5.8 KiB
§126 — The carve-within-a-carve: an ADDRESS RANGE is not an OPTIMIZATION REGION (P30 T2, byte-proven end-to-end)
A 4th -O0 region was found inside an -O2 jr split (0x80183CF0..0x80184920, ov_SC03_014 +
ov_SC03_015). Banking it needs the containing object sub-split into pre/-O0/post — the
"carve within a carve" the roadmap had flagged as blocked on the Arm-A splat %lo +0x20 defect.
It is not blocked. Four probes, each isolating exactly one variable, SHA vs config/check.<ov>.sha
from a clean tree:
| probe | isolated | result |
|---|---|---|
| 1 | sub-split at arbitrary addresses, everything still -O2 |
BYTE-NEUTRAL — the re-carve does not shift %lo; Arm-A does not bite |
| 2 | same split, middle region routed -O0 |
diverged (two variables changed at once — inconclusive) |
| 3 | probe-1's name, only the -O0 flag added |
diverged ⇒ the FLAG, not the subseg name |
| 4 | -O0 regions cut to EXCLUDE matched bodies |
BYTE-IDENTICAL — route proven |
The finding: opt level is per FILE, so the file's contents must be opt-HOMOGENEOUS
§116 says opt level is a property of the FILE. The corollary nobody had needed until now: when you
select a region by address range, you get everything in that range — including functions that are
already MATCHED, whose bodies expand from engine_core.h as DEFINE_func_*() instantiations and
are compiled -O2. Flipping the file recompiles them, and they stop matching. Here two matched bodies
(func_80184440, func_801848E4) sat interleaved among the 15 -O0 stubs. Cut around them —
[lo..matched), matched stays -O2, [after..hi) — and the image is byte-identical.
So the region bound is: (address range) MINUS (already-matched bodies), and a range with K
interleaved matched functions needs K+1 -O0 sub-regions, not one.
The instrument trap that hid it (and it is §124's shape again)
I first derived "15 contiguous -O0 functions, clean cut" by scanning asm/<ov>/nonmatchings/**/*.s
for the frame-pointer prologue (addu $fp,$sp,$zero / 21F0A003). A MATCHED function emits no
.s — splat writes none, because its .c carries real C. So that scan is structurally blind to
precisely the bodies that break the flip, and it reported a clean run where the range was mixed.
Derive the region's contents from the SOURCE anchors (INCLUDE_ASM stubs and DEFINE_func_*()
instantiations, in address order), never from an asm-file scan. corpus.stubs gives the stubs; the
DEFINE_func_ instantiations in the region .c give the matched ones.
The mechanics
- Cuts:
jr_isolate_all'splan()/build_new_config()already accept arbitrary cut vrams — region naming is purely positional, so nothing new is needed for the split itself. Inject the cut list and reuse its source-repartition, carve-repoint and ascending/unique validation verbatim. - The one-carve-per-region law still applies: every already-banked jr in the object must ALSO be
a cut, or two carve owners share one object and its single contiguous
.rodatamust host both. - Naming + the Makefile: name each
-O0sub-region<ov>_o0<letter>and let ONE widened rule select them — the glob is now$(wildcard src/ov_*/ov_*_o0?.c)(was_o0b). A missed-O0rule is SILENT: the region compiles-O2and every residual it produces is a pure artifact (§116).corpus.o0_sources()parses this rule and resolves?via glob, so the-O0oracle stays honest. - Verify the routing, don't assume it:
corpus.is_o0("src/<ov>/<ov>_o0c.c")must return True before you read a single residual from that region.
Method note
Probe 2 changed the name and the flag and was therefore uninterpretable. Probe 3 — same name as the proven-neutral probe 1, flag only — is what produced the answer. One variable per probe, and keep the previous probe's proven-neutral configuration as the control.
§126a — a bare except: continue around a coverage-asserting oracle re-creates the silent skip (P30 S28)
Sizing this cluster, I reported "275 open stubs across 18 overlays". The true figure is 2,184 across 138 — an 8× under-count that would have mis-scoped the whole task.
The scan was:
for ov in overlays:
try: st = corpus.stubs(ov)
except Exception: continue # <-- the defect
and it ran while make extract-all was rebuilding in the background, so corpus.stubs() hit its
R32 coverage assertion ("N stub(s) have NO .s on disk — the tree and the source disagree") for most
overlays. The bare except turned every one of those loud refusals into a silent skip, and the loop
happily reported a total over the ~18 overlays that happened to be re-extracted already.
Two rules, both already ours, both violated at once:
- A measurement taken during a rebuild is not a measurement. Earlier the same session the same
mistake was caught because
corpus.pyrefused — the assertion worked. Here I wrapped the assertion inexcept: continueand threw its answer away. - R32 lives in the CALLER too. A coverage-asserting oracle only asserts coverage if the caller
lets it raise.
except Exception: continuearound it is precisely the silent-skip class R32 exists to delete — reintroduced one level up, where no audit looks.
Practice: in any scan that will SCOPE work, let the oracle raise. If some binaries legitimately have no data, filter them by an explicit predicate you can state, and print the count you skipped and why. A total is only trustworthy if the denominator was asserted.
(It also cost credibility in the other direction: I used the bad number to call the T0(f) pin of "2,192 open members" STALE. The pin was right. Re-derivation is only worth more than a carried number if the re-derivation is sound — R35 applies to the re-measurement as much as the original.)