TARGET BLOCK HEAD (P31 S67; main/func_80013154, closeness 12, NOT solved) L31059 - **§332** — THE maspsx `la`-IN-A-DELAY-SLOT GAP: gcc EMITS A SYMBOLIC ADDRESS LOAD AS ONE ATOMIC length-2 INSN, SO IT CAN NEVER FILL A JUMP DELAY SLOT — 6 FUNCTIONS FLEET-WIDE, NONE BANKABLE FROM C (P31 S67; byte-traced main/func_80062144, func_8005DBD8) L31071 - **§332a** — MAIN'S RESIDUAL FRONTIER IS CONTAMINATED WITH TOOLCHAIN WALLS: 4 OF 7 IN ONE WAVE (P31 S67, measured) L31096 - **§333** — FRAME SIZE IS SET BY *DECLARED* AGGREGATES, NOT USED ONES: AN UNREFERENCED TRAILING LOCAL IS A REAL DIAL (P31 S67; three independent byte-proven instances in one wave) L31115 - **§334** — A RELOAD SPILL SLOT IS ROUNDED TO `BIGGEST_ALIGNMENT` (8B), SO ONE SPILLED 4-BYTE PSEUDO CAN GROW THE FRAME BY 16 (P31 S67; byte-proven ov_SC05_008/func_8017DF68, 82 -> 53 residual) L31129 - **§335** — AN `extern u16 A[]` READ AT A VARIABLE SUBSCRIPT ALLOCATES DEAD STACK TEMPS (~8B PER ACCESS) THAT INFLATE THE FRAME WHILE EMITTING ZERO EXTRA INSTRUCTIONS (P31 S67; byte-proven ov_SC06_025/func_8017EA74, closeness 141 -> 20) L31140 - **§336** — THE §5a CROSS-JUMP BARRIER GOES AT THE *BOTTOM* OF THE TWIN, NOT THE TOP: `find_cross_jump` WALKS BACKWARD FROM THE CONVERGING JUMP (P31 S67; byte-proven ov_SC05_001/func_80183C9C) L31149 - **§337** — THE CC1-ONLY BLOCKER CLASS: `blocker_probe`'s STATIC ORACLE REPORTS "none" AND THE WHOLE-TU COMPILE STILL FAILS (P31 S67; ov_SC04_011/func_801827DC, md_MAIN_027/func_800CB4A4) L31157 - **§338** — `jtbl_carve._sltiu_bounds` MISREADS A NON-SWITCH `sltiu` AS A BOUNDS CHECK, OVER-SPANNING THE TABLE (P31 S67; ov_SC06_022/func_80185B80, byte-diagnosed) L31171 - **§339** — A 2-CASE SWITCH OMITS THE LOW-BOUND RANGE TEST, SO THE PRESENCE OF `slti/bnez` BETWEEN THE `beq`s IS A **COUNT TELL** FOR A THIRD CASE NODE (P31 S67; byte-proven ov_SC02_005/func_80190538, 197 ins) L31181 - **§340** — §194-K COROLLARY: **FLIP THE FALSE EDGE YOU CANNOT DELETE.** A "scheduler" residual can be sched.c's ALIAS ORACLE emitting a FALSE true-dependence; source order chooses its DIRECTION (P31 S67; byte-proven ov_SC03_107/func_8017CF48, 10 -> 0 in one compile, zero bytes) L31209 - **§341** — AN HImode STORE TEMP REWEIGHTS A sched2 TIE-BREAK THAT NO STATEMENT ORDER CAN REACH (P31 S67; byte-proven ov_SC03_006/func_801823B8, last 4 ins) L31243 - **§342** — A `void *` PARAMETER CAST TO ITS REAL TYPE IN A LOCAL IS **NOT** BYTE-NEUTRAL WHEN A LATER PARAMETER ALSO NEEDS A CALLEE-SAVED REGISTER (P31 S67; byte-proven ov_SC07_002/func_80181394, NEW LAW) L31257 - **§343** — `decl_prior`'s FLEET MAJORITY CAN BE WRONG ABOUT THE TRUE SIGNATURE — READ THE RIVALS, NOT JUST THE WINNER (P31 S67; measured on func_8012BD14 / func_8012D624 / func_80143C74) L31274 - **§344** — RAISE A BIV'S global_alloc PRIORITY WITH A ZERO-BYTE REFERENCE INSTEAD OF PINNING IT; PINNING THE COUNTER KILLS LSR ENTIRELY (P31 S67; byte-proven ov_SC03_121/func_80180E64, 222 ins) L31296 - **§345** — A VOLATILE **STORE** EVICTS THE MEM FROM cse AND KEEPS `sh`; A VOLATILE **LOAD** BLOCKS combine AND DEGRADES `lh` INTO `lhu+sll+sra` (P31 S67; byte-proven ov_SC01_084/func_80181A7C) L31312 - **§346** — `c ? X : -X` TAKES expand_expr's COND_EXPR **SINGLETON** PATH (copy, then negate IN PLACE) — AN if/else STATEMENT GIVES THE TWO-ARM FORM (P31 S67; byte-proven ov_SC03_102/func_80180C38, closed the last instruction) L31322 - **§347** — LOOP REGISTER ASSIGNMENT IS A **DECLARATION-ORDER + LIVE-RANGE** DIAL: FIVE COMPOSABLE LEVERS, 178 -> 0 (P31 S67; byte-proven ov_SC06_029/func_8017EF34, 243 ins) L31342 - **§347-addendum** — A THIRD INSTANCE, AND THE SHARPEST STATEMENT OF THE RULE (md_MAIN_025/func_800CB300, 243 ins) L31372 - **§343-addendum** — SECOND INSTANCE OF THE WRONG-MAJORITY DECL (same function) L31390 - **§348** — THE BASE SPELLING PICKS THE ADDRESSING MODE: A SYMBOL GIVES THE 3-INSN `lui/%lo` FORM, A POINTER VARIABLE GIVES THE 2-INSN `addu/lw` FORM (P31 S67; byte-proven ov_SC07_007/func_80182184, 264 -> 30 on this row alone) L31397 - **§349** — RE-ASSIGN A BASE POINTER AT THE END OF THE LOOP BODY TO MAKE `n_times_set > 1` — THAT KILLS BOTH loop.c's INVARIANT HOIST **AND** THE ADDRESS GIV, REPRODUCING A REMATERIALISED `addiu $aN,$sp,K` (P31 S67; byte-proven ov_SC06_029/func_801804C8, 255 ins) L31414 - **§350** — A ZERO-BYTE RE-TIE SETS `reg_n_sets=2`, WHICH KILLS sched1's `birthing_insn_p` LAUNCH_PRIORITY BOOST — THE MECHANISM BEHIND "MY ADDS ARE GLUED TO THEIR STORES" (P31 S67; byte-proven ov_SC04_011/func_80180B24, 215 ins) L31435 - **§351** — `/s` (MEM_IN_STRUCT_P) IS A DIAL YOU CHOOSE PER ACCESS: A COMPONENT_REF GRANTS IT AND LETS cse KEEP AN INDEX ACROSS THE STORE; A PLAIN CAST DENIES IT (P31 S67; ov_SC01_000/func_8017DD04, 186 -> 5) L31456 - **§352** — ⚠ TWO IDENTICAL `__asm__ __volatile__("")` BARRIERS **MERGE WITH EACH OTHER** — SPELL THE SECOND ONE DIFFERENTLY (P31 S67; byte-proven resident/func_800D128C, measured closeness 105 when they merged) L31486 - **§353** — USE `-fno-thread-jumps` AS AN **ORACLE** TO PROVE A RESIDUAL IS thread_jumps, THEN LAUNDER THE *VALUE* TO KEEP A DEAD RE-TEST (P31 S67; byte-proven ov_SC01_008/func_8017EC68, 279 ins) L31519 - **§354** — THE giv **WORTH-WHILE TEST** IS A DIAL: RE-ASSOCIATE THE ADDEND INTO THE INDEX TERM AND `strength_reduce` DECLINES (P31 S68; byte-proven ov_SC03_105/func_801824CC, 320 ins, 201 → 5 → 0) L31542 - **§355** — A REMAPPED SIBLING'S **SOURCE BIAS IS NOT ITS EMITTED BIAS** — DO NOT HAND-SHIFT OFFSETS TO MATCH THE ASM (P31 S68; byte-proven ov_SC07_007/func_8013DD68, 187/187 in 2 iterations) L31560 - **§356** — MEASURE A DRAFT IN THE TU IT WILL LIVE IN, NOT IN THE STANDALONE PROBE (P31 S68; measured over 47 stored drafts) L31574 - **§357** — ONE STRUCT POINTER, NOT TWO: A SECOND SOURCE VARIABLE BUILDS A THIRD IV (P31 S68; byte-proven ov_SC06_029/func_80181DF8, 335 ins, 330 → 13) L31589 - **§358** — (sharpens §333) — AN **UNREFERENCED** FIXED-SIZE AGGREGATE LOCAL IS LOAD-BEARING (P31 S68; same function) L31598 - **§359** — (§43-adjacent) — SPELL A SIGN-WIDEN AS AN EXPLICIT TWO-STEP, FUNCTION-SCOPED TEMP (P31 S68; byte-proven main/func_80012B58, 69 ins, 58 → 3 → 0) L31608 - **§360** — THE "COMPILER FOUND A SHORTER EQUIVALENT THAN THE TARGET" PAIR (P31 S68; main/func_800241C0, 68 ins, 68 → 19) L31621 - **§361** — ★ — A LOOP-TAIL BYTE SIGNATURE THAT NAMES ITS SOURCE SHAPE — AND THE LAW THAT A "SCHEDULING TIE" MAY BE YOUR OWN EARLIER LEVER (P31 S68; byte-proven main/func_800241C0, fable escalation, 19 → 0 in 3 iterations) L31637 - **§362** — TWO TRAPS WHEN A CARVE MOVES A STUB INTO THE `-O0` TU (P31 S68; byte-proven, 6 fns / 2,547 ins across ov_MAIN_012 / ov_SC02_037 / ov_SC03_107) L31682 - **§363** — ★★ — THE OVERLAY-LAYOUT ASSUMPTION IS A SYSTEMIC BUG CLASS, AND `main` IS THE EXCEPTION THAT FINDS IT (P31 S68; six instances, four of them in one session) L31705 - **§364** — ★ — THE libgpu `P_TAG` BITFIELD SPELLING IS **OPT-LEVEL DEPENDENT** (P31 S68; two functions, opposite verdicts, same session) L31734 - **§365** — PIN **BOTH** MASKS OR NEITHER (P31 S68; ov_SC01_000/func_8017E594, 357 ins) L31748 - **§366** — ★★ — `group_case_nodes` MERGES **STACKED CONSECUTIVE** CASE LABELS: GIVE EVERY CASE ITS OWN BODY (P31 S68; ov_SC01_001/func_8017EC28, **first-try MATCH 360/360**, 96/96 relocs audited) L31757 - **§367** — RECONCILING A DECL CONFLICT BETWEEN TWO DRAFTS FOR THE SAME TU (P31 S68; main) L31777 - **§368** — ★★★ — THE **RELOAD-REMAT CONSTANT**: REACH A REGISTER NO PIN CAN REACH (P31 S68; ov_SC03_105/func_80187A30, 339 ins, fable escalation closed 8 → 0 in ONE edit) L31792 - **§369** — REUSE THE **COMPARE CONSTANT'S OWN VARIABLE** FOR A MASK THAT KEEPS COALESCING (P31 S68; md_SC07_004/func_801AEC38, 365 ins) L31822 - **§370** — ★★ — A **HARD BOUND** FROM sched.c, AND THE reorg SLOT-STEAL DIAGNOSTIC (P31 S68; main/func_8001BC6C, 69 ins, NOT closed — 33 → 28 over ~45 measured compiles) L31838 - **§371** — ★★ — CARVING A **SINGLE-OBJECT MODULE BINARY**, AND THE spimdisasm RODATA-MIGRATION TRAP THAT FOLLOWS (P31 S68; byte-proven md_MAIN_003, func_800D0D6C 345 ins) L31890 - **§372** — ★★★ — THE **COPY-CAPTURE PAIR**, AND THE ONE ZERO-BYTE EDIT THAT DEFEATS BOTH (P31 S68; byte-proven main/func_8003491C, 78 ins, fable escalation closed 5 → 0) L31939 - **§373** — ★★★ — THE **DEAD-RESET CSE-BREAKER**, THE PIN THAT BREAKS A sched2 ANTI-DEP, AND WHY AN `asm` CAN NEVER RAISE PRIORITY (P31 S68; byte-proven ov_SC06_010/func_8017E764, 438 ins, fable escalation closed 8 → 0) L31977 - **§3-1.** — DEAD-RESET CSE-BREAKER — the zero-footprint replacement for a §195-I asm re-tie L31979 - **§3-2.** — A REGISTER PIN THAT DELETES A sched2 ANTI-DEPENDENCE L31997 - **§3-3.** — HARD FACT FOR THE SCHEDULING MAP — an `asm` ALWAYS has priority 1 L32010 - **CROSS-REFERENCE** — TO §370 — checked and found INAPPLICABLE here, which is the point L32018 - **§374** — A `register … __asm__("$30")` RESERVATION IS **NOT HONOURED** BY `move_movables` (P31 S68; main/func_80015608, 86 ins) L32026 - **§375** — AN `$a0`-`$a3` PIN USED LATE RELOCATES AN **EARLIER** OUTGOING-CALL USE OF THAT REGISTER (P31 S68; main/func_8005F0C8, 88 ins) L32042 - **§376** — ★★★ — A STANDALONE `match_one` CLOSENESS OF 0 IS A CLAIM ABOUT THE **BODY**, NEVER ABOUT THE **TU** (P31 S69; measured 0/28) L32055 - **§377** — THREE HARNESS DEFECTS FOUND IN ONE GATING SESSION, ALL "A CONFIDENT NUMBER ABOUT A SMALLER WORLD" (P31 S69) L32097 - **§378** — ★★★ — THE **SELF-CALLER CAST**: LET A TU KEEP CALLING THE FUNCTION IT IS ABOUT TO DEFINE (P31 S69; byte-proven ov_SC04_010/func_8017D6CC) L32114 - **§379** — ★★★ — **MEM_IN_STRUCT_P**: THE SAME LOAD, WRITTEN AS A STRUCT MEMBER, SCHEDULES WHERE A CAST CANNOT (P31 S69; byte-proven main/func_80021284 220 ins and main/func_8002D904 217 ins, found INDEPENDENTLY by two agents) L32164 - **§380** — ★★★ — **A SECOND SET OF A PSEUDO DISQUALIFIES IT FROM `move_movables`** (P31 S69; main/func_800215F4, 465 ins, closeness 106 → 59 → 39) L32195 - **§381** — THE `insn_count` HOIST THRESHOLD IS A DIAL YOU CAN READ WITH `cc1 -dL` (P31 S69; four independent uses in one wave) L32216 - **§382** — TWO FOLD REASSOCIATIONS THAT NEED THEIR OWN STATEMENT (P31 S69) L32232 - **§383** — TWO TOOLCHAIN FACTS THE PACKS DID NOT CARRY (P31 S69) L32244 - **§384** — ★★★ — A CARVE-CONFIG BANK IS RED UNTIL YOU RE-EXTRACT, AND THAT LOOKS EXACTLY LIKE A FALSE BANK (P31 S69; measured twice, cost one destroyed match) L32259 - **§385** — ★★★ — THE **SCHED2 PRIORITY-DONOR ASM**: closing the "hoisted-invariant vs IV-init preheader swap" class (P31 S69; byte-proven main/func_80038A58, 347 ins, fable escalation 2 → 0) L32309 - **§386** — ★★★ — A BYTE LOAD ON THE **BIV** BASE WAS BORN IN THE COMBINE PASS: SPELL IT AS A SHIFT-MASK, NEVER A DEREF (P31 S69; byte-proven main/func_80020598, 292 ins, escalation 1 → 0) L32335 - **§387** — ★★ — **SPLIT-FOLD DISPATCH CLOBBER**: one switch case needs a reload, another must keep the fold (P31 S69; byte-proven main/func_80030F80, 343 ins, escalation 3 → 0) L32361 - **§388** — ★★★ — THE **-O0 COLOURING ORACLE**: simulate `stupid.c` instead of grinding spellings (P31 S69; main/func_80011380 proved a C-level WALL at 6) L32384 - **§389** — ★★★ — `h_norm` IS BLIND TO INDEXED-GLOBAL RELOCS, SO FREE WORK BECOMES AN INVISIBLE SINGLETON (P31 S69; 31 stubs / 4,811 ins recovered, 8 banked same day) L32409 - **§390** — ★★★ — MINIMUM DISTANCE IS NOT MINIMUM WORK; RANK TWIN CANDIDATES BY EFFORT, AND FILTER LOOKALIKES BY RATIO (P31 S69; byte-proven ov_SC01_077/func_80184D50, banked) L32450 - **§391** — ★★ — A BYTE-ALIGNED STRUCT COPIES IN FOUR INSTRUCTIONS, A WORD-ALIGNED ONE IN TWO (P31 S69) L32488 - **§392** — ★★★ — THE SONNET-WAVE HARVEST (P31 S69): SEVEN TYPE/ORDER LEVERS THAT EACH CLOSED A MATCH L32502 - **§393** — ★★ — THE **BIRTHING BOOST**: A SINGLE-SET LOCAL IS SCHEDULED LAST; GIVE IT A SECOND SET (P31 S69; byte-proven ov_SC02_017/func_8017FCFC) L32543 - **§394** — ★★ — TWO ALIGN-1 ACCESSES IN ONE FUNCTION RESERVE A PHANTOM STACK SLOT (P31 S69; ov_SC02_005/func_80180610) L32560 - **§378b** — ★★★ — THE FOUR VARIANTS OF THE DECL BLOCKER, AND THE TWO PLACES §378 DOES **NOT** APPLY (P31 S69, all four measured the same day) L32572 - **§395** — ★★★ — FIVE NARROWING/PLACEMENT LEVERS FROM ONE 91-INSTRUCTION CRACK (P31 S69; byte-proven ov_SC06_018/func_80189E60, warm start 32 off → MATCH 91/91) L32611 - **§314b** — ★★ — TWO ABS-RANGE GUARDS IN ONE FUNCTION NEED **DIFFERENT SPELLINGS** (P31 S69; byte-proven ov_SC04_002/func_8018691C, 111 ins) L32645 - **§322b** — ★★★ — THE CARVE CLASS IS COMPLETABLE, AND EVERY WORKTREE `CARVE-REFUSED` WAS AN INSTRUMENT VERDICT (P31 S69, Fable-3 audit; byte-proven end-to-end) L32667 - **§332b** — ★★★ — THE §332 "WALLS" ARE A PER-OBJECT ASSEMBLER MODE, NOT A C LIMIT — 6 CLOSE AS REAL C (P31 S69, Fable-3) L32702 - **§378c** — ★★ — THE FIFTH DECL-BLOCKER VARIANT: THE DRAFT REDECLARES WHAT THE TU ALREADY OWNS (P31 S69) L32722 - **§396** — ★★★ — SIX LEVERS FROM THE S69 SINGLETON ROUND, INCLUDING ONE THAT ONLY A `COND_EXPR` REACHES (P31 S69) L32737 - **§397** — ★★★ — RE-RUN THE TWIN SCAN AFTER EVERY EXEMPLAR BANK; A CLUSTER SIBLING IS FREE THE MOMENT ITS EXEMPLAR LANDS (P31 S69; ~250k tokens spent proving it the expensive way) L32785 - **§396g** — ★★ — A GUARD LADDER'S RUNGS MUST STAY SYMMETRIC OR `reorg.c` LOSES ITS BRANCH REDIRECT (P31 S69; byte-proven ov_SC03_028/func_80184C90, 92 ins) L32818 - **§398** — ★★★ — `family_remap` CARRIES THE **SOURCE** TU's DECL ENVIRONMENT INTO A DESTINATION THAT ALREADY OWNS THOSE NAMES (P31 S69; measured 3 banked of 22) L32835 - **§398b** — ★★ — NAMING A SUB-EXPRESSION IN A LOCAL CHANGES WHICH PSEUDO SURVIVES; INLINE IT AT BOTH USE SITES (P31 S69; byte-proven ov_SC03_028/func_80183264, 93 ins) L32865 - **§399** — ★★★ — FOUR LEVERS FROM THE FINAL S69 ROUND (P31 S69; each byte-proven, none previously in the cookbook) L32892 - **§400** — ★★ — A BASELINE CHECK THAT CONFLATES "ABSENT EVERYWHERE" WITH "CHANGED UNDER US" SILENTLY DROPS NEW FILES (P31 S69; 8 files, one session) L32932 - **§401** — §401 L32967 - **§402** — §402 L33000 - **§403** — §403 L33024 - **§404** — §404 L33056 - **§405** — ★★★ — THE S70 WAVE HARVEST: 130 agents, 113 MATCH, and the laws they brought back L33092 - **§3-A.** — THE ORACLE HAS A HOLE: match_one cannot see a jump table (§405-A) L33098 - **§3-B.** — THE SCHEDULER DIALS (the dominant residual family this wave) L33108 - **§3-C.** — REGISTER ALLOCATION FROM C, WITHOUT PINS L33124 - **§3-D.** — INTEGRATION IS STILL THE BOTTLENECK, AND THE TU IS THE AUTHORITY L33140 - **§3-E.** — WHAT THE AGENTS REFUTED L33148 - **§406** — ★★ — THE PROLOGUE-WEAVE CLASS IS MECHANICAL AND LARGE (134 open stubs) L33158 - **§407** — ★★ — LATE-WAVE ADDENDA TO §405 (the last agents in) L33180 - **§408** — ★★★ — §406 REFUTED AS A SWEEP: THE SHAPE IS THE FAMILY, THE DISAGREEMENT IS THE DEFECT (P31 S71; 0 MATCH / 14 applied, 0 / 210) L33209 - **§409** — ★★★ — THE S71 JOURNAL-FUELLED WAVE: 100% FIRST-PASS MATCH, AND THE NINE LAWS IT BROUGHT BACK (P31 S71) L33261 - **§3-The** — nine laws this wave produced L33288 - **§410** — ★★★ — COPY THEN ACCUMULATE ON THE COPY: resolving the birthing-boost vs register-allocation dilemma (P31 S71; byte-proven `ov_SC04_015/func_8017EB78`, 98 ins) L33353 - **§411** — ★★★ — THE PACK MUST CARRY THAT FUNCTION'S OWN HISTORY (P31 S71; measured 38/39 vs 124/131) L33386 - **§412** — ★★★ — §323 CARVE BLOCKER 2 WAS A REGEX THAT COULD NOT SEE PAST `__attribute__` (P31 S71) L33424 - **§413** — ★★★ — DIFFICULTY IS THE RESIDUAL CLASS, NOT `nins` — ROUTE THE MODEL TIER OFF HISTORY (P31 S71, Drew) L33473 - **§414** — ★★★ — `parallel_gate` ON `main` IS A FALSE PASS, AND THE RULE WAS ALREADY WRITTEN DOWN (P31 S71) L33510 - **§415** — ★★ — A FILE-SCOPE DECL MAKES gcc-2.7.2 MERGE THE TU'S LATER *BLOCK-SCOPE* EXTERNS INTO IT (P31 S71; byte-proven `ov_SC04_011/func_80180B24`, 215 ins) L33547 - **§416** — ★★ — FOUR LEVERS FROM THE S71 OVERNIGHT LANE, none of which the cookbook held (P31 S71) L33572 - **§417** — ★★★ — A REGISTER PIN CAN BLOCK `jump.c`'s SELECT COLLAPSE, AND UNPINNING THEN EXPOSES A `cse` SKIP-BLOCKS MERGE (P31 S71; byte-proven `ov_SC03_013/func_8017E6F4`, 182 ins) L33605 - **§418** — ★★★ — TWO LOOP-STRUCTURE LEVERS: MAKE THE SECOND INDEX A GIV, AND KEEP A TABLE ADDRESS UNFOLDED (P31 S71; byte-proven `ov_SC04_016/func_8017DF8C`, 184 ins, 32 → 0 in seven compiles) L33632 - **§419** — ★★★ — WHEN A PIN IS IMPOSSIBLE, WIN THE local-alloc DENSITY CONTEST INSTEAD (P31 S71; byte-proven `ov_SC01_000/func_8017DD04`, 297 ins) L33658 - **§420** — ★★★ — A MULTI-CLUSTER SYMBOL REBASE, AND THE BARE-NAME DEDUP THAT HID THREE QUARTERS OF IT (P31 S71; 4 banked in 57 s) L33692 - **§421** — ★★★ — A `la $tN` + `addiu` PAIR CAN BE A **RELOAD** ARTIFACT THAT NO C SPELLING REACHES (P31 S71; byte-proven `md_SC07_003/func_801A293C`, 313 ins, 6 → 0) L33729 - **§422** — ★★ — QImode ARITHMETIC VIA `(u8)(x - K)`, AND `flag ^ 1` NEEDS ITS OWN TEMP (P31 S71; byte-proven `resident/func_800D06E8`, 344 ins) L33760 - **§423** — ★★★ — "MATCH IN ISOLATION + GATE REJECTS + CAUSE NOT DETERMINED" ⇒ GREP THE TU FOR A FILE-SCOPE TYPEDEF THE DRAFT ALSO CARRIES (P31 S71; byte-proven `ov_SC03_092/func_8017FA74`) L33780 - **§424** — ★★★ — EQUAL-PRIORITY STORES COME OUT **REVERSED**: sched1's LUID tie picks the LAST statement first (P31 S71; byte-proven `ov_SC07_006/func_801890FC`, 387 ins) L33807 - **§425** — ★★★ — `sb` ALIASES SCALAR GLOBALS WHILE `sh`/`sw` STRUCT STORES DO NOT, AND TWO MORE ALIAS/BOOST RULES (P31 S71; `md_MAIN_003/func_800CF3E8`, 467 of 469 ins, all four byte-verified from `-dS`/`-dR`/`-dl`/`-dr`) L33829 - **§426** — ★★★ — main's SWITCH FUNCTIONS WERE NEVER A CODEGEN WALL: ONE RODATA CARVE HAD BEEN MISSING SINCE PHASE 7 (P31 S72; 3 of the 11 "PROVEN gate-rejects" banked byte-identical in 14 s) L33855 - **§427** — ★★ — A HASH IS A CORRECTNESS ORACLE WITH ZERO DIAGNOSTIC CONTENT; PRESERVE THE RED ARTIFACT BEFORE ANYTHING REBUILDS OVER IT (P31 S72) L33931 - **§428** — ★★★ — A ZERO-BYTE CROSS-JUMP BARRIER: ADVANCE THE POINTER INSIDE EACH SWITCH ARM (P31 S72; `main/func_80026D64`, 218 ins, MATCH in 2 compiles) L33950 - **§428a** — ★★★ — TWO RESIDUALS THAT MOVE IN OPPOSITE DIRECTIONS UNDER EVERY LEVER USUALLY SHARE ONE CAUSE (P31 S72; `main/func_8001B0D4`, NEAR/53 -> MATCH; **my first answer here was WRONG and is kept below as the refutation**) L33988 - **§430** — ★★★ — A SHARED TAIL IS A LATE CROSS-JUMP MERGE, NOT A SOURCE `goto` — AND SPELLING IT AS ONE CAN INVALIDATE A LOOP (P31 S72; `main/CdReadSectorReadyCB`, 422/424 ins, verified with `cc1 -dL`) L34023 - **§431** — ★★★ — SPLITTING A 27,000-LINE TU AT ITS ORIGINAL BOUNDARIES: THE JTBL SPANS TELL YOU WHERE, AND THE COMPILER TELLS YOU WHAT CROSSES (P31 S72; `src/800.c` -> `800.c`/`800_b.c`/`800_c.c`, byte-identical with nothing banked) L34061 --- ## L-number → section (if you cited `§1234` and the grep failed, it was a LINE number) Index rows carry a `L…` anchor = the section's line in `docs/matching-cookbook.md`. Notes routinely quote that as a section id. This table resolves it. Grep bait: `L-number`, `line number cited as section`, `§ grep failed`. | L | section | title | |---|---|---| | L30 | §3-How | to use this | | L39 | §1 | Idiom catalog (asm pattern → C that produces it) | | L41 | §3-I1 | Unsigned range check: `(x - lo) < (hi-lo)` → `addiu`+`sltiu` | | L47 | §3-I2 | Byte mask forces `andi` even after `lbu` | | L54 | §3-I3 | Division by a constant → magic multiply | | L60 | §3-I4 | Runtime (variable) division → `divu` + zero-check `break` (NEEDS `--expand-div`) | | L69 | §2 | Writing matching C (what makes gcc emit X) | | L71 | §3-T1 | Loop pointer: top-of-body for `addu` induction, not constant-folded `addiu` | | L78 | §3-T2 | Source statement order drives instruction scheduling | | L85 | §3-T3 | Types | | L90 | §3-T4 | Branch polarity: invert the source condition to flip gcc's chosen branch | | L107 | §3 | When a diff is pure scheduling → decomp-permuter (harness built, Phase 6) | | L128 | §3a | Escalation TIER above the permuter — web-research the compiler internals (HIGH VALUE, prov | | L147 | §3b | §31-directed permuter mutation — bias the search over the class's levers (Phase 24 T5) | | L190 | §4 | Flag/toolchain gotchas | | L199 | §5 | Known hard-residual classes (instruction-identical, one byte-exact blocker) | | L211 | §5a | Cross-jump tail-merge — gcc collapses two byte-identical blocks the original kept separate | | L265 | §6 | Per-module optimization mixing — the -O0 boot module (Phase 7) | | L273 | Detecting | the opt level (do this first) | | L307 | Build | mechanism — per-file opt override (splat resegmentation) | | L322 | §7 | PsyQ SDK types & symbols (the library-call prerequisite) | | L339 | §8 | rodata island (compiler jump tables) — the `.data→.rodata→.data` sandwich (Phase 7) | | L361 | §8a | rodata island in a flat OVERLAY — the tail sandwich, per matched jr-function (Phase 26 — P | | L399 | §8a-pad | a trailing `.word 0x00000000` under a jtbl dlabel is `.align` PAD, not an entry (Phase 26 | | L423 | §8b | MULTI-jtbl per overlay — the `ld_interleave --order` sandwich + the same-subseg cases (Pha | | L456 | §8c | Splitting a TU means rebuilding its DECLARATION ENVIRONMENT, not moving text (Phase 26 ses | | L502 | §8d | Templating a body INTO a TU must not CHANGE its declaration environment — demote the carri | | L549 | §8e | The jtbl ALIGNMENT LAW + the pad-spec filter — multi-table .rodata spans (Phase 29, byte-p | | L632 | §9 | Link real PsyQ library objects byte-exact (Phase 7 — GO proven) | | L661 | §9.1 | Generalised per-object linker — `tools/psyq_link.py` (+ `psyq_link_lib.py`), 18/18 libcd b | | L685 | §9.2 | Wire a library region into the build with NOLOAD — no data carving (`tools/psyq_link_regio | | L704 | §9.3 | Make it the build: resegment + swap + resolve (`tools/psyq_integrate.py`, libcd DONE) | | L731 | §9.4 | Integrating a SECOND library (libgs block 6 after libcd) — multi-library gotchas | | L759 | §9.5 | Integrating a WHOLE multi-block library in one call (full libgs — Phase 7 session G) | | L785 | §9.6 | Scaling library linking to the whole EXE (Phase 8 — 8 libs linked, 20%→50% byte-identical) | | L821 | §9.7 | Binary-agnostic toolchain refactor (Phase 9) — the reusable pattern for Gen2 | | L854 | §10 | Closing the regalloc/scheduling hard tail by hand (LZSS, Phase 7 session F — the full clos | | L863 | §3-The | clean object-level metric (use this, not the permuter score, for jtbl/rodata functions) | | L875 | Residual | A — commutative `|`/`&`/`+` result lands in the wrong source-operand register | | L886 | Residual | B — a `return ` materialised late / merged instead of distributed per-site | | L927 | §11 | Cross-binary dedup & code-sharing (Phase 11 — "one match unlocks many") | | L945 | §3-The | mechanism: game-code dedup is SOURCE-LEVEL, not an object swap (R-D1, the key lesson) | | L978 | Per-binary | toolchain provenance (R24) | | L983 | §12 | Ultracode harvest — parallel-draft + byte-gate at scale (Phase 12, resident: 1.4%→71.7% in | | L1075 | §13 | Add a location overlay — the canonical runbook (Phase 13; the Phase-15 fleet recipe) | | L1081 | One-command | onboarding — `tools/new_overlay.sh ` | | L1090 | §3-The | flat-blob overlay config (what the template encodes) | | L1098 | §3-THE | NON-4-ALIGNED-OVERLAY GOTCHA (≈75% of the fleet; fixed in the template + Makefile, automat | | L1110 | §3-The | A→B→C per-overlay workflow | | L1127 | Dedup-credit | (§11) for overlays — two shapes | | L1139 | Fleet | build — `make build-all` / `make check-all` | | L1145 | §14 | Propagate a matched function across the fleet — `tools/dedup_propagate.py` (Phase 15) | | L1188 | §14a | The fleet bulk run (Phase 15 — `--auto-from`, 947 REAL → 74,527; 3.82% → 22.14% in one pas | | L1211 | §14b | Harvesting the UNMATCHED shared core — the match_one wall (Phase 15) | | L1232 | §14c | Callee-signature-aware harvest — breaking the extern-type-conflict wall (Phase 15, T6) | | L1288 | §14d | Deterministic recovery beats agent waves on the hard tail (Phase 15, the final-session fin | | L1317 | §14e | Two hard-tail dead-ends (Phase 15 — documented so they aren't re-attempted) | | L1332 | §15 | Struct-heavy shared-core pipeline (Phase 16) — empirical determinations (S0) | | L1354 | §16 | Guided hand-matching the struct-heavy core (Phase 17 — beats the §15 brute-force) | | L1395 | §17 | The compiler-quirk wall — the matching TOOLKIT (Phase 18; gcc-2.7.2 source + byte-gated) | | L1403 | Register-allocation | ORDER (call-crossing $s0/$s1 swap) → FORCE it with register pins (byte-proven) | | L1423 | §3-The | STEERABLE idioms (byte-confirmed this phase) | | L1440 | §3-The | pipeline gotcha — match_one ≠ the gate; `sig_unify` is MANDATORY | | L1447 | §3-The | LOOSE-TYPING wall is real for narrow params (Phase 16, reconfirmed) | | L1454 | Strategic | conclusion — the match-% lever post-research | | L1464 | §17a | The TOOLKIT at WAVE scale (Phase-18 Step-3b/Step-1 — measured) + the pipeline-integration | | L1538 | §18 | Per-file `-O0` split inside an overlay/blob (Phase 19 T1) | | L1616 | §19 | Scaling the toolkit waves — the recovery PIPELINE + the propagation CAP (Phase 19 T3) | | L1651 | §20 | The wave-at-scale GATE CAP + residual-class verdicts (Phase 20) | | L1656 | §3-THE | CAP: at this tail the match_one→gate gap is the LOOSE-TYPING CALL-GRAPH wall (not cheap pl | | L1673 | Diagnostic | lesson: a failed in-TU build leaves a STALE `.o` | | L1679 | §3-NEW | / CONFIRMED residual classes (this session) | | L1700 | Operational | gotchas (cost real time) | | L1708 | What | WORKED — the Phase-20 reusable wins | | L1720 | Phase-20 | RESOLUTION — `tools/cast_call_sites.py` BUILT + the cap re-diagnosed (R14, byte-proven) | | L1771 | §21 | wave-distilled idioms (Phase 21) | | L2024 | §22 | DEF-side loose-typing recovery + grinder blacklist (Phase 21) | | L2051 | §23 | Giant `func_80153E00` cracked (scalar-data CAST); BUT most giant drafts are STALE+INCOMPLE | | L2104 | §24 | The `ov_SC01_077_a.c` split-file vein: split-aware propagation, but loose-typing-gated (Ph | | L2151 | §25 | The "schedule" class is mostly COALESCING (pin-crackable), not scheduling; + the gate two- | | L2163 | §3-The | crack: the residual was gcc-2.7.2 COPY-COALESCING, not the instruction scheduler | | L2179 | §3-The | genuine scheduler — `rank_for_schedule` (sched.c), for when it IS scheduling | | L2188 | §3-The | genuine schedule WALLS (do NOT re-grind — stub) | | L2196 | §3-h | _exact OVER-COUNTS ×134 — verify shareability before crediting a class's "reach-134" (R14) | | L2208 | §3-The | gate two-stage — sig_unify is a FALLBACK, not unconditional (`gate_stage.py`, §19 folded i | | L2218 | §26 | The cheap close=0 recovery lever is EXHAUSTED; `idiom_loop --assess` was DOUBLY inflated ( | | L2224 | §3-The | `_a` close=0 recovery banks 0/20 — same def-side wall as MAIN (0/40) | | L2252 | Where | this leaves the reach-134 tail (cont.6 option-3, now CONFIRMED byte-backed) | | L2278 | §27 | Giant matching recipe (Phase 21 cont.7b — validated on func_80176D94, 152 ins) | | L2344 | §28 | Banking a "close=0 gate-rejected" giant: the canonical-extern recovery (Phase 22 T1, byte- | | L2364 | §28a | decomp.wiki GCC patterns worth trying on BFM giants (decomp.wiki/compilers/GCC, raw at dec | | L2371 | §28c | The close=0 recovery is NOT fully exhausted (§26 corrected, R14); + the dedup_propagate re | | L2376 | §28b | The struct-walled close=0 giant (§28 case #3) IS bankable: the engine_types.h type-lift (P | | L2385 | §28d | The "macro-extern-injection" lever: freeing reach-134 inline matches dedup_propagate skips | | L2393 | §29 | Reasoning-model (GLM5.2) DEF-side reconciliation idioms + the wall's hard limit (Phase 23 | | L2401 | §30 | Fable5Max cracks §20/§10 "unsteerable" from the gcc SOURCE: store-vs-load is a `/s` aliasi | | L2413 | §30a | §30 generalizes to the FULL near-miss backlog (via STANDARD Opus agents, not just Fable5) | | L2421 | §31 | THE gcc-2.7.2 CODEGEN MAP: pass → residual → C-lever catalog (Phase 23; 4 Fable5 agents re | | L2441 | §32 | The region-a CAMERA-GIANT idiom set: struct-base hoisting + 4 sibling levers (Phase 24 T7, | | L2453 | §33 | Automating the giant decl-reconcile: `tools/reconcile_decls.py` (the DATA analog of §20's | | L2473 | §34 | The `func_80138ED0` giant crack: gcc-2.7.2's **3-qty sort bug** + the **zero-byte asm allo | | L2490 | §35 | The region-a sibling-giant harvest: difficulty ≠ $s-reg count (it's global-array hoisting) | | L2506 | §36 | Fable5 giant-crack levers (Phase 24 T7 Fable5 batch; accumulates as each lands — full RTL | | L2525 | §37 | The T7 §G giant endgame: 6/8 cracked, meta-laws + transferable levers (Phase 24, 2026-07-0 | | L2546 | §38 | The WHALE `func_80144B9C` (770 ins): the -O0 struct-assign memcpy idiom + the -O0 reach-13 | | L2556 | §39 | The ×1→×134 giant-endgame: propagate a matched **-O2** giant via the NATIVE DEFINE-macro p | | L2572 | §40 | Structural families: the MECHANICAL symbol-remap (crack one exemplar → remap the rest, ~0 | | L2620 | §40a | The DECL-RECONCILE pass (type-lift so remapped drafts compile in the sibling TU) (Phase 25 | | L2653 | §40b | The reloc-tracker blind spot: the indexed-global idiom that hid the "reach-1 tail" (Phase | | L2695 | §40c | The h_seq per-sibling reconcile: templating a reconcile-class crack ×134 (Phase 26 Task 8, | | L2712 | §31-triage | R17 applies to CODEGEN residuals, never to a compile ERROR (Phase 26 session 7, Drew asked | | L2729 | §41 | The DEF-SIDE canonical-sig wall: mechanically banking a drafted giant past `conflicting ty | | L2788 | §41a | v3.1: the def-side wall was ~71% TOOL-shaped — the five measured defects + the laws that d | | L2843 | §41b | T7 execution: the object-only probe OVER-counts BANKABLE by two link/rodata classes (Phase | | L2873 | §41c | T7-M2: the ×134 def-side-wall sweep via per-sibling RE-reconcile (Phase 25, 2026-07-10; 4, | | L2892 | §41b | addendum — M4 "reconcile_decls" tier is ALSO a probe over-count: 0/8 mechanical (Phase 25 | | L2912 | §41d | `void`→`s32` is NOT always byte-neutral: gate the RAW draft FIRST (Phase 26 session 6, byt | | L2934 | §42 | The F-band ≤28 regalloc crack wave: register-pin/DENSITY levers beat the permuter (Phase 2 | | L2987 | §42a | addendum — wave 2 (residuals + 29-100 band): iso-MATCH ≠ real-TU bank, the memcpy→struct-a | | L3028 | §42b | addendum — wave 3 (Max, 2026-07-10c): THE STALE-OBJECT GATE TRAP + the read-global `&`-cas | | L3067 | §42c | addendum — wave 3 (Max orchestrator + CORRECTED Ultracode fan-out, 2026-07-10c): the real- | | L3116 | §42d | addendum — wave 4 (rtu_match fan-out over the mapped frontier, 2026-07-10c): 24/26 MATCH, | | L3155 | §42e | propagating a CRACK ×134: the def-finder bug + the byte-drift residual (the "remap-fail" m | | L3229 | §43 | The K&R s16-param definition DISSOLVES the "narrow-param wall" for by-value register args | | L3276 | §44 | The Phase-25 cheap-Opus giant batch: 5 structural levers + the §43 extension (2026-07-11, | | L3332 | §45 | The flagship `func_80133CD4` crack (399 ins ×134): the merged-variable permutation-breaker | | L3347 | §46 | The `func_80178D40` crack (890 ins ×134, the heaviest core in the game): four LOOP-STRUCTU | | L3399 | §47 | The live-length SLIDER: splitting a global.c allocno-priority TIE with one zero-byte asm ( | | L3439 | §48 | The 12-core jr crack wave: the ALLOCNO-PRICING dials and the EBB rule (Phase 26 session 8, | | L3447 | §3-A. | ALLOCNO-PRICING DIALS — move a value into the register you want, byte-neutrally | | L3478 | §3-A4 | SINK THE CONSUMER CALL INTO THE ARMS (the inverse of A1; `func_8016AB6C`, byte-proven) | | L3502 | §3-B. | THE EBB RULE — the general form of §46-L2 | | L3518 | §3-C. | TYPE- AND SHAPE-DRIVEN CODEGEN (the C type literally selects the addressing mode) | | L3542 | §3-D. | THE CROSS-JUMP RATCHET (the sharpest new trap — `func_80131340` L-C) | | L3552 | §3-E. | Meta | | L3561 | §49 | The LUID DIAL: a zero-byte SCHEDULING dial (the sched.c analogue of §47) — `func_8017A4AC` | | L3610 | §50 | Refinements that BOUND §47/§48 (from the `func_80135EB0` wall, 21→6; Phase 26 session 8) | | L3664 | §51 | TOOLING INTEGRITY: the silent skip, and how to hunt it | | L3670 | §51a | The bug class | | L3686 | §51b | Why the byte-gate cannot save you | | L3696 | §51c | THE METHOD (do not audit by reading the regex) | | L3711 | §51d | THE LAWS | | L3773 | §51e | The false-wall pipeline (why this is not just hygiene) | | L3789 | §51f | Checklist for any new corpus-scanning tool | | L3803 | §51g | When the thing you are scanning has a GRAMMAR, parse the grammar (`tools/cdecl.py`) | | L3947 | §52 | The WALKER-FAMILY skeleton: 6 regalloc-order levers + a deeply-characterized intrinsic wal | | L3958 | §3-The | 6 levers (the "walker-family skeleton" — apply to the 12 siblings; levers 1-5 retire ~half | | L3979 | §3-Why | the wall is (probably) intrinsic | | L3993 | §52a | The regalloc sibling wave: new levers + two new wall classes (cheap-Opus applying §52, 202 | | L4031 | §52b | Sibling wave 2: more de-pin levers, a third wall class, and the match_one→whole-binary gap | | L4062 | §53 | SWEEP A FAMILY WITH THE TOOL ITS EXEMPLAR NEEDED: the jr/switch carve, and how omitting it | | L4067 | §3-The | case | | L4079 | §3-Why | 0/8 was structural, and predictable from two words | | L4096 | §3-The | rule | | L4112 | §3-The | meta-lesson (R35, and why this one is expensive) | | L4127 | §55 | Core-crack wave levers + the GATE-ORCHESTRATION law (Phase 29 T3, 13-agent ultracode wave, | | L4132 | §55a | New byte-proven levers (each from a banked or near draft) | | L4156 | §55b | THE GATE-ORCHESTRATION LAW (3 traps, ~3.5h lost; all recovered, 0 data lost) | | L4175 | §55c | Sizing the propagate: a TARGETED propagate is ~4 min/core, and "it's slow" was a BROKEN-TR | | L4197 | §54 | `--fix-def-sig`: the member's CANONICAL DECLARATION is a build step too (tiny-IMM mega-poo | | L4221 | §56 | Banking a hand-drafted GIANT into its exemplar TU: self-contained draft vs live-TU decls, | | L4266 | §56b | PROPAGATING an h_seq giant: the exemplar's externs MUST be fleet-canonical, not the draft' | | L4290 | §57 | The SELF-decl normalize: the sibling's OWN caller declares the templated fn divergently (t | | L4337 | §57a | Two NSD corrections + the SURGICAL-ONLY law + the honest broad-sweep yield (Phase 29, 2026 | | L4377 | §58 | match_one MATCH ≠ BANK: the four blind spots + the crack-wave reconcile-before-bank law (P | | L4411 | §59 | Three h_seq sweep-residual classes match_one/the-exemplar-bank don't reveal (Phase 29 crac | | L4441 | §60 | Classify the residual, don't rank it: the deterministic residual→class classifier and what | | L4465 | What | it measured — the whole open backlog, byte-grounded | | L4484 | §3-Two | corollaries worth remembering | | L4497 | §3-The | parallel-probe race this surfaced | | L4506 | §60a | What the first DIRECTED grinder run exposed (Phase 29 Task-13B, 2026-07-21) | | L4544 | §60b | The plateau autopsy's verdict: a `partial` drift is a WRONG DRAFT, not a missing transform | | L4579 | §61 | Task 14: the gate ladder's missing stage is the ARITY pre-pass, and it is TU-side not draf | | L4640 | §61a | The Task-5 wave: 11/12 MATCH, 0 banked — three DISTINCT integration walls, each now named | | L4692 | §61b | The jtbl gate stage: built, and the ORDERING law it exposed (Phase 29 Task-14 stage 4, 202 | | L4747 | §61c | The jtbl bank is INCREMENTALLY valid and CLEAN-INVALID (Phase 29, 2026-07-21) — the blocki | | L4813 | §61d | The undo was eating the tree: two tools, one defect, invisible to the byte-gate (Phase 29, | | L4867 | §62 | The jtbl RECONCILE must also follow the carve: the post-carve draft reconcile (`harvest_ve | | L4911 | §63 | The fresh-138 DEF-SIDE blocker: fix the HEADER decl, not the draft (`fix_header_decl.py`, | | L4942 | §64 | The §20 type-lift's three laws: fold the tagged typedef, check VISIBILITY, and strip only | | L4991 | §64a | VARIANT types: UNIQUIFY the camps, do not reconcile them (`uniquify_type.py`, Phase 29 SES | | L5034 | §63 | UPDATE (Phase 29 SESSION-14) — `fix_header_decl`'s "SAFE" verdict is FLEET-BLIND; it MUST | | L5049 | §65 | The stranded-draft recovery: BLAST-RADIUS TIERS, and the per-overlay de-macroize that refu | | L5064 | §65a | The blast-radius taxonomy (makes §61's law structural instead of remembered) | | L5079 | §65b | The escape: de-macroize the instantiation, don't touch the shared header | | L5115 | §65c | `rtu_match` MATCH → bank held 13/13 on self-decl, but broke on the FIRST callee-decl case | | L5125 | §65d | Existing-ladder baseline, measured (do this before building a recovery stage) | | L5135 | §65e | Two oracles, and the disagreement is the finding (R34 in practice) | | L5152 | §65f | The de-macroize lever's BOUNDARY, measured: byte-neutral 14 times of 15, and the 15th is w | | L5173 | §65g | Where the cheap levers STOP: the local-type and in-TU-self-decl classes did not yield | | L5193 | §66 | Exercise a banking driver's SUCCESS path before pointing it at a wave: the free re-bank te | | L5215 | §66a | The widest write in a pipeline is the one most likely to be UNDECLARED | | L5234 | §66b | A metric parsed out of another tool's prose goes NULL silently when the label changes | | L5251 | §66c | Before a wave, verify the FUEL exists; an "already attempted" set built from the wrong dir | | L5279 | §66d | The permuter⇄reader loop: alternate a random search with a byte-verified idiom, and let `r | | L5314 | §66d-1 | What transfers between giants is the LOOP, not the PIN | | L5323 | §66d-2 | Two operational sharp edges | | L5334 | §66d-3 | Read the ILS per-cycle SERIES, not its final best: a repeated score and a still-falling on | | L5349 | §67 | The arg-copy PLACEMENT lever: launder a parameter into a fresh pseudo AT the statement whe | | L5439 | §67a | Run the symbol-set guard BEFORE you pay for a gate (`tools/symcheck.py`, Phase 29 SESSION- | | L5472 | §66d-4 | "ILS converged" means converged FOR THAT WEIGHT PROFILE, not a floor (amends §66d-3; Phase | | L5525 | §66d-5 | `residual_class`'s "structural ⇒ permuter CPU is waste" is WRONG for schedule permutations | | L5558 | §68 | A comment-only line halted the extern scan, and the skip label blamed the type cap (Phase | | L5603 | §69 | How to attack a behemoth: map it, don't draft it (Phase 29 SESSION-18, `func_80183814`, 5, | | L5653 | §70 | The giv-init base register: walk the PARAMETER, not a copy of it (Phase 29 SESSION-18, `fu | | L5694 | §71 | Before mapping a giant, look for an already-matched SIBLING beside it (Phase 29 SESSION-18 | | L5760 | §72 | A `register __asm__` pin is a PREFERENCE, not a reservation (Phase 29 SESSION-18, `func_80 | | L5784 | §3-The | honest fix was source-level and cheap | | L5794 | §3-Giv | record order (the §70 family) | | L5800 | What | is left, and what is byte-recorded as SPENT | | L5817 | §73 | A def-side self-decl conflict has TWO axes: RETURN (fleet widen, T2) and PARAMS (casts at | | L5856 | §74 | Auditing a pinned draft: the §72 hazard is CALLER-SAVED pins spanning a call, and only the | | L5900 | §75 | A propagation cap is usually a MINORITY-SPELLING SOURCE OVERLAY, not a wall: census the ca | | L5959 | §75a | The exclusion classes, enumerated with named causes (Phase 29 SESSION-19, the 134-binary ` | | L5982 | §75b | A body's preamble can carry `#define`s, not just `extern`s; extraction lifts only the exte | | L6031 | §75c | Class-B's remedy is the FULL §17a-1 PAIR (decl **and** call-site cast); a decl-only fix mo | | L6062 | §76 | The allocno CLASS (local vs global) is the dominant regalloc lever, and C reaches it ONLY | | L6071 | §3-The | mechanism, with citations | | L6091 | §3-The | attribution primitive (use this before calling anything a scheduling residual) | | L6098 | §3-Two | diagnosis traps this function proved | | L6108 | Practice | Practice | | L6118 | §77 | Every extraction tool carries a NARROW hard-coded preamble set; anything outside it silent | | L6158 | §3-The | CANDIDATE gate and the REAL gate need DIFFERENT preambles — keep the difference out of the | | L6208 | §78 | A LENGTH drift can be a register grant in disguise; and `fold` never leaves a literal firs | | L6214 | §3-The | drift was an allocation decision, not missing code | | L6245 | §3-The | economics | | L6254 | §79 | For a 0-callee giant, fingerprint by DATA symbols (§71 cannot fire); and the STACK-SLOT OR | | L6260 | §71 | has a blind spot, and this is it | | L6274 | §3-NEW | LEVER — the frame layout reads back the original declaration order | | L6285 | §76 | confirmed at scale, and a pin nuance | | L6294 | §3-The | residual, and the honest read | | L6304 | §80 | A do-not-re-buy entry is scoped to its BASE, not to the function; and the pin's hidden cos | | L6325 | §3-The | pin's hidden cost, with the citation | | L6336 | §3-The | flagged "#1 move" LOST — and why the failure is informative | | L6346 | §78 | 's attribution primitive, run and reproduced | | L6352 | Cold-start | economics, now complete | | L6357 | §81 | Banking a jr (jump-table) function: the 3-step carve chain, and why `match_one` cannot see | | L6388 | §3-The | defect this exposed: a shared type that is present but invisible | | L6404 | §82 | Two source-shape oracles from behemoth #6: a duplicated `addiu $aN,$sp,K` across a `jal` m | | L6409 | §3-1. | The inlined-helper signature | | L6423 | §3-2. | Scalar vs aggregate decides *when* the slot is allocated | | L6435 | Also | reproduced on this function | | L6439 | §3-And | the banking footnote (§75a class A, one line) | | L6446 | §83 | The parameterised-repeat law, the spill-area trap, and why a per-case edit cannot move a p | | L6453 | §83a | READ THE HEADLINE NUMBER CORRECTLY: a LENGTH drift makes `match_one`'s count meaningless | | L6461 | §83b | THE LEVER: find the parameterised REPEAT before decoding case-by-case | | L6479 | §83c | TRAP: a "dead local" in a prior draft may be gcc's OWN spill area | | L6486 | §83d | CSE's quantity budget is WHOLE-FUNCTION, so a local rewrite cannot fix a local symptom | | L6500 | §83e | §80 vindicated again, on the same day it was written | | L6506 | §84 | The DERIVED-OFFSET remap bug: a hand-computed literal that encodes the DISTANCE between tw | | L6511 | §3-The | construct | | L6529 | §3-Why | it survived every candidate gate | | L6544 | §3-THE | FIX IS MECHANICAL — the tool already holds the answer | | L6552 | Scope | , measured (do not over-generalise — §80) | | L6562 | §3-Two | ladder lessons banked with it | | L6573 | §85 | The RETURN-axis fleet widen is ALL-OR-NOTHING: widening the shared header alone guarantees | | L6578 | §3-The | conflict | | L6586 | §3-THE | FAILURE MODE — widening only `engine_core.h` is worse than not starting | | L6593 | §3-The | precondition, and how to check it in one grep | | L6601 | §3-Do | the WHOLE axis in one edit, then R22 once | | L6610 | Reading | , for the next person | | L6623 | §86 | Pinned-exemplar templatability is a PER-FAMILY property, not a per-member rate; and the §4 | | L6625 | §3-The | guard refuses a class that largely works | | L6634 | §3-THE | LAW: all-or-nothing PER FAMILY | | L6661 | §3-Why | the two live families differ from the three dead ones — the open question | | L6667 | §87 | `match_one` COMPILES but never LINKS, so an unresolvable data symbol reads as MATCH; and s | | L6683 | §3-The | blindness ladder, now complete — FOUR classes `match_one` cannot see | | L6693 | Consequence | for the backlog ledger | | L6700 | §3-The | cheap discriminator, before spending a sweep | | L6708 | §88 | `cross_jump` will not merge a common suffix containing a CALL; and §78 is scoped to ORDERE | | L6713 | §88a | repeated CALL-shaped blocks are left UNMERGED; call-free tails are merged for you | | L6720 | §88b | the `slti` literal-position law (extends §78 to comparisons) | | L6735 | §88d | BANKING ORDER: run the §81 carve chain BEFORE banking, never after | | L6742 | §88e | a wrong diagnosis, refuted properly (the model for how to treat an inherited lever) | | L6752 | §88f | the missing rung: a RELOCATION gate between `match_one` and the binary | | L6760 | §89 | Two throughput rules the project already had written down and was not following (Phase 29 | | L6766 | §89a | MEASURE the write set; do not assert its tier (`tools/blast_radius.py`) | | L6779 | §89b | the parallel gate farm existed; the family path could not reach it (`tools/sweep_parallel. | | L6792 | §3-The | standing sequence | | L6800 | §90 | Five tool-integrity laws from one session, each of which changed an answer (Phase 29 SESSI | | L6806 | §90a | A comparison tool MUST share its reference oracle's index space, exactly | | L6823 | §90b | "Byte-neutral" is not "wanted": undo on the SUCCESS path too | | L6833 | §90c | A library-callable function must FAIL CLOSED on an unconfigured module | | L6844 | §90d | Do not measure a live wave's drafts (§87 in real time) | | L6852 | §90e | An agent's CONCLUSION and its EVIDENCE fail independently — re-derive the premise, not the | | L6876 | §91 | A structure-TRANSFER is only valid where the structure corresponds: the `--like` role trap | | L6905 | §3-The | three-hypothesis trail, because two of them were wrong and the wrongness is instructive | | L6925 | §92 | Conforming a DECLARATION: pointer changes are caller-neutral, scalar-WIDTH changes are not | | L6956 | §93 | `set -o pipefail` attributes a pipeline failure to the LAST stage, not the failing one (Ph | | L6981 | §94 | A family sweep's `0/N` is a TYPE-CARRY failure until proven otherwise: lift the exemplar's | | L7017 | §95 | `reconcile_tu` dropped the SIBLING declarators of a multi-symbol `extern` line (Phase 29 S | | L7052 | §96 | The same rewrite, one shape down: `reconcile_tu` matched statements to lines by TEXT, so e | | L7100 | §97 | The gate's own tree hygiene: a refused carve, an unchecked recovery, and a snapshot that c | | L7147 | §98 | `conform_decls` had three defects, and only the third needed R22 to find (Phase 29 SESSION | | L7201 | §99 | The narrow-param wall is a DEF-side problem with a ZERO-blast-radius fix: convert the defi | | L7224 | §3-Two | `reconcile_tu` bugs found underneath, one introduced while fixing the other | | L7250 | §100 | Prefer the DRAFT-LOCAL fix: a type only one function uses belongs in its BODY, not in a sh | | L7279 | §101 | The STALE DEFAULT class: a guard whose cause was removed is a silent skip wearing a safety | | L7306 | §102 | A PLUMBING verdict can MASK a DIFF; and K&R is not always a codegen change (Phase 29 SESSI | | L7341 | §103 | A FILE-scope `extern` in a shared overlay TU is a GLOBAL constraint on every LATER functio | | L7429 | §104 | Two silent-skip defects in one scan: match on MASKED text, emit from the ORIGINAL (Phase 2 | | L7465 | §105 | A gate's revert must survive an EXCEPTION, not just a failure (Phase 29 T53, `jtbl_family_ | | L7504 | §106 | Persist the MEASUREMENT, derive the POLICY: a stored route let a stale file out-vote the l | | L7547 | §107 | A lever wired into ONE gate path is a lever most families cannot reach (Phase 29 T56, `fun | | L7585 | §108 | Diagnosing a family `0/N`: the four causes, and the third opt-in lever (Phase 29 T59) | | L7634 | §109 | Conforming a definition to a shared header: fix the NAMES, then check the RETURN precondit | | L7674 | §110 | A unit must define exactly ONE function, and "ends in `;`" does not tell you which line de | | L7715 | §111 | The distinct-code metric is not noisy: a family pays it only if its members are byte-VARIA | | L7764 | §112 | A macro-scoped declaration only collides where the macro is INSTANTIATED (Phase 29 T67/T69 | | L7810 | §113 | An ARITY blocker only exists if the macro CALLS the function; an address-taken use has no | | L7842 | §114 | The THIRD decl axis: a CALLEE the draft declares differently from the target TU (Phase 29 | | L7884 | §115 | A `func_XXXXXXXX` predicate rots by design: the same name-form assumption in THREE places | | L7911 | §116 | Optimization level is a property of the FILE, not the function: read a family 0/N against | | L7929 | §3-The | fix moves the DEFINITION, not the stub — and here is why the obvious shortcut fails | | L7960 | §117 | Spell the sibling's symbol from the SIBLING's address, not the exemplar's kind (Phase 29 T | | L7987 | §3-Why | it survived so long: a MASKED oracle will MATCH a wrong symbol | | L7997 | §118 | Ordinal (positional) immediate resolution: compare C tokens to the DIFFERING asm uses (Pha | | L8031 | §119 | Two levers on the SAME axis, opposite directions: test the off-diagonal (Phase 29 T89) | | L8060 | §120 | Uniquify draft-defined TYPE names; and check which of N staging sites you actually patched | | L8071 | §3-Do | NOT "strip the duplicate typedef" — it breaks the extern that uses it | | L8077 | §3-The | wiring trap that cost two attempts | | L8095 | §121 | Synthesise externs for macro-DEFINED callees from the macro's own definition head (Phase 2 | | L8118 | §122 | GATE RAW BEFORE TRANSFORMING; the undo belongs to the WRITER, as a per-edit journal (P30 T | | L8150 | §123 | PROPAGATE A FAMILY WITH THE TOOL ITS TIER NEEDS: `dedup_propagate` is h_exact-only; its re | | L8187 | §124 | A "not matched" verdict can mean the definition is there under a DIFFERENT C NAME: the asm | | L8232 | §124a | a family sweep's `0 matched-exemplar families` may be a FILTER, not a wall | | L8240 | §125 | Split the CARVE from the BODY before calling a jr residue a wall — and measure it by SHA f | | L8247 | §3-The | method (keep this) | | L8257 | §3-The | instrument rules that make its answer trustworthy (this is where I failed) | | L8272 | §3-The | corrected results (each SHA-verified, from a clean tree, restore re-verified) | | L8282 | §3-Two | further notes worth keeping | | L8291 | §3-The | meta-lesson | | L8298 | §126 | The carve-within-a-carve: an ADDRESS RANGE is not an OPTIMIZATION REGION (P30 T2, byte-pro | | L8313 | §3-The | finding: opt level is per FILE, so the file's contents must be opt-HOMOGENEOUS | | L8324 | §3-The | instrument trap that hid it (and it is §124's shape again) | | L8333 | §3-The | mechanics | | L8351 | §126a | a bare `except: continue` around a coverage-asserting oracle re-creates the silent skip (P | | L8383 | §127 | The `-O0` regime: the CONSTANT-OFFSET FOLD, and why `-O0` needs its own idiom set (P30 T3 | | L8390 | §3-The | idiom they kept re-deriving: the constant-offset fold | | L8401 | §3-The | rest of the `-O0` regime (write PLAIN C, and mean it) | | L8411 | §127a | §71 (sibling-first) is the strongest `-O0` lever, and it beats the index | | L8420 | §127b | the knowledge was in a SOURCE COMMENT, not the cookbook | | L8427 | §128 | A raw NUL in C source makes grep SILENTLY SKIP the file (P30 S28, 137 files) | | L8459 | §128a | a negative control must corrupt a SCRATCH COPY, never the tracked file | | L8471 | §129 | Post-carve, `rtu_match`/`match_one` COUNT THE JUMP TABLE AS INSTRUCTIONS; and a carve must | | L8475 | §129a | the target instruction count is INFLATED after a carve | | L8496 | §129b | never commit a carve whose owner is still a stub (it strands the carve) | | L8511 | §3-The | real blocker underneath, for the record | | L8520 | §130 | An INCREMENTAL build can report BYTE-IDENTICAL for a change the CLEAN build cannot even LI | | L8557 | §3-The | diagnostic ladder that finally located it (reusable) | | L8567 | §131 | The jtbl OVER-SPAN: `sltiu N` is ground truth in BOTH directions, and the zero-word rule o | | L8604 | §132 | The `JR-PAIR-IN-ONE-O0-OBJECT` "wall" was TWO instrument defects: a merged-double span the | | L8613 | Defect | 1 — a pre-§8e MERGED DOUBLE is not a single-table predecessor | | L8631 | Defect | 2 — `as` writes a corpse and nothing deletes it | | L8641 | §3-The | fingerprint, and the 30-second ladder that found it | | L8662 | §3-The | transferable rule | | L8669 | §132a | `--like` is for a sibling with NO record; against one that HAS a record it over-derives (P | | L8694 | §132b | When the span's already-matched owner is ITSELF multi-switch: `--span-rel` (P30 S1, `func_ | | L8719 | §133 | The DEFAULT-FILTER class: three times in one session, a tool silently answered a narrower | | L8745 | §134 | MULTI-LINE BLINDNESS: one root cause, four faces, in `family_remap`'s preamble scanner (P3 | | L8799 | §135 | Six byte-verified gcc-2.7.2 idioms from the P30 S6f-h waves (and the two-lane wave shape t | | L8804 | §3-The | codegen idioms | | L8838 | §3-The | integration idioms (these decide whether a byte-correct draft BANKS) | | L8853 | §3-The | wave shape that produced these | | L8871 | §136 | The LOCAL-VARIABLE lever: how many C locals, at what scope (P30 wave 4a, 25 byte-verified | | L8887 | §3-The | splitting/merging rules (each closed a residual, byte-gated) | | L8913 | §3-The | type-form rules | | L8946 | §3-The | scheduling rules (refining §135-2 and §135-4) | | L8975 | §3-The | declaration surface (integration, not codegen) | | L8987 | Wave | economics (measured, for the next batch's sizing) | | L9010 | §136a | Blocker capture: classify on the OUTPUT, never on the exit status | | L9067 | §136b | A prior wave's "genuine byte-DIFF" verdict is NOT reliable evidence (4 of 4 refuted) | | L9103 | §136c | SIBLING-FIRST is a DERIVATION shortcut, not just a conflict fix (the fastest route in a fa | | L9128 | §136d | Four gcc-2.7.2 levers the redraft lane found (each closed a residual no other lever moved) | | L9172 | §136e | §136c's PRECONDITION, and two more symptom keys (wave 4b batch 3) | | L9220 | §136f | Two declaration sub-cases the reconcile lane surfaced (lane now 15/15 lifetime) | | L9245 | §136g | When the index points at the WRONG lever: two byte-refuted routings (func_801863B4) | | L9274 | §136h | CORRECTION: the zero-crack pool does NOT "refill with cheap work" (my error, byte-measured | | L9304 | §136i | The drafter model LADDER: Haiku → **Sonnet** → Opus → Fable5 (Drew, 2026-08-03) | | L9336 | §136j | The failure MIX flips with function size (measured across four bands, one session) | | L9378 | §137 | REGALLOC-PERM is a TWO-COMPILE ARITHMETIC PROBLEM, not a permuter job | | L9420 | §137a | A gate verdict has a TIMESTAMP; re-check it against the draft's mtime | | L9449 | §138 | The propagation lanes: a gate refusal is a DECLARATION, and which lever you owe depends on | | L9455 | §3-The | triage, cheapest first | | L9507 | §3-The | DEFINITION-side alias is the only escape when the fleet canon disagrees on a promoting par | | L9515 | Rank | the lane by measured concentration, not by class count | | L9524 | THREE | carry variants hide in one "CARRY-FIXABLE" bucket — and they need different fixes | | L9560 | §134 | again, in a second tool — and the waiter rule corrected | | L9580 | STEP | 0 of sibling-first: grep `src/` for a distinctive LITERAL from the `.s` | | L9599 | Reconciling | a gate-refused draft: which way you edit depends on WHERE the TU's decl is | | L9628 | §139 | A GATE THAT GREPS FOR VERDICTS MUST ASSERT 1:1 ACCOUNTING; and a `--src` filter must not s | | L9660 | §3-The | generalisation — three corollaries worth more than the bug | | L9677 | §3-And | the inverse-lookup trap, same session | | L9694 | §140 | A METRIC IS NOT A MEASUREMENT UNTIL IT IS REPRODUCIBLE FROM THE COMMITTED TREE (P30 S1e: a | | L9714 | §3-The | three-line proof (do this before diagnosing any metric movement) | | L9723 | §3-The | two instrument defects it exposed | | L9743 | §3-The | same swallow, twice more, in the integration spine | | L9754 | §3-Two | wrong mechanisms I chased first, and why they were wrong | | L9774 | §141 | The §134 class is CLOSED: every line-shape decision now routes through `cdecl._mask` (P30 | | L9812 | §142 | An open stub whose `h_exact` class is MATCHED elsewhere is FREE. Propagate the body; do no | | L9824 | §3-The | measurement (do this before any wave; it is ~20 lines and needs no builds) | | L9839 | §3-The | trap that hid it — SAME FUNCTION, TWO ROUTES, ONLY ONE IS FREE | | L9848 | Route | selection (why `--addr` sometimes says "nothing changed") | | L9856 | §3-And | the report-vs-bytes lesson attached to it | | L9868 | §143 | `cast_call_sites` read a RETURN STATEMENT as a prototype and deleted it. A 0/39 sweep beca | | L9922 | §144 | THE LITERAL'S SPELLING PICKS THE IMMEDIATE ENCODING (P30 S40 wave 1, `func_801822E0`) | | L9961 | §145 | Three loop/combine levers from the S40 wave-2 drafters (16/16 match_one) | | L10011 | §146 | RE-MEASURE A WALL BEFORE YOU RESPECT IT. Both "permanent" giants fell to drafts already on | | L10022 | §3-Why | a correct draft can read as an intrinsic wall | | L10034 | Then | propagation returned 0/137 TWICE — both times a missing TYPE | | L10043 | §3-Two | errors of mine, both instructive | | L10057 | §3-The | rule | | L10070 | §147 | The three-stratum FRAME LAW, and four "stop searching" verdicts (P30 S42, `func_8017C294`, | | L10075 | §3-A. | The frame has THREE strata, and stratum 3 is unreachable from C | | L10091 | §3-B. | A `?:` on MEMORY operands costs ~16 bytes of invisible frame; on REGISTER operands, zero | | L10102 | §3-C. | Inner-block declaration does NOT delay slot allocation — BYTE-REFUTED | | L10107 | §3-D. | A lone `$t8`/`$t9` in the target is RELOAD SCRATCH — reproduce the spill, don't pin the re | | L10117 | §3-E. | A `qty_compare` TIE is not spelling-reachable — recognise it and stop | | L10129 | Consequence | for the family (a real scheduling decision) | | L10179 | §148 | The loop.c hoisting THRESHOLD is arithmetic you can compute, and the `?:` clamp that folds | | L10185 | §3-A. | `move_movables` hoists iff `threshold × savings × lifetime ≥ insn_count` — and you can rea | | L10204 | §3-B. | `(v < 0x40) ? v : 0x3F` is folded to `MIN_EXPR` and expands to the WRONG SHAPE | | L10218 | §3-C. | A zero-byte ALLOCNO-PRIORITY slider | | L10228 | §3-D. | Reproduce the original's BUGS verbatim | | L10277 | §149 | Four instrument defects in one session, and the two questions they were hiding (P30 S43) | | L10283 | §3-A. | A prep step that returns its input on failure is indistinguishable from a search that foun | | L10301 | §3-B. | Same address + same name ≠ same body — and the ledger keys on address | | L10317 | §3-C. | `make: *** [...] Error N` is a summary, never a diagnosis | | L10327 | §3-D. | "Cheap fuel" that was never probed: 0 of 31 templatable | | L10346 | §150 | A register ROTATION across symmetric blocks is VARIABLE-IDENTITY evidence, not an allocato | | L10353 | §3-The | fix | | L10363 | §3-The | method that found it (this is the transferable part) | | L10379 | §3-Two | corrections to the record | | L10390 | Diagnostic | order (adopt this) | | L10401 | §151 | THE GHOST WEDGE: when a load-before-store transposition is unreachable by ANY statement or | | L10406 | §3-The | mechanism (read from cc1's own `-dR` trace, not inferred) | | L10421 | §3-The | lever — a zero-emission insn that absorbs the blocked tick | | L10429 | §3-The | two fallouts, and how to close them (both measured, in order) | | L10441 | When | to reach for it | | L10452 | §152 | BYTE SIZE is the family key that name- and h_seq-grouping both miss (P30 S43, the 0xECC fa | | L10457 | §3-The | finding | | L10466 | §3-The | key | | L10477 | §3-Two | cautions that must travel with this technique | | L10488 | §3-The | companion defect (open) | | L10500 | §153 | THE ADDRESS-REMATERIALISATION LAUNDER: a third zero-emission asm lever (P30 S43, `func_801 | | L10508 | Symptom | Symptom | | L10513 | Mechanism | (gcc source + RTL dumps, not inferred) | | L10520 | What | does NOT work (14 byte-measured probes) | | L10526 | §3-The | cure — a fresh launder per site, each in its own block | | L10536 | Companion | levers from the same function | | L10556 | §154 | Reading a disc payload: the module-id word, static base derivation, and "type 1 = uncompre | | L10561 | §3-A. | Payload word0 is a global MODULE ID; code starts after the header | | L10570 | §3-B. | Two static base-derivation methods that must AGREE (use both) | | L10582 | §3-C. | PAC type 1 = the same payload class as type 4, just NOT compressed | | L10592 | §155 | hi/lo literal scanning MUST track base registers (S45) | | L10601 | §155a | the same failure class, one level up: SHAPE-blind table scanning (S45 p5) | | L10621 | §155b | check the TYPE your oracle returns before comparing against it (S45 p5) | | L10644 | §155c | the ZERO-REFERENCE trap: gcc splits a global-array address across the `lui` and the LOAD ( | | L10674 | §156 | an ORPHANED reconcile poisons the fleet: `dedup_propagate`'s kept edit (S45 p6/p7) | | L10721 | §157 | the cheap-tier size cliff, measured (S45 p6) | | L10746 | §158 | The RANGE-EXTENDER: a fourth zero-emission asm lever completes the allocno toolkit (P30 S4 | | L10755 | Symptom | Symptom | | L10761 | §3-Why | the fork is chained (gcc source, validated insn-by-insn against -dS/-dR dumps) | | L10774 | §3-The | method (dump-arithmetic first, then place — no probing) | | L10791 | Bonus | facts worth keeping | | L10806 | §156 | THE PREFERENCE-DONOR MERGE: cross-region variable reuse is what fills a0-a3, and a call-ar | | L10862 | §159 | THE DECLARATION AXIS: conform to byte-truth, and make every guard state its COVERAGE (P30 | | L10927 | §160 | THE REACH-15 WAVE HARVEST: an align-1 block move, and the instrument that called it a wall | | L11003 | §161 | THE RETRY-WAVE HARVEST: a jump table indexed from zero, and two allocator traps (P30 S47) | | L11048 | §162 | S48 WAVE-1 HARVEST (P30, 2026-08-11): the reach-ordered sibling campaign's first 12 target | | L11075 | §162a | SHARPENS *(sharpens §161a, §131, §8a-pad, §129a)* | | L11104 | §162b | SHARPENS *(sharpens §48-A3, §156, §150, §76)* | | L11133 | §162d | SHARPENS *(sharpens §31, §21, §30, §55a)* | | L11175 | §162e | NEW | | L11177 | §162 | THE LICM PAIR: what makes an address a movable AT ALL, and why the preheader order is the | | L11243 | §162f | SHARPENS *(sharpens §42d, §41d, §73, §10)* | | L11298 | §162g | NEW | | L11300 | §162 | CROSS-JUMP DIRECTION: the surviving copy is always the LATER one, so a BACKWARD `j` into a | | L11334 | §162h | SHARPENS *(sharpens §88, §88a, §50-B, §8)* | | L11336 | §162 | The cross-jump "CALL veto" is a COUNT law, not a CALL law (BOUNDS §88a; P30 S48, `func_801 | | L11402 | §162i | SHARPENS *(sharpens §135, §21, §42, §32)* | | L11427 | §162j | SHARPENS *(sharpens §25, §136d-1, §48-B, §46-L2)* | | L11456 | §162k | SHARPENS *(sharpens §1-I2, §12, §160d, §21)* | | L11519 | §162l | SHARPENS *(sharpens §48-B, §48-C1, §20, §21)* | | L11574 | §162m | SHARPENS *(sharpens §36, §158, §148, §153)* | | L11576 | §158a | THE FIFTH LEVER IS NOT AN ASM: `do { } while (0)` is a REGION ref-multiplier you MINT (P30 | | L11583 | §3-The | law | | L11594 | Size | it before you write it (§158 step 1-2, applied) | | L11615 | §3-The | wrap BOUNDARY is the dial — and it is indiscriminate | | L11621 | §3-Not | a pure dial | | L11625 | DIAGNOSTIC | TELL — two faces, one law | | L11647 | §162n | NEW | | L11680 | §162o | SHARPENS *(sharpens §158, §136-1, §136-6, §79)* | | L11739 | §162p | SHARPENS *(sharpens §48-B, §46-L2, §156, §136d-1)* | | L11756 | §162q | SHARPENS *(sharpens §30, §30a, §135-2, §136-13)* | | L11794 | §163 | S48 WAVES 2-3 HARVEST (P30, 2026-08-11/12): the five that were byte-probed and are actiona | | L11862 | §163z | THE UNVETTED REMAINDER (do not cite as law; each needs a dedupe pass) | | L11882 | §164 | S48 §163z SKEPTIC PASS (P30, 2026-08-12): 190 claims vetted, 82 banked | | L12334 | §16Xy | SHARPENS *(sharpens §136d-3, §37 /s-DEP LATTICE, §135-2, §136-13, §162q)* | | L12336 | §3-The | `/s` drop clause is in ALL THREE dependence predicates, so the FIXED-ADDRESS STORE is what | | L13670 | §164z | REFUTED CLAIMS: do NOT re-derive these | | L13736 | §165 | S48 WAVE-4 HARVEST (P30, 2026-08-12): banked the same day the wave landed | | L14394 | §16Z | SHARPENS *(sharpens §37 "the /s-DEP LATTICE", §136-13, §136-14, §16Xy, §162q, `gcc-2.7.2- | | L14396 | §3-The | ADDRESS-CLASS TABLE: which load/store pairs even REACH the `/s` clause (P30 S48 wave 4, `f | | L14912 | §165z | REFUTED THIS WAVE: do NOT re-derive | | L14956 | §166 | THE DESTINATION-TU ORACLE (P30 S48): the seven-attempt bug that was never codegen | | L15012 | §167 | S48 WAVE-5/6 HARVEST (P30, 2026-08-12): the saturation point | | L16208 | §167z | REFUTED IN WAVES 5/6: do NOT re-derive | | L16265 | §168 | THE COUSIN TIER (P30 S49, 2026-08-12): h_seq's exact-hash brittleness, measured — and the | | L16317 | §169 | THE MICRO-ADAPT LANE (P30 S49): edit a proven body, don't crack a new one | | L16364 | §170 | THE A-PROP WORD-DIFF CARD (P30 S49): the lane that had no owner | | L16408 | §171 | THE STALE SEED SYMBOL (P30 S50, 2026-08-13): why §170's 91%→57% was never codegen | | L16474 | §171a | THE MECHANICAL A-PROP DRAFT (P30 S50): 256 members banked with no agent in the loop | | L16524 | §171b | THREE CARRIES THE MECHANICAL DRAFT NEEDS (P30 S50, banking the top-reach families) | | L16557 | §172 | THE ORPHAN-SLOT MECHANISM v2 (P30 S50-Max): the complete frame-residue model for gcc-2.7.2 | | L16611 | §172a | TWO DECOMPILATION TELLS FROM THE SAME DIG (P30 S50-Max) | | L16627 | §172b | THREE MORE TELLS FROM THE GCC READ (P30 S50-Max, banked on Drew's ask) | | L16670 | §173 | THE STORED-PLUMBING RECOVERY RECIPE (P31 T6): symfix-first, per-group isolation, and where | | L16706 | §174 | THE ADAPT-CARD WAVE RECIPE (P31 waves A/B, 2026-08-14): prevention beats recovery | | L16776 | §175 | A CALLER-SAVED REGISTER PIN CAN BE A CORRECTNESS BUG, NOT JUST A SCHEDULING CHOICE (P31 wa | | L16801 | §176a | THE VERIFICATION-LAYER LAWS (P31 overnight, 2026-08-15). What each check can and cannot pr | | L16841 | §176b | BATCH-GATING MECHANICS (P31): what changes when N drafts land in ONE .c | | L16867 | §176d | THE CONFLICT TABLE MUST BE SEEDED FROM THE TU, AND KEYED PER FILE (P31 S52, 2026-08-15) | | L16906 | §176e | SYMBOL IDENTITY IS COMPUTABLE OFFLINE (P31 S52): `tools/reloc_identity.py` | | L16963 | §176f | THE DECLARATION FORM IS A MATCHING LEVER, SO RECONCILE TOWARD THE FORM THE MATCH NEEDS (P3 | | L16994 | §176g | SIZE A WAVE BY INSTRUCTIONS, NOT BY CARDS (P31 S52 — the adopted doctrine) | | L17032 | §176h | THE BATCH-SUBSTITUTION HAZARD MAP (P31 S52): seven holes, three wrong fixes, one law | | L17040 | §3-A. | The seven under-reporting holes (all in `gate_main`, all the same shape) | | L17058 | §3-B. | Typedef handling — the only strategy that survives contact | | L17080 | §3-C. | The limit that remains (recorded, not solved) | | L17087 | §3-C2. | RECONCILE BEFORE THE FIRST GATE — a parked draft gets HARDER to bank, not easier | | L17110 | §3-D. | The measured cost shape, and what to build next | | L17128 | §176i | WHAT A STATIC PRE-GATE CHECK CAN AND CANNOT PROVE (P31 S52, wave Q) | | L17160 | §176j | STOPPING A WAVE MID-FLIGHT COSTS THE IN-FLIGHT TAIL (and how much is recoverable) | | L17186 | §176j-2 | THE REPAIR PASS, MEASURED (do this instead of resuming) | | L17206 | §176k | TWO SELECTOR BUGS THAT SILENTLY SHRINK A WAVE | | L17223 | §177 | 🔴 THE EPILOGUE RETURN-DELAY SLOT IS DECIDED BY YOUR SAVED-REGISTER SET, NOT BY SCHEDULING | | L17280 | §178 | SIX LEVERS MINED FROM THE WAVE-P JOURNALS (P31 S52), each byte-proven and source-cited | | L17292 | §3-A. | THE `$0`-ADD OPAQUE COPY defeats `make_regs_eqv` (func_80033398, 93 ins) | | L17308 | §3-B. | A `return ` IS A PRIORITY-1 HARD-REG SET THE SCHEDULER PLACES FIRST (func_8001BE30, | | L17321 | §3-C. | SINGLE-SET TEMPS GET THE BIRTHING BOOST (func_8001D3FC, 196 ins) | | L17329 | §3-D. | A NARROW TYPE BLOCKS COPY ELISION (func_8001D3FC — new idiom) | | L17336 | §3-E. | THE ZERO-OFFSET ALIAS HOLE (func_80037028, 71 ins) | | L17345 | §3-F. | `MEM_IN_STRUCT_P` ASYMMETRY IN `true_dependence` (func_80037144, 124 ins) | | L17351 | §3-G. | TWO MODELLING TRAPS THAT COST THESE AGENTS SWEEPS OF HUNDREDS OF COMPILES | | L17367 | §179 | IDIOMS MINED FROM THE WAVE P/Q JOURNALS (P31 S52, harvest pass) | | L17377 | §179-A | 🔴 A LOOP-WALKED POINTER **PARAMETER** HANDS ITS ARGUMENT REGISTER TO THE GIV (9 byte-proof | | L17426 | §179-B | 🔴 THE HAND-WRITTEN-ASM TRANSCRIPTION CHECKLIST (maspsx + masked_diff; 10 byte-proofs) | | L17476 | §179-C | 🔴 A FUNCTION WITH NO EPILOGUE (falls into a sibling's shared tail) MUST BE FILE-SCOPE `__a | | L17527 | §179-D | `gte_stflg` MUST CLOBBER `"$12"` OR THE WHOLE TEMP FILE ROTATES BY ONE | | L17547 | §179-E | A `>2*MAX_MOVE_BYTES` BLOCK COPY IS A **STRUCT ASSIGNMENT**, NOT A HAND LOOP | | L17573 | §179-F | PINNING A LOOP-WALKED POINTER IS A TOTAL OFF-SWITCH FOR STRENGTH REDUCTION | | L17596 | §179-G | 🟡 A PIN CAN **CREATE** A COMBINE `LOG_LINK` AND DELETE AN `andi` (sixth RC-5 channel, n=1) | | L17623 | §179-H | A MID-BODY `.global LABEL` PAIR SLICES A BYTE-COMPARABLE FRAGMENT OUT OF A LARGER ROUTINE | | L17646 | Considered | and NOT banked | | L17663 | §176c | MAIN (SLUS_007.26) CANNOT BE GATED INCREMENTALLY | | L17674 | §176 | SEVEN LEVERS FROM THE P31 OVERNIGHT WAVES (2026-08-15): statement order, false regalloc, a | | L17680 | §176-A | "SCHEDULE / DELAY-SLOT / LENGTH-DRIFT ±1" ⇒ check STATEMENT ORDER around the call first | | L17704 | §176-B | "REGALLOC-PERM, 1-4 instructions off" ⇒ it is usually NOT register allocation | | L17750 | §176-C | 🔴 WALL REFUTATION: a hard-register pin CANNOT schedule around a call, because of a genuine | | L17776 | §176-D | CSE-class levers used in reverse (two sharpenings of §153 and cse_expr §2) | | L17802 | §176-E | Two cheap source spellings, both cc1-probed | | L17824 | §176-F | Misdiagnosis triage: four residual verdicts that were lying | | L17841 | What | is NOT banked here | | L17854 | §180 | THE LEFTOVER-DRAFT HARVEST: RE-VERIFY WHAT YOU ALREADY HAVE BEFORE DRAFTING ANYTHING NEW | | L17883 | §180b | WHAT THE PRE-GATE LADDER ACTUALLY FINDS IN A COLD PILE (the shape of integration debt) | | L17902 | §180c | WHEN A BINARY'S MASS BAND IS SPENT, THE FLEET-WIDE DRAW IS STRICTLY BETTER | | L17920 | §181 | WHAT A WAVE'S GATE ACTUALLY REJECTS (P31 S53, measured on wave R's 45-draft main pile) | | L17921 | Only | ONE of 27 blocked drafts was wrong. The other 26 were correct and unbankable. | | L17976 | §182 | §177's HONEST NEGATIVE: the epilogue lever cracked 4 of 16, and the `800c3` cluster held | | L17990 | §180d | THE `pgrep` BRACKET TRICK PROTECTS THE PATTERN, NOT THE COMMAND LINE | | L18002 | §183 | THE DECLARATION-RECONCILIATION PLAYBOOK (P31 S53, measured on 20 byte-verified drafts) | | L18003 | §3-18 | of 20 reconciled while keeping the match. The two that did not are mechanism, not effort. | | L18073 | §184 | COMMENT-BLINDNESS IS A DEFECT CLASS, NOT A BUG (P31 S53: three tools, one root cause, one | | L18101 | §185 | EDIT THE SIDE THAT IS CHEAP TO VERIFY, AND CHECK A TU RETYPE AT ITS USE SITES | | L18133 | §186 | CROSS-JUMPING RUNS **AFTER** SCHEDULING, SO NO C-LEVEL BARRIER CAN STEER IT | | L18154 | §186b | A NO-SAVE 16-BYTE FRAME IN A LEAF FUNCTION MEANS `s16` LOCALS, NOT A HIDDEN CALL | | L18162 | §186c | WHERE A VALUE IS LOADED DECIDES WHICH ALLOCATOR OWNS IT, AND THEREFORE ITS REGISTER | | L18179 | §187 | 🔴 "SAME SOURCE" IS NOT "SAME OBJECT": THE SDK BUILD AND THE GAME BUILD DISAGREE ON GTE NOP | | L18217 | §188 | 🔴 THE `jr $ra` + `addiu $sp` TAIL IS AN **ASSEMBLER** ARTIFACT, NOT A FRAME SHAPE | | L18267 | §189 | FIVE COMPILER LAWS MINED FROM THE WAVE R/S JOURNALS (P31 S53), each source-cited and re-de | | L18342 | §190 | THREE PRESCRIPTIONS FROM THE SAME HARVEST (weaker evidence than §189, honestly labelled) | | L18379 | §191 | WHAT THIS HARVEST DID **NOT** BANK (4 rejected, 4 narrowed) — recorded so it is not re-der | | L18401 | §192 | THE PRE-GATE LADDER WAS MAIN-ONLY, AND NOBODY COULD SEE IT (P31 S54) | | L18402 | Three | defects in one call path; the overlay slates that carry most of the wave work were being w | | L18466 | §193 | THE WAVE-T HARVEST (P31 S54): 71 index_gap reports -> 9 laws, 5 rejected, 61 already-cover | | L18483 | §193-A | The wave card ships only OPEN-set pointers and discards the atlas's BANKED one — `exemplar | | L18550 | §193-B | A NARROW CAST OF A WIDE PARAMETER COSTS ONE EXTRA INSTRUCTION WHEN ITS STATEMENT SITS AFTE | | L18588 | §193-C | gcc-2.7.2 cross_jump merges the SCHEDULED common SUFFIX only — there is no prefix/head mer | | L18622 | §193-D | A COMPILER-GENERATED ARGUMENT COPY IS A `optimize_reg_copy_1` TRIGGER: when the pointer's | | L18693 | §193-E | A varying-address (pointer) load is re-emitted once per CSE-LIVE INTERVAL, and naming it i | | L18723 | §193-F | §148-A2 — The `threshold -= 3` STAIRCASE: `move_movables` admits a COUNT of invariants, no | | L18787 | §193-G | §164-54's "scope to ≥4 arms" bound is byte-wrong — the dispatch-topology oracle goes live | | L18848 | §193-H | A pointer-derived base load `*(s32*)(p+K)` is uncacheable across ANY memory write or call | | L18888 | §193-I | A DECLARED AGGREGATE LOCAL HAS AN 8-BYTE FRAME STRIDE — CEIL(size,8), NOT size. N ARRAYS T | | L18947 | §193-REJECTED | what this harvest did NOT bank (recorded so it is not re-derived) | | L18974 | §194 | THE WAVE-U HARVEST (P31 S54): 64 index_gap reports -> 14 laws, 5 rejected, 44 already-cove | | L18991 | §194-A | A zero-byte scheduling fence goes AFTER the defining statement to make that computation em | | L19057 | §194-B | A `addu $rA,$rB,$zero` copy feeding ≥2 `sh` stores is a SECOND, 16-BIT-DECLARED local — th | | L19095 | §194-C | A CALLER-SAVED loop counter proves its live range crosses ZERO calls — so it cannot share | | L19158 | §194-D | Declared width of a computed-value local is a sched1 dial (count-neutral) — a replication | | L19199 | §194-E | The wave card's `exemplar` is the TARGET ITSELF on 42/73 wave-U and 36/71 wave-T cards — a | | L19236 | §194-F | `if ((*p = v = f()) == 0)` is an expand-time pseudo SPLITTER (store_expr's `want_value && | | L19309 | §194-G | Reading the integer half of a 16.16 stack aggregate: REGISTER-LIVENESS, not the C spelling | | L19352 | §194-H | §164-29's WAR fence runs again at SCHED2 ON HARD REGISTERS: an in-place `v &= K` before a | | L19390 | §194-I | §16N+2's magic-per-odd-part ladder has exactly one broken row — read the divisor arithmeti | | L19433 | §194-J | Back-to-back identical stores: flow.c's `last_mem_set` deletes the first, and only `volati | | L19485 | §194-K | Blind sched1's alias oracle with a second SET of a pointer pseudo — the first zero-byte, n | | L19563 | §194-L | §88b and §189-E are BOTH half-wrong, but not the way the candidate says: the compare-const | | L19611 | §194-M | A STORE in a CONDITIONAL branch's delay slot proves its C statement DOMINATES the branch — | | L19669 | §194-N | §193-D's C dial is misstated: the lever is a SURVIVING CODE_LABEL (a label with a real inc | | L19729 | §194-REJECTED | what this harvest did NOT bank (recorded so it is not re-derived) | | L19750 | §195 | THE WAVE-V HARVEST (P31 S54): 67 index_gap reports -> 14 laws, 9 rejected, 76 already-cove | | L19764 | §195-A | §167-08's "an $aN READ before the jal is scratch" has a byte-proven FALSE-NEGATIVE class: | | L19835 | §195-B | A CALL_INSN does not start a basic block in gcc-2.7.2 — so a call-crossing temp can be a L | | L19877 | §195-C | A call-argument `%hi/%lo` pair sitting at the block head, far above its `jal`, is a load-d | | L19925 | §195-D | §195 — `masked_diff.mask_for` returns 0 for EVERY `j`/`jal` word, so an internal `j` desti | | L19993 | §195-E | A 0/1 materialised at a JOIN immediately before the controlling `beqz`/`bnez` proves the s | | L20051 | §195-F | fold-const.c:4825 canonicalises a `?:` whose THEN arm is zero (or constant against a non-c | | L20103 | §195-G | §NEW — TWO ARMS CALLING THE SAME CALLEE MERGE INTO ONE `jal` UNLESS EACH ARM'S OWN CODE CO | | L20151 | §195-H | §165-27g — ON A FIXED-SYMBOL GLOBAL, `extern T D[];` + `D[0]` IS THE CSE RELOAD DIAL, AT Z | | L20198 | §195-I | §145(b) AMENDED — the pointer-bump `addiu` is saved by cse, not combine: ANY second SET of | | L20263 | §195-J | GTE / PsyQ op CALL-vs-INLINE is a PER-SITE SOURCE FACT, not a TU style — both forms coexis | | L20307 | §195-K | At -O2 the §18 array-of-struct lever is a FRAME lever, not a length lever — but only when | | L20359 | §195-L | The cse store-re-seed does not cross a JOIN LABEL: per-arm stores + a join read keep the r | | L20411 | §195-M | Frame `vars` is a SEQUENTIAL bump-allocation, not a flat sum: §193-I's CEIL(aggregate,8) t | | L20460 | §195-N | In a call-bearing chain of N≥2 `if (f(...)) return 1;` tests closed by `return 0;`, the LA | | L20507 | §195-REJECTED | what this harvest did NOT bank (recorded so it is not re-derived) | | L20553 | §196 | PUT ON THE CARD WHAT THE TREE ALREADY KNOWS: the fleet's declaration consensus (P31 S54) | | L20608 | §197 | THE WAVE-W HARVEST (P31 S54): 68 index_gap reports -> 4 laws, 3 rejected, 41 already-cover | | L20622 | §197-A | A NARROW SIGNED MEMORY READ FEEDING A CONSTANT `>>` LOSES ITS `lh`, AND THE CURE IS AN ASM | | L20660 | §197-B | A REPEATED COMPARE OF ONE VALUE AGAINST ONE CONSTANT IS DELETED BY cse's `qty_comparison_c | | L20688 | §197-C | Fix A1 (operand order) cannot move a commutative destination whose .greg conflict set alre | | L20733 | §197-REJECTED | §197-REJECTED | | L20748 | §199 | THE WAVE-X HARVEST (P31 S54/S55): 63 index_gap reports -> 7 laws, 2 rejected, 56 already-c | | L20759 | §199-A | §189-A's asm→source inference is byte-FALSE: an interloper between a split constant's `lui | | L20808 | §199-B | A permutation sweep that holds ANY statement fixed is not a sweep: the statement an agent | | L20853 | §199-C | A NEGATIVE CONSTANT MULTIPLY ALWAYS TAKES expmed's negate_variant — but whether you ever S | | L20901 | §199-D | A narrow UNSIGNED value compared in an ordered `if` emits `sltiu`/`sltu`; the only dial is | | L20961 | §199-E | §189-A BOUNDED AND CORRECTED — the discriminator is INSN_PRIORITY, not "is the interloper | | L21020 | §199-F | §164-36b — THE TARGET-HEAD FENCE IS A DELAY-SLOT THREAD SELECTOR, AND IT ONLY FIRES WHEN ` | | L21074 | §199-G | At TWO case nodes the switch-vs-if oracle is not blind — but the tell is ALL tests positiv | | L21129 | §199-REJECTED | §199-REJECTED | | L21140 | §200 | THE ALIAS IS THE UNIVERSAL DECLARATION ESCAPE: stop negotiating with the TU's spelling (P3 | | L21189 | §201 | THE WAVE-Y HARVEST (P31 S55): 67 gap reports -> 5 laws, 8 rejected, 53 already-covered | | L21199 | §201-A | §150-B applies to `decl_prior`'s DEF row: for an overlay-window symbol the banked "definit | | L21231 | §201-B | In a narrowed PLUS/MINUS/AND/IOR/XOR expression the destination pointee is INERT — the sig | | L21311 | §201-C | §X — A CALL'S OWN DELAY SLOT AND THE UPSTREAM CONDITIONAL BRANCH'S SLOT COMPETE FOR ONE IN | | L21362 | §201-D | THE SIGNEDNESS OF A div/mod MAGIC IS DECIDED BY THE STATIC TYPE OF THE DIVIDEND TREE AFTER | | L21409 | §201-E | §194-J-2 — The `last_mem_set` deletion window is measured in SOURCE/expand order, not in t | | L21465 | §201-REJECTED | eight, the session's highest | | L21490 | §202 | THE ALIAS CARRIES A DEFINITION, NOT JUST A DECLARATION: the DEF-SIDE-RETURN wall (P31 S56) | | L21527 | §203 | A DEDUPED TYPEDEF MUST PRECEDE EVERY SPLICE POINT, NOT JUST ITS OWN (P31 S56) | | L21588 | §204 | THE WAVE-Z HARVEST (P31 S56): 82 gap reports -> 5 laws, 16 rejected, 30 already-covered | | L21607 | §204-A | A COMPARE THAT APPEARS BOTH IN A BRANCH'S DELAY SLOT AND AGAIN ON THE FALL-THROUGH IS A JO | | L21682 | §204-B | A LOOP COUNT THAT ARRIVES ON THE STACK IS DECREMENTED IN PLACE: a fresh counter local can | | L21746 | §204-C | WHEN A LOCAL BUFFER'S ADDRESS IS PASSED TO A CALL, ITS SIZE IS A FACT ABOUT THE CALLEE'S B | | L21804 | §204-D | A LOOP-INVARIANT LOAD IS ADMITTED AS A MOVABLE ONLY IF ITS ADDRESS CANNOT TRAP: `local.fie | | L21879 | §204-E | `decl_prior`'s `%hi/%lo` ARM HAS NEVER FIRED: the card's promised GLOBAL-TYPE row is 0 of | | L21931 | §204-CONFIRMED | 30 reports that the index already answered | | L22025 | §204-REJECTED | sixteen, twice the previous record | | L22098 | §205 | THE CHAINED ASSIGNMENT IS ITS OWN SCHEDULING DIAL: `*b = *a = v;` moves an argument copy t | | L22153 | §206 | THE JTBL-CARVE DRAFTING IDIOM: the bounds check is the entry count, and an EMPTY case owns | | L22222 | §207 | THE WAVE ab–ag HARVEST (P31 S58): 278 byte-banked notes → 25 laws, 103 self-reported no-ga | | L22243 | §208 | TWO NAMED LOCALS FOR ONE RELOADED EXPRESSION BUY TWO ALLOCNOS — the naming granularity own | | L22292 | §209 | THE NARROW LOCAL IS A DIAL IN TWO OPPOSITE DIRECTIONS, AND §194-B's "≥2 `sh` STORES" BOUND | | L22369 | §210 | THE SINGLE-BIT MASK IN A BOOLEAN TAIL: `andi K ; sltu $zero,v` vs `srl n ; andi 1` is a ST | | L22415 | §211 | HOIST THE LOOP INIT ABOVE THE DOMINATING GUARD: it fills the guard's delay slot AND flips | | L22474 | §212 | THE WALKING CURSOR IS COUNTABLE: `*wp++` emits one `addiu` PER STORE, `wp[0..2]` emits one | | L22519 | §213 | INDEPENDENT SAME-BASE STORES: THE EMISSION ORDER IS A PERMUTATION OF SOURCE ORDER, AND THE | | L22555 | §214 | THE BANKED TWIN MAY BE A MACRO, A DELETED `.s`, OR A SEMANTIC INVERSE — six ways a ≥0.9 si | | L22601 | §215 | PIN ECONOMY: the twin's pins are NOT part of the shape, and §17's "pin every call-crossing | | L22657 | §216 | DISTINCT ADJACENT SCALARS vs ONE ARRAY: one `lui` per access is the tell, and the array de | | L22697 | §217 | DECODING A CALL'S STACK ARGUMENT SLOTS: `sw` at `0x10`/`0x14`/`0x18` are params 5/6/7 **(s | | L22723 | §218 | A NARROW TYPE AT THE ABI BOUNDARY COSTS AN IN-PLACE `sll/sra` PAIR — on the RETURN as well | | L22752 | §219 | COMPOUND `+=`, FULL ASSIGNMENT, AND AN EXPLICIT TEMP ARE THREE DIFFERENT SCHEDULES OF ONE | | L22779 | §220 | THE PARAMETER ITSELF IS A REGALLOC DIAL: use it directly, prefer `s32` to `void*`, and pla | | L22819 | §221 | A CONSTANT SHARED BY TWO STORES DIES AT THE CALL WHOSE DELAY SLOT REFILLS ITS REGISTER **( | | L22835 | §222 | SWITCH vs IF-CHAIN, PART 3: source arm order IS emission order, a leading EMPTY case buys | | L22877 | §223 | READING A `jal` DELAY SLOT: the value in it was produced BEFORE the call, so it is NEVER t | | L22939 | §224 | CROSS-JUMP: WRITE THE DUPLICATE, AND READ A SHARED DELAY SLOT AS THE MERGE SIGNATURE (P31 | | L22975 | §225 | THREE CONTROL-FLOW SHAPES NO STRUCTURED SPELLING REACHES (P31 S58) | | L23018 | §226 | FRAME PADS: FOUR WAYS §162i1/§2429's DEAD-LOCAL LEVER MISFIRES (P31 S58) | | L23059 | §227 | TYPE THE SOURCE BY THE **LOAD** WIDTH, NOT BY THE STORE WIDTH (P31 S58) | | L23079 | §228 | READING THE DIVIDE, PART N: the off-by-one compare is `% K == 1`, and three more discrimin | | L23116 | §229 | THE ADDRESS IS A VALUE: NAMING IT MOVES THE `lui`/`addiu` PAIR — AND §L14410 SAYS THE OPPO | | L23165 | §230 | THE ANCHOR PROBE: with `%hi`/`%lo` masked, the surviving `addiu` deltas tell you which ass | | L23180 | §231 | TRANSCRIPTION AND SEMANTIC-READ HYGIENE: six ways the listing misleads (P31 S58) | | L23221 | §232 | WHEN THE `jr` DELAY SLOT'S STORE STORES THE RETURN VALUE, TIE THEM WITH ONE PSEUDO **(sing | | L23257 | §30 | addendum (P31 S58) — the `/s` grant closes a SCHEDULING residual and a REGISTER residual w | | L23277 | §194-B | addendum (P31 S58) — BOUND 2 is byte-wrong; see §209 Direction A | | L23283 | §176-B | addendum (P31 S58) — the misdiagnosis direction | | L23289 | §165-40 | addendum (P31 S58) — the barrier goes at the COPY SITE, not inside the region it protects | | L23298 | §164-63 | addendum (P31 S58) — the interposed asm works when the SECOND value is an ordinary assignm | | L23307 | §193-A | / §194-E addendum (P31 S58) — where the twin's body actually lives | | L23313 | §233 | THE WAVE aa–bg HARVEST (P31 S58b): 1,101 byte-banked notes → 24 new laws, 21 addenda, ~700 | | L23357 | §234 | CONSTANT MATERIALISATION: THE STORE LVALUE'S SIGNEDNESS PICKS `addiu` vs `li`/`ori` (P31 S | | L23398 | §235 | THE PHANTOM SYMBOL: A MASKED `MATCH` CAN CARRY A RELOCATION THAT DOES NOT EXIST (P31 S58b) | | L23427 | §236 | THE DECLARATION LAYER IS THE DOMINANT BANK-BLOCKER: NINE WAYS A BYTE-PERFECT BODY FAILS TH | | L23506 | §237 | THE CAST-AT-CALL-SITE DECISION TABLE: WHAT §17a-1 FIXES, WHAT IT CANNOT, AND THE FOUR ESCA | | L23561 | §238 | SAME NAME, DIFFERENT FUNCTION: THE OVERLAY-HOMONYM TRAP (P31 S58b) | | L23601 | §239 | TWO-STATEMENT INTEGER-SPACE MATERIALISATION REORDERS `la` vs `sll`; AND THE PLUS-TREE OPER | | L23635 | §240 | `A + K + B`: WRITE THE CONSTANT **BETWEEN** THE TWO RUNTIME TERMS (P31 S58b) | | L23664 | §241 | THE FOLDED SIGN-EXTEND-AND-SCALE: `sll 16 ; sra (16 − log2 scale)` (P31 S58b) | | L23693 | §242 | `*k` vs `<>n`: EXPRESSION SPELLING OWNS THE LOAD WIDTH AND THE ROUNDI | | L23721 | §243 | SPELL THE CSE BARRIER AS A REASSIGNED POINTER; AND THE `nop`-AFTER-EVERY-`lh` SIGNATURE (P | | L23751 | §244 | `volatile` IS A COUNTING INSTRUMENT, A STORE-ORDER PIN, AND MUST SOMETIMES BE ASYMMETRIC ( | | L23786 | §245 | THE CALL'S ARGUMENT LIST IS A SCHEDULING SLOT (P31 S58b) | | L23833 | §246 | THREE-LIVE-VALUE SCAN LOOPS WANT ADDRESS-FROM-INDEX; AND TWO SYMBOLS CAN SHARE ONE giv (P3 | | L23873 | §247 | TWO BRANCHES TO **ONE** LABEL MEANS THE SOURCE CONDITION IS NEGATED (P31 S58b) | | L23907 | §248 | SPLIT THE LOAD FROM THE ARITHMETIC: A FUSED `g + K` DENIES THE CALLEE-SAVED REGISTER ITS D | | L23931 | §249 | THE SELF-ASSIGN, THE DEAD RE-ASSIGN, AND THE `+ zr` COPY: THREE WAYS TO MAKE A DELETED INS | | L23973 | §250 | `%hi/%lo` vs `lw`: THE EXTERN'S ARRAY-vs-SCALAR SHAPE DECIDES ADDRESS MATERIALISATION (P31 | | L24010 | §251 | IMMEDIATE-SPELLING TRIGGERS: `+= 0xFF`, FULL-WIDTH `~K`, AND THE TWO-OR SPLIT (P31 S58b) | | L24032 | §252 | THE GUARDED PRE-DECREMENT: `(x != 0) && (--x == 0)` (P31 S58b) | | L24053 | §253 | POSTFIX `++` vs `+= 1` PICKS A DIFFERENT SCRATCH REGISTER **(single observation — not yet | | L24067 | §254 | THE DEAD PARAMETER IS A REGISTER-PLACEMENT TOOL **(single observation — not yet cross-conf | | L24079 | §255 | THE EMPTY CASE, PART 2: FOUR TREE SHAPES IT BUYS (P31 S58b) | | L24114 | §256 | GOTOS IN THE TARGET'S BLOCK ORDER REPRODUCE SWITCH PLACEMENT WITHOUT SWITCH'S SIDE EFFECTS | | L24151 | §257 | THE DEAD-END LEDGER (P31 S58b): ELEVEN LEVERS THAT MEASURED NULL OR BACKFIRED | | L24194 | §258 | ADDENDA TO EXISTING SECTIONS (P31 S58b) | | L24199 | §30 | addendum (P31 S58b) — THE ANONYMOUS STRUCT MEMBER REF GRANTS `/s`, AND THAT IS A TWO-FOR-O | | L24220 | §194-B | / §209 addendum (P31 S58b) — TWO MORE INSTANCES, AND THE BOUND IS NOW REFUTED FOUR WAYS | | L24243 | §202 | addendum (P31 S58b) — THE DEF-SIDE ALIAS ALSO CLEARS A RETURN+PARAM DOUBLE CONFLICT | | L24254 | §205 | addendum (P31 S58b) — CHAINED ASSIGNMENT: N≥3 IS INNERMOST-FIRST, AND THE TEXT MIRRORS EMI | | L24271 | §208 | addendum (P31 S58b) — IT SCALES TO SIX SITES, AND IT HAS AN EXACT INVERSE | | L24300 | §210 | addendum (P31 S58b) — THREE CONFIRMED SPELLINGS OF THE BOOLEAN TAIL | | L24316 | §211 | addendum (P31 S58b) — INIT PLACEMENT: FIVE MORE DIALS BEYOND THE GUARD HOIST | | L24359 | §213 | addendum (P31 S58b) — THREE MORE PERMUTATION LAWS FOR INDEPENDENT SAME-BASE STORES | | L24388 | §214 | addendum (P31 S58b) — FOUR MORE WAYS A HIGH-SIMILARITY TWIN LIES | | L24424 | §215 | addendum (P31 S58b) — PIN ECONOMY, PART 2: NINE REFINEMENTS | | L24476 | §217 | CROSS-CONFIRMED (P31 S58b) — AND THE INCOMING HOME SLOT IS THE MIRROR | | L24493 | §220 | addendum (P31 S58b) — THE PARAMETER, NOT A COPY (SEVEN CARDS) | | L24518 | §222 | addendum (P31 S58b) — IF-CHAIN vs SWITCH: THREE MORE DISCRIMINATORS | | L24536 | §223 | addendum (P31 S58b) — FIVE MORE CONFIRMATIONS, AND THE CONSTANT-IN-`$v0` CASE | | L24560 | §224 | addendum (P31 S58b) — CROSS-JUMP MERGES *CALLS*, AND THE DELAY SLOT IS THE DISCRIMINATOR | | L24590 | §225 | addendum (P31 S58b) — THE GUARD-CLAUSE FINGERPRINT, AND THREE MORE SHAPES | | L24617 | §226 | addendum (P31 S58b) — THE FRAME CATALOGUE: SEVEN MORE LEVERS, AND SLOT ORDER IS DECLARATIO | | L24662 | §229 | addendum (P31 S58b) — NAME IT **INSIDE** THE ARM | | L24673 | §230 | CROSS-CONFIRMED (P31 S58b) | | L24682 | §231 | addendum (P31 S58b) — FOUR MORE WAYS THE LISTING MISLEADS | | L24713 | §232 | CROSS-CONFIRMED (P31 S58b) | | L24724 | §259 | THE DISCARD LEDGER FOR THE aa–bg HARVEST (P31 S58b): WHAT WAS MINED AND REJECTED, AND WHY | | L24763 | §260 | THE §154-A LEADING-ISLAND SPLIT: ONE CONFIG LINE, AND THE ISLAND PEELS FROM THE END (P31 S | | L24813 | §260-A | STAGE 2 IS PROVEN, AND THE WHOLE jtbl PIPELINE IS AUTOMATED AT THE GATE (P31 S59, same day | | L24849 | §261 | THE -O0 ORACLE: DERIVE THE OPT LEVEL FROM THE TARGET, AND `$fp` IS NOT THE TELL (P31 S59) | | L24875 | §261a | THE -O0 FRAME-RELOAD GRAMMAR: reload COUNT disambiguates the C spelling (P31 S59, byte-pro | | L24897 | §262 | A LANE'S YIELD IS ONLY A LANE FACT IF IT IS SIZE-MATCHED (P31 S59) | | L24927 | §263 | A STOLEN DELAY SLOT WHOSE INSTRUCTION IS AN ARG-REGISTER COPY IS AN ARITY ERROR, NOT A SCH | | L24968 | §264 | FOUR TELLS-LANE C RECIPES, EACH DRIVEN TO MATCH (P31 S59) | | L25018 | §265 | THE VERBATIM-ASM BANK LANE: A FUNCTION NO -O2 C CAN EVER MATCH BANKS AS A RAW `__asm__` BO | | L25080 | §266 | THE INERT-RIDER LAW: A LEVER IS ONLY CITABLE WHEN ITS SOLO REMOVAL BREAKS THE MATCH (P31 S | | L25120 | §267 | ADDENDA HARVESTED FROM WAVES at/bh/bk/bl (P31 S59b) | | L25128 | ADD-1 | → §231 addendum (also cross-ref from §195-D) — THE MASKED-`jal` "MISSING CALL" ILLUSION | | L25137 | ADD-2 | → §42a addendum — A SHARED CONSTANT *NAMED IN A LOCAL* ACROSS A `jal` IS AN ISO→TU DRIFT H | | L25149 | ADD-3 | → §236, item 10 — THE UN-DELETED `INCLUDE_ASM` STUB IS A DUPLICATE DEFINITION | | L25159 | ADD-4 | → §225-3/-4 addendum — THE MIRROR ROW: VALUE-RETURN IN THE *TAKEN* ARM + TRAILING BARE `re | | L25173 | ADD-5 | → §1/I1 addendum — THE INVERTED RANGE TEST: `(u32)(x-lo) >= N` WITH THE ZERO-ARM AS THE TR | | L25182 | ADD-6 | → §172b-1 / §264 addendum — SHIFT-AS-TEST: `(x << 16) != 0` TESTS THE LOW HALF WITHOUT TRU | | L25191 | ADD-7 | → §256 addendum — THE SINGLE-GUARD GOTO: THEN-BLOCK OUT OF LINE AT THE TAIL | | L25203 | ADD-8 | → §245 addendum — THE RE-TIE BARRIER PINS CALL-ARG SETUP TO SOURCE ORDER (construct 6) | | L25215 | ADD-9 | → §213-3 / §217 addendum — ADJACENT PRE-CALL FRAME STORES ARE ONE AGGREGATE; THE UNESCAPED | | L25225 | ADD-10 | → §237 addendum (arity-evidence paragraph) — AN `la` PAIR ABOVE THE PROLOGUE `sw $ra` IS A | | L25234 | ADD-11 | → Cross-confirmation card block (per §259's standing instruction: confirmation, not news) | | L25285 | §268 | A `register __asm__` PIN ON A CALL-CLOBBERED REGISTER IS HONORED EXACTLY WHEN THE PINNED R | | L25339 | §269 | ADDENDA HARVESTED FROM WAVES ax/bm (P31 S59c) | | L25354 | ADD-1 | → §257-8 addendum — THE INTERPOSED ASM'S `__volatile__` IS A PER-SHAPE DIAL, AND THE "NO-O | | L25367 | ADD-2 | → §236 addendum (item 1 corollary) — THE SILENT-SPLICE DECLARATION LADDER: WHERE THE TU HA | | L25381 | ADD-3 | → §238 addendum — TWO BINARIES CAN EACH DEFINE THE SAME `func_` NAME WITH DIFFERENT BYTES, | | L25394 | ADD-4 | → §167-37 addendum — THE FIFTH PRECONDITION, NOW MEASURED: DOWNSTREAM FIELD RE-READS ⇒ NAM | | L25411 | ADD-5 | → §267-ADD-6 / §172b-1 addendum — THE SIGN-TEST FACE: `(s16)v < 0` IS `sll 16` + `bgez` ON | | L25427 | ADD-6 | → §220-addendum — THE FOURTH FACE: WHEN THE NAMED COPY ITSELF BUYS THE EXTRA CALLEE-SAVED, | | L25443 | ADD-7 | → §229 addendum — THE VALUE FACE: A LOOP-STORE CONSTANT SPELLED AS A LITERAL HAS NO SOURCE | | L25456 | ADD-8 | → §30a addendum — THE THIRD COLUMN: `*p++` IS ALSO SERIALIZED BUT BURNS `addiu`; ONLY CAST | | L25471 | ADD-9 | → §255 "AND CASE-BODY PLACEMENT" bound / §222-addendum-3 — ON A LARGE SPARSE TREE, BODIES | | L25485 | ADD-10 | → Cross-confirmation card block (per §259's standing instruction: confirmation, not news) | | L25526 | §3-1a. | The §266 sweep — every solo-lever A/B run for this batch | | L25559 | §270 | The A-prop 0-bank anatomy: a byte-correct body still needs FOUR layers to agree (P31 S59) | | L25577 | §271 | Ordinal IMM pairing: text order is NOT emission order; emit CANDIDATES, let the oracle pic | | L25599 | §272 | The `(void)`-decl + empty-call wall: K&R the DEFINITION, not just the decls (P31 S59) | | L25619 | §273 | A standalone compile is the WRONG oracle for a TU-destined draft (P31 S59) | | L25634 | §274 | ADDENDA HARVESTED FROM 18 WAVES (P31 S60): 315 candidates, 255 already covered, 21 sharpen | | L25640 | ADDENDUM | to §179-C — the `.type NAME, @function` requirement | | L25687 | ADDENDUM | to §134 — a typedef defined BELOW the splice point is stripped anyway | | L25717 | ADDENDUM | to §179-D (GTE macro reference family) — `gte_SetRotMatrix`/`gte_SetTransMatrix` bodies | | L25743 | ADDENDUM | to §82 — struct copies must stay MEMBER-WISE, not block-moved, to match a spill-slot save | | L25781 | ADDENDUM | to §136d-1 (RC-12, the `$0`-add / opaque-copy family) — two symptoms beyond "compare reads | | L25820 | ADDENDUM | to §20 — a global declared as `T *` may itself BE the array base, not a pointer to derefer | | L25849 | ADDENDUM | to §1-I5 | | L25914 | ADDENDUM | to §164-51 | | L25930 | ADDENDUM | to §176-F5 | | L25959 | ADDENDUM | to §225 | | L26004 | ADDENDUM | to §224 — CROSS-JUMP: THE DUPLICATE CAN BE A PLAIN STORE, NOT ONLY A CALL | | L26038 | ADDENDUM | to §164-64 — AN EMPTY CLOBBER ON AN ARGUMENT REGISTER CAN BE THE DELIBERATE FIX, NOT JUST | | L26069 | ADDENDUM | to §244 — THE COMPILER BARRIER, NOT `volatile`, BLOCKS A STORE→LOAD HOIST THROUGH A POINTE | | L26100 | ADDENDUM | to §172b-1 — TWO PLACEMENT DIALS THE PROMOTION LAW DOESN'T NAME: NARROW THE COUNTER'S DECL | | L26147 | ADDENDUM | to §229 — A POINTER'S NUMBER OF USES DECIDES WHETHER ITS ADDRESS FOLDS OR SURVIVES A CALL | | L26192 | ADDENDUM | to §172b-4 — THE PLAIN CAST-DIVISION ALREADY PRODUCES THE PATTERN; DON'T HAND-ROLL THE BIA | | L26222 | ADDENDUM | to §8 — WHEN `INCLUDE_RODATA` NEEDS A STANDALONE `.s` YOU CAN'T CREATE, CARRY THE FRAGMENT | | L26265 | ADDENDUM | to §226 — A DEAD LOCAL SCOPED TO A NESTED BLOCK BUYS A MID-FUNCTION `addiu sp` PAIR, NOT A | | L26304 | ADDENDUM | to §172a — RE-READING MEMORY (NOT NAMING A TEMP) IS WHAT KEEPS AN INCREMENT'S DELAY-SLOT F | | L26335 | ADDENDUM | to §225 / §256 — A GOTO TO A SHARED SET-POINT PREVENTS IF-CONVERSION FROM COLLAPSING A LAT | | L26377 | ADDENDUM | to §211 — AN IN-LOOP ACCUMULATOR WANTS A CLOSED-FORM EXPRESSION WHEN THE TARGET REMATERIAL | | L26412 | §275 | THE LEFTOVER-REGISTER READ | | L26452 | §276 | MIXED ADDRESS-EXPRESSION SPELLING FOR ADJACENT RELOCATABLE SYMBOLS IS A CSE-UNIFICATION DI | | L26561 | §277 | RETURN-TAIL C SPELLING PICKS THE DELAY-SLOT-FILL vs TRAILING-MOVE TOPOLOGY, AND A NARROWER | | L26625 | §278 | ADDENDA HARVESTED FROM WAVE cf (P31 S60): 34 candidates, 13 already covered, 8 sharpenings | | L26633 | ADDENDUM | to §74 (func_800D0E30, resident) | | L26669 | ADDENDUM | to §172b-4 (func_80185054, ov_SC03_097) | | L26707 | ADDENDUM | to §265 (func_8017DC80, ov_SC07_002) | | L26746 | ADDENDUM | to §17 (func_800CB794, md_MAIN_036) | | L26794 | ADDENDUM | to §162p (func_8017C120, ov_MAIN_012) | | L26828 | ADDENDUM | to §20 (~L1947) (func_80186AD0, ov_SC06_032) | | L26858 | ADDENDUM | to §164-56 (func_8017F644, ov_SC04_005) | | L26893 | ADDENDUM | to §237 (func_8017F7FC, ov_SC03_092) | | L26922 | §279 | A `do/while (p < end)` LOOP UNDER AN ENTRY GUARD: the guard decides the compare, not the l | | L26923 | §NNN | A DO-WHILE'S GUARD AND LATCH MUST REPEAT THE SAME BOUND EXPRESSION, NOT SHARE ONE LOCAL: T | | L26956 | §280 | THE CURSOR'S DECLARED TYPE PICKS `sltu` vs `slt`: a `T*` bound test is UNSIGNED by C rule, | | L26957 | §NNN | A LOOP CURSOR'S C TYPE (POINTER vs PLAIN INTEGER) SELECTS `sltu` vs `slt` FOR ITS BOUND TE | | L26990 | §281 | GROUP COPY-THEN-RMW BY OPERATION KIND, NOT FIELD BY FIELD: sched1 does the interleaving, t | | L26991 | §NNN | A DEPENDENT COPY-THEN-RMW BLOCK MUST BE SOURCE-GROUPED BY OPERATION KIND, NOT BY FIELD, AN | | L27036 | §282 | gcc's OWN LOOP REVERSAL PUTS THE COUNTER INIT AFTER THE HOISTED MOVABLES — a position no h | | L27037 | §NNN | WRITE THE UP-COUNT LOOP: gcc's OWN REVERSAL PRODUCES A COUNTER-INIT INSTRUCTION THAT LANDS | | L27074 | What | I could not verify | | L27121 | §283 | ADDENDA HARVESTED FROM THE 36-WAVE BATCH (P31 S60): 1,216 candidates, 859 already covered, | | L27131 | ADDENDUM | to §164-75 — the fold-reassociation law also fires at a variable's INITIALIZER, not only a | | L27157 | ADDENDUM | to §21 — the `bltz`+`slti` (or N-separate-compares) signed-range-split bullet is now CONFI | | L27203 | ADDENDUM | to §202 — the DEF-SIDE ALIAS also resolves a function-vs-DATA-symbol identifier clash, not | | L27226 | ADDENDUM | to §22 (`volatile`-qualified-global reload lever, cookbook ~L1922) — for a NON-constant, s | | L27245 | ADDENDUM | to §195-E — a goto-ladder's STORES must sit AT the labels, after the gotos, not inline bef | | L27307 | ADDENDUM | to §195-N — a GNU statement-expression slider must sit INSIDE the conditional arm's value | | L27364 | ADDENDUM | to §176-B2 — in a micro-function with no long/short lifetime asymmetry, BOTH contending ps | | L27411 | ADDENDUM | to §199-G — A `default:` LABEL GROUPED ONTO THE LAST CASE REMOVES THE `j default` TAIL, EV | | L27480 | ADDENDUM | to §220 — REFERENCING THE RAW PARAMETER (NO NAMED COPY, NOT EVEN A PIN) LETS THE CALLEE-SA | | L27538 | ADDENDUM | to §252 — a `>=0`/`<0` split on an unconditionally-decremented value needs the POSTFIX ope | | L27565 | ADDENDUM | to §215 — FIFTH SHAPE: reused mask constants across two call-free merge sites each get the | | L27648 | What | I could not verify | | L27719 | Harness-defect | flags | | L27812 | ADDENDUM | to §167-40 (func_8017E2CC, ov_SC04_015 — wave dg) | | L27832 | ADDENDUM | to §20's cross-jump EXPLOIT bullet (func_8017E360, ov_SC05_007 — wave dg) | | L27846 | ADDENDUM | to §87 (func_801815F4 ov_SC06_032; corroborating func_801840DC ov_SC05_017, func_80189C68 | | L27865 | ADDENDUM | to §153 / §236-5 (func_801A419C, md_SC07_003 — waves di and dl, corroborating; refutes a c | | L27885 | ADDENDUM | to §263 (func_801E83AC, md_SC04_029 — wave dj) | | L27899 | ADDENDUM | to §265 (func_8017D878, ov_SC03_107 — wave dj; corroborated by a REJECTED, contradicted ca | | L27913 | ADDENDUM | to §6 (func_801811F0, ov_SC03_102 — waves dj and dl, corroborated by a self-reported "noth | | L27927 | ADDENDUM | to §195-G (func_80183BB0, ov_SC05_001 — wave dj) | | L27955 | ADDENDUM | to the zero-byte-asm-slider family (§47 / §148-C / §153) (func_800CB874, md_MAIN_040 — wav | | L27973 | ADDENDUM | to §194-B (func_8017EB34, ov_SC03_117 — wave dk; distinct from the §74 co-pinning finding | | L28005 | ADDENDUM | to §74 (func_8017EB34, ov_SC03_117 — counter/clamp variant; wave dj, corroborated by dk/dl | | L28025 | ADDENDUM | §37 — merged into the §153/§236-5 entry above (func_801A419C, wave dl) | | L28033 | ADDENDUM | §6 — merged into the §6 entry above (func_801811F0, wave dl) | | L28041 | ADDENDUM | to §238 (func_80182CB4, ov_SC02_000 — wave dl) | | L28059 | ADDENDUM | to §137a (func_801684B4, ov_MAIN_012; corroborated independently by func_80189E68, func_80 | | L28075 | ADDENDUM | to §8c / §88d (func_8016AB6C, ov_MAIN_012 — wave dm) | | L28089 | ADDENDUM | to §73 / §30#2 (func_800D1984, resident — wave dm) | | L28105 | What | I could not verify | | L28125 | ADDENDUM | to §174 Law 4 (func_8017E9A8, ov_SC06_015) | | L28165 | ADDENDUM | the zero-emission-asm family gains a REF-SLIDER PLACEMENT LAW and a paired RESTORER (func_ | | L28217 | From | ck + cl + cm | | L28223 | ADDENDUM | §NNN — sharpens §55a / §164-37 / §165-28 (switch-vs-tree cluster): A SHAPE THAT LOOKS LIKE | | L28260 | ADDENDUM | §NNN — sharpens §167-13's boundary: CHAINING TWO IDENTICAL SIDE-BY-SIDE STORES INTO ONE C | | L28293 | ADDENDUM | §NNN — sharpens §162a3/§60b: A `sll $v0,16 / sltiu $v0,1` ZERO-TEST OF A JUST-DECREMENTED | | L28326 | ADDENDUM | §NNN — sharpens §37/§124 (unspecified-parameter-list family): DERIVE A CALLEE'S ARITY LOWE | | L28359 | ADDENDUM | to §5a (func_80181F74, ov_SC03_112, wave cn) | | L28409 | ADDENDUM | to §265 (func_8017E26C, ov_SC04_016, wave cn) | | L28447 | ADDENDUM | to §42b (func_8018247C, ov_SC07_002, waves cu + cw) | | L28478 | ADDENDUM | to §199-F family (func_8017EFB0, ov_SC02_021, wave cu) | | L28533 | ADDENDUM | to §195-E (func_800CFC1C, md_MAIN_003, wave cv) | | L28578 | ADDENDUM | to §215 addendum (func_800CB2C8, md_MAIN_033, waves cv + cw) | | L28634 | ADDENDUM | to §236 item 4 (func_8017D268, ov_SC04_006, wave cw) | | L28663 | What | I could not verify | | L28695 | Harness-defect | flags (not idioms — flagged for the operator) | | L28736 | ADDENDUM | to §250 (func_8017D7CC, ov_SC03_115 — cx/cy/cz/dr) | | L28781 | ADDENDUM | to §225 (func_8017E190, ov_SC03_115 — cx/cy/cz) | | L28834 | ADDENDUM | to §45-A (func_8017F6A4, ov_SC02_016 — cy/cz) | | L28878 | ADDENDUM | to §249 (func_80182ED4, ov_SC04_004 — dp/dr/dt) | | L28923 | ADDENDUM | to §199-A (func_801816FC, ov_SC02_005 — dp/dr/dt) | | L28969 | What | I could not verify | | L29012 | Harness-defect | flags | | L29074 | §284 | COMBINE CAN REASSOCIATE TWO SEQUENTIAL BITWISE-AND MASKS INTO ONE AGAINST THE PRE-MASK VAL | | L29078 | §285 | PRE-INITIALIZING A VARIABLE WITH A SHARED CONSTANT BEFORE A BRANCH MAKES BOTH ARMS OF THE | | L29082 | §286 | FOLD A STATEMENT'S SIDE EFFECT INTO A COMMA-EXPRESSION IN AN ARGUMENT POSITION TO PLACE IT | | L29086 | §287 | A STACK-FRAME HOLE BELOW TWO ADDRESS-TAKEN AGGREGATE LOCALS IS A LEADING PAD MEMBER OF ONE | | L29090 | §288 | A REGISTER PIN DECLARED UNINITIALIZED AND ASSIGNED ONLY AT ITS LATE, SOLE USE STILL FORCES | | L29094 | §289 | an array local's address-taken base keeps every element's store alive, even though only on | | L29098 | §290 | A SINGLE STRENGTH-REDUCED GIV CAN DRIVE STORES TO SEVERAL DISTINCT RELOCATABLE SYMBOLS, EA | | L29102 | §291 | THE DELAY-SLOT FALSE-VALUE: A CONDITIONAL BRANCH'S ZERO ARM MUST BE A FALL-THROUGH-ADJACEN | | L29106 | §292 | DECLARING A SYMBOL UPSTREAM OF AN ALREADY-BANKED SIBLING THAT RELIES ON THAT SYMBOL'S IMPL | | L29109 | §293 | THE "WHOLE-OBJECT GATE NEEDS EVERY SIBLING" LAW, WRITTEN PROPERLY: IT IS THREE LAWS, AND T | | L29159 | §294 | ADDENDA HARVESTED FROM THE S61 GEN0/MAXTOK/MAIN/DEEPSEEK BATCH (waves ab8/ab16/ab24/ab32 · | | L29170 | ADDENDUM | to §127 — the -O0 constant-offset fold keys on the MEMBER-ACCESS tree shape, not on the in | | L29198 | ADDENDUM | to §261a — FOUR MORE -O0 DIALS BEYOND THE RELOAD COUNT (boot.c + md_MAIN_011/003, wave m0a | | L29248 | ADDENDUM | to §264-3 — the explicit entry copy's BOUND: required exactly when the RAW value must outl | | L29268 | ADDENDUM | to §172b-1 (counter-type dial) — the sll's SOURCE REGISTER is the placement discriminator | | L29280 | ADDENDUM | to §276 — the SHARE direction: spell the second adjacent symbol RELATIVE to force ONE anch | | L29296 | ADDENDUM | to §31's density-dummy dial (L2460/L2497) — the dose is TWO refs, and the dummy must sit w | | L29313 | ADDENDUM | to §282 — the ADDRESS-GIV face: write the walked address INLINE so strength reduction birt | | L29336 | ADDENDUM | to §253 — SECOND byte-proven card (upgrade from single-observation), and the placement fac | | L29357 | ADDENDUM | to the L1800 anchor-steer bullet — a DERIVED-POINTER local silently flips the merged giv's | | L29380 | ADDENDUM | to §31's asm→layout inference — TWO WIDTH-PAIR DISCRIMINATORS (same offset, different widt | | L29401 | §295 | THE KERNEL-TRAP STUB: §81's jr-DETECTOR WITHOUT A TABLE IS A PsyQ SYSCALL TRAMPOLINE — ROU | | L29456 | §296 | THE FRAME CHECK OUTRANKS THE ATLAS LEVER: READ PROLOGUE/EPILOGUE BEFORE DRAFTING ANY C — A | | L29499 | §297 | ONE GIV SERVING MIXED-WIDTH LOADS *AND* A STORE NEEDS STRUCT-MEMBER SPELLING; CAST/INDEX S | | L29542 | §298 | THE SHARED-TAIL POSITION DIAGNOSTIC: A FOLDED TAIL *BETWEEN* SWITCH ARMS MEANS PER-ARM DUP | | L29567 | §299 | TWO INDEPENDENT EXTRACTION CHAINS EMIT CONTIGUOUSLY INSIDE ONE EXPRESSION; ONLY A STATEMEN | | L29602 | §300 | S61 DISTILL BATCH NOTES (waves ab8/ab16/ab24/ab32 · g0a–g0f · m0a · ds1/ds2 · m0b) | | L29671 | §301 | AN INTERNAL `j` CARRIES `R_MIPS_26 .text`: rtu/match_one "MATCH" COULD NOT SEE WHICH LABEL | | L29719 | §302 | A RED BINARY IS A DRIFTED SPEC, NOT A MYSTERY: THE THREE CARVE-STATE INVARIANTS AND HOW TO | | L29763 | §303 | MODULE ISLAND TABLES: DERIVE THE PADS AT BUILD TIME, PEEL NOTHING — THE §154-A/§260 "islan | | L29799 | §304 | SELF-DEFINING RODATA: WHEN A FUNCTION'S `.s` IS THE ONLY OWNER OF THE DATA IT REFERENCES, | | L29822 | §305 | "CARVE-REFUSED" AT GATE TIME IS THREE NAMED, DETERMINISTIC CLASSES — NONE OF THEM A CARVE | | L29874 | §306 | A HAZARD `nop` IN FRONT OF A DIV-RESULT STORE IS A STATEMENT-ORDER DEFECT: THE INDEPENDENT | | L29901 | §306a | T4 DISTILL ADDENDA (P31 S62; four byte-proven refinements to existing laws, verified again | | L29939 | §307 | THE BRUTE-FORCE-THE-STATEMENT-ORDERS LEVER HAS A BOUND: A FAN-OUT COPY'S PRIORITY IS SCHED | | L29983 | §308 | A NAIVE FINAL `goto` DELETES THE TARGET'S `j`+`nop`: SPELL THAT EDGE AS A TAUTOLOGICAL `if | | L30012 | §308a | A TWO-INSTRUCTION ARM STUB LAID *BEFORE* THE OTHER ARM AND REACHED ONLY BY A TRAILING `j` | | L30046 | §309 | A FRAME-ADDRESS EQUIVALENCE RIDES *THROUGH* A SKIPPABLE CONDITIONAL: POST-`if` STORES FOLD | | L30086 | §310 | A TWO-OPERAND `subu`'s DESTINATION TIES ONLY TO THE OPERAND THAT IS BLOCK-LOCAL: SHARE *ON | | L30117 | §311 | A JOIN-BLOCK STORE CAN SWALLOW AN ARM'S LOAD-DELAY `nop`: WHEN ONE ARM'S VALUE COMES FROM | | L30159 | §312 | A BARE RELATIONAL IN AN `if` GIVES THE `slt` NO TARGET: ASSIGN THE COMPARISON INTO THE ALR | | L30185 | §313 | A RECOVERY STAGE THAT REWRITES THE DRAFT IS PART OF THE MEASUREMENT: GATE THE RAW DRAFT FI | | L30241 | §314 | AN IF/ELSE-IF ABS-RANGE CHECK'S C SPELLING IS INERT: FOUR STRUCTURALLY DIFFERENT REWRITES | | L30273 | §315 | ALL-CONSTANT AGGREGATE FILL: THE EMISSION ORDER IS SHARED-LITERAL GROUPS × DESCENDING INDE | | L30310 | §316 | A GUARD CHAIN THAT GATES A SUCCESS BLOCK ROUTES ITS FAILING GUARDS TO A LABEL **BEFORE** T | | L30344 | §317 | A NARROW STRUCT-FIELD STORE TURNS A *LIVE SImode VARIABLE* INTO A `li`: convert.c's TRUNCA | | L30378 | §318 | A UNARY MINUS STORED BACK INTO THE SAME HALFWORD IS COMPUTED IN HImode, SO ITS LOAD IS `lh | | L30453 | Addendum | §148-A2 addendum — the empty-asm insn_count dial (N bare `__asm__("")` = exactly +N real i | | L30461 | Addendum | §312 addendum — naming the compare's dest is the vehicle, the hard-reg pin on that name is | | L30465 | Addendum | subu/sh dest reuses a pinned operand's dying register (func_8017F498) | | L30473 | Addendum | Addendum to §261a — the -O0 increment-operator copy also fires on the POINTER LOCAL itself | | L30477 | Addendum | Addendum to §164-XX/§165-06 — at -O0 a bare local IS a memory lvalue, so the increment ope | | L30481 | Addendum | Addendum to §312 — the compare's named destination must itself carry a hard register: nami | | L30485 | Addendum | Addendum to §167-12 — the single-operand volatile keepalive, re-confirmed at a gated MATCH | | L30489 | Addendum | A §5a BARRIER SITS IN REORG'S FILL WINDOW TOO, SO ITS SIDE OF THE INNER `goto` IS CHOSEN P | | L30493 | Addendum | Loop sentinel wrongly hoisted out of a call-containing loop (func_801835B0) | | L30505 | Addendum | Reversed-operand sltu then xori 1 means unsigned less-or-equal (func_8017D948) | | L30509 | Addendum | Chained *2*2 array index folds to one copy;sll, not two (func_80011380) | | L30523 | Addendum | REGALLOC-PERM: one memory-clobber barrier insufficient — stack two (func_80182D1C) | | L30529 | Addendum | Last if-arm's nested if un-fuses the whole preceding chain (func_8017FE88) | | L30533 | Addendum | A plain global-RMW triplet is a fillable scheduling window too — zero drift, and the fille | | L30537 | Addendum | Shared arithmetic that CONSUMES the selected value cannot be hoisted above the `if` — narr | | L30541 | REFUTED | claim — Dead call-arg register address-fold: no C-level lever found (func_8017ECAC) | | L30560 | Addendum | Truncating assign must be the lazy `||` operand, not hoisted (func_80012B58) | | L30572 | Addendum | WIDTH sh!=lhu residual: hoist a sibling field's load first (func_80182538) | | L30589 | REFUTED | claim — REFUTED — the `j`-slot store is an ASPSX macro-expansion hop, not a cse split; mas | | L30591 | §NNN | REFUTED: A `sw %lo(SYM)($at)` IN A JUMP'S DELAY SLOT WITH ITS `lui $at` STRANDED ABOVE THE | | L30615 | Addendum | Static local_type blocker survives typedef removal — it's textual (func_801588CC) | | L30622 | Addendum | Orphan sh triplet to $sp is a write-only local array (func_8017F274) | | L30626 | Addendum | REGALLOC-PERM: the store reads the narrow copy's register — split the one narrow local by | | L30630 | Addendum | REGALLOC-PERM store in a cross-jump shared tail defeats §137's barrier (func_8017EDE8) | | L30634 | Addendum | LENGTH-DRIFT nop clears when offset math precedes the symbol launder (func_80039B20) | | L30638 | REFUTED | claim — REFUTED: a block shared across TWO switch statements is ordinary forward cross_jum | | L30640 | §NNN | REFUTED: A CODE BLOCK SHARED BY TWO *DIFFERENT* SWITCH STATEMENTS IS ORDINARY FORWARD `cro | | L30656 | RETRIEVAL | FAILURES this round (not new knowledge — a RETRIEVAL defect) | | L30671 | §319 | N TEXTUALLY DUPLICATED `return v;` TAILS PUT THE LAST `or` AND THE RETURN-REGISTER MOVE IN | | L30700 | Addendum | Masked-OR field-merge plateaus at close=10; bitfield store clears it (func_8017FD64) | | L30704 | Addendum | Integer-space address arithmetic is a THIRD no-movable spelling, and a distant `SYM[0]` re | | L30714 | Addendum | LENGTH-DRIFT −1 on a coalesced-away copy: a CALLER-SAVED SOURCE pin can resurrect it, boun | | L30721 | Addendum | Return-0 statement order: extra j+move vs delay-slot fusion (func_8018BB50) | | L30725 | Addendum | Counter zero in the DECLARATION slot, empty for-init — the prologue SHIFT-DRIFT/+K face of | | L30743 | Addendum | The dying-pinned-register reuse on a sign-extend chain: route every later read through a s | | L30747 | Addendum | Volatile zero-byte asm slider scrambles the prologue schedule (func_801814B0) | | L30757 | Addendum | Register-pinned helper pointer local regresses closeness; use plain local (func_80013CFC) | | L30761 | Addendum | §194-A addendum — the bare/colon-less fence measured NULL and only the "memory"-clobber fo | | L30765 | RETRIEVAL | FAILURES this round | | L30786 | §320 | THE §43 "RETURN-TYPE FLIP PAIR" IS **NOT** TU-EDIT-REQUIRED: THREE DRAFT-ONLY ESCAPES (P31 | | L30845 | §321 | FILE-SCOPE DUPLICATE ANONYMOUS-STRUCT TYPEDEFS ARE A HARD ERROR; THE SAME TEXT AT BLOCK SC | | L30866 | §322 | A PROBE THAT ANSWERS A *NECESSARY BUT NOT SUFFICIENT* QUESTION WILL PRICE BLOCKED WORK AS | | L30896 | §323 | CARRYING FILE-SCOPE TYPES BETWEEN SPLIT TUs: DEDUPE BY NAME, SKIP HEADER-PROVIDED, AND THE | | L30926 | §323a | R53, TWICE IN ONE HOUR: A FAILED BUILD LEAVES THE PREVIOUS BINARY, AND `sha1sum` READS GRE | | L30935 | §323b | A SCRIPT THAT PARSES argv AT IMPORT CANNOT BE SHARED; EXTRACT THE PREDICATE, DO NOT COPY I | | L30949 | §324 | THE ARITY-SELF WALL NEEDS *BOTH* HALVES: A K&R DEFINITION **AND** A NO-PROTO TU DECL; EITH | | L30987 | §325 | REGALLOC: A SHARED SMALL CONSTANT STORED TWICE IN THE PRE-LOOP BLOCK IS A *local-alloc* $s | | L31000 | §326 | DEFEATING ADDRESS-CSE: SPELL TWO READS OF THE SAME HALFWORD DIFFERENTLY AND GCC CANNOT SHA | | L31009 | §327 | A RANGE TEST MUST BE HImode: WITH `s32` + A `(u16)` CAST GCC *PROVES* THE MASK REDUNDANT A | | L31024 | §328 | THE VOLATILE ALIAS MUST BE AN *OBJECT*, NOT A CAST: `*(volatile s32*)&sym` UNFOLDS %lo INT | | L31034 | §329 | fold-const NARROWS `(int)s16_var & 0xFFF` ONTO THE *RAW HImode PSEUDO*, BREAKING THE SIGN- | | L31042 | §330 | THE NEIGHBOUR-SHAPE LEVER IS THE CHEAPEST FIRST MOVE, AND IT IS UNDER-USED (P31 S67; four | | L31059 | §331 | OPEN GAP: NO LEVER ELIMINATES AN *UNWANTED DUPLICATE* COPY AT A BRANCH-TARGET BLOCK HEAD ( | | L31071 | §332 | THE maspsx `la`-IN-A-DELAY-SLOT GAP: gcc EMITS A SYMBOLIC ADDRESS LOAD AS ONE ATOMIC lengt | | L31096 | §332a | MAIN'S RESIDUAL FRONTIER IS CONTAMINATED WITH TOOLCHAIN WALLS: 4 OF 7 IN ONE WAVE (P31 S67 | | L31115 | §333 | FRAME SIZE IS SET BY *DECLARED* AGGREGATES, NOT USED ONES: AN UNREFERENCED TRAILING LOCAL | | L31129 | §334 | A RELOAD SPILL SLOT IS ROUNDED TO `BIGGEST_ALIGNMENT` (8B), SO ONE SPILLED 4-BYTE PSEUDO C | | L31140 | §335 | AN `extern u16 A[]` READ AT A VARIABLE SUBSCRIPT ALLOCATES DEAD STACK TEMPS (~8B PER ACCES | | L31149 | §336 | THE §5a CROSS-JUMP BARRIER GOES AT THE *BOTTOM* OF THE TWIN, NOT THE TOP: `find_cross_jump | | L31157 | §337 | THE CC1-ONLY BLOCKER CLASS: `blocker_probe`'s STATIC ORACLE REPORTS "none" AND THE WHOLE-T | | L31171 | §338 | `jtbl_carve._sltiu_bounds` MISREADS A NON-SWITCH `sltiu` AS A BOUNDS CHECK, OVER-SPANNING | | L31181 | §339 | A 2-CASE SWITCH OMITS THE LOW-BOUND RANGE TEST, SO THE PRESENCE OF `slti/bnez` BETWEEN THE | | L31209 | §340 | §194-K COROLLARY: **FLIP THE FALSE EDGE YOU CANNOT DELETE.** A "scheduler" residual can be | | L31243 | §341 | AN HImode STORE TEMP REWEIGHTS A sched2 TIE-BREAK THAT NO STATEMENT ORDER CAN REACH (P31 S | | L31257 | §342 | A `void *` PARAMETER CAST TO ITS REAL TYPE IN A LOCAL IS **NOT** BYTE-NEUTRAL WHEN A LATER | | L31274 | §343 | `decl_prior`'s FLEET MAJORITY CAN BE WRONG ABOUT THE TRUE SIGNATURE — READ THE RIVALS, NOT | | L31296 | §344 | RAISE A BIV'S global_alloc PRIORITY WITH A ZERO-BYTE REFERENCE INSTEAD OF PINNING IT; PINN | | L31312 | §345 | A VOLATILE **STORE** EVICTS THE MEM FROM cse AND KEEPS `sh`; A VOLATILE **LOAD** BLOCKS co | | L31322 | §346 | `c ? X : -X` TAKES expand_expr's COND_EXPR **SINGLETON** PATH (copy, then negate IN PLACE) | | L31342 | §347 | LOOP REGISTER ASSIGNMENT IS A **DECLARATION-ORDER + LIVE-RANGE** DIAL: FIVE COMPOSABLE LEV | | L31372 | §347-addendum | A THIRD INSTANCE, AND THE SHARPEST STATEMENT OF THE RULE (md_MAIN_025/func_800CB300, 243 i | | L31390 | §343-addendum | SECOND INSTANCE OF THE WRONG-MAJORITY DECL (same function) | | L31397 | §348 | THE BASE SPELLING PICKS THE ADDRESSING MODE: A SYMBOL GIVES THE 3-INSN `lui/%lo` FORM, A P | | L31414 | §349 | RE-ASSIGN A BASE POINTER AT THE END OF THE LOOP BODY TO MAKE `n_times_set > 1` — THAT KILL | | L31435 | §350 | A ZERO-BYTE RE-TIE SETS `reg_n_sets=2`, WHICH KILLS sched1's `birthing_insn_p` LAUNCH_PRIO | | L31456 | §351 | `/s` (MEM_IN_STRUCT_P) IS A DIAL YOU CHOOSE PER ACCESS: A COMPONENT_REF GRANTS IT AND LETS | | L31486 | §352 | ⚠ TWO IDENTICAL `__asm__ __volatile__("")` BARRIERS **MERGE WITH EACH OTHER** — SPELL THE | | L31519 | §353 | USE `-fno-thread-jumps` AS AN **ORACLE** TO PROVE A RESIDUAL IS thread_jumps, THEN LAUNDER | | L31542 | §354 | THE giv **WORTH-WHILE TEST** IS A DIAL: RE-ASSOCIATE THE ADDEND INTO THE INDEX TERM AND `s | | L31560 | §355 | A REMAPPED SIBLING'S **SOURCE BIAS IS NOT ITS EMITTED BIAS** — DO NOT HAND-SHIFT OFFSETS T | | L31574 | §356 | MEASURE A DRAFT IN THE TU IT WILL LIVE IN, NOT IN THE STANDALONE PROBE (P31 S68; measured | | L31589 | §357 | ONE STRUCT POINTER, NOT TWO: A SECOND SOURCE VARIABLE BUILDS A THIRD IV (P31 S68; byte-pro | | L31598 | §358 | (sharpens §333) — AN **UNREFERENCED** FIXED-SIZE AGGREGATE LOCAL IS LOAD-BEARING (P31 S68; | | L31608 | §359 | (§43-adjacent) — SPELL A SIGN-WIDEN AS AN EXPLICIT TWO-STEP, FUNCTION-SCOPED TEMP (P31 S68 | | L31621 | §360 | THE "COMPILER FOUND A SHORTER EQUIVALENT THAN THE TARGET" PAIR (P31 S68; main/func_800241C | | L31637 | §361 | ★ — A LOOP-TAIL BYTE SIGNATURE THAT NAMES ITS SOURCE SHAPE — AND THE LAW THAT A "SCHEDULIN | | L31682 | §362 | TWO TRAPS WHEN A CARVE MOVES A STUB INTO THE `-O0` TU (P31 S68; byte-proven, 6 fns / 2,547 | | L31705 | §363 | ★★ — THE OVERLAY-LAYOUT ASSUMPTION IS A SYSTEMIC BUG CLASS, AND `main` IS THE EXCEPTION TH | | L31734 | §364 | ★ — THE libgpu `P_TAG` BITFIELD SPELLING IS **OPT-LEVEL DEPENDENT** (P31 S68; two function | | L31748 | §365 | PIN **BOTH** MASKS OR NEITHER (P31 S68; ov_SC01_000/func_8017E594, 357 ins) | | L31757 | §366 | ★★ — `group_case_nodes` MERGES **STACKED CONSECUTIVE** CASE LABELS: GIVE EVERY CASE ITS OW | | L31777 | §367 | RECONCILING A DECL CONFLICT BETWEEN TWO DRAFTS FOR THE SAME TU (P31 S68; main) | | L31792 | §368 | ★★★ — THE **RELOAD-REMAT CONSTANT**: REACH A REGISTER NO PIN CAN REACH (P31 S68; ov_SC03_1 | | L31822 | §369 | REUSE THE **COMPARE CONSTANT'S OWN VARIABLE** FOR A MASK THAT KEEPS COALESCING (P31 S68; m | | L31838 | §370 | ★★ — A **HARD BOUND** FROM sched.c, AND THE reorg SLOT-STEAL DIAGNOSTIC (P31 S68; main/fun | | L31890 | §371 | ★★ — CARVING A **SINGLE-OBJECT MODULE BINARY**, AND THE spimdisasm RODATA-MIGRATION TRAP T | | L31939 | §372 | ★★★ — THE **COPY-CAPTURE PAIR**, AND THE ONE ZERO-BYTE EDIT THAT DEFEATS BOTH (P31 S68; by | | L31977 | §373 | ★★★ — THE **DEAD-RESET CSE-BREAKER**, THE PIN THAT BREAKS A sched2 ANTI-DEP, AND WHY AN `a | | L31979 | §3-1. | DEAD-RESET CSE-BREAKER — the zero-footprint replacement for a §195-I asm re-tie | | L31997 | §3-2. | A REGISTER PIN THAT DELETES A sched2 ANTI-DEPENDENCE | | L32010 | §3-3. | HARD FACT FOR THE SCHEDULING MAP — an `asm` ALWAYS has priority 1 | | L32018 | CROSS-REFERENCE | TO §370 — checked and found INAPPLICABLE here, which is the point | | L32026 | §374 | A `register … __asm__("$30")` RESERVATION IS **NOT HONOURED** BY `move_movables` (P31 S68; | | L32042 | §375 | AN `$a0`-`$a3` PIN USED LATE RELOCATES AN **EARLIER** OUTGOING-CALL USE OF THAT REGISTER ( | | L32055 | §376 | ★★★ — A STANDALONE `match_one` CLOSENESS OF 0 IS A CLAIM ABOUT THE **BODY**, NEVER ABOUT T | | L32097 | §377 | THREE HARNESS DEFECTS FOUND IN ONE GATING SESSION, ALL "A CONFIDENT NUMBER ABOUT A SMALLER | | L32114 | §378 | ★★★ — THE **SELF-CALLER CAST**: LET A TU KEEP CALLING THE FUNCTION IT IS ABOUT TO DEFINE ( | | L32164 | §379 | ★★★ — **MEM_IN_STRUCT_P**: THE SAME LOAD, WRITTEN AS A STRUCT MEMBER, SCHEDULES WHERE A CA | | L32195 | §380 | ★★★ — **A SECOND SET OF A PSEUDO DISQUALIFIES IT FROM `move_movables`** (P31 S69; main/fun | | L32216 | §381 | THE `insn_count` HOIST THRESHOLD IS A DIAL YOU CAN READ WITH `cc1 -dL` (P31 S69; four inde | | L32232 | §382 | TWO FOLD REASSOCIATIONS THAT NEED THEIR OWN STATEMENT (P31 S69) | | L32244 | §383 | TWO TOOLCHAIN FACTS THE PACKS DID NOT CARRY (P31 S69) | | L32259 | §384 | ★★★ — A CARVE-CONFIG BANK IS RED UNTIL YOU RE-EXTRACT, AND THAT LOOKS EXACTLY LIKE A FALSE | | L32309 | §385 | ★★★ — THE **SCHED2 PRIORITY-DONOR ASM**: closing the "hoisted-invariant vs IV-init prehead | | L32335 | §386 | ★★★ — A BYTE LOAD ON THE **BIV** BASE WAS BORN IN THE COMBINE PASS: SPELL IT AS A SHIFT-MA | | L32361 | §387 | ★★ — **SPLIT-FOLD DISPATCH CLOBBER**: one switch case needs a reload, another must keep th | | L32384 | §388 | ★★★ — THE **-O0 COLOURING ORACLE**: simulate `stupid.c` instead of grinding spellings (P31 | | L32409 | §389 | ★★★ — `h_norm` IS BLIND TO INDEXED-GLOBAL RELOCS, SO FREE WORK BECOMES AN INVISIBLE SINGLE | | L32450 | §390 | ★★★ — MINIMUM DISTANCE IS NOT MINIMUM WORK; RANK TWIN CANDIDATES BY EFFORT, AND FILTER LOO | | L32488 | §391 | ★★ — A BYTE-ALIGNED STRUCT COPIES IN FOUR INSTRUCTIONS, A WORD-ALIGNED ONE IN TWO (P31 S69 | | L32502 | §392 | ★★★ — THE SONNET-WAVE HARVEST (P31 S69): SEVEN TYPE/ORDER LEVERS THAT EACH CLOSED A MATCH | | L32543 | §393 | ★★ — THE **BIRTHING BOOST**: A SINGLE-SET LOCAL IS SCHEDULED LAST; GIVE IT A SECOND SET (P | | L32560 | §394 | ★★ — TWO ALIGN-1 ACCESSES IN ONE FUNCTION RESERVE A PHANTOM STACK SLOT (P31 S69; ov_SC02_0 | | L32572 | §378b | ★★★ — THE FOUR VARIANTS OF THE DECL BLOCKER, AND THE TWO PLACES §378 DOES **NOT** APPLY (P | | L32611 | §395 | ★★★ — FIVE NARROWING/PLACEMENT LEVERS FROM ONE 91-INSTRUCTION CRACK (P31 S69; byte-proven | | L32645 | §314b | ★★ — TWO ABS-RANGE GUARDS IN ONE FUNCTION NEED **DIFFERENT SPELLINGS** (P31 S69; byte-prov | | L32667 | §322b | ★★★ — THE CARVE CLASS IS COMPLETABLE, AND EVERY WORKTREE `CARVE-REFUSED` WAS AN INSTRUMENT | | L32702 | §332b | ★★★ — THE §332 "WALLS" ARE A PER-OBJECT ASSEMBLER MODE, NOT A C LIMIT — 6 CLOSE AS REAL C | | L32722 | §378c | ★★ — THE FIFTH DECL-BLOCKER VARIANT: THE DRAFT REDECLARES WHAT THE TU ALREADY OWNS (P31 S6 | | L32737 | §396 | ★★★ — SIX LEVERS FROM THE S69 SINGLETON ROUND, INCLUDING ONE THAT ONLY A `COND_EXPR` REACH | | L32785 | §397 | ★★★ — RE-RUN THE TWIN SCAN AFTER EVERY EXEMPLAR BANK; A CLUSTER SIBLING IS FREE THE MOMENT | | L32818 | §396g | ★★ — A GUARD LADDER'S RUNGS MUST STAY SYMMETRIC OR `reorg.c` LOSES ITS BRANCH REDIRECT (P3 | | L32835 | §398 | ★★★ — `family_remap` CARRIES THE **SOURCE** TU's DECL ENVIRONMENT INTO A DESTINATION THAT | | L32865 | §398b | ★★ — NAMING A SUB-EXPRESSION IN A LOCAL CHANGES WHICH PSEUDO SURVIVES; INLINE IT AT BOTH U | | L32892 | §399 | ★★★ — FOUR LEVERS FROM THE FINAL S69 ROUND (P31 S69; each byte-proven, none previously in | | L32932 | §400 | ★★ — A BASELINE CHECK THAT CONFLATES "ABSENT EVERYWHERE" WITH "CHANGED UNDER US" SILENTLY | | L32967 | §401 | §401 | | L33000 | §402 | §402 | | L33024 | §403 | §403 | | L33056 | §404 | §404 | | L33092 | §405 | ★★★ — THE S70 WAVE HARVEST: 130 agents, 113 MATCH, and the laws they brought back | | L33098 | §3-A. | THE ORACLE HAS A HOLE: match_one cannot see a jump table (§405-A) | | L33108 | §3-B. | THE SCHEDULER DIALS (the dominant residual family this wave) | | L33124 | §3-C. | REGISTER ALLOCATION FROM C, WITHOUT PINS | | L33140 | §3-D. | INTEGRATION IS STILL THE BOTTLENECK, AND THE TU IS THE AUTHORITY | | L33148 | §3-E. | WHAT THE AGENTS REFUTED | | L33158 | §406 | ★★ — THE PROLOGUE-WEAVE CLASS IS MECHANICAL AND LARGE (134 open stubs) | | L33180 | §407 | ★★ — LATE-WAVE ADDENDA TO §405 (the last agents in) | | L33209 | §408 | ★★★ — §406 REFUTED AS A SWEEP: THE SHAPE IS THE FAMILY, THE DISAGREEMENT IS THE DEFECT (P3 | | L33261 | §409 | ★★★ — THE S71 JOURNAL-FUELLED WAVE: 100% FIRST-PASS MATCH, AND THE NINE LAWS IT BROUGHT BA | | L33288 | §3-The | nine laws this wave produced | | L33353 | §410 | ★★★ — COPY THEN ACCUMULATE ON THE COPY: resolving the birthing-boost vs register-allocatio | | L33386 | §411 | ★★★ — THE PACK MUST CARRY THAT FUNCTION'S OWN HISTORY (P31 S71; measured 38/39 vs 124/131) | | L33424 | §412 | ★★★ — §323 CARVE BLOCKER 2 WAS A REGEX THAT COULD NOT SEE PAST `__attribute__` (P31 S71) | | L33473 | §413 | ★★★ — DIFFICULTY IS THE RESIDUAL CLASS, NOT `nins` — ROUTE THE MODEL TIER OFF HISTORY (P31 | | L33510 | §414 | ★★★ — `parallel_gate` ON `main` IS A FALSE PASS, AND THE RULE WAS ALREADY WRITTEN DOWN (P3 | | L33547 | §415 | ★★ — A FILE-SCOPE DECL MAKES gcc-2.7.2 MERGE THE TU'S LATER *BLOCK-SCOPE* EXTERNS INTO IT | | L33572 | §416 | ★★ — FOUR LEVERS FROM THE S71 OVERNIGHT LANE, none of which the cookbook held (P31 S71) | | L33605 | §417 | ★★★ — A REGISTER PIN CAN BLOCK `jump.c`'s SELECT COLLAPSE, AND UNPINNING THEN EXPOSES A `c | | L33632 | §418 | ★★★ — TWO LOOP-STRUCTURE LEVERS: MAKE THE SECOND INDEX A GIV, AND KEEP A TABLE ADDRESS UNF | | L33658 | §419 | ★★★ — WHEN A PIN IS IMPOSSIBLE, WIN THE local-alloc DENSITY CONTEST INSTEAD (P31 S71; byte | | L33692 | §420 | ★★★ — A MULTI-CLUSTER SYMBOL REBASE, AND THE BARE-NAME DEDUP THAT HID THREE QUARTERS OF IT | | L33729 | §421 | ★★★ — A `la $tN` + `addiu` PAIR CAN BE A **RELOAD** ARTIFACT THAT NO C SPELLING REACHES (P | | L33760 | §422 | ★★ — QImode ARITHMETIC VIA `(u8)(x - K)`, AND `flag ^ 1` NEEDS ITS OWN TEMP (P31 S71; byte | | L33780 | §423 | ★★★ — "MATCH IN ISOLATION + GATE REJECTS + CAUSE NOT DETERMINED" ⇒ GREP THE TU FOR A FILE- | | L33807 | §424 | ★★★ — EQUAL-PRIORITY STORES COME OUT **REVERSED**: sched1's LUID tie picks the LAST statem | | L33829 | §425 | ★★★ — `sb` ALIASES SCALAR GLOBALS WHILE `sh`/`sw` STRUCT STORES DO NOT, AND TWO MORE ALIAS | | L33855 | §426 | ★★★ — main's SWITCH FUNCTIONS WERE NEVER A CODEGEN WALL: ONE RODATA CARVE HAD BEEN MISSING | | L33931 | §427 | ★★ — A HASH IS A CORRECTNESS ORACLE WITH ZERO DIAGNOSTIC CONTENT; PRESERVE THE RED ARTIFAC | | L33950 | §428 | ★★★ — A ZERO-BYTE CROSS-JUMP BARRIER: ADVANCE THE POINTER INSIDE EACH SWITCH ARM (P31 S72; | | L33988 | §428a | ★★★ — TWO RESIDUALS THAT MOVE IN OPPOSITE DIRECTIONS UNDER EVERY LEVER USUALLY SHARE ONE C | | L34023 | §430 | ★★★ — A SHARED TAIL IS A LATE CROSS-JUMP MERGE, NOT A SOURCE `goto` — AND SPELLING IT AS O | | L34061 | §431 | ★★★ — SPLITTING A 27,000-LINE TU AT ITS ORIGINAL BOUNDARIES: THE JTBL SPANS TELL YOU WHERE |